Select Your Residential State
Please select your state
There are some errors on this page.
  • Please enter your state.
  • Product offerings may differ among geographic locations. By selecting your state of residence, you'll be shown the specific terms and rates that will apply to your new account.

    Please note: If you choose to cancel this process, you may be redirected to a page other than the one you requested.

    E-mail Fraud

    Learn to spot spoof emails.

    Several signs can help you determine if an e-mail is legitimate or a spoof. Learn how to recognize and protect yourself from fraudulent e-mails.

    E-mail Fraud

    What is a spoof?

    Spoof e-mails (also known as phishing or hoax e-mails) appear to be from well-known companies. To bait you, an e-mail may say there's an urgent situation concerning your account, then ask you to click a link back to a spoof website to provide personal information.

    Even if you don't supply any information, just selecting the link may enable thieves to access your computer, record your keystrokes, and capture your passwords.

    Also, beware of spoof web forms that ask you to provide confidential information that a legitimate company would not ask the customer to enter for a particular transaction.

    How to spot a spoof

    • Sense of urgency — Messages claim your account will be closed or temporarily suspended, and warn you'll be charged if you don't respond.
    • Spelling errors — There may be obvious spelling errors, which help spoof e-mails avoid spam filters.

    Our e-mail security practices

    What we do:

    • Include an "E-mail Security Zone" with your first and last name, and either the last 4 digits on your ATM/Debit or Credit Card or the last 4 digits of your specified bank account number. See how it looks
    • Send you e-mails with links to features such as online tours and information or promotions about Citi products. These links are only for convenience and you can always type in our URL directly.
    • Notify you by e-mail when there's a message waiting for you in your
      secure online inbox.

    How to protect yourself

    • Go directly there — The best way to get to any site is to type its address (URL) into your browser and then bookmark it.
    • Set up a login cookie — Some sites like let your computer remember your User ID. This way, when you return to the site from an e-mail to sign on, your User ID will be visible in the sign on box. A spoof, or fake, website will not be able to display your User ID. (Never use the Remember Me feature on a public or shared computer.)

    Report a spoof

    If you suspect that you've received a fraudulent e-mail message, please forward it to us. Don't change or retype the subject line, as this makes it more difficult to properly investigate. After forwarding the e-mail, you should delete it from your inbox.

    • Forward suspicious e-mails to:
    • You may also want to forward it to the Federal Trade Commission at:
    • Or contact them at: , 1-877-IDTHEFT

    Think you've responded to a spoof e-mail by mistake?

    If you have already replied to an e-mail with personal information and now think the e-mail was fraudulent, call us immediately at: 1-888-285-9696

    Did you know...

    • It's important to let us know when your e-mail address has changed. You can view the information we have on file for you in the Service Center and update it online.
    • You should only send e-mail messages to us or reply to Citibank messages through the Message Center . This online inbox is secure and protects all your banking communication.

    Spoof websites

    A spoof website is one that mimics a popular company's website to lure you into disclosing confidential information. To make spoof sites seem legitimate, thieves use the names, logos, graphics and even code of the real company's site.

    They can even fake the URL that appears in the address field at the top of your browser window and the padlock that appears in the lower right corner. The links in the spoof e-mails almost always take you to a spoof website.

    Spoof web forms

    A spoofed web form is one that is injected by malware and rendered by your browser after you sign on to the company's site asking you to provide confidential information. These spoofed web forms seems legitimate since they use the same logos and graphics of the real company's site. Spoofed web forms can be recognized since they ask you to enter extra confidential data that the company's legitimate form won't ask the user to enter for that transaction.

    E-mail Security Zone

    Secure online inbox

    Each time you sign on to your accounts online you have access to your secure online inbox. You can read messages we've sent, reply to messages, and send us a new message, all from the Message Center. As this area is secure and protected, we recommend you always use the Message Center when you need to e-mail us.

    Sign on box

    Think you're a victim of identity theft?
    (NY metro area)
    (other areas)

    Report a lost or stolen credit card.

    Report suspicious e-mails or phishing.