Section: Technology & AI Author: IN Reading Length: ~27 min Sources and further reading: 22 items Topics: cyber security, bank fraud, phishing, smishing, vishing, MFA SEO / Working Title: How to recognise a fraudulent e-mail, SMS or phone call?
The question is: how to recognise a fraudulent email, SMS or phone call? It sounds simple until we notice that we are not comparing one thing. The number on the display is not an identity. Phishing is not vishing and vishing is not smishing. MFA is not a duress lock. An authorized payment that you have confirmed yourself is no longer unauthorized. Only when these four things are separated, it is possible to read what the Police of the Czech Republic, NÚKIB, CNB and CBA are actually measuring in 2024 and 2025 — and whatflows before the money leaves.
1. The bank, the police and the office see the same call in three statistics
Let's imagine an afternoon at home. The familiar name of the bank appears on the display. The voice claims that the account is running a suspicious operation. A message on the phone asks for confirmation. There is a link to "secure verification" in the email. One does not ask for a definition of cyberspace. He wants to know if he is talking to the bank or someone impersonating the bank.
But the institutions that describe the problem do not see the same unit. The Police of the Czech Republic and the Ministry of the Interior monitor registered acts in cyberspace. In 2024, there were 18 495 of them, i.e. 10.67% of the 173 322 acts of total crime, a year-on-year decrease of 5.5%; clarity was 15.4% [1][2]. In 2025, there were 21 137 of them, i.e. 12.4% of 170 051 acts, year-on-year by 2 642 more, i.e. by 14.3%; clarity was 15.1% [3][4]. That's a broad police category. It's not the number of fraudulent calls.
The CZSO and criminal statistics for narrow qualified cybercrime according to Sections 230 to 232 of the Criminal Code show a different total: 1 224 acts in 2025, 93 less than the previous year, i.e. 7.1% [5]. NÚKIB records cyber incidents according to its legal and work framework. In 2024, there were 268 of them, of which 1 was very significant and 18 were significant [6]. In 2025, the Ministry of the Interior reports 203 incidents cited from NÚKIB [4]. The Czech Banking Association talks about clients of member banks, their damages and attacks [12][13].
At first glance, it is one threat. In fact, each one adds a different object. The police see the deeds. CZSO a narrow legal category. NÚKIB incidents at regulated and addressed organizations. CBA bank clients. CNB legal regime and complaints. Therefore, they may all be partially correct, and a common number of "how many fraudulent calls were there" still cannot be honestly compiled.
The known number on the display is not an identity.
— Jiný Kontext
2. One action request has at least five layers
Fraud doesn't start with damage. It starts with a channel. An email has a header, a link and an attachment. An SMS or RCS has a short message, the name of the sender and often a push for speed. The call has voice, intonation, and the ability to induce instant fear. Messenger adds the appearance of a personal relationship. Each channel carries different traces and a different rhythm of decision making.
The second layer is the sender mask. It can be the name of the bank in an SMS, a similar domain in an e-mail or a fake calling number. The mask reduces drag. It does not prove identity. That's the first rule of thumb: identity doesn't start with what the display shows. It starts with whether the verification will take place through a channel that you have chosen and that you know in advance.
The third layer is the script. Some legends rely on fear: the account is hacked, the police are investigating, someone misused the ID card. Others rely on greed: an investment, a quick return, a missed opportunity. Others rely on trust: a colleague, family, a familiar voice. Time pressure is not proof of authenticity. It's part of the script.
The fourth layer is the required action. Fill in the information. Dictate the code. Confirm MFA. Send money. Install remote access. This is where a suspicious message turns into harm. The fifth layer is redress: the bank, the Police of the Czech Republic, the financial arbitrator or the court, depending on what happened and what legal regime applies. None of these layers are instant returns.
This build is important because the defense is not supposed to guess how convincing the mask is. It is supposed to stop the action. If the call asks for a code, it's not just the voice that's the problem. If an SMS asks for a click, it's not just the text that's the problem. If the email asks to sign in via a link, it's not just the logo that's the problem. We always ask what action the channel wants us to take and whether we verify it elsewhere.
