Scam messages — the fake delivery text, the “your account is suspended” email, the surprise refund — all follow the same playbook. They manufacture urgency, then push you to click or pay before you think. Slow down and the cracks show.

The red flags

  • Urgency and threat: “Act now or your account will be closed.” Real organisations don't rush you like this.
  • Unexpected links or attachments — especially asking you to “verify” details.
  • Requests for passwords, PINs, or full card details — legitimate companies never ask for these by message.
  • Odd sender addresses — a bank email from a random Gmail or a misspelt domain.
  • Poor spelling and generic greetings like “Dear Customer”.
  • Too good to be true — refunds, prizes, or parcels you didn't expect.

What to do

  • Don't click. Go to the company's site or app directly and check there.
  • Verify independently — call the number on their official website, not the one in the message.
  • Report and delete. Most countries have a number to forward scam texts to.
💡

The golden rule

Any message pressuring you to act fast and share details is suspicious by default. Pause, verify through official channels, and you defeat almost every scam. Related: protecting your information online.

The scams that catch even careful people

Knowing the red flags isn't the same as being immune. The messages that actually work don't look like scams at all. They arrive at the exact moment you're expecting something similar, which is what makes them dangerous.

  • The delivery text that lands the same week you're waiting on a parcel. You're not suspicious because you genuinely have something coming.
  • The bank alert that copies the real one word for word, then adds one line asking you to "confirm" a payment you don't recognise.
  • The boss message from a number you don't have saved, saying they're in a meeting and need you to sort something urgently.
  • The refund or rebate that offers you money instead of asking for it. Getting paid lowers your guard far more than being charged.
💡

The 30-second gut check

Ask yourself one thing: did I start this? If a message asks you to click, log in, or pay, and you didn't initiate the contact, treat it as a scam until proven otherwise. Genuine organisations are happy for you to call back on a number you found yourself.

A worked example: the fake delivery text

Here's how one plays out, so you can see the machinery. You get a text: a parcel couldn't be delivered, pay a small fee to reschedule. The amount is tiny on purpose, usually a pound or two, small enough that you don't think twice.

  1. You tap the link. The page looks exactly like a real courier's site, logo and all.
  2. You enter card details to pay the small fee. That's the real prize, not the pound.
  3. Minutes later you get a call from someone claiming to be your bank's fraud team, saying suspicious activity has been spotted. They already have some of your details, so they sound legitimate.
  4. They ask you to move money to a "safe account" or read out a code. That's the moment the real money leaves.

The lesson: the first message is just the door. Never pay a fee to a courier by clicking a text link, and remember that no real bank will ever ask you to move money to keep it safe. That request alone is the scam, every single time.

What to do if you've already clicked or paid

Panicking wastes the minutes that matter most. Work through this calmly instead.

  • Call your bank now using the number on the back of your card, not any number the message or caller gave you. The sooner you report it, the better your chances of stopping or reversing a payment.
  • Change the password for any account you entered details into, and change it anywhere else you reused that same password.
  • Turn on two-factor authentication on your email and banking, so a stolen password alone isn't enough.
  • Report and forward the message, then delete it, and warn anyone who might get the same one from a shared contact list.
Written by Niharika Parashar

Frequently asked questions

Is it dangerous to just open a scam text or email?
Usually opening it alone is low risk. The danger is what you do next, tapping a link, downloading an attachment, or replying. Replying is worse than it looks: it confirms your number or address is live, so you get targeted with more. Read it, don't interact, then delete.
How can a scam text show up in the same thread as real messages from my bank?
Scammers can fake, or "spoof", the sender name so it reads as your bank, and your phone groups messages by name rather than by trusted source. So a fake slots neatly under genuine ones. Never trust a message just because of where it appears. Judge it on what it's asking you to do.
Should I click the link just to check whether it's real?
No. Even loading the page can expose you, and any details you type are captured instantly. If you're unsure whether a message is genuine, go to the company yourself, through their app or a number you already have, and ask. Never verify a suspicious message by using anything inside that same message.
They knew my name and address, so surely it's genuine?
Not at all. Names, addresses, and even recent purchases are widely leaked in data breaches and bought cheaply by scammers. A personal detail is designed to lower your guard, not prove identity. Treat a correct name as meaningless. What matters is whether they're asking you to pay, click, or hand over a code.
What's the safest way to reply if I'm 50/50 on a message?
Don't reply to the message at all. Contact the organisation through a channel you find independently, their official app or the number printed on your card or a real letter. Ask them directly whether they sent it. Genuine bodies will never mind you checking. Only a scammer needs you to act right now, inside their message.

People also ask