That “suspicious activity” text is probably not your bank.
“ALERT: a payment of $487 was attempted from your account. If this was not you, verify immediately: [link].” It arrives at dinner, it looks exactly like the real thing, and the fake login page behind that link empties accounts in minutes. This is smishing — SMS phishing — and it works because it borrows your bank's own voice.
Fear in, credentials out.
Mass-sent texts spoof a bank's name or short code. The amount is specific, the tone is official, and “if this was not you” makes ignoring it feel dangerous.
The link opens a pixel-perfect copy of the bank's login. Everything you type — username, password, even the one-time code — goes straight to the attacker, who is logging into the real bank as you type.
Minutes later, “bank security” calls to help with the fraud they invented. Now they have your trust, and they talk you through approving transfers or reading out codes.
Every element is borrowed from real fraud alerts you have actually received. The scam does not look suspicious — it looks familiar.
Three things the fake cannot survive.
Never log in through a link that arrived by text or email, and never read a one-time code to anyone who calls — including “bank security.” The code is the key to your money; the caller is the reason it is being requested.
One habit: the app is the only door.
Decide it once, tell your family once: money alerts are only ever checked by opening the bank's app or typing the bank's address yourself. Alert texts can be read — never obeyed. Pair it with a saved official number for callbacks and this entire scam category dies in your household.