Protect your finances from scams, part 2: Common types of online scams
Online scams are real and have unfortunately left millions out of pocket. Protecting your finances is more critical than ever, we explain what you need to know and how to stay safe online.
Nearly 43 million adults encountered suspected scams online in the UK. And among those who lost money, one in five lost more than £1,000 to online fraud, according to a study commissioned by Ofcom and conducted in 2022. We believe knowledge and awareness will help you identify an online scam and take precautions. So, what techniques do fraudsters use?
- What is phishing?
- What is smishing?
- What is pharming?
- What is malware?
- What you should do to protect yourself and your finances online
What is phishing?
Phishing is a type of email scam in which the message is made to look like it has come from a legitimate source. This source can be a retailer or shopping site such as Amazon, eBay, or a travel company. It could also be your bank or an email from government institutions such as HMRC or the NHS.
The message will usually ask you to do something, such as login by clicking on a link to a fake site or download "important" attachments designed to infect your device or computer with malware. The ultimate goal of the scammer is to steal your details so they can access your credit card and bank account.
Fraudsters may also attempt to use your details to apply for credit, for example, to get a short term loan or a personal loan. If successful, they will get the money taken out in your name and leave you to pay the instalments.
Many COVID-19 scams involved phishing techniques made to look genuine and like they had come from the government or a health organisation. Many claimed to provide guidance on safety measures and required you to click a link or open an attachment to view.
Vishing is a version of phishing in the form of a phone call. The scammer pretends to be calling from a legitimate source, and, like phishing, they will try to persuade you to reveal personal financial information.
How can I spot a phishing email scam?
When getting an unexpected communication or if prompted to do something, the best thing is to stop and look for tell-tale signs:
- Are you expecting to receive an email from the organisation or company? Do you have an account with them, or have you signed up for a service from them? Remember, legitimate organisations or companies do not send unsolicited or random emails.
- Are there any spelling errors or grammatical errors? If there are, it's unlikely the email came from a reputable source.
- Are you addressed personally, with your name correctly written, or is this generically addressed as Dear Sir, Madam, or Customer? A genuine email will mostly address you by your name.
- Where did the email come from? Does the domain or the email address look correct or does it look odd? Does it contain random letters or numbers or characters, or is it misspelt? Has it come from a generic email service such as Gmail or Hotmail? Online fraudsters will unlikely be able to use a real domain name.
- Are you being told you must act immediately? Are you being bullied, blackmailed or threatened to do something? Remember, as we mentioned in Part 1 of our Protect Your Finances From Scams series, scammers want you to make panic decisions. Instead, take your time to make sure it is genuine. No reputable company will want you to rush or threaten you to act immediately.
What should I do if an email looks suspicious?
If you think an email looks suspicious, don't click on any link, do not download any attachments and do not reply or forward the email. Instead, contact the company directly (or the person if you know them) to verify if it is genuine. Remember not to use the contact details shown in a suspicious email.
If it is a scam, inform the company or organisation so they can take steps to warn others. Some email services, like Gmail, allow you to report an email as spam or phishing. This can help email providers and services block the same communication from going to others.
What is smishing?
Smishing is the SMS or text message version of phishing. The text message will claim to be from your bank, your mobile network provider, a retailer or another organisation. It can be an SMS or even a social media message, such as WhatsApp.
Usually, there is a "problem" of some sort, or confirmation is required. For example, payment was not received, and you need to log in to update your card details. Or there is a lack of funds in your account. Or you need to log in to your account to confirm your personal information. Or it's a delivery company that requires confirmation that you want to receive a parcel.
There will likely be a fake phone number, a link to a bogus site, or a link to install harmful malware - all of which are designed to steal your personal information and, ultimately, your money.
How do I recognise a smishing scam?
Here are signs you can look for in a smishing scam:
- Check if the number used to send the message to you differs from the number used to contact you in the past. Also, check whether the message is from an international or a random mobile number. If yes, then it could be a scam.
- Ask yourself: "Do I know the company or organisation contacting me? Have I signed up for a service offered by them, or have I been contacted out of the blue?" As with emails, legitimate companies will not send random unsolicited SMS or text messages.