3. The number on the display is not an identity
One tends to believe what looks familiar. The name of the bank in the message, the number of the infoline on the display, the name of the office in the e-mail. However, the CNB and NÚKIB draw attention to fraudulent phone calls and spoofing, i.e. a situation where the fraudster tries to look like a well-known institution [7][9][11]. It does not follow that every known number is fake. It follows that a known number does not itself verify identity.
Technical systems for verifying the calling number solve only part of the problem. The American STIR/SHAKEN framework, which the FCC writes about, works with the authentication of a telephone number in the network and with the relationship of operators to the number [18]. This is a useful layer. It is not proof of who exactly is speaking, why they are calling and whether they have the right to request your action. The success rate of similar verification in Czech networks is not publicly disclosed in the file as a map according to which each call could be evaluated.
It is not enough to look up the number on the Internet. If the mask shows a bank number, the internet will only confirm that the number really belongs to the bank. It won't prove that the bank is calling from him. The correct step is different: hang up, do not call back the number from the display and use the official contact from the institution's website, from the payment card or from the application. Where a bank offers in-app call verification, it's a better check than voice on the phone.
So identity is not what comes to you. Identity is what you verify. That's a small shift, but it changes the whole decision-making process.
4. Phishing is not vishing. Vishing is not smishing
The word phishing is often used for everything. For e-mail, SMS and phone calls. Practically, it helps in heading, but hurts in defense. Email phishing leaves different traces than SMS smishing and voice call vishing. The CNB distinguishes channels in its overview [9][10]. The point is simple: same goal, different channel, different test.
For e-mail, address, domain, header, attachment and link can be addressed. With SMS, there is little space and the sender's name, urgency and link play a bigger role. There is real-time pressure on the call. One does not have time to read in peace. That's why it's so important to hang up on a call. Not because the call is always a scam. Because the same channel that caused the push is not supposed to be the verification channel.
In its Threat Landscape 2025 report, ENISA works with a European dataset of 4 875 incidents between 1 July 2024 and 30 June 2025. It reports that 77% of incidents were of the DDoS type and that phishing appears in around 60% as an intrusion vector [17]. These numbers cannot be translated into the sentence that 60% of Czech criminal statistics are phishing. It measures a different population and a different unit. Nevertheless, they remind us that social input into the system remains important even where the incident is described in technical language.
From a practical point of view, it is better to forget about the label and look at the requirement. Does the channel want data? Does he want a code? Does he want confirmation? Does he want a transfer? Want remote access? If so, the defense is not to determine the correct Latin word. Defense is the second channel.
5. Wide cyberspace is not narrow cybercrime
According to the Police of the Czech Republic and the Ministry of the Interior, the year 2025 brought 21 137 registered acts in cyberspace [3][4]. In the same year, however, the CZSO lists 1 224 acts in narrowly qualified cybercrime according to Sections 230 to 232 of the Criminal Code [5]. Both numbers can be correct. They don't measure the same thing.
Broad cyberspace includes acts in which the digital environment plays a substantial role. It can be advertising fraud, investment legends, phishing and other forms of social engineering. Narrowly qualified cybercrime aims at crimes related to unauthorized access to the system, passwords and similar actions. If someone convinces a person to transfer over the phone, it may look different in the statistics than an attack on the system.
Clarification of 15.1% in 2025 for cyber crimes is not a share of refunds [3][4]. It is a police indicator of the clarification of the deed. There may be a case that is cleared but the money is not back. And there may be a payment that the bank will help stop without the quick unraveling of the entire criminal network.
Here again it shows why one big number is not enough. The reader does not need to know just how big the problem is in the sum. It needs to know when to stop taking action in the channel that is asking it for action. The statistics show the range. They do not decide for him in the minute of the call.
