Bank & Financial Scams

Chase Scam Emails: How to Spot Them

Fake Chase alerts are among the most common bank phishing messages. Here is how to check one without clicking anything in it.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

Do not use any link or phone number in the message. Open the Chase mobile app or type chase.com into your browser yourself and sign in — every genuine alert also appears in your account or secure message centre. Chase, like every major bank, will not email, text, or call to ask for your password, your ATM PIN, your card's security code, or a one-time passcode, and will never ask you to move money to a different account for safekeeping. If a message asks for any of those, it is a scam.

Warning signs to look for

  • A text or email saying your Chase account is locked, restricted, or under review
  • A 'Did you make this purchase?' message with a link rather than a prompt inside the app
  • A sender domain that is not chase.com — for example chase-alerts.net or chasebank-secure.com
  • A request for your one-time passcode 'to confirm your identity'
  • A caller who follows up minutes after the message and knows what it said
  • Instructions to send money to yourself by Zelle to 'reverse' a fraudulent charge

The impersonation patterns you are most likely to see

Fake Chase messages cluster around a few stories. The first is a fraud alert asking you to confirm or deny a transaction, which pushes you to a lookalike sign-in page. The second is an account restriction that must be lifted within hours. The third — the most costly — is a phone call that arrives right after the text, from someone claiming to be Chase fraud prevention, who walks the victim through sending a Zelle payment 'back to themselves'. Because Zelle transfers settle within minutes and are difficult to reverse, this variant does the most damage and is the one to be most alert to.

What a genuine Chase message looks like

Real alerts are short, refer you to the app or to chase.com, and stop there. Chase's own security guidance is consistent with every other large US bank: staff will not ask for your password, PIN, security code, or a one-time passcode, in any channel. Genuine account activity is always visible after you sign in independently, and the secure message centre inside the app is the authoritative place to read anything important. Anything that only exists in your inbox, and nowhere in your account, should be treated as fake.

How to verify in two minutes

Close the message. Open the Chase app you already have installed, or type the address into your browser rather than tapping. Sign in and look at recent transactions and your secure messages. If you want to speak to someone, use the number printed on the back of your Chase card or on a paper statement — never a number supplied by the message you are checking. If the alert is genuine, you will find it. If it is not, you have lost two minutes and nothing else.

What Chase says to do with suspicious messages

Chase publishes a fraud and security centre with a reporting address for suspicious emails and texts, and asks customers to forward the message rather than reply to it. Report the loss of any card or credentials by phone using the number on your card. Do this even if you did not fall for it — reporting is what lets the bank take down the fake site and warn other customers.

If you already entered your details

Call Chase on the number on your card immediately and say credentials were entered on a phishing site. Change your chase.com password from a device you trust, then change it anywhere else you reused it. Review transactions for small test charges. Report to the FTC at reportfraud.ftc.gov, and if money left the account, file at ic3.gov the same day — speed is the single biggest factor in whether a transfer can be recalled.

Not sure? Have it checked first

Bank phishing is deliberately hard to call, and the cost of getting it wrong is high. Forward the original email to check@spamcheck.com before you click anything. SpamCheck reviews the sender, the authentication results, and the real link destinations, then replies in plain English with what it found and what to do next.

SpamCheck is not affiliated with or endorsed by the companies mentioned in this guide. Brand names are used only to help consumers identify potential impersonation scams.

Frequently asked questions

Chase texted me a code and then someone called about it. What is happening?
Someone is trying to sign in as you and needs the code to finish. Never read a code aloud or type it into a page someone sent you. Hang up, change your password, and call Chase on the number on your card.
The message showed the last four digits of my card. Is it real?
Not necessarily. Partial card numbers appear on receipts and in breach data and are used to build trust. Verify by signing in to the app instead.
Can I get Zelle money back?
Zelle payments are fast and often irreversible, but you should still report to Chase immediately — some claims are investigated and reimbursed, particularly when the transfer was unauthorised rather than authorised under deception. Report the same day.
Is SpamCheck affiliated with Chase?
No. SpamCheck is an independent service and has no affiliation with, sponsorship from, or endorsement by JPMorgan Chase. We reference the brand only to help people identify impersonation attempts.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides