“This is the bank's anti-fraud department. There is a suspicious transaction of SAR 8,400 on your card. Give me the code you just received so we can stop it.” One sentence like this has taken money from many accounts, and the owners recovered only part of it.
The direct answer: banks and government bodies do not ask you for a verification code (OTP) by phone. Anyone who pretends to be a bank or an official body to take your money by phone or online is punished by up to three years in prison and a fine of up to SAR 2 million, or one of them (Article 4 of the Anti-Cyber Crime Law). The harsher penalty applies if the Anti-Fraud and Breach of Trust Law also applies (up to seven years). Anyone who pretends to be a security officer or an official with public authority also falls under the Law on Penalties for Impersonating a Public Authority Officer. If you have already given the code, call your bank immediately and then file a report.
The call that sounds official
The method is well known but still works. A confident person who knows your name, and perhaps part of your details, says he is from your bank's fraud department, a government body or a security authority. The message is always urgent: your account will be stopped, there is a suspicious transaction, or you must update your details now.
You receive a call from someone who says he is a bank employee and tells you your card was used in a suspicious transaction.
He asks for the code you will receive by text message “to stop the transaction”.
You give him the code, and minutes later you discover it was to approve a transfer from your account or to add a new beneficiary.
In this example no one hacked your phone. You handed over the key, because the caller pretended to have a capacity people trust.
The capacities used vary: a bank employee, a delivery company agent asking for a small fee, a government body asking you to update details or pay a fine through a link, or someone who presents himself as a security officer and asks to verify your identity. What they share is that the capacity is used to switch off your caution, and the urgency stops you from thinking.
How does Saudi law deal with impersonation scams?
The Anti-Cyber Crime Law deals with this directly. Article 4 punishes anyone who takes, for himself or others, movable property, a document or the signature of a document through fraud, using a false name or claiming a false capacity. Paragraph 2 of the same article separately makes it a crime to access, without a valid legal reason, bank or credit data, or data on ownership of securities, in order to obtain data, information, money or services they provide.
The Anti-Fraud and Breach of Trust Law is wider in terms of method; its Article 1 covers any fraudulent method used to take someone else's money. If the act is a crime under more than one law, Article 9 of that law applies the harsher penalty.
| Act | Text | Maximum penalty |
|---|---|---|
| Taking money through technical means by claiming a false capacity or name | Anti-Cyber Crime Law, Article 4(1) | 3 years in prison and a SAR 2 million fine, or one of them |
| Accessing bank or credit data without a valid reason | Anti-Cyber Crime Law, Article 4(2) | 3 years in prison and a SAR 2 million fine, or one of them |
| Taking someone else's money by any fraudulent method | Anti-Fraud Law, Article 1 | 7 years in prison and a SAR 5 million fine, or one of them |
| Committed by an organised gang or a repeat offender | Anti-Fraud Law, Article 5 | No less than half of the maximum and no more than double it |
The Anti-Cyber Crime Law has its own aggravating circumstances in Article 8: the prison term or fine is no less than half of its maximum if the crime is committed by an organised gang, by a public employee abusing his job or influence, if it involves misleading minors, or if the offender was previously convicted of similar crimes.
What is the penalty for impersonating a police officer or government official in Saudi Arabia?
This case has its own older law, which is still in force: the Law on Penalties for Impersonating a Public Authority Officer (Nizam Uqubat Intihal Sifat Rajul al-Sultah al-Ammah). A public authority officer under this law is anyone the law gives the power to enforce orders and instructions and to record violations within his area of competence (Article 1).
Article 2 punishes anyone who claims this capacity with up to three years in prison, or a fine of up to SAR 50,000, or both. The penalty rises to up to ten years in prison or a fine of up to SAR 150,000, or both, if the impersonation is accompanied by intimidation or exploitation, or if the capacity claimed is that of criminal investigation (mabahith) or intelligence officers, or military personnel and those treated as such. Article 4 allows the offender to be tried for any other crime committed with the impersonation, such as defrauding you of your money.
A bank employee is not a public authority officer, so someone who pretends to be one to take your money is dealt with under the Anti-Cyber Crime Law and the Anti-Fraud Law.
Anyone who helps the fraudster, such as a person who opens an account in his own name to receive stolen money, may also be held liable. Article 9 of the Anti-Cyber Crime Law punishes anyone who incites, assists or agrees by up to the maximum penalty if the crime takes place as a result, and up to half of it if it does not.