- Check if you’re personally addressed or if it is merely generically addressed to Customer or Mate or Friend. Look for spelling or grammar errors. A text message from a company or organisation with whom you already have a relationship will likely use your name when writing to you. And a reputable company will unlikely send communications with typos and spelling errors.
- Finally, check for panicked urgency - like you must act immediately. Don’t! Remember, scammers want you to feel confused and rushed, and a reputable organisation or company would not want to do that to you.
What should I do if a text message looks like a scam?
Do not respond to an SMS or message that looks odd or suspicious. Do not call the number of the sender. Do not click on any link.
It’s best to avoid clicking on message links at all (including messaging services like WhatsApp or Facebook Messenger) unless you are absolutely sure it is genuine and safe to do so. If in doubt, call the company or organisation from whom the text claims to have been sent (or the individual if you know them) and check if the message is genuine.
TIP: You can report suspicious SMS or spam texts directly to your mobile phone service provider by forwarding them to 7726, free of charge. This will help UK mobile phone operators and relevant authorities to take action to protect others.
What is pharming?
With pharming, online criminals target the website you visit by redirecting you to a fake or cloned version of the “real" site. The purpose is to capture your personal or security details, such as passwords, and defraud you of your money.
According to the cybersecurity firm Norton, pharming scams are performed in two ways. One involves criminals infecting a device or computer with malicious code or software that redirects users to a bogus site.
The other is criminals using a rogue or corrupted DNS (Domain Name Systems) server. DNS computers or servers direct users' website requests to the correct IP address of the requested websites. A corrupted or rogue DNS server directs users to fake versions of the same sites. In both scenarios, you are redirected seamlessly, making it hard to detect.
How can I identify pharming?
When visiting a website or a similar online service, check for the following:
- Is the connection secure? Remember to look for the padlock icon or an HTTPS before the address. Check the security certificate is valid to ensure the connection is secure and encrypted.
- Does the website address or URL show as you expect it? Look for odd characters, numbers, or misspellings of the company or organisation’s name on the web address.
- Are there any obvious errors, spelling mistakes or grammatical issues? As with emails and text messages, websites by reputable businesses and organisations should not have typos.
- Does the website look odd? Are there any inconsistencies, such as the colours or fonts? Do the images and logos look pixelated, low-resolution or stretched? Most companies will ensure their website looks good and is consistent with their brand - so it is unlikely their logos and images will look pixelated or the colours will be inconsistent.
- Is the site up to date? Is the content very sparse—for example, there are only one or two blogs? Blogs, reviews, and comments on an official website will be recent and up to date. And there will be plenty of helpful content available.
- Has your internet browser displayed a security alert? For example, have you been informed of a problem with an SSL certificate? Legitimate organisations will ensure their website is secure at all times.
What should I do if a website looks odd?
If a website looks odd or suspicious, do not enter any details or try to log in. You should report the matter to protect others if you suspect it is a scam. According to Money Advice Service, there are several steps you can take to report pharming and fake websites. You should let the company or organisation know about the clone website.
You should also report the scam to Action Fraud online or by calling 0300 123 2040. You can also notify Google of suspected phishing websites.
What is malware?
Malware is short for malicious software. Devices and computers can be infected in many ways. Some of these have been mentioned above, including opening infected attachments on an email, opening a link to a malicious website in a text message, and installing a file from a dubious website.
Computer viruses and malware can infect just about any computer, device, and operating system (including Windows, Mac OS or Linux). Malware is mostly designed to access your details and accounts; they include:
- Computer viruses: A type of malware that spreads and infects a computer. The virus is usually part of an infected download and unknowingly installed by the user.
- Worms: These break into a system, usually without any action or trigger by the user. Worms replicate by themselves and spread by themselves. They can steal and delete files.
- Spyware: Collects data by effectively "spying" on the user. Data collected can include personal information and logins, which is then passed to third parties and criminals.
- Ransomware: This malicious software stops users from accessing their computer, device or files. It requires the user to pay a "ransom" or money to unblock access or release the files.
- Trojan files: These programs mimic legitimate files and programs but change a computer without the user knowing.
- Adware: As the name implies, this type of malware generates endless pop-ups, regardless of whether a web browser is open or not.
