Skip to main content

Loan Scam Using Your Data: Two Callers, Fake Documents, and a 'Technical Account' (2026)

A call about a loan allegedly taken out in your name, followed shortly by the 'bank's security department' and an email with a forged ID and police notification; a scheme described in the announcement from the Chief Police Headquarters and FinCERT.pl ZBP from December 2025: how it works, why the number on the display lies, what the bank never does, how to verify an advisor in the app in a minute, and what sanction protects you after blocking your PESEL number.

⚠️ If you just received such a call – three sentences

  1. Hang up. You don't have to be polite. You don't have to explain anything.
  2. Call back the number on the back of your payment card or from the bank's official website – never to the number provided by the caller, and never by 'calling back' to an incoming call.
  3. The number on the display means nothing. Bank Pekao states it directly: 'criminals can spoof any phone number.'

And one thing you should never do: do not transfer money to a 'technical account' or 'secure account.' The police and the Polish Bank Association summarize it in one sentence: 'a real advisor will never ask for that.'

This scheme is not a rumor or urban legend. On December 12, 2025, the Chief Police Headquarters, together with FinCERT.pl – the Banking Cybersecurity Center of the Polish Bank Association issued a statement describing it step by step. Below, we break it down and show exactly where it can be interrupted.

This material is for informational purposes only and does not constitute legal or financial advice.

Anatomy of the Attack

The core of the scheme is always the same: two callers. The first builds trust and evokes fear, the second reaps the harvest.

This is how the first call is described in the police and ZBP announcement:

“A fraudster calls a bank customer, informing them that they are calling from a loan company and formally convincing them that a loan has been taken out in the customer's name by a third party. They assure the customer that they are acting for their safety and that this is a fraud that has already been reported to the bank and the police.”

Note the construction. The caller does not ask for anything yet. On the contrary – they offer help and inform that the matter has already been reported. This is the entire function of the first call: to instill fear and position themselves on your side.

Then the second one comes in:

“After a moment, a second fraudster calls, posing as a Bank Security employee, who through a factual and formal conversation convinces the bank customer that their financial resources are at risk and that it is necessary to secure the funds by transferring them to a technical account. To substantiate their claims, the fraudsters send the customer a forged bank employee ID, a forged so-called 'Funds Security Protocol,' and a forged so-called 'Notification of the Initiation of Criminal Proceedings by the Police.' At the same time, they provide the account number to which the money should be transferred from the personal account. Throughout the process, the fraudsters maintain contact with the victim, manipulating them to make further transactions.”

An element that most people do not expect: fake documents

An email arrives with a service ID, funds security protocol, and notification of the initiation of criminal proceedings. All forged, all looking official.

This is the moment when most people stop doubting – because 'they sent documents.' A piece of paper with a stamp in a PDF costs the fraudster five minutes in a graphic editor and proves nothing.

Why It Works

MechanismHow It Appears in Conversation
Fear and Urgency“Someone took a loan in your name” – triggers immediate action mode and disables verification
Apparent Authority“Security department,” “reported to the police” – you hand over decisions to “experts”
Alliance Against a Common EnemyThe caller is on your side, the enemy is somewhere outside. You do not suspect the person who is helping you
Small Concession Before a Big OneFirst, you confirm a trivial matter, then you make a transfer. Each “yes” makes the next one easier
Gag Order“This is a procedure, confidentiality applies” – cuts you off from the only person who could say: this is a scam
Continuity of ConnectionThe fraudsters do not hang up. You do not have a moment to think or call someone

The gag order is documented. In a case from Sosnowiec, the police described it as follows: “the fraudster instructed the woman not to inform anyone about the entire situation, explaining it as a supposed safety procedure and confidentiality of the ongoing actions”.

Observation from accounts we have not verified in sources

In descriptions of this scheme, a detail appears: the first caller asks the victim which bank they have an account with, and a few minutes later, the “security department” of that very bank calls.

If this happens, it is a first-class warning signal – the bank calling you, by definition, knows you are its customer. We note, however: we have not found this element in any official warning we have accessed. Treat this as an observation from victim accounts, not as a documented rule of the scheme.

