Banks really do restrict accounts for security — which is exactly why the fake Chase “your account has been locked, verify your identity” email works so well. If one just landed in your inbox, here’s how to tell the genuine alert from the phish, and the safe way to check without clicking anything.
Published 22 August 2026 · ~8 min read · By the Phixo team
The email says your Chase account has been locked — unusual activity, verify your identity, act now or lose access. Your bank account is about as high-stakes as an inbox gets, so the instinct to click and sort it out immediately is strong. That instinct is exactly what the scam is built to trigger.
Here’s the uncomfortable part that makes this one effective: banks including Chase really do send security alerts and can restrict an account they think is at risk. The premise is plausible, so it survives a quick gut-check. But a genuine Chase alert behaves very differently from the phishing version — and once you know the difference, the fake falls apart in under a minute. Let’s walk through it.
Treat a “Chase account locked” email as a scam if any of these are true: the sender’s domain isn’t chase.com (watch for lookalikes like chase-verify-online.com or chase-secure.net), it threatens to suspend your account within hours, it asks you to confirm your Social Security number, card number, PIN or password, or it opens with “Dear Customer.” The single most reliable move: don’t click anything in the email. Open the Chase app you already have, or type chase.com into a fresh browser tab and sign in. If there were a real problem, Chase would tell you there — and if you can sign in normally, the email was the fake.
Phishing kits recycle the same lines because they work. If your email reads like a remix of the phrases below, that’s the pattern — not a coincidence:
Every one of those lines is doing a job: manufacturing urgency, borrowing Chase’s authority, and steering you toward a form that harvests your credentials. The tell isn’t the wording — kits copy Chase’s tone well. It’s the combination: a scary claim, a deadline, and a request for information your bank would never ask you to type into an email link.
Knowing the genuine behaviour makes the fakes obvious:
The text-message version: a lot of these “Chase account locked” scams arrive as a text (SMS), not an email — that variant is called smishing. The tells are identical: a lookalike link, a deadline, a demand for credentials. The safe move is the same too: never tap the link; open the Chase app or type chase.com yourself.
The display name — “Chase,” “Chase Online Security,” “Chase Fraud Department” — is trivial to fake. Tap or click the sender name to reveal the full address and read the part after the @.
The registered domain must be chase.com. A domain that merely contains “chase” — chase-verify-online.com, chase-secure.net, chasebank-support.com — is not Chase.
“Verify within 24 hours or your account will be permanently suspended.” A real bank’s security process doesn’t hinge on you clicking an email link before a countdown runs out. The manufactured urgency is the attack’s engine — it’s there to stop you pausing to check.
Hover over the button (or press and hold on mobile) to preview the true destination before clicking.
Genuine Chase links live on chase.com. A different domain, a URL shortener, or a raw IP address means don’t click.
The page behind the button is a credential harvester — it wants your online-banking login, and often your Social Security number, card number and PIN as a bonus. This is the brightest red line there is: real Chase never collects these through an email link. If a message asks you to type them to “restore access,” it’s a scam, full stop.
“Dear Customer, your account has been locked for security reason.” A real Chase message is polished and can address you by name. Generic greetings, odd capitalisation and slightly broken phrasing are cheap to fix, yet phishing kits keep shipping them — treat them as the gift they are.
Take the email out of the equation entirely — check your account where Chase actually manages it:
Report the fake: Chase asks customers to forward suspicious emails to abuse@chase.com, and you can report phishing to the U.S. FTC at reportfraud.ftc.gov. A minute of your time feeds the takedown pipeline that protects the next person.
This verify-at-the-source habit is the same defence that beats the fake PayPal “account limited” email and the fake Amazon “account suspended” email — the scams are siblings, and one habit defeats them all.
The Chase version of this scam borrows credibility from two directions at once. The premise is real bank behaviour — accounts genuinely do get restricted for suspicious activity, so it passes a quick mental fact-check. And the stakes are unusually concrete: this is your money, right now. Fear plus a plausible premise plus real financial stakes is about the most effective phishing fuel there is.
Appearance won’t separate real from fake — the kits copy Chase’s logo, colours and layout closely. The reliable tells are the ones a template can’t fake: the sender’s registered domain, the true link destination, whether it’s asking for credentials no bank collects by email, and whether the problem actually exists when you sign in through Chase’s own front door. For the technical trail, our free email header analyzer shows where a message really came from and whether it passed authentication.
Don’t panic — act quickly, in this order:
For the full walkthrough — including what to check in the days after — see I gave my password to a phishing site — what now?
Chase does send security and account alerts, and it can restrict an account it believes is at risk. But a real alert won’t ask you to confirm your full SSN, card number, PIN or password through a link. If a message pressures you to “verify your identity” on a deadline by entering credentials, treat it as phishing and check by going to chase.com or the app directly.
Check the sender’s real address — genuine Chase email comes from chase.com, not lookalikes like chase-verify-online.com. Treat it as fake if the domain is anything else, if it threatens to suspend your account within hours, if it asks for your SSN, card number or PIN, or if it opens with a generic greeting.
Don’t click anything in the email. Open the Chase app or type chase.com in a fresh tab and sign in. If there’s a real problem, Chase will tell you there. If you can sign in normally, the email was the fake. When in doubt, call the number on the back of your card.
Phixo is a browser extension that checks the email open in your Gmail or Outlook against several of the signals above — sender and domain reputation, link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language, and flags anything suspicious in seconds. (It reads the email in your inbox, not text messages — so it catches the emailed version of these bank scams.) Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.