I clicked a link in a scam text: what to do now (UK)
Checked by TextCheckUK · Last checked · How we check
If you tapped a link in a scam text, what to do depends on what you did next. Only opened the page: close it, forward the text to 7726 and delete it. Typed a password: change it. Gave card or bank details, or paid: call your bank now, on 159 or the number on your card. Installed an app: don't log in to anything and factory reset the phone, as the NCSC advises.
Start here: what did you do after you tapped?
| What you did | Do this first | Then |
|---|---|---|
| Opened the page, typed nothing, installed nothing | Close the page and don't go back to it. | Forward the text to 7726, report the website to the NCSC and keep your phone's software up to date. |
| Typed a password | Change it, and the password of any other account that uses the same one. | Log out of that account on all your apps and devices, and turn on 2-step verification. |
| Typed card or bank details | Contact your bank: call 159 or the number on the back of your card. | Treat any later call or text 'from your bank' with suspicion, and call back on 159. |
| Installed an app | Don't log in to any account. Factory reset the phone as soon as you can, without backing it up first. | Change the passwords of accounts you used since the install (steps below). |
| Paid or lost money | Tell your bank straight away. | Report it to Report Fraud (England, Wales and Northern Ireland: reportfraud.police.uk or 0300 123 2040) or to Police Scotland on 101. |
You only opened the page and closed it
The NCSC says the purpose of a scam text is often to get you to tap a link, and that the website behind it is used to download viruses or to steal passwords and other personal information. On phones, its missed-parcel guidance describes the download as an "app" the page asks you to install.
If you typed nothing and installed nothing, neither of those things happened. Report the text and the site (see below), and make sure your phone is up to date: the NCSC advises installing the latest software and patches.
You typed a password or a code
Change that password now. The NCSC says to change the password on any of your accounts that use the same one, and Stop! Think Fraud explains why: criminals try a stolen password on other accounts. Then log out of the account on all your apps and devices, so anyone else using it has to enter the new password, and turn on 2-step verification.
If what you typed was a one-time code, see verification code texts you didn't ask for. If it was your Apple Account password, see Apple and iCloud scam texts.
You gave card or bank details
Call your bank now. The NCSC's advice when you have given out banking details is to contact your bank and let them know. Use 159 or the number on the back of your card: Stop Scams UK says 159 puts you through to your own bank and cannot be faked. For texts that pretend to be your bank, see how to check a bank text.
You installed an app
The NCSC has guidance for exactly this case. It says the "app" in these texts is malware that can steal your banking details, passwords and other sensitive information, and that it also tries to send scam texts to your contacts.
If you installed an app from a text link
Don't log in to anything
Not your bank, email or shopping apps: the NCSC warns that the malware may steal what you type.
(NCSC, missed parcel texts and malware, read 2 October 2026)
Don't back up first
A backup made now would contain the malware too, so skip it, however tempting.
(NCSC, missed parcel texts and malware, read 2 October 2026)
Factory reset the phone
Do it as soon as you can, from Settings (some phones call it 'Erase all content'). The reset deletes everything on the phone.
(NCSC, missed parcel texts and malware, read 2 October 2026)
Restore only an older backup
Only restore a backup if you are sure it was made before you installed the app. If you can't be sure, restore none.
(NCSC, missed parcel texts and malware, read 2 October 2026)
Change your passwords
For every account you logged in to since the install, and for any other account that uses the same password.
(NCSC, missed parcel texts and malware, read 2 October 2026)
Turn on 2-step verification
On every account that offers it, so a stolen password alone is not enough to get in.
(Stop! Think Fraud, if you've been hacked, read 2 October 2026)
Steps from the NCSC's guidance on missed-parcel malware; drawn by us, not screenshots.
You lost money
Tell your bank first, then report it as a crime: the NCSC names Report Fraud for England, Wales and Northern Ireland (reportfraud.police.uk or 0300 123 2040) and Police Scotland, on 101, for Scotland. Report Fraud replaced Action Fraud in December 2025, so ignore older pages that still send you to Action Fraud.
Report the text and the website
- Forward the text to 7726, free on most networks, then delete it. The NCSC says reporting helps cut the scam texts you get and protects other people.
- Report the website to the NCSC.
- Can't forward it? The NCSC also takes a screenshot or screen recording of the text at report@phishing.gov.uk.
Written by us; not a real message. [COURIER] and [link] stand in for details we leave out.
1. An app offered through a text
The NCSC says these texts link to what look like official tracking apps, and that the app is malware that can steal banking details and passwords. Install apps only from your phone's official app store.
“But the ‘app’ is in fact a type of malware.” (NCSC, missed parcel texts and malware, read 2 October 2026)
2. The link
To check a delivery, the NCSC points you to the delivery company's own website or app, typed or opened yourself, never the link in the message.
“a safer way of tracking its status is to use the official website of the delivery companies.” (NCSC, missed parcel texts and malware, read 2 October 2026)
3. A deadline
Being told you have only a short time to act is one of the tell-tale signs of a scam in the NCSC's checklist.
“Are you told you have a limited time to respond” (NCSC, how to spot a scam, read 2 October 2026)
What to watch for in the next few weeks
The NCSC's advice for people whose details have been exposed applies here too: stay alert to suspicious messages, which can arrive some time later, and to remember that your bank, or any other official organisation, will never ask you to supply personal information.
Stop! Think Fraud lists the signs that an account has been taken over: you can't log in, your security settings have changed, messages you don't recognise were sent from your account, someone tried to log in from an unusual place, or there are payments you didn't make. If a caller says they are from your bank and asks you to act, hang up and call 159.
Got another text you are unsure about? Paste it into the scam text checker. More on texts pretending to be your bank and parcel delivery scam texts.
Sources
- NCSC, if you've shared sensitive information: NCSC, 'Phishing scams: If you've shared sensitive information' (published 26 November 2021, reviewed 5 September 2022): "You’ve provided your banking details: Contact your bank and let them know. ... You've given out your password: You should change the passwords on any of your accounts which use the same password. ... You've lost money: Tell your bank and report it as a crime to Report Fraud (for England, Wales and Northern Ireland) or Police Scotland (for Scotland)." Contains public sector information licensed under the Open Government Licence v3.0. — https://www.ncsc.gov.uk/collection/phishing-scams/what-to-do, read on 2026-10-02
- NCSC, missed parcel texts and malware: NCSC, 'Scam 'missed parcel' SMS messages: advice on avoiding malware' (published 23 April 2021, reviewed 15 December 2023): "The scam SMS messages contain links to what appear to be ‘official’ delivery/parcel-tracking apps, which you’re encouraged to install. But the ‘app’ is in fact a type of malware. If installed, this malware can steal your banking details, passwords, and other sensitive information. ... if you think you may have been tricked into installing malware from a scam message, then it’s important that you don’t log into any accounts, as the malware may steal these details. Instead, as soon as you can, you should perform a factory reset on your device. Note: It’s important that you don’t back up your data before you perform a factory reset, as the backup will also contain the malware. For the same reason, when you’re given the option to restore backups, you should only do so if you’re confident that the backup was created before you installed the malware. If you can’t be sure, you should perform a factory reset and not restore any backups. ... If you have logged into any accounts or apps since installing the malware, you must change the password for that account ... set up two-step verification (2SV) on accounts, where possible. ... a safer way of tracking its status is to use the official website of the delivery companies. ... Ensure your device is kept up to date by installing the latest software and patches." Contains public sector information licensed under the Open Government Licence v3.0. — https://www.ncsc.gov.uk/guidance/scam-missed-parcel-sms-messages, read on 2026-10-02
- NCSC, report a scam text: NCSC, 'Report a scam text' (published 26 November 2021, reviewed 5 September 2022): "By reporting, you can: reduce the amount of scam texts you receive; make yourself a harder target for scammers; protect others from cyber crime online. 40.9K scams removed across 93.3k URLs as of July 2026 as part of the 7726 service. ... You can also take a screenshot or screen recording of the text message and send it to us at report@phishing.gov.uk ... If 7726 doesn't work, you can find out how to report a text message by contacting your phone provider. ... The purpose of a scam text message is often to get you to click a link. This will take you to a website which criminals use to download viruses to your computer, or steal passwords or other personal information." Contains public sector information licensed under the Open Government Licence v3.0. — https://www.ncsc.gov.uk/collection/phishing-scams/report-scam-text-message, read on 2026-10-02
- NCSC, how to spot a scam: NCSC, 'How to spot a scam email, text message or call' (published 26 November 2021, reviewed 5 September 2022): "Urgency Are you told you have a limited time to respond (such as 'within 24 hours' or 'immediately')? Criminals often threaten you with fines or other negative consequences. ... If you have any doubts about a message, contact the organisation directly. Don’t use the numbers or address in the message – use the details from their official website." Contains public sector information licensed under the Open Government Licence v3.0. — https://www.ncsc.gov.uk/collection/phishing-scams/spot-scams, read on 2026-10-02
- NCSC, after your details are exposed: NCSC, 'Data breaches: guidance for individuals and families' (published 28 January 2021): "Be alert to suspicious messages (we've published guidance that can help you with this), which may be sent some time after the breach is made public. Remember, your bank (or any other official organisation) will never ask you to supply personal information." Contains public sector information licensed under the Open Government Licence v3.0. — https://www.ncsc.gov.uk/guidance/data-breaches, read on 2026-10-02
