Skip to main content
Consumer protection attorney in Tampa, Florida. Cases anywhere in Florida.
Free, confidential case review(813) 921-3516

Bank impersonation scams · FloridaA caller posed as your bank, and your account is empty. Who pays depends on who moved the money.

The phone showed your bank's name. The caller knew the last four digits of your account and said fraud was happening right now. They asked you to read back a code, confirm a password, or install an app, and within minutes your checking account was drained. Now the bank says you gave the scammer access, so the loss is yours. For Florida consumers, federal law often says otherwise, and the answer turns on one question.

The numbers that decide it
Scammer moved it with your code
Unauthorized transfer
You pressed send yourself
Federal law generally requires no refund
Bank's decision deadline
10 business days, or 45 days with provisional credit
Police report required?
No
Deadline to sue
1 year, often counted from the bank's misstep

Last reviewed October 8, 2026 by Jackson McMillan, Florida attorney

Short answer: If a caller posing as your bank tricked you into sharing a one-time code, password, or card number, and the scammer then moved the money, Regulation E treats those transfers as unauthorized and your bank must investigate and limit your loss. If the caller talked you into sending the money yourself, federal law generally does not require a refund.

What happens in a bank impersonation scam, and which version did you get?

A bank impersonation scam starts with a call, text, or email that looks like it came from your bank or credit union. The caller claims fraud is happening and needs you to act fast. The goal is access to your account: a one-time passcode, your password, your card details, or control of your phone or computer.

Caller ID is usually spoofed to show the bank's real number, and a data breach supplies the personal details that make the caller sound legitimate. Neither changes your rights.

The fake fraud alert

A text that reads like the bank's real alerts asks whether you made a $900 purchase. You reply NO, your phone rings, and the "fraud department" walks you through canceling the charge, which includes reading back the code the bank just texted you. The scammer used that code to log in and send money out.

"Move your money to a safe account"

The caller says your account is compromised and your balance must move to a "secure" account. Sometimes the scammer, already logged in with your credentials, moves it. Other times the caller coaches you through sending it yourself. That distinction matters more than anything else on this page.

The remote-access app

The caller has you install a screen-sharing or remote-access program so a "technician" can secure your device. The scammer can then read incoming codes and move money while you watch. In the bank's records those transfers come from your device and your login, which is why banks so often label them yours.

The two-step "refund" setup

Here the scammer first shuffles money between your own accounts, say from savings to checking, or draws on a credit line, then claims the bank "accidentally refunded" too much and asks you to send the overage back. That first internal transfer was the scammer's act and can be unauthorized on its own, even if you later sent money out yourself.

Is the money covered if I gave the scammer my code or password?

Yes, when the scammer used it to move the money. Regulation E's official commentary says a transfer made by a person who got your access device, meaning your card, code, or login, through fraud is an unauthorized transfer. The CFPB's Electronic Fund Transfers FAQs apply that rule directly to bank impersonation calls. Being fooled does not cost you the protection.

The Electronic Fund Transfer Act (EFTA) is the federal law covering money that moves electronically out of a consumer's bank account, and Regulation E is the rule that spells out how it works. Under both, a transfer is unauthorized when someone other than you starts it without actual authority and you get no benefit from it (12 C.F.R. § 1005.2(m)).

An "access device" is the card, code, or other means of access you can use to move money; your online banking login and a one-time passcode both count. When a scammer obtains one from you through fraud, the official comment says the resulting transfers are unauthorized, the same as if the scammer had robbed you of your card (comment 2(m)-3).

Banks sometimes answer that you "furnished" the access device, invoking the rule that transfers by someone you voluntarily handed your card to are not unauthorized until you revoke permission. The Consumer Financial Protection Bureau (CFPB) addresses this in its FAQs: a consumer fraudulently induced to share account information has not furnished an access device.

Your carelessness doesn't change the answer either. The official commentary says a consumer's negligence cannot be the basis for increasing liability for unauthorized transfers (comment 6(b)-2). Trusting a spoofed number or reading back a code you were told never to share does not raise what the bank can put on you. Only the timing of your report does that.

