Phishing scams try to trick you into handing over Relay login credentials, card numbers, or 2FA codes; this article helps you spot them and report them fast.
Who this article is for
Relay account owners protecting business funds
Team members with any level of access to a Relay account
Anyone who has received a suspicious message, call, or ad that claims to be from Relay
What is a phishing attempt?
A phishing attempt is any message, call, or ad that impersonates Relay to steal your account credentials, personal data, or money. Attackers use email, SMS, phone, social media, and paid ads to reach targets, and they update tactics constantly.
How do I recognize a phishing attempt?
Six patterns are the most common tells. If a message shows one or more, treat it as phishing until you can verify the sender through a known Relay channel:
Unexpected contact from a source you didn't reach out to
Urgency or pressure to act right away
Requests for sensitive information like passwords, 2FA codes, or full card and account numbers
Links or website addresses that don't match Relay's real domains
Unprofessional or inconsistent branding, spelling, or formatting
A general sense that something is off
What does a phishing email look like?
A phishing email impersonates Relay to get you to click a malicious link or reveal account information. Common patterns include:
Asking you to "verify" or "confirm" your account through an embedded link
Requesting personal or financial data by reply
Creating artificial urgency, such as claiming your account will be closed in 24 hours
Copying Relay branding, colours, or logos to look legitimate
What does a phishing text (SMS) look like?
Also called smishing, a phishing text tries to trick you into clicking a link or sharing information over SMS. Watch for:
Fake account lockout warnings asking you to tap a "reactivate" link
Suspicious activity alerts asking you to reply with a code
Short URLs or links to domains you don't recognize
What does a phishing phone call sound like?
A phishing phone call impersonates Relay staff and pressures you to hand over a 2FA code, your password, or your card details. Relay employees will never ask you for any of these, no matter what reason a caller gives, so hang up and report the call.
How do I spot fake ads and impersonation attempts?
Scammers sometimes buy ads or create social profiles that look like Relay's. Before you click, message, or share information:
Check the URL. Relay's only web addresses are relayfi.com and bankwithrelay.com
Look at the account handle. Relay's verified social handle is @relayfinancial
Check for professional quality. Legitimate Relay ads and social posts use consistent branding, correct spelling, and complete profile information
What will Relay never ask you for?
Relay will never ask for any of the following, on any channel, for any reason:
Your 2FA login codes
Your password
Your full debit or credit card number
Your full external bank account number
If someone contacting you claims they need one of these, they are not from Relay. End the conversation and report it.
How do I safely access my Relay account?
Only sign in to Relay through one of these three sources:
relayfi.com
bankwithrelay.com
The official Relay mobile app on the Apple App Store or Google Play
Bookmark the desktop URL and search for Relay by name in your app store to avoid look-alike domains and copycat apps.
How will Relay actually contact me?
Relay contacts customers through a limited set of official channels:
Emails from official Relay email addresses, typically ending in @relayfi.com
The verified social media handle @relayfinancial
The phone number 1-888-205-9304
Any message from a different domain, handle, or number that claims to be Relay should be treated as phishing until you verify it through one of these known channels.
What should I do if I think I've been phished?
Contact Relay's Customer Experience team right away and include:
What happened (email, text, call, or ad)
The sender's address, number, or handle
Any link or attachment you received (do not click it)
Whether you shared any information, and if so, what
If you shared login credentials, sign in to Relay through relayfi.com or the mobile app and change your password. If you shared card details, freeze the affected card in the Relay app or web dashboard. If you shared external bank account numbers, contact that bank directly.
How can I keep my Relay account secure going forward?
Three habits reduce phishing risk the most:
Turn on two-factor authentication (2FA) using an authenticator app where possible instead of SMS
Bookmark relayfi.com and bankwithrelay.com; never click "login" links inside unexpected messages
Review session activity in your Relay account regularly and log out of any sessions you don't recognize
Related articles
Talk to our Customer Experience team
If this article did not fully answer your question, our Customer Experience team is here to help.