If someone calls saying they are from your bank, do not give any card number, PIN, password or token code. Hang up and call the bank yourself, using the number on your card or the bank’s official site. CONDUSEF, the agency that protects bank customers in Mexico, says banks never ask for this data by phone when you did not start the operation.

What is a fake bank call?

CONDUSEF calls it vishing, or phone phishing. In its fraud-types guide, it says criminals pretend to be employees of a financial institution and “generalmente” tell you there are irregular charges on your account or that they need some information.

An older CONDUSEF alert describes how one version worked. First a text message reports a charge you supposedly did not make and asks you to reply NO. Then a fake operator calls and walks you through “cancelling” it on a fake website, where you are asked for your card number, PIN, email and password. The call is the tool that keeps you calm and on the line while you type.

What will a real bank never ask you by phone?

CONDUSEF’s wording is direct: companies and banks “NUNCA” ask for your financial data or card numbers by phone or internet when you did not start the operation. Its list of phishing warning signs also includes being asked for your token digits.

CONDUSEF’s advice for these calls:

  • Do not give your data. Call the financial institution directly to check the story.
  • Never type your passwords, especially bank ones, on a site you reached from an email, chat or text message.
  • Do not reply to suspicious messages from unknown senders.
  • Be wary of urgency. CONDUSEF notes that these criminals use alarming tactics and urgent requests so you do not stop to think.

Caller ID will not save you here. The US FTC warns that scammers can fake the name and number on your screen. Our own advice, not CONDUSEF’s: call back on a number you looked up yourself, not the one that called or one the caller gave you.

How can you check a phone number?

CONDUSEF has a free tool called Consulta y reporte de números sospechosos. On its page, it lets you check whether a number has records “relacionados con fraude, spam, llamadas sospechosas o prácticas no reconocidas”, and lets you report a new one. You type the number with the country code, for example +52 followed by the ten digits.

There are two limits. It is a website, so you use it after the call, not during it. And a number with no records is not proof of a safe caller: it may just be new. The page itself does not claim otherwise.

What if you already gave your data or see strange charges?

Act fast. CONDUSEF’s page on unrecognized charges says:

  1. Stay calm. Call your bank, report the charges you do not recognize and cancel the card.
  2. File a complaint at your bank’s Unidad Especializada (UNE). You get a clarification request, which can be done on the bank’s website.
  3. The bank must give you a receipt with a folio number, date and time. Keep it.
  4. Generally, 48 hours after you complain, the bank should credit the amount back. It keeps investigating for up to 45 days. The credit can be reversed if it turns out you authorized the purchase.
  5. The bank cannot charge late-payment interest on the disputed amount or report you to the credit bureau.

CONDUSEF’s stolen card page adds that you have up to 90 calendar days to file the complaint, and that you can block the card in the bank’s app. If you want help, CONDUSEF’s contact center is 55 53 400 999.

What does REPEP do about these calls?

Nothing. PROFECO’s advertising registry excludes banks, and its complaints page excludes fraud. Read what REPEP covers and what it does not.

A short checklist

  • Hang up.
  • Look up your bank’s number on your card or its official site, and call that.
  • Never share PINs, passwords or token codes by phone.
  • Check and report the number on CONDUSEF’s tool.
  • If money moved, call your bank at once and file the aclaración.

Sources: CONDUSEF pages, read on 2026-10-08. The vishing alert is undated and the bank-specific details have been left out.