Independent KheloMore India resource18+ only · play within limits
Account access

Troy teen loses bank account access after falling for a job scam disguised as a school email: how the check-deposit pattern works and why a student bank account can close for five years

A 16-year-old Troy student received a work-study offer in June that appeared to come from a Bloomfield Hills Schools address, deposited three $500 checks sent by the scammer, and was then asked to send $900 back through Zelle. The checks later bounced, the bank closed the account, and the family was told the closure would be reported to ChexSystems and Early Warning — a designation that can keep a minor from opening a new bank account for up to five years. The teen did not ultimately lose money, but the account he did have is gone, and the path back to a normal account is now longer than his high-school career.

Wide evening view of a school building and athletic field establishing the setting for a work-study email that arrived in June

The scam was reported on 30 July 2026 by WXYZ Channel 7 in Detroit, with the teen's father confirming the account closure and the ChexSystems notification. The Bloomfield Hills Schools district told WXYZ it was unaware of the incident and urged families to verify any unexpected email before responding, even when the sender appears to be a school staff member. The checks arrived by mail, the deposit was made through the Bank of America mobile app, and the Zelle request landed on the same phone that had been used to apply for the "job." Each step was small enough to look routine. Each step was also enough on its own to make the next one feel safe.

The teen told WXYZ that he recognised the offer as a scam after the checks had already been deposited and the Zelle request had already been made. He did not send the $900. The check images the family had kept on file showed a Boston-area return address, the spelling of the bank's name was inconsistent with the real institution, and the work-study description asked for personal data and a bank account before any offer letter, interview, or paperwork had been exchanged. None of those details were visible to the teen at the moment of deposit, because the deposit screen on a mobile app shows routing and account numbers, not the front of the check.

How the school-email part of the scam worked

The work-study message arrived in June to the teen's school-issued email account. The body described a position, a schedule, and a compensation figure, and it was signed as Bloomfield Hills Schools. The sender address, however, was a student account using a bloomfield.org domain that any student in the district could have created. The address was not a staff or faculty address, and it did not require district approval to set up. To a 16-year-old reading the message on a phone between classes, the combination of a school email, a school domain, and a school signature looked convincing enough to reply.

That is the core of the school-email pattern. The scammer does not need to break into a school system; they need to use a school-branded surface that the recipient will not pause to verify. The two surfaces that work best are the school-issued email account (which the recipient expects to receive school mail on) and the school domain (which is a public suffix any student can register an address against). When both appear in the same message, the recipient's instinct to be cautious is replaced by the instinct to respond to a teacher.

The reply chain is where the personal data is collected. In the Troy case, the teen supplied his phone number, residential address, and personal email through the application. That is the minimum the scammer needs to send the checks by mail and to follow up by Zelle. It is also the maximum the scammer will ask for before the deposit step, because the deposit step requires those three pieces of information to match the name on the bank account.

Why three checks for $500 each

Three $500 checks is the smallest setup that produces a problem worth the bank's attention. A single $500 check is too small for a routine bank to flag on mobile deposit; a single $1,500 check is large enough that a 16-year-old with a student account might pause. Splitting the deposit into three pieces keeps each individual deposit below the threshold that triggers a hold, while the total of $1,500 is enough that the $900 Zelle request feels plausible alongside it. The math is the scam: the teen thinks the bank has cleared $1,500 of "their" money, and the scammer has not yet sent any of it.

The mobile-deposit feature is what makes the three-piece pattern work. Bank of America's mobile deposit accepts a check image in under a minute, places a hold on the funds until the check clears, and makes the "available balance" visible to the account holder before the check has actually been paid by the issuing bank. The available balance, not the cleared balance, is what the teen sees on the screen. The available balance is what makes the Zelle request feel safe.

Zelle is what turns the available balance into a transfer the teen cannot reverse. Zelle settles in minutes, and the bank does not intervene in a Zelle transfer the way it sometimes intervenes in a wire or a card transaction. The combination of a held check on the deposit side and an instant Zelle on the reverse side is the geometry of the scam: the bank's hold takes days to fail, and the Zelle transfer is already gone by the time the bank sees the bounced check.

