https://whitelabel-manager-production.ams3.digitaloceanspaces.com/thumbs/unnamed-2985e.png_800x.png
August 21, 2026
Author: Adam Collins

Bank of America Scams: How They Work and How to Protect Your Account

In a Nutshell

  • Mass Target: Bank of America’s 69M+ customers make it the #1 target for identity theft and impersonation scams.
  • New 2026 Malware Threat: Cybercriminals are using fake "Account Guard" security emails to silently hijack computers with remote-access trojans.
  • Caller ID Deception: Scammers easily spoof official bank phone numbers and use leaked data to trick victims into self-initiating Zelle transfers.
  • Zero-Trust Rule: Never click links or share one-time passcodes—always navigate to bankofamerica.com manually or use the official mobile app.

Bank of America is the most impersonated bank in the United States. That's not a coincidence: with over 69 million consumer and small business clients, it's the single largest target for fraudsters who know that a convincing BofA alert will land in millions of inboxes. According to the FTC's June 2026 data, Americans lost $3.5 billion to imposter scams in 2025 alone, with bank impersonators responsible for the single largest share of those losses, nearly $1 billion.

The real danger: these scams no longer look like obvious fakes. Modern BofA phishing emails copy the bank's exact logo, color palette, and email formatting. Some even install remote access software on your device before you realize anything is wrong.

This guide covers every major Bank of America scam type active in 2025 and 2026, with real examples, the red flags that give each one away, and a step-by-step plan for what to do if you've already been targeted.

The Most Common Bank of America Scams Right Now

Fraudsters rotate their tactics constantly, but the underlying playbook stays the same: impersonate the bank, create urgency, and harvest credentials or money before the victim has time to think. Here are the active scam types you need to know.

1. Phishing Emails

Phishing emails are the oldest trick and still among the most effective. Scammers send messages that look identical to official BofA communications, right down to the logo and footer. The emails typically arrive with subject lines designed to trigger panic:

  • "Suspicious Activity Detected on Your Account"
  • "Unusual Sign-In Attempt – Verify Your Identity"
  • "Alert: Unauthorized Transaction on Your BofA Account"

The tell: the sender address is never from @bankofamerica.com or @ealerts.bankofamerica.com. Common fakes include addresses like security@bankofamerica-alerts.com, noreply@bofasecure.net, or alerts@boa-online.com. The "Verify" button inside the email links to a lookalike login page that captures your credentials the moment you type them.

2. The August 2026 "Account Guard" Malware Campaign

This is the most sophisticated Bank of America scam identified to date. Cybersecurity firm Huntress flagged the campaign on August 5, 2026, after it landed in their honeypot inbox on July 28.

Here is exactly how it worked:

  1. Victims received an email from onlinebanking@ealerts[.]bkofamerica[.]com (note the subtle typo: "bkofamerica" instead of "bankofamerica") warning that their account would be "restricted" unless they confirmed their information.
  2. Clicking the link took Windows users to a convincing BofA lookalike page hosted on kleinschnitg[.]com, which had nothing to do with the real bank.
  3. That page prompted users to click "Update My Information" and download a file called AccountGuardSetup.zip.
  4. Running the script inside the zip installed ScreenConnect, a legitimate remote monitoring tool, giving the attacker full, silent access to the victim's computer.
  5. Mac users who clicked the same link were taken to a credential-harvesting form requesting their full name, mailing address, government ID, Social Security number, and payment card details.

Why this matters: the attacker could now log into the victim's bank account, transfer funds, and even lock the victim out, all while the victim believed they had just "updated" their security settings.

3. Smishing (Text Message Scams)

Bank of America is one of the biggest targets for smishing, phishing delivered by SMS. These texts are engineered to look like legitimate bank alerts. A 2025 analysis found over 59 card suspension messages, 97 unique phone numbers, and 254 spoofed email addresses all tied to a single BofA smishing campaign.

Real examples of BofA smishing texts in circulation:

  • "(Fraud) Alert: Your BofA ATM/Debit card has been suspended. Please call 1-870-XXX-XXXX to verify."
  • "BofA Payment Accepted for $153.48 at PetSmart on 04/21. Was this you? IF NO RING 1-XXX-XXX-8834."
  • "Did you authorize check #0000008124 for $39,182.00? View image: [URL]"
boa-2-386b6.png boa-3-5e1e5.png

Examples of BoA Text scams

The texts either include a link to a cloned BofA login page or a phone number that connects you to a scammer posing as the bank's fraud department. Once you "log in" on the fake page, your credentials go straight to the attacker.

