distribution
Suspicious message? Report it through the right UK channel
SMS, email and app messages have different reporting routes. If you have shared banking details or lost money, contacting the bank and reporting the crime are separate urgent steps.
A suspicious delivery notice or urgent account warning does not need a reply from you. Pause before touching the link. In the UK, reporting the message can help the organisation responsible for that channel act; it is a different task from protecting an account or getting help after money has gone.
- Do not reply, open attachments or follow an uncertain message's links.
- Report SMS to 7726, suspicious email to report@phishing.gov.uk, and app messages inside the app.
- If banking details or money are involved, contact the bank immediately; do not wait for a message-report response.
Check without using the message's route
GOV.UK's phishing guidance says not to disclose private information, reply to uncertain texts, download attachments or click uncertain email links. A familiar logo or an urgent deadline is not a reason to skip that pause. You do not have to establish who sent a message before deciding not to engage.
If you need to check a claim, use a contact route you independently trust. Ofcom advises using an organisation's official website or your account statement, not the number supplied by a suspicious caller. The same practical separation helps with a message demanding that you call its supposed fraud team.
SMS, email and chat are not one inbox
- SMS: forward the suspicious text to 7726. The free UK service reports it to your mobile provider.
- Email: forward a suspicious email to report@phishing.gov.uk, the NCSC Suspicious Email Reporting Service.
- WhatsApp, Telegram or Signal: use the app's reporting and blocking features; these messages cannot usually be forwarded to 7726.
Ofcom distinguishes SMS from RCS, iMessage and internet-based chat. Use the relevant built-in reporting controls where available; the 7726 forwarding route is for SMS. If a forwarding option is unclear, check the provider's official help rather than clicking the suspect link to investigate. These UK routes are not universal international short codes.
Reporting a message is not reporting a loss
The NCSC's email-reporting guidance expressly distinguishes this service from crime reporting. It analyses suspicious messages and linked sites, but does not tell senders the outcome of its review. Forwarding an email is not confirmation that your account is secure or that a payment has been reversed.
If you have entered banking or card details, NCSC guidance says to contact your bank immediately. Use the bank's trusted app, official site or the number on your card. If you disclosed a password, change it and any other account using the same password. Follow the provider's official recovery guidance if you have lost account access.
For fraud or cyber crime in England, Wales or Northern Ireland, the current route is Report Fraud, online or on 0300 123 2040. Scotland uses Police Scotland on 101. Current NCSC guidance confirms that distinction. Do not wait for the suspicious-message service before contacting the bank or making a crime report.
Give useful information, not more access
Keep a short record of what happened, when, what you shared and any payment reference for the bank or official reporting channel. Do not publish passwords, recovery codes or other people's details in a public warning. If it happened on a work device, NCSC advises telling your IT team. Reporting supports a response; it does not guarantee recovery or an individual investigation.
For readers travelling between Britain and an African country, distinguish your mobile provider's reporting tools from the jurisdiction handling a loss. This guide covers UK routes, not local police, banks or telecom rules overseas. The useful next step is the correct official channel, not further conversation with the sender.
Sources and disclosures
- Disclosure
- RIGHTS REVIEW REQUIRED — private draft only. Supplied media has no established publication licence. Do not publish or schedule until exact rights are documented. The attached media is under review; this is not a reuse licence. Documentation-based UK scam-message reporting guide, checked 8 October 2026, with AI-assisted research and drafting. PING has not opened malicious links, tested a reporting service or handled reader incidents. This is general official-guidance navigation, not an account-recovery service or a promise of investigation, reimbursement or protection from further contact. The supplied message image is a generated example for private review, not an actual scam report; do not use its visible contact details. Public image rights are unconfirmed.
- Declared media rights
- Generated illustration
- Sources and method
- RIGHTS REVIEW REQUIRED — private draft only. Supplied media has no established publication licence. Do not publish or schedule until exact rights are documented. The attached media is under review; this is not a reuse licence. Assets requiring rights review: suspicious-message-flow-private-20261008. UK reporting guidance checked 8 October 2026 against GOV.UK, Ofcom, NCSC and Report Fraud. Ofcom's guide was published 15 July 2026 and updated 24 August 2026. NCSC's email-reporting page displays publication on 26 November 2021 and review on 5 September 2022; the reporting routes were checked again for this guide. Other help pages do not display a publication or update date. Suspicious-message reporting is separate from bank contact and crime reporting. Current NCSC and Report Fraud guidance routes England, Wales and Northern Ireland to Report Fraud, and Scotland to Police Scotland. This guide does not cover overseas reporting systems or guarantee investigation or recovery. Sources: https://www.gov.uk/report-suspicious-emails-websites-phishing ; https://www.ofcom.org.uk/phones-and-broadband/scam-calls-and-messages/what-to-do-about-a-scam-call-text-or-message ; https://www.ncsc.gov.uk/section/respond-recover/phishing ; https://www.reportfraud.police.uk/faqs ; https://www.ncsc.gov.uk/collection/phishing-scams/report-scam-email . Private media review only. User-supplied Google Flow illustration; creator and reuse rights unconfirmed. Generated illustration supplied unchanged for private review, not a real received message. Visible contact details are illustrative, unverified and must not be used. Public reuse rights unconfirmed. Original download route: https://flow.google.com/ . Embedded generation assertions were observed, not cryptographically validated; ownership and reference inputs are unconfirmed. The article's reporting routes do not direct readers to any contact string visible in the illustration. Cover: Generated illustration supplied unchanged for private review, not a real received message. Visible contact details are illustrative, unverified and must not be used. Public reuse rights unconfirmed.
Reader comments
Comments are not open yet. When available, submissions will require free sign-in and editorial approval before appearing. PING does not promise a response.
Privacy information