Skip to content

Companies

Wells Fargo scams: how the fake messages work

Wells Fargo bank impersonation scams involve fraudsters sending fraudulent text messages, emails, or making spoofed phone calls claiming to be from the bank's fraud department. These attacks typically warn victims of unauthorized transactions or frozen accounts to induce panic. Scammers then pressure targets into revealing online banking credentials, one-time passcodes, or transferring funds to external accounts via peer-to-peer services like Zelle under the false pretext of securing their money.

Last reviewed: August 9, 2026  ·  Drafted with AI assistance. Every figure on this page was checked against the source cited for it. Not yet reviewed by a human editor.

ScamPreventionGuide is an independent consumer-protection resource. We are not affiliated with, endorsed by, or sponsored by Wells Fargo. Company names and trademarks are the property of their respective owners and are used here only to identify the companies that scammers impersonate.

01

Is the Wells Fargo message real?

How the brand actually contacts customers: Wells Fargo communicates via secure messages within online/mobile banking, official emails from the @wellsfargo.com domain, and text alerts originating exclusively from designated five-digit short codes (935-57, 937-33, 937-29, or 546-87). Wells Fargo representatives will never call, text, or email asking customers to disclose their online banking passwords, PINs, full debit/credit card numbers, CVV codes, One-Time Passcodes (OTPs), or to transfer money to "safe accounts" or via peer-to-peer apps like Zelle.

FTC Imposter Scam Statistics: According to Federal Trade Commission data published in June 2026, consumers reported losing a staggering $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020 and exceeding 1 million total reports.

02

Which versions are in circulation?

The versions in circulation, and what each one is after:

VersionHow it reaches youWhat it wants
Fake Fraud Alert (Walmart Purchase)SMSPanic the victim into calling a spoofed number or clicking a phishing link to steal login credentials.
Zelle Safe Account TransferPhone / SMSTrick the victim into unlinking their Zelle account and transferring funds to a "safe account controlled by the bank" (scammer account).
Account Frozen Identity VerificationEmailCapture online banking usernames, passwords, Social Security numbers, and photo IDs via a rogue phishing portal.
Zelle Unauthorized Payment DisputePhone / SMSGain remote access to the victim's device or convince them to authorize wire/P2P transfers to reverse a phantom charge.
Malware Delivery via Security UpdateEmail / WebInfect the victim's smartphone or computer with keylogging or info-stealing malware to intercept session cookies.
Fake Customer Service Social Media AdsSocialRoute victims through call centers staffed by scammers posing as bank representatives to harvest banking credentials.
03

What do the fake messages actually say?

We are not quoting example wording on this page. On 16 August 2026 we checked the quoted messages against the sources they were credited to, and the sources did not contain them — so the quotes were removed rather than reworded. We would rather show you nothing than show you an invented example of a real crime.

The exact wording changes constantly anyway. What does not change is the shape: a message you did not ask for, about a problem you cannot verify, with a link or a phone number supplied for you to use. Do not use either — reach the company the way you normally would.

04

How can you tell a real message from a fake one?

The differences you can check yourself:

  • Sender Short Code Discrepancy: Genuine Wells Fargo text alerts originate exclusively from five-digit short codes (935-57, 937-33, 937-29, or 546-87); any text arriving from a standard 10-digit phone number or international number is fraudulent.
  • URL Domain Imposture: Fake emails direct users to domains using hyphenated look-alike structures (e.g., wellsfargo-secure-login.com or wf-support-portal.net) instead of the exact official domain wellsfargo.com.
  • Urgency and Coercion Tactics: Scammers demand immediate action within minutes (e.g., "within 24 hours" or "your account will be permanently closed"), whereas legitimate bank notifications direct you to check your secured message center inside the official app.
  • Requests for Sensitive Credentials: Fraudulent callers and texts ask for your complete online banking password, PIN, CVV, or One-Time Passcode (OTP); genuine bank representatives never ask for your password or OTP.
  • Zelle Safe Account Instructions: Scammers instruct you to send money to yourself or a "safe holding account" via Zelle to block fraud; genuine banks never instruct customers to transfer funds to external accounts for safekeeping.
05

What should you do in the first hour?

It depends on how far it got. Find your situation:

  • If you contacted them but gave nothing:
  • Hang up immediately or close the browser window. Do not click any further links.
  • Forward any suspicious phishing emails or text screenshots to reportphish@wellsfargo.com.
  • Block the sender's phone number and delete the text message.
  • If you gave information (Usernames, Passwords, SSN):
06

Where do you report it?

Official reporting channel: Call 1-800-869-3557 (available 24/7 for personal accounts) or forward suspicious emails/texts to reportphish@wellsfargo.com. Commercial and corporate banking customers should dial 800-289-3557.

Whatever the brand, two official channels take the report. File with the US Federal Trade Commission at reportfraud.ftc.gov, and — if money was lost or a computer was accessed — with the FBI's Internet Crime Complaint Center at ic3.gov. Reporting rarely recovers money on its own; it is what makes the next person's warning possible.

07