4. Vishing (Phone Call Impersonation)

Vishing scams involve a caller who claims to be from Bank of America's fraud department. They often spoof the bank's real phone number so it shows up correctly on your caller ID. The script is consistent: there's "suspicious activity" on your account, and you need to act immediately to protect your funds.

The call typically ends with one of these requests:

  • Transfer your money to a "safe account" (which the scammer controls)
  • Provide your one-time passcode to "verify your identity"
  • Purchase gift cards and read the codes over the phone

Key fact: Bank of America itself states it will never ask you to send money, share a verification code, or purchase gift cards as part of any fraud investigation.

5. Fake BofA Websites

Scammers register lookalike domains to host convincing copies of the Bank of America login page. These domains follow predictable patterns:

boa-4-d9a11.png

Once you enter your username and password on one of these pages, the scammer has everything needed to access your real account.

How to Spot a Fake Bank of America Alert

The goal of every BofA scam is the same: make you act before you think. Slowing down for 30 seconds and running through this checklist is the single most effective defense.

Check the Sender Address (Emails)

This is the fastest way to identify a phishing email. Click on the sender's display name to reveal the full email address. Legitimate Bank of America emails come exclusively from two domains:

  • @bankofamerica.com
  • @ealerts.bankofamerica.com

Any other domain, including variations like @bankofamerica-alerts.com or @bofasecure.net, is fraudulent. Display names can be faked easily; the underlying domain cannot.

Inspect the Link Before You Click

On desktop, hover your mouse over any button or link to see the destination URL in your browser's status bar. On mobile, long-press the link to preview it. The URL must point to bankofamerica.com, not any subdomain or variation of it.

Red flag URLs to watch for:

  • bankofamerica-login.com (hyphen is the giveaway)
  • bkofamerica.com (missing a letter)
  • bankofamerica.com.securelogin.net (the real domain is after the .com, not before it)
  • Any domain that doesn't end in bankofamerica.com

Verify a Suspicious Website with ScamAdviser

If you receive a link you're unsure about, don't click it. Copy the domain and check it on ScamAdviser before opening it. ScamAdviser analyzes hundreds of signals including domain age, hosting location, blacklist status, and traffic patterns to generate a trust score. A newly registered domain with a BofA-style name is an immediate red flag.

Recognize What Bank of America Will Never Ask For

Bank of America will never ask you to share your password, PIN, one-time verification code, or to transfer money to a "safe account" via email, text, or phone.

This is the single most important rule. If any message or caller requests any of the following, it is a scam regardless of how official it looks:

  • Your full Social Security number via email or textYour online banking password or PIN
  • A one-time passcode sent to your phone
  • Gift card purchases to resolve fraud
  • A wire transfer to a "protected" account

Look for Urgency and Pressure

Legitimate banks do not threaten to close your account within 24 hours or demand you act before the end of a call. Urgency is a manipulation tactic designed to short-circuit your judgment. If a message or caller is pressuring you to act immediately, that pressure itself is the red flag.

What to Do If You've Already Been Targeted

Speed matters here. If you clicked a link, entered your credentials, or spoke to someone you now believe was a scammer, take these steps immediately, in order.

If You Clicked a Phishing Link or Entered Your Credentials

  1. Change your BofA password immediately. Go directly to bankofamerica.com by typing it into your browser (do not use any link from the suspicious email). Change your online banking password.
  2. Call Bank of America's fraud hotline: 800-432-1000. Report the incident so the bank can flag your account, monitor for unauthorized transactions, and issue new card numbers if needed.
  3. Enable two-factor authentication on your BofA account if it isn't already active.
  4. Review your recent transactions for any activity you don't recognize. Report fraudulent charges immediately through the app or by phone.
  5. Change passwords on any other accounts where you used the same credentials. A banking phishing attack is often just the starting point.
  6. Forward the phishing email to abuse@bankofamerica.com.

