Phishing and suspicious messages

An email, text or personalised message that wants you to act

Phishing usually arrives by email, smishing by text, and spear-phishing is tailored to a particular person or organisation. The label matters less than stopping and verifying the request safely.
Reviewed 29 August 2026 Next review 29 November 2026

What to do first

  1. Do not reply, click a link, open an attachment, scan a QR code or use a telephone number from the message.
  2. Check the claim through a separate route you already trust: open the organisation’s official app, type its known website yourself or use a number from a statement or card.
  3. Forward a suspicious email to report@phishing.gov.uk. Forward a suspicious SMS text to 7726 free of charge; for WhatsApp, iMessage and other app messages, also use the app’s block and report controls.
  4. If you shared a password, change it anywhere it was reused and secure the account. If you shared bank details or sent money, contact the bank or payment provider immediately.
  5. If you installed software, run a full security scan and tell your workplace IT team if it happened on a work device. Report financial loss or account hacking through the police route for where you live.

Warning signs

  • A message uses authority, urgency, emotion, scarcity or a current event to make you act before checking.
  • An unexpected login alert, invoice, parcel problem, refund, tax message or document asks you to follow a link or scan a QR code.
  • The display name looks familiar but the full sender address, reply address or web domain is different.
  • A request for passwords, one-time passcodes, card details, money, gift cards or a change to payment instructions.
  • Real details such as your name, job, colleague, supplier or recent activity are used to make the message feel credible. This personalisation is characteristic of spear-phishing.
  • The message arrives inside a genuine-looking conversation or from a compromised account but asks for something unusual.

What not to do

  • Do not assume good spelling, correct branding, a familiar display name or real personal details make a message genuine.
  • Do not rely on hovering over a link as your only check; avoid the link and reach the organisation independently.
  • Do not reply “STOP” to an unknown sender, because replying can confirm that your number is active.
  • Do not approve a sign-in, share a one-time passcode or accept a password-reset request you did not start.
  • Do not blame yourself if a message looked convincing. Some phishing is carefully researched and can fool experienced people; act quickly to limit harm.

Sources checked

Cleverways summarises these sources in plain English. Follow the source organisation’s current instructions where they differ.