Phishing and Scams

Learn how online criminals try to trick you with realistic messages, and how to protect your accounts, money, and personal data.

What is phishing? (Explained simply)

Imagine someone dressing up as a postman, knocking on your front door, and asking you to hand over your house keys. That is exactly what a phishing scam is on the internet.

The Big Secret: Criminals do not hack past complex computer firewalls with movie-style coding. Instead, they send you a fake message that looks identical to a company you trust (like Netflix, Amazon, Apple, Roblox, or your bank). They trick you into typing your own password or sending them money voluntarily.
1. The Bait You receive an unexpected text, email, or direct message claiming an urgent problem.
→
2. The Panic The scammer tells you your account will be deleted or your money is in danger.
→
3. The Shield You stop, refuse to click their link, and check directly through the official app.

4 common scam traps you will see

1. Fake Email (Phishing)

Claims your subscription expired, an invoice needs paying, or someone tried to sign in. The email button leads to a fake login clone.

2. Fake SMS (Smishing)

A text saying: "Evri: Your parcel has a £1.45 unpaid delivery fee. Click here to reschedule". The link steals credit card details.

3. Fake Call (Vishing)

A caller pretending to be from your bank, the police, or Microsoft support, warning you to move your money immediately.

4. Fake QR Codes (Quishing)

Scam stickers placed over legitimate parking meters, posters, or restaurant menus that send your phone to a counterfeit payment page.

Red Flag Warning Signs: Artificial urgency ("Act within 15 minutes!"), threats of legal trouble or account closures, unexpected free gift cards, slight spelling blunders in the address bar, or any message asking for a code sent to your phone.

The 3-step defense: Stop, Check, Protect

1. STOP Take a breath. Never click links, download attached files, make payments, or read codes aloud under pressure.
→
2. CHECK Verify independently. Open the official app directly or type the company's verified address into your browser.
→
3. PROTECT Block the scammer, report the text or email, and share what happened with a trusted adult or family member.
Remember: A genuine bank, school, government service, or company will never disappear because you took 5 minutes to verify. Scammers need you to rush because panic stops you from thinking clearly.
PHONE CALL DEFENSE

What to do if you receive an unexpected call

Scammers can use computer tools to disguise their caller ID so that your phone screen displays the name of your real bank or local police station.

Incoming Call → Do Not Trust Display → Hang Up → Wait 5 Minutes → Call Official Number
  1. Never trust the name on your phone screen: Criminals spoof telephone numbers easily. Just because the screen says "Barclays", "Santander", or "Apple" does not prove it is them.
  2. Do not answer security questions: If the caller says, "To verify your identity, tell me your mother's maiden name or passcode", stop immediately. They called you; you do not have to prove anything to them.
  3. Hang up firmly: Say: "I will hang up and call back through the official customer number." Do not worry about being impolite. Genuine staff will completely understand and encourage this.
  4. Never use a phone number given by the caller: Never call back numbers recited by the person on the line or sent via text. Look at the back of your physical plastic bank card or the official app for the real customer care number.
  5. The "Safe Account" trap: A bank will never ask you to move your savings into a "safe account" or "holding vault" because of fraud. If anyone tells you this, it is 100% a scam.
  6. Refuse remote-control software: Never download apps like AnyDesk, TeamViewer, or QuickSupport because a caller asks you to. This gives them complete remote control over your mouse, screen, and banking logins.
✓ Safe Rule: Hang up, wait 5 minutes (or use a different phone so the line is completely clear), and dial the number on your card.

What to do if you clicked, paid, or entered details

If you realize you made a mistake and typed your password or card details into a scam site, do not panic and do not feel ashamed. Even cybersecurity professionals encounter sophisticated traps. Taking rapid action makes all the difference:

Step 1: Sever Contact Hang up the phone, close the scam webpage, and block the telephone number or sender immediately.
→
Step 2: Alert Your Bank If bank details or card numbers were entered, call your bank using the phone number on the back of your card straight away.
→
Step 3: Reset Passwords Change the password on the affected account and your primary Gmail/email account from a trusted device.
→
Step 4: Tell an Adult Inform a parent, teacher, or trusted family member. Fast communication helps freeze fraudulent charges in time.
  1. Freeze your payment cards: Open your banking app on your phone. Most banking apps have a button under "Cards" to instantly freeze your card so no unauthorized transactions go through.
  2. Secure your email first: Your email address is the master key to your digital identity. If scammers get into your email, they can reset passwords on every other service you use. Reset your email password first and ensure 2FA is active.
  3. Terminate active sessions: In your Google, Apple, or Microsoft security settings, look for Devices or Active Sessions and click Log out of all other sessions to kick the scammer off your account.
  4. Collect the evidence: Take quick screenshots of the fake text message, scam website URL, or email header before deleting them. This helps your bank and the police investigate.
The Absolute "Never Share" List: No genuine company representative, bank manager, police officer, or game moderator will ever ask you for:
  • Your master passwords or device screen PINs
  • Temporary 6-digit authenticator or SMS verification codes
  • Your emergency offline backup recovery codes
  • Your Bitwarden, Google, or Apple master account passwords

Essential scam defense checklist

  • Treat all unexpected urgent texts, calls, and emails with healthy suspicion.
  • Never click links inside SMS messages regarding missed deliveries or account warnings.
  • Check website URLs from right to left before typing any username or password.
  • Always use official smartphone apps or saved browser bookmarks to log in.
  • Ensure two-factor authentication (passkey or authenticator app) is active on every account.