# Bank of America phishing email: verify it safely

> Learn how to check a Bank of America phishing email, verify a transaction safely, report the message, and respond after sharing banking details.

Treat an unexpected Bank of America email as unverified until you check the claimed transaction or account event in the banking app, a browser session you open independently, or by calling the number on your card. Do not use the email's sign-in button, reply address, attachment, or phone number. A familiar logo, masked account number, or urgent fraud warning is not enough.

## Quick takeaways

- Open the bank app independently and check the exact transaction or alert.
- Call the number printed on your card, not a number in the email.
- Never send a password, one-time code, PIN, or full card details in response.
- Treat payment reversals, locked accounts, and transfer alerts as claims to verify.
- Report the email through your mailbox and the bank's current official path.
- Contact the bank promptly through a verified channel if money or account access is at risk.

## What does a Bank of America phishing email look like?

A Bank of America impersonation email often claims that something changed in the account: a card was locked, an unusual purchase occurred, a transfer or payment needs review, a statement is ready, a deposit is pending, or personal information must be updated. The message may say that access will be limited unless the reader acts quickly.

The requested action can be signing in, calling a fraud number, replying with account information, opening a statement, confirming a transfer, or sharing a one-time code. Another pattern promises a refund or reversal but requires the reader to move money or reveal banking details first.

These are pattern shapes, not descriptions of a breach or a specific campaign. The bank is being impersonated. The safest response is to remove the email from the verification process and check the claimed event in records controlled by the customer and bank.

The Federal Trade Commission explains in its [phishing guidance](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams) that impersonation messages can seek personal information or money. Banking lures add urgency because recipients want to stop a transfer or restore access before checking the contact route.

The [phishing examples guide](/learning/phishing-email-examples) covers general patterns. This page focuses on transactions, account access, cards, and payment recovery.

## Which banking email clues matter most?

Start with the transaction. Does the independently opened account show the purchase, transfer, card status, or profile change described? A reference number inside the message does not count as separate proof. Match the amount, merchant, date, account, and status against your own records.

Read the full sender address and Reply-To value. A display name can say "Bank of America" while the address uses an unrelated or lookalike domain. Extra words and spelling substitutions support suspicion. A familiar-looking sender still does not prove that the phone number, button, or transaction claim is safe.

Preview links without opening them. Do not infer ownership because the bank's name appears somewhere in a longer hostname or URL path. Compare the complete destination with the banking route you opened independently. Do not use the email to learn the bank's correct address.

Treat requests for a password, PIN, one-time code, full card number, bank-account credentials, or remote access as stop signs. Do not debate the sender or provide partial information. Open a new path to the bank and explain what the message requested.

## How do I verify the transaction safely?

Open the banking app you already use or use a trusted bookmark. You can also call the number printed on the back of your card or on a statement you already possessed. Do not search the suspicious email for a better number.

Check the specific account evidence:

- Review posted and pending card transactions for the named merchant and amount.
- Review transfers and bill payments for the claimed recipient or destination.
- Check whatever transaction, alert, or profile evidence the independently opened account exposes.
- Compare a statement claim with the statement retrieved through your normal banking route.
- Ask another authorized account holder whether they initiated the activity.

If the event is real and expected, continue only in the independent session. If it is real and unauthorized, locate the bank's current fraud process there or through the card number. If no matching event exists, report the email and keep its links and phone number unused.

A fake email can arrive while an unrelated real transaction is pending. Match exact details instead of treating any account activity as confirmation.

## How do I handle a transfer or refund request?

Do not move money to "protect" it because an email or caller instructs you to. A transfer request changes the situation from message verification to potential financial loss. End the sender-controlled conversation and contact the bank through a verified route.

Refund pretexts can ask you to share card details, sign in, install remote-access software, or return an alleged overpayment. Check whether the original debit exists and whether a credit appears in the account. Do not rely on a screenshot, email receipt, or balance shown by a person who controls your device.

For a business account, use the established payment-approval process. Confirm any beneficiary or routing change with the known requester through a separate channel. A security team can examine the email; finance or treasury must validate the payment authority.

Keep the call, account, and device paths separate. A caller who knows the amount written in the email has not proved anything because both details came from the same source.

