October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Banco do Brasil

Fake Banco do Brasil SMS Messages: How to Spot Them and What to Do

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fake text messages impersonating Banco do Brasil (BB) are an SMS-phishing, or “smishing,” threat. They may claim that a purchase is suspicious, an account is blocked, loyalty points are expiring, or a security update is required. The goal is to make you click, call, install software, reveal credentials, or authorize a transaction.

BB’s published guidance supports an ongoing impersonation threat, not a confirmed new BB data breach, a single mass campaign, or a verified victim or loss total. Treat the message as untrusted and verify everything through an app or website you open independently.

How the Banco do Brasil SMS scam works

A criminal sends an SMS designed to look like it came from BB. The message creates fear, urgency, or a tempting benefit, then gives you an instruction that moves the conversation outside your normal banking routine.

  1. The text claims there is a suspicious transaction, blocked card or account, expiring points, security problem, promotion, or prize.
  2. It provides a link, callback number, WhatsApp contact, or request to install a “security” application.
  3. You are sent to a lookalike BB page or a fraudulent call center.
  4. The criminal collects your agency, account, CPF, password, card details, one-time code, or device access.
  5. Those details may be used for account access, Pix or other transfers, bill payments, withdrawals, card fraud, or a second-stage impersonation call.

BB describes phishing as a fake message that leads to a page resembling the bank’s site and persuades the victim to enter banking credentials. See BB’s explanation of common scams.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A message can be fraudulent even when it has no link. Some scams ask you to call first, then move the interaction to a fake support center or WhatsApp. A genuine transaction alert can also be followed by a criminal who uses that information to sound convincing.

Claims commonly used in fake messages

  • “Suspicious” purchases, payments, Pix transfers, or card transactions.
  • Immediate account or card blocking.
  • A mandatory registration, security, or contact-information update.
  • Loyalty points that expire today or a special redemption offer.
  • A prize, discount, refund, or other benefit.
  • A request to call a supposed security department.
  • An instruction to cancel or reverse a transaction, boleto, or purchase.
  • A request to install a security app, browser component, or remote-access tool.

Banco Central do Brasil warns that fake employees may direct customers to an app, link, document, or “cancellation” procedure that actually authorizes a payment or compromises the device. Its guidance is available at bcb.gov.br/meubc/faqs/s/golpes.

Which BB SMS identifiers are current?

In guidance published by BB and current as of August 18, 2026, the bank identifies 4004-0001 (without an area code) for transactional SMS. Since April 2025, promotional texts may appear as BB INFORMA without a visible telephone number.

These are indicators, not proof. Sender-ID spoofing can make a fraudulent text display a familiar number or name. Conversely, an unexpected message from a recognized sender can still be part of a scam. BB says its SMS messages do not ask for passwords or personal or financial information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Warning signs to check before doing anything

  • Urgency or threats: same-day deadlines, immediate suspension, or demands that you act while staying on the line.
  • A link or callback number: especially a shortened URL, lookalike domain, or number supplied only in the text.
  • Requests for secrets: passwords, full card data, CPF, authentication codes, or other confidential information.
  • Software or remote access: instructions to install an app, browser extension, configuration profile, or screen-sharing tool.
  • A payment instruction: requests to transfer money, make a “test,” cancel a purchase, or send funds to protect your account.
  • Branding without independent confirmation: logos, polished language, correct personal details, and good spelling can all be copied.

Do not assume that a sender name, logo, or absence of spelling errors makes a message genuine.

Safe checks for a message you have received

  1. Do not use the message. Do not tap its link, reply, call its number, or download anything.
  2. Open BB independently. Launch the official BB app from your phone’s installed apps, or type bb.com.br yourself or use a saved bookmark. Check transactions and alerts there.
  3. Compare the context. If the app shows no matching event, treat the SMS as suspicious. Even if it does show one, contact BB through an official channel rather than replying to the text.
  4. Inspect the address only without opening it. BB advises using bb.com.br and warns about lookalike domains; a similar spelling or extra domain ending is not BB.
  5. Remember that sender verification is limited. Spoofing means the displayed sender cannot authenticate the message.