The hard line is who pressed send. If the caller talked you into opening your banking app and sending the money yourself, to a "safe account" or anywhere else, you initiated the transfer, and federal law generally does not treat it as unauthorized, as federal courts in other states have held. Some banks and payment networks reimburse certain impostor scams under voluntary policies, and other legal theories sometimes apply, so report right away and send me the facts anyway. But I won't tell you federal law requires a refund when it doesn't.

Mixed cases are common: a scammer logs in with your code and sends three transfers, then talks you into sending a fourth. The first three are unauthorized; the fourth generally isn't. Sorting each transfer by who initiated it is the first thing I do with a denial letter.

Not sure who "pressed send"?

Send me the denial letter, your statements, and your notes about the call, and I'll sort each transfer under the federal rules at no charge.

Start my free case review

What should I report, and how fast?

Report every transfer to your bank the moment you realize what happened, by phone first and then in writing. How fast you report controls how much of the loss the bank can put on you. Your report does not need a police report, a notarized affidavit, or a branch visit to count, no matter what you're told.

When an access device was lost or stolen, your share is capped at $50, or the amount taken before you reported if less, when you report within 2 business days after learning of it (12 C.F.R. § 1005.6(b)(1)). Report later and the cap can reach $500, but only for transfers the bank proves a prompt report would have prevented (§ 1005.6(b)(2)). Courts have not squarely settled whether a code read to a scammer is a "stolen" access device for these tiers, one more reason to report the same day.

Separately, report anything on a statement within 60 days after the bank sends it. Miss that window and you can be responsible for transfers made after the 60 days and before your report, if the bank shows a timely report would have stopped them (§ 1005.6(b)(3)). The first unauthorized transfers stay protected regardless; there is no reporting deadline for those, though the one-year limit to sue is the practical outer edge.

If a hospital stay, extended travel, or another extenuating circumstance kept you from reporting, the bank must extend these time periods to a reasonable time (§ 1005.6(b)(4)).

A phone call is valid notice. The bank may ask you to confirm in writing within 10 business days and must tell you where, but it may not delay its investigation while it waits. Skip the written confirmation and the bank can decline provisional credit, so send it.

Tell the bank the whole story, including the part where you read back a code. People leave that out from embarrassment, and an incomplete account gives the bank a reason to doubt the rest. Give the date and amount of each transfer, state that you did not make them and received no benefit, describe how the scammer got in, and ask in the same letter for copies of any documents the bank relies on if it finds no error.

What does the bank have to do after I report it?

Your bank must investigate and decide within 10 business days. If it needs longer, it must put the disputed amount back in your account as a provisional credit within those 10 business days and finish within 45 days. When it finishes, it has 3 business days to report the result, and a denial must come with a written explanation.

"Provisional credit" is a temporary refund of the disputed amount; the bank must tell you its amount and date and give you full use of the money (12 C.F.R. § 1005.11(c)(2)). The deadlines stretch to 20 business days and 90 days for a new account, one whose first deposit came within 30 days before the transfer, and to 90 days for point-of-sale debit card purchases and transfers started outside the United States (§ 1005.11(c)(3)).

The investigation has to be real: when the bank has an agreement with a third party involved in the transfer, such as a payment network built into its app, it cannot stop at its own records (§ 1005.11(c)(4)). The bank may not charge you a fee for investigating. If it finds an error, it must correct it within 1 business day, including any fees and interest.

The bank cannot make a police report, a notarized affidavit, a branch visit, or a call to the recipient a condition of investigating; the CFPB's FAQs and federal examiner guidance say so.

If the bank finds no error, it must explain its findings in writing and tell you about your right to request the documents it relied on, which it must then provide promptly in a form you can understand (§ 1005.11(d)(1)).

And the burden of proof is the bank's. When your liability for an unauthorized transfer is in dispute, the EFTA requires the bank to show that the transfer was authorized or that the conditions for making you pay were met (15 U.S.C. § 1693g(b)).

Why do banks deny bank impersonation claims?

Most denials say the transfers were "authorized" because they came from your device, your login, or a code sent to your phone. Those facts describe how the scam worked, not who made the transfer. A denial letter that rests on them without asking who was holding the phone is the kind of decision a court can review.

