You won a cash prize, and the "sponsor" says they just need to log into your bank to drop the money in. Stop right there. Paying money into an account and pulling money out of it require completely different information — and no legitimate payer on earth needs your online banking username and password to send you a dollar. That one ask flips a prize into a robbery.

What a real payer actually needs (and what they never do)

To send you cash, a sponsor uses one of a handful of ordinary rails, and each needs only inbound details you can safely share. A paper check needs your name and mailing address. A direct ACH deposit needs your routing number and account number — the same two numbers printed on the bottom of every check you hand a landlord or employer. Newer options like Zelle, PayPal, or Venmo need only the email or phone number tied to your account. None of these require your password, your PIN, or a one-time login code. If a US prize is $600 or more, expect a request for a W-9 so they can issue a 1099 — that's your name, address, and Social Security number for tax reporting, delivered on an IRS form, not typed into a stranger's website.

Notice what's missing from every one of those methods: the keys to your online banking. Your username and password exist to let you move money out — pay bills, wire funds, drain the balance. A payer never needs the withdrawal keys to make a deposit, any more than a delivery driver needs your house key to leave a package on the porch. The moment "deposit your winnings" turns into "log in for us" or "give us your banking password so we can set it up," the story has stopped being about paying you.

Why handing over a login is account takeover, not a deposit

When you type your credentials into a scammer's link — or read them aloud over the phone — you have handed over account takeover on a silver platter. With your login they can drain checking and savings, open a linked credit line, add themselves as an authorized payee, and change your address and phone so the fraud alerts never reach you. If they trigger a one-time passcode to your phone and you read it back, you've defeated the two-factor protection that was your last wall. Many victims don't even realize the account is being emptied until days later, because the thief also turns off the very notifications that would warn them.

Recovery is nasty. Under Regulation E, banks generally must refund unauthorized electronic transfers, but the fight gets murky when the bank's logs show your verified login and your one-time code approving the transfers — it can look "authorized," and disputes drag on for weeks. Compare that to the downside of the safe methods: the worst that happens if a "sponsor" turns out to be fake after you shared a routing and account number is that they deposit to you, which is harmless, since those numbers can't pull money out on their own. The asymmetry is the whole tell. Inbound info is safe to share; the outbound keys never are.

If any "sponsor" asks for your online banking login, password, PIN, or a verification code, it is 100% a scam — hang up, and report it at reportfraud.ftc.gov. 🏦

A real prize costs you nothing and needs only where to send it — never how to get in.