Bank of America phishing email: verify it safely
In brief
Learn how to check a Bank of America phishing email, verify a transaction safely, report the message, and respond after sharing banking details.

Treat an unexpected Bank of America email as unverified until you check the claimed transaction or account event in the banking app, a browser session you open independently, or by calling the number on your card. Do not use the email's sign-in button, reply address, attachment, or phone number. A familiar logo, masked account number, or urgent fraud warning is not enough.
At a glance
Quick takeaways
- Open the bank app independently and check the exact transaction or alert.
- Call the number printed on your card, not a number in the email.
- Never send a password, one-time code, PIN, or full card details in response.
- Treat payment reversals, locked accounts, and transfer alerts as claims to verify.
- Report the email through your mailbox and the bank's current official path.
- Contact the bank promptly through a verified channel if money or account access is at risk.
What does a Bank of America phishing email look like?
A Bank of America impersonation email often claims that something changed in the account: a card was locked, an unusual purchase occurred, a transfer or payment needs review, a statement is ready, a deposit is pending, or personal information must be updated. The message may say that access will be limited unless the reader acts quickly.
The requested action can be signing in, calling a fraud number, replying with account information, opening a statement, confirming a transfer, or sharing a one-time code. Another pattern promises a refund or reversal but requires the reader to move money or reveal banking details first.
These are pattern shapes, not descriptions of a breach or a specific campaign. The bank is being impersonated. The safest response is to remove the email from the verification process and check the claimed event in records controlled by the customer and bank.
The Federal Trade Commission explains in its phishing guidance that impersonation messages can seek personal information or money. Banking lures add urgency because recipients want to stop a transfer or restore access before checking the contact route.
The phishing examples guide covers general patterns. This page focuses on transactions, account access, cards, and payment recovery.
Which banking email clues matter most?
Start with the transaction. Does the independently opened account show the purchase, transfer, card status, or profile change described? A reference number inside the message does not count as separate proof. Match the amount, merchant, date, account, and status against your own records.
Read the full sender address and Reply-To value. A display name can say "Bank of America" while the address uses an unrelated or lookalike domain. Extra words and spelling substitutions support suspicion. A familiar-looking sender still does not prove that the phone number, button, or transaction claim is safe.
Preview links without opening them. Do not infer ownership because the bank's name appears somewhere in a longer hostname or URL path. Compare the complete destination with the banking route you opened independently. Do not use the email to learn the bank's correct address.
Treat requests for a password, PIN, one-time code, full card number, bank-account credentials, or remote access as stop signs. Do not debate the sender or provide partial information. Open a new path to the bank and explain what the message requested.
How do I verify the transaction safely?
Open the banking app you already use or use a trusted bookmark. You can also call the number printed on the back of your card or on a statement you already possessed. Do not search the suspicious email for a better number.
Check the specific account evidence:
- Review posted and pending card transactions for the named merchant and amount.
- Review transfers and bill payments for the claimed recipient or destination.
- Check whatever transaction, alert, or profile evidence the independently opened account exposes.
- Compare a statement claim with the statement retrieved through your normal banking route.
- Ask another authorized account holder whether they initiated the activity.
A fake email can arrive while an unrelated real transaction is pending. Match exact details instead of treating any account activity as confirmation.
How do I handle a transfer or refund request?
Do not move money to "protect" it because an email or caller instructs you to. A transfer request changes the situation from message verification to potential financial loss. End the sender-controlled conversation and contact the bank through a verified route.
Refund pretexts can ask you to share card details, sign in, install remote-access software, or return an alleged overpayment. Check whether the original debit exists and whether a credit appears in the account. Do not rely on a screenshot, email receipt, or balance shown by a person who controls your device.
For a business account, use the established payment-approval process. Confirm any beneficiary or routing change with the known requester through a separate channel. A security team can examine the email; finance or treasury must validate the payment authority.
Keep the call, account, and device paths separate. A caller who knows the amount written in the email has not proved anything because both details came from the same source.
How do I report a Bank of America phishing email?
Bank of America publishes abuse@bofa.com for reporting suspicious email (Bank of America: report suspicious activity). Verify any account claim by signing in through the app or by typing the address yourself, never through the message.
Locate the reporting process documented for the receiving mailbox. If it reached a work account or involved a business banking relationship, follow the organization's security and finance escalation paths. Follow their retention or deletion instructions rather than assuming a universal workflow.
To notify Bank of America, open the bank's app or official site independently and locate its current fraud or suspicious-message instructions. You can also call the number on your card or existing statement. Do not guess a reporting email address and do not use a form, link, or number provided by the suspected message.
Handle an unauthorized transaction through the bank's current account or card process, reached independently. Handle the suspicious email through the receiving mailbox's documented reporting process. This article does not assume that one submission starts both workflows.
The phishing reporting guide explains the evidence and destination choices without restating brand-specific examples.
What if I already shared banking information?
Contact the bank promptly through the card number, known app, or trusted statement. Tell the bank exactly what you disclosed: username, password, PIN, one-time code, card number, account number, identity data, transfer approval, or remote access. Those exposures require different controls.
Use a trusted device to change exposed passwords and follow the account-recovery checks supplied through the bank's independent app, site, or card number. If you reused the banking password elsewhere, replace it on those accounts too.
If money moved, preserve transaction records and ask the bank or payment provider about the available recovery process. If remote-access software was installed, follow a device incident process and do not let the original caller reconnect. If identity documents were shared, use independently located identity-recovery channels.
Reporting the email can wait a few minutes while you protect the account and payment path. The clicked-phishing-link recovery guide provides separate actions for credentials, payments, and devices.
Why did a Bank of America phishing email reach me?
Sender authentication provides domain-identity evidence, not proof that a delivered banking claim is true. The transaction and support path still need independent verification.
DMARC connects an aligned authentication pass with the domain visible in the From address and publishes a requested policy for failures. Treat that as domain-identity evidence, then verify the transfer, card charge, or support contact through the independent banking route.
Read why phishing emails can pass SPF and DKIM for that technical limit. The decisive banking evidence remains the account session and the contact route you opened independently.
A safe Bank of America email decision rule
Write down the claimed account event, amount, and requested action. Then set aside every button, number, address, and attachment that came from the email. Open the bank account or call the number on your card and compare the details.
If no matching event exists, report the email. If an expected event exists, handle it in the independent session. If an unauthorized event exists, begin the bank's fraud process. If you already exposed credentials, codes, money, or device access, state that clearly and complete each matching recovery step.
This decision rule does not depend on recognizing a perfect fake. It prevents the sender from controlling both the alarming claim and the supposed solution.
Evidence
Sources and further reading
Questions readers ask
Frequently asked questions

Written by
Samuel ChenardCEO & Co-Founder, Palisade
Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.
More from Samuel →


