How to spot phishing email and phone scams

We've teamed up with fraud expert Tim Mitchell from Get Safe Online to help you stay one step ahead of the fraudsters and spot even the most cunning of scams - including the latest AI-powered phishing attacks and smishing texts targeting people in 2026.

It's a common scenario: you open up your emails and there in your inbox is an email congratulating you on your million pound win. All you have to do is click the link to share all your account details and pay £100 to cover the transfer fee. It can be pretty easy to scoff at examples like this. After all you'd never fall for it, right?

But losing money to a scam is much easier than you'd think. In recent research by Get Safe Online, 80% of respondents to a survey said they could confidently identify a scam email or phone call. However, in a separate test of over 63,000 people, only 9% who completed the quiz scored full marks. It's a pretty eye-watering stat, and just goes to show how anyone can become a victim, however smart or savvy.

To help stop it happening to you, we've teamed up with Get Safe Online's fraud expert Tim Mitchell. With his help you'll be better equipped to identify even the most cunning of online scams - from classic phishing emails to the latest deepfake voice scams - to keep your money and your identity safe online.

What is the number one type of fraud that you think our users need to be aware of?

The biggest issue right now is people falling victim to what we call 'social engineering' fraud - and in 2026, fraudsters have supercharged these tactics using artificial intelligence. This simply means manipulating or tricking someone into performing certain actions, such as divulging personal or financial information. A con, in other words - but one that's increasingly hard to detect.

Unfortunately, financial fraud has always been a massive issue. But as we live more of our lives online, more people are becoming vulnerable to this type of fraud, and more people are losing money to it. AI-generated scam emails and deepfake phone calls have made social engineering even more convincing - but while these scams are becoming more convincing, knowing the warning signs can reduce your risk.

To help our users steer clear, how do these social engineering scams trick people into handing over too much information?

At Get Safe Online we've seen how social engineering scams come in all shapes and sizes ranging from the ridiculous to the nearly impossible to identify. And unfortunately people are falling for these every day. Here are the main ones you need to be aware of:

Phishing email scams

Phishing is still the most common entry point for fraud, and in 2026 it's more sophisticated than ever. Fraudsters often pretend to be someone official such as a bank, online retailer, HMRC, or a government agency - and AI tools now let them craft near-perfect, personalised messages that are far harder to spot than the misspelled emails of the past. They'll ask you to share confidential private information such as your banking details or login credentials. Some phishing emails contain an attachment which, if clicked, can lead to a virus or spyware being downloaded on to your device.

A newer and rapidly growing variant is spear phishing - highly targeted attacks that use your name, employer, or recent activity to appear even more convincing. Always be suspicious of any unexpected email asking you to click a link or provide details, even if it looks personalised and legitimate.

Smishing: SMS and WhatsApp scams

Smishing - phishing carried out via text message or WhatsApp - has surged in recent years and is now one of the most reported scam types in the UK. You might receive a text claiming to be from Royal Mail, your bank, or even HMRC, asking you to click a link to resolve an issue. These messages often create a false sense of urgency. Never click links in unexpected texts; go directly to the official website instead.

Social media scams

We've seen a big rise in people losing money through social media, and this trend has only accelerated. You may have seen posts promising a free £50 supermarket voucher in return for clicking on a link, or fake giveaways impersonating well-known brands and celebrities. In 2026, AI-generated video content - sometimes called deepfakes - is being used to make these scams look even more credible. Just consider why any company or public figure would be giving money away before you click.

So does this sort of thing only happen online, or should we be keeping watch elsewhere too?

Phone call scams and vishing

It's certainly not all online - in fact some of the most convincing scams come via a phone call, a tactic known as vishing (voice phishing). Typically, you'll get a call from someone claiming to be from your bank, telling you that your account has been compromised, and that the bank needs your OK to move your balance into a new account. In reality a bank would never ask for your full password, PIN, or one-time passcode over the phone - and they will never ask you to move money to a 'safe account'.

In 2026, fraudsters are also using AI voice-cloning technology to impersonate people you know - a family member, your boss, or even your GP - to make requests seem urgent and trustworthy. If you receive an unexpected call asking you to transfer money or share sensitive information, hang up and call the person or organisation back on a number you find yourself.

