Guide · Security and privacy

How to spot phishing and online scams

The warning signs of phishing emails, scam texts, fake calls and fake shops, plus what to do if you clicked and how to report a scam.

By Ishan Kakkar · Published 9 Oct 2026

Most phishing and online scams share the same signs: an unexpected message, pressure to act quickly, a link or sender address that is slightly wrong, and a request for money, a password, a code or personal details. The safest habit is simple. Never act on the message itself. Open the company's app or type its address yourself, and check from there. If you have already clicked and entered details, change the password, turn on two-factor authentication, and call your bank if money or card details are involved.

The warning signs in any message

  • It is unexpected: a delivery you did not order, a prize you did not enter, a refund you did not ask for.
  • It is urgent: your account will be closed, a payment has failed, a fine is due today.
  • It asks for something sensitive: a password, a one-time code, card details, an ID document or a payment.
  • The sender does not match: the display name says it is your bank, but the email address belongs to someone else.
  • The link does not match: hovering over a link, or pressing and holding it on a phone, shows an address that is not the company's.
  • The greeting is generic or the wording is odd. Many scam messages are now well written, though, so good grammar proves nothing.

One rule covers a lot of cases: a genuine organisation will never ask you to read out or forward a one-time code it has sent you. Anyone who asks for that code is trying to sign in as you.

Texts, messaging apps and phone calls

Scam texts often pretend to come from delivery companies, banks, tax authorities or phone networks, and include a short link. Messaging apps add another version: a message from an unknown number claiming to be a family member with a new phone who needs money urgently. Check by calling that person on the number you already have.

Phone scams rely on pressure. Callers may claim to be from your bank's fraud team, a tech support desk or a government office, and may already know a few details about you. Caller ID can be faked. Hang up, wait a moment, and call back using the number on your card, your statement or the official website.

Lookalike domains and fake shops

Scammers register web addresses that are easy to misread: a swapped letter, an extra word such as "secure" or "support", a different ending, or a familiar name placed at the start of an unrelated address. The part that matters is the name immediately before the ending, such as .com, together with that ending. In an address like yourbank.com.account-check.example, the real site is account-check.example, not your bank.

Fake shops tend to show the same signs:

  • Prices far below what everyone else charges, especially on popular brands.
  • A very new website, no clear company details, and no way to reach anyone except a form.
  • Payment only by bank transfer, gift cards, cryptocurrency or payment apps with no buyer protection.
  • Reviews that are all glowing and posted around the same time, or that appear only on the shop's own site.

Where you can, pay with a credit card or another method that offers buyer protection. It gives you a way to dispute the charge if the goods never arrive.

Tools that help

Password managers are one of the most effective defences against phishing. They fill in your login only on the exact site where you saved it, so if a page that looks like your bank gets no autofill, treat that as a warning sign, not a glitch to work around.

Two-factor authentication limits the damage a stolen password can do. Passkeys and hardware security keys go further, because they are tied to the real website and will not work on a fake one.

Major browsers have built-in protection that warns you about known dangerous sites. Keep it switched on and keep your browser updated. Some security apps and VPN services also include threat protection features that block known malicious websites and downloads. These are a useful extra layer, but new scam sites appear constantly, so no tool catches everything. Your own check of the sender and the address still matters most.

What to do if you clicked

Clicking a link is usually less serious than entering details after it. What matters is what happened next.

  • If you entered a password, change it straight away on the real site, and on any other site where you used the same password. Turn on two-factor authentication.
  • If you shared card or bank details, or sent money, contact your bank or card provider immediately using the number on your card. Acting fast gives the best chance of stopping a payment.
  • If you shared a one-time code, assume the account is at risk. Change the password and check for unfamiliar devices, forwarding rules and changed recovery details.
  • If you downloaded and opened a file, disconnect from the internet, run a full scan with reputable security software, and install any pending updates.
  • Watch your accounts and statements for anything unusual over the following weeks.

Reporting scams

Reporting helps stop the same scam reaching other people. Use the report phishing or report spam option in your email app, and the report junk option in your messaging app. Tell the real company about the impersonation through its official website. If you lost money or shared identity details, report it to your bank and to the national cybercrime or consumer protection reporting service in your country. Keep screenshots, the sender's details and any payment references, because you will usually be asked for them.

More to read

  • Guide

    How to judge a lifetime software deal

    What lifetime really means, and the checks to run before you buy: the maker, the licence, redemption and refund windows, the roadmap and the real cost.

    Productivity · 9 Oct 2026

  • Guide

    Staying safe on public Wi-Fi

    Public Wi-Fi is convenient but shared. These practical steps cut the main risks: fake hotspots, unencrypted traffic and open sharing settings.

    Security and privacy · 9 Oct 2026