Your bank protects its side of the connection well. The gap is on yours — specifically, whether the page asking for your login is really theirs.
Banks have spent two decades hardening their side of online banking. Encryption, device fingerprinting, transaction monitoring, step-up authentication on unusual payments — the infrastructure is genuinely good.
None of it helps if you type your credentials into a page that is not your bank.
Most phishing wants credentials it can resell. Banking phishing wants a live session, and that changes how the attack is run.
The convincing version does not simply capture your password and disappear. It relays your login to the real bank in real time, shows you whatever the bank shows — including a request for the code your bank just texted you — and passes that code straight through. You see a normal login. The attacker sees an authenticated session.
This is why “I have two-factor authentication” is not the reassurance it once was. A one-time code entered into a fake page is a code handed to whoever built it, and it is valid for as long as the real bank considers it valid.
The defence that matters for banking is not stronger authentication. It is knowing that the page in front of you is genuinely your bank before anything is typed into it.
Rarely by a link in an email these days, because people have learned to distrust those. More often:
A search result. Someone searches for their bank’s login page and clicks a paid advertisement above the real result. The advertisement leads to a convincing copy. This is common enough that several banks have publicly warned about it.
A text message about a payment. A message claiming a transaction needs approving, with a link. Urgency plus a plausible pretext, arriving on a phone where the address bar is truncated and harder to inspect.
A phone call that directs you to a page. The caller claims to be from the fraud team and walks you to a “secure verification” page. Social engineering does the work; the page just collects.
Navigate, do not click. Reach your bank by typing the address or using a bookmark you created yourself. This single habit defeats the search-advertisement and text-message routes entirely, because the attack depends on you following their link rather than your own.
Use a password manager, and notice when it stays quiet. A password manager matches saved credentials to the exact domain. On a lookalike domain it will not offer to fill, and that silence is a signal worth taking seriously. It is one of the few defences that fails safe by default.
Add live page analysis. A security extension that assesses the page as it loads can flag a banking login that is impersonating your bank, including one built this morning that no blocklist has seen. Given how short-lived these pages are, this is the layer most likely to catch a genuinely new one.
Prefer the bank’s app for routine tasks. A pinned app cannot be impersonated by a web page. It removes the address-verification problem from most of your banking rather than solving it.
Turn on transaction alerts. This does not prevent anything, but it compresses the time between something happening and you knowing, and with payment fraud that window is the difference between a recall and a loss.
Speed matters more than certainty. Call your bank using the number on your card, not one from any message. Tell them you may have entered credentials on a fraudulent page and ask them to review recent activity and re-secure the account. Change the password from a different device, and check whether the same password is used anywhere else.
Do not wait to confirm the page was fake before calling. Banks would far rather investigate a false alarm than a completed transfer.
SafeToOpen checks links in your browser and inbox in real time — free to start.
See plans →