Personal Reputation

ING Scam: Fake ING Calls, Phishing Texts and Remote Access Cons

An ING scam uses fake fraud team calls, phishing texts and remote access requests to get your banking login or your money. Learn the warning signs, what to do now and where to report it in Australia.

By Editorial Team 8 min read
Black smartphone on laptop

An ING scam is a call, text, email or message from criminals pretending to be ING, usually to get your banking login or one-time codes, persuade you to move money to a “safe account”, or get remote access to your computer or phone. Like other Australian banks, ING warns customers that it won’t ask them to move money to protect it or to share passwords or codes. If you’re unsure, hang up or ignore the message, then contact ING yourself through the official ING app or the number on your card.

ING is a large bank in Australia, and the ING group also operates across Europe, so its name appears in scams in many countries. This guide focuses on Australia. Scammers who use bank names are organized and well practiced. Being targeted, or even caught out, doesn’t mean you did something foolish. It means you need to act quickly.

How ING scams usually work

Most attempts fall into three patterns: impersonation, phishing and remote access. A single scam often combines two or three of them.

Impersonation calls from the “fraud team”

A caller says they’re from ING’s fraud or security team and that there’s suspicious activity on your account. They may already know your name, address or part of your card number, and the caller ID may look like a real ING number, because caller ID can be spoofed. Some scams begin with a text that looks like it’s in the same thread as genuine bank messages.

The caller then asks you to “confirm” your identity by reading out a code, approve a request in your banking app, or move your savings to a new account while they “investigate”. Every one of those requests is a sign of a scam. Our guide to vishing explains how phone scams build trust.

Phishing texts and emails

A message says your account is locked, a payment is on hold, your details need updating or a new device has been added. A link takes you to a copy of ING’s login page. Whatever you type, including your client number, access code and one-time codes, goes straight to the scammer, who uses it to log in as you.

Remote access scams

The caller claims your computer or phone has been hacked, or that they need to “secure” your banking, and talks you through installing a remote access app. Once connected, they can see your screen and may move money while keeping you talking. The same method appears in Telstra scams and fake tech support calls, and fake support calls also use Optus’s name, as our Optus scam guide explains.

Warning signs of an ING scam

  • Any request to move money to a “safe” or “secure” account. Banks don’t protect your money this way.
  • Requests for one-time codes, passwords, your access code or approval of an in-app request you didn’t start.
  • Any request to install an app or give someone control of your device during an unexpected call.
  • Links in texts or emails that ask you to log in. Open the app yourself instead.
  • Pressure and secrecy: “act now”, “don’t tell anyone”, “stay on the line”.
  • A caller who already knows some of your details. Scammers get these from data breaches and public sources.
  • A familiar-looking number. Spoofing means caller ID can’t be trusted.

ING publishes its own scam and security guidance on its official website. Check it there for the current details of how it contacts customers.

What to do right now

  1. End the contact. Hang up and don’t click links. If you’re mid-call, say you’ll call back and end it.
  2. If someone has remote access, disconnect the device from the internet straight away, remove the remote access app, and have the device checked before using it for banking again.
  3. Contact ING immediately through the official ING app or the number on your card. Tell them you’ve been scammed and ask them to stop payments, block cards and check for new payees or devices.
  4. Change your passwords from a different, clean device, starting with your email and banking, and turn on two-factor authentication. Our guide on what to do if your bank account was hacked covers this in more detail.
  5. Protect your identity if you shared ID documents, your date of birth or your driver license. IDCARE, Australia and New Zealand’s not-for-profit identity and cyber support service, can help you work out a plan.
  6. Save evidence: phone numbers, messages, links, screenshots, the times of calls and any payment details.

Where to report an ING scam in Australia

  • ING: report it through the official app or the contact details on ING’s website, even if you didn’t lose money.
  • Scamwatch: report the scam to Scamwatch, run by the National Anti-Scam Centre, which uses reports to warn others and disrupt scams. Our guide on how to report a scam to Scamwatch explains what to include.
  • ReportCyber: if you lost money or data through a cybercrime, such as remote access or a hacked account, report it through ReportCyber at cyber.gov.au.
  • IDCARE: contact IDCARE if your personal details or ID documents were exposed.

