Skip to main content

The Money Overview

A verbal password on a bank account blocks a caller who spoofs the bank

A phone rings with the bank’s own customer-service number on the display, and the caller already knows the account holder’s name and the last four digits of the account. That is often enough to convince a careful, longtime customer to read back a one-time passcode to someone posing as a fraud-prevention agent. The trick behind the fake number is what regulators call spoofing, and one low-tech defense that many banks and credit unions already offer blunts it completely: a spoken password attached to the account that a stranger calling in cold has no way to produce.

How Caller ID Spoofing Turns a Bank’s Trusted Number Into a Weapon

Caller ID spoofing does not require hacking into a bank’s phone system. Cheap, widely available VoIP calling tools let a caller type in any outbound number before dialing, so a fraud ring can display the exact support line printed on the back of a debit card or the number a customer has called a dozen times before. The screen offers no clue that the call originated somewhere else entirely, often overseas. Combined with basic information about a target — a name, a partial account number, a recent transaction — the display alone is often the last piece of doubt a targeted customer needed cleared before cooperating.

The Consumer Financial Protection Bureau defines the underlying tactic as a caller disguising the information a phone displays so it appears to come from a specific person or organization, and pairs it with a related pattern it calls imposter scams — callers who pretend to be a bank, a government agency or someone the target trusts in order to extract money or account access. Bank-impersonation calls borrow both: a spoofed number supplies the visual proof, and a scripted claim of unauthorized activity supplies the urgency, pushing a customer to act before verifying anything independently.

Older account holders are disproportionately targeted in these calls, in part because they are more likely to answer an unfamiliar-looking but locally displayed number and less likely to have been warned that a legitimate-looking caller ID proves nothing about who is actually calling. Federal regulators track bank-impersonation fraud as a form of elder financial exploitation when the victim is an older adult, reflecting how frequently the tactic is aimed at retirement and pension accounts rather than everyday checking balances.


Free retirement updates: One number can cost or save hundreds a month in retirement. The free Retirement Shield newsletter surfaces the ones worth knowing. Sign up free.

Why a Shared Verbal Password Defeats a Spoofed Caller

A verbal password — sometimes called a telephone passphrase or callback code — is a word or short phrase an account holder sets with a bank in advance, stored on the account like a security question, that has nothing to do with the number on the caller ID. When it is in place, a legitimate fraud-department agent verifying a call is expected to ask for it, and a customer who is suspicious of an inbound call can ask the caller to supply it before continuing. A scammer working from a spoofed number and a partial data profile has no access to that phrase, because it was never printed on a statement, card or public record.

The mechanic works because it shifts the trust test away from the caller ID display, which spoofing defeats for free, and onto a shared secret that only the account holder and the institution possess. Unlike a Social Security number or a mother’s maiden name, both of which show up in old data breaches and public records that scammers already trade, a self-chosen verbal password exists nowhere except inside the bank’s own system and the account holder’s memory, so leaked personal data cannot be used to guess or bypass it.

Most large banks and many credit unions already support some version of this control, though it is rarely offered by default — a customer typically has to call in and specifically request a verbal password, callback PIN or account passphrase be added to the file. Some institutions instead offer a related tool, a security callback number the customer designates in advance, so any call claiming to be from fraud prevention can be independently verified by hanging up and dialing that pre-set number rather than trusting whatever shows on the screen or whatever number the caller supplies.

Setting Up and Protecting a Verbal Password Without Creating a New Opening

The safeguard only works if the phrase itself stays as protected as a PIN. Because the entire point is that a caller who does not already have the password cannot pass as the bank, account holders undermine the tool the moment they read it aloud to somebody who called them rather than somebody they called. The Consumer Financial Protection Bureau’s general guidance on imposter calls applies directly here: hang up on an unexpected call claiming to be a bank and dial the number printed on a card or statement, a number known to be genuine, rather than continuing the conversation or calling back a number the caller provided.

Setting the password up requires the same discipline. It should be established by calling the number on the back of a card or logging into the bank’s verified app or website, never by giving information to an inbound caller who offers to add one during the same conversation as an unrelated fraud alert. A password that doubles as an answer to a common security question — a pet’s name, a street someone grew up on — is also weak, since that information often already circulates in social media profiles or old data-breach dumps that scammers can search before they ever place the call.

Adoption remains uneven largely because the option is opt-in and under-advertised; most bank websites bury it inside fraud-prevention or account-security pages rather than presenting it during account opening, so the customers most likely to benefit from it are also the ones least likely to know it exists until after a spoofed call has already cost them money. Whether that changes depends less on customer demand than on a bank’s own service scripts — a verbal password only stops a fraudulent call when every legitimate employee is trained to ask for it every time, not just when a customer thinks to bring it up.

This article was produced with the assistance of AI and reviewed by The Money Overview editorial team before publication.

More Financial Reading


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.