In the last year the public forwarded 10.9 million suspicious emails to the NCSC's reporting service. Since it opened in 2020 it has passed 45 million reports, and the NCSC has taken down more than 412,000 malicious web addresses off the back of them.
Every one of those started the same way. A message that looked close enough to real.
Attackers rarely break in. They persuade you to open the door, using trust in a familiar name, worry about a problem, and pressure to act before you've thought it through. The useful part is that almost every scam pulls the same few levers, and once you can see them they're very hard to unsee.
What you get
The Anatomy of a Scam. A real phishing email pulled apart flag by flag, showing the five tells that turn up in nearly every scam message: the lookalike sender, the manufactured urgency, the generic greeting, the artificial deadline, and the disguised link.
The Decision Matrix. Four checks that let you judge any message in seconds, with one simple rule. If two or more fire, treat it as a scam.
Clarity Scripts. Exact wording for a three-question gut check, verifying a message independently, inspecting a link before you click, refusing a request for a code, and reporting what you've found.
Six self-tests. Run against your own inbox, not made-up examples. Including the one that protects you most: seeing where a link actually leads before you touch it.
What the guide covers
- The three buttons every scam pushes: urgency, authority, and fear or reward
- Link inspection on both computer and phone, so you can preview a destination before clicking
- The full scam spectrum, because phishing isn't only email. The same playbook arrives by text, by phone call, and in social media messages
- The golden rule, "don't click, navigate", which defeats most phishing outright
- What to do when you've already clicked, in a calm order rather than a panic
This is for you if
- You've hesitated over a message wondering whether it was real
- You've had a text or call claiming to be your bank or a delivery company
- You don't know how to check where a link goes before clicking it
- You'd rather train on real examples than read abstract theory
- You want a system, not another warning to "be careful online"
By the last page
You'll have a working radar for scams, the habit of checking links before you click, and a scripted response for when something looks off, instead of the panic the message was designed to cause.
Course details
- Format: downloadable PDF, 13 pages
- Time to complete: 50 to 65 minutes
- Series: Course 06 of 20, GhostNet Cyber Fundamentals
- Track: Track B, Threats and How to Spot Them (Course 1 of 5)
- Prerequisites: none, though Track A makes you a harder target to begin with
- Works on: any device, any operating system
- Level: complete beginner, no technical background needed
Buy with confidence
Every course comes with a 30-day money-back guarantee. If it isn't useful, email us within 30 days and we'll refund you in full. You don't need to give a reason.
Where to go next
Course 07, Malware, Viruses and Ransomware Explained, continues the series. Or take Threats and How to Spot Them, the five-course bundle covering Courses 06 to 10, for £100 instead of £150.