6. The NÚKIB incident is not a crime of the PČR
NÚKIB is an important institution, but its statistics are not the same as police crime statistics. It recorded 268 cyber incidents in 2024, which the dossier describes as a series record; of these, 1 was very significant and 18 were significant [6]. In a survey of 415 respondents, of which 324 were regulated and 91 were unregulated, more than 90% of respondents encountered phishing and more than 80% encountered fraudulent e-mails [6]. NÚKIB states that it did not verify these questionnaire data. "Encountered" is not the same as "suffered damage".
In 2025, the Ministry of the Interior reports 203 incidents cited from NÚKIB; the decline towards 2024 was mainly related to DDoS [4]. The direct download of the PDF report of NÚKIB for the year 2025 was not loaded according to the file as of September 1, 2026. Therefore, it is accurate to stick to what the MV states and not add your own certainty.
NÚKIB also defines the boundaries of its agenda for fraudulent phone calls to citizens [7]. That doesn't mean the call isn't dangerous. It means that another institution is looking at a different part of the problem. The Big Reveal campaign can be a useful source of warning and education [21]. It's not a series of police deeds.
Distinguishing these things is practical. When a business deals with an incident, it asks about systems, responsibilities and reporting. When a household handles a call from a supposed bank, they ask for identity verification and stop action. Both belong to cyber security. It's not the same door.
7. MFA is not a duress lock
Strong authentication protects against many attacks. The Payment System Act works with it as an obligation of the provider in specified situations [14]. But an MFA is not a magic lock against social engineering. If the attacker gets the human to confirm the authentication themselves, the technology has done part of its job and the human has done something they shouldn't have done at the same time.
On September 27, 2024, the CNB warned against multi-factor authentication fraud. Describes the situation where the victim self-confirms the verification and warns that after such confirmation the consumer may bear the loss [8]. This is annoying, but essential for defense. MFA is intended to stop unauthorized use without cooperation. It is more difficult to stop a situation where a person cooperates under pressure.
It does not follow that the victim is "to blame" for the fraud in a moral sense. It follows that the legal and operational regime changes after confirmation. The bank, the police, the CNB, the financial arbitrator and the court will not deal only with the fact that the call sounded convincing. They will deal with what was confirmed, what information the person saw and whether it was gross negligence.
The practical sentence is short: don't confirm an MFA that you didn't run yourself. If someone in the call tells you to confirm verification to protect you, verify the situation through another channel. Not in the same call.
8. An authorized payment is no longer unauthorized
The word "unauthorized" sounds natural in bank fraud. Someone robbed you, so the payment wasn't yours after all. However, the Act on Payment Systems distinguishes between situations where you do not authorize a payment transaction and situations where you confirm it, albeit with a fraudulently lured scenario [14]. In its explanations, the CNB points out that a consumer who himself confirms the amount and recipient or other action may bear the loss as gross negligence [8][9].
This is not the same as a stolen card without the cooperation of the client. In remote fraud, the key is whether the person shared the data, confirmed the MFA, approved the transfer or otherwise helped the transaction go through. This is why so many recommendations are focused on the action, not the appearance of the message.
It does not follow that every case is a foregone conclusion. The CNB itself emphasizes the circumstances and at the same time says that it does not decide disputes about refunds; this is done by a financial arbitrator or a court depending on the nature of the case [9]. There is something more practical about this: the defense must come before the confirmation, not after it.
When the payment is gone, the only thing left is a quick reaction: contact the bank, block another possibility of misuse and file a report with the Police of the Czech Republic. The bank may try to stop the outgoing payment. However, this is not the same as an automatic refund claim.
9. Škoda CBA is not a shame of PČR
According to the press conference and quotes, the Czech Banking Association reports an average damage of CZK 23 462 per client of member banks who suffered damage in 2025. There is also talk of less than 91 thousand attacks, CZK 12.2 billion saved by banks and an attempt over CZK 14 billion [12][13]. These numbers are important, but they have precise limits.