For every reporting route in one place, including other countries, see our guide on how to report a scammer.

Can you get your money back?

It depends on how the money was taken and how quickly you act.

  • Unauthorized transactions: if someone else made payments without your authority, tell ING straight away. Banks investigate these under their own terms and industry codes.
  • Transfers you were tricked into making: ING can try to recall the money from the receiving bank, but this works only sometimes, and usually only if you’re very quick.
  • Card payments: ask about a chargeback or dispute as soon as possible.
  • Crypto and gift cards: these are often impossible to reverse. Contact the exchange or card issuer anyway.
  • If you’re unhappy with the outcome: make a complaint to ING first, then take it to the Australian Financial Complaints Authority (AFCA), which is free to use.

Be wary of anyone who contacts you afterward offering to recover your money for a fee, sometimes posing as a bank, lawyer or government agency. These are recovery scams.

Not sure where to start?

Get a free audit of your search results and review profiles, with a prioritized fix list.

Get a free audit

A worked example

This is an illustrative scenario, not a real case. Daniel gets a text that seems to come from ING, saying a large payment is on hold and he should expect a call. Minutes later a calm caller from the “fraud team” knows his name and suburb. She says his account has been compromised and he needs to move his savings into a new account set up for his protection.

  1. Daniel remembers that banks don’t ask customers to move money to keep it safe. He says he’ll call back and hangs up.
  2. He opens the official ING app. There’s no held payment and no new payee.
  3. He calls ING on the number on his card to report the call, and the bank adds a note to his account.
  4. He reports the text and call to Scamwatch.

If Daniel had moved the money, the right order would have been: call ING immediately to try to recall it, change passwords from a clean device, then report to ReportCyber and Scamwatch.

How to protect your ING accounts

  • Use the official ING app or type the website address yourself, never a link in a message.
  • Never read out codes or approve in-app requests you didn’t start.
  • Turn on the security features ING offers in its app, such as transaction alerts, and review them now and then.
  • Make a household rule: nobody gives remote access after an unexpected call.
  • Learn to read links. Our guide on how to spot a phishing email shows how to check where a link really goes.
  • Compare notes. The CommBank scam guide shows how similar scripts are used against other Australian banks.

If scammers are using your own name or business in fake messages and people are finding it when they search for you, our personal reputation management team can help you see what’s out there.

Common mistakes to avoid

  • Calling back the number that called you. Use the number on your card or in the app.
  • Trusting a text because it sits with real bank messages. Sender names can be spoofed.
  • Using the same device for banking before it’s checked after remote access.
  • Waiting to report because you feel embarrassed. Speed makes recalls more likely to work.
  • Paying someone to get your money back. That’s usually a second scam.

Frequently asked questions

Will ING ever ask me to move money to a safe account?

Banks don’t protect your money by asking you to move it. A request to transfer savings to a “safe” or “secure” account is a scam. Hang up and contact ING through the official app or the number on your card.

What should I do if I clicked an ING phishing link?

If you entered your login or codes, contact ING straight away through the app or the number on your card, change your passwords from a clean device and watch your accounts. Then report it to Scamwatch and ReportCyber.

Is ING the same bank in Australia and Europe?

ING Australia is part of the international ING group, which also operates in Europe. The scam patterns are similar, but reporting routes differ by country. This guide covers Australia.

Where do I report an ING scam in Australia?

Tell ING through its official app or website, report the scam to Scamwatch, and use ReportCyber if you lost money or data to a cybercrime. IDCARE can help if your identity details were exposed.

Editorial Team

The 123 Reputation Management editorial team writes practical guides on reviews, search results and online reputation.

Start with step 1

See what people see when they search for you.

Get a free, no-obligation reputation audit covering search results, review profiles and social mentions, with clear next steps.