The parcel delivery message
A text or email claims a delivery failed and asks for a small redelivery fee or a confirmed address. It is the most common phishing format worldwide because almost everyone is waiting for something, and a one or two currency-unit charge feels too trivial to question.
The purpose is rarely the fee itself. Entering card details on the fake page hands over a working card number, and the follow-up is either a larger charge or a phone call from a 'fraud department' asking you to approve a transfer.
- Carriers do not request payment by SMS link for a standard delivery
- The domain is a lookalike: the brand name appears before the real domain
- Tracking numbers in these messages do not match any order you placed
- Check the order in the retailer's own app instead of the message
The bank security alert
A message reports a suspicious payment and invites you to cancel it. The link leads to a convincing copy of your bank's login page which forwards your credentials to the attacker in real time, then prompts for the one-time code your bank has just legitimately sent you.
The tell is the direction of the request. A real bank blocks a suspicious transaction and asks you to confirm in its own app. It never asks you to enter a code, move money to a 'safe account' or install remote-access software while on a call.
The workplace and invoice scam
Business email compromise targets whoever pays invoices. The message appears to come from a supplier or a senior colleague, references a genuine project, and announces changed bank details or an urgent payment that must stay confidential.
Reply-to addresses differ subtly from the display name, and the pressure is always to bypass normal process. The defence is procedural rather than technical: verify any change of bank details by phoning a number you already had, never one supplied in the message.
- Display name matches a colleague, underlying address does not
- Urgency combined with a request for confidentiality
- A change of payment details on an otherwise familiar invoice
- Requests to buy gift cards or process a payment outside hours
Subscription and account-expiry notices
Streaming, cloud storage and mailbox providers are impersonated constantly. The message says your payment failed or your storage is full and your account will be deleted within twenty-four hours unless you update your details.
Open the service directly in your browser or app instead of following the link. If there is a genuine billing problem, it will be visible in your account; if nothing is wrong, the message was fraudulent.
AI-assisted voice and video approaches
Cloned voices have moved from demonstration to routine use in family-emergency scams: a short call, a distressed relative, a new phone number and an urgent transfer request. Video deepfakes are appearing in investment adverts and in fraudulent meeting invitations.
Technical detection is unreliable and getting worse. Agree a family code word, insist on calling back on a known number, and treat any unexpected request for money as false until verified through a separate channel.
If you already clicked or entered details
Act in order and do not lose time on self-reproach. Change the password for the affected account and for your email, sign out of all active sessions, and turn on two-factor authentication. If card or banking details were entered, contact your bank immediately and request a block.
Then scan the device, check the account's recovery options and forwarding rules for additions you did not make, and report the message to your national fraud reporting service and to the impersonated brand.
- Change the account password, then your email password
- Sign out of all sessions and enable two-factor authentication
- Call your bank if card or account details were submitted
- Check mail forwarding rules and recovery addresses
- Report to your national fraud service and the impersonated brand