Another kind of phone scam is the computer support scam. I was working at an online safety event recently, and a man told me that his computer had been locked by ransomware, asking me how this might have happened. He swore that, knowing the dangers, he hadn't clicked on any links or attachments. It was only after probing, that he told me he'd had a call from 'Microsoft' a couple of weeks earlier, and the nice operative on the other end had fixed his problem. What had in fact happened, is that the caller was a scammer, who had infected his computer with the malware. Not only that, but he'd been charged as well!

Phishing vs smishing vs vishing: how to tell them apart

The article above covers three major social engineering channels. Here's a quick-reference table so you can tell them apart at a glance - including the typical warning signs and how to report each one in the UK.

Scam type

Channel

Common impersonators

Typical red flags

How to report (UK)

Scam type

Phishing

Channel

Email

Common impersonators

Banks (e.g. Santander, HSBC), HMRC, PayPal, Amazon, Royal Mail

Typical red flags

Urgent language demanding immediate action; suspicious sender address or misspellings; links that don't match the official domain; unexpected attachments

How to report (UK)

Forward the email to report@phishing.gov.uk and report to Action Fraud (0300 123 2040)

Scam type

Smishing

Channel

SMS or WhatsApp

Common impersonators

Royal Mail, delivery couriers, banks, HMRC, NHS

Typical red flags

Short, urgent message with a shortened or unfamiliar link; request to verify identity or pay a fee; messages appearing in the same thread as legitimate texts

How to report (UK)

Forward the text to 7726 and report to Action Fraud

Scam type

Vishing

Channel

Phone call

Common impersonators

Bank fraud teams, police, HMRC, Microsoft tech support, broadband providers

Typical red flags

Caller asks for PINs, passwords, or one-time codes; pressure to transfer money to a "safe" account; AI-cloned voice of someone you know; spoofed caller ID

How to report (UK)

Hang up, call 159 (the Stop Scams Helpline) to verify, then report to Action Fraud

If you're ever unsure which type of scam you're dealing with, the golden rule is the same across all three: stop, don't engage, and verify independently by contacting the organisation through its official website or phone number.

What are the main warning signs of a scam?

Is the email or message threatening you to take action right now?

Typically, messages claiming to be from your bank, HMRC, the DVLA or the police will tell you that there's a problem that will result in your money or identity being put at risk, and will urge you to click through to a website to take action. This will normally involve supplying your confidential login details. Any message that asks you to act immediately is likely to be suspect - it's designed to make you flustered in the hope you'll make a mistake.

Have you been promised a reward, a competition win or a tax refund?

Any email, text, or call claiming to be giving you money should be considered with a watchful eye - especially if they are demanding your details in order to claim it. Reveal your logins, and a fraudster has free rein to get into your bank account (and maybe other accounts if you use the same details). HMRC tax refund scams are perennially common, particularly around the end of the tax year.

Could the message have been sent to anyone?

Generic greetings like 'Dear Sir or Madam' or 'Dear valued customer' are an easy sign that this message has probably been fired off to as many addresses as possible. That said, more sophisticated spear phishing attacks in 2026 may include your real name - so personalisation alone is no longer a guarantee of legitimacy.

Does something feel slightly off, even if you can't put your finger on it?

Trust your instincts. Fraudsters go to great lengths to make scams look real, but there's often something subtly wrong - an unusual request, an odd tone, or a link that doesn't quite match. If something feels off, don't act. Pause, verify through official channels, and report it.

Sometimes everything looks pretty legitimate, but there's a link you're not too sure about. How exactly can you weed out the fakes?

It can sometimes be tricky to identify a dodgy link. The key is to check that the domain name matches the legitimate one (which you can find through a quick Google search). You can also hover over any link before clicking to preview the full web address.

Here's an example. Let's say you've got an email asking you to follow a link to reactivate your account with PayPal. How can you tell if these links are the real deal or a fake?