If You Downloaded the "Account Guard" Software (August 2026 Campaign)

If you were targeted by the ScreenConnect malware campaign described above, the attacker may have had live access to your computer. Act immediately:

  1. Disconnect your device from the internet.
  2. Run a full malware scan using a reputable security tool.
  3. Contact Bank of America fraud at 800-432-1000 and explain that remote access software may have been installed.
  4. Change all passwords from a different, uncompromised device.
  5. Consider having a professional remove the ScreenConnect software, as the attackers deliberately made it difficult to uninstall.

If You Shared Your Social Security Number

A shared SSN opens the door to identity theft beyond your bank account. Take two additional steps:

  • Place a credit freeze with all three major bureaus (Equifax, Experian, and TransUnion). A freeze prevents anyone from opening new credit accounts in your name.
  • File a report with the FTC at ReportFraud.ftc.gov. This creates an official record and generates a personalized recovery plan.

Report the Scam

Reporting helps protect other Bank of America customers. Use these channels:

  • Where to Report:Phishing email abuse:@bankofamerica.com
  • What to Report:Suspicious text (smishing)
    Forward to 7726 (SPAM)
  • Any fraud:Report it at Fraud.ftc.gov
  • Phishing URL: Submit it to Google Safe Browsing

How to Protect Your Account Going Forward

Reactive steps matter, but prevention is cheaper. These habits eliminate the most common entry points for BofA scammers.

Never Click Links in Financial Messages

Make it a rule: when you receive any message claiming to be from Bank of America, do not click the link. Instead, open a new browser tab, type bankofamerica.com, and navigate to your account from there. If the alert was real, it will be visible in your account dashboard.

Use the Official BofA App

The Bank of America mobile app is the safest way to check your account status. It connects directly to the bank's servers and cannot be spoofed the way a website can. If you receive an alert by text or email, verify it in the app before taking any action.

Protect Your Credentials

  • Use a password manager. Password managers autofill credentials only on the correct domain. If you're on a fake BofA site, the manager won't autofill, which is a built-in warning signal.
  • Enable two-factor authentication. Even if a scammer captures your password, they cannot access your account without the second factor.
    Never share a one-time code. If someone calls asking for the code that was just texted to you, hang up. That is always a scam.
  • Verify Before You Act: The three-step rule from Bank of America's own security guidance is worth memorizing:
  1. Stop. Urgency is a manipulation tactic, not a bank policy.
  2. Verify. Call Bank of America using the number printed on the back of your debit card, never a number from the message.
  3. Protect. Report anything suspicious before it becomes a loss.

Stay Alert to Evolving Tactics

The August 2026 ScreenConnect campaign is a reminder that scammers are getting more sophisticated. What used to be a simple fake login page now involves multi-stage malware delivery, operating system-specific infection chains, and software designed to be difficult to remove. The best defense is a consistent habit of verification, not a one-time security check.

Quick reference: Bank of America's official contact details

  • Fraud hotline: 800-432-1000
  • Official website: bankofamerica.com
  • Report phishing emails to: abuse@bankofamerica.com
  • Report suspicious texts: forward to 7726

Frequently Asked Questions

Is Bank of America being hacked right now?

Bank of America itself is not being hacked. What is happening is that scammers are impersonating the bank through phishing emails, fake websites, and fraudulent text messages. The bank's own systems are secure; the attacks target customers directly.

What do Bank of America scam emails look like?

They are designed to look identical to real BofA emails, using the same logo, colors, and formatting. The giveaway is always the sender's email address, which will not end in @bankofamerica.com or @ealerts.bankofamerica.com, and the link destination, which will point to a domain other than bankofamerica.com.

Will Bank of America refund money lost to a scam?

It depends on the circumstances. If you were deceived into authorizing a transfer, recovery is often difficult. If unauthorized transactions occurred without your involvement, the bank's fraud protection may cover the loss. Call 800-432-1000 immediately to report the fraud and begin an investigation.

How do I report a Bank of America scam?

Forward phishing emails to abuse@bankofamerica.com. Forward suspicious texts to 7726. Report any financial fraud to the FTC at ReportFraud.ftc.gov. You can also file a report with your local FBI field office via IC3.gov if the loss was significant.

 How can I check if a Bank of America website is real?The only legitimate domain is bankofamerica.com. Any variation is suspect. For any link you're uncertain about, copy the domain and run it through ScamAdviser for a free trust score before clicking.

Report a Scam!
Have you fallen for a hoax, bought a fake product? Report the site and warn others!
About Us Check Yourself Contact Disclaimer
Developed By: scamadviser-logo