Filed under: Banks, tax & authorities

Is this 'your card is locked, reply YES/NO' text a scam?

Last reviewed: 2026-08-01 · Checked with Hunch’s on-device engine, the same one inside the extension. How Hunch checks →

Part of our guide: How to recognize a bank-impersonation scam →

Yes. That 'card locked, reply YES if this was you or verify within 24 hours to unlock' text pointing at card-secure.example is a bank impersonation. Your actual issuer confirms charges through its app alert or the phone number printed on your card, and it would never unlock anything on a look-alike page. Replying YES or NO does nothing but tell the sender your number is live, and the 'unlock' link is where they steal your login.

Got a message like this? Paste it here →

Detection runs 100% locally on your device. We store nothing.

Please don’t paste other people’s personal data. Detection runs 100% locally on your device, and we store nothing.

Or check it on Telegram

Cardholders who've had a real fraud-lock before will find this eerily familiar, which is exactly why it works. The 'reply YES/NO' option feels harmless and even helpful, so people engage, validating their number and lowering their guard for the 'unlock' link. The scam trades on the mild panic of a frozen card and the desire to fix it in one quick tap before a shop, a bill, or a deadline.

The exhibit
EXHIBIT · CHECK BEFORE YOU ENTER YOUR PASSWORD.
Received via: SMS EN
Your card was locked for your protection. Reply YES if this was you, or verify your account within 24 hours to unlock it: card-secure.exampleunexpected domain, verify where it really leads/unlock

Illustrative example of the pattern, not a real message someone received.

How to verify it yourself

  • Don't reply YES or NO, a response only tells the sender your number is active.
  • Call the number printed on the back of your card and ask if anything is actually locked.
  • Use your bank's official app to check card status, never the card-secure.example link.
  • Real issuers don't ask you to 'verify your account' on an outside domain to unlock a card.

Common questions

is card-secure.example my bank's real unlock page

No. Banks use their own domains and apps. A generic 'card-secure' on .top is a spoof built to capture the credentials you enter to 'unlock' the card.

should I reply YES to a card locked text

No. Replying anything confirms a real person reads that number, which invites more scam texts. Verify only through your bank's official app or the number on your card.

does a bank unlock your card through a link

No. Card locks are managed inside the bank's app or by phone with the number on your card, never on a link from a text with a deadline.

is 'your card is locked' text a scam

Yes, when paired with a reply-YES/NO prompt, a look-alike link, and a 24-hour clock. Those are the signs of card-lock smishing.

If you already responded

  1. If you entered card or login details, call the number on your card and have it frozen or reissued.
  2. Change reused passwords, enable two-factor authentication, and review recent transactions.
  3. Report the text at reportfraud.ftc.gov.

Source: FTC, How To Recognize and Avoid Phishing Scams