A suspicious email, text or call is untrusted until you check it through a separate route. The real danger is not the message itself. It is being rushed into using its link, number or instructions.
- Open your bank, NS&I or mobile provider app yourself. Look for a secure message there.
- Type the official website address into your browser. Do not follow a link in the message.
- Call the number on your bank card, statement or official letter.
- Some UK banks support 159 from your linked number. Check that your bank supports it first.
A bank will not ask you to move money to a “safe account”. It will not ask for a one-time passcode or remote-access software. End the call if someone asks for any of these.
Use a separate check for every unexpected request. Do this even if the message shows your name or account number.
For a bank, open its official app. You can also call the number on your card. Do not call the number in the text.
For HMRC, sign in through GOV.UK by typing the address yourself. HMRC does not send tax refund texts asking for bank details. For an NHS appointment, use details held by your GP, hospital or NHS service.
For a delivery, enter the tracking number on the courier’s official website. For a mobile provider or public body, use a recent bill or official letter. This stops criminals from controlling both the warning and the supposed fix.
Spot phishing, smishing and vishing clues
Phishing emails, smishing texts and vishing calls seek the same things. They want passwords, card details, one-time codes, remote access or a payment.
| Contact route | Typical lure | Main risk | Safe action |
| Phishing email | HMRC refund or account warning | Fake sign-in page or attachment | Type the official website address yourself |
| Smishing text | Delivery fee, NHS alert or bank lockout | Card details or harmful app | Open the official app, not the link |
| Vishing call | Fraud team or police warning | Transfer, code or remote access | Hang up and call independently |
A familiar logo does not prove a message is real.
QR codes and WhatsApp messages
Safe verification route
1. Stop
Do not tap, reply or call back.
2. Separate
Close the message or end the call.
3. Verify
Use an app, statement or official website.
Treat any surprise request for a code, payment or app as a likely scam. Check it by an independent route.
Scam wording sounds believable because it mixes a known brand with urgency. A bank impersonation scam may claim there has been an unusual payment. It may demand confirmation within 30 minutes.
The link can lead to a fake sign-in page. The page may steal your password and card details. An HMRC refund scam may offer a small repayment but request a card “verification” fee.
A delivery fee scam may say a parcel needs a £1.99 payment. Treat an NHS text alert scam with the same care. Check appointment details through your usual NHS contact.
QR code scams are sometimes called quishing. A code on a poster, parking notice or email can open a fraudulent page. Never scan a code that asks for payment or account details without checking first.
WhatsApp scams can come from a hijacked contact. They may ask for a code or an urgent payment. Caller ID spoofing can also show a genuine-looking number.
The error most people make is trusting the number on screen. The request matters more than the displayed number. Hang up if you are told to move money, share a code or install software.
If you clicked, shared or paid: act step by step
If you sent money, call your bank at once. Minutes are better than hours.
Choose the action that matches the harm
| What happened | Do this now | Who to contact |
| You only clicked or replied | Close the page, update the device and check accounts | Report the message where appropriate |
| You entered a password | Change it on a clean device, starting with email | Bank, NS&I or affected provider |
| You gave a one-time code | Call the provider at once and secure the account | Bank or account provider |
| You installed remote access | Disconnect internet, remove access, then change passwords | Bank and trusted technical help |
| You sent money or card details | Ask the bank to freeze, trace or recall funds | Bank first, then Action Fraud |
A clicked link does not always result in a loss. A shared code or sent payment needs faster action. Tell the bank exactly what happened and when.
Report it through the right UK route
Forward suspicious texts to 7726. Forward suspected phishing emails to [email protected]. Do not reply to the sender first.
Report fraud to your bank before reporting elsewhere. The bank may be able to freeze access or try to recall money. Action Fraud can record the crime after you have contacted the bank.
A cross-cut shredder can help when clearing old statements and account letters. It cuts account numbers and addresses into small pieces. This lowers the risk from household rubbish or recycling.
A common case is someone sharing a one-time code after a fake bank call. The bank can act sooner when told immediately. Waiting until the next day can make tracing funds harder.
Your email and number need extra protection
Your email is the master key for many online accounts. It receives password-reset links.
Build a safer savings routine
Use a long, unique password for your email account. Store it in a reputable password manager. Turn on multi-factor authentication where it is available.
An authenticator app is often safer than a text code. It can reduce the risk from SIM-swap fraud. A SIM swap is when a criminal tries to take over your mobile number.
Turn on spam and phishing filters in your email account. Check recovery email addresses and phone numbers. Keep your phone, browser and apps up to date.
Updates close known security gaps.
Use call screening or spam-call blocking on your device. Ask your mobile network about suspicious-call and SIM-swap protection. These settings cannot stop every scam, but they can reduce nuisance calls.
If a criminal has your email and phone number, they can send convincing follow-up messages. Those details alone do not give them account access. Strong email security stops many takeover attempts.
Report beyond the United Kingdom
Report messages through the service in the country where you live. If you are in England, use 7726 for texts. Use [email protected] for phishing emails.
The National Cyber Security Centre gives UK guidance on reporting suspicious messages. Its advice supports the same rule: do not trust a link or caller number by itself.
This advice is less relevant when there was no unexpected contact or request for information. It does not replace urgent help after major loss, identity theft or a compromised device. Contact your bank, Action Fraud, police or a cyber security professional.
Frequently asked questions
Can a scammer hack my phone from a text?
A scam text rarely hacks your phone merely by arriving. Risk usually rises after you tap a link, open an attachment or install an app. Rare zero-click attacks exist, but they are not the usual threat for UK consumers.
How do I forward a text to 7726 on iPhone?
Press and hold the message, tap More, then choose Forward. Send it to 7726 and include the sender’s number if asked. Do not reply to the scammer before forwarding.
What should I do with a suspicious email?
Forward a suspected phishing email to [email protected], then delete it. Do not open its links, attachments or reply address. Change your password through the official service if you entered it.
Is it bad if a scammer has my email and phone number?
Having both details raises the risk of follow-up scams. It does not give automatic account access. Use a unique email password, two-factor authentication, and watch for reset links or security codes.
Keep one rule for every unexpected contact: stop, separate and verify. Use contact details you find yourself. Never trust the link, number or QR code in the message.
- The essentials: Sender names, logos and phone numbers can be faked. Check through contact details you find independently.
- The essentials: Forward UK scam texts to 7726. Send phishing emails to [email protected] without replying.
- The essentials: Call your bank immediately after sharing a code, installing remote access or sending money.
- The essentials: Unique passwords, two-factor authentication and app updates limit damage after a stolen login.
Further reading
If you want to learn more about this topic, these sources may interest you: