
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

If you’ve noticed more scam calls and increasingly convincing phishing emails recently, you’re not alone.
Summary
The UK National Cybersecurity Centre (NCC) itself has said that “scams are getting smarter, and some even fool the experts”. AI tools and voice cloning (where fraudsters use clips of someone’s voice to mimic a loved one on the phone) might make your online life feel increasingly fraught. Following ASOS’ unauthorised “hack” notification this week, cyber-attacks on various UK airports , and the back-to-back digital supermarket breaches of 2025 , affected customers are often advised not to click on or engage with suspicious links.
But what if you’ve already selected it by accident? Here, cybersecurity experts share their advice on what to do next. General advice if you’ve clicked on a suspicious link Tomas Stamulis, the chief security officer at digital privacy company Surfshark, said that you shouldn’t assume the worst if you’ve clicked on a suspicious link – though you should “act quickly”.
In fact, all the experts we spoke to said speed matters here. “Close the page straight away and avoid entering any personal information, passwords or payment details. If anything has downloaded or been installed, disconnect the device from the internet and run a full malware scan,” he added.
Neil Bayliss, director of IT support experts Hubtel IT , agreed that you should act immediately, but stressed you shouldn’t panic. “Scammers often count on you panicking and losing your ability to think rationally,” he explained. And Stephen Bailey, director of client delivery at global cyber security company NCC Group, told us: “One of the biggest mistakes people make is delaying because they’re worried about admitting they clicked a link or opened an attachment.” Both in your workplace or on a personal device, “taking action quickly can limit the damage and make it much harder for an attacker to gain further access”.
If you used, or think you might have used, a work account or device when entering your card details, contact your company’s IT team too, both Bailey and Bayliss shared. What if I opened a link and shared my password? Stamulis said that if you did enter some login details, change them from a “clean” device – not the one on which you received the scam email, text or call.
Start with your email address, he added, as access to your email can give hackers a path to other services via password changes. Stamulis advised using unique passwords and two-factor authentication. Keep an eye on your bank, email, and “other important accounts for unfamiliar logins, password changes, or transactions over the following days and weeks,” he continued.
“Be particularly vigilant about unexpected calls, texts or emails offering to help with the issue, as scammers can use the situation to pose as a trusted company or support service and try to gather more information from you.” What if I opened a link and shared financial details? You should call your bank at once if you shared any financial information like your card or account details, stated Bayliss. “Make sure you use its official website or app, or call the contact number on the back of your card,” he said.
All the experts we spoke to said scammers might use the aftermath of a data breach to get more financial information from you, too. Maybe your initial click on the link didn’t lead to any information they could use to directly draw money from your account. But people should be very cautious of any unsolicited requests for credentials, financial information, or urgent action.
“Instead, verify information through official channels and trusted sources before taking any action,” stated Bailey. How can I report scam links? Stamulis said that if the scam came via email, report it to your email provider and the National Cyber Security Centre .
Don’t click on the link again, and don’t reply to the scammers. You can also “forward suspicious emails to [email protected] and suspicious text messages to 7726 free of charge,” Bayliss said. You can also report scam calls to 7726, per Ofcom .
Just select the phone number that called you (don’t dial it), copy it and paste into a SMS message to 7726. How can I spot scam links going forward? “There used to be quite common signs of a scam such as spelling mistakes or suspicious-looking links, but some criminals use AI tools to create convincing and polished messages,” suggested Bayliss.
Scams have gotten more “sophisticated” but one giveaway can be a sense of urgency. If you receive a message or call that tells you you need to take immediate action, like resetting a password or following a link, consider it suspicious. Bayliss warned: “Don’t let yourself become pressured or lose sight of clear red flags.” And Stamulis said you should “treat unexpected contact with caution, avoid clicking links in messages and go to the relevant website or app independently”.
“It is also worth changing any reused passwords, enabling two-factor authentication and keeping an eye out for unusual account activity or unexpected password-reset requests,” he said. Related...
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
We've archived 262 other articles touching the same topic (life, tech, evergreen) , see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.