The 7 dominant UK vishing patterns

1. Bank fraud team

"This is [bank]'s fraud team. We've detected suspicious activity on your account. To verify your identity, please read out the code I'm about to send you." The code is a real OTP requested by the criminal to log into your account; reading it out gives them access.

Real banks never ask you to read out OTP codes. They send the code so YOU can use it to confirm an action you're taking — not for someone else to use against you.

2. "Safe account" pattern

"Your account has been compromised. We need to move your money to a safe account while we investigate." The "safe account" is the criminal's. UK Finance: this is the single largest single-pattern source of APP fraud losses.

No UK bank operates a "safe account" facility. Anyone using this phrase is a criminal.

3. HMRC tax debt

"You owe £2,340 in unpaid tax. An arrest warrant has been issued. To avoid arrest, pay immediately via [bank transfer / gift cards / cryptocurrency]." The payment goes to the criminal.

HMRC never threatens immediate arrest by phone and never accepts payment by gift cards. Real HMRC tax debt is communicated by letter; payment plans are negotiable; arrest is judicial process, not phone-call threat.

4. Police fraud investigation

"This is DS [name] from [city] police. We're investigating fraud from your account. We need you to help us by withdrawing money and depositing it at a designated bitcoin ATM as part of our undercover operation."

UK police never ask members of the public to participate in undercover money operations, especially involving cryptocurrency. Real police investigation doesn't work this way.

5. Courier / Royal Mail "depot fee"

"Your parcel is held at our depot. Pay £1.99 release fee by card." Captures card details + 3D Secure codes for later abuse. Often paired with SMS variant.

Royal Mail, Evri, DPD, Yodel never call customers to demand small release fees by phone. Real undelivered parcels follow standard re-delivery / collection processes via the company app.

6. Tech support (Microsoft / Apple / "your ISP")

"Your computer has a virus we've detected on our network. We need remote access via [TeamViewer / AnyDesk / Quick Assist] to fix it. Please install [tool] now." Once installed, criminal has full access to your computer — banks, files, passwords, everything.

Microsoft, Apple, your ISP never cold-call about computer viruses. Genuine tech-support contacts happen through company-initiated channels (in-app, support tickets you opened).

7. Investment cold-call

"This is [broker name]. We have an exclusive limited-time opportunity in [crypto / shares / commodities]. Returns of 25% in 6 months guaranteed."

Authorised UK investment firms don't cold-call retail customers with high-return products. The FCA's Cold-Calling Ban on investment products has been in force since 2018. Any unsolicited investment pitch by phone is unauthorised at minimum, scam at most.

Why caller-ID is unreliable

Caller-ID is set by the calling system at the originating end. Criminals using VoIP services can display any number — including:

  • Your bank's real fraud-line number
  • HMRC's real number
  • Your local police station's number
  • A UK +44 number when the call originates from offshore

UK Ofcom rolled out "Do Not Originate" (DNO) lists in 2023 that block spoofed numbers for major institutions (HMRC, banks, etc.). This has reduced some spoofing but offshore calls and inbound international routes can still spoof. Treat caller-ID as informational only, not proof of identity.

The 3-step callback discipline (in detail)

Step 1 — Tell the caller you'll call back

Say: "I'd like to call you back from a number I can verify."

Don't justify it. Don't apologise. Don't engage with the caller's resistance. If the call is real, the caller will say "of course, please call 0800 XXX" — and they're patient. If the call is a scam, the caller will pressure ("there's no time", "the fraud is happening now", "I'll wait on the line"). Resistance is itself confirmation of scam.

Step 2 — Hang up. Wait 5 minutes.

Why wait? Some criminals hold the line open after you hang up. If you immediately dial 0800 XXX, you may still be connected to them (they play a fake dial tone). Five minutes ensures the line is genuinely cleared.

Step 3 — Call back on a verified number

  • Bank: number on back of card, OR dial 159 (cross-bank UK fraud verification line, free, participating: Bank of Scotland / Barclays / Co-op / Halifax / HSBC / Lloyds / Metro / Monzo / Nationwide / NatWest / RBS / Santander / Starling / TSB / Tide / Virgin)
  • HMRC: 0300 200 3300 (verified at gov.uk)
  • Police (non-emergency): 101
  • Courier: the company's customer-service number from their official website
  • Tech support: NEVER call back tech-support cold-calls — they're 100% scam
  • Investment firm: verify the firm at register.fca.org.uk first; use the FCA-register-published phone number

If you've already given information or money

If you gave OTP codes or password

  1. Call your bank fraud line immediately on the number on the back of your card.
  2. Change the password via the real banking app/website.
  3. Bank will likely freeze the account temporarily as a precaution.