It's not about the median. It is not about the entire population of the Czech Republic. It's not just about vishing. The definition of an "attack" unit is internal, and the association's official PDF with full methodology is missing from the file as of the date of the search. It is therefore not possible to calculate a simple proportion of victims who received the money back after sending. Nor can these numbers be added up with police actions and create one universal measure from them.
This does not weaken the practical message. Banks capture a large volume of attempts, and the damage to those who suffer it is not small. But for the reader, the mechanism is key: the amount saved usually means an intervention before the damage is done or in its immediate vicinity. If a person himself confirms the transfer and time is running out, the room for correction narrows.
Therefore, it is more accurate to say: CBA figures show the banking part of the problem. Police numbers show the criminal part of the problem. The CNB shows the legal regime. The user's defense lies between them, in the decision not to take the desired action in the channel that caused the pressure.
10. The SIM farm explains the mask. It doesn't explain your transfer
In the IOCTA 2026 report, Europol describes a 2025 operation against infrastructure that it says involved 40 000 SIM cards, a network of 7 Latvian nationals, at least 1 200 SIM boxes and numbers from more than 80 countries. More than 49 million online accounts were to be created based on the service [16]. This is an example of industrialization. Not the EU sum of all frauds and not the number of Czech victims.
Such numbers help to understand why fraud does not have to look amateurish. Infrastructure, leased services, automation and AI-assisted impersonation reduce the cost of the mask. The scammer doesn't have to be technically proficient in everything himself. It may use services that facilitate mailing, account management or impersonation of an institution. But there is a necessary boundary here: the description of the infrastructure is not a guide to its use.
For the reader's defense, the most important thing is not how exactly the mask is put together. The important thing is that the mask itself does not prove anything. If the attacker can better look like a bank, the appearance should not be the deciding factor. The action and the second channel should decide.
So the SIM farm explains why a lot of convincing contacts can come from different numbers. It does not explain why one should confirm the transfer. There is still a step between the mask and damage. That step needs to be delayed, interrupted and verified.
11. Deepfake voice is not a condition of legend
Deepfake voice changes the boundary of trust. If one's voice can be imitated, hearing ceases to be a sufficient test of identity. Another Context deals with this in a separate text about the deepfake of a well-known voice [22]. This article does not want to repeat the same argument. For e-mail, SMS and regular calls, to say the least: most defenses don't rely on voice recognition. It stands on the second channel.
Many documented legends do not need a synthetic voice. All you need is a familiar number on the display, an urgent scenario and a call to action. A person under pressure does not verify because they believe in artificial intelligence. He is verifying because he wants to quickly stop the damage the caller just described.
This is why it's not a good idea to teach people to listen for "weirdness" in the voice as a primary defense. The voice can be genuine and the request fake. The voice may be unfamiliar and the call genuine. The voice can be synthetic and technically convincing. Hearing is not the test. The test is to return to a previously known channel.
Deepfakes therefore belong in the picture. But only as another layer of mask. Not as a necessary condition for fraud and not as a reason to change the basic rule: do not confirm the action in the channel that requested it.
12. Clarification is not a refund
Cybercrime policing was 15.4% in 2024 and 15.1% in 2025 [2][3]. These numbers measure crime work in police statistics. They are not saying how many victims have received refunds. They don't even say that nothing happened in the other cases. They say what proportion of deeds were clarified according to the rules of the given statistic.
A bank seizure is another matter. CBA reports CZK 12.2 billion saved in 2025 [12][13]. This is bank protection and response to attempts. It's not a police clarification. The CNB is another layer: it supervises, explains the regime, accepts suggestions, but does not decide the dispute between the client and the bank about the return of money [9].
These three achievements may not be added together. Stopped payment, clarified deed and won compensation dispute are different outcomes. Each can occur without the other. For the reader, there is practical urgency, not panic: speed after suspicion is important, but it's even more important not to get to the stage of just waiting for a fix.
The phrase "the police will investigate" is not meant to be the last line of defense against confirmation. The police come after the event. The second channel comes before her.
