NS&I will not ask you to share passwords, one-time codes or bank details through an unexpected email, text or call. Before signing in, claiming a Premium Bonds prize, changing details or moving money, use NS&I’s official website or contact details you found independently.
Check the contact channel before trusting its wording.
| Channel | What may look convincing | Never treat as proof | Safe action now |
|---|
| Email | NS&I logo, prize wording, a familiar name | Display name or a blue login button | Do not open links; inspect the full sender address |
| Text message | A message in an existing thread | Sender ID, thread history or urgency | Do not reply; forward it to 7726 |
| Phone call | A familiar number or account details | Caller ID or a calm, informed caller | End the call; find NS&I independently |
| Website | HTTPS padlock and copied NS&I design | Padlock, certificate or a polished page | Close it; enter NS&I through a trusted bookmark |
A text appearing alongside older genuine NS&I messages proves nothing: criminals can spoof sender IDs. Never call the number in a suspicious message to check it, because that keeps you on the scammer’s route.
Verify through an independent route
Open a new browser window and use a saved bookmark or trusted paper record.
NS&I phishing scams sent by email often use a genuine-looking display name while hiding a different reply-to address or a misspelt domain. Treat a message about an unclaimed Premium Bonds prize, a suspended account or an urgent security update with caution, especially if it contains a fraudulent email link, an attachment or pressure to act before a deadline. Hover over a link without selecting it to view its destination, but do not rely on the visible wording alone.
A legitimate-looking logo and polished layout do not make an email safe. Instead, open NS&I separately through a known route and check whether the claimed alert appears after you sign in.
Reject spoofed calls and fake NS&I sites
Reject unexpected requests for a password, code or payment.
Treat caller ID as decoration
End the call if the caller asks you to act while they wait.
A spoofed caller ID is a false number shown on your phone. Do not trust a caller because they know your postcode, bond number or bank details; hang up and contact NS&I through a number you found independently.
Check the domain, not the padlock
Read the web address character by character before entering account details.
Safe NS&I verification route
1. Stop
Do not tap, reply or call
2. Separate
Open a fresh browser
3. Verify
Use a known NS&I route
4. Act
Follow the exposure level
A pharming scam can be harder to spot than an ordinary phishing link because it may redirect you from a correctly typed NS&I address, or even a saved bookmark, to a fake NS&I website. This can happen if malicious software, a rogue browser extension or altered router DNS settings change where your device is sent. To verify a website safely, check the complete domain carefully, look for unexpected extra words or spelling changes, and be suspicious of a login page that asks for information it does not normally request.
An HTTPS padlock scam is still possible: HTTPS encrypts the connection but does not prove the operator is NS&I. If several devices on the same Wi-Fi show unusual redirects, stop using that network for sign-ins, update the router and seek trusted technical help.
Act by your level of exposure
Match your response to what you shared or clicked.
Follow the exposure action matrix
| Your exposure | Do this now | Keep before blocking |
|---|
| Received only | Do not reply or click; report, then block | Screenshot, sender and time |
| Clicked a link | Close it; run security updates and checks | Exact URL and screenshot |
| Entered NS&I details | Change passwords from a trusted device; contact NS&I independently | Page address and time |
| Shared bank details or code | Call your bank fraud team immediately | Number called and code request |
| Paid or installed software | Ask the bank to trace payment; disconnect the device from the internet | Amount, reference, app name |
If you installed remote-access software, disconnect the device and do not use it for banking, NS&I or email. Use another trusted device to contact your bank, especially if money or security codes were involved.
Save evidence without reopening harm
Save screenshots, sender details, the exact URL, date, time, amount and payment reference.
Report NS&I impersonation without delay
Report through separate, trusted channels.
Tell the right organisation
Contact NS&I independently if the scam used your account, prize claim or details.
Contact your bank’s fraud team immediately if you disclosed bank details, gave a code or sent money. Report texts to 7726 and phishing emails to [email protected]; you can also check Action Fraud and the National Cyber Security Centre.
Know when this guide is not enough
Call your bank urgently if a payment is pending or an account is being accessed.
This guidance does not replace urgent contact with your bank or emergency services where a transfer is in progress, unauthorised access is happening or there is immediate risk. An unexpected contact is not automatically a scam, so verify it through an independent NS&I route rather than assuming either way.
Keep a record before reporting: save screenshots of the message or page, the full sender address or number, the exact URL, date and time, and any payment reference. Forward suspicious text messages to 7726 so your mobile network can investigate scam texts; do not forward links to friends or family. Send suspicious emails to [email protected], and report a scam or financial loss through the appropriate UK fraud-reporting route, including Action Fraud where applicable. If caller ID spoofing was used, tell your phone provider the displayed number, time and nature of the call.
For bank detail scams, one-time code fraud or an unauthorised payment, contact your bank first because it may be able to stop or trace a transfer. Then contact NS&I through an independent contact route and carry out account security checks from a trusted device.
Questions & answers
Do NS&I send text messages?
NS&I may send texts, but a message alone does not prove it is genuine. Verify independently.
Can a fake text appear in my NS&I thread?
Yes. Sender ID spoofing can place a fraudulent text in an existing-looking NS&I thread.
Does the HTTPS padlock prove an NS&I site is safe?
No. It shows an encrypted connection, not that the website belongs to NS&I.
Why would NS&I call me?
NS&I may call about an account, but independently check any unexpected call or request.
What should I do if I gave a security code?
Call your bank’s fraud team immediately, then change affected passwords from a trusted device.
What is pharming on an NS&I login?
Pharming redirects you to a false site, sometimes through altered device or router settings.
- The essentials: a familiar sender name, number or message thread cannot verify NS&I identity.
- The essentials: verify through a browser route or contact detail you already trust, never through the suspicious contact.
- The essentials: preserve the URL, sender, time and payment reference before blocking when you have interacted.
- The essentials: contact the bank first when money, bank details or security codes are involved.
Further reading
If you want to learn more about this topic, these sources may interest you: