RBFCU Impersonation Scam: How Spoofed Bank Calls Steal Your Life Savings

The caller ID says RBFCU. The person on the line knows how a fraud department should sound and says your savings are being drained by an employee inside the credit union.

Then comes the solution: withdraw cash, move funds, share a code, or hand money to a courier before the criminals can take it. The number looks right, but the story is designed to steal the money it claims to protect.

Reconstructed call log showing a spoofed RBFCU phone number marked as unverified

Overview

Scammers can make RBFCU’s number appear on caller ID

Caller ID spoofing lets an incoming call display a trusted organization or phone number even when the call originated elsewhere. Seeing 210-945-3300 or 1-800-580-3300 does not prove that RBFCU placed the call.

RBFCU has publicly warned that impersonators are spoofing both numbers. The credit union advises members to hang up and dial an official number themselves when an unexpected caller requests action.

The caller creates a crisis around the member’s money

The impersonator may claim that an account is compromised, a transfer is pending, or corrupt employees are involved. The story makes normal verification seem dangerous and immediate obedience feel protective.

A polished caller can know a member’s name, address, or partial account details from breached and commercially available data. Those facts are used to establish trust before sensitive information is requested.

The “safe” action sends control to the scammer

Victims may be told to reveal a password or one-time code, transfer savings, withdraw cash, buy cryptocurrency, or give money to a rideshare or courier pickup. None of these actions protects an account.

RBFCU says members should never share sign-in information, security answers, recovery codes, or one-time passcodes, even with someone claiming to be an employee.

  • The incoming call displays a real RBFCU phone number.
  • The caller claims the account or funds face immediate danger.
  • A fake case number and fraud-department identity build authority.
  • The member is told not to visit a branch or speak with staff.
  • Codes, credentials, transfers, cash, or a courier handoff are requested.
  • The criminal keeps the victim on the line while money is moved.

Why Spoofed Bank Calls Feel So Real

People have been taught to watch for strange phone numbers. Spoofing turns that defense around by placing the expected number directly on the screen.

The caller may transfer the victim between supposed departments, play hold music, or provide an employee ID. Those theatrical details create the impression of a staffed institution without providing independent verification.

Information from a data breach can make the conversation personal. The scammer might know the member’s previous address, last four card digits, or recent merchant, then ask the victim to “confirm” everything else.

A false insider-investigation story explains why ordinary employees cannot be trusted. The caller says branch staff are part of the fraud or that discussing the case will alert a suspect.

That isolation is essential to the scam. A teller, family member, or separately contacted RBFCU representative could interrupt the scripted emergency before the money leaves the victim’s control.

Artificially generated or altered voices can make calls sound polished, but advanced technology is not required. Pressure, authority, and a plausible caller ID are often enough.

How the RBFCU Impersonation Scam Works

Step 1: The criminal profiles a potential target

Phone numbers, names, addresses, and financial affiliations can appear in breach data, phishing lists, public records, and stolen mail. A scammer may also call broadly and learn who banks with RBFCU from the victim’s reaction.

Older adults and people with substantial savings can be targeted repeatedly. Once a person answers and engages, the number may be shared with other fraud groups.

Step 2: Caller ID is manipulated to display RBFCU

The call arrives showing 210-945-3300, 1-800-580-3300, or an RBFCU label. Spoofing changes what the recipient sees; it does not route the call through the credit union’s verified staff.

A text or voicemail may arrive first, saying that a transaction needs immediate review. Calling the number in that message returns the victim to the same criminal operation.

Step 3: A believable fraud case is invented

The impersonator describes unauthorized transfers, a compromised debit card, or a dishonest employee. They may ask whether the victim recognizes a transaction, knowing that “no” will deepen concern.

The caller frames every next step as fraud prevention. Requests that would otherwise look dangerous are recast as necessary cooperation with an official investigation.

