It seems that, whenever there is a major worldwide event taking place, there’s almost no delay at all in a scam emerging to prey on people’s fear, paranoia and uncertainty.

In today’s online world these scams can spread with extreme rapidity and dupe many people in a short space of time. Worse still, they can be unwittingly passed on by the unsuspecting to all their friends and family. In fact, many of them actively rely on just that happening in order to make them most effective.

Contrary to popular belief, the more modern and sophisticated ones don’t require you to do much more than click a link in an email or message. A link can actually trigger a download or place a cookie on your browser to track your future site activity, meaning the hackers/scammers can even read the keyboard strokes you make when you (for example) sign into your email or your bank.

Now, don’t panic, these things are rare and most secure sites have measures in place to stop them happening. But you still need to be cautious. We are going to give a few examples of the kind of things you need to look out for.

If you receive an email with a link in it

Err on the side of caution here, the best advice would be just don’t click the link at all. However, you can often check a few basic things to make sure it is legitimate or not. These can often appear to come from legitimate companies.

Firstly, check the email address it has come from. As with the example below, you can see that it is telling your email client that it comes from Rackspace.com (a legitimate company) but when you click to expand the information you see that the email address is actually a load of gobbledegook.

This is a perfect example of how to check that the source is genuine or not. Always check the spelling of the words too. Often it can look like it is actually from the company, but on closer inspection a few of the letters are swapped around. Just a trick they’ll try.

If you receive a text with a link in it

Again, unless this appears to be from a legitimate source, it is usually best to delete it right away, don’t even bother doing anything further.

However, they can be very convincing. It is possible to add a name to your text number so when it hits someone’s phone, it looks to be from a genuine source.

A couple of perfect examples are:

These scams can sound very real.

The NatWest one instils a sense of urgency with it’s language use and it is asking you to click a link to log in and secure your account. What the scammers will have done is built a page that LOOKS like it’s NatWest’s website and it will simply copy the login information you provide.

In effect you’re giving them your banking login details.

The HMRC one works another way, it suggests you are due some money, so you go to the link which will have been set up to LOOK like the HMRC website and be asked to enter your bank details, address, DOB etc so they can pay you. In effect, you’re giving them all the information they need to undertake identity theft and/or access your bank and make withdrawals.

Some simple rules

In order to help you make sure you avoid such issues, scams and phishing (data theft) attempts, here are some of our top tips:

  1. Banks/HMRC/credit card companies do not ever send you texts/emails to log into your account via – They’ll always instruct you to go to your app or contact them.
  2. Check any link/phone number they provide – if you get a link sent through or a phone number to call in an email or text, make sure it’s real. Read the URL carefully, Google the phone number (if it’s a real number for your bank you’ll find it on Google).
  3. Check the email address it has come from – Again, banks, Amazon, etc will almost never email you asking you to log in to your account. On the occasions they do (for example your card has been declined on a purchase you made) don’t ever click the link in the email.
  4. Log in to your account on your computer/phone separately – check/update anything that needs to be. This breaks the loop that scammers are trying to trap you in.
  5. Change your password/logins the moment you suspect something – if you’ve been given reason to believe that your account has been hacked or otherwise compromised, log in right away and change your login details.
  6. Think “how likely is this” whenever you receive anything – it might sound simple but do a reality check when you get something unexpected through. And, if in doubt, contact your bank/card company etc directly to verify it.

We hope this article is useful. Of course, there is no way to guarantee that you’ll never fall victim to something like this, and the more sophisticated scams/hacks are very clever and very difficult to spot.

The best advice is to always err on the side of caution and only use the apps/sites that you use most often to log into things. Don’t trust direct links or buttons in emails that may appear legitimate, find your own way there. It’s just safer.

Stay safe, stay alert, stay protected.

If you would like any information on security and data protection within your business, please feel free to drop us a line, or message us via our contact page.