- Bots: Bots can be good or bad - depending on their source. These programs perform specific tasks automatically. Malicious bots are often used by cybercriminals to steal information or attack networks and websites.
How do I know if my computer has been infected with malware?
According to Kaspersky Lab, a leading cybersecurity and anti-virus provider, there are no distinct ways to tell if your computer or device is infected with a virus or malware. But there are some signs you can look out for:
- Your computer or device is running slower than usual. For example, the operating system and programs take much longer to load and crash regularly.
- You notice changes made to your browser and internet homepage when you did not make these changes yourself.
- A significant number of pop-ups, unusual messages and annoying ads continuously appear.
- Your anti-virus or security software has been disabled and does not automatically update.
- Your contacts have informed you that they are receiving odd emails or messages from you.
- You cannot access your system settings or particular files.
- You notice your computer processor is continually working, and unknown programs load up when switching on your computer.
You can check what programs are running and how much memory and CPU they take on your computer. To view running tasks and activities on Windows machines, use the Task Manager. On a Mac, you can find this in Activity Monitor.
What can I do if I think my computer has a virus or malware?
If you suspect your computer or device is infected, disconnect it from the internet. This will help prevent more data from being stolen and the virus from spreading further. You should only connect if you need to download a malware removal tool. Do not reconnect until your computer has been cleaned.
Scan your system with anti-virus software from a reputable company. If nothing is found, you can run an alternative anti-virus software, but make sure it is up to date. If your device is already infected, you may need to enter Windows Safe Mode if you are using a PC (you can also enter Safe Mode on Mac).
You could also try a System Restore on Windows (or Time Machine Backup on Mac). This restores the computer's previous state by selecting a date. System restoration can help resolve ransomware issues.
If your device is infected, do not try to access or log in to any online accounts, especially your bank account, email accounts, and social media accounts—you could be giving your security logins to scammers. If you need to, login from another computer or device you know is safe and secure, preferably not on the same network.
Contact your provider immediately if your bank or card details have been compromised. Always report lost or stolen debit and credit cards. You should also report the matter to Action Fraud online or by calling them on 0300 123 2040.
We've pulled together some additional resources that you may find helpful:
- Panda Security: How to remove malware from a Mac or PC
- Norton: How to know if your computer has a virus: 9 warning signs
- Norton: How to remove malware from Android phones
- Macworld: How to remove a virus from an iPhone or iPad
What you should do to protect yourself and your finances online
Online scams can be hard to detect, and many have become very sophisticated. But there are practical steps you can take. Here are some of our MustCompare top tips on what you should do to protect yourself and your finances online:
- Install top-rated, reputable anti-virus software and make sure it's up-to-date
- Keep your operating system up to date
- Use strong passwords and update them regularly
- Avoid all unsolicited communications
- Do not open files or attachments unless you were expecting them, you know they are safe, and you know the sender
- Do not open links, emails and messages unless you are sure they are genuine and safe
- Only visit secure sites - remember to look for the padlock icon
- Avoid websites, emails and messages that don't look right, even if they seem only slightly suspicious
- Keep your mobile safe and with you all the time. Fraudsters may try to use lost or stolen phones to access banking apps, payment cards and passwords
- Avoid free public WiFi connections or WiFi that does not require a password
- Only download software from secure sites operated by reputable companies. Never download apps from unofficial, third-party App Stores
- Check your credit report regularly and look for any searches or attempts to apply for a loan or other forms of credit not made by you - this could be a sign your personal details have been compromised or identity fraud
Remember to also use our telltale signs listed above. If you have not already read it, you can find more helpful tips in Part 1: How to identify an online scam.
In summary
In Part 2 of our ‘Protect your finances from scams’ series, we examined four online scam techniques: phishing, smishing, pharming and malware. We looked at what they are, how to spot them and what to do if you suspect a scam or fraud. We also looked at practical steps you can take to protect yourself online.
The key to spotting a scam is taking time before parting with personal information, clicking links, or opening a file. Even if it sounds important, be cautious and don't rush. Make sure it is genuine and they are who they say they are. Our final tip is to stay informed and keep up to date. Being informed can help protect you and your money from online fraudsters.
In Part 3, we will examine what we learned from COVID-19 scams.
Enjoyed this guide? Let us know by hitting the like icon below!