IS IT REAL? · THE REGISTER9 September 2026 · 11 min read

Nine banks publish the numbers their fraud alerts come from. The text in your hand either matches, or it does not.

A text says there is a suspicious charge on your card. It wants a YES or a NO, or a tap, or a call. The one fact that settles most of these in ten seconds is the number it came from, and every bank buries that number on a different page. So we read those pages, on one day, and put the numbers in one place.

$470M
lost to text scams, 2024 (FTC)
$3,000
median loss, fake bank alert (FTC)
11
institutions read at source
2
codes shared by two banks
The short answer

Real bank fraud alerts come from short codes, the five- or six-digit numbers each bank publishes. Chase uses 28107, 36640 and 72166. Capital One uses 227898, 227767 and 227373. Navy Federal uses 20270 and 33748. Truist uses 878228, PNC 94387 and 76205, KeyBank 65076 and 72678, USAA 698722 and 868722. A genuine alert names the transaction and asks for one word back. It never carries a link, never asks for a passcode, and never tells you to move money. A ten-digit sender fails the first test; a request for anything beyond YES or NO fails the second.

"Some of the costliest impersonation scams start with a fake security alert, often from a bank. People are convinced to move money to 'protect' it, with their losses often limited only by their available funds."

Federal Trade Commission, press release on 2025 Consumer Sentinel data, 15 June 2026. The same release puts 2025 losses to imposter scams at $3.5 billion, with the highest business-impersonation losses to people pretending to work for a bank.

The fake fraud alert is not a new trick and it is not a subtle one. The FTC's own text-scam spotlight put copycat bank fraud prevention alerts at number one for 2022, with a median loss of $3,000 and reports up nearly twentyfold since 2019. By 2024 people were reporting $470 million lost to scams that started with a text, and the fake bank alert was still on the FTC's list of the most reported kinds. What has changed is only the polish.

What has not changed is the mechanism, and the mechanism is why the sender number matters. Bulk business texting in the United States runs on short codes: a bank leases a five- or six-digit number, registers it, and sends its alerts from it. A criminal running a phishing kit from a burner phone or a cheap SMS gateway sends from a full ten-digit number, because a registered short code costs money, takes weeks, and is tied to an identity. So the first check is mechanical. Before you read a word of the message, read the number.

The register: every code, read on the bank's own page

Each row below was read on the institution's published page on 9 September 2026. The fraud or security codes are set large; everything else the bank publishes sits beside them, because a one-time passcode arriving from a code listed for passcodes is also information. The source link on each row is the thing to trust when this table and the bank disagree.

The register · published short codesread at source 9 Sep 2026
Chase
281073664072166
fraud and account security
one-time codes 242733, 60969 · phone-number change 41868 · card servicing 63202, 85640
Capital One
227898227767227373
account servicing messages, such as fraud alerts
bank account servicing 61869 · app download 80101
PNC
9438776205
fraud prevention transaction confirmations
card activity 762273 · one-time passcodes 76200, 76201, 32858 · identity verification 76214, 668439, 76213, 89787 · alerts and text banking 762265
Truist
878228
fraud alert notifications
alerts 878478, 878476, 878477 · one-time passcodes 878478, 28458, 760814 · commercial 73227, 957486, 957497
KeyBank
6507672678
debit card and credit card activity confirmation
authentication codes 32858 · online banking alerts 70378 · account set-up 32471 · home lending codes 61731
Navy Federal
2027033748
credit card and debit card fraud alerts
security alerts 35038 · one-time passcodes 668439
USAA
698722868722
fraud and account security
the page names these two as the example fraud and account security codes
Wells Fargo
93557
alerts and one-time passcodes (spells WELLS)
the FAQ names one code for enrolment, alerts and passcodes
Chime
24463
transactional messages
marketing 78740
EnFact (Fiserv), used by many credit unions
37268
debit card fraud alerts
the vendor behind a large share of credit union card alerts; your own institution's page decides
Bank of America
7398199217
Zelle enrolment authorisation codes only
no fraud-alert code on any public page we could reach; see the section below
Venmo
86753
verification codes only
Venmo publishes no fraud-alert code
Every code was read on the institution's own page on 9 September 2026. Codes change; the source link on each row is the thing to trust, not this table. A bank missing from the register means we could not verify a code at source, never that a message from it is fake.