  • http://www.paypal-reactivate.com/link

  • http://www.reactivate-account.com/paypal

  • http://www.paypal.com.11982pypl.com/reactivate

The trick here is to look for the first forward slash (/) after the http:// and then go back to the next two dots. What's in between those is the true domain name and tells you what site you'll be accessing if you click. You can see that actually none of these have a domain name of paypal.com or paypal.co.uk. The first may have PayPal in it, but it's really taking you to a site 'paypal-reactivate.com', the second to 'reactivate-account.com' and the third is directing you to the even dodgier sounding '11982pypl.com'.

If you're not sure about a link, type it into your browser rather than clicking on it so that you can see the full address. You can also use a free link-checking tool to flag known malicious URLs before you visit them.

If you get an email that seems to come from someone a bit odd, how can our users be sure it's a scam?

A fake email address is one of the hardest things to spot as fraudsters can get pretty cunning. Let's try out another example. Which of these do you think could be a scam account?

  • paypal@accounts.com

  • customerservcie@sentander.com

Actually, both of these addresses are probably fake. With the first one the domain name is 'accounts.com' so this could literally be from anyone. Always check that the correct company name comes after the @ as that will confirm who it's really coming from. The second one is easy to miss, but the giveaway here is the spelling mistakes - particularly in the name of the bank. This is a classic sign of a phishing attempt.

In 2026, it's also worth being aware of email spoofing, where scammers can make a fraudulent email appear to come from a legitimate address. If in doubt, contact the sender directly through an official phone number or website - never by replying to the suspicious email itself.

What to do if you've fallen for a phishing scam

Spotting scams is vital - but what happens if you've already clicked a dodgy link, shared your details, or transferred money? The good news is that acting quickly can limit the damage. Here are the steps you should take straight away.

  • Contact your bank immediately. If you've shared financial details or made a payment to a scammer, call your bank's fraud team as soon as possible. Ask them to freeze your account and any cards that may have been compromised. In many cases your bank can attempt a chargeback or recall the payment - but speed is critical. Most banks have a 24-hour fraud hotline, so don't wait until the morning.

  • Change compromised passwords and enable two-factor authentication. If you've entered login credentials on a fake website, change those passwords immediately - and change them on any other accounts where you've used the same password. Enable two-factor authentication (2FA) on every account that supports it, so that a stolen password alone isn't enough for a fraudster to get in.

  • Report the scam to Action Fraud. In England and Wales, report fraud and cyber crime to Action Fraud online or by calling 0300 123 2040. In Scotland, contact Police Scotland on 101. Your report helps law enforcement track and disrupt criminal networks, even if you haven't lost money.

  • Forward scam texts to 7726 and phishing emails to report@phishing.gov.uk. You can report suspicious text messages by forwarding them to 7726 (which spells "SPAM" on your keypad). For phishing emails, forward the full message to report@phishing.gov.uk - the National Cyber Security Centre (NCSC) will investigate and can take down fraudulent websites.

  • Check your credit report for unfamiliar activity. Scammers who have your personal details may try to open accounts in your name. Check your ClearScore credit report for any applications or accounts you don't recognise - checking won't affect your score, as it's a soft search only visible to you. If you spot anything suspicious, flag it immediately and consider adding a protective registration with CIFAS.

  • Scan your devices for malware. If you clicked a suspicious link or downloaded an attachment, run a full malware scan on your device straight away. Use a reputable antivirus tool and make sure your operating system is up to date. If your device was locked by ransomware, do not pay the ransom - contact a professional or report it to the NCSC.

Remember, falling for a scam doesn't make you foolish - these attacks are designed to exploit trust and urgency. The most important thing is to act fast, report it, and take steps to protect yourself going forward.

How to protect yourself from phishing and online scams

Knowing how to spot a scam is half the battle. The other half is putting practical defences in place so that even if a phishing message slips through, the damage is contained. Here are the most effective steps you can take right now.

  • Use a unique, strong password for every account - and use a password manager. Reusing passwords is one of the biggest security risks there is. If a fraudster obtains one set of credentials, they'll try them on every major site. A password manager generates and stores complex, unique passwords for each of your accounts, so you only need to remember one master password.

  • Enable two-factor authentication (2FA) wherever available. Two-factor authentication adds an extra layer of security by requiring a second form of verification - usually a code sent to your phone or generated by an app - on top of your password. Even if your password is stolen, 2FA can stop a fraudster from accessing your account.

