Bank Impersonation Scams: How One Target Wasted the Fraudsters' Time for Hours

A reader who received a fake Barclays automated call decided not to hang up. What followed is a useful case study in how these scams work, and what you can do when one lands in your lap.

ThreatVectr Newsdesk· 3 min read
Close-up top-down view of a smartphone lying on a wooden table, its screen displaying a generic colourful digital invitation card with balloons and confetti gra
Share

Key points

  • Bank impersonation scams, where criminals pretend to call from your bank to steal account details, are among the most common fraud types reported to UK consumers.
  • The victim in this case does not even bank with Barclays, the institution the automated call claimed to represent.
  • The fake call alleged an unauthorised payment of over £1,000 to Argos had been made from the target's account.
  • Keeping fraudsters on the line wastes their time and stops them reaching other, more vulnerable targets.
  • No regulator has opened a specific investigation into this incident; the pattern is well-documented by the Financial Conduct Authority (FCA), the UK body that oversees financial services firms.

One Sunday morning, just after 11am, a reader's phone rang. An automated voice claimed to be from Barclays Bank, warning of a suspicious payment of more than £1,000 to the retailer Argos. Two things were immediately wrong: the reader had not made any such payment, and they do not even hold an account with Barclays.

The call was a classic bank impersonation scam. Criminals use recorded messages or live callers posing as bank fraud departments to create a sense of panic, then persuade targets to hand over account numbers, passwords, or one-time passcodes, which are the short codes banks send by text to confirm your identity.

How does this kind of scam actually work?

The goal is simple: frighten you into acting before you think. A believable alert about a large, unauthorised payment is designed to trigger alarm. Once you are alarmed, the caller's next step is to "help" you secure your account, which in practice means asking for the very details they need to empty it.

Rather than hang up, this particular reader decided to play along. As first reported by The Guardian's Money section, the reader spent hours feeding the fraudsters invented account details, made-up PINs, and fictional large balances. Every minute a scammer spends on a dead-end call is a minute they are not targeting someone less prepared.

What information do these scams try to steal?

Bank impersonation calls typically fish for a specific set of personal and financial data:

Data type Why fraudsters want it
Full name and address To pass bank security checks
Account number and sort code To initiate transfers
Online banking password Direct account access
One-time passcode (sent by text) To authorise payments
PIN number Card-present fraud

No single piece of data is the whole prize. Fraudsters build a picture across the call.

What should you do if you get one of these calls?

Hang up and call your bank back directly using the number on the back of your card or on its official website. Never use a number the caller gives you. Banks will never call and ask for your full PIN or a one-time passcode over the phone.

If you want to waste their time as this reader did, that is your call. But there is no obligation to engage, and vulnerable people should not feel pressured to do so. The safer move is always a clean hang-up.

Report the call to Action Fraud, the UK's national fraud reporting centre, on 0300 123 2040. If the scammers claim to represent a specific bank, that bank's fraud team also wants to know.

© 2026 Threat Vectr