Your phone buzzes while you are cooking: a text says a parcel could not be delivered and asks you to confirm your address through a link. Texts like that are sometimes genuine and sometimes not. This post is about how to spot a scam before it costs you anything, and WhatsOnTech keeps it simple: not a hundred tricks to memorise, just the pattern most scams share and one habit that beats it.

The pattern behind most scams

Scams change their costumes, but most use some mix of the same four parts. Once you can see them, you know how to spot a scam even when the story is new.

  1. Urgency. Act now or something bad happens: an account closes, a fine doubles, a prize expires. The rush is the point: a hurried person does not check.
  2. A trusted-looking sender. Your bank, a delivery company, a government office, your boss or a family member. Borrowed trust does the persuading.
  3. Secrecy. Do not tell anyone, do not hang up. A second opinion often ends a scam, so scammers try to keep you alone.
  4. An unusual way to pay or act. Gift cards, cryptocurrency, a wire transfer, reading out a one-time code, or installing an app that lets a stranger control your screen. A request to pay a bill in gift cards is a near-certain sign of fraud.

WhatsOnTech’s rule of thumb: urgency alone can be innocent, since real companies do send urgent notices. Two or more signs together means stop, and the fourth deserves a pause on its own.

How to spot a scam in texts, emails and calls

The pattern stays the same. Only the disguise changes.

Text messages

Scam texts sound short and practical: a missed delivery, an unpaid toll, a strange card payment. Most want you to tap a link, which opens an official-looking page asking for card details or a small “redelivery fee.”

Emails

Email scams, often called phishing (fishing for your details), rely on look-alikes. The sender’s name might say your bank, while the address after the @ sign is a jumble or a near-miss spelling. Even a correct-looking address can be faked, so it is a clue, not proof. On a computer, hovering over a link without clicking usually shows where it really goes.

Be wary of unexpected attachments, especially one asking you to “enable” something before you can read it. And spelling mistakes are no longer a reliable giveaway: AI writing tools produce fluent text for scammers too.

Phone calls and pop-ups

Caller ID can be faked, so a scam call can show your bank’s real number. A real bank will not ask you to move money to a “safe account.” A pop-up saying your computer is infected, with a number to call, is fake: real Windows and macOS warnings never include one.

Another twist is AI voice cloning: software can copy a voice from a short clip posted online, so a panicked call from a relative needing money can sound just like them. Hang up and call back on the number you already have. Some families agree on a code word for emergencies.

The one habit that beats most scams

You do not need expert judgement, just one habit that WhatsOnTech puts ahead of every other tip:

  • Stop. Urgency is the scammer’s main tool, so take it away. A real problem can wait five minutes.
  • Use nothing the message gives you. Not the link, the phone number or the “reply YES” option. If the message is fake, each one leads back to the scammer.
  • Contact the organisation yourself. Open its official app, type its web address, or call the number on the back of your card. A real problem will show up there too.

The trade-off: it takes a couple of minutes, and sometimes you will check a message that was real. A genuine message loses nothing by being checked; a fake one loses everything.

Never share a one-time code

Those short codes sent by text or shown in an app prove it is really you logging in or approving a payment. Anyone who asks you to read one out is trying to become you, whatever reason they give. That includes a friend saying they sent you a code by mistake: their account may already be hijacked.

Banks and major services generally say they never ask for them. The WhatsOnTech take: type a code only into an app or website you opened yourself.

What to do if you already clicked or paid

Scams catch careful people too, so speed matters far more than embarrassment. If you only opened a link and typed nothing, the risk is usually small: close the page, leave any download unopened, and keep your devices updated. If you entered details, sent money or let someone onto your device, act now:

  1. Call your bank or card issuer immediately. Use the number on your card. The sooner they hear, the more they can do to freeze a card or stop a payment.
  2. Change any password you gave away. Do it on the real site or app, not the scam link, and anywhere else you reused it.
  3. Turn on two-factor authentication. This adds a second step to logging in, usually a code or app prompt, so a stolen password alone is not enough.
  4. Report it. Mark the email as phishing or junk, tell your mobile provider about scam texts, and contact the police or your country’s fraud reporting service.

If a stranger controlled your computer, remove any app they had you install and get it checked before logging in anywhere important. Then read your statements closely for a few weeks, a habit WhatsOnTech already suggests for anyone who pays by tap, because a scammer’s first charge can be small enough to miss.

The takeaway

Scams keep changing their story, but the script stays the same: hurry, trust me, keep it quiet, pay in an odd way. Knowing how to spot a scam comes down to seeing that script, answering it through a route you chose yourself, and guarding one-time codes like house keys. You do not need to fear every message; you need one calm habit that works on nearly all of them. Giving you habits like that, in plain English and without the panic, is exactly what WhatsOnTech is here for.