Two rows deserve a word. Bank of America publishes short codes only for Zelle enrolment codes on the page we could reach; its fraud-alert number is not on any public page we found, and the numbers circulating for it on third-party sites are not something we will repeat as fact. Wells Fargo's FAQ names one code, 93557, which spells WELLS on a keypad, for enrolment, alerts and passcodes together. Neither is a criticism. It is the reason a list like this has to say where each number came from.

The codes people search for most, and who owns them

Google's own data on what people type is the reason this page exists. The searches are for a bare number followed by the words text message, and the four most searched are these.

37268 is EnFact. A debit card fraud detection service from Fiserv that many credit unions and community banks run behind the scenes, which is why the text arrives from a name that is not on your card. Hancock Whitney and Winston-Salem Federal Credit Union both publish 37268 as their debit alert code. A real one asks for one word and never carries a link; the full signature is in our EnFact breakdown.
33748 is Navy Federal's debit card fraud alert code. Its credit card alerts come from 20270 and its security alerts from 35038. Navy Federal describes its short codes as unique five- to six-digit phone numbers that are only used by its system, and states it will never solicit your personal information over the phone or through text, email or social media.
28107 is one of Chase's three fraud and account security codes. The others are 36640 and 72166. Chase describes these as interactive texts sent when it has reason to believe someone may be trying to get into your account, and its instruction for anything that seems strange is not to reply but to call the number on the back of your card.
20763 is on nobody's list. It is the most searched number of the four, and it does not appear on the published short-code page of any institution in the register. People who describe texts from it describe unsolicited offers, not a bank alert. We cannot tell you who leases it. We can tell you that no bank we checked says it does, which for a message claiming to be your fraud department is the whole answer.
Two recreated phone screens side by side. Left, a genuine bank fraud alert from a five-digit short code that names a charge of $1,200 and asks for a reply of YES or NO. Right, a fake alert from a ten-digit mobile number that says fraudulent activity has been detected, tells the reader to act now, and carries a link with the dot replaced by brackets so it cannot be tapped.
Recreated examples, not screenshots of real messages. The genuine one follows the shape the banks using EnFact publish: the short code, the amount and merchant, a one-word reply, no link. The fake follows the sequence the FTC describes, a reply that triggers the call. The link is deliberately inert.

Why a matching code is still not proof

Reading the eleven pages side by side turned up something no single bank's page will tell you. Two of the codes belong to two banks at once. PNC lists 32858 for one-time passcodes; so does KeyBank. PNC lists 668439 for identity verification; Navy Federal lists it for one-time passcodes. That is not a mistake on anyone's part. It means the code belongs to the vendor that runs the messaging platform, not to the bank whose name is in the text, and several institutions ride on the same vendor.

The consequence is simple. A short code proves that a registered business platform sent the message. It does not by itself prove which business, and it says nothing about what the message will ask you to do next. The FTC describes the live version: a text asks you to reply yes or no to a large transaction you did not make, and when you reply, the call comes from the fake fraud department. The number checked out well enough to get a reply. The reply is what they wanted.

Three tests, in order. One: is the sender a five- or six-digit code that your bank publishes, or a ten-digit phone number? A phone number ends it. Two: does the message name the transaction and ask for one word back, or does it want a tap, a call, a login, a code, or a transfer? Anything beyond one word ends it. Three: if it passed both, confirm it anyway on the number printed on the back of your card. A real hold on your card is visible to whoever answers. A fake one does not exist.

What a real alert can ask, in the banks' own words

The banks agree with each other on this, which is unusual enough to be worth quoting directly.