  • Keep your operating system, browser, and apps up to date. Software updates frequently include patches for security vulnerabilities that scammers actively exploit. Turn on automatic updates on your phone, tablet, and computer so you're always running the latest, most secure versions.

  • Use your email provider's built-in phishing filters and mark spam. Most email services - including Gmail, Outlook, and Yahoo - have sophisticated spam and phishing filters. Make sure these are enabled, and always mark suspicious messages as spam or phishing rather than simply deleting them. This trains the filter to catch similar messages in future.

  • Never share one-time passcodes (OTPs). A legitimate bank, retailer, or government body will never ask you to read out or forward a one-time passcode. If someone contacts you asking for an OTP, it's almost certainly a scam - hang up or delete the message immediately.

  • Register with the Telephone Preference Service (TPS). The TPS is a free service that lets you opt out of unsolicited sales and marketing calls in the UK. While it won't block all scam calls, it reduces the volume of cold calls you receive and makes it easier to treat unexpected calls with suspicion. You can also ask your phone provider about call-blocking features.

  • Set up credit monitoring and dark web alerts. Proactive monitoring helps you catch problems early. ClearScore Protect offers free dark web monitoring that scans for your stolen passwords every three months and alerts you if your data appears in a breach - giving you time to act before a fraudster does.

No single step makes you invulnerable, but combining these measures significantly reduces your risk. Think of it as layered security - the more barriers you put between yourself and a scammer, the safer you are.

Frequently asked questions about phishing scams

Can you get a virus just by opening a phishing email?

In most cases, simply opening a phishing email will not infect your device. The danger lies in clicking links, downloading attachments, or enabling macros within the message. However, some highly sophisticated exploits can target vulnerabilities in your email client, which is why keeping your software up to date is so important. As a rule, if an email looks suspicious, don't interact with it at all - mark it as spam or phishing and delete it.

How do AI deepfake scams work and how can you spot them?

AI deepfake scams use artificial intelligence to clone a person's voice or create realistic video of them. In a typical scenario, a fraudster might clone a family member's voice from a short clip found on social media and then call you pretending to be them, often claiming an emergency and asking for an urgent bank transfer. To spot a deepfake, listen for subtle audio glitches, unnatural pauses, or responses that don't quite match the conversation. If in doubt, hang up and call the person back on a number you already have saved.

Are banks required to refund you if you fall for a scam in the UK?

Under the UK's Authorised Push Payment (APP) fraud reimbursement rules, most banks and payment providers are required to reimburse victims of APP scams in many circumstances, provided you have taken reasonable steps to protect yourself. However, each case is assessed individually, and your bank may not refund you if it can demonstrate gross negligence on your part. If your bank refuses a refund and you believe the decision is unfair, you can escalate your complaint to the Financial Ombudsman Service for free.

How do I check if a website is legitimate before entering my details?

Start by checking the URL carefully - look for the padlock icon and make sure the address begins with https://. Verify the domain name matches the organisation's official site (use the forward-slash trick described earlier in this article). Search for the company independently rather than following links from emails or texts. You can also use free online tools such as Google's Safe Browsing checker or the NCSC's suspicious URL reporting service to see whether a site has been flagged as malicious.

What is the difference between phishing and spear phishing?

Standard phishing casts a wide net - the same generic email is sent to thousands or even millions of addresses, hoping a small percentage will fall for it. Spear phishing, by contrast, is highly targeted. The attacker researches a specific individual, using details like their name, employer, job title, or recent purchases to craft a convincing, personalised message. Because spear phishing emails look so legitimate, they are significantly harder to spot and are more likely to succeed - making vigilance and verification even more important.

It's time to get serious about your online security

With scams on the rise - and AI making them harder to detect than ever - it's important to remain vigilant but not paranoid. To help you keep your data safe, we've launched ClearScore Protect: free dark web monitoring for all ClearScore users.

Next step: Try ClearScore Protect for free today.

Every three months, we'll scan the dark web for your passwords to see if they have been stolen. And if we find anything, we'll let you know, so you can change your password and protect yourself. Scans are periodic rather than continuous, so breaches that occur between scans may not be detected straight away. Find out more about ClearScore Protect.