Reconstructed fraudulent bank page directing a $12,500 cash withdrawal and courier pickup

Step 4: Credentials or account approvals are captured

The victim may be asked for a username, password, card number, PIN, or one-time code. A real code can arrive because the criminal is simultaneously trying to sign in, reset access, or authorize a transfer.

The caller tells the victim to read the code as identity confirmation. The notification’s actual wording may say that the digits approve a login or payment.

Step 5: Money is moved to a supposed safe location

One route uses a wire, payment app, or cryptocurrency transfer to an account controlled by the criminal. Another tells the victim to withdraw thousands in cash and keep the reason secret from branch employees.

RBFCU has described impersonation scams involving rideshare pickups or courier-style exchanges. A stranger collects the cash, and the caller claims it will be deposited into a protected account.

Step 6: The victim is delayed while funds disappear

After receiving the money, the scammer may promise a replacement balance within hours or schedule a follow-up security call. The delay reduces the chance of a rapid fraud report.

If the victim questions the process, another impersonator may join as a supervisor, police officer, or federal investigator. Each character supports the same false case.

Common RBFCU Impersonation Stories

The compromised-account version says online banking is under attack. The caller requests a one-time code to block access, but uses it to complete an unauthorized sign-in.

A refund version claims that the caller must enter the account to reverse a fraudulent charge. The victim is asked for credentials under the guise of returning money.

The insider-fraud version alleges that an RBFCU employee changed account details. It tells the member not to visit a branch because local staff are supposedly under investigation.

A safe-account story orders the victim to transfer the entire balance to a temporary account. Banks and credit unions do not protect money by moving it to a stranger’s account.

The cash-courier version uses physical withdrawal. The victim is instructed to package cash for pickup by a driver who may know only that a parcel needs transport.

Another variation claims that law enforcement found the member’s identity connected to drug trafficking or money laundering. Payment or cooperation is demanded to avoid arrest.

Text messages can request a click to deny a charge. The page captures online-banking credentials, then the follow-up call uses the stolen information to sound authoritative.

Some criminals ask the victim to install remote-access software so they can “secure the device.” Remote control can expose accounts, messages, and verification prompts.

The script may change, but legitimate fraud handling does not require secrecy, irreversible payments, or surrendering authentication secrets to an incoming caller.

How to Stop a Suspicious Bank Call

End the call. Do not let the caller stay connected while you open the app, drive to a branch, or contact someone else.

Wait briefly if needed, then dial the number printed on the back of the card, shown on a statement, or published on rbfcu.org. Manually initiating the call breaks the scammer’s control of the connection.

Tell the genuine representative exactly what was requested. Mention any codes read aloud, links opened, software installed, transfers initiated, or cash withdrawn.

Review pending transfers and account alerts inside official online banking. Deny any sign-in prompt you did not initiate and never approve a transfer simply to cancel it.

If a caller says police or bank employees must not know, contact those organizations independently. Secrecy is not a valid authentication factor.

Discuss high-pressure calls with a trusted family member before moving funds. A five-minute pause can defeat a script that depends on isolation and urgency.

Do not assume that an incoming call becomes safe because the person accurately describes a recent transaction. Criminals may have obtained merchant information through phishing, a compromised email account, or access to a card-notification service.

Turn on transaction alerts through the official banking app, but read them independently. A scammer may trigger a real alert and then misrepresent what approving or denying it will do.

Consider setting lower transfer limits and requiring additional verification for large movements. These controls create time for review when a caller tries to rush an unusual transaction.

Never let an unknown caller coach your explanation to a teller. Instructions to describe a withdrawal as a home purchase, family expense, or vehicle payment are meant to bypass staff trained to recognize exploitation.

A genuine representative will tolerate a disconnected call and independent verification. Anger, threats, or claims that hanging up will freeze the account are signs that the caller needs to preserve control.

Caregivers can create a family rule that large withdrawals or new payees require a second conversation. The rule should apply regardless of who supposedly called or how official the number appears.