## How do I report a Bank of America phishing email?

Bank of America publishes `abuse@bofa.com` for reporting suspicious email ([Bank of America: report suspicious activity](https://web.bankofamerica.com/en/security/report-suspicious-activity)). Verify any account claim by signing in through the app or by typing the address yourself, never through the message.

Locate the reporting process documented for the receiving mailbox. If it reached a work account or involved a business banking relationship, follow the organization's security and finance escalation paths. Follow their retention or deletion instructions rather than assuming a universal workflow.

To notify Bank of America, open the bank's app or official site independently and locate its current fraud or suspicious-message instructions. You can also call the number on your card or existing statement. Do not guess a reporting email address and do not use a form, link, or number provided by the suspected message.

Handle an unauthorized transaction through the bank's current account or card process, reached independently. Handle the suspicious email through the receiving mailbox's documented reporting process. This article does not assume that one submission starts both workflows.

The [phishing reporting guide](/learning/report-email-phishing-scams) explains the evidence and destination choices without restating brand-specific examples.

## What if I already shared banking information?

Contact the bank promptly through the card number, known app, or trusted statement. Tell the bank exactly what you disclosed: username, password, PIN, one-time code, card number, account number, identity data, transfer approval, or remote access. Those exposures require different controls.

Use a trusted device to change exposed passwords and follow the account-recovery checks supplied through the bank's independent app, site, or card number. If you reused the banking password elsewhere, replace it on those accounts too.

If money moved, preserve transaction records and ask the bank or payment provider about the available recovery process. If remote-access software was installed, follow a device incident process and do not let the original caller reconnect. If identity documents were shared, use independently located identity-recovery channels.

Reporting the email can wait a few minutes while you protect the account and payment path. The [clicked-phishing-link recovery guide](/resources-post/what-to-do-if-you-clicked-on-a-phishing-link) provides separate actions for credentials, payments, and devices.

## Why did a Bank of America phishing email reach me?

Sender authentication provides domain-identity evidence, not proof that a delivered banking claim is true. The transaction and support path still need independent verification.

[DMARC connects an aligned authentication pass with the domain visible in the From address and publishes a requested policy for failures](https://www.rfc-editor.org/rfc/rfc9989.html). Treat that as domain-identity evidence, then verify the transfer, card charge, or support contact through the independent banking route.

Read [why phishing emails can pass SPF and DKIM](/learning/why-do-phishing-emails-pass-spf-and-dkim) for that technical limit. The decisive banking evidence remains the account session and the contact route you opened independently.

## A safe Bank of America email decision rule

Write down the claimed account event, amount, and requested action. Then set aside every button, number, address, and attachment that came from the email. Open the bank account or call the number on your card and compare the details.

If no matching event exists, report the email. If an expected event exists, handle it in the independent session. If an unauthorized event exists, begin the bank's fraud process. If you already exposed credentials, codes, money, or device access, state that clearly and complete each matching recovery step.

This decision rule does not depend on recognizing a perfect fake. It prevents the sender from controlling both the alarming claim and the supposed solution.

## Sources and further reading

- [Bank of America: report suspicious activity](https://web.bankofamerica.com/en/security/report-suspicious-activity)
- [Federal Trade Commission: How to recognize and avoid phishing scams](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams)
- [RFC 9989: Domain-based Message Authentication, Reporting, and Conformance](https://www.rfc-editor.org/rfc/rfc9989.html)
- [Palisade phishing reporting guide](/learning/report-email-phishing-scams)
- [Palisade phishing email examples](/learning/phishing-email-examples)

## Frequently asked questions

### Does a masked account number prove the email is from Bank of America?

No. Compare the claimed event with the independently opened account and contact the bank through the number on your card if needed.

### Should I call the fraud number in the email?

No. Call the number printed on your card or a statement you already trust, or use the bank app you opened independently.

### What if the transaction in the email really appears in my account?

Handle it through the account's official fraud or transaction process. Do not return to the email's link or phone number.

### Is changing my banking password enough after sharing a code?

Not always. Contact the bank and review sessions, recovery details, transfer recipients, and account changes because a shared code may have authorized access.

### Can reporting the email stop a bank transfer?

No. Contact the bank or payment provider through a verified channel. Mailbox reporting and financial recovery are separate actions.