13. The best defense is the one whose mistake you manage to reverse
Defending against a fraudulent email, SMS or call should not be a test of genius. You don't have to recognise every mask. It should have a procedure that stops the action even if it doesn't recognise the mask. Therefore, the following diagram does not show how to build the scam. Indicates where to break.
| A kind of failure | What does he look like? | How to test | What will limit the damage |
|---|---|---|---|
| Number as identity | The display shows the bank or the police | Hang up and use a contact from the website, card or app | Taking spoofing as a possible mask [7][9] |
| MFA as a lock | A person confirms the verification because "the bank asks" | Don't approve MFA that you didn't run yourself | CNB: may bear loss after confirmation [8] |
| Total statistics | 21 137 = phishing = shame CBA = NÚKIB incident | Separate PČR, CZSO, NÚKIB, CBA and CNB | Do not leave other units in the same sentence |
| Authorization as card theft | One expects an automatic return | Separate authorization and unauthorized transaction | Immediately the bank and the Police of the Czech Republic; the dispute belongs to an arbitrator or a court [9][14] |
| Hearing as evidence | "I hear the headmaster, so it's him" | Second channel | Voice is another layer, not authentication [22] |
Illustrative diagram: The line shows the channel: e-mail, SMS, call. Actions are listed in the column: data, code, MFA, transfer, remote access. The sender mask is just a header. The control sits in the action column and runs through the second channel.
The best defense is not one that never doubts. It is a defense whose mistake can be reversed. If you hang up on the real banker and call back to the official line, you're wasting time. If you stay in the scam call and confirm the transfer, you lose more.
14. The second channel says more than the header
The second channel is not a call back to the number that just appeared on the display. It is not a reply to the same SMS. It's not clicking on a link in an email and then "verifying". The second channel is the path you know before the incident: official website of the institution, number on the card, banking application, internal company contact, personal verification outside the original message.
What needs to be tested before you confirm MFA
The first question is: did you initiate the verification? If not, don't confirm it. The CNB explicitly warns against fraud in which the victim is induced to confirm the MFA [8]. The second question is: do you see the amount and the recipient that you yourself expect? The third question is: why is the verification coming now? If the response is delivered by the same call that raised the validation, it's not validation. It's part of the pressure.
How to test the second channel
Hang up or stop replying in the same channel. Take the official contact from the institution's website, from the payment card or from the application. For a bank that offers in-app call verification, use this option. CISA recommends not clicking on links in suspicious messages and verifying through trusted sources [19]. CSIRT.CZ accepts reports of incidents, including phishing, and works with URLs and email headers [20]. That's the way to report, not panic click.
The second channel must also be known in the company in advance. It is not enough to write to a colleague in the same thread from which the request came. It is not enough to reply to an email with an urgent invoice. It's not enough to call the number in the signature of the message if that very signature may be part of the problem. The company needs a simple rule for payments, supplier account changes and remote access: authenticate through the contact stored in its own system, not through the contact supplied in the request.
This procedure is not distrust of colleagues. It is to protect colleagues from having their name become a tool of pressure. The accountant does not have to decide whether the email style really suits the director. An IT technician may not be able to tell if the call sounds like a contractor. It is enough for him to know that the change of payment account, one-time code and remote access do not go through the same channel in which they are requested.
The household needs the same principle on a smaller scale. Parents and grandparents will not be helped by a long list of types of attacks if they are afraid that someone will already steal the account at the crucial moment. A sentence that can be used without thinking will help: I will call back the number from the card or from the official application. If the caller is pushing the person not to hang up, that in itself is reason to hang up. The right institution assumes that the client authenticates the call through its own channel.
A good second channel has another quality: it does not require improvisation. The bank number, the procedure for blocking the card, the contact for the accountant and the rule for changing the supplier's account should be saved before the pressure comes. You can easily choose the right path. In a call, the fastest is often chosen. The scam relies on this very exchange. Therefore, preparing a contact list is not an administrative trifle. It is a security tool.