What to do when you only received the SMS

  1. Take a screenshot that includes the sender, message, link or number, and time.
  2. Do not click, call, reply, enter data, or install software.
  3. Check your account in the independently opened BB app.
  4. Forward the suspicious SMS to 7726, the carrier spam-reporting short code.
  5. Send links, pages, or messages impersonating BB to [email protected].
  6. After preserving evidence, delete and block the sender.

Reporting a message helps flag a campaign but does not secure an account if credentials or money have already been exposed.

If you clicked the link

Clicked but entered nothing

  • Close the page and do not download or install anything.
  • Update the phone’s operating system and security software.
  • Check for newly installed apps, configuration profiles, accessibility permissions, browser extensions, or device administrators.
  • Monitor BB and other accounts that may share passwords.
  • If you are unsure whether data was entered or copied, change affected passwords from a trusted device.

Entered credentials or personal information

  • Contact BB immediately through a number or channel obtained independently.
  • From a clean device, change banking and email passwords first, then any reused passwords.
  • Review account access, scheduled payments, Pix keys, beneficiaries, loans, cards, and authorized devices.
  • Enable available protections, including BB Code where appropriate.
  • Expect follow-up calls claiming to be BB security; do not disclose more information or approve a “verification” transfer.

BB’s assistance guidance is at its security help page.

Installed an app or remote-access tool

  • If active compromise is possible, disconnect the phone from the internet.
  • Stop using that device for banking until it has been checked.
  • Document the suspicious software and permissions before removing it if evidence may be needed.
  • Contact BB from a different trusted device.
  • Change passwords from a clean device and revoke unknown sessions or device authorizations.
  • Consider professional assistance or a factory reset when malware or remote control was installed, after preserving essential evidence and arranging secure backups.

Deleting an app alone does not prove that a device or account is safe.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If money was transferred or a transaction is unauthorized

  1. Contact BB immediately and request fraud intervention and attempted recovery.
  2. If funds went to another bank, notify the receiving institution immediately as well.
  3. Preserve the SMS, URL, phone numbers, screenshots, receipts, Pix details, timestamps, and conversation history.
  4. Ask BB for a service or fraud protocol number and keep every communication.
  5. File a police report (boletim de ocorrência).

Fast reporting may allow attempts to recover transferred funds, but reimbursement is not guaranteed. The outcome depends on the transaction, timing, authentication, evidence, bank investigation, and applicable Brazilian rules.

How the false-central follow-up scam works

After a text, a criminal may call pretending to be BB’s security team. The caller may quote the transaction in the SMS, claim the account is under attack, and instruct you to “cancel” a purchase, move money to a safe account, read out a code, or install remote-access software. BB’s July 22, 2026 publication notes that false-central scams can begin through phone, WhatsApp, or SMS and use spoofing; see BB’s current warning.

End the call and make contact yourself through the official app, bb.com.br, or a verified number. Never authorize a test, cancellation, or security transfer because an incoming caller told you to.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Official BB channels (verify before calling)

Use BB’s own website to confirm current contact details. The bank’s published security-help page lists:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Purpose Channel Qualification
Relationship center 4004-0001 Capital cities
Relationship center 0800-729-0001 Other locations
SAC 0800-729-0722 Customer service
Ouvidoria 0800-729-5678 Ombudsman channel
WhatsApp 61 4004-0001 BB-listed WhatsApp channel
Impersonation reports [email protected] Send suspicious BB links, pages, or messages
Spam reports 7726 Forward suspicious SMS to your carrier’s reporting short code

These channels are reproduced from BB’s security assistance guidance. Do not obtain a contact number from the suspicious SMS itself.

What this threat does—and does not—show

  • Impersonation: criminals send messages that imitate BB.
  • Credential theft or malware: a victim may disclose data or compromise a device.
  • Bank breach: the available guidance does not establish that BB’s systems were hacked, nor does it provide a verified campaign size or loss total.

The safest response is procedural: ignore the instructions embedded in the SMS, verify through an independently opened BB channel, preserve evidence, and report quickly when data or money may be at risk.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.