Skip to content
isthisaigenerated.appsignals behind the content
Image detectorText detectorDocument detectorCheckersAppsHow it works ▾TeamsFor developersDocsPricingAccuracyTrustBlogContactNLSign in

Card fraud

Your card in someone else's wallet: spotting a fake 'your card was linked' alert

A text or email arrives: your payment card has been linked to Apple Pay or Google Wallet, and if that was not you, you should call a number or open a link. Sometimes nothing about that message is invented and the criminal really does hold your card details on their own phone: the Dutch Fraud Helpdesk warns that fraudsters add stolen credit card data to their own device and then spend large amounts, with average losses above 1,000 euros and one victim losing 2,100 euros (RTL Nieuws, 10 July 2026). Sometimes the message itself is the trick: a forged alert carrying a phone number that leads you to a fake agent (Opgelicht?!, 10 July 2026). Both cases need the same first move: do not trust the message, open your own wallet and your own bank.

The rule that breaks the pattern: a message about your payment card never comes with a number to call back, and you never hand a verification code to anyone — not even to someone claiming to be securing your card.

Direct answer: five checks before you call or click

  1. Open your own wallet and banking app, not the message. Check in Apple Wallet or Google Wallet which cards are linked and whether you recognise them, and check the status of your card in your bank's app. If you see a link or a transaction that is not yours, call your bank through the app or a number you already have and have the card blocked or replaced. For credit cards, fraud reported in time is almost always covered by the card issuer (RTL Nieuws).
  2. Never call the number in the message and never follow the link. With spoofing, a fraudster makes Google Pay, Apple Pay or your bank's name appear on your screen while the number belongs to nobody; the number in the message is not Apple's and not your bank's (Opgelicht?!, fake Apple Pay text). What you can verify lives in your own wallet and banking app, not in the channel warning you.
  3. Never share a verification code, not even for a card you do not recognise. Adding a card to a wallet can require confirmation, and that confirmation goes to the real cardholder. A code you did not ask for means someone is trying to complete an action with your card details; the code is the last door and it stays with you. Google itself lists the situations in which you may legitimately receive a text — a password reset, two-step verification, signing in from a new device or location — and none of them asks you to call about a wallet link (Opgelicht?!).
  4. Check your statements regularly, not only when a message arrives. Because card details can come from earlier breaches or phishing, misuse can start without any warning reaching you first. Review your bank and credit card statements every few days and act on any unknown transaction immediately: the earlier you report and block, the better the chance of cover and a recall (RTL Nieuws).
  5. Recognise the robocall variant and report the message. There are also calls claiming to come from PayPal and Apple Pay, where you first hear an automated recording and a menu connects you to an 'agent'; the Fraud Helpdesk advises ending such calls immediately and sharing nothing (Fraudehelpdesk). Report the text or email to your national fraud desk and file a police report if you lost money; the same pattern exists as a fake bank email saying 'a payment card was added to Apple Pay' (Fraudehelpdesk, fake email example).

What a detector does and does not see

This pattern is not generated content but a forged label: a text claiming to be Google Pay, a recording claiming to be Apple. A detector score on the text or on a screenshot therefore says nothing about the sender. You can run the message through the text detector as triage, for instance when it arrives as an attachment or screenshot, but the decision is made in your own wallet and at your bank.

Why this is growing

Paying with a card in a wallet feels to a criminal like cash: contactless and without a PIN. As long as card details from breaches and phishing remain plentiful and activation is judged by Apple, Google and the card issuer as a risk signal (RTL Nieuws), this will keep attracting attempts — and with them the fake alerts that ride on the real fear of it.

If you already called, clicked or shared something

  • Call your bank or card issuer immediately on a number you already have and have the card blocked; state exactly what you shared and when.
  • If you handed over a code or card details, ask for the card to be replaced, not just blocked.
  • If you opened a link or installed anything, check the device, remove unknown software and change passwords, using an authenticator app instead of SMS for two-factor.
  • Keep the message, the sender number, the link and the timestamp; report it to your national fraud desk and file a police report if there is damage.

More checks are in the guides on a fake call from your bank, SIM swap and your phone number and a fake payment proof. To check a single file or message as triage, use the free checker.

Frequently asked questions

Is a text from Google Pay or Apple Pay about my card always fake?

Not always: legitimate sign-in and verification messages exist. But no legitimate message asks you to call a number inside it about a wallet link, and Google does not list that call route. Verify the link in your own wallet and banking app.

My bank asks for a code to secure the card. Is that real?

No. Your bank never asks for a verification code or PIN to 'secure' something, and a code you receive unexpectedly is precisely the sign that someone else is trying to complete an action. Do not share it, and call the bank on a number you already have.

Does a high detector score prove this message is fake?

No. The score describes patterns in text or images and says nothing about the sender. A low score does not prove a message is genuine either; use the outcome only as a reason to check your own wallet and statements.

isthisaigenerated.appWhat’s real? What’s fake?

Signals support human judgement. They do not prove origin.

ProductCheck mediaCheckersBlogAppsHow it worksPricing
BuildFor developersDocsDetection APIAccuracyBenchmarks
CompanyTrustTeamsPilotContact
LegalPrivacyTermsProvenanceC2PA

© 2026 isthisaigenerated.app · Open beta · No detector output is standalone proof.