Bank of America 844-844-0585 Text Scam: Do Not Call

A text message that looks like a Bank of America security alert says a payment, transfer or new device was detected. It may appear to come from or be associated with the short code 22498, then instruct you to call 844-844-0585 immediately.

The warning is meant to produce one reaction: panic. If you call the supplied number, you do not reach a trusted Bank of America channel. You reach scammers prepared to impersonate the bank’s fraud department and guide you through a convincing account takeover.

The Bank of America alert directing recipients to 844-844-0585 is a phishing and bank-impersonation scam. Do not call that number, reply to the text or provide a password, card number, PIN or verification code. Bank of America is a legitimate financial institution being impersonated in this campaign.

Illustration warning about bank impersonation texts, stolen logins and payment fraud
A fake fraud alert creates urgency, then sends the recipient to a scam call center rather than the bank.

844-844-0585 Bank of America Text Scam Overview

The scam uses a familiar bank-alert format: a short message, an alarming transaction and a telephone number presented as the fastest way to stop the charge. Some versions mention a card purchase, Zelle transfer, wire, account lock or login from an unfamiliar device.

The message may use Bank of America branding, the last digits of a card obtained from leaked data, or a short code that makes the text look automated. None of those details proves the callback number is genuine. The instruction to call 844-844-0585 is the trap.

Once the victim calls, a fake representative may ask for credentials and one-time codes, persuade the victim to transfer money to a so-called safe account, or take remote control of a phone. The conversation is carefully structured to make every dangerous action sound like part of the bank’s security process.

How the 844-844-0585 Text Scam Works

Step 1: A fake fraud alert arrives

The text claims that Bank of America detected suspicious activity. A typical script mentions a transaction you do not recognize and asks whether you authorized it.

The amount and merchant are selected to feel plausible. If the transaction is too small, you might ignore it; if it is unrealistically large, you might doubt it. Scammers often choose a believable amount that is high enough to make you react quickly.

Step 2: The message creates a security emergency

The text warns that your card, online banking or funds are at risk. It may say your account will be restricted unless you respond immediately or that a transfer is still pending and can only be stopped by phone.

This urgency is psychological pressure. It keeps you focused on the invented transaction instead of checking whether 844-844-0585 appears in the official Bank of America app, website or on the back of your card.

Step 3: You are directed to call 844-844-0585

The callback number is the most important warning sign. Scammers want you to initiate the call because people naturally trust a number they dial themselves, even when that number came from an unverified message.

The line may answer with professional hold music, a recorded menu and a greeting that names Bank of America. Those features are inexpensive to reproduce and do not establish that the call center belongs to the bank.

Step 4: A fake fraud agent builds credibility

The person who answers may already know your name, phone number, email address or partial card information. That data can come from public records, marketing databases or previous breaches.

The fake agent may read back the transaction from the text, give you a case number and say the call is being recorded. These details create the appearance of an internal bank process while the scammer studies your reactions and asks increasingly sensitive questions.

Step 5: The scammer tries to pass account security

You may be asked to confirm your Online ID, password, full card number, expiration date, CVV, PIN or Social Security number. The caller might disguise these requests as identity verification.

If the scammer attempts to log in or reset your password, the real bank may send a one-time authorization code to your phone. The caller will then ask you to read it aloud. That code is not a case number or cancellation code; it is a key that can let the criminal into your account.

Step 6: Money is moved under the label of protection

In another version, the caller says the account is compromised and your balance must be transferred to a secure account. You may be instructed to send money through Zelle, make a wire transfer, withdraw cash or move funds between accounts.

A real bank will not tell you to send money to yourself or another person to protect it. Once you authorize a transfer, recovering the funds can be difficult, which is why the scammer stays on the phone until the transaction is complete.

Step 7: The scammer hides the takeover

After gaining access, the criminal may change contact details, add a recipient, lock you out or move money rapidly. The fake agent may tell you not to open your banking app because it could “interrupt the investigation.”

That instruction buys time. By the time you contact the real bank, the funds may have been routed through other accounts or converted into a form that is difficult to reverse.

What the Fake Text May Say

The exact wording changes, but most versions use one of these claims:

  • A debit or credit card purchase was declined or approved.
  • A Zelle payment or wire transfer is waiting for confirmation.
  • A new device signed in to online banking.
  • Your account has been temporarily locked.
  • Your card was added to a mobile wallet.
  • You must call 844-844-0585 to cancel an unauthorized transaction.