- Stop! Think Fraud, if you've been hacked: Stop! Think Fraud (UK Government campaign), 'What to do if you've been hacked': "There are a number of signs that your email account, social media account or bank account might have been hacked. They include being unable to log into your accounts, changes to your security settings, messages sent from your account that you don’t recognise, attempted log-ins from unusual locations, and unauthorised payments from your online accounts. ... If you use the same password for any other accounts or sites, you will need to change all of them, as cyber criminals will try the same ‘hacked’ password across multiple accounts. ... Once you’ve changed your passwords, you need to make sure you log out of your accounts on all your apps and devices. ... 2SV (also known as two-factor authentication or 2FA) usually works by sending you a PIN or code, which you’ll then have to enter to prove that it’s really you." Contains public sector information licensed under the Open Government Licence v3.0. — https://stopthinkfraud.campaign.gov.uk/recovery-from-fraud/recovering-losses/what-to-do-if-youve-been-hacked/, read on 2026-10-02
- Stop Scams UK, 159: Stop Scams UK, '159 Phone number', summarised in our own words: the short number 159 puts you through to your own bank (it covers more than 99% of UK retail bank current accounts), and its caller ID cannot be faked. — https://stopscamsuk.org.uk/our-programmes/159-phone-number/, read on 2026-10-02
- NCSC, forwarding to 7726: NCSC, Report a scam text: "Most phone providers are part of a scheme that allows customers to report suspicious text messages for free by forwarding it to 7726. If you forward a text to 7726, your provider can investigate the origin of the text and arrange to block or ban the sender, if it's found to be malicious." — https://www.ncsc.gov.uk/collection/phishing-scams/report-scam-text-message, read on 2026-09-29
- Report Fraud: Action Fraud / City of London Police press release, 4 Dec 2025, summarised in our own words: from 4 December 2025 fraud and cyber crime in England, Wales and Northern Ireland are reported to the new Report Fraud service, which replaced Action Fraud, at reportfraud.police.uk or on 0300 123 2040; people in Scotland keep calling Police Scotland on 101. — https://www.wired-gov.net/wg/news.nsf/articles/Report+Fraud+service+goes+live+04122025143000; https://www.reportfraud.police.uk/, read on 2026-09-29
Quotes from GOV.UK, legislation.gov.uk, mygov.scot, the NCSC, the ICO and NHS England are used under the Open Government Licence v3.0; material from Ofcom is Ofcom copyright. Other pages are summarised in our own words or quoted briefly, with a link. How we check.
Frequently asked questions
- I clicked a scam link but closed it straight away. Am I OK?
- The NCSC's guidance puts the risk in what the page gets you to do: type passwords or details, or install an app. If you did neither, forward the text to 7726, report the website to the NCSC, keep your phone updated and be wary of follow-up messages.
- Can opening a scam link infect an iPhone?
- The NCSC says the website behind a scam link is used to download viruses or to steal passwords and personal details, and its advice for phones centres on apps the page pushes you to install. Keep your iPhone updated, and if you did install something, follow the factory reset steps on this page.
- I only typed my card number. Should I still call my bank?
- Yes. The NCSC's advice when you have given out banking details is to contact your bank and let them know. Call 159 or the number on the back of your card.
- Someone called 'from my bank' after I clicked. What should I do?
- Hang up. The NCSC says your bank will never ask you to supply personal information, and to contact the organisation using the details from its official website. Call 159 or the number on your card.
- Do I need to report it if nothing happened?
- It helps. Forwarding the text to 7726 is free on most networks, and the NCSC says reporting cuts the scam texts you receive and protects other people.
More guides
- How to block spam texts on iPhone and Android (UK settings that work in 2026)
How to stop spam texts in the UK: filter unknown senders on iPhone, turn on spam protection in Google Messages, report, block and forward to 7726.
- Got a verification code text you didn't ask for? What it means and what to do
A code you didn't request means someone typed your number into a sign-in page. Never share it, not even with friends: the WhatsApp code scam explained.
- Should you reply STOP to a spam text? And can opening a text hack your phone?
Reply STOP only to companies you know, says the ICO. Why replying to unknown senders backfires, STOP ALL for premium-rate texts, and opening a text.
- Scam texts from an email address, iMessage or RCS: why they get through and how to report them
A blue-bubble scam text from an email address is an iMessage, outside the networks' filters and 7726. How SMS, RCS, iMessage and WhatsApp differ.
Last updated 2026-10-02. Independent information service. Number data from Ofcom shows the original range holder; numbers can be ported or spoofed. Not affiliated with any organisation named on this page, including Ofcom, the FCA, the ICO, the NHS, DWP, HMRC, TV Licensing, Apple, Google or any police service.