What ChexSystems and Early Warning do to a minor

Close view of a bank account screen showing a closed status and a flag that limits the holder from opening new accounts for several years

ChexSystems and Early Warning are the two consumer reporting agencies that banks use to decide whether a new account applicant can be approved. They are not the credit bureaus; they do not hold a credit score. They hold a banking history: every closed account, every unpaid fee, every instance of a deposited item that bounced after the funds were spent. When a bank closes an account for fraud-related reasons, the closure is reported to one or both of those agencies, and the report stays on file for up to five years.

For adults, a five-year ChexSystems flag means five years of prepaid debit cards, cash-only banking, and second-chance accounts at higher fees. For a 16-year-old, a five-year flag means the teen cannot open a standard checking account when he turns 18 — the year most American teenagers expect to open their first real bank account. The teen's first job, first lease, first car loan, and first credit card are all gated on a basic checking account, and the basic checking account is now five years away. The five-year figure in the WXYZ report is the timeline the family was given, not the worst-case figure; for an adult, the same flag can extend further.

The closure also removes the account the teen walked into the scam with. The teen does not get to keep the account and add a flag; the account is closed, the balance is returned (in this case, because the teen did not actually send the $900), and the account number is recycled into the bank's pool. The teen's next bank will run a ChexSystems pull, see the closure, and either decline the application or offer a second-chance account with monthly fees that a standard account would not have. The five-year figure is the period the family is now planning around.

The four pre-deposit checks that would have stopped it

Four checks, taken in order, would have caught this pattern before any check was deposited. The first is the sender address. A work-study email from a school district should come from a staff or faculty address, not a student account. A student account on a school domain is a registered address, not an institutional one, and any reply to a student account for an official matter should be a flag. The teen's father told WXYZ that the department had not sent the message; the district itself confirmed it. The verification step is one extra email to the school's front office, and it is the check that fails first in this pattern.

The second check is the position itself. A work-study offer that arrives without an application, an interview, an offer letter, or a payroll schedule is not a normal school-side job. Normal school-side jobs involve a teacher or a coordinator, a defined set of hours, an IRS Form W-4 or W-9, and a payroll account that the school controls. A job offer that asks for a personal bank account before any of those steps is, by definition, not a payroll job, and the absence of paperwork is the signal that the "payroll" is a check the applicant has to manage themselves.

The third check is the check itself. A check is a negotiable instrument, and the issuing bank, the routing number, and the account number on the front of the check should match the issuing bank's records. A Boston-area return address on a check sent to a Troy student is a geographic mismatch that the bank can verify in ninety seconds with a phone call. The spelling of the bank's name on the check should match the spelling of the bank's legal name on the FDIC's institution directory. In the Troy case, the spelling did not match, and that mismatch was visible on the image the family kept.

The fourth check is the request to send money back. A payroll job does not pay an employee and then ask the employee to refund a portion of the payment. The Zelle request is the moment the shape of the transaction stops being a job and starts being a routing exercise, and the routing exercise is the one the scammer needs the teen to complete before the check has bounced. The four checks, taken in order, move from "is this email real" to "is this cheque real" to "is this job real" to "is this transaction real." Any one of the four failing would have stopped the chain before the account was closed.

What the under-20 loss numbers really mean

WXYZ cited a Consumer Federation of America report that said Michigan residents lost $2.7 billion to online scams and crimes in 2025, nearly 60% more than the prior year. The same report said reported losses among people under 20 increased 198% from 2024, even though that age group remained the smallest targeted demographic in absolute dollars. The Detroit station ran the figures alongside the Troy story to give the under-20 number context, and the context is worth reading carefully.

A 198% increase in a small base is not a 198% increase in the threat to the average teenager. The under-20 group is the smallest targeted demographic in absolute dollars, which means the average teenager is still far less likely to be the target of a scam than the average adult. The 198% number is the rate of change, not the rate of occurrence. The rate of occurrence is what matters for any individual teen, and the rate of occurrence remains low.

What has changed is the conversion rate. When a teen is targeted, the pattern is more likely to succeed than it was two years ago, because the school-email surface and the mobile-deposit surface are both more credible than they were in 2024. The Troy case is the conversion-rate story: the teen was targeted, the teen engaged, the teen reached the deposit step, and the teen only stopped at the Zelle step. The next year's data will tell whether the same pattern is converting at the same rate on a larger target list.

What the Troy police advice actually covers

Troy police sergeant told WXYZ that the warning signs are the same ones any first-time scam briefing covers: an unsolicited offer of money, a request for personal data before any paperwork, a payment that requires a return payment, and a sense of urgency that pushes the recipient past the verification steps. The sergeant's advice was to slow down, verify the offer through a separate channel, and refuse any payment that requires a partial return. None of that advice is new. The Troy case is the reminder that the standard advice still works when it is followed, and the standard advice still fails when the routing is good enough that the recipient does not pause to follow it.

For a parent, the practical version of the police advice is to put the verification step on the parent. The teen should not be the only person reading the work-study email, the check, the deposit confirmation, and the Zelle request. A parent, a guardian, or an older sibling who sees the same message on a separate device is the second set of eyes that converts the school-email surface from a credible channel into a suspicious one. The Troy case had a parent who saw the checks after the fact; the version of the case where the parent saw the email before the deposit is the version where the account is still open.

For a teen, the practical version is to treat the deposit screen as the deadline. The point at which the teen is asked to take a photo of the check and tap "deposit" is the point at which the teen has the most information and the least time pressure. The bank will still hold the cheque for several days; the deposit can be cancelled before the cheque is sent for clearing by calling the bank's mobile-deposit support line. The deposit screen is the place to pause, not the place to confirm.

What a school district can and cannot do

Bloomfield Hills Schools told WXYZ it was unaware of the incident and urged people to verify unexpected emails or requests before acting. The district's response is the district's only realistic response: it cannot stop a student from registering an email address on its own domain, and it cannot stop a person outside the district from sending a message that looks like it came from inside the district. The most a district can do is publish a routine reminder to families that work-study offers and similar messages will come from a staff email, not a student email, and that any offer should be verified through the school's front office before the recipient replies.

Districts that have moved to staff-only email for student communications have raised the bar. A district that uses a separate communications system for student-facing messages (a learning management system, a parent portal, a robocaller) makes the school-email surface less useful for a scammer, because the parent and the teen both know that real school mail arrives through the specific system, not through a Gmail or Outlook address on the school domain. The Troy case is one data point in a longer argument for that kind of change.

A district cannot, however, refund a bounced check, reopen a closed bank account, or remove a ChexSystems flag. Those consequences live at the bank, and the bank's remedy is the closure itself. The district's job is to prevent the next email from being credible. The bank's job is to prevent the next cheque from being deposited. The family's job is to make sure the verification step happens before either of those jobs starts to matter.

How this pattern looks on a mobile app

Medium view of a phone screen showing the mobile deposit step and a Zelle request arriving on the same device

The mobile app is the surface where the four checks fail in sequence. The email arrives on the phone, the reply is typed on the phone, the check is photographed on the phone, the deposit is submitted on the phone, and the Zelle request arrives on the phone. The teen's hands never leave the device, and the device's screen never shows the suspicious context. The bank is on one app, the school is on another app, the Zelle transfer is on a third app, and the phone's lock screen is the only place where the four pieces of context sit side by side.

For any reader who has a teen in the household, the parallel pattern on a sports-booking app is worth naming. A "part-time job" or "work-study" offer that arrives by email, asks for a deposit or a returned payment, and uses a school or academy domain to look credible is the same pattern as a "trial credit" or "venue deal" that arrives by SMS, asks for a UPI payment to confirm the slot, and uses a familiar brand name to look credible. The structure is identical. The difference is the audience: one targets a 16-year-old, the other targets a 25-year-old.

Both patterns fail in the same place: the verification step. A teen who forwards the work-study email to a parent before replying is the same as a sports-booker who opens the KheloMore app and checks the official slot before paying the UPI request. The verification step is short, free, and frictionless. The cost of skipping it is the closed account, the bounced cheque, and the five-year flag. The four pre-deposit checks listed above work for both patterns, and the order of the checks is the same.

For KheloMore users, the practical read is that the account on the other side of any UPI or card request is the same kind of account that failed in Troy. The verification step is the same. The phone is the same. The sense of urgency is the same. The KheloMore account-access notes for Indian players walk through the same shape for a sports-booking account, with the practical differences a user should expect when phone verification, recovery options, and funding sources each behave slightly differently on a real device in a real Indian city. The pattern is the same; the specifics are local.

