Owners of Android smartphones often encounter alarming notifications that come from short numbers, in particular from the service 900. Most often, such SMS contain a confirmation or registration code that the user did not request. This phenomenon causes natural concern, since the number 900 is strongly associated with the official service of Sberbank, and any message from it is perceived as critically important.
However, the nature of such messages can be completely different: from a technical error when another person entered the number to an attempt by attackers to gain access to your account or SIM card. Understanding how these notifications work and reacting correctly to them is a key skill for ensuring the digital security of your device and financial assets.
In this article, we will look in detail at why the registration code is sent, how to distinguish a real bank message from a phishing attack, and what steps need to be taken in the settings of your smartphone to prevent similar incidents in the future. Android-smartphone to prevent similar incidents in the future.
Nature of number 900 and types of incoming messages
The number 900 is an official short number for subscribers of the operator MegaFonthrough which communication with clients of Sberbank is carried out. The system automatically generates and sends messages when certain actions are performed: confirming a transaction, logging into your personal account, changing a password or registering a new device.
Technically, the message is a standard SMS data package that is routed through the telecom operator's gateway directly to your device. It is important to understand that the mere fact of receiving a message does not mean hacking. Often this is just a security system reaction to an attempt to log in from an unfamiliar IP address or device.
⚠️ Attention: Official messages from 900 never contain links to third-party sites and do not ask to call back mobile numbers. If the SMS contains a URL, this is a 100% sign of fraud, even if the sender is listed as 900 (the number can be replaced through special gateways).
There are several scenarios in which you can receive such a code without your active actions. First, someone could have gotten one digit wrong when entering their phone number in the bank's app or website. Secondly, this may be an attempt to brute-force data, when bots check the validity of the numbers. Thirdly, in rare cases, the database may be compromised, although large banks have multi-level protection.
Analysis of the message content helps to quickly classify the threat. If the text contains phrases like “Login confirmation code” or “Authorization code”, but you did not try to log in, this is an alarm. Ignoring such a message is usually safe, but requires vigilance.
If you received the code but did not initiate any action, simply delete the message. Never share this code with third parties, even if the caller introduces himself as a bank employee.
Threat analysis: phishing and social engineering
The greatest danger is not the fact of receiving an SMS, but the subsequent actions of the user. Fraudsters often use social engineering to trick them into receiving the code. The scheme works simply: an attacker tries to log into your account, the system sends you a code, and then the fraudster calls you, posing as the security service.
During the conversation, a “bank employee” may report allegedly suspicious activity and ask you to dictate a code to “cancel the operation” or “block the card.” Remember: bank employees never ask for codes from SMS. By passing on the code, you actually give criminals full access to your account or personal office.
- 🛑 Never dictate codes from SMS over the phone, even if they are calling from a number similar to a bank one.
- 🔒 Do not follow links in messages from unknown senders masquerading as 900.
- 📞 In case of suspicious calls, hang up and call back to the official bank number indicated on the back of the card.
Another attack vector is substitution of the sender's number (SMS Spoofing). Technical capabilities allow scammers to configure the sending of messages so that the "From" field will display 900, although the real message came from the attackers' server. Such SMS often contain links to fake clone sites where you will be asked to enter card details.
How does number spoofing work?
The technology allows you to change the sender field in the SMPP protocol. Telecom operators combat this by filtering traffic, but some messages still get through. Always check the content of the text, and not just the name of the sender.
Particular attention should be paid to messages requiring you to urgently update an application or confirm your identity. These are classic triggers used to manipulate the user's attention. Panic and haste are the main allies of hackers. Calm analysis of the text of the message allows you to identify inconsistencies, such as grammatical errors or incorrect language.
Android security settings to protect against spam
The operating system Android provides built-in tools to filter unwanted messages and protect against fraud. Properly configuring these settings significantly reduces the risk that you will become a victim of an attack or simply be annoyed by spam.
The first step is to activate anti-spam protection in the standard messages application. In modern versions of Android, especially on Google Pixel, Samsung and Xiaomi smartphones, this feature is integrated deep into the system. It automatically detects suspicious numbers and moves such messages to a separate “Spam and Blocked” folder.
To access the settings, go to the menu Settings → Applications → Messages → Antispam. Here you can enable a filter that will analyze the contents of incoming SMS. Algorithms use databases of known fraudulent numbers and text patterns to identify threats.
| Protection function | Where to find in the menu | Efficiency |
|---|---|---|
| Spam filter | Settings → Messages | High |
| Blocking by number | Contacts → Blocked | Medium (for short numbers) |
| Google Play Protection | Play Market → Play Protection | High (for applications) |
Additionally, it is recommended to install third-party antivirus solutions or call identification applications, such like Kaspersky Who Calls or Yandex with caller ID. These applications have extensive databases updated by a community of users, which allows you to block new fraud schemes faster than official filters.
