Coffee Time with Tracer
The headquarters door refused to open.
Not “slightly difficult.” Not “try the handle again.” The keypad had gone completely silent, apparently choosing that morning to retire from public service.
I stood outside with a bag of pastries in one hand and a thermos in the other. The pastries were beginning to tilt. My patience was doing the same.
After three failed codes, I tried the emergency key. The lock flashed a red light and made a sound that felt less like a warning and more like laughter.
Then my phone rang.
The caller said they were from my bank’s fraud department.
They knew I was traveling. They knew the country. They even knew the town.
That is the kind of detail that makes a scammer sound legitimate. It also creates the perfect opening for one of the most dangerous bank-impersonation tricks now targeting travelers, retirees, seniors, and busy families: the two-caller relay scam.
Are you being contacted about suspicious purchases while you are overseas? Before you say anything, stop. The fact that the caller knows where you are does not prove the call is from your bank.

How the Two-Caller Relay Scam Works
This scam uses two criminals working together.
The first caller focuses on you. The second caller contacts your real bank. Their goal is to place you between the bank and the authorization code.
Here is the pattern.
1. Caller One creates fear
The first scammer claims to be a fraud specialist. The scammer says something like this:
- “We see suspicious purchases on your account.”
- “Your card is being used overseas.”
- “Did you just authorize these transactions?”
- “We need to secure your account immediately.”
The caller already knows you are traveling. They know your destination and recent movements. That information is used to make the story feel personal and urgent.
2. Caller One keeps you occupied
The scammer asks questions, makes small talk, and places you on hold while they supposedly “review” the account.
This is not casual conversation. It is a distraction.
While you remain engaged, the second scammer calls the real bank and pretends to be you. They request changes to your account, reset access, add a new contact, or initiate another action that requires verification.
3. The real bank sends a real code
Because the second scammer is interacting with the real bank, the bank sends a legitimate one-time verification code to the phone number it has on file. That code is the bank's standard way of proving the person on the other end of the line is really you.
The message is real. It is the code the bank uses to confirm that the caller is the account holder — which is exactly why the scammers need you to read it back to them.
That is what makes this scam so effective.
Caller One then tells you:
“You should receive a code shortly. Please read it back so I can authenticate you and stop the fraud.”
4. You read the code aloud
The code is not proving your identity to the first caller.
It is authorizing the action the second scammer just started with the real bank.
When you read the code aloud, Caller One relays it to Caller Two. Caller Two gives the legitimate code to the bank.
The bank’s system then treats the second scammer as an authenticated customer.
Depending on the bank’s controls and the information already available to the criminals, the scammer can gain access to account-management functions, change contact details, reset credentials, add payees, or attempt transfers. Additional security checks can still stop them, but the code opens a critical door.
That is the relay.
The first scammer handles the human conversation. The second handles the real bank. The code travels between them through you.
Why Knowing Your Travel Location Makes the Call Believable
The victim in this type of story may reasonably wonder:
How did they know the country and town I was visiting?
One possibility is public travel information.
Many people post airport photos, hotel views, restaurant visits, landmarks, street scenes, and vacation updates while they are still traveling. Even without a location tag, those images may contain clues:
- Recognizable buildings or monuments
- Road signs and language
- Transit systems
- Hotel or resort details
- Landscapes and architecture
- Time of day and local weather
- Reflections, menus, or business names
Recent research reported by McAfee examined how artificial intelligence can infer locations from travel photos, even after GPS and EXIF metadata are removed. On its curated travel-photo dataset, one tested model identified the city and country with up to 91 percent accuracy.
That does not mean every random photograph can be located correctly 91 percent of the time. Travel images often contain landmarks and distinctive visual clues. Accuracy can be lower with ordinary, generic photographs.
But criminals do not need perfect accuracy. They need enough correct information to make one call sound convincing.
A scammer scrapes a public photo, uses AI to estimate where it was taken, and then calls with a carefully timed story:
“We noticed unusual card activity in the town where you are staying.”
If you are actually in that town, your defenses may drop. The caller appears to know something only your bank should know.
They may have learned it from your social media.

