Bank & Financial Scams

Bank of America Scam Emails: How to Spot Them

Fake Bank of America alerts lean on urgency and a lookalike sign-in page. Here is how to tell the difference safely.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

Ignore every link and phone number in the message and check independently: open the Bank of America app or type bankofamerica.com yourself and sign in. Genuine alerts are mirrored in your account. Bank of America does not ask customers for their passcode, PIN, card security code, or a one-time authorisation code by email, text, or phone, and will never ask you to move money to another account to protect it.

Warning signs to look for

  • 'Your account has been temporarily locked' with a link to restore access
  • A sender domain that is not bankofamerica.com, such as bofa-secure-alerts.com
  • A request to confirm your online ID and passcode on a linked page
  • A refund, rebate, or rewards balance you must claim before it expires
  • An attached 'secure document' that opens a login form
  • A caller who says the email is genuine and asks you to read out a code

How the fake Bank of America messages are built

The common versions are an account-lock notice, a suspicious-sign-in warning, a declined-payment alert, and a rewards or refund claim. Each opens a page that copies the bank's sign-in screen closely, sometimes including the security image feature to look authentic — a detail criminals fake by simply showing a plausible picture. Some campaigns capture the passcode and immediately prompt for the one-time code that the real site has just sent you, which is how attackers defeat two-factor authentication in real time.

What real Bank of America communications look like

Genuine alerts are brief, avoid embedding sensitive details, and direct you to sign in through the app or the website rather than completing forms by email. The bank's published security guidance mirrors industry practice: employees will not request your passcode, PIN, card security code, or an authorisation code, and legitimate staff never require you to transfer funds to a 'safe' account. Anything of consequence is also available in your online banking alerts and message centre.

Verify without touching the message

Close the email or text. Open the app you already have, or type the bank's address in yourself. Check your alerts, recent transactions, and secure messages. To call, use the number on the back of your card or on a statement. If a real alert exists, you will find it there; if it does not, delete the message. This works even when the fake is technically excellent, which is why it is the habit worth building.

What the bank asks you to do with suspicious messages

Bank of America operates a security centre with a page for reporting suspicious emails, texts, and calls, and asks customers to forward the message rather than respond to it. If you disclosed information, they ask you to call using the number on your card or statement so the account can be protected right away. Reporting also helps get the fake page taken offline faster.

If you already gave information

Call the bank on a trusted number now. Change your online passcode from a device you trust and anywhere else you reused it. Sign out other sessions and review devices in your security settings. Watch for small test transactions. Report to the FTC at reportfraud.ftc.gov, and if funds moved, file with the FBI at ic3.gov the same day.

Get a second opinion before you act

If a message concerns your money and you cannot tell whether it is genuine, forward the original to check@spamcheck.com and wait for the answer. SpamCheck explains what the sender details and links actually show, in plain English, so you are not guessing.

SpamCheck is not affiliated with or endorsed by the companies mentioned in this guide. Brand names are used only to help consumers identify potential impersonation scams.

Frequently asked questions

The page showed my SiteKey image. Doesn't that prove it is the real bank?
No. A phishing page can display any picture it likes, and many simply show a generic image and hope you do not look closely. Treat a security image as a weak signal at best.
Are text messages safer than emails?
No. Text-based phishing, sometimes called smishing, uses the same tactics with even less visible detail. Verify texts the same way: through the app, not the link.
Should I reply STOP to a fake bank text?
No. Replying confirms your number is active. Block the sender, report the message to your carrier by forwarding it to 7726 (SPAM), and delete it.
Is SpamCheck affiliated with Bank of America?
No. SpamCheck is independent and is not affiliated with, sponsored by, or endorsed by Bank of America. The brand is named only to help people recognise impersonation.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides