Security
Spotting a Scam Before It Costs You
Every fraud attempt runs the same play: manufacture urgency, then ask you to move money or hand over a code. Learn the pattern and the tactics stop working.

Losses to text-message fraud alone are now measured in the hundreds of millions a year.
Scams do not usually succeed because the victim was careless. They succeed because a competent adult was rushed. Every version of this, whether it arrives by email, text, phone, or a pop-up, is built around the same three-beat structure: establish authority, create urgency, and request an action that is difficult to reverse.
Learn to hear that rhythm and the specific details stop mattering.
The one rule that covers most of it
Summit will never call, text, or email you to ask for your password, your full account number, your card's CVV, or a one-time verification code. Not during a fraud investigation, not to verify your identity, not ever, under any circumstance we can construct.
That last item, the one-time code, is where most account takeovers now happen. A criminal who already has your username and password triggers a login, which sends a code to your phone. Then they call, claim to be the fraud department, and ask you to read back "the code we just sent to verify it is you." The code is the last lock on the door. Reading it aloud opens it.
What Summit will and will not ask
We may call about unusual card activity and ask you to confirm whether a specific transaction was yours. We will never ask for a password, a PIN, a full card number, a CVV, or a verification code. We will never ask you to move money to a "safe account," install remote-access software, or buy gift cards. If any of those come up, the call is not from us.
Phishing email
The classic. An email that appears to come from your financial institution, a delivery service, or a familiar retailer, warning that your account is suspended, a payment failed, or a package could not be delivered. The link goes to a login page that is a pixel-accurate copy of the real one, and whatever you type there goes straight to the person who built it.
The reliable tell is the sender's actual address, not the display name. Hover over it, or tap and hold on a phone, and read the domain after the @ symbol. Anything with an extra word, a hyphen, or a different top-level domain is fake. Attachments you did not expect are also a strong signal, particularly .zip, .html, or macro-enabled Office documents.
Grammar errors used to be a giveaway. They are not anymore. Modern phishing is written cleanly, sometimes better than the legitimate emails it imitates. Judge by the domain and the request, never by the prose.
Smishing, the text-message version
Text scams work well because a phone number carries an unearned sense of legitimacy and because people read texts within minutes. The two dominant formats are the fake fraud alert ("Summit FCU: Did you authorize a $482.19 charge at BestBuy? Reply NO to dispute") and the delivery notice with a link.
Replying NO does not dispute anything. It confirms the number is live and hands the sender a conversation, and within seconds you get a call from someone who "saw your reply" and needs to walk you through securing the account. Do not reply, do not tap the link. If you want to know whether a charge is real, open the Summit app or call the number on the back of your card.
Phone scams and spoofed caller ID
Caller ID is trivially spoofed. A call can display Summit's real main number and originate anywhere in the world. Treat the number on your screen as decoration.
The strongest defense costs nothing: hang up and call back on a number you looked up yourself. A legitimate representative will not object. Someone running a script will pressure you to stay on the line, often insisting that hanging up will let the fraud proceed. That objection is itself the tell.
The variants worth recognizing
A note on the check scams, because the mechanic is not obvious. Funds from a deposited check become available in a day or two, but the check itself can take weeks to be returned as fraudulent. Availability is not the same as clearance. When it bounces, the money you already sent onward is yours to repay.
The payment methods a scammer will insist on
Fraud follows irreversibility. Wire transfers, gift card codes, cryptocurrency, and person-to-person apps like Zelle or Cash App all move money in a way that cannot practically be recalled. That is the entire reason they get requested.
No government agency, utility, hospital, or financial institution collects payment in gift cards. If someone explains why gift cards are necessary this one time, that explanation is the scam.
If you think you have been hit
Speed matters more than certainty. Do not wait until you are sure.
First, freeze the card in the Summit app, which takes one tap and is instantly reversible if you were wrong. Second, call our member support line, or the number on the back of your card, and tell them what happened. Third, change your online banking password from a different device than the one involved, and revoke any active sessions. Fourth, if you shared a Social Security number, place a fraud alert with one of the three credit bureaus; that bureau is required to notify the other two.
Then report it. File with the FTC at ReportFraud.ftc.gov and, for anything involving the internet, with the FBI's Internet Crime Complaint Center at ic3.gov. Reports do not usually recover money directly, but they feed the case files that shut networks down.
One last thing worth saying plainly: nobody at Summit will make you feel foolish for calling. These operations are professional, well-resourced, and practiced. Calling early is what limits the damage, and embarrassment is the only thing that reliably delays it.
Rates current as of July 2026 and subject to change. Membership eligibility required. This is a demonstration website; rates, products, and figures shown are illustrative only.
Know what to do next
Our Security Center has current fraud alerts, reporting steps, and the direct numbers to call. If a card is gone, report it now.