How it works Detection Roadmap Pricing Blog Phishing Email Checker Header Analyzer Phishing Quiz Install free
Security guide

Is that Chase “account locked” email real or a scam?

Banks really do restrict accounts for security — which is exactly why the fake Chase “your account has been locked, verify your identity” email works so well. If one just landed in your inbox, here’s how to tell the genuine alert from the phish, and the safe way to check without clicking anything.

Published 22 August 2026 · ~8 min read · By the Phixo team

The email says your Chase account has been locked — unusual activity, verify your identity, act now or lose access. Your bank account is about as high-stakes as an inbox gets, so the instinct to click and sort it out immediately is strong. That instinct is exactly what the scam is built to trigger.

Here’s the uncomfortable part that makes this one effective: banks including Chase really do send security alerts and can restrict an account they think is at risk. The premise is plausible, so it survives a quick gut-check. But a genuine Chase alert behaves very differently from the phishing version — and once you know the difference, the fake falls apart in under a minute. Let’s walk through it.

The quick answer

Treat a “Chase account locked” email as a scam if any of these are true: the sender’s domain isn’t chase.com (watch for lookalikes like chase-verify-online.com or chase-secure.net), it threatens to suspend your account within hours, it asks you to confirm your Social Security number, card number, PIN or password, or it opens with “Dear Customer.” The single most reliable move: don’t click anything in the email. Open the Chase app you already have, or type chase.com into a fresh browser tab and sign in. If there were a real problem, Chase would tell you there — and if you can sign in normally, the email was the fake.

Illustration of Phixo flagging a fake Chase account locked email in Gmail: Critical Risk verdict with a lookalike chase-verify-online.com sender, a verify-your-identity credential request, a generic greeting and threat language detected
What this catch looks like (illustration): Phixo flags a fake “Chase account has been locked” email in Gmail — the lookalike sender domain, the demand to “verify your identity” through a lookalike login link, the generic greeting and the deadline threat earn a Critical Risk verdict. The warning text shown is Phixo’s real output for these signals.

The words these scams actually use

Phishing kits recycle the same lines because they work. If your email reads like a remix of the phrases below, that’s the pattern — not a coincidence:

Subject lines you’ll seeYour Chase account has been locked
Action required: verify your identity
Unusual sign-in activity on your account
We’ve temporarily suspended your account
Body text you’ll see “Dear Customer, we detected unusual sign-in activity and have temporarily locked your account.”

“For your security, you must verify your identity within 24 hours or your account will be permanently suspended.”

“Please confirm your Social Security number, card number and PIN to restore access.”

Every one of those lines is doing a job: manufacturing urgency, borrowing Chase’s authority, and steering you toward a form that harvests your credentials. The tell isn’t the wording — kits copy Chase’s tone well. It’s the combination: a scary claim, a deadline, and a request for information your bank would never ask you to type into an email link.

What Chase really does — and doesn’t

Knowing the genuine behaviour makes the fakes obvious:

The text-message version: a lot of these “Chase account locked” scams arrive as a text (SMS), not an email — that variant is called smishing. The tells are identical: a lookalike link, a deadline, a demand for credentials. The safe move is the same too: never tap the link; open the Chase app or type chase.com yourself.

5 signs of a fake “Chase account locked” email

1. The sender domain isn’t chase.com

The display name — “Chase,” “Chase Online Security,” “Chase Fraud Department” — is trivial to fake. Tap or click the sender name to reveal the full address and read the part after the @.

What you see vs. what’s really there From: Chase Online Security
<secure-alert@chase-verify-online.com>

The registered domain must be chase.com. A domain that merely contains “chase” — chase-verify-online.com, chase-secure.net, chasebank-support.com — is not Chase.

2. A deadline and a threat

“Verify within 24 hours or your account will be permanently suspended.” A real bank’s security process doesn’t hinge on you clicking an email link before a countdown runs out. The manufactured urgency is the attack’s engine — it’s there to stop you pausing to check.

3. Links that don’t go to chase.com

Hover over the button (or press and hold on mobile) to preview the true destination before clicking.

The button lies Button text: Verify My Identity
Actual destination: http://chase-verify-online.com/secure-login

Genuine Chase links live on chase.com. A different domain, a URL shortener, or a raw IP address means don’t click.

