top of page

The Mobile Banking Login Clone

  • Writer: Richard Stocks
    Richard Stocks
  • Jul 21
  • 2 min read

Flggd Scam School · Bank & Financial Institution Scams · Lesson 9 of 16

A text says your banking session expired and offers a link to sign back in. The page it opens looks perfect. Here is how to spot a fake mobile banking login page anyway.


The message looks like this

Example of a fake mobile banking login scam text

Why this is a scam

Banking sessions don't expire by text. Your app manages its own sign-ins and never needs an outside link to let you back in.

The cloned page copies your bank's colors, logo, and layout down to the pixel. The only thing it can't copy is the web address. Whatever you type on that page, username, password, and the "debit card for security", lands in a scammer's inbox in real time.

That last line is the tell within the tell: no login page on earth needs your physical card "ready."


Red flags checklist

  • The web address isn't your bank's; extra words like "secure-login" are a giveaway.

  • You arrived from a text or email link, not by opening the app yourself.

  • The page wants your card number just to sign in.

  • Small oddities: fuzzy logo, old design, misspelled words, wrong greeting.

  • Your app, opened directly, shows no expired session at all.


The manipulation tactic

Familiarity. The page looks like a hundred logins you've done before, so your fingers type on autopilot before your eyes check the address.


What to do, and what not to do

  • Don't sign in through links sent by text or email. Ever.

  • Open your banking app directly, or type your bank's address yourself.

  • If you already typed your password on such a page, change it now and call the number on the back of your card.

  • Turn on login alerts in your app so you'd know about real intrusions.

  • Forward the text to 7726 (SPAM), then delete it.


Not sure about a message you've received? Check it in seconds with the free Flggd app.

bottom of page