☑️ Setting up smartphone protection
Actions when receiving a registration code
If you receive a message from 900 with a code on your screen, the algorithm of your actions should be clear and verified. The first rule: do not panic and do nothing in a hurry. The code itself does not mean anything without your participation in the authorization process.
If at this moment you did not try to log into Sberbank Online or issue a card, simply delete the message. No additional actions are required from you. The bank system automatically cancels the code after a few minutes if it has not been used.
However, if you received a series of such messages or the code came immediately after a suspicious call, the situation requires a more serious approach. In this case, it is recommended to temporarily block the card through the app or call the contact center to make sure that everything is in order with your account.
⚠️ Attention: The interfaces of mobile applications and banking services are regularly updated. The location of menu items and names of functions may differ depending on the software version. Current blocking instructions can always be found in the "Help" section of the official application.
It is also important to check whether unknown applications are installed on your phone that could intercept SMS. Attackers sometimes use malware to read incoming messages and forward verification codes to their servers. Conduct a full antivirus scan of your device.
The most important rule: if you did not request a code, do not enter it anywhere and do not tell anyone. Ignoring is the best protection in 99% of cases.
Technical reasons for failures and false positives
Receiving a code from 900 does not always indicate malicious interference. There are technical reasons why users encounter such notifications. One of the common reasons is the operator’s error when reselling numbers.
When a subscriber changes a number or terminates service, the telecom operator after a certain time (usually from 3 to 6 months) returns the number to circulation and sells it to a new client. If the previous owner of the number has not unlinked it from their bank accounts, the registration code may be sent to the new owner of the SIM card.
In such a situation, the new owner of the number finds himself in an unpleasant position: he gets access to other people's financial notifications, but does not have rights to manage the account. The solution to the problem is to contact the operator’s communication salon to clarify the history of the number and, if necessary, replace it, as well as inform the bank about the change of owner of the number.
Another reason is failures in the operation of the operator’s gateways. Sometimes messages may be duplicated or delayed, creating the illusion of a massive attack. There may also be cases when the bank application on your own phone does not work correctly and repeatedly requests a code due to a software glitch.
- 🔄 Clear the bank application cache:
Settings → Applications → Sberbank → Memory → Clear cache. - 📱 Check the date and time on the device: incorrect settings may interfere with security protocols.
- 🌐 Switch the network type: try temporarily switching from 4G to 3G or Wi-Fi to eliminate routing problems.
If the problem is systemic in nature and codes are constantly coming for no apparent reason, you should reset the network settings. This will return the connection parameters to factory defaults and eliminate possible configuration conflicts.
Prevention and long-term account protection
To minimize risks in the future, it is necessary to implement a comprehensive approach to digital hygiene. The security of your Android device and bank accounts depends not only on responding to threats, but also on preventive measures.
Use two-factor authentication (2FA) wherever possible. However, instead of SMS codes, which are vulnerable to interception via Sim-Swapping or number spoofing, try to use authenticator applications such as Google Authenticator or Yandex.Key. They generate codes locally on the device and do not depend on the operator's network.
Regularly update the operating system and all installed applications. Developers Android and banking services are constantly closing vulnerabilities through which attackers can gain access to data. Outdated software is an open door for viruses and Trojans.
It is also recommended to set up notifications for all card transactions. This will allow you to instantly respond to any unauthorized charges. In the settings of your personal bank account, you can select the notification method: Push, SMS or e-mail. A combination of several methods increases the reliability of control.
What should I do if I accidentally gave the code to scammers?
If you have already given the code, immediately call the bank at the official number and block the card. After this, change the password for your personal account and check your transaction history. It is also recommended to write a statement to the police.
Is it possible to completely block messages from 900?
Technically, you can block the short number 900 through the message settings, but this is not recommended. You will no longer receive important notifications from the bank about transactions, which will reduce the security of your funds.
How to find out who tried to log into my account?
The bank's mobile application usually has a "Security" or "Devices" section, which displays the login history indicating the time, device type and geolocation. Check this section for unfamiliar sessions.
Is it dangerous to simply open a message from 900?
The very fact of opening and reading the text of an SMS message is safe. Viruses cannot enter your phone simply by reading text. The only danger is following links inside the message or entering data on phishing sites.
Why did the code arrive on a switched off phone after turning it on?
Messages are saved on the telecom operator's server if the phone was switched off or was out of network coverage. As soon as the device connects to the tower, all accumulated SMS are delivered to the recipient.