“NHS: We’ve noticed you haven’t applied for your Covid pass, please follow the link to complete registration to avoid fees.”

Have you received a text message like this?

If you have, you may have realised it is a scam though many unsuspecting people have fallen for it. What makes it so convincing to the unwary is that the text links to a site that looks very much like the NHS website asking you to enter payment details:

Fairly convincing, isn’t it?

What is obviously needed from all of us is caution when opening links on emails and text messages, but also a refusal to enter card payment details which are giving scammers free licence to skim your money, with you having given them access to expiry date, card number and CVV. It may say £4.99 but we’re fairly certain, without testing it of course, that more than a fiver would disappear.

Trading Standards are fully aware

Katherine Hart, CTSI lead officer, said: “The public should apply for an NHS Covid Pass or vaccination certificates on the official platforms, which are different, depending on if they are resident in England, Scotland, Wales, or Northern Ireland.

“Whenever we receive these messages, we should not only avoid these scams, but also report them to Action Fraud, or if in Scotland, contact Police Scotland.

“By reporting scams, authorities can build a fuller picture of this dangerous fraud blighting communities throughout the United Kingdom.”

But how do you spot a texting scam? What are some signs to watch out for?

  1. Message from an unknown number
  2. Urgent requests for payments or details
  3. Fake website address
  4. Spelling errors and odd wording

And here’s more advice from David Lovell on not falling prey to text fraud.

The first thing I’d advise is not to follow any links, particularly if the text message falls into one of the 4 suspicious categories above. Links can also contain malware and these have been known to affect the Android operating system, which is more open than iOS.

Never disclose personal and financial information. Why would a bank or credit card company ask for your date of birth, credit card number, expiry date and CVV?

Do not reply. Often responses are tracked and if you reply or call the number, you’re potentially opening the doors for more attempts like this.

Report it. Not many people know that you can forward a suspicious text message to 7726. This is free, as it’s paid for by network operators, like EE, O2, Three etc.

If you’re pretty convinced the text message is genuine, contact the organisation directly via official channels using the details on a company website or documents etc.

Just on the Malware, there is a system circulating called “FluBot”, where a link leads you to download an app that spies on your data on your Android phone.

Official advice is to do the following, if you’ve clicked a suspicious link:

  • Don’t enter any passwords or log into any accounts.
  • Perform a factory reset on your device.
  • After resetting your device you may be prompted to restore from a backup, but do not restore any apps that you’ve accessed or downloaded since your device was compromised.
  • Once you’ve restored your device you should change your passwords on your accounts to ensure they are secure

We live in a world of digital communication, meaning we have access to information 24/7. As consumers and users of technology, we need to be vigilant, always, about Covid scams that play on our fears and skim funds from our accounts.