4. It asks for your SSN, card number, PIN or password

The page behind the button is a credential harvester — it wants your online-banking login, and often your Social Security number, card number and PIN as a bonus. This is the brightest red line there is: real Chase never collects these through an email link. If a message asks you to type them to “restore access,” it’s a scam, full stop.

5. A generic greeting and subtly off English

“Dear Customer, your account has been locked for security reason.” A real Chase message is polished and can address you by name. Generic greetings, odd capitalisation and slightly broken phrasing are cheap to fix, yet phishing kits keep shipping them — treat them as the gift they are.

The single safest way to check

Take the email out of the equation entirely — check your account where Chase actually manages it:

  1. Don’t click any link or button in the email.
  2. Open the Chase app you already have installed and sign in. A real account problem shows up there.
  3. Or in a browser: open a new tab and type chase.com yourself, then sign in.
  4. If there’s a genuine issue, Chase tells you inside the app or on the site. If you can sign in normally — the email was the fake.
  5. When in doubt, call the number on the back of your Chase card — never a phone number printed in the email.

Report the fake: Chase asks customers to forward suspicious emails to abuse@chase.com, and you can report phishing to the U.S. FTC at reportfraud.ftc.gov. A minute of your time feeds the takedown pipeline that protects the next person.

This verify-at-the-source habit is the same defence that beats the fake PayPal “account limited” email and the fake Amazon “account suspended” email — the scams are siblings, and one habit defeats them all.

The 30-second Chase email check

Why this fake fools careful people

The Chase version of this scam borrows credibility from two directions at once. The premise is real bank behaviour — accounts genuinely do get restricted for suspicious activity, so it passes a quick mental fact-check. And the stakes are unusually concrete: this is your money, right now. Fear plus a plausible premise plus real financial stakes is about the most effective phishing fuel there is.

Appearance won’t separate real from fake — the kits copy Chase’s logo, colours and layout closely. The reliable tells are the ones a template can’t fake: the sender’s registered domain, the true link destination, whether it’s asking for credentials no bank collects by email, and whether the problem actually exists when you sign in through Chase’s own front door. For the technical trail, our free email header analyzer shows where a message really came from and whether it passed authentication.

What if you already clicked or entered your details?

Don’t panic — act quickly, in this order:

  1. Call Chase using the number on the back of your card and tell them your details may be compromised. They can lock the card, watch for fraud and reissue it.
  2. Change your chase.com password — typed by hand, not through the email — and change it anywhere you reused it.
  3. Turn on account alerts and two-factor authentication so a stolen password alone can’t move money.
  4. If you shared your Social Security number, consider placing a fraud alert or credit freeze with the three credit bureaus.
  5. Watch your statements closely over the next weeks and report anything you don’t recognise immediately.

For the full walkthrough — including what to check in the days after — see I gave my password to a phishing site — what now?

Frequently asked questions

Does Chase send emails saying your account is locked?

Chase does send security and account alerts, and it can restrict an account it believes is at risk. But a real alert won’t ask you to confirm your full SSN, card number, PIN or password through a link. If a message pressures you to “verify your identity” on a deadline by entering credentials, treat it as phishing and check by going to chase.com or the app directly.

How can I tell if a Chase account locked email is real or fake?

Check the sender’s real address — genuine Chase email comes from chase.com, not lookalikes like chase-verify-online.com. Treat it as fake if the domain is anything else, if it threatens to suspend your account within hours, if it asks for your SSN, card number or PIN, or if it opens with a generic greeting.

What is the safest way to check?

Don’t click anything in the email. Open the Chase app or type chase.com in a fresh tab and sign in. If there’s a real problem, Chase will tell you there. If you can sign in normally, the email was the fake. When in doubt, call the number on the back of your card.

Keep reading

Not sure about an email? Let Phixo check it

Phixo is a browser extension that checks the email open in your Gmail or Outlook against several of the signals above — sender and domain reputation, link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language, and flags anything suspicious in seconds. (It reads the email in your inbox, not text messages — so it catches the emailed version of these bank scams.) Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.

Install Phixo free →

Your email body is never stored. Analysis happens in real time and is discarded immediately.