How/Paano
ENTL
HowPaano / Technology

How to tell a real bank message from a scam text

Six checks that take about thirty seconds and catch almost every smishing attempt currently working in the Philippines.

18 September 2026 3 min read Basahin sa Tagalog

Scam texts stopped being obvious a few years ago. The spelling is fine now, the sender name says the bank, and the message arrives in the same thread as your real one-time passwords. That last part throws most people, so it is worth saying plainly: a message appearing inside an existing thread proves nothing about who sent it.

What follows is the order to check things in. It works because it does not depend on the message looking suspicious.

Step 01

Never act inside the message

Do not tap the link. Do not call the number in the text. Open your banking app the way you normally do, or type the bank address into the browser yourself.

If the message is real, whatever it is warning you about will also be visible inside the app. If nothing is there, the message was not real.

  • Open the app from your home screen, not from the message.
  • Type the web address by hand rather than tapping a link.
  • Use the number printed on the back of your card to call.
Step 02

Read the link, not the text around it

Press and hold a link to preview it instead of opening it. You are looking at the part immediately before the first single slash, because that is the only part the sender cannot fake.

Everything after the slash is decoration. A link reading bpi.secure-login.example.com belongs to example.com, not to BPI.

  • Read right to left from the first slash.
  • Hyphens and extra words before the real domain are a common trick.
  • A shortened link hides all of this, so treat one as unverified.
Step 03

Check what is being asked for

No bank asks you to confirm an OTP, a PIN, a card number or a password through a message, a call or a form. Staff cannot ask either, including when they call you back.

An OTP is a one-way code. It travels from the bank to you and stops there. Anyone asking you to read one out is trying to log in as you right at that moment.

  • An OTP request from another person is always fraud.
  • Genuine fraud teams verify you, never the other way around.
  • Nobody legitimate needs your full card number by message.
Step 04

Treat urgency as the warning sign itself

Scam messages create a deadline because a deadline stops people checking. Account suspended in 24 hours. Unauthorised login, confirm now. Package held, pay a small fee.

Banks freeze first and explain afterwards. They do not give you a countdown and a link.

  • A stated deadline in the first two lines is a strong signal.
  • Small amounts are used because they feel easier to just pay.
  • Threats about legal action or closure are not how banks write.
Step 05

If you already tapped it

Move quickly and in this order. Do not wait to see whether anything happens.

  • Call the bank using the number on your card and report it.
  • Change the password, then sign out of all devices in the app.
  • Check and remove any linked e-wallet or recurring payment.
  • Report the sender number to your telco so it can be blocked.
  • Watch the account daily for a week, including small amounts.

In closing

The single habit that protects you is refusing to act inside the message. Open the app yourself, every time, even when the message turns out to be genuine. It costs a few seconds and it removes the entire category of attack.

If you did tap through and enter something, treat it as compromised and call the bank now rather than after you see a transaction.