upvote
No "challenge code" your profile can be used to authenticate a caller. Profiles get leaked, almost all of them have been at some point, or at least that's the safe assumption to operate under.
reply
In the UK, banks like Starling, Monzo and Revolut (and building societies such as Nationwide) have added a call status feature in their apps [0][1][2] that tells you if they are actually the ones calling.

[0] https://www.starlingbank.com/news/starling-bank-launches-in-...

[1] https://monzo.com/help/monzo-fraud-category/monzo-call-statu...

[2] https://www.bbc.co.uk/articles/c1mj02vr0emo

reply
Yeah, this is a no brainer (and I think most banks let you verify via the app rather than personal info) to avoid the annoying uncertainty (but note my mother would not be able to handle that I expect)
reply