The NHS COVID Vaccine Phishing Campaign
Millions of UK residents received fake NHS texts and emails offering early vaccine appointments.
Timeline: How It Unfolded
As the UK's COVID-19 vaccination programme ramps up, scammers begin sending millions of texts and emails claiming to be from the NHS.
Messages say: "You are eligible for the COVID vaccine. Apply now to book your appointment" with a link to a convincing fake NHS website.
Victims are asked to "verify their identity" by entering their name, date of birth, address, NHS number, and bank card details (to "confirm address for the booking system").
The NCSC reports eliminating 442 phishing campaigns using NHS branding. Over 12 million blocks are applied against COVID-19 phishing domains between January 2020 and July 2021.
Variants of the scam continue — fake "vaccine passport" sites, fake booster booking pages, and fake test result portals.
How the Scam Worked
- The scam exploited widespread public anxiety about getting vaccinated and the genuine confusion about how the NHS booking system worked.
- Fake websites were near-perfect copies of the real NHS website, using the correct logo, colours, and layout.
- The request for bank details was disguised as "address verification" — plausible enough during a time when many systems were being set up quickly.
- The scam used the same channels (SMS, email) that the real NHS was actually using to contact people, making it harder to distinguish.
Red Flags That Were Missed
What You Should Learn From This
Outcome
The NCSC's Active Cyber Defence programme removed 2.7 million scam campaigns in 2021 — nearly four times more than 2020 — including 442 NHS-branded phishing campaigns and 43 fake COVID apps. The campaign led to increased public awareness about health-related phishing and prompted the NHS to issue clear guidance that vaccinations are always free.