The law does not require the fraudster to succeed to be punished. Article 10 punishes an attempt to commit any of its crimes by up to half of the maximum penalty. So a caller who tried to get the code from you and failed has committed a punishable act, and your report about him has value even if you lost nothing.
Simple habits that protect you
- The verification code you receive by text message is your signature on the transaction. Do not give it to anyone by phone or chat, whatever capacity he claims.
- If someone calls in the bank's name, hang up and call the official number printed on your card or in the bank's app yourself.
- Do not click links in messages asking you to update your details or pay a fine; go to the service directly through its official app or website.
- Do not install a remote-control app at the request of a caller you do not know.
- Read the text of the code message before using it; it often states the type of transaction it will approve.
- A caller knowing your name or ID number does not prove he is an official body.
What to do if it has already happened
- Call your bank immediately on its official number and ask it to suspend the card and account temporarily and check the recent transactions.
- Change the passwords and login details for your banking apps and email.
- Write down the caller's number, the time of the call, the text of the messages and the transaction numbers, and keep screenshots.
- File a report with the competent security authority without delay, and attach what you saved.
Investigation and prosecution of financial fraud crimes belong to the Public Prosecution, as Article 10 of the Anti-Fraud Law provides.
Does the bank bear the loss if you gave the code yourself?
The Saudi Central Bank's Financial Consumer Protection Principles and Rules require a bank to protect its customers' assets from fraud with effective technical and control systems (Principle 5), and to compensate a customer who suffers a direct loss because the bank's electronic channels were breached or had a security weakness (General Rule 12). They contain no text that settles the case of a customer who handed the code to a caller himself, so that case is considered on its facts: when you reported, what kind of transaction the code approved, and whether the bank had what it needed to stop it.
The same rules require banks and card issuers to provide a free 24-hour phone number for reporting fraud and suspicious transactions. Submit your complaint to the bank in writing and keep its reference number; if the reply does not satisfy you, you can escalate it to the Saudi Central Bank through the SAMA Cares platform.
This is general information based on the official Arabic texts of Saudi laws, which prevail over any translation. It is not legal advice for your specific case.
Practical solutions for both sides
If someone impersonated a bank or official body to target you:
- End the call immediately and contact the body on its official number.
- If you gave them a verification code, call your bank at once and ask it to stop the card and transfers.
- Change your passwords, and delete any remote-control app you installed at their request.
- File an official report with the caller's number, the messages and the transaction numbers, and state the amount you claim.
If your name or account was used in a fraud without your knowledge:
- Tell your bank and the competent authorities immediately that you were not the party dealing.
- Do not withdraw or transfer any amount that entered your account from a source you do not know.
- Keep proof that your details were stolen or your account was misused.
- Do not contact the victims directly before you understand your legal position.
What you do in the first hour protects your money and your record. Send us on WhatsApp what happened, the report number and the transaction statement, and we will review it with you and arrange the next step.
Need advice on your own case?
Every case turns on its own facts and documents. Send us a short summary and we'll arrange a session with a licensed Saudi lawyer who will tell you clearly where you stand.
Frequently asked questions
What is the penalty for impersonating a security officer or government official in Saudi Arabia?
Up to three years in prison or a fine of up to SAR 50,000, or both. It rises to ten years or SAR 150,000 if accompanied by intimidation or exploitation, or if the capacity claimed is that of criminal investigation, intelligence or military personnel (Article 2 of the Law on Penalties for Impersonating a Public Authority Officer). If the impersonation was used to take money, the offender is also tried for fraud.
I gave the caller the verification code. Will the bank refund me?
No text provides an automatic refund in this case. The Central Bank's consumer protection rules require compensation where the loss results from a breach or security weakness of the bank's channels; handing over the code yourself is assessed on the facts. Tell the bank immediately, file a written complaint and an official report, then escalate to the Central Bank if the reply does not satisfy you.
I received a message in the bank's name with a link. What should I do?
Do not click the link or reply. Open the bank's official app or call its known number to check, and if you have already entered your details, contact the bank immediately.
Does the bank call and ask for the verification code?
You should not give the code to any caller, because the code is your signature on a specific transaction. Hang up and call the bank on its official number.
General information, not legal advice. The official Arabic texts of Saudi laws prevail over any translation. Disclaimer