Company, Address, and Fulfillment Checks

Verify the caller by placing a new call

Do not use redial or a number supplied by the caller. Obtain contact details from the card, statement, official app, or independently typed RBFCU website.

Caller ID is not verification. The same number can appear on a fraudulent incoming call and be safe only when you dial it through a known channel.

Test the request against RBFCU’s published rules

RBFCU says it will not ask members to share passwords, security answers, multi-factor codes, recovery codes, or one-time passcodes with employees.

A demand for those secrets conflicts with the credit union’s own fraud guidance, even if the speaker knows personal facts.

Reject cash and “safe account” instructions

No legitimate account-protection process requires a member to hand cash to a courier, rideshare driver, or unknown representative. Money moved this way is difficult to recover.

Likewise, a transfer to a new account does not become safe because the caller describes it as protected or federally monitored.

Use branch and transaction records

Visit an official branch if the situation remains unclear. Bring notes about the caller, the displayed number, requested action, and any transaction reference.

Ask staff to confirm the case through internal records. A fabricated investigation will not appear merely because the impersonator supplied a convincing case number.

What to Do if You Have Fallen Victim to This Scam

  1. Call RBFCU immediately. Use the number on your card or the official website, report the impersonation, and ask staff to secure accounts and stop pending transactions.
  2. Contact law enforcement. If cash is awaiting pickup, a courier is en route, or a handoff just occurred, call local police and provide the location and description.
  3. Change online-banking credentials. Use a trusted device, choose a unique password, replace compromised security answers, and review authorized devices.
  4. Revoke exposed codes and sessions. Tell RBFCU which one-time codes or approvals were shared so staff can identify the action they authorized.
  5. Remove remote access. Disconnect a controlled device from the internet, uninstall the tool, and run a reputable scan such as Malwarebytes before resuming financial activity.
  6. Block malicious links. AdGuard can reduce exposure to known phishing domains and deceptive ads, but it cannot reverse cash handoffs or authorized transfers.
  7. Contact every payment channel. Notify banks, wire services, cryptocurrency exchanges, gift-card issuers, or payment apps and request an immediate fraud review.
  8. Preserve evidence. Save call logs, voicemails, texts, URLs, receipts, withdrawal records, courier details, and the exact instructions given.
  9. File external reports. Report the incident to the FTC and IC3, and watch for recovery scammers who promise guaranteed reimbursement for an upfront fee.

When an older or vulnerable adult is involved, contact trusted family and consider reporting suspected financial exploitation to local adult protective services.

Frequently Asked Questions

Can scammers spoof RBFCU’s real phone number?

Yes. RBFCU specifically warns that impersonators have displayed 210-945-3300 and 1-800-580-3300 on caller ID.

Will RBFCU ask for my one-time passcode?

RBFCU says not to share one-time passcodes, multi-factor codes, recovery codes, passwords, or security answers with anyone, including employees.

What if the caller knows my account details?

Knowledge of personal facts can come from breaches, stolen mail, phishing, or earlier fraud. End the call and verify through a contact route you selected.

Does moving money to a safe account protect it?

No. “Safe account” transfers are a common impersonation tactic. Legitimate institutions do not protect savings by sending them to a stranger’s account.

Would a bank ever send a courier for cash?

Not as a fraud-protection procedure. A request to withdraw cash for a courier or rideshare pickup is a severe warning sign.

Can money from the RBFCU scam be recovered?

Recovery is not guaranteed, but immediate reports to RBFCU, the payment service, and law enforcement give the best chance of stopping funds.

The Bottom Line

The RBFCU impersonation scam uses a real-looking number to make dangerous instructions sound official. Its goal is to move money out of protected accounts while the victim believes a fraud case is being solved.

Hang up, place a new call using independently obtained contact information, and keep every password and code private. No legitimate investigation requires a secret cash pickup or transfer to a so-called safe location.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Greetings Island Invitation Scam: How Fake RSVPs Hijack Email Accounts

Next

VZN Free Message Scam: How the Paid Bill Gift Text Steals Private Data