Meet the author

Content Director at Get Safe Online

Tim Mitchell

How to spot phishing email and phone scams

We've teamed up with fraud expert Tim Mitchell from Get Safe Online to help you stay one step ahead of the fraudsters and spot even the most cunning of scams - including the latest AI-powered phishing attacks and smishing texts targeting people in 2026.

It's a common scenario: you open up your emails and there in your inbox is an email congratulating you on your million pound win. All you have to do is click the link to share all your account details and pay £100 to cover the transfer fee. It can be pretty easy to scoff at examples like this. After all you'd never fall for it, right?

But losing money to a scam is much easier than you'd think. In recent research by Get Safe Online, 80% of respondents to a survey said they could confidently identify a scam email or phone call. However, in a separate test of over 63,000 people, only 9% who completed the quiz scored full marks. It's a pretty eye-watering stat, and just goes to show how anyone can become a victim, however smart or savvy.

To help stop it happening to you, we've teamed up with Get Safe Online's fraud expert Tim Mitchell. With his help you'll be better equipped to identify even the most cunning of online scams - from classic phishing emails to the latest deepfake voice scams - to keep your money and your identity safe online.

What is the number one type of fraud that you think our users need to be aware of?

The biggest issue right now is people falling victim to what we call 'social engineering' fraud - and in 2026, fraudsters have supercharged these tactics using artificial intelligence. This simply means manipulating or tricking someone into performing certain actions, such as divulging personal or financial information. A con, in other words - but one that's increasingly hard to detect.

Unfortunately, financial fraud has always been a massive issue. But as we live more of our lives online, more people are becoming vulnerable to this type of fraud, and more people are losing money to it. AI-generated scam emails and deepfake phone calls have made social engineering even more convincing - but while these scams are becoming more convincing, knowing the warning signs can reduce your risk.

To help our users steer clear, how do these social engineering scams trick people into handing over too much information?

At Get Safe Online we've seen how social engineering scams come in all shapes and sizes ranging from the ridiculous to the nearly impossible to identify. And unfortunately people are falling for these every day. Here are the main ones you need to be aware of:

Phishing email scams

Phishing is still the most common entry point for fraud, and in 2026 it's more sophisticated than ever. Fraudsters often pretend to be someone official such as a bank, online retailer, HMRC, or a government agency - and AI tools now let them craft near-perfect, personalised messages that are far harder to spot than the misspelled emails of the past. They'll ask you to share confidential private information such as your banking details or login credentials. Some phishing emails contain an attachment which, if clicked, can lead to a virus or spyware being downloaded on to your device.

A newer and rapidly growing variant is spear phishing - highly targeted attacks that use your name, employer, or recent activity to appear even more convincing. Always be suspicious of any unexpected email asking you to click a link or provide details, even if it looks personalised and legitimate.

Smishing: SMS and WhatsApp scams

Smishing - phishing carried out via text message or WhatsApp - has surged in recent years and is now one of the most reported scam types in the UK. You might receive a text claiming to be from Royal Mail, your bank, or even HMRC, asking you to click a link to resolve an issue. These messages often create a false sense of urgency. Never click links in unexpected texts; go directly to the official website instead.

Social media scams

We've seen a big rise in people losing money through social media, and this trend has only accelerated. You may have seen posts promising a free £50 supermarket voucher in return for clicking on a link, or fake giveaways impersonating well-known brands and celebrities. In 2026, AI-generated video content - sometimes called deepfakes - is being used to make these scams look even more credible. Just consider why any company or public figure would be giving money away before you click.

So does this sort of thing only happen online, or should we be keeping watch elsewhere too?

Phone call scams and vishing

It's certainly not all online - in fact some of the most convincing scams come via a phone call, a tactic known as vishing (voice phishing). Typically, you'll get a call from someone claiming to be from your bank, telling you that your account has been compromised, and that the bank needs your OK to move your balance into a new account. In reality a bank would never ask for your full password, PIN, or one-time passcode over the phone - and they will never ask you to move money to a 'safe account'.

In 2026, fraudsters are also using AI voice-cloning technology to impersonate people you know - a family member, your boss, or even your GP - to make requests seem urgent and trustworthy. If you receive an unexpected call asking you to transfer money or share sensitive information, hang up and call the person or organisation back on a number you find yourself.

