Nobody is drilling into the vault. They are calling you and asking you to open it from the inside.
Last verified: July 2026
Key takeaways
- Almost all successful bank fraud now depends on persuading the account holder to act, not on breaking into a system.
- Three patterns cover most cases: the phantom investment, the authorised push payment, and the credential hijack.
- A legitimate Swiss bank never asks for a one-time code, never manages money through a messaging app, and never promises a guaranteed return.
- FINMA publishes a public warning list of unauthorised providers. Checking it is free and takes under a minute.
- Once a transfer is authorised by the account holder, recovery is difficult. Recognising the pattern early is the only reliable protection.
How do bank impersonation scams actually work?
A bank impersonation scam is a fraud in which criminals adopt the identity of a regulated financial institution in order to obtain money or credentials from its clients or from the public. The bank’s own systems are never touched. What is attacked is the trust attached to its name.
The tooling has improved considerably. Cloned websites now reproduce a bank’s design faithfully, spoofed numbers display a plausible caller ID, and generated audio can imitate a voice well enough to survive a short call. What has not changed is the underlying structure. Nearly every case fits one of three patterns.
| Pattern | How it presents | What it is really asking for |
|---|---|---|
| The phantom investment | A polished advertisement, a professional-looking dashboard, an attentive adviser and a return that sounds generous but not absurd. The relationship is built over days or weeks. | A transfer to an external account, wallet or platform described as being managed on your behalf. |
| The authorised push payment | An urgent call or message from someone presenting themselves as your bank, the police or a supplier. Something is wrong and it must be fixed now. | A payment you make yourself, with your own credentials, to an account controlled by the caller. |
| The credential hijack | An SMS or email about a blocked account, a failed payment or a required verification, linking to a convincing login page. Sometimes followed by an offer to help. | Your login details, your one-time code, or remote control of your device. |
All three share one principle. The criminal cannot open the vault, so the objective is to get the account holder to open it voluntarily. That is also why the countermeasure is not technical. It is recognition.
Ten rules a real Swiss bank never breaks
These are not one institution’s promises. They are the operating conditions that follow from being a licensed, supervised bank in Switzerland. If any interaction with someone claiming to represent a Swiss bank breaks even one of them, the interaction is not with the bank.
- No guaranteed returns. In regulated wealth management, return and risk are inseparable, and no supervised institution may present investment performance as certain. Certainty is a sales device, not a financial product.
- Money stays inside the regulated environment. A licensed bank holds and manages client assets within its own supervised structure. A request to move money to an external crypto wallet, a foreign trading platform or a third-party holding account is the point at which the money leaves the protected system.
- No wealth management over messaging apps. Regulated advice is documented and takes place through official channels. An adviser executing trades or requesting funds through WhatsApp, Telegram or Signal from a private number does not work for the bank.
- No time pressure. An offer that expires in ten minutes exists to remove the interval in which you would have checked. Legitimate banking never requires you to suspend your judgement, and any real matter will still be there after a verification call.
- Verification codes are never requested. A one-time password is the key to the account. No employee of a real bank will ever ask you to read one out by phone, type it into a chat or send it by email. There is no legitimate scenario in which that request occurs.
- One domain, no variations. Impersonators register addresses that differ from the genuine one by a hyphen, a word or a suffix. Alpian, for example, publishes the fakes circulating under its name, including alpianmanagement.com, alpian.private-eu.com and alpian-egibilite.com, and confirms that alpian.com is its only web address. If a single character differs, close the tab.
- No outsourced advisers cold-calling from abroad. A Swiss bank’s advisory relationship is internal and based in Switzerland. An unsolicited call from a third-party broker or partner in another country, offering access to a Swiss institution’s products, is not how the relationship is formed.
- No remote access software. A request to install TeamViewer, AnyDesk or a similar tool so that support can help resolve an issue is a request for control of your device. With screen and input access, the caller can authorise transfers without ever needing your password.
- A real bank is happy to be verified. Ending a call and reaching the institution through a channel you found yourself is normal, expected and never resented. Never use a number, link or address supplied by the person who contacted you.
- Reporting is part of the system. Banks track and take down impersonation infrastructure, and client reports are how most of it is found. Alpian asks clients to forward suspicious calls, messages, adverts and websites to fraud-report@alpian.com with screenshots and numbers where possible.
How do you verify that a Swiss financial provider is real?
Verification in Switzerland is public, free and quick. Four checks in sequence will settle almost any case, and none of them require contacting the provider being checked.