The reasons I see in denial letters tend to repeat:

  • "The customer shared their credentials." True, and legally beside the point when the scammer then made the transfer. Fraud-induced sharing is not furnishing an access device, and negligence cannot raise your liability.
  • "The transaction was authenticated with a one-time passcode." The passcode confirms that whoever typed it had your text messages. The scammer did, because you read them aloud.
  • "The recipient was added by the customer's login." So was everything else the scammer did while logged in. The login was the stolen access device.
  • "The customer directed the payment to a safe account." If you sent it yourself, this is the one reason that can hold up under federal law. If the scammer sent it from inside your account, it doesn't.
  • "The fraud model did not flag the activity." Federal supervisory reports and published enforcement orders have faulted investigations that consist of a fraud score and a form letter. A model's silence is not an investigation of your claim.

What are my rights as a Florida consumer?

Florida has no state law for electronic transfers, and Florida's deceptive practices statute exempts banks and credit unions, so the federal EFTA is the main tool. The EFTA lets you sue in state or federal court, and Florida federal courts have applied its investigation and timing rules to banks and credit unions.

I work from one office, in Tampa, and represent people with these claims from every part of Florida by phone, email, and video.

Two Florida decisions matter here. In Monroe v. Grow Financial Federal Credit Union (M.D. Fla. 2022), the federal court for the Middle District of Florida concluded that a credit union had not reasonably investigated a disputed debit or carried its burden of showing it was authorized. In Katz v. JPMorgan Chase (S.D. Fla. 2015), the court held that a claim over a mishandled error report accrues when the bank's deadline passed, not when the money left.

Florida's Deceptive and Unfair Trade Practices Act exempts banks, credit unions, and savings associations (Fla. Stat. § 501.212), so that state-law claim is usually unavailable against your bank, and the EFTA's fee shifting fills the gap.

Courts also require a concrete injury; losing the use of your money, even temporarily, generally counts.

One caution: if the scammer had you send a wire from a branch, the EFTA does not apply. Florida's version of the Uniform Commercial Code's funds-transfer article governs wires, a South Florida federal court applied that exclusion in 2022, and wires are hard to reverse.

What is a bank impersonation claim worth?

If your bank violated the EFTA, you can seek your actual damages, meaning the money the scammer moved and related losses, plus statutory damages of $100 to $1,000, plus reasonable attorney's fees and costs. When a bank skipped provisional credit and didn't investigate in good faith, the court can award up to three times your actual damages.

Statutory damages are available even when your actual loss is small, and the court weighs the frequency, persistence, and nature of the bank's noncompliance in setting the amount (15 U.S.C. § 1693m(a), (b)). Fee shifting is what makes a claim over a few thousand dollars worth bringing.

The treble provision has two triggers. The first: the bank did not provisionally recredit your account within the 10-business-day period, and either did not investigate in good faith or had no reasonable basis for believing there was no error. The second: the bank knowingly and willfully concluded there was no error when that conclusion could not reasonably be drawn from the evidence in front of it (§ 1693f(e)). Trebling applies to your actual damages, the money you lost, not to the $100 to $1,000 statutory figure.

A bank can defend by showing a bona fide error despite reasonable procedures, and the statute allows fees against a consumer who sues in bad faith or to harass, so I review the facts before recommending suit. You don't pay me unless you win. I take these cases on contingency: no attorney's fees and no case costs owed to me unless you recover money. If a case is lost, a court can sometimes order the losing side to pay the other side's court costs, and some Florida laws, including the security deposit and deceptive practices statutes, also let the winner recover attorney's fees from the loser. I explain that risk before anything is filed, and every term is in a written agreement before you sign.

How long do I have to sue?

One year from the violation. For a bank that mishandled your report, the violation is the bank's failure, so a federal court in South Florida counted the year from when the bank's 10-business-day deadline passed, not from the day the scammer struck. Even so, treat the scam date as your safe deadline and act well before it.

