Common Scam Types
Learn to recognize the most common fraud schemes
Scams aren’t infinite. They look like they are — the brands change, the channels shift from email to text to phone, the AI polish improves — but underneath the dressing, the same handful of structural patterns repeat. This page is the taxonomy: the categories ScamSupport sorts the cluster of scam patterns into, the recognition signals that distinguish each category from the others, and the link from each category to the in-depth guide covering the brands and variations within it. The point of the taxonomy is not classification for its own sake. It is that recognising the type of scam in front of you matters more than recognising the specific brand being impersonated, because the type predicts what the criminal will ask for next.
If you have a specific message in front of you right now and want a verdict in seconds, paste it into the ScamSupport scanner — the 23 detection checks behind it produce a classification along these category lines automatically. If you want to read about the patterns themselves, the cards below link to the in-depth guides; each guide carries a “Last reviewed” date and a sources footer, and we re-date the affected guides when UK rules change (Action Fraud being replaced by Report Fraud in December 2025, the FSCS deposit limit rising to £120,000 in the same month, the PSR mandatory APP-fraud reimbursement scheme launching in October 2024).
Why a taxonomy at all
The scam landscape would be easier to navigate if every scam had a unique name, but it doesn’t — criminals iterate the same handful of underlying patterns across brand after brand, channel after channel. A “Royal Mail redelivery” text and an “Evri delivery fee” text are the same scam wearing different clothes; the structural pattern (urgent small payment to release a held item) is what makes the trick work, and the brand is interchangeable. A taxonomy organised around the underlying pattern rather than the brand on the surface gives you something more durable: once you have seen the “delivery-fee” pattern, every variant becomes recognisable the first time, regardless of which courier the scammer chose to wear.
The same applies across the categories below. An “account-suspended” email from Apple uses the same structural manipulation as one from Microsoft or your bank: it manufactures urgency around a credential, hopes you act before checking, and routes the action through a link the criminal controls. Recognising the category is half of the recognition work; the brand is decoration. Each card below names a category, lists the structural red flags that define it, and links to the in-depth guide for the brand-level patterns inside.
How These Categories Overlap
The categories above are descriptive rather than mutually exclusive. A single message often combines patterns from several at once: a "tax refund" lure (HMRC scam) delivered by SMS (smishing) impersonating a government brand (impersonation) and pointing to a fake login page (phishing) is one campaign, not four. The detection model treats the categories as overlapping signals rather than strict labels — what matters for the risk score is whether the message uses the techniques, not which heading we file it under.
If you've received something that doesn't fit any single category neatly, that's normal. Run it through the main ScamSupport tool, which scores the underlying patterns regardless of the cover story.
The Universal Tells
Across all 15 categories, four signals appear in roughly 90% of scam messages we see:
- Manufactured urgency. "Within 24 hours", "immediately", "final notice". Real organisations don't pressure you in their first contactemail — they have escalation procedures that take weeks.
- Sender / display-name mismatch. The friendly name says "PayPal" but the actual address is a Gmail account or a misspelt lookalike domain. Always check the right-hand side of the @ sign.
- Off-platform action requested. "Click here to verify", "follow this link to log in". Genuine companies tell you to log in through their app or by typing the URL yourself, never through an embedded link.
- A request that doesn't match the relationship. Your bank already has your address, your name, and your account number. If a "bank" email asks you to confirm them, the only thing it can be doing is collecting that data for the first time.
If a message clears all four of those, it's probably real. If it fails any one of them, treat it as suspect until you've verified through the company's normal channel.