{"id":403596,"date":"2026-08-19T13:21:02","date_gmt":"2026-08-19T13:21:02","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=403596"},"modified":"2026-08-19T13:21:02","modified_gmt":"2026-08-19T13:21:02","slug":"citibank-scam-calls-exposed-fake-fraud-desk","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/citibank-scam-calls-exposed-fake-fraud-desk\/","title":{"rendered":"Citibank Scam Calls EXPOSED: Fake Fraud Desk Wants the Code"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The phone says Citi. Sometimes the screen says Fraud Department. Sometimes it shows a number that looks like the one on the back of a card. The voice is not shouting. It says there is a charge you did not make, or a login from another city, or a card that is about to be closed. Then the ask arrives. Read the text that just landed. Say the code out loud. Move the money to a safe account while they stay on the line.<\/p><div id=\"mwtad466575172\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">That is the trap. Citi is a real bank. The costume is not. A fake fraud desk wants the SMS code, or a transfer, or a remote session on your phone. The rest of the call is theater so you will not hang up.<\/p>\n\n\n\n<div id=\"mwtad687519204\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p class=\"wp-block-paragraph\">Hang up. Do not stay on the line to be polite. Do not call back the number the voice just recited. Open the official Citi app yourself, or type the official Citi site yourself, or use the number printed on the card in your wallet.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"800\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-fraud-early-warning.png\" alt=\"Official Citi Card Benefits page titled Fraud Early Warning saying Citi will never ask for passwords or Social Security numbers through text or email\" class=\"wp-image-403593\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-fraud-early-warning.png 1280w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-fraud-early-warning-300x188.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-fraud-early-warning-1024x640.png 1024w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><figcaption class=\"wp-element-caption\">Citi&#8217;s official Fraud Early Warning page says the bank may contact you about suspicious activity, and that it will not ask for passwords or Social Security numbers through text or email.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad336731304\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The trap is a live call that borrows Citi&#8217;s name so you will hand over a one-time code or move money. The caller may say they are from the fraud desk, the security team, or CitiCards. They may already know your name. They may already know the last four digits of a card. None of that proves the person works for Citi.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi is real. Citibank accounts and Citi cards are real products. People bank there every day. This article is not a warning that Citi itself is a fraud. It is a warning about people who dress up as Citi on the phone.<\/p>\n\n\n\n<div id=\"mwtad2311310132\" class=\"gas_fallback-ad_309686-ad_309691-placement_400597\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\">Citi&#8217;s own Card Benefits pages say the bank may contact you by text, email, phone, or mail if something looks wrong. That sentence matters, because a real alert can exist. The costume uses that fact. A real bank sometimes calls. A fake desk always needs something from you before you can check.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the official <a href=\"https:\/\/www.cardbenefits.citi.com\/en\/Products\/Fraud-Early-Warning\" target=\"_blank\" rel=\"noopener\">Fraud Early Warning page<\/a>, Citi says it will never ask you to provide confidential information like passwords or Social Security numbers through text or email. The same page tells cardmembers how to recognize a Citi Fraud Early Warning text. Those messages use the short code 95686. The emails it names come from citicards@info3.citibank.com. A voice that wants the password, the PIN, or the code that just arrived is not following that page.<\/p>\n\n\n\n<div id=\"mwtad3045943442\" class=\"mwtadp3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"5910219726\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p class=\"wp-block-paragraph\">On <a href=\"https:\/\/www.citibank.com\/tts\/solutions\/commercial-cards\/fraud-protection\/\" target=\"_blank\" rel=\"noopener\">Citi&#8217;s commercial-card fraud page<\/a>, the bank is even more specific about one-time passcodes. It says it will never contact you requesting that you disclose your OTP. It also says it will never send you an OTP unexpectedly and then call you to read it back. If a stranger wants the digits on your lock screen, the call is over.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Federal Trade Commission has been writing the same rule for bank impersonation. In a <a href=\"https:\/\/consumer.ftc.gov\/consumer-alerts\/2024\/06\/got-call-about-fraud-activity-your-bank-account-it-could-be-scammer\" target=\"_blank\" rel=\"noopener\">July 2024 consumer alert<\/a>, the FTC said a caller who claims to have spotted fraud, then asks you to share a verification code or to move money to protect it, is always running a scam. In a <a href=\"https:\/\/consumer.ftc.gov\/consumer-alerts\/2024\/03\/whats-verification-code-why-would-someone-ask-me-it\" target=\"_blank\" rel=\"noopener\">March 2024 alert<\/a>, the FTC said anyone who asks you for your account verification code is a scammer. The code is a second key. If you read it out, they can become you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi&#8217;s own fraud-prevention leadership has published the same habit. In a <a href=\"https:\/\/www.citigroup.com\/global\/news\/perspectives\/2026\/two-sides-one-shield-joint-effort-fraud-prevention\" target=\"_blank\" rel=\"noopener\">March 2026 Citigroup piece<\/a>, Jeff Crawford, Managing Director, Fraud Prevention, told readers not to take the incoming call. Hang up. Find the official number on the website or the back of the card. Call that number yourself. He also wrote that you should never verbally share your debit PIN or online passcode, even with someone claiming to be from your bank.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That same piece cited public FTC figures. Consumers in the United States reported more than $12.5 billion lost to fraud in 2024, a 25% jump from the year before. Those numbers are a reason to slow down, not a reason to stay on a scary call.<\/p><div id=\"mwtad3690495284\" class=\"mwtadp4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"5910219726\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This article is about the phone. It is not about a payout email, a compensation fund, or a message that claims Citi is sending you a share of a giant settlement. Those pitches exist. They are a different costume. The call you are getting wants something smaller and faster. A six-digit code. A Zelle. A wire. A screen-share.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The costume on caller ID<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Caller ID is a costume. Criminals can make the screen say Citi, Citibank, or Fraud Department. They can make it show a number that looks like a real bank line. The FTC has heard from people who said the incoming number matched a bank&#8217;s own fraud number. That is still not proof.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A callback number the caller recites is part of the same costume. There is no official &#8220;scam desk&#8221; number to publish here, because the number is the product. Once you dial it, you are back inside their room. Use the number printed on the physical card, or the number you find after you type the <a href=\"https:\/\/www.citi.com\" target=\"_blank\" rel=\"noopener\">official Citi site<\/a> yourself.<\/p>\n\n\n\n<div id=\"mwtad830568276\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p class=\"wp-block-paragraph\">Citi&#8217;s commercial-card fraud page describes vishing in plain language. A recording claims there is unusual activity and gives you a number to call. The advice is the same for any phone service. When you contact Citi, use a trusted number, like the one on the back of your card.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The code they want<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The SMS code is the prize. Banks send those codes so that only you can finish a login, add a payee, or approve a high-risk change. The FTC describes the password and the code as two keys. A scammer who already has one key needs you to hand over the other.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The story around the code is always helpful. We sent a text to verify it is you. Read the number so I can stop the charge. Confirm the code so I can reverse the purchase. Approve the prompt so I can lock the account. Each line is a request for the same thing. Access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi&#8217;s commercial-card page says OTPs are for actions you started, such as a login, a purchase you are making, or a high-risk change inside the bank&#8217;s own tools. It says Citi will not send a code out of nowhere and then call you to recite it. If you did not just try to sign in, and a voice wants the code anyway, you are not helping Citi. You are helping the caller.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The transfer they want<\/h3>\n\n\n\n<div id=\"mwtad3656612709\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p class=\"wp-block-paragraph\">The other prize is a transfer you make yourself. Move the money to a safe account. Buy a cashier&#8217;s check. Send it by Zelle. Wire it to a holding account. Buy gift cards so the fraud team can secure the funds. The FTC&#8217;s July 2024 alert is blunt about this. Someone who says you have to move your money to protect it is a scammer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That alert also explains why the transfer is so dangerous. Credit cards often have stronger dispute rights than a bank account you emptied yourself. If you send the money, you may not get it back. Citi&#8217;s Card Benefits pages describe <a href=\"https:\/\/www.cardbenefits.citi.com\/en\/Products\/0-Liability-on-Unauthorized-Charges\" target=\"_blank\" rel=\"noopener\">$0 liability for unauthorized charges<\/a> on eligible consumer credit cards. A payment you chose to send because a stranger told you to is a different problem. Time still matters. The bank still needs to hear from you. Do not assume the money will walk home on its own.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"800\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-credit-account-protection.png\" alt=\"Official Citi Card Benefits Credit and Account Protection page showing FICO Score and Citi Quick Lock\" class=\"wp-image-403595\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-credit-account-protection.png 1280w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-credit-account-protection-300x188.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-credit-account-protection-1024x640.png 1024w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><figcaption class=\"wp-element-caption\">Official Citi Card Benefits pages put locks and alerts inside the real app and site. A stranger on an incoming call is not that path.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">How a real Citi alert looks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A real Citi alert can exist. The Fraud Early Warning page says Citi often detects trouble before you notice it, then reaches out to confirm activity. It names a text short code and an email address. It tells you to keep your phone number and email current so the bank can reach you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What a real path does not require is a secret you speak into an unexpected call. Citi&#8217;s published Fraud Early Warning page says it will not ask for passwords or Social Security numbers through text or email. The commercial-card page says it will not ask you to disclose an OTP. The Citigroup fraud-prevention piece says you should not take the incoming call at all. You make the next call.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi also publishes self-serve tools that do not need a stranger on the line. The <a href=\"https:\/\/www.cardbenefits.citi.com\/Credit-And-Account-Protection\" target=\"_blank\" rel=\"noopener\">Credit and Account Protection<\/a> pages describe Citi Quick Lock inside the Citi Mobile app and Citi Online. Eligible cardmembers can lock a card so new purchases and cash advances stop, while recurring charges can still go through. That is a tool you open yourself. It is not a download a caller emails you.<\/p>\n\n\n\n<div id=\"mwtad23876297\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How The Scam Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. The phone already looks official<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The first second does most of the work. Your screen says Citi. The voice uses the words fraud desk the way a real employee would. There may be hold music. There may be a case number. There may be an employee ID. None of those props is a file you can take to a branch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some calls start as a recording. Press 1 if you do not recognize the charge. Press 2 to speak with an investigator. The keypad is not a door into Citi. It is a door into a call center that is waiting for you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you missed the call, a voicemail may ask you to ring a number. That is still their number. Citi&#8217;s own advice, and the FTC&#8217;s advice, is to ignore the callback they handed you and start from a number you already trust.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. They pick a story you cannot ignore<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The story has to feel more important than hanging up. A $2,400 charge at an electronics store. A wire leaving a checking account. A new card mailed to an address you do not know. A login from another state. A claim that someone tried to open a Citi account in your name even if you do not bank there.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You do not have to have a Citi account to get the call. The name is useful because millions of people recognize it. If you do have an account, the fear is sharper. If you do not, the fear becomes identity theft. Either way, the caller wants you talking before you look at a statement yourself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A dollar amount in the story is not evidence. A merchant name is not evidence. A city you visited last month is not evidence. Those details are cheap. The only expensive thing in the conversation is the code they want you to speak, or the transfer they want you to start.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. They prove they &#8220;know&#8221; you<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A good costume uses a few true details. Your name. A city. The last four of a card. A recent merchant. Those pieces leak from breaches, from merchant receipts, from older phishing, from a wallet photo posted years ago. Hearing them does not mean a Citi investigator opened your file this morning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The caller may ask you to confirm the rest. Full Social Security number. Online username. Date of birth. Mother&#8217;s maiden name. Card number and expiration. The CVV on the back. Each answer fills a gap they did not have. A real bank that needs to talk to you can wait while you hang up and call the printed number.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi&#8217;s commercial-card fraud page describes this as social engineering. Fraudsters impersonate Citi, law enforcement, or another institution, then ask for security details, card details, or verification codes. The page tells you to treat any request for an OTP with suspicion. That is the whole test. If they want the code, they are not the bank.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. The text arrives while you are still talking<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the moment the trap closes. The voice says a one-time code is on the way. Your phone lights up. The message may even mention Citi, a login, or a payment. The caller asks you to read it. They may say they cannot see the code, so you have to say it. They may say the system will not lock the card until you approve the prompt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What actually happened is simpler. Someone is already on the real login page, or already in a reset flow, or already adding a payee. The bank sent the code because that action started. The voice wants you to finish their action.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not read the code. Do not tap Approve on a push prompt you did not start. Do not stay on the line while you just check the text. Hang up first. Then look at the official app by opening it yourself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the text says Citi will never ask for the code, believe the text, not the voice. Many real one-time messages carry that warning for a reason. The person on the phone is hoping you will treat the warning as fine print.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. They want the money moved<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If the code does not work, or if you hesitate, the script often changes. The account is not safe where it is. You need a temporary holding account. You need to buy gift cards and read the numbers. You need to send the balance by Zelle or wire so the fraud team can protect it. The Citigroup fraud-prevention piece lists urgent payment demands, especially through irreversible methods like wire transfers, Zelle, or gift cards, as a red flag.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FTC&#8217;s language is shorter. Never move or transfer your money to protect it. Your money is fine where it is. A person who says otherwise is not from your bank.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They may offer to stay on the phone while you walk to a branch, an ATM, or a store. That walk is part of the script. It keeps you from calling the printed number. It also turns a frightened conversation into cash they can take the same hour.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you already sent something, keep reading. Speed still helps. Shame does not.