Your Bank Says It Will Never Ask for Your Password. Then Why Does It?
At some point, you've probably received a message from your bank that says something like this:
We'll never ask for your full password, Social Security number, or PIN via email or phone. If someone contacts you claiming to be us and asks for this information, it's a scam.
Good advice. Accurate advice.
And then, two weeks later, you get a call from what appears to be your bank's number. The representative asks you to verify your account by confirming the last four digits of your Social Security number, your date of birth, and the answer to your security question.
You comply. Because that's what you've always done when your bank calls.
Here's the problem: a fraudster can run that exact same script. And you'd have no way to tell the difference.
This is the gap between performative security and real security. It's not a small gap. It's the gap where most financial fraud actually happens.
Security Theater Is a Real Thing
Performative security is when an institution takes actions that look like security, communicate the appearance of security, and satisfy a compliance checkbox, but don't actually change the behavior patterns that create risk.
It shows up in a few consistent ways.
The disclaimer that contradicts the process. Your bank tells you it'll never ask for sensitive information over the phone. But its own verification process — the one every representative uses when you call in — requires you to provide your date of birth, the last four digits of your Social Security number, your mother's maiden name, or some combination of these. These are the same pieces of information a social engineer would need to impersonate you. The disclaimer is real. The process that contradicts it is also real. Both exist at the same institution, and the left hand doesn't know what the right hand is doing.
Security questions treated as secrets. The institution asks you to set up security questions: your first pet's name, the street you grew up on, your high school mascot. Then it uses those answers as a verification method, as if they're private. They're not private. They're the kind of information that appears in obituaries, Facebook posts, and public records. A motivated person can find most of them in under an hour. Using them as authentication isn't security. It's the appearance of security, and it gives you false confidence in a process that doesn't hold.
Fraud warnings delivered through the fraud vector. You receive an email warning you about phishing emails. The email contains a link. The link goes to a page asking you to log in. This isn't hypothetical. It happens regularly, and it trains people to click links in emails from their bank and enter credentials on the resulting page. The warning and the vulnerability arrive in the same envelope.
Text message codes presented as strong protection. Many institutions have added 2FA via text message and present this as a meaningful security upgrade. It's better than nothing.
It's also arguably the weakest modern form of MFA available, vulnerable to SIM-swapping attacks where a fraudster convinces your carrier to transfer your phone number to a device they control. Institutions that offer only text message codes while calling it 2FA are technically correct and practically misleading.
What Real Security Actually Looks Like
The contrast isn't always dramatic, but it's consistent.
Institutions that take security seriously build verification processes that don't rely on information a social engineer could find or guess. Instead of asking for your mother's maiden name, they use a one-time code sent to a device you registered in person, a voice biometric enrolled during account setup, or a callback to a number you pre-verified — not a number the caller provides during the call.
They're also consistent. If the policy is that representatives will never ask for your full password, the system is built so that representatives can't see your full password and have no reason to ask for it. The policy and the process match each other.
Real security also tends to be less convenient, at least at the start. Strong authentication requires setup. Verification methods that can't be socially engineered require more infrastructure. Institutions that have invested in this will sometimes be slower to onboard you, more particular about identity verification, and less flexible about account recovery. That friction isn't a flaw. It's the point.
How to Audit Your Own Accounts
You don't need to trust an institution's marketing language. You can observe their actual behavior.
Call your own bank. Go through the verification process as a normal customer. Write down exactly what they ask for. Then ask yourself: could someone who had done thirty minutes of research on me answer these questions? If the answer is yes, the verification process isn't protecting you. It's protecting the institution from liability while creating the appearance of due diligence.
Try to recover your account. Go through the account recovery flow for a sensitive account as if you'd forgotten your password. What does it ask for? Email confirmation is reasonable. Security questions are not. A code sent to a pre-registered phone is reasonable. A code sent to any phone number you provide during recovery is not.
Check what MFA options are available. If the only option is a text message code, that's a signal worth noting. If the institution offers an authenticator app or a hardware security key and you're not using it, that's a gap worth closing today. If the institution offers no MFA at all on a financial account, that's a serious red flag.
Read the fine print on fraud liability. Some institutions shift liability to the customer if the customer "authorized" a transaction, even if that authorization was obtained through deception. Understanding where the liability sits tells you something real about how seriously the institution takes the threat.
The One Habit That Closes Most of the Gap
The goal here isn't to distrust every institution you work with. Most of the people who work at your bank aren't thinking about social engineering. They're following a process that was designed by someone else, years ago, and hasn't been revisited since.
The goal is to stop letting an institution's security theater substitute for your own judgment.
When someone calls you claiming to be your bank, the verification process they use tells you almost nothing about whether they're legitimate. A real fraudster can ask for your date of birth just as easily as a real representative can. What matters is who initiated the contact.
If you called them, you're probably fine. If they called you, hang up and call back using the number on the back of your card or on the institution's official website.
That one habit closes more of the gap than any disclaimer your bank has ever sent you.
What Good Actually Looks Like
Since we've spent most of this post describing the problem, here's a concrete target to aim for on your most important accounts.
For your bank and financial accounts:
Log in and go to your security settings. Look for an option to add an authenticator app (Google Authenticator, Authy, and Microsoft Authenticator are all solid choices) rather than relying on text message codes. If the option exists, use it.
Set up account alerts for every transaction, login, and password change. These don't prevent fraud, but they give you an early warning when something is wrong.
Find the number on the back of your card or on the institution's official website and save it in your phone. When something feels off, hang up and call that number. Don't call back a number left in a voicemail.
For your email account:
This is the most important account you own. If someone gets into your email, they can reset every other password you have. Use an authenticator app here without exception.
Review your recovery options. Make sure the backup email address and phone number on file are current and actually belong to you.
For your healthcare and insurance portals:
Enable whatever the strongest available login option is, even if the portal only offers text message codes. It's still better than a password alone.
Check what information is visible once logged in. Many portals expose your full Social Security number, date of birth, and address on the account summary page. Knowing what's there helps you understand what's at stake.
The honest baseline: An authenticator app on your email and your primary bank account, combined with the habit of always being the one who initiates contact when sensitive information is involved, covers the majority of real-world risk for most people. If an institution calls you and asks you to verify anything, ask for an extension or reference number, hang up, and call back using the number on the back of your card or on their official website. A legitimate institution will never object to this.
