Home › Guides › Phishing emails and scam calls: how to spot them and what to do

Phishing attacks and scam calls have become more convincing. Scammers are getting better at impersonating legitimate organisations, and they know personal details about you from social media and data breaches. Learning to spot them can protect you from losing money or having your identity stolen. Unlike technical hacks, spotting phishing relies on noticing what feels wrong.
What is phishing?
Phishing is a social engineering attack: a message (email, text, or call) that tricks you into revealing passwords, personal information, or financial details, or into clicking a link that installs malware. The attacker impersonates someone you trust—your bank, a government department, a delivery company, or even someone in your workplace.
Five common phishing tactics
Scammers use five psychological tricks repeatedly. Recognising them helps you spot phishing:
1. Authority. The message claims to be from a trusted organisation: your bank, HMRC, Ofcom, an IT company. Scammers use official logos and language to seem legitimate.
2. Urgency. The message creates artificial time pressure: “Your account will be closed in 24 hours” or “Verify your identity immediately.” Urgency makes you skip thinking and act fast.
3. Emotion. The message triggers fear, excitement, or curiosity. A threat (“Your card has been cloned”) or a reward (“You’ve won a prize”) can make you react without questioning.
4. Scarcity. The message claims something is limited: “Last few spaces available” or “This offer expires today.” Scarcity makes people feel they’ll miss out if they don’t act now.
5. Current events. Scammers use news, holidays, or seasonal moments for credibility. A phishing email about a delivery issue arrives during the busy Christmas shopping period when you genuinely expect parcels.
Spotting a phishing email
Look for these signs, though modern phishing is subtle and a well-made fake can fool anyone:
Unusual sender address. Your bank isn’t emailing from “[email protected] ”—check the full email address carefully. Scammers register similar domain names hoping you won’t look closely.
Requests for passwords or financial details. Your bank will never ask you to confirm your password via email or phone. Legitimate organisations don’t ask for sensitive information unsolicited. If you’re unsure, hang up and call the organisation directly using a number you know.
Suspicious links. Hover over a link in an email (don’t click) to see the actual address it points to. Does it match the supposed sender? A link saying “Click here to verify your account” might point to “phishing-site.net/fake-bank” instead of your actual bank’s website. If in doubt, don’t click.
Unfamiliar attachments. Emails with attachments from unknown senders are high risk. Attachments can contain malware. If you weren’t expecting it, don’t open it.
Misspellings or odd formatting. Legitimate companies proofread. A message with spelling mistakes, strange spacing, or odd grammar is a red flag. That said, modern scammers can write well, so this isn’t reliable on its own.
Generic greetings. “Dear customer” instead of your name is a warning sign, though mass phishing often uses your name harvested from data breaches.
Spotting a scam call
Scammers call claiming to be from:
- Tech support (“We’ve detected a virus on your computer”)
- HMRC (“You owe tax”)
- Your bank or building society (“Unusual activity on your account”)
- Ofcom (“Your internet has been compromised”)
Red flags:
- They want you to give them remote access to your computer or to tell you a password
- They’re pressing you to act immediately
- They’re asking for financial information or asking you to transfer money
- They claim you’ll be arrested or disconnected from services if you don’t comply
What legitimate support never does:
- Calls unsolicited claiming there’s an emergency with your computer, account, or internet
- Asks for your password
- Asks for remote access to your computer
- Pressures you to pay immediately
What to do if you spot phishing
For suspicious emails:
- Don’t click links or open attachments
- Forward the email to [email protected] (a free service run by the NCSC and Action Fraud)
- Delete the email
- If the email claims to be from your bank or another trusted organisation, contact that organisation directly using a phone number or website you know is genuine
For text message scams:
- Don’t reply or click links
- Forward the message to 7726 (free, and works on most UK mobile networks; you text “7726” and forward the scam message to that number)
- Delete the message
For scam calls:
- Hang up immediately
- Don’t give any personal or financial information
- Don’t press buttons or give the caller any response (scammers record responses to sell to other criminals)
- Report the call to Action Fraud using the online form or by calling 0300 123 2040
If you’ve already been caught
If you’ve given your password or financial details:
- Change your password immediately from a different device if possible
- Contact your bank and credit card companies to report the fraud
- Monitor your accounts for suspicious activity
- Report the fraud to Action Fraud (0300 123 2040 or online at actionfraud.police.uk)
- Check your credit report (free via Experian, Equifax, or Clearscore) to spot identity theft
If you’ve installed what you think is malware:
- Disconnect the computer from the internet
- Scan it with antivirus software (Windows Defender, Malwarebytes, or Kaspersky)
- If you can’t remove it, take the computer to IT support
- Change passwords from a different device
If you’ve sent money to a scammer:
- Contact your bank or payment provider immediately—they may be able to freeze the transaction if it hasn’t cleared
- Report it to Action Fraud
- The police rarely recover money from scam transfers, but reporting creates records that help law enforcement track organised scam operations
Protecting your organisation
For small businesses, train staff to:
- Question unexpected emails, even if they seem to come from management
- Verify requests for financial transfers via a phone call to the person using a known number
- Report suspicious emails to the admin rather than just deleting them
- Enable two-factor authentication on important accounts (email, banking, cloud storage)
- Use a password manager to generate unique passwords so a breach at one organisation doesn’t compromise others
Key points
- Phishing uses five tactics: authority, urgency, emotion, scarcity, and current events—spotting them reduces your risk
- Bank calls and emails requesting passwords or financial details are phishing; legitimate organisations never ask this
- Report phishing emails to [email protected] ; report texts to 7726; report calls to Action Fraud (0300 123 2040)
- If you’ve been caught by phishing, contact your bank and Action Fraud immediately—speed matters
- Tech support calls claiming you have a virus and offering to “fix” your computer are scams; hang up
- If your organisation has multiple staff, security training and procedures reduce everyone’s risk
Related: Find IT support near you