Banks use clear channels. An e-mail about a “blocked account” or “confirm this payment now” via a non-official app link deserves a pause — even if the attachment looks like a PDF statement.
Attackers count on busy finance teams. A quick call to the bank using the number from the official website — not from the e-mail — usually clarifies the case.
SMS, short links, and fake apps
Scam texts often use URL shorteners or look-alike domains, then redirect to a phishing site or an APK outside official stores. Sideloaded Android packages bypass store review; iOS scams more often push credential harvesting on the web.
Real banks steer you to their app via the official store, not an installer attached to random mail.
Why phone-only users are still at risk
Many older adults rely on mobiles only — exactly where scam SMS and “bank” calls demand “instant transfers to a safe account” or “read me the code that just arrived.” Legitimate banks do not operate that way. A simple household note helps: “The bank never asks for your password or SMS codes on the phone” plus the hotline from the official site.
Adult children often help parents “with IT” — avoid sharing primary banking passwords; use in-app delegation where banks offer it, or visit a branch together.
In the business and for automated ingestion
Document how statements really arrive (sender, format, whether links are ever used). If you ingest statements from mail automatically, validate senders and templates — fakes can mimic alert layouts.
Programmatic ingestion should align with mail authentication (DMARC, domain reputation). For payment matching, logging Authentication-Results and flagging SPF/DKIM failures reduces silent trust in forged mail.