- Check the FINMA warning list. FINMA maintains a published list of companies and individuals suspected of providing financial services without the required authorisation. Note that the list is explicitly not exhaustive and is not updated daily, so absence from it is not a clearance.
- Check the authorisation itself. A Swiss bank is licensed by FINMA and appears in its register of authorised institutions. A firm that claims Swiss regulation but cannot be found there is claiming something it does not have.
- Check the domain against the official one. Find the institution’s real address independently, through a search or the app you already have installed, and compare character by character. Do not navigate from the link you were sent.
- Check the wider warning lists. The Zurich cantonal police maintain a public warning list at cybercrimepolice.ch, and IOSCO operates an international investor alerts portal covering providers flagged by regulators worldwide.
One structural point is worth holding on to. Most providers on FINMA’s warning list have no physical presence in Switzerland at all. They claim a Swiss office because the credibility of the Swiss financial centre is the asset being stolen. A Swiss-sounding name, a Swiss flag and an address in Zug prove nothing on their own.
What does a legitimate bank do instead?
| Situation | What a scam does | What a licensed Swiss bank does |
|---|---|---|
| Discussing returns | Promises a fixed or guaranteed profit | Presents past performance with the risks and the costs attached |
| Holding your money | Directs it to an external wallet or partner account | Holds it within its own supervised structure, protected up to CHF 100,000 under the Swiss depositor protection scheme |
| Contacting you | Calls out of the blue with an offer and a deadline | Contacts existing clients and registered prospects, and never objects to being called back |
| Authentication | Asks you to read out a one-time code | Never asks for a code, a password or remote access to your device |
| Getting started | Requires urgency and secrecy | Runs a documented onboarding process, with identification, inside the app or on the official site |
The asymmetry is useful. A scam needs speed and isolation, because both prevent checking. A regulated institution can afford to be slow, because everything it is doing survives inspection. Any interaction that resists being verified is telling you what it is.
What should you do if you have already transferred money?
Act immediately and in this order. Contact your bank through its official app or published number and ask for the payment to be recalled, because the first hours are when a receiving account can still be frozen. File a report with the police, which is required for most subsequent steps. Change the credentials for the account and for the email address attached to it, and remove any remote access software that was installed.
Then report the impersonation itself, to the institution whose name was used and to Switzerland’s National Cyber Security Centre. This is the part people skip because the money already feels gone. It is also the part that gets a cloned domain taken down before it reaches the next person.
Verify before you act
Alpian publishes the fake domains circulating under its name, the red flags to check, and where to report an approach.
See Alpian’s security pageFrequently asked questions
How can I tell if a call from my bank is real?
End the call and reach the bank yourself, through the app you already have installed or a number you found independently. A legitimate bank never objects to this. Two requests identify a scam with near certainty: asking you to read out a one-time code, and asking you to install remote access software.
Will a Swiss bank ever ask for my one-time password?
No. A one-time password authenticates an action on your account, so anyone requesting it is asking you to authorise something on their behalf. No employee of a FINMA-licensed Swiss bank will ask you to read a code aloud, type it into a chat or send it by email, under any circumstances.
How do I check whether a financial provider is authorised in Switzerland?
Start with the FINMA warning list of suspected unauthorised providers, then confirm the firm appears in FINMA’s register of authorised institutions. The warning list is not exhaustive and is not updated daily, so absence from it is not proof of legitimacy. The Zurich cantonal police also publish a warning list at cybercrimepolice.ch.
What is an authorised push payment scam?
It is a scam in which you are manipulated into transferring your own money to a criminal, using your own credentials. Because you authorised the payment, it is technically legitimate and recovery is difficult. It is now the leading category of credit-transfer fraud in the European Economic Area by value.
Where do I report someone impersonating Alpian?
Send the details to fraud-report@alpian.com, including screenshots of any emails or websites, the number that called you, and the domains you were directed to. Suspected unauthorised providers can also be reported to FINMA, and cyber incidents to Switzerland’s National Cyber Security Centre.
The infrastructure of a Swiss bank is not the weak point, and the criminals working this market know it better than anyone. Deposits at a FINMA-licensed institution sit inside a supervised framework and are protected up to CHF 100,000 per client, whether the bank is digital or has a marble lobby. What is being attacked is the short interval between a convincing sentence and a decision. Ten rules, four checks, and one habit of verifying independently close most of that gap. Real investment products are still there after you have checked. Fraudulent ones rarely are.
Sources

