Where I Actually Report a Scam, Depending on What Kind It Is

Sep 01, 2026By Jay Kells
Jay Kells

Where I Actually Report a Scam, Depending on What Kind It Is

For a long time my idea of "reporting a scam" was vague, a general sense that somewhere out there was a form I should probably fill in eventually. That vagueness is exactly why so many scams go unreported, the advice to "just report it" doesn't tell you where, and if the where isn't obvious, most people quietly close the tab and move on instead. Once I actually mapped out which channel handles which kind of scam, reporting stopped feeling like a chore and started taking me a couple of minutes, because I already know exactly where each type is supposed to go before I've even finished reading the message.

Forwarding a Suspicious Text to 7726

This is the one most people in the UK have never used even though it's sitting on their phone right now. Forwarding a spam or scam text message to 7726 sends it straight to your mobile network provider, who use it to identify and block the numbers and short codes behind mass scam campaigns. It costs nothing, takes about ten seconds, and I do it automatically for every fake delivery text or bogus "your account has been suspended" message before I delete it. I used to just delete these and move on, which felt like the responsible thing to do, until I realised deleting silently does nothing to stop the same message reaching everyone else in that campaign. Forwarding it first means my phone contributes to blocking the number, not just protecting me from it.

Reporting a Scam Email to the Right Inbox

Email scams get a bit more nuanced because where they go depends on what they're impersonating. A general phishing attempt, something pretending to be a bank, a delivery firm, or a well-known brand, is worth reporting to Action Fraud if I've actually engaged with it or lost anything, but for the ones I've simply received and spotted, forwarding the raw email to the National Cyber Security Centre's suspicious email service does more good, because it feeds directly into the takedown process for the fake site behind it. I've learned the difference matters, one channel is about investigating an incident that's already affected me, the other is about getting a malicious site pulled down before it catches someone else. Knowing which of the different kinds of cybercriminals is actually behind a message also shapes which route I take, a mass phishing email gets forwarded and deleted, but anything that looks like a targeted, researched attempt gets a proper Action Fraud report because there's a specific person or account behind it worth investigating.

Macro close-up of digital payment card highlighting security chip and holographic anti-fraud features

Calling My Bank's Fraud Team the Moment Money's Involved

The instant any money has actually moved, or I've entered card details somewhere I shouldn't have, reporting to a general body stops being the priority and my bank becomes the first call, not the third or fourth. Every UK bank has a fraud line, and the 159 short number now works as a fast, verified route to your own bank's fraud team without having to hunt for the right digits on a suspicious call or email first. Time matters enormously here, a transaction reported within minutes can sometimes be stopped or reversed, one reported a week later usually can't be. I've also made it a habit to never check my balance or move money over public wifi without a VPN running, NordVPN encrypts that connection regardless of how trustworthy the network looks, which matters most in exactly the moment I'm already dealing with a fraud scare and not thinking as carefully as I normally would.

Using the Platform's Own Report Button First

For fake listings, cloned social media profiles, and dodgy marketplace sellers, the platform itself is almost always faster than any external body, because it can act immediately by removing content or suspending an account in a way that Action Fraud simply can't. Every major platform, Meta, Google, Amazon, eBay, has its own reporting flow built directly into the listing or profile, and I use that first for anything that's clearly a platform-specific problem rather than a wider criminal operation. I still separately report it to Action Fraud if actual money or personal details were involved, but for a fake shop that's just sitting there scamming browsers, the platform's own removal process protects the next person faster than any other route I know of.

Why I Still Report the Ones That Feel Too Small to Matter

The message I most often see people skip reporting is the one that feels too minor to bother with, a slightly odd text, a voicemail that hung up when I answered, an email with just enough wrong about it to notice but nothing you'd call a real attempt. I report these anyway, because a single report rarely changes anything on its own, but the pattern across thousands of small reports is exactly what lets networks and platforms spot and block a campaign before it scales up. I've stopped asking myself whether something feels serious enough to be worth ten seconds of my time, and started asking whether it's actually a scam attempt at all, which is a much easier question to answer honestly. If you want the fuller reasoning behind treating every one of these as worth flagging, my free Safety Toolkit covers the wider habits I'd recommend building around it, and Take Five to Stop Fraud is a genuinely useful UK resource for understanding the bigger picture behind why reporting, even the small stuff, actually works.