The Mobile Banking Login Clone
- Richard Stocks
- Jul 21
- 2 min read
Flggd Scam School · Bank & Financial Institution Scams · Lesson 9 of 16
A text says your banking session expired and offers a link to sign back in. The page it opens looks perfect. Here is how to spot a fake mobile banking login page anyway.
The message looks like this

Why this is a scam
Banking sessions don't expire by text. Your app manages its own sign-ins and never needs an outside link to let you back in.
The cloned page copies your bank's colors, logo, and layout down to the pixel. The only thing it can't copy is the web address. Whatever you type on that page, username, password, and the "debit card for security", lands in a scammer's inbox in real time.
That last line is the tell within the tell: no login page on earth needs your physical card "ready."
Red flags checklist
The web address isn't your bank's; extra words like "secure-login" are a giveaway.
You arrived from a text or email link, not by opening the app yourself.
The page wants your card number just to sign in.
Small oddities: fuzzy logo, old design, misspelled words, wrong greeting.
Your app, opened directly, shows no expired session at all.
The manipulation tactic
Familiarity. The page looks like a hundred logins you've done before, so your fingers type on autopilot before your eyes check the address.
What to do, and what not to do
Don't sign in through links sent by text or email. Ever.
Open your banking app directly, or type your bank's address yourself.
If you already typed your password on such a page, change it now and call the number on the back of your card.
Turn on login alerts in your app so you'd know about real intrusions.
Forward the text to 7726 (SPAM), then delete it.
Not sure about a message you've received? Check it in seconds with the free Flggd app.


