A real EnFact alert wants one word back. Anything that wants more than that is not one.
A text arrives about a suspicious charge on your debit card, from a company called EnFact that you have never heard of and that is not the name on your card. You search the name, and the results are a scatter of individual bank pages that each describe their own version. Nobody answers the actual question.
The answer is unusually clean, because a genuine EnFact alert is allowed to do very few things.
The short answer
EnFact is real. It is a debit-card fraud-detection service from Fiserv, used by many US banks and credit unions. A genuine alert has a narrow signature: it comes from a five-digit short code, it never contains a link, it names the suspect transaction, and it asks you to reply with a single short word such as yes, no, help or stop. It never asks for your PIN, your full card number, your password, or a one-time passcode. A message that breaks any of those rules is not a real EnFact alert, whatever it says at the top.
What EnFact actually is
EnFact is a card-risk product from Fiserv, one of the large payment processors that runs card infrastructure behind the scenes for smaller banks and credit unions. Fiserv's own Card Risk Mitigation brochure describes EnFact as a sophisticated, real-time, neural network solution that assesses fraud risk for card transactions without delaying or inconveniencing cardholders — which is a technical way of saying it watches your card and flags the transactions that do not fit your pattern. The same document notes that its supported notification channels include text, email and letters, which is why an alert can reach you more than one way.
That is the whole reason the name is unfamiliar. You never signed up for EnFact and it is not printed on your card, because your relationship is with your bank and your bank's relationship is with Fiserv. Pinnacle Bank, one of the institutions that publishes how it uses the service, describes the sequence: an email first, then a text message, and a phone call if there is no response within fifteen minutes. So an unexpected contact from a name you do not recognise is genuinely how the real system behaves — which is exactly why an imitation of it works so well.
Recreated examples, not screenshots of real messages. The link in the fake is deliberately inert.
The signature of a genuine alert
These are the properties banks that use the service publish about it. Each one is something you can check on the message in your hand, without calling anyone.
—It comes from a five-digit short code. SCU Credit Union states that a text alert from EnFact will always be from a 5-digit number and not a 10-digit number resembling a phone number. Winston-Salem Federal Credit Union and Hancock Whitney both name 37268 for their debit-card alerts. Codes differ between institutions, so check your own bank's published number rather than memorising one.
—It never contains a link. This is the strongest rule available and it is stated without qualification. SCU Credit Union writes that a text alert from EnFact warning you of suspicious activity will never include a link to be clicked, and that cardholders should never click a link in a text supposedly from EnFact. There is no legitimate version of this message that needs you to tap something.
—It tells you about the transaction. A real alert carries the detail that lets you judge it — Winston-Salem FCU describes the message as offering basic information about the suspected transaction, including the amount and the merchant where available. Vagueness is not a feature of the genuine article.
—It asks you to reply with one word. Yes, no, help or stop. Winston-Salem FCU puts it as replying YES to mark a transaction legitimate, and STOP to the same short code to opt out. That is the entire interaction the real system expects from you.
—It never asks for secrets. Pinnacle Bank states it directly: we will never ask you to verify your PIN or password via text or email. Not your PIN, not your full card number, not your online-banking password, and not a one-time passcode.
The one-word test. Put the five rules together and a single question does most of the work: what is this message asking me to do? A genuine EnFact alert asks you to type one short word into a reply. That is all it can do — it has no link, no phone number to ring, no form, no code to read out. Every fake version needs something bigger from you, because a reply of "no" earns a criminal nothing. If the message needs you to tap, call, log in, read out a code, or move money, it has already failed the test, and you do not need to identify the sender to know that.
Where the fake version goes
A counterfeit fraud alert is rarely the scam by itself. It is the opening, and the FTC has documented where it leads. Its warning on text scams describes exactly this shape: some text scams start as fake fraud alerts, a message claiming to be from the fraud department at your bank, offering help with a suspicious charge — but that is the hook to get you to reply or call a number, after which come the elaborate lies that drain the account.
Two demands mark the end of that road, and the FTC is unambiguous about both. One is the verification code: no caller, especially someone claiming to be from your bank's fraud department, will ever ask for it, because sharing the code is how a stranger proves to your bank that they are you. The other is the instruction to move money somewhere safe. In the FTC's words, your money is fine where it is, no matter how urgently someone says otherwise — anyone telling you to move money to protect it is a scammer. We take that particular move apart in our breakdown of manufactured urgency.
From the field. I have spent my working life on the other end of persuasion, and the thing that makes a fake fraud alert so effective is not the wording. It is the role reversal. Every other scam has to talk you into trusting a stranger; this one arrives already on your side, warning you about someone else. Your guard goes up at the imaginary thief and stays down for the person in the message. That is why the tells here are deliberately mechanical rather than instinctive — a link, a ten-digit number, a request for a code. You are not going to feel your way out of a message engineered to feel like rescue. You check it against the specification instead.
The safest move never depends on judging the message at all. Do not reply, do not tap, and do not ring any number the message gives you. Call your bank on the number printed on the back of your card, or open your banking app and look for the alert there. A real suspicious-transaction hold will be visible to the person who answers. A fake one will not exist.
What to do with the message in front of you
—Check the sender against the specification. Five-digit short code or a full phone number? Any link at all? Does it name the merchant and amount, or stay vague? One of those usually settles it.
—Reply only if it is a genuine short-code alert, and only with the one word. Confirming or denying a transaction by replying is the intended use. Nothing beyond that word is ever required.
—Verify independently the moment anything feels off. The number on the back of your card is the one contact route a scammer cannot control. Use it in preference to everything else, including a number found by searching.
—Never read out a passcode, and never move money to protect it. These are the two instructions that convert a scare into a loss. Neither has a legitimate version.
—Check the email sender carefully, but do not lean on it. Hancock Whitney publishes noreply@enfactnotifications.com as the genuine debit-card sender. A From line can be forged, so a matching address is reassurance, never proof.
The reason this scam works is that the real thing is genuinely strange: an unfamiliar company, an unexpected message, an urgent-sounding charge. You cannot make that feel normal, and you do not need to. The genuine version is narrow enough to describe in five rules, and almost every counterfeit fails one of them in the first line.