forumNew topic

someone claiming to be from my bank asked for account info, did i make the right call or is the bank actually checking

YYiğit B***Expert
Job title
Quality control inspector
Sector
Textile
Organization type
40-person manufacturing company
Joined
May 2023
Message
70
#1

got a call today from someone claiming to be customer service from my bank. said there was suspicious activity on my account and asked for my password. immediately thought of credit card fraud, hung up and looked into it.

then i called the bank to ask what happened — the person wasn't anyone there. relieved but really shaken. other people might be facing these attacks too.

can a bank really ask for a password? shouldn't they never ask? i want to warn others too.

OOsman K***Member
Job title
Logistics planning
Sector
Energy
Organization type
a company within a holding
Joined
Sep 2025
Message
125
Most Helpful#2

banks never ask for passwords, PINs, or full credit card numbers over the phone. what you experienced is a typical social engineering attack.

you made the right call — by ending the call and calling the bank directly. protocol: never engage with an incoming call, find the caller yourself.

to warn others: forward the message 'Banks never ask for passwords' to your family and friends. that's the important warning.

SSadıkNew member
Job title
Tradesman
Joined
Dec 2024
Message
24

Doki · KVKK compliance consulting · 2026

#3

bro i went through the same thing... was so scared. then the bank called from customer support said it was a scam then edit: actually got really angry

RRabia B***Expert
Job title
Sales Manager
Sector
Education
Organization type
family business
Joined
May 2025
Message
83
#4

rules are simple: 1. NEVER give password, PIN, credit card over phone 2. if bank calls, hang up 3. call the bank from your phone check 4. if suspicious activity go reset and check 5. report to police if needed

İİlknur G***MemberCommunity member
Joined
May 2025
Message
172
#5

i remind myself banks never call. never ever ask. but still every call speeds up my heart...

ÖÖzge T***Member
Job title
Quality control inspector
Sector
Jewelry
Organization type
workshop
Joined
Feb 2023
Message
193
#6

social engineering method: Authority (bank), Urgency (suspicious activity), Fear (account will be closed). you recognized this.

YYavuz S***MemberCommunity member
Joined
Jun 2025
Message
3
#7

how much damage was done to the account? or no damage at all? should i be paranoid?

AAslı K***MemberCommunity member
Joined
Aug 2022
Message
60
#8

great incident! really great reflex. people fall for these scams so easily. you acted smartly

HHavva K***Member
Job title
Front office accounting
Sector
Cleaning services
Organization type
boutique agency
Joined
May 2024
Message
145
#9

Thanks, this was very helpful. Forgotten test environments are more often the entry point than live systems.

Taking measures without an inventory leaves doors you haven't seen open. Of course, it varies if your situation is different.

ÖÖzge Ç***Member
Job title
Administrative manager
Sector
Accounting & advisory
Organization type
120-person company
Joined
Nov 2024
Message
2
#10

Let me share my experience. The harder it is to reverse a decision, the slower you should make it.

An automated scan report is not the same as a penetration test. Hope this helps.

HHakan Ş***New memberCommunity member
Joined
Aug 2026
Message
2
#11

Let me summarize the topic, since several different answers were given. If 2FA is on, a stolen password alone is useless.

AAhmet N***Expert
Job title
Store associate
Sector
Construction
Organization type
a company within a holding
Joined
Jul 2022
Message
153
#12

I've been down this road, let me tell you. Most time waste accumulates in tasks waiting for approval.

An automated scan report is not the same as a penetration test. If you post the result here, it will help others too.

IIrmak K***Member
Job title
Warehouse Manager
Sector
Tourism
Organization type
sole proprietorship
Joined
Jan 2022
Message
42
#13

I felt relieved reading this answer, so it's not just me. If 2FA is on, a stolen password alone is useless.

The answer varies greatly by industry; there is no one-size-fits-all rule. That's all, sorry if I went on too long.

KKadir S***Member
Job title
Secretary
Sector
Textile
Organization type
sole proprietorship
Joined
Oct 2023
Message
308
#14

There's a trap here, let me mention it. Taking notes for two weeks yields better results than a six-month estimate.

If you don't write this down from the start, it leads to arguments later. If you post the result here, it will help others too.

DDefneMember
Job title
SOC Analyst
Organization type
a company within a holding
Joined
Feb 2024
Message
146
#15

Three different views emerged, they all complement each other. Security isn't absolute; it's about making attacks not worth the effort.

Correct me if I'm wrong.

ZZafer A***Member
Job title
Secretary
Sector
Jewelry
Organization type
20-person company
Joined
Nov 2024
Message
142
#16

Great work. Everything goes well for the first three months; problems arise in the fourth.

OOrhan G***Member
Job title
Courier coordinator
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
173
#17

let me summarize what's been said so far but when we decide without measuring we always end up in the same place.

of course, it varies if your situation is different.

SSelin V***Veteran
Job title
Operations manager
Sector
Law
Organization type
a company within a holding
Joined
Feb 2022
Message
21

Doki · Phishing awareness training · 2023

#18

I feel the same way. Your time to detect an issue directly determines its cost.

DDilara B***Member
Job title
Operations manager
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Jun 2024
Message
1

Doki · Interface design · 2024

#19

This is exactly what we experienced. An automated scan report is not the same as a penetration test.

KKazımNew member
Job title
Plastic manufacturing
Joined
Sep 2024
Message
36
#20

Good call starting this thread.

Reply