Another kind of phone scam is the computer support scam. I was working at an online safety event recently, and a man told me that his computer had been locked by ransomware, asking me how this might have happened. He swore that, knowing the dangers, he hadn't clicked on any links or attachments. It was only after probing, that he told me he'd had a call from 'Microsoft' a couple of weeks earlier, and the nice operative on the other end had fixed his problem. What had in fact happened, is that the caller was a scammer, who had infected his computer with the malware. Not only that, but he'd been charged as well!

Phishing vs smishing vs vishing: how to tell them apart

The article above covers three major social engineering channels. Here's a quick-reference table so you can tell them apart at a glance - including the typical warning signs and how to report each one in the UK.

Scam type

Channel

Common impersonators

Typical red flags

How to report (UK)

Scam type

Phishing

Channel

Email

Common impersonators

Banks (e.g. Santander, HSBC), HMRC, PayPal, Amazon, Royal Mail

Typical red flags

Urgent language demanding immediate action; suspicious sender address or misspellings; links that don't match the official domain; unexpected attachments

How to report (UK)

Forward the email to report@phishing.gov.uk and report to Action Fraud (0300 123 2040)

Scam type

Smishing

Channel

SMS or WhatsApp

Common impersonators

Royal Mail, delivery couriers, banks, HMRC, NHS

Typical red flags

Short, urgent message with a shortened or unfamiliar link; request to verify identity or pay a fee; messages appearing in the same thread as legitimate texts

How to report (UK)

Forward the text to 7726 and report to Action Fraud

Scam type

Vishing

Channel

Phone call

Common impersonators

Bank fraud teams, police, HMRC, Microsoft tech support, broadband providers

Typical red flags

Caller asks for PINs, passwords, or one-time codes; pressure to transfer money to a "safe" account; AI-cloned voice of someone you know; spoofed caller ID

How to report (UK)

Hang up, call 159 (the Stop Scams Helpline) to verify, then report to Action Fraud

If you're ever unsure which type of scam you're dealing with, the golden rule is the same across all three: stop, don't engage, and verify independently by contacting the organisation through its official website or phone number.

What are the main warning signs of a scam?

Is the email or message threatening you to take action right now?

Typically, messages claiming to be from your bank, HMRC, the DVLA or the police will tell you that there's a problem that will result in your money or identity being put at risk, and will urge you to click through to a website to take action. This will normally involve supplying your confidential login details. Any message that asks you to act immediately is likely to be suspect - it's designed to make you flustered in the hope you'll make a mistake.

Have you been promised a reward, a competition win or a tax refund?

Any email, text, or call claiming to be giving you money should be considered with a watchful eye - especially if they are demanding your details in order to claim it. Reveal your logins, and a fraudster has free rein to get into your bank account (and maybe other accounts if you use the same details). HMRC tax refund scams are perennially common, particularly around the end of the tax year.

Could the message have been sent to anyone?

Generic greetings like 'Dear Sir or Madam' or 'Dear valued customer' are an easy sign that this message has probably been fired off to as many addresses as possible. That said, more sophisticated spear phishing attacks in 2026 may include your real name - so personalisation alone is no longer a guarantee of legitimacy.

Does something feel slightly off, even if you can't put your finger on it?

Trust your instincts. Fraudsters go to great lengths to make scams look real, but there's often something subtly wrong - an unusual request, an odd tone, or a link that doesn't quite match. If something feels off, don't act. Pause, verify through official channels, and report it.

Sometimes everything looks pretty legitimate, but there's a link you're not too sure about. How exactly can you weed out the fakes?

It can sometimes be tricky to identify a dodgy link. The key is to check that the domain name matches the legitimate one (which you can find through a quick Google search). You can also hover over any link before clicking to preview the full web address.

Here's an example. Let's say you've got an email asking you to follow a link to reactivate your account with PayPal. How can you tell if these links are the real deal or a fake?