What the Fraudsters Really Want

A transfer to a “technical account” is just one of the paths. Documented vectors:

  • Transfer to a “technical account” or “secure account” – the core of the scheme according to the police and ZBP announcement.
  • Authorization codes from SMS and sensitive data – the same.
  • Installation of remote desktop applications. The Central Bureau of Combating Cybercrime described it as follows: the perpetrators “also encouraged the installation of software enabling remote access to the mobile device (…) As a result, they took out loans and made transfers to their accounts.”
  • Encouraging the victim to take out additional loans themselves – supposedly to “block” the actions of the criminals. Over 240,000 PLN was lost in Sosnowiec this way.
  • Cash withdrawal and deposit using BLIK codes at an ATM – a variant recorded by the police in 2025.

Documented Cases

DateCaseLoss
03/19/2025CBZC breaks up a group impersonating bank employees – 9 arrested in the latest wave, a total of 23 arrested in the caseapprox. 3.87 million PLN losses for 97 victims
06/27/2025Ciechanów County – a 32-year-old woman was convinced that a loan was attempted in her name and that she had to “secure the funds”29,870 PLN
July 2025Działdów County – cash withdrawal and deposit using BLIK codes; two people arrestedamount not specified
03/30/2026Sosnowiec – “bank employee,” then “policeman”; the victim took out additional loans to “block” the scamover 240,000 PLN

Two notes to avoid creating a false image. First, there are no nationwide statistics on this method – we checked the annual report from CERT Polska for 2025 and the word “vishing” does not appear in it even once. The amount of 3.87 million PLN pertains to one proceeding, not the scale of the phenomenon in the country. Second, the amount of “around 10,000 PLN” that circulates in descriptions of this scheme is not confirmed in official materials – actual losses can be many times higher.

Why the Number on the Display Lies

The key question is: if a real hotline number is calling, how is that possible?

The technique is called CLI spoofing and has a statutory definition in Poland. The Act of July 28, 2023, on combating abuses in electronic communication defines it as:

“unauthorized use or exploitation by a user or telecommunications entrepreneur initiating a voice call of address information indicating a natural person, legal entity, or organizational unit without legal personality other than that user or telecommunications entrepreneur, serving to impersonate another entity, in particular for the purpose of inducing fear, a sense of threat, or persuading the recipient of that call to a specific behavior, especially to provide personal data, disadvantageous disposal of property, or installation of software”

The law imposes a specific obligation on operators. Article 16 is a single sentence:

“In order to prevent and combat CLI spoofing, the telecommunications entrepreneur blocks voice calls or hides the identification of the calling number for the end user.”

In addition, there is a mechanism tailored for hotlines: the President of UKE maintains a public list of numbers used solely for receiving calls. The bank registers its hotline number there, and operators block incoming calls from that number within three days. Since the hotline is only for receiving, any call “from it” is by definition forged.

Spoofing is also a crime: Article 31 of the law provides for a prison sentence of 3 months to 5 years, and in the case of lesser offenses, a fine or restriction of freedom.

And yet, do not trust the display

The regulations have been in effect since 2023, but neither CERT Polska nor banks say that the problem has disappeared. CERT Polska states directly:

“Do not blindly trust the displayed number or the name of the caller. Criminals can spoof them!”

Bank Pekao states exactly the same: “Remember, criminals can impersonate any phone number.”

The number on the screen is not proof of identity. It never was.

More about how number spoofing works – why it is technically possible, what exactly the 2023 law changed, what the public list of UKE numbers 'for receiving only' is, and what settings on your phone actually help – in a separate guide: CLI spoofing: why the number on the display lies and how to defend against it.

What the Bank Never Does

This is a list worth memorizing – because there is no time to search during a call. All the sentences below are direct quotes from Polish bank websites.

The bank never asks for...Source
“The bank never asks for the full password to electronic banking services.”Pekao
“Do not install applications (e.g., AnyDesk, TeamViewer, or Quick Support) at the request of a third party (…) The bank never asks you to run such applications.Pekao
We never ask you to install any software.Pekao
“Do not provide third parties with your card details and CVV2/CVC2 code – the bank never asks for that.Pekao
“A bank employee will never ask you for your payment card details and PIN, your login and password for electronic banking, your full PESEL number, or your BLIK code. They will also not encourage you to install additional software.”PKO BP
The bank will never ask you to confirm a transaction that you did not initiate yourself.Alior
“Under no circumstances allow the caller to temporarily take control of your computer (bank employees never do this)”CERT Polska

One sentence deserves special mention, as it dismantles a very effective trick. mBank states:

“We do not send SMS messages to confirm that we are calling from mBank. Such confirmation will only be received in the mobile application and only after logging in.”

So: an SMS “confirming” that the bank is calling is by definition false at mBank.

Honest disclaimer: despite searching, we did not find any bank stating “we never ask for a verification transfer”. The closest is the statement from the police and ZBP – “a real advisor will never ask for that” – and we present it here as the position of the police and the Polish Bank Association, not as a quote from a specific bank.

How to Verify if the Calling Bank is Real in a Minute

This is the most practical part of the entire guide, and few people know about it. Three major banks allow you to verify the identity of the calling advisor in the mobile app.

  1. Say you want to verify the caller in the app

    PKO BP states it directly: “During the conversation with the bank employee, say that you want to verify their identity in the IKO app.” In Pekao: “ask for verification of their identity in PeoPay or Pekao24 or hang up.” In mBank, the consultant sends a notification themselves.

  2. Log in to the app and check the notification

    You will see the name, surname, position, and location from which the caller is calling. Compare it with what they said.

  3. If the data matches – confirm and continue the conversation

    Only now is the conversation credible.

  4. If not – hang up immediately

    mBank leaves no room for interpretation: if there is no notification or the caller claims that “they cannot send you such a notification, e.g., due to technical problems”“hang up as soon as possible to avoid fraud.”

“Technical problems” are not an excuse – they are a signal. A real consultant has this function and uses it. A fraudster does not have it and must convince you to skip it.

We did not check if ING, Santander, and Alior have a similar function – if you have an account there, ask about it on the hotline, calling yourself.

What to Do During the Call

A sentence that ends the matter

“Thank you, I am hanging up and will call back the number on my card.”

You do not have to justify it or apologize. A real bank employee will consider it reasonable – because that is exactly what banks teach you. A fraudster will start to protest, explain that “the matter is urgent,” that “the line is secure,” or will resort to aggression. This reaction in itself is an answer.

Several rules for the duration of the call:

  • Do not confirm data that the caller does not know. If they ask for your PESEL number, account number, or which bank you have an account with – this is not verification, but information gathering.
  • Do not read codes from SMS aloud. Instead, read the content of the SMS to yourself – it describes the operation you are currently approving.
  • Do not install anything. Without exceptions.
  • Do not let yourself be cut off from loved ones. The gag order is an element of the scheme, not a bank procedure.
  • Hang up for real. After hanging up, wait a few seconds or call from another phone – this is how caution looks, and it costs nothing.
  • Aggression is not proof that it is the bank. It is the last attempt to break your resistance.

If Money Has Been Transferred or You Provided Data

  1. Immediately call the bank's hotline

    The number from your card or the official website. Demand to block the card and access, report the recipient's account as suspicious, and record a complaint with the date of receipt. In the case of a transfer, minutes count, not hours.

  2. Block your PESEL number

    For free, via gov.pl or the mObywatel app. Why this is so important – below.

  3. Block your documents

    The DOKUMENTY ZASTRZEŻONE system of the Polish Bank Association: by phone at +48 828 828 828, at the bank, or through mObywatel. This is a separate register from the blocking of PESEL – it is worth activating both.

  4. Secure the evidence

    The number from which the call was made, call times, emails with fake documents (do not delete them), transfer confirmations, recipient account number.

  5. File a report with the police

    At any unit. Fake documents and call records are real evidence here.

  6. If you installed remote access software

    Uninstall it, and treat the device as compromised: change passwords from another device, log out of all sessions. Consider restoring factory settings.

How to Protect Yourself in Advance

Blocking PESEL – and a sanction that few know about

Blocking your PESEL number is free and takes a moment: via gov.pl (the system redirects to mObywatel) or at any municipal office. From June 1, 2024, financial institutions will be required to verify the register when entering into a loan or credit agreement.

However, the most important thing is what happens when someone ignores this obligation. The Act of July 7, 2023, introduced a sanction – and in three places at once, so it applies not only to banks but also to loan companies. The wording from the Banking Law:

“A domestic bank, credit institution, branch of a credit institution, and branch of a foreign bank may not demand from the consumer and their legal successors satisfaction of a claim arising from the agreement specified in paragraph 1 nor transfer the receivable arising from this agreement, if at the time of concluding the agreement from which the claim arises, the PESEL number of that consumer was blocked in the register of blocked PESEL numbers.”

