Skip to content

Companies

Chase scams: how the fake messages work

Victims are tricked into calling back or clicking phishing links, where scammers manipulate them into approving fraudulent Zelle transfers or wiring funds to a so-called "safe account." To protect yourself, never share one-time passcodes or transfer money upon urgent instructions, as genuine bank representatives will never ask you to move funds to secure accounts.

Last reviewed: August 9, 2026  ·  Drafted with AI assistance. Every figure on this page was checked against the source cited for it. Not yet reviewed by a human editor.

ScamPreventionGuide is an independent consumer-protection resource. We are not affiliated with, endorsed by, or sponsored by Chase. Company names and trademarks are the property of their respective owners and are used here only to identify the companies that scammers impersonate.

01

Is the Chase message real?

How the brand actually contacts customers: Chase contacts customers via secure push notifications inside the official Chase Mobile app, interactive text messages from verified short codes (28107, 36640, 72166) regarding legitimate fraud alerts, and emails or phone calls. However, Chase never asks customers for their online banking username, password, full account numbers, debit/credit card PINs, CVV codes, full Social Security numbers, or one-time passcodes (OTPs), and never instructs customers to wire money to "safe accounts" or execute test Zelle transfers to reverse fraud.

FTC / IC3 Figures: According to Federal Trade Commission (FTC) data published in June 2026, consumers reported losing $3.5 billion to imposter scams in 2025, nearly tripling losses since 2020. Imposter scams were the most reported fraud category, accounting for nearly one in three fraud reports (FTC Press Release, June 15, 2026; https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025). Source: FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025.

02

Which versions are in circulation?

The versions in circulation, and what each one is after:

VersionHow it reaches youWhat it wants
Fake Fraud Alert (Zelle/Wire Transfer)SMS / PhoneVictim to panic, verify fake details, and authorize a Zelle transfer or wire to a "safe account" controlled by the scammer.
Spoofed Caller ID Bank ImpersonationPhoneVictim to read out OTP (one-time passcode), approve mobile wallet provisioning, or transfer funds to a "secure reserve account".
Account Suspension / Locked Account PhishingEmail / SMSVictim to click phishing link, enter online user ID, password, full card numbers, and 2FA codes on a credential-harvesting replica site.
Unauthorized Direct Deposit / Refund ScamPhone / SMSVictim to send their own genuine funds via Zelle or wire transfer to "return" the fabricated credit before the bank catches the fake deposit.
03

How can you tell a real message from a fake one?

The differences you can check yourself:

  • The "Safe Account" Wire/Zelle Demand: Genuine Chase employees will never instruct you to transfer money via Zelle, wire, or cryptocurrency to a "safe account" or "reserve account" to protect your funds.
  • Incoming Call Caller ID Spoofing: Scammers frequently spoof Chase’s customer service phone number on your caller ID; genuine Chase representatives will never call and ask you to read out your one-time passcode (OTP) or mobile banking password over the phone.
  • URL Domain Check in SMS: Genuine Chase interactive fraud text messages originate strictly from official short codes (28107, 36640, or 72166) and never contain clickable external web links or URLs.
  • Request for Full Credentials: Fake security alert emails and SMS messages direct you to external web links asking for your username, password, full credit card numbers, and PIN; genuine Chase security prompts inside the mobile app never require re-entering full banking credentials via external links.
04

What should you do in the first hour?

It depends on how far it got. Find your situation:

  • If you contacted them but gave nothing: Immediately close all browser tabs, block the scammer's phone number, and report it to Chase by calling 1-800-935-9935, opt. 8 — the number on Chase's own report fraud page. To forward a suspicious email, JPMorgan Chase publishes abuse@jpmorgan.com.
  • If you gave information (usernames, passwords, or SSN): Immediately log into the official Chase Mobile App or call Chase Customer Service at 1-800-935-9935 to freeze your accounts, change your online banking username and password, and update your security questions.
  • If you paid/transferred funds or gave remote access:
  • Call Chase immediately on 1-800-935-9935, opt. 8 (personal checking or savings) to report unauthorized transfers and request recall or freeze actions. If the money left a commercial account, JPMorgan Chase's Global Bank Recoveries Team is on 866-954-3718, option 4.
  • File an official cybercrime complaint with the FBI Internet Crime Complaint Center (IC3) at www.ic3.gov.
05

Where do you report it?

Official reporting channel: Chase's report fraud page — personal checking or savings 1-800-935-9935, opt. 8. If money has already left the account, JPMorgan Chase's Global Bank Recoveries Team is on 866-954-3718, option 4 (source). Suspicious emails can be forwarded to abuse@jpmorgan.com.

Whatever the brand, two official channels take the report. File with the US Federal Trade Commission at reportfraud.ftc.gov, and — if money was lost or a computer was accessed — with the FBI's Internet Crime Complaint Center at ic3.gov. Reporting rarely recovers money on its own; it is what makes the next person's warning possible.

06