Three tests before transfer
First test: hang up and verify with the second channel. Second test: don't confirm MFA that you didn't run yourself. Third test: upon suspicion, immediately contact the bank for blocking and the Police of the Czech Republic for notification. Don't listen to the deepfake voice. Solve by channel.
An authorization that you have confirmed yourself is no longer an unauthorized payment.
— Jiný Kontext
15. The period of thirteen months is not a refund
The Payment System Act contains a deadline for reporting an unauthorized payment transaction. According to Section 175, the payer must notify the provider of an unauthorized transaction without undue delay, no later than 13 months after the amount was written off; if the provider objects to the late notification, the court will not grant the right to remedy [14]. That's the deadline. It's not a money back promise.
In addition, there are other provisions of the Payment System Act, including strong verification and correction rules [14]. And next to them the criminal code, for example § 209 on fraud [15]. This legal map is important for the reader mainly because it does not lead to one automatic return. Early notification is a requirement. Not a guarantee.
If a person has confirmed a transaction under duress or under deception, the dispute may revolve around complicity and gross negligence. The CNB repeats that it does not decide the dispute about the refund itself [9]. The practical procedure therefore remains twofold: immediately contact the bank and file a report with the police. At the same time, keep communication, numbers, messages and time data for further solutions.
The best legal term is the one you don't need to use. This is not cynicism. It is a description of the order. The second channel decides before confirmation. After confirmation, deadlines, banking processes and disputes are already decisive.
16. Five to ten calls a day on the CNB line is not an annual map of victims
In the FAQ on fraud in the payment system, the CNB states that the Green Line deals with 5 to 10 fraud complaints per day. The same overview says that in 2021 it did not register such complaints and in 2022 there were already hundreds [9]. This is a useful signal of change. It is not an annual total of victims and it is not a statistic of successful frauds.
The range 5 to 10 per day is the number from the CNB's communication channel. It does not include those who call the bank, the police, the financial arbiter or anyone. It does not say how much damage was done, how much money was recovered or how many cases overlap with police statistics. It does not include the 21 137 acts in cyberspace or the average damage of CZK 23 462 for damaged clients of member banks [3][12].
Still, this number makes sense. It shows that fraud in the payment system is not a peripheral question. People ask because the line of responsibility is not intuitive. One feels that one has been robbed and at the same time hears that one has confirmed the payment oneself. This is exactly where you need to talk about the second channel before the complaint.
So the line statistics are not a casualty map. It is a warning sign at the counter that people are late for.
17. The hidden cost is the action in the same channel
A fraudulent message or call often does not win by being perfectly genuine. It wins by shortening the path between fear and action. It will not allow one to leave the channel. The call continues, the SMS adds a link, the email offers a button, the alleged banker dictates the next step. Everything happens in the same pipe where the pressure was created.
The hidden cost is not only monetary damage. It is also the confusion after the event. Who to call? What is authorized? What is unauthorized? What does an MFA mean? Who decides the dispute? Why do the police talk about clarity and the bank about capture? Why does NÚKIB count incidents and CBA clients? The later we resolve these differences, the more expensive they are.
This does not mean that one has to know all the statistics. It means that it should have one rule stronger than the mask: I don't validate the action in the channel that requests it. A number, logo, voice, urgency, or correct personal information alone are not enough. Data, code, MFA, transfer and remote access belong to the second channel.
This rule is boring, which is why it works even under normal pressure.
So the question is not how to recognise a fraudulent email, SMS or phone call based on whether it looks like a bank. It is: which action are you willing to confirm in the same channel without a second, previously known verification? If the answer is "none", it is not a matter of mistrust of the world. It's about the exact location of the control.
Related texts in this series
- How to find out if your password or email has been leaked? — a leak in the index is not the same channel as an emergency call.
- In the folder: Deepfake of a familiar voice — voice is no longer a seal of identity; this text takes e-mail, SMS and call as three channels of pressure.
