NCSC warns of phishing wave exploiting global IT outage disruption
Impersonating: IT vendors / Microsoft (impersonation)
What is this scam?
The National Cyber Security Centre issued an urgent warning on 19 July 2026 following a major global IT outage, alerting businesses and the public to a significant spike in phishing emails and texts opportunistically impersonating IT vendors and software providers. Attackers are sending messages falsely claiming to offer emergency patches, recovery tools, or support for affected systems — links in these messages lead to malware downloads or credential harvesting pages. The NCSC advises applying only vendor-sanctioned mitigations through official channels and treating any unsolicited offer of technical help or a patch link as potentially fraudulent.
Example scam message
Red flags to look out for
- The message creates urgency — threatening a fine, missed delivery, or account closure.
- Links lead to unofficial domains that don't match the real company's website.
- You weren't expecting this message and can't verify the event it references.
- It asks you to confirm payment details or personal information via a link.
- The sender's number or email address doesn't match the company's official contact.
What to do if you receive this
- Do not call any numbers or click any links in the message.
- Log in to your account directly via the official website or app to check for any real alerts.
- Forward the message to 7726 or email report@phishing.gov.uk.
- Report it to Action Fraud at actionfraud.police.uk.
Not sure if your message is a scam?
Check it instantly with our free AI-powered detector.
Check a message nowSource: NCSC