Back to news
Cybersecurity Alert
September 12, 2026 by EmailMeNow IT Consulting

Fake Chase ‘Card Hold’ Texts Ask You to Call a 10-Digit Number

A Chase-branded card-hold text hit a real Chase customer on the number tied to that account — coincidence or a purchased/stolen pairing, not proof Chase was hacked. Real Chase fraud SMS uses short codes. Audits (ideal 100%): ic3.gov 87%, chase.com 79%, jpmorganchase.com 65%, cruzovote.com 29%.

Source: Chase · EmailMeNow field sample

NewsPhishingSmishingChaseBanksMFAYubiKeyAuthenticator AppsCybersecurity
Smartphone showing a redacted Chase card-hold text with a sticky note that says type the app yourself

A Chase-branded text we reviewed on September 12, 2026 claimed “Monitor Alert / Fraud detection activated,” said a card hold was in place, and demanded immediate verification — then ended with a 10-digit callback, not a Chase short code. The lure landed on a real Chase customer, on the mobile number associated with that account. That pairing can be coincidence (a Chase-branded spray that happened to hit a Chase household) or a purchased / stolen bank-plus-phone list. It is not proof Chase was hacked, and Chase is not reported breached. This is smishing: a fake bank text meant to get you on the phone or into a fake portal.

This is not a duplicate of the national bank MFA scorecard (login methods), Chameleon search phishing (fake results in Google/Bing), WindRelay / SpyNote (sideloaded RAT), or the May $300K text-scheme recap. Those are different delivery paths.

Recipient phone numbers, mailbox local-parts, and other personal identifiers from the sample are redacted. We do not publish the callback.

Smartphone showing a redacted Chase card-hold text with a sticky note that says type the app yourself

Snapshot

FieldDetail
PatternFake Chase card-hold SMS + 10-digit callback
TargetingHit a real Chase customer on the number on file
How they knewCoincidence (spray) or a bought/stolen pairing — not a confirmed Chase hack
Real Chase SMSShort codes such as 28107, 36640, 72166
Chase statusNot reported breached
CourtListenerNo matching card-hold SMS dockets as of Sept 12, 2026

Chase’s own self-service SMS terms say fraud and account-security texts come from 5- or 6-digit short codes. If a message looks odd, Chase says do not reply — call the number on the back of the card or on the statement.

What the lure looks like

The body mashed several scare words together: monitor alert, fraud detection, card hold, immediate verification. There was no Chase short code. The thread was not from 28107, 36640, or 72166.

The sending side used a mailbox on an unrelated domain (cruzovote.com) that has nothing to do with Chase. We are not reprinting the full address. Treat any “Chase” text that arrives from a random .com mailbox, a 10-digit number, or a saved-contact label as unverified.

They already knew the bank and the number

What made this sample sting is not only the wording. The scammers named Chase and reached the phone number tied to that Chase account. From one text we cannot tell whether they:

  • Guessed and got lucky — mass “Chase card hold” texts to large number lists, and this recipient really banks at Chase, or
  • Already had the pairing — a data-broker file, an older breach dump, a prior phish, or another leak that listed “Chase customer + this mobile.”

Knowing the bank and the number on file is not the same as being the bank. It is a standard way to make a 10-digit callback feel “verified.” It does not mean Chase sent the SMS. It does not mean Chase’s systems were hacked. It does mean you should not treat a correctly branded text as authentic just because it arrived on the line you gave the bank.

A real Chase fraud text, per Chase’s public short-code page, is an interactive YES/NO about a specific charge. It does not tell you to call a random 10-digit line to “release” a hold.

Printed SMS with phone numbers redacted beside a note that real Chase uses short codes

What to do

  1. Do not call the number in the text. Do not reply YES, NO, or STOP to a 10-digit “Chase” line you did not save as the bank. A text that correctly names your bank and arrives on the number the bank has is still a scam if it is not from a Chase short code.
  2. Open the Chase app you already have, or type chase.com yourself. Check alerts there.
  3. If you need a human, use the number on the back of the card.
  4. Forward a scam text to 7726 (SPAM). You can also report at IC3 and ReportFraud.ftc.gov.
  5. If you already called or read a one-time code: freeze the card in the app, change the Chase password on a host you typed, and tell the bank.

MFA: YubiKey and Google Authenticator

A hardware key does not stop you from reading a code to a stranger on a callback. It does cut a lot of the follow-on fake-login sites that show up after a “card hold” text. Grades match our MFA directory.

GradeMeaning
FailDocumented second factor is SMS, voice, or email OTP — or no public path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
ChaseFailNoNo
Bank of AmericaStrongYesNo

Chase documents passkeys and still documents phone / email OTP. That stays Fail under the SIM-swap rule. There is no public retail YubiKey or Google Authenticator path. Bank of America documents a USB security key — Strong. Neither grade stops a voice callback.

Directory: MFA support directory · Category → Banks.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a face-down debit card

Independent cybersecurity audits

We audited the official Chase, JPMorgan Chase, reporting, and sender-mailbox hosts on September 12, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean Chase was breached.

OrganizationDomainOverallvs 100%
FBI IC3ic3.gov87%−13
Chasechase.com79%−21
JPMorgan Chasejpmorganchase.com65%−35
Sender mailbox hostcruzovote.com29%−71
DomainIdentityTransportWebsite
ic3.gov90%45%97%
chase.com75%15%94%
jpmorganchase.com90%15%40%
cruzovote.com0%15%40%

Audit links: ic3.gov · chase.com · jpmorganchase.com · cruzovote.com

chase.com at 79% is still −21 from the ideal. Transport 15% is the familiar Chase mail-transport gap — not a reason to trust a 10-digit “fraud” callback. cruzovote.com Identity 0% and no MX / web IPs in the blacklist probe mean it is a weak mailbox host, not a Chase property. ic3.gov is the reporting host.

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on September 12, 2026:

DomainStack signal
chase.comNext.js; DigiCert TLS expires 2027-03-25
jpmorganchase.comStack undetected; DigiCert TLS expires 2026-12-20
cruzovote.comStack undetected; HTTP→HTTPS redirect not confirmed
ic3.govStack undetected; DigiCert TLS expires 2027-01-05

Point-in-time only. A live bank homepage is not a forensic finding on the SMS path.

Blacklist and lookalike domains

Email blacklist checks (public DoH, September 12, 2026): chase.com, jpmorganchase.com, and ic3.gov were clear on mail/domain lists we can query. Chase and JPMorgan web/CDN IPs showed informational SPFBL notes — not mail-reputation hits. Do not lead as “Chase is blacklisted.” cruzovote.com returned no_ips (no MX/web addresses in the probe).

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
chase.com9702
jpmorganchase.com4200
ic3.gov1501
cruzovote.com100

High-interest registered names (investigate; not proof this text used them):

LookalikeTechniqueNote
chase.iotld-swapBEC staging (NS + MX)
chasen.cominsertionBEC staging (NS + MX)
ic3.comtld-swapBEC staging — not the .gov bureau
cruzvote.comomissionLive NS + A + MX — not Chase

Type chase.com, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing response aimed at the 100% ideal.


Sources: Chase self-service SMS terms · Chase how you can protect yourself · Bank of America USB security key · EmailMeNow field sample September 12, 2026 (personal numbers and mailbox local-parts redacted). Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 12, 2026. Domain scores: audit.emailmenow.com only.