If you transferred money

  1. Bank fraud line — within 60 minutes is critical for recovery.
  2. PSR Mandatory Reimbursement Scheme covers UK bank-transfer fraud — qualifying claims refunded within 5 working days.
  3. Start PSR claim.

If you gave remote access to your computer

  1. Disconnect computer from internet immediately.
  2. Remove the remote-access software (TeamViewer, AnyDesk, Quick Assist, Supremo, etc.).
  3. Run full antivirus scan — Malwarebytes, Microsoft Defender.
  4. Change every password that was visible during the criminal's session.
  5. If banking apps were open: call bank fraud line.
  6. Consider full OS reinstall if you're uncertain what was accessed.

If you gave ID details (NI, passport, driving licence)

  1. Add CIFAS Protective Registration. £25 / 2 years.
  2. Notify HMRC at 0300 200 3300 (NI compromise) / DVLA at 0300 790 6802 (driving licence).
  3. Quarterly credit-report checks for 24 months. See post-scam health check.

Universal steps

  1. File Report Fraud report at reportfraud.police.uk.
  2. Watch for follow-up recovery scams — vishing victims are heavily targeted. Recovery scam warning.

Frequently asked questions

What is vishing?

Vishing — voice phishing — is a phone-call scam where criminals pose as a trusted person or organisation (your bank's fraud team, HMRC, police, a courier, a tech-support agent) to trick you into transferring money, revealing credentials, or installing remote-access software. UK Finance reports vishing accounted for £176 million in UK consumer losses in 2024. The 2024-2026 escalation: AI voice cloning + caller-ID spoofing make the calls increasingly convincing, defeating perception-based detection.

What are the dominant UK vishing patterns?

Seven dominant. (1) Bank fraud — 'this is your bank's fraud team, we've detected suspicious activity, please verify by reading your OTP code'. (2) Safe account — 'we need to move your money to a safe account while we investigate'. (3) HMRC tax debt — 'unpaid tax, arrest warrant pending, pay immediately via gift cards or transfer'. (4) Police fraud team — 'we're investigating fraud from your account; you need to help us'. (5) Courier / Royal Mail — 'parcel held at depot, pay £1.99 release fee'. (6) Tech support — 'your computer has a virus, we need remote access to fix'. (7) Investment cold-call — 'limited-time opportunity, exclusive to you'.

How does caller-ID spoofing work?

Caller-ID is determined by the calling system at the originating end, not the receiving end. Criminals using VoIP can set the displayed number to anything they want — including your bank's real fraud-line number, HMRC's real number, your local police station's number. The displayed number is not proof of identity. UK Ofcom has tightened number-spoofing rules and rolled out 'do not originate' lists that block spoofed numbers for major institutions, but enforcement is partial and offshore calls still spoof regularly.

What's the 3-step callback discipline?

For any urgent phone call asking for money, credentials, OTP codes, or remote access: (1) Tell the caller you'll call back. Hang up. (2) Wait 5 minutes — criminals sometimes hold the line open to intercept your callback. (3) Call the institution back on a known number: bank's number on back of card, HMRC at gov.uk, police at 101, dialled 159 for banks. If the original call was genuine, the institution will confirm. If fake, you've defeated the scam. Real institutions EXPECT you to do this; they have no problem with the friction. Resistance to callback is itself the strongest scam signal.

What if the caller threatens arrest or court action?

Threats to arrest, freeze accounts, or take court action are core scam-pressure tactics. Real HMRC, police, courts never make pay-immediately-or-be-arrested phone calls. Real bank fraud teams don't threaten you; they're trying to help. Real courts don't ask for payment via phone. If the caller threatens: it's a scam, full stop. Hang up. The threat itself is the proof. Don't engage to 'sort it out'; don't transfer money to 'avoid arrest'; just end the call.

I gave information / money on a vishing call — what now?

Act in this order. (1) Call your bank fraud line on the number on the back of your card. UK bank transfers covered by PSR Mandatory Reimbursement. (2) Change any password disclosed on the call. (3) If remote access was given (TeamViewer, AnyDesk, etc.): immediately disconnect your computer from internet; remove the software; run antivirus full scan; treat all credentials entered while criminal had access as compromised. (4) File Report Fraud report at reportfraud.police.uk. (5) Start PSR claim with our wizard. (6) Add CIFAS Protective Registration if ID details were shared. (7) Watch for follow-up recovery scams targeting known-victim status.

Related scam guides

Just had a call like this? Use our free Cold-Call Checker to find out in a minute whether it was legal under the 2026 UK rules, who to report it to (ICO, Ofcom or Action Fraud), and get a ready-to-send complaint — or browse the “who called me?” number guide.