In layman's terms: if someone takes out a loan in your name despite the blocking, the institution cannot demand repayment from you or sell that debt to a collection agency. This is a real shield, not just a declaration.

By the way: blocking PESEL also suspends cash withdrawals at a branch above three times the minimum wage for 12 hours – even if someone subsequently cancels the blocking.

BIK Alerts and Credit Blocking

BIK Alerts are an annual subscription that sends an SMS “when someone applies for a loan/credit in your name”. As of August 2026, it costs 48 PLN per year (36 PLN at the starting price for new users); a package with six reports – 139 PLN per year. Promotional prices can vary, so check the current ones before purchasing.

Included with the Alerts is a free BIK credit blocking – you inform institutions that you do not agree to credit in your name. However, BIK itself notes a limitation: when asked if it provides a guarantee, it answers “No, credit blocking does not provide such a guarantee” – because it covers institutions using BIK. The statutory PESEL blocking is stronger in this regard and is free. It is best to have both.

How to Check if Someone Has Already Taken a Loan in Your Name

  • Free copy of data from BIK – entitled to “once every 6 months” under GDPR. It shows, among other things, obligations: the name of the institution, the date taken, the amount, and delays.
  • PESEL verification history in mObywatel – in the blocking section, you will see the history of status changes and verification of your number by companies and institutions. An unrecognized verification is a signal that someone has tried.

We did not find an official, governmental step-by-step instruction in case a loan has already been fraudulently taken out – neither on gov.pl nor in the BIK guide. The formal path remains to demand correction of data in BIK (deadline: one month, with a possibility of extension by two), a complaint with the institution, a police report, and – if the institution rejects the complaint – an application to the Financial Ombudsman.

Frequently Asked Questions

Can I report a suspicious call to the number 8080?

No. The number 8080 is used exclusively for forwarding suspicious SMS messages – as stated in the law, which refers to “recipients of short text messages.” You can report a suspicious call through the form on incydent.cert.pl, which has a separate category “Suspicious Phone” – and also to your bank and the police. Details in the guide on CLI spoofing.

A real number from my bank called. Was it definitely the bank?

No. This is the most common mistake. The number can be spoofed, and CERT Polska and banks warn against this directly. Moreover, bank hotline numbers are sometimes listed in the UKE register as “for receiving only” – then a call “from the hotline” is by definition fake.

They sent me an ID and protocol. After all, these are official documents.

This is a standard element of this scheme, described directly by the police and ZBP. Fake IDs, protocols, and notifications of the initiation of proceedings are a PDF file, not proof.

They told me not to tell anyone because it is a secret procedure.

No real bank or police procedure prohibits you from talking to family. The gag order is a tool of isolation – and is sufficient in itself to end the conversation.

The caller was nice and factual, knew my data.

Personal data leaks en masse, and knowledge of them proves nothing. Politeness is a tool of work, not proof of identity – which is why the only sensible verification is to hang up and call back the number you found yourself.

Can a transfer to a “technical account” be reversed?

Sometimes, but only before the money is withdrawn – which is why the first call goes to the bank, not the police. The sooner, the greater the chance.

Related Materials

One sentence to send to parents

If someone calls and says a loan has been taken out in your name – hang up and call the number on the back of your card. The bank will never ask you to transfer money to a 'secure account' and will never prohibit you from talking to family.

Status as of August 28, 2026. This material is for informational purposes only and does not constitute legal or financial advice. We have consciously noted in the text what we could not confirm at the source – including questions about the bank as an element of the scheme, amounts of 'around 10,000 PLN,' and nationwide statistics on this method. Prices of services and banking practices change; check the current status at the source before making a decision.

Official sources

Was this guide helpful?

Help others – share your experience

Answer one question below. Your answer will help people in similar situations.

Have you ever received a call about a loan taken out in your name? How did you react and what happened next?

Your response will be reviewed before publication.

Comments (0)

No comments yet. Be the first!


Add a comment

Log in to skip email verification, or comment as guest:

Comment may be moderated before publishing.