Skip to content
Safety & Privacy

Recognising Phishing Emails and Messages

Back to Security Center

Your safety guides how we build. Read this at your own pace, and reach our team any time from the Security Center.

What Is Phishing?

Phishing is a type of social engineering attack where criminals send fraudulent messages designed to trick you into revealing sensitive information. These messages typically impersonate trusted organisations, such as your bank, a delivery company, a government agency, or a platform like KF.Social. The goal is to make you click a malicious link, download an infected attachment, or enter your login credentials on a fake website.

Phishing is not limited to email. Attackers also use text messages (known as smishing), phone calls (vishing), and social media direct messages to reach their targets.

Red Flags: How to Spot a Phishing Message

While phishing messages are becoming increasingly sophisticated, most share common characteristics that you can learn to recognise:

Examples of Common Phishing Tactics

Understanding real-world examples makes it easier to spot phishing in practice:

What to Do If You Receive a Suspicious Message

  1. Do not click any links or download any attachments.
  2. Do not reply to the message or provide any personal information.
  3. Verify independently: If the message claims to be from a specific organisation, contact them directly using the official contact details on their website, not the contact information in the suspicious message.
  4. Report it: Forward suspicious emails to report@phishing.gov.uk, the NCSC's suspicious email reporting service. You can also report phishing to Action Fraud.
  5. Delete the message after reporting it.

What to Do If You Already Clicked

If you have already clicked a phishing link or entered your details on a suspicious website, act quickly:

  1. Change the password for the affected account immediately.
  2. Enable two-factor authentication if you have not already done so.
  3. Check your account for any unauthorised changes, messages, or transactions.
  4. Run a full antivirus scan on your device.
  5. Monitor your financial accounts for unusual activity.
  6. Report the incident to Action Fraud and notify the platform involved.

Staying Protected

The most effective defence against phishing is awareness. Take a moment to scrutinise any message that asks you to take urgent action or provide sensitive information. The NCSC's phishing guidance offers further practical advice on identifying and reporting phishing attempts. Remember: if something feels wrong, trust your instincts and verify before you act.

Back to Security Center

Meet people, safely.

ID checks you can see, real dinners, and a team that has your back. See how it works.

KF.Social
Go for dinner. Leave with friends.
Get the app