That decision is Katz, mentioned above. It helps people who reported promptly and then waited months for a denial, because the clock on the bank's failure starts at the failure. It does not help anyone who sits on a denial, and while courts have occasionally extended the year for fairness reasons, no one should plan around that.

What to do today

  • Call the number on the back of your card, not any number from the scam, report every transfer, and get a claim number. Then send written notice to the error-resolution address in your account agreement and keep proof of delivery.
  • Lock the account down: new banking and email passwords, two-step verification on, any remote-access app deleted, and a call to your carrier if your number stopped working.
  • Write down the call while it's fresh: the number that showed on your screen, the time, what they asked you to read or type, and who pressed send on each transfer.
  • Gather the documents: a screenshot of your call log with the incoming number and time; the fake fraud-alert texts; the real one-time passcode texts with timestamps; login or new-payee alerts; statements showing each transfer and any internal transfer before it; recipient names or account details; the name of any app you installed and when; and every letter from the bank, including the denial.
  • Don't send another dollar, including to anyone who calls offering to "recover" your money for a fee. That is usually the same crew.
  • If the bank has already said no, request in writing every document it relied on, and note the date you asked.
  • Send it to me. Request a free case review and attach what you have. I'll tell you which transfers federal law covers and whether the bank followed its rules.

Sources: 15 U.S.C. §§ 1693a(12), 1693f(e), 1693g(b), 1693m(a), (b), (c), (f), (g); 12 C.F.R. §§ 1005.2(m), 1005.6(b), 1005.11; Official Interpretations to Regulation E, comments 2(m)-3, 6(b)-2, 11(b)(1)-2, 11(c)-2, 11(c)-3, 11(c)(4)-5; CFPB, Electronic Fund Transfers FAQs, Error Resolution: Unauthorized EFTs, Questions 3 to 6; Katz v. JPMorgan Chase, 2015 WL 11251764 (S.D. Fla. Feb. 10, 2015); Monroe v. Grow Financial Federal Credit Union, 2022 WL 17417034 (M.D. Fla. Dec. 5, 2022); Stepakoff v. IberiaBank Corp., 637 F. Supp. 3d 1309 (S.D. Fla. 2022); Fla. Stat. § 501.212. Last reviewed October 8, 2026.

Questions

Bank impersonation scam FAQ

I read a one-time code to someone who said they were my bank. Is the money gone for good?

Not necessarily. If the scammer used that code to log in and move the money, Regulation E treats the transfers as unauthorized, your bank must investigate, and the bank carries the burden of proving otherwise. Report every transfer today, in writing as well as by phone, and keep the texts that show when the code arrived.

The bank says the transfers passed two-factor authentication, so I must have authorized them. Is that right?

No. Two-factor authentication shows that whoever made the transfer had your code, and the scammer had it because you were tricked into reading it aloud. The official commentary to Regulation E says a transfer made with an access device obtained through fraud is unauthorized. Who typed the code matters, not whether the code worked.

The caller told me to move my money to a "safe account" and I did it myself. Am I covered?

Generally not under federal law, because you initiated the transfer. Some banks reimburse impostor scams voluntarily, so ask, and other legal theories occasionally apply. Also check whether the scammer made any transfers before you did, such as moving money from savings into checking; those are a different story and can be unauthorized.

Do I have to file a police report before the bank will investigate?

No. A police report is not a legal condition of a Regulation E investigation, and neither is a notarized affidavit or a branch visit. Filing one anyway can support your claim and is often worth doing, but the bank's deadlines start running when it receives your notice, with or without it.

I installed the app the caller told me to install. Does that make the transfers mine?

Not by itself. If the person on the other end of that remote-access session moved the money, someone other than you initiated the transfer, which is the definition of unauthorized. The bank's logs will show your device, which is exactly why you should describe the remote access in your written notice and ask for the documents the bank relied on.

Free case review

Find out where you stand. You don't pay me unless you win.*

Tell me what happened and send what you have. You'll get a plain-English answer about whether the law gives you a claim and what the next step would be.

Start my free case review Call (813) 921-3516

*Consumer protection claims: no attorney's fees or costs owed to me unless you recover. Debt defense is priced case by case. Confidential, no obligation.

Call Free Case Review