A Chase-branded text we reviewed on September 12, 2026 claimed “Monitor Alert / Fraud detection activated,” said a card hold was in place, and demanded immediate verification — then ended with a 10-digit callback, not a Chase short code. The lure landed on a real Chase customer, on the mobile number associated with that account. That pairing can be coincidence (a Chase-branded spray that happened to hit a Chase household) or a purchased / stolen bank-plus-phone list. It is not proof Chase was hacked, and Chase is not reported breached. This is smishing: a fake bank text meant to get you on the phone or into a fake portal.
This is not a duplicate of the national bank MFA scorecard (login methods), Chameleon search phishing (fake results in Google/Bing), WindRelay / SpyNote (sideloaded RAT), or the May $300K text-scheme recap. Those are different delivery paths.
Recipient phone numbers, mailbox local-parts, and other personal identifiers from the sample are redacted. We do not publish the callback.

Snapshot
| Field | Detail |
|---|---|
| Pattern | Fake Chase card-hold SMS + 10-digit callback |
| Targeting | Hit a real Chase customer on the number on file |
| How they knew | Coincidence (spray) or a bought/stolen pairing — not a confirmed Chase hack |
| Real Chase SMS | Short codes such as 28107, 36640, 72166 |
| Chase status | Not reported breached |
| CourtListener | No matching card-hold SMS dockets as of Sept 12, 2026 |
Chase’s own self-service SMS terms say fraud and account-security texts come from 5- or 6-digit short codes. If a message looks odd, Chase says do not reply — call the number on the back of the card or on the statement.
What the lure looks like
The body mashed several scare words together: monitor alert, fraud detection, card hold, immediate verification. There was no Chase short code. The thread was not from 28107, 36640, or 72166.
The sending side used a mailbox on an unrelated domain (cruzovote.com) that has nothing to do with Chase. We are not reprinting the full address. Treat any “Chase” text that arrives from a random .com mailbox, a 10-digit number, or a saved-contact label as unverified.
They already knew the bank and the number
What made this sample sting is not only the wording. The scammers named Chase and reached the phone number tied to that Chase account. From one text we cannot tell whether they:
- Guessed and got lucky — mass “Chase card hold” texts to large number lists, and this recipient really banks at Chase, or
- Already had the pairing — a data-broker file, an older breach dump, a prior phish, or another leak that listed “Chase customer + this mobile.”
Knowing the bank and the number on file is not the same as being the bank. It is a standard way to make a 10-digit callback feel “verified.” It does not mean Chase sent the SMS. It does not mean Chase’s systems were hacked. It does mean you should not treat a correctly branded text as authentic just because it arrived on the line you gave the bank.
A real Chase fraud text, per Chase’s public short-code page, is an interactive YES/NO about a specific charge. It does not tell you to call a random 10-digit line to “release” a hold.

What to do
- Do not call the number in the text. Do not reply YES, NO, or STOP to a 10-digit “Chase” line you did not save as the bank. A text that correctly names your bank and arrives on the number the bank has is still a scam if it is not from a Chase short code.
- Open the Chase app you already have, or type chase.com yourself. Check alerts there.
- If you need a human, use the number on the back of the card.
- Forward a scam text to 7726 (SPAM). You can also report at IC3 and ReportFraud.ftc.gov.
- If you already called or read a one-time code: freeze the card in the app, change the Chase password on a host you typed, and tell the bank.
MFA: YubiKey and Google Authenticator
A hardware key does not stop you from reading a code to a stranger on a callback. It does cut a lot of the follow-on fake-login sites that show up after a “card hold” text. Grades match our MFA directory.
| Grade | Meaning |
|---|---|
| Fail | Documented second factor is SMS, voice, or email OTP — or no public path |
| Pass | Self-serve Google Authenticator-style open TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| Chase | Fail | No | No |
| Bank of America | Strong | Yes | No |
Chase documents passkeys and still documents phone / email OTP. That stays Fail under the SIM-swap rule. There is no public retail YubiKey or Google Authenticator path. Bank of America documents a USB security key — Strong. Neither grade stops a voice callback.
Directory: MFA support directory · Category → Banks.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited the official Chase, JPMorgan Chase, reporting, and sender-mailbox hosts on September 12, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean Chase was breached.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| FBI IC3 | ic3.gov | 87% | −13 |
| Chase | chase.com | 79% | −21 |
| JPMorgan Chase | jpmorganchase.com | 65% | −35 |
| Sender mailbox host | cruzovote.com | 29% | −71 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| ic3.gov | 90% | 45% | 97% |
| chase.com | 75% | 15% | 94% |
| jpmorganchase.com | 90% | 15% | 40% |
| cruzovote.com | 0% | 15% | 40% |
Audit links: ic3.gov · chase.com · jpmorganchase.com · cruzovote.com
chase.com at 79% is still −21 from the ideal. Transport 15% is the familiar Chase mail-transport gap — not a reason to trust a 10-digit “fraud” callback. cruzovote.com Identity 0% and no MX / web IPs in the blacklist probe mean it is a weak mailbox host, not a Chase property. ic3.gov is the reporting host.

Website stack note
Passive website-tech probes on September 12, 2026:
| Domain | Stack signal |
|---|---|
| chase.com | Next.js; DigiCert TLS expires 2027-03-25 |
| jpmorganchase.com | Stack undetected; DigiCert TLS expires 2026-12-20 |
| cruzovote.com | Stack undetected; HTTP→HTTPS redirect not confirmed |
| ic3.gov | Stack undetected; DigiCert TLS expires 2027-01-05 |
Point-in-time only. A live bank homepage is not a forensic finding on the SMS path.
Blacklist and lookalike domains
Email blacklist checks (public DoH, September 12, 2026): chase.com, jpmorganchase.com, and ic3.gov were clear on mail/domain lists we can query. Chase and JPMorgan web/CDN IPs showed informational SPFBL notes — not mail-reputation hits. Do not lead as “Chase is blacklisted.” cruzovote.com returned no_ips (no MX/web addresses in the probe).
DNS lookalike scans (BEC profile, registered signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| chase.com | 97 | 0 | 2 |
| jpmorganchase.com | 42 | 0 | 0 |
| ic3.gov | 15 | 0 | 1 |
| cruzovote.com | 1 | 0 | 0 |
High-interest registered names (investigate; not proof this text used them):
| Lookalike | Technique | Note |
|---|---|---|
| chase.io | tld-swap | BEC staging (NS + MX) |
| chasen.com | insertion | BEC staging (NS + MX) |
| ic3.com | tld-swap | BEC staging — not the .gov bureau |
| cruzvote.com | omission | Live NS + A + MX — not Chase |
Type chase.com, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- National banks MFA — SMS vs YubiKey
- Chameleon SEO poisoning — fake bank logins in search
- WindRelay / SpyNote Android NFC relay
- FaceTime bank scam
- MFA support directory
Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing response aimed at the 100% ideal.
Sources: Chase self-service SMS terms · Chase how you can protect yourself · Bank of America USB security key · EmailMeNow field sample September 12, 2026 (personal numbers and mailbox local-parts redacted). Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 12, 2026. Domain scores: audit.emailmenow.com only.