  • http://www.paypal-reactivate.com/link

  • http://www.reactivate-account.com/paypal

  • http://www.paypal.com.11982pypl.com/reactivate

The trick here is to look for the first forward slash (/) after the http:// and then go back to the next two dots. What's in between those is the true domain name and tells you what site you'll be accessing if you click. You can see that actually none of these have a domain name of paypal.com or paypal.co.uk. The first may have PayPal in it, but it's really taking you to a site 'paypal-reactivate.com', the second to 'reactivate-account.com' and the third is directing you to the even dodgier sounding '11982pypl.com'.

If you're not sure about a link, type it into your browser rather than clicking on it so that you can see the full address. You can also use a free link-checking tool to flag known malicious URLs before you visit them.

If you get an email that seems to come from someone a bit odd, how can our users be sure it's a scam?

A fake email address is one of the hardest things to spot as fraudsters can get pretty cunning. Let's try out another example. Which of these do you think could be a scam account?

  • paypal@accounts.com

  • customerservcie@sentander.com

Actually, both of these addresses are probably fake. With the first one the domain name is 'accounts.com' so this could literally be from anyone. Always check that the correct company name comes after the @ as that will confirm who it's really coming from. The second one is easy to miss, but the giveaway here is the spelling mistakes - particularly in the name of the bank. This is a classic sign of a phishing attempt.

In 2026, it's also worth being aware of email spoofing, where scammers can make a fraudulent email appear to come from a legitimate address. If in doubt, contact the sender directly through an official phone number or website - never by replying to the suspicious email itself.

What to do if you've fallen for a phishing scam

Spotting scams is vital - but what happens if you've already clicked a dodgy link, shared your details, or transferred money? The good news is that acting quickly can limit the damage. Here are the steps you should take straight away.

  • Contact your bank immediately. If you've shared financial details or made a payment to a scammer, call your bank's fraud team as soon as possible. Ask them to freeze your account and any cards that may have been compromised. In many cases your bank can attempt a chargeback or recall the payment - but speed is critical. Most banks have a 24-hour fraud hotline, so don't wait until the morning.

  • Change compromised passwords and enable two-factor authentication. If you've entered login credentials on a fake website, change those passwords immediately - and change them on any other accounts where you've used the same password. Enable two-factor authentication (2FA) on every account that supports it, so that a stolen password alone isn't enough for a fraudster to get in.

  • Report the scam to Action Fraud. In England and Wales, report fraud and cyber crime to Action Fraud online or by calling 0300 123 2040. In Scotland, contact Police Scotland on 101. Your report helps law enforcement track and disrupt criminal networks, even if you haven't lost money.

  • Forward scam texts to 7726 and phishing emails to report@phishing.gov.uk. You can report suspicious text messages by forwarding them to 7726 (which spells "SPAM" on your keypad). For phishing emails, forward the full message to report@phishing.gov.uk - the National Cyber Security Centre (NCSC) will investigate and can take down fraudulent websites.

  • Check your credit report for unfamiliar activity. Scammers who have your personal details may try to open accounts in your name. Check your ClearScore credit report for any applications or accounts you don't recognise - checking won't affect your score, as it's a soft search only visible to you. If you spot anything suspicious, flag it immediately and consider adding a protective registration with CIFAS.

  • Scan your devices for malware. If you clicked a suspicious link or downloaded an attachment, run a full malware scan on your device straight away. Use a reputable antivirus tool and make sure your operating system is up to date. If your device was locked by ransomware, do not pay the ransom - contact a professional or report it to the NCSC.

Remember, falling for a scam doesn't make you foolish - these attacks are designed to exploit trust and urgency. The most important thing is to act fast, report it, and take steps to protect yourself going forward.

How to protect yourself from phishing and online scams

Knowing how to spot a scam is half the battle. The other half is putting practical defences in place so that even if a phishing message slips through, the damage is contained. Here are the most effective steps you can take right now.

  • Use a unique, strong password for every account - and use a password manager. Reusing passwords is one of the biggest security risks there is. If a fraudster obtains one set of credentials, they'll try them on every major site. A password manager generates and stores complex, unique passwords for each of your accounts, so you only need to remember one master password.

  • Enable two-factor authentication (2FA) wherever available. Two-factor authentication adds an extra layer of security by requiring a second form of verification - usually a code sent to your phone or generated by an app - on top of your password. Even if your password is stolen, 2FA can stop a fraudster from accessing your account.

