Scam messages — the fake delivery text, the “your account is suspended” email, the surprise refund — all follow the same playbook. They manufacture urgency, then push you to click or pay before you think. Slow down and the cracks show.
The red flags
- Urgency and threat: “Act now or your account will be closed.” Real organisations don't rush you like this.
- Unexpected links or attachments — especially asking you to “verify” details.
- Requests for passwords, PINs, or full card details — legitimate companies never ask for these by message.
- Odd sender addresses — a bank email from a random Gmail or a misspelt domain.
- Poor spelling and generic greetings like “Dear Customer”.
- Too good to be true — refunds, prizes, or parcels you didn't expect.
What to do
- Don't click. Go to the company's site or app directly and check there.
- Verify independently — call the number on their official website, not the one in the message.
- Report and delete. Most countries have a number to forward scam texts to.
The golden rule
Any message pressuring you to act fast and share details is suspicious by default. Pause, verify through official channels, and you defeat almost every scam. Related: protecting your information online.
The scams that catch even careful people
Knowing the red flags isn't the same as being immune. The messages that actually work don't look like scams at all. They arrive at the exact moment you're expecting something similar, which is what makes them dangerous.
- The delivery text that lands the same week you're waiting on a parcel. You're not suspicious because you genuinely have something coming.
- The bank alert that copies the real one word for word, then adds one line asking you to "confirm" a payment you don't recognise.
- The boss message from a number you don't have saved, saying they're in a meeting and need you to sort something urgently.
- The refund or rebate that offers you money instead of asking for it. Getting paid lowers your guard far more than being charged.
The 30-second gut check
Ask yourself one thing: did I start this? If a message asks you to click, log in, or pay, and you didn't initiate the contact, treat it as a scam until proven otherwise. Genuine organisations are happy for you to call back on a number you found yourself.
A worked example: the fake delivery text
Here's how one plays out, so you can see the machinery. You get a text: a parcel couldn't be delivered, pay a small fee to reschedule. The amount is tiny on purpose, usually a pound or two, small enough that you don't think twice.
- You tap the link. The page looks exactly like a real courier's site, logo and all.
- You enter card details to pay the small fee. That's the real prize, not the pound.
- Minutes later you get a call from someone claiming to be your bank's fraud team, saying suspicious activity has been spotted. They already have some of your details, so they sound legitimate.
- They ask you to move money to a "safe account" or read out a code. That's the moment the real money leaves.
The lesson: the first message is just the door. Never pay a fee to a courier by clicking a text link, and remember that no real bank will ever ask you to move money to keep it safe. That request alone is the scam, every single time.
What to do if you've already clicked or paid
Panicking wastes the minutes that matter most. Work through this calmly instead.
- Call your bank now using the number on the back of your card, not any number the message or caller gave you. The sooner you report it, the better your chances of stopping or reversing a payment.
- Change the password for any account you entered details into, and change it anywhere else you reused that same password.
- Turn on two-factor authentication on your email and banking, so a stolen password alone isn't enough.
- Report and forward the message, then delete it, and warn anyone who might get the same one from a shared contact list.