What the bank does and does not do after the closure

After the bank closes an account for fraud-related reasons, the bank returns the account balance to the account holder (in this case, the teen recovers the original funds because the Zelle transfer was not sent), reports the closure to ChexSystems and Early Warning, and assigns the account number to the bank's internal pool. The bank does not refund the bounced-cheque fees that were charged during the deposit window, does not refund the mobile-deposit fees that were charged on each of the three checks, and does not refund any overdraft fees that may have accrued while the available balance was temporarily inflated by the uncleared cheques. The bank also does not refund the time it takes to clean up the closure, which is the largest cost of the incident for the family.

The bank also does not automatically contact the police. The family filed the report with the Troy police after the closure, and the case is being handled as a fraud complaint. The cheque images and the Zelle request are the evidence in that case. The cheque images show the Boston-area return address and the inconsistent bank spelling. The Zelle request shows the phone number, the email address, and the recipient name on the Zelle side. The combination is enough for a fraud report; it is not enough for a recovery of the $1,500 in cheques, because the cheques themselves were fake.

For the teen, the next eighteen months are the period that matters most. The ChexSystems flag runs for five years from the closure date, but second-chance accounts and prepaid accounts are available in the meantime. A second-chance account at a different bank, with monthly fees that are higher than a standard account, gets the teen through the next eighteen months with a basic checking account. The five-year flag is the timeline for a standard account. The eighteen months is the timeline for a routine, fee-bearing account. The two are different products, and the family should plan for the second-chance account first and the standard account later.

What to watch for in the next school email

Three patterns will tell a reader whether the next school email is the same scam. The first is the sender address. A work-study email from a school district should come from a staff or faculty address, not a student account. The second is the offer itself. A work-study offer that arrives without an application, an interview, an offer letter, or a payroll schedule is not a normal school-side job. The third is the request for a personal bank account and a personal phone number before any paperwork has been exchanged. The three patterns together are the signature of the school-email scam. Any one of them appearing alone is a flag; any two of them appearing together is a stop.

Two further patterns will tell a reader whether the cheque is the same cheque. The first is the geographic mismatch: a cheque with a Boston return address arriving at a Troy address is a flag that the bank can verify in ninety seconds. The second is the spelling of the bank's name: a cheque whose issuing bank name does not match the spelling of the bank's legal name on the FDIC's institution directory is, by definition, a check that a real bank did not issue. The bank can confirm both. The teen can sit with the cheque image for a minute before depositing and verify both. The sixty seconds is the gap between a closed account and an open one.

One pattern will tell a reader whether the request is the same request. The pattern is the request to send money back. A payroll job does not pay an employee and then ask the employee to refund a portion of the payment. The Zelle request is the moment the shape of the transaction stops being a job and starts being a routing exercise. A reader who reads the WXYZ story has seen the pattern. A reader who sees the same pattern in the next email is the version of the case where the account is still open.

A short checklist for teens and parents

Verify the sender address before replying. A work-study email from a school district should come from a staff or faculty address, not a student account. Forward the email to a parent or a guardian before the reply is sent. The verification step is short, free, and frictionless; the cost of skipping it is the five-year flag.

Verify the position before any data is shared. A work-study offer that arrives without an application, an interview, an offer letter, or a payroll schedule is not a normal school-side job. The absence of paperwork is the signal that the "payroll" is a check the applicant has to manage themselves.

Verify the cheque before the deposit. The cheque's return address, the issuing bank's name, the routing number, and the account number should all match. A Boston-area return address on a check sent to a Troy student is a geographic mismatch that a phone call to the issuing bank will resolve in ninety seconds.

Verify the request before any money is sent. A payroll job does not pay an employee and then ask the employee to refund a portion of the payment. The Zelle request is the moment the shape of the transaction stops being a job and starts being a routing exercise. The teen should refuse the request, and the parent should be the one who calls the bank.

File the fraud report with the local police within the first 24 hours. The cheque images and the Zelle request are the evidence. The bank will need the police report number to confirm the closure, and the family will need the police report number to start the ChexSystems dispute process. The 24-hour window is the window in which the evidence is still on the phone, the bank account is still being closed, and the recipient is still reachable.

The Troy case is the pattern. The version of the case where the verification step happens before the deposit is the version where the account is still open. The four pre-deposit checks fail in sequence, and the teen who reads the WXYZ story has seen all four. The next school email is the test. The parent who reads the cheque before the teen taps deposit is the answer.