Phishing scams: how to spot and report them
How to recognise and report scam emails, texts, websites, adverts or phone calls across Europe.
Phishing remains the most common way criminals reach victims in Europe. Messages arrive by email, text, social media or phone, pretending to be banks, delivery firms, government agencies or colleagues. Their goal is always the same: your details, your money, or a foothold in your organisation.
Spot the signs
Most phishing messages share a small set of tell-tale signs:
- urgency or threats — 'act now or your account will be closed'
- a request for payment, gift cards, or personal information
- sender addresses that look almost — but not quite — right
- links that don't match the organisation's genuine web address
- unexpected attachments, or messages that arrive at odd times
If you think you've been targeted
Don't reply, don't click, and don't download attachments. Report the message to your national cyber crime reporting service and to the organisation being impersonated, then delete it. If you already clicked or shared details, change the affected passwords straight away and contact your bank if money or card details were involved.
How EC3 helps
EC3 coordinates cross-border investigations into the criminal groups behind large-scale phishing campaigns, and works with banks, telecoms operators and platforms to take down the infrastructure they rely on. Your reports help build that picture.
If you can't recover your account
In some cases it may not be possible to recover an account. If so, create a new one, tell your contacts you've abandoned the old account, and update any bank, utility or shopping websites with your new details. If the incident involved money or personal data, report it to your national police portal — your report feeds into Europe-wide investigations coordinated by EC3.