PNC: it will never call you asking for a one-time passcode, username or password, and its instruction for a suspicious text is to call the number on the back of your card before tapping anything.
Navy Federal: it will never solicit your personal information over the phone or through text, email or social media.
Chime: it will never ask for your full Social Security number, account or routing numbers, card details, PIN, username or password, and it will never request money in exchange for services.
Chase: if a text seems strange or suspicious, do not reply; call Chase using the number on the back of your card or on your statement.
KeyBank: if a text claims to be from KeyBank and does not match a code on its list, refrain from providing sensitive information and verify through a known KeyBank contact.
PayPal: never provide personal, credit card, or account information via email, text, or phone.
The FCC, for all of them: regardless of the pitch, it is always a scam; banks will never call or text and ask you to move your money to protect it.
From the field. I sold for a living before I did this, and the fake fraud alert is the cleanest piece of persuasion in the whole scam economy, because it does not ask you to trust a stranger. It arrives as your protector. It warns you about somebody else. Your suspicion goes up at the imaginary thief and stays down for the message itself, and the YES you send is not a decision, it is a reflex. That is why I will not tell you to feel your way through one. Feeling is the channel they are using. Read the number, count what it asks for, and let the specification decide.
The safest move never depends on judging the message at all. Do not reply, do not tap, do not ring any number the text gives you. Open your banking app, or call the number on the back of your card, and ask whether there is a hold. The real system will show it. If anyone, on any call, tells you to move money to a safe account, to buy gold, or to read out a code that was just texted to you, hang up. Those three instructions have no legitimate version.

Who is not on the register, and why that is not a verdict

Discover's SMS terms say it may text about fraud activity independent of your alert preferences, but they name no code. U.S. Bank's alert pages describe text, email and push alerts and name no code. Citi's card-benefits page and Cash App's scam page refused to load for us, and American Express's US pages we could read name none. That is four large institutions whose fraud alerts we cannot help you check by number today, and it is the honest limit of a register built from published pages.

So read the absence correctly. A bank missing from the list means we could not verify its code at source. It does not mean a text from that bank is fake, and it does not mean a text from a five-digit number is real. For those institutions the second and third tests carry the whole load: one word back, then the number on the back of the card. We will add rows as banks publish, and the date at the top of the table will move when we re-read it.

If you already replied, tapped, or read out a code

  1. 1.Call the bank on the number printed on the back of your card, not any number from the message or from a search result. Say exactly what you shared and, if you moved money or read out a passcode, say that first.
  2. 2.Ask for the card to be locked and for a check on new payees and changed contact details. A criminal who has your passcode often changes the phone number on file so the next alert goes to them.
  3. 3.Change your online banking password from a device you trust, and turn on any extra verification the bank offers.
  4. 4.If money moved, ask about the rail. An unauthorised card transaction and a transfer you were talked into are treated differently; whether banks refund scammed money depends on which one you have.
  5. 5.Report the text. Forward it to 7726, then report at ReportFraud.ftc.gov. Reporting does not get your money back, but it is what the FTC's numbers above are built from.
  6. 6.Expect the second call. Anyone who contacts you afterwards offering to recover the money for a fee is running the recovery scam, aimed at the same victim twice.

Every fake fraud alert is built on one bet: that you will answer the message before you check the sender. Read the number first. If it is not one your bank publishes, the message has already told you everything it can.

Sources

Chase — how to identify Chase text messages and short codesCapital One — SMS terms and short codesPNC — verify if PNC contacted youTruist — SMS banking program termsKeyBank — identifying legitimate KeyBank text messagesNavy Federal — phishing scams and short codesUSAA — how to tell it's USAAWells Fargo — text message FAQsChime — is this communication from Chime?Bank of America — Zelle enrolment short codesVenmo — phone and email verificationDiscover — SMS terms and conditionsPayPal — how to detect phishing scamsFTC — $3.5 billion lost to imposter scams in 2025 (15 Jun 2026)FTC — top text scams of 2024, $470 million (16 Apr 2025)FTC Data Spotlight — the top text scams of 2022 (Jun 2023)FCC — bank impersonation scamsScott Credit Union — fraud alert text messages (25 Aug 2026)

Keep reading

IS IT LEGIT? · THE ONE-WORD TEST
A real EnFact alert wants one word back. Anything that wants more than that is not one.
FREE TOOL
Impersonation Index: what companies say they will never ask you for
FREE TOOL
Is that text real? Sort a US scam text in three taps
THE PSYCHOLOGY
Why scammers create urgency, and why the clock is always fake