Phishing and suspicious messages
An email, text or personalised message that wants you to act
Phishing usually arrives by email, smishing by text, and spear-phishing is tailored to a particular person or organisation. The label matters less than stopping and verifying the request safely.Reviewed 29 August 2026 Next review 29 November 2026
What to do first
- Do not reply, click a link, open an attachment, scan a QR code or use a telephone number from the message.
- Check the claim through a separate route you already trust: open the organisation’s official app, type its known website yourself or use a number from a statement or card.
- Forward a suspicious email to report@phishing.gov.uk. Forward a suspicious SMS text to 7726 free of charge; for WhatsApp, iMessage and other app messages, also use the app’s block and report controls.
- If you shared a password, change it anywhere it was reused and secure the account. If you shared bank details or sent money, contact the bank or payment provider immediately.
- If you installed software, run a full security scan and tell your workplace IT team if it happened on a work device. Report financial loss or account hacking through the police route for where you live.
Warning signs
- A message uses authority, urgency, emotion, scarcity or a current event to make you act before checking.
- An unexpected login alert, invoice, parcel problem, refund, tax message or document asks you to follow a link or scan a QR code.
- The display name looks familiar but the full sender address, reply address or web domain is different.
- A request for passwords, one-time passcodes, card details, money, gift cards or a change to payment instructions.
- Real details such as your name, job, colleague, supplier or recent activity are used to make the message feel credible. This personalisation is characteristic of spear-phishing.
- The message arrives inside a genuine-looking conversation or from a compromised account but asks for something unusual.
What not to do
- Do not assume good spelling, correct branding, a familiar display name or real personal details make a message genuine.
- Do not rely on hovering over a link as your only check; avoid the link and reach the organisation independently.
- Do not reply “STOP” to an unknown sender, because replying can confirm that your number is active.
- Do not approve a sign-in, share a one-time passcode or accept a password-reset request you did not start.
- Do not blame yourself if a message looked convincing. Some phishing is carefully researched and can fool experienced people; act quickly to limit harm.
Sources checked
- NCSC — how to spot and report phishing scams
- NCSC — what to do after sharing sensitive information
- NCSC — phishing and spear-phishing explained
- GOV.UK — report suspicious emails, texts and websites
- Ofcom — report suspicious mobile messages to 7726
Cleverways summarises these sources in plain English. Follow the source organisation’s current instructions where they differ.