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6. They want your screen<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some scripts skip the code and go straight to remote access. The caller says they need to see your online banking to reverse a charge. They ask you to install a helper app so the fraud team can walk you through the lock. They may name a tool that sounds like tech support. They may send a link. They may stay on the phone while you download it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi&#8217;s published security pages do not describe a process where an unexpected caller takes over your phone or computer. A person who wants your screen wants your session. Once they can see the page, they can add a payee, change an email, or approve their own transfer while you watch and think you are being helped.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you already installed something, disconnect that session. Use a different device to call Citi. Treat every password on that machine as shared until you change it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. They keep you on the line<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The call is designed so you never get a quiet minute. Do not hang up, they will say, or the charge will go through. Stay with me while you walk to the ATM. Stay with me while you open the app. Put me on speaker at the grocery store gift-card rack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That instruction is the tell. A real bank can survive a two-minute gap. A costume cannot. If you hang up and dial the printed number, their room goes dark. They will often call back immediately and sound angry that you left. Let it ring. Make your own call on a second phone if you have one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Jeff Crawford&#8217;s public advice from Citi is the same habit in one line. Do not take the call. Make the call. That is not a slogan for later. It is the move that ends the script.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8. They call back as someone else<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After a first scare, a second voice may appear. A supervisor. A claims officer. Someone who says they are with a government fraud task force. Someone who says they can get the money back if you pay a small recovery fee. People who already shared a code or a transfer are easier to call again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi does not need a second stranger to finish a real case. You already have the official path. Card, app, site, printed number. A new voice that wants another code, another transfer, or another remote session is the same trap in a new badge.<\/p>\n\n\n\n<div id=\"mwtad3212667166\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What To Do If You Already Shared the Code<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you read a code, approved a prompt, or sent money, you are not the first person to do it. The next hour matters more than the story you tell yourself about how obvious it should have been.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. End the call and start a new one<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Hang up. If they call back, do not answer. Use a different phone if the first one is still in a session they started. Do not use a number they gave you. Do not use a number that just appeared in a text.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open the Citi Mobile app yourself, or type the official Citi site yourself. If you have the physical card, turn it over. That printed number is the one you want.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi&#8217;s Card Benefits Fraud Early Warning page and its $0 liability page both publish 1-800-950-5114 as Citi Customer Service for cardmembers, with TTY through 711 or another relay service. The same pages list a collect number for people outside the United States: 605-335-2222. Products differ. Banking and cards are not always the same desk. If the number on your card or inside the signed-in app is different, use the one on the card or in the app.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Tell Citi what left your mouth<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Say the plain facts. You got a call that used Citi&#8217;s name. You shared a one-time code, a password, a card number, or a transfer. Ask them to review recent logins, payees, phone numbers, and email addresses on the account. Ask whether a card should be replaced. Ask whether online access should be reset.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you bank somewhere else as well, call that bank too. A code from one login can be a door into a password you reused.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi&#8217;s <a href=\"https:\/\/www.citi.com\/credit-cards\/understanding-credit-cards\/what-to-do-when-you-lose-your-credit-card\" target=\"_blank\" rel=\"noopener\">lost-card guidance<\/a> also points people to lock a card first when something is wrong, then contact the issuer. You can do both. The app lock is not a substitute for telling a human what you shared. It is a way to stop new charges while you talk.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"800\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-zero-liability.png\" alt=\"Official Citi Card Benefits page titled 0 Liability on Unauthorized Charges with Citi customer service number\" class=\"wp-image-403594\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-zero-liability.png 1280w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-zero-liability-300x188.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/citi-zero-liability-1024x640.png 1024w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><figcaption class=\"wp-element-caption\">Citi publishes $0 liability for unauthorized charges on eligible consumer credit cards, and lists customer service on that same official page. A transfer you sent because a caller told you to is a different problem, and it still needs a same-day call.