Which? warns of bank impersonation scam using one-time passcodes

Which? has reported how a Barclays customer was defrauded after a genuine fraud call from the bank primed them to trust a later scam call asking for one-time passcodes.

Which? published a case on 4 May 2026 in which a reader from East Yorkshire was defrauded after a genuine call from Barclays' fraud team was followed by a scam call claiming to be from the same bank1.

The reader's account states that the first call was genuine: after hanging up and calling the number on the back of their card, they found £120 had been spent at Sainsbury's, were reimbursed and had the card cancelled1. A new card arrived, and two days later a second caller, claiming to be from Barclays, asked whether the reader recognised a £589 Deliveroo transaction1. The caller said the team would cancel it and that the reader needed to hand over one-time passcodes (OTPs) sent by text to stop other fraudulent transactions1.

The reader challenged the request because the texts warned not to share the code, but the caller said the reader knew it was Barclays because the bank had contacted them before1. The reader said:

"I gave him the OTPs. When another OTP arrived for a payment of over £900, I was suspicious and hung up."
Which?, 4 May 20261

Faye Lipson, a senior researcher at Which?, said the fraudster probably had the original card details and phone number throughout, and may have obtained the replacement card's long number through an automatic billing updater1. She said the information may have been stolen in a data breach or gathered in an earlier scam, and that the initial genuine call primed the reader for the scam call1. The reader has since spoken to Barclays and agreed additional security measures for phone calls1.

Which? advises that anyone receiving a call claiming to be from their bank should hang up and call 159, which connects to the bank, using a different phone line or waiting at least 15 minutes in case the scammer is still connected1. It says scam attempts can be reported to reportfraud.police.uk, or by calling 101 in Scotland1. The article does not state how much was lost in total, whether the reader was reimbursed for the later transactions, or whether Barclays has commented.

Why it matters for households

The case turns on a detail that makes bank impersonation fraud harder to spot: the first call was real. A household that has genuinely been contacted by its bank's fraud team may treat a later call as trustworthy, which is what the reader describes happening here1. The sums involved in the reported case were £120 spent at Sainsbury's, a £589 Deliveroo transaction the reader did not recognise, and a further payment of over £900 for which an OTP arrived before the reader hung up1.

The practical point is that a one-time passcode is the last step in authorising a payment. Which? reports that the scammer asked for OTPs on the basis that they were needed to cancel transactions, and that the reader handed them over1. Its guidance is that a bank call should be ended and the bank contacted on 159, from a different line or after at least 15 minutes1. The article does not set out what a bank will or will not ask for, beyond the reader's account that the texts themselves said not to share the code1.

What happens next

Which? says the reader has agreed additional security measures with Barclays for phone calls1. No further steps, dates or outcomes have been reported. Which? invites readers to report scam attempts to reportfraud.police.uk, or to call 101 in Scotland, and to send scams stories to yourstory@which.co.uk1.

Sources1 cited
  1. Scam watch: 'I was sent a one-time passcode from my bank' - Which? which.co.uk