Skip to main content
European CyberCrime Centre
Guidance

Phishing scams: how to spot and report them

How to recognise and report scam emails, texts, websites, adverts or phone calls across Europe.

Illustration for Phishing scams: how to spot and report them
EC3 illustration

Phishing remains the most common way criminals reach victims in Europe. Messages arrive by email, text, social media or phone, pretending to be banks, delivery firms, government agencies or colleagues. Their goal is always the same: your details, your money, or a foothold in your organisation.


Spot the signs

Most phishing messages share a small set of tell-tale signs:

  • urgency or threats — 'act now or your account will be closed'
  • a request for payment, gift cards, or personal information
  • sender addresses that look almost — but not quite — right
  • links that don't match the organisation's genuine web address
  • unexpected attachments, or messages that arrive at odd times

If you think you've been targeted

Don't reply, don't click, and don't download attachments. Report the message to your national cyber crime reporting service and to the organisation being impersonated, then delete it. If you already clicked or shared details, change the affected passwords straight away and contact your bank if money or card details were involved.

How EC3 helps

EC3 coordinates cross-border investigations into the criminal groups behind large-scale phishing campaigns, and works with banks, telecoms operators and platforms to take down the infrastructure they rely on. Your reports help build that picture.


If you can't recover your account

In some cases it may not be possible to recover an account. If so, create a new one, tell your contacts you've abandoned the old account, and update any bank, utility or shopping websites with your new details. If the incident involved money or personal data, report it to your national police portal — your report feeds into Europe-wide investigations coordinated by EC3.

Back to top