  • Keep your operating system, browser, and apps up to date. Software updates frequently include patches for security vulnerabilities that scammers actively exploit. Turn on automatic updates on your phone, tablet, and computer so you're always running the latest, most secure versions.

  • Use your email provider's built-in phishing filters and mark spam. Most email services - including Gmail, Outlook, and Yahoo - have sophisticated spam and phishing filters. Make sure these are enabled, and always mark suspicious messages as spam or phishing rather than simply deleting them. This trains the filter to catch similar messages in future.

  • Never share one-time passcodes (OTPs). A legitimate bank, retailer, or government body will never ask you to read out or forward a one-time passcode. If someone contacts you asking for an OTP, it's almost certainly a scam - hang up or delete the message immediately.

  • Register with the Telephone Preference Service (TPS). The TPS is a free service that lets you opt out of unsolicited sales and marketing calls in the UK. While it won't block all scam calls, it reduces the volume of cold calls you receive and makes it easier to treat unexpected calls with suspicion. You can also ask your phone provider about call-blocking features.

  • Set up credit monitoring and dark web alerts. Proactive monitoring helps you catch problems early. ClearScore Protect offers free dark web monitoring that scans for your stolen passwords every three months and alerts you if your data appears in a breach - giving you time to act before a fraudster does.

No single step makes you invulnerable, but combining these measures significantly reduces your risk. Think of it as layered security - the more barriers you put between yourself and a scammer, the safer you are.

Frequently asked questions about phishing scams

Can you get a virus just by opening a phishing email?

In most cases, simply opening a phishing email will not infect your device. The danger lies in clicking links, downloading attachments, or enabling macros within the message. However, some highly sophisticated exploits can target vulnerabilities in your email client, which is why keeping your software up to date is so important. As a rule, if an email looks suspicious, don't interact with it at all - mark it as spam or phishing and delete it.

How do AI deepfake scams work and how can you spot them?

AI deepfake scams use artificial intelligence to clone a person's voice or create realistic video of them. In a typical scenario, a fraudster might clone a family member's voice from a short clip found on social media and then call you pretending to be them, often claiming an emergency and asking for an urgent bank transfer. To spot a deepfake, listen for subtle audio glitches, unnatural pauses, or responses that don't quite match the conversation. If in doubt, hang up and call the person back on a number you already have saved.

Are banks required to refund you if you fall for a scam in the UK?

Under the UK's Authorised Push Payment (APP) fraud reimbursement rules, most banks and payment providers are required to reimburse victims of APP scams in many circumstances, provided you have taken reasonable steps to protect yourself. However, each case is assessed individually, and your bank may not refund you if it can demonstrate gross negligence on your part. If your bank refuses a refund and you believe the decision is unfair, you can escalate your complaint to the Financial Ombudsman Service for free.

How do I check if a website is legitimate before entering my details?

Start by checking the URL carefully - look for the padlock icon and make sure the address begins with https://. Verify the domain name matches the organisation's official site (use the forward-slash trick described earlier in this article). Search for the company independently rather than following links from emails or texts. You can also use free online tools such as Google's Safe Browsing checker or the NCSC's suspicious URL reporting service to see whether a site has been flagged as malicious.

What is the difference between phishing and spear phishing?

Standard phishing casts a wide net - the same generic email is sent to thousands or even millions of addresses, hoping a small percentage will fall for it. Spear phishing, by contrast, is highly targeted. The attacker researches a specific individual, using details like their name, employer, job title, or recent purchases to craft a convincing, personalised message. Because spear phishing emails look so legitimate, they are significantly harder to spot and are more likely to succeed - making vigilance and verification even more important.

It's time to get serious about your online security

With scams on the rise - and AI making them harder to detect than ever - it's important to remain vigilant but not paranoid. To help you keep your data safe, we've launched ClearScore Protect: free dark web monitoring for all ClearScore users.

Next step: Try ClearScore Protect for free today.

Every three months, we'll scan the dark web for your passwords to see if they have been stolen. And if we find anything, we'll let you know, so you can change your password and protect yourself. Scans are periodic rather than continuous, so breaches that occur between scans may not be detected straight away. Find out more about ClearScore Protect.

Meet the author

Content Director at Get Safe Online

Tim Mitchell