Spelling and grammar are not reliable tests. Modern scam texts can be polished, correctly branded and personalized. Judge the message by what it asks you to do and verify the alert through a channel you independently trust.

Why a Short Code or Familiar Text Thread Is Not Proof

People often assume that a short code is automatically safe. Banks do use short codes for legitimate alerts, but the sender display alone should never override the content of a suspicious message or validate an unfamiliar callback number.

Messages can be forwarded, altered, delivered in confusing conversation threads or combined with social-engineering calls. More importantly, a criminal can simply claim that an unrelated short code belongs to the bank. The safe test is to ignore the supplied contact details and check your account independently.

Bank of America publishes fraud-reporting instructions through its Security Center. Its official guidance tells customers who responded to a suspicious message to call the number on their card or bank statement. The bank also accepts suspicious emails and texts at abuse@bofa.com.

Red Flags That Confirm the Message Is Unsafe

  • The text creates an emergency and insists that you call 844-844-0585.
  • The caller asks for a password, PIN, CVV or complete card number.
  • You are asked to read a one-time authorization or verification code.
  • The “fraud agent” tells you to move money to keep it safe.
  • You are told to send a Zelle payment to yourself or another account.
  • The caller asks you to install an app or share your phone screen.
  • You are warned not to contact the bank through its official app.
  • The representative becomes threatening or tries to keep you on the line.

How to Verify a Bank of America Alert Safely

  1. Do not call 844-844-0585. Do not click links or reply to the message.
  2. Open the official app yourself. Check recent transactions, alerts and the secure Message Center.
  3. Use a trusted number. Call the number printed on the back of your card or on a recent bank statement.
  4. Type the bank’s address manually. Visit BankofAmerica.com rather than following a text link.
  5. Ask about the exact alert. The real bank can verify whether it sent a message and whether a transaction exists.

If there is no matching transaction in the official app, that is strong evidence that the text was bait. Even if a real suspicious transaction exists, contact the bank independently; criminals sometimes time their calls around genuine account activity.

What to Do If You Called 844-844-0585

Hanging up before sharing information is usually enough. Block the number, preserve a screenshot and forward the suspicious text to your carrier at 7726, which spells SPAM.

If you disclosed information or followed instructions, take these steps immediately:

  1. Call Bank of America using the number on your card or statement and say that you may have responded to an impersonation scam.
  2. Ask the bank to secure the account, review recent activity and stop any pending transfers if possible.
  3. Change your online banking password from a clean device. Also change your email password if it is reused or may have been exposed.
  4. Remove unknown devices, recipients and contact details from the account.
  5. Lock affected cards and request replacements when advised by the bank.
  6. If you shared a Social Security number, place a credit freeze with all three major credit bureaus and use IdentityTheft.gov.
  7. Report the scam to the Federal Trade Commission.

What If You Shared a Verification Code?

Treat the account as actively compromised. A verification code is designed to prove that the person logging in controls your phone. If you give that code to a caller, the scammer may use it immediately to enter or modify your account.

Call the real bank without delay. Do not wait to see whether money disappears. Ask the bank to invalidate online sessions, review profile changes and check for newly added transfer recipients.

Frequently Asked Questions

Is 844-844-0585 a Bank of America number?

Do not treat 844-844-0585 as a trusted Bank of America contact number. It is used in the scam message described here. Verify every alert through the official app or by calling the number printed on your card or statement.

Is a text from 22498 automatically legitimate?

No sender label, short code or conversation thread should be treated as sufficient proof by itself. If a message directs you to 844-844-0585 or requests credentials, codes or money, do not follow those instructions. Contact the bank independently.

Will Bank of America ask for my one-time code?

Do not give a one-time authorization code to an unexpected caller. Bank of America warns that scammers may request account verification codes, and its Zelle guidance says the bank will not contact you by phone or text to ask for a security code.

Can the bank recover money sent to a scammer?

Recovery depends on the payment method, timing and circumstances. Contact the bank immediately. A pending card transaction or transfer may be easier to stop than money that has already been received and moved.

Final Verdict

The message directing Bank of America customers to call 844-844-0585 is a scam. Its purpose is to move the conversation away from the real bank and into a controlled call center where criminals can steal credentials, verification codes and money.

Do not call the supplied number. Open the official Bank of America app or use the number on the back of your card. A real security check will survive independent verification; a scam depends on keeping you inside the contact path chosen by the scammer.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Universal Tax Council Scam: How the Tax Relief Pitch Works

Next

Tax Consultants of America Voicemail Scam: How It Works