The Moment You Should Know Something Is Wrong
Here is the rule to remember:
If you receive an unsolicited call, the caller pressures you to stay on the line, and asks you to read back a code tied to a change, reset, or transaction you did not initiate, something is wrong.
Banks and other legitimate companies do sometimes ask customers to read back a code they just sent during a customer-initiated verification process.
The red flag is the context.
If you did not request the change, reset, or transaction, do not read the code. If a code arrives unexpectedly, treat it as a warning sign and verify through an official channel.
A legitimate SMS code can still be part of a scam. The message may genuinely come from your bank because the criminals triggered it through the real banking system.
The message is real. The caller is not.
The FDIC warns consumers to call the bank directly using a trusted number, such as the number printed on a debit or credit card. Wells Fargo gives similar guidance and specifically says not to use or share a one-time access code for a transaction you did not initiate, even when the person claims to work for the bank.
Other warning signs include:
- The caller pressures you to act immediately.
- They insist you stay on the line.
- They discourage you from calling the bank yourself.
- They ask for a password, PIN, Social Security number, or verification code.
- They tell you to move money to a “safe” account.
- A second caller suddenly joins as a supervisor or security specialist.
- Caller ID displays your bank’s name or familiar number.
Caller ID can be spoofed. A genuine bank text does not make an incoming call genuine.
Five Practical Ways to Protect Yourself
1. Hang up and call the number on your card
Do not call a number supplied by the caller, text message, or email. Use the number printed on the back of your bank card, a statement you already trust, or the bank’s official app.
You can also open the bank’s app directly and review alerts there.
2. Never read a verification code aloud
Treat every one-time passcode as private. If you receive a code for an action you did not initiate, do not share it and do not enter it anywhere. Contact the bank through an independently verified channel.
3. Post travel photos after returning
Avoid announcing your exact location in real time. Review privacy settings on social media and limit vacation posts to trusted contacts.
Removing metadata is still useful, but it is not enough by itself. AI may infer location from the visible content of an image.
4. Use in-app fraud alerts when possible
If your bank offers fraud reporting or secure messaging inside its official application, start there instead of trusting an unexpected inbound call.
Do not open the app through a link in a suspicious message. Open it directly from your device.
5. Add another layer of verification
Ask your bank whether it supports stronger options, such as app-based authentication, transaction limits, account alerts, or a hardware security key. A second verification method may reduce reliance on SMS alone.
If you already shared a code, contact your bank immediately through the official number. Ask them to secure the account, review recent activity, change online-banking credentials, check contact information, and block or investigate unauthorized transactions. If the same password was used elsewhere, change it there too.

Tracer’s Pick Giveaway
I keep a rotating Tracer’s Pick ready for community members who stay alert and share useful security lessons.
If this article helped you recognize a dangerous call pattern, drop a comment for a shot at being selected. No purchase is necessary. The goal is awareness, knowledge, and protection across the entire community.
For questions about privacy concerns, digital exposure, or possible unauthorized access, contact Patricia at 321-342-0040. FindASpy’s services include cyber consultation, spyware and breach removal, secure-phone assistance, and professional support for privacy concerns.
You can also learn more about the team on our About Us page, review available security equipment in All Products, or explore the Community Finds submitted by other readers.
Important Disclaimer
This article is for general education and scam-awareness purposes. It is not banking, legal, financial, or law-enforcement advice. Scam methods and bank procedures vary. If you suspect fraud, contact your financial institution immediately through an official, independently verified channel. If money has been lost or your identity has been misused, report the incident to the appropriate authorities and preserve relevant messages, phone numbers, screenshots, and transaction records.
Community Conversation
Have you or someone you know received a “fraud department” call while traveling? Did the caller know a detail that made the story sound real?
Tell us which State you are writing from and share your experience without posting account numbers, passwords, verification codes, or other sensitive information.
What would your first reaction be if the SMS code looked completely legitimate? Would you hang up immediately, open your bank app, or call a trusted family member first?
Tracer reads all posts.
If you have found a hidden camera, tracker, suspicious device, or other unusual gadget, protect your personal information and upload it to share with the community by clicking here.
Lesson
A real code can be used in a fake conversation. The message may be genuine, but the person requesting it may be a criminal. If you did not initiate the change, reset, or transaction, do not read the code to an unsolicited caller. Hang up and call the number on your card.
Coffee Challenge
Before your next trip, save your bank’s official phone number in your contacts. Then tell one trusted person your family rule:
“If someone calls about my money, I hang up and call the bank myself.”
Tomorrow’s Hint
Tomorrow, Tracer looks at another way criminals turn ordinary personal information into a convincing emergency. Until then, stop, independently verify the situation, and contact someone you trust before sending money, installing software, or sharing information. And if you have a hidden gadget to report, upload it through the Community Finds page.
How important was this article?
Your vote helps determine FindASpy Insider’s Readers’ Top Picks. One rating is allowed per reader for each article.
Today’s Coffee Conversation
Tracer shares cybersecurity stories, scam alerts, privacy tips, and investigative insights. Pull up a chair, share your experience, and help shape tomorrow’s discussion.