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">3. Change the keys they may now have<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">From a device they did not control, change the Citi password. Change the email password that receives Citi codes. Change any other bank or brokerage password that matches the old one. Turn on alerts for logins, payments, and payee changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you use an authenticator app, that is better than a text code going forward. A text code is what the caller just harvested. An app on a phone they do not hold is harder to steal on a second call.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Lock the card from inside the real app<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you can still sign in, use the official lock. Citi describes Citi Quick Lock in the Citi Mobile app and at Citi Online. On eligible cards it can block new purchases and cash advances while letting recurring charges continue. That is the opposite of a remote-access session. You are the one who toggles it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you cannot sign in, the printed customer-service number is the path. The $0 liability page also points cardmembers to a replacement-card request when a card is lost or stolen.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. If you already sent money<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Call Citi, and call the bank or service you sent the money through, on the same day. Ask about a recall, a hold, or a dispute. Wires, Zelle, and gift-card codes move fast. The FTC has said you probably will not get money back if you were talked into moving it yourself. That is a warning, not a reason to sit still.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Save what you still have. The caller ID screenshot. The text with the code. The confirmation of the transfer. The name they used. You will need those for the bank and for a report.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6. If you let them onto the device<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Disconnect the remote session. Uninstall the tool they told you to install. Do not keep chatting with them while you clean it up. Use another device to change passwords. If the machine held tax files, stored cards, or password-manager data, treat those as exposed until you change them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then tell Citi the session happened. A person who watched you sign in may have added a payee or changed a phone number while you were looking at a different window.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. Watch your credit file<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you shared a Social Security number, a full card number, or a scan of an ID, place a fraud alert or a credit freeze with the credit bureaus. The FTC&#8217;s <a href=\"https:\/\/www.identitytheft.gov\" target=\"_blank\" rel=\"noopener\">identity theft site<\/a> walks through that work. It is slower than a phone code, and it still matters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Citi&#8217;s Card Benefits pages also mention FICO score access on some cards through the official app and site. That is a monitoring habit, not a cure. It does not replace a freeze if a stranger now has your identifiers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8. Report it, then ignore the recovery pitch<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The FTC wants these calls in its file. Use the official <a href=\"https:\/\/reportfraud.ftc.gov\" target=\"_blank\" rel=\"noopener\">ReportFraud<\/a> site. If money moved online, the FBI&#8217;s <a href=\"https:\/\/www.ic3.gov\" target=\"_blank\" rel=\"noopener\">Internet Crime Complaint Center<\/a> takes those reports as well. Citi&#8217;s March 2026 fraud-prevention piece names both paths after you have already called your bank.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a Citi email or text looks wrong, Citi&#8217;s commercial-card fraud page asks people to forward the message to spoof@citi.com as an attachment, then delete it. That mailbox is for suspicious mail. It is not a substitute for calling about a code you already read.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not pay a second stranger to recover the first loss. Do not buy a package that promises the funds will return after a clearance fee. The next costume often arrives the same week.<\/p>\n\n\n\n<div id=\"mwtad1980010274\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Citi is a real bank with real fraud teams and real alerts. The person who just rang you is not proven by the word Citi on your screen. The trap is small and specific. They want the SMS code, or they want you to move the money, or they want your screen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hang up. Open the official app or the official site yourself. Use the number on the card. Never read a one-time code to an incoming voice. Never move money to protect it. If you already did either of those things, call Citi now and say so. The costume wants another minute. You do not have to give it one.<\/p>\n\n<div id=\"mwtad4270113312\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The phone says Citi. Sometimes the screen says Fraud Department. Sometimes it shows a number that looks like the one on the back of a card. The voice is not shouting. It says there is &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Citibank Scam Calls EXPOSED: Fake Fraud Desk Wants the Code\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/citibank-scam-calls-exposed-fake-fraud-desk\/#more-403596\" aria-label=\"Read more about Citibank Scam Calls EXPOSED: Fake Fraud Desk Wants the Code\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":403594,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2840,49],"tags":[],"class_list":["post-403596","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-product-scams","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/403596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=403596"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/403596\/revisions"}],"predecessor-version":[{"id":403651,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/403596\/revisions\/403651"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/403594"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=403596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=403596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=403596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}