Back to Help Center

Help articles

How to Identify and Report Phishing Attempts

UpdatedAugust 11, 2026

Phishing scams try to trick you into handing over Relay login credentials, card numbers, or 2FA codes; this article helps you spot them and report them fast.

Who this article is for

  • Relay account owners protecting business funds

  • Team members with any level of access to a Relay account

  • Anyone who has received a suspicious message, call, or ad that claims to be from Relay

What is a phishing attempt?

A phishing attempt is any message, call, or ad that impersonates Relay to steal your account credentials, personal data, or money. Attackers use email, SMS, phone, social media, and paid ads to reach targets, and they update tactics constantly.

How do I recognize a phishing attempt?

Six patterns are the most common tells. If a message shows one or more, treat it as phishing until you can verify the sender through a known Relay channel:

  • Unexpected contact from a source you didn't reach out to

  • Urgency or pressure to act right away

  • Requests for sensitive information like passwords, 2FA codes, or full card and account numbers

  • Links or website addresses that don't match Relay's real domains

  • Unprofessional or inconsistent branding, spelling, or formatting

  • A general sense that something is off

What does a phishing email look like?

A phishing email impersonates Relay to get you to click a malicious link or reveal account information. Common patterns include:

  • Asking you to "verify" or "confirm" your account through an embedded link

  • Requesting personal or financial data by reply

  • Creating artificial urgency, such as claiming your account will be closed in 24 hours

  • Copying Relay branding, colours, or logos to look legitimate

What does a phishing text (SMS) look like?

Also called smishing, a phishing text tries to trick you into clicking a link or sharing information over SMS. Watch for:

  • Fake account lockout warnings asking you to tap a "reactivate" link

  • Suspicious activity alerts asking you to reply with a code

  • Short URLs or links to domains you don't recognize

What does a phishing phone call sound like?

A phishing phone call impersonates Relay staff and pressures you to hand over a 2FA code, your password, or your card details. Relay employees will never ask you for any of these, no matter what reason a caller gives, so hang up and report the call.

How do I spot fake ads and impersonation attempts?

Scammers sometimes buy ads or create social profiles that look like Relay's. Before you click, message, or share information:

  • Check the URL. Relay's only web addresses are relayfi.com and bankwithrelay.com

  • Look at the account handle. Relay's verified social handle is @relayfinancial

  • Check for professional quality. Legitimate Relay ads and social posts use consistent branding, correct spelling, and complete profile information

What will Relay never ask you for?

Relay will never ask for any of the following, on any channel, for any reason:

  • Your 2FA login codes

  • Your password

  • Your full debit or credit card number

  • Your full external bank account number

If someone contacting you claims they need one of these, they are not from Relay. End the conversation and report it.

How do I safely access my Relay account?

Only sign in to Relay through one of these three sources:

  • relayfi.com

  • bankwithrelay.com

  • The official Relay mobile app on the Apple App Store or Google Play

Bookmark the desktop URL and search for Relay by name in your app store to avoid look-alike domains and copycat apps.

How will Relay actually contact me?

Relay contacts customers through a limited set of official channels:

  • Emails from official Relay email addresses, typically ending in @relayfi.com

  • The verified social media handle @relayfinancial

  • The phone number 1-888-205-9304

Any message from a different domain, handle, or number that claims to be Relay should be treated as phishing until you verify it through one of these known channels.

What should I do if I think I've been phished?

Contact Relay's Customer Experience team right away and include:

  • What happened (email, text, call, or ad)

  • The sender's address, number, or handle

  • Any link or attachment you received (do not click it)

  • Whether you shared any information, and if so, what

If you shared login credentials, sign in to Relay through relayfi.com or the mobile app and change your password. If you shared card details, freeze the affected card in the Relay app or web dashboard. If you shared external bank account numbers, contact that bank directly.

How can I keep my Relay account secure going forward?

Three habits reduce phishing risk the most:

  • Turn on two-factor authentication (2FA) using an authenticator app where possible instead of SMS

  • Bookmark relayfi.com and bankwithrelay.com; never click "login" links inside unexpected messages

  • Review session activity in your Relay account regularly and log out of any sessions you don't recognize

Talk to our Customer Experience team

If this article did not fully answer your question, our Customer Experience team is here to help.

Was this article helpful?

Relay is a financial technology company and is not an FDIC-insured bank. Banking services provided by Thread Bank, Member FDIC.