Santander Email Scam: How to Spot a Fake Bank Email (UK)
Santander won't email you asking for your password, PIN, or card details—but scammers will.
What a fake Santander email looks like
A Santander email scam is a phishing message dressed as bank correspondence. Its job is to move you onto a copycat sign-in page, where whatever you type — Santander credentials, card numbers, a one-time passcode, or personal details — is collected by criminals. A typical example arrives from a display name such as "Santander Security", carries a subject like Your account has been temporarily locked, and ends in a large "Restore access" button.
The excuse varies: a locked account, a held payment, an unrecognised device, an overdue security check. The mechanism does not. This guide covers the warning signs, the safe way to check, and where to report the message in the UK.
Why these emails fool people
Phishing emails can copy Santander logos, colours, and wording. The visible sender name can be set to almost anything, and link text can say one thing while sending you somewhere else. A message can also be sent from a compromised account, so checking only one detail is not enough.
A genuine bank email should not require you to use an email link to reveal a password, share a passcode, or move money. Santander's official fraud page also gives direct reporting routes: suspicious emails can be sent to phishing@santander.co.uk, and suspicious texts referring to Santander can be forwarded to 7726 and emailed to smishing@santander.co.uk.
Signs a Santander email is phishing
- A generic greeting such as "Dear Customer", especially when paired with an urgent threat.
- A sender address that is not clearly Santander-owned, or a link that points to an unfamiliar domain. Even a plausible address is not enough on its own.
- A button or link telling you to "verify", "reactivate", "restore access", or "secure" your account.
- A request for your full password, PIN, card details, or one-time passcode.
- An unexpected attachment.
- A demand to move money to a new or "safe" account.
- Spelling, spacing, or design that feels off. This can help, but polished emails can still be scams.
How the email scam works
The chain has five links. It opens with an unexpected alert styled as Santander security. The alert supplies the pressure and the button. The button lands on a copycat sign-in page that harvests every keystroke. The fake page may ask for a genuine one-time passcode that Santander has just sent. The real message explains what the code would authorise. If the description does not match what you are doing, stop; giving the code to the fake page may let the criminal complete that separate action.
What follows is a payment approved, a card raided, or your details resold for the next attempt.
Break the chain at the button: check independently instead of clicking.
How to check if a Santander email is genuine
Leave the email alone — no clicks, no attachments — and go to Santander by a route you picked yourself:
- Open the Santander app and read your messages and recent activity there.
- Type
santander.co.ukinto the browser, or use a bookmark you saved earlier. - Ring the number printed on the back of your card.
- Use 159. Stop Scams UK lists Santander as a 159 participant.
Santander's fraud pages state that a genuine bank or organisation will never contact you out of the blue to ask for your PIN, password, or one-time passcode. Hovering over a link can reveal where it really points, but treat that as one signal rather than a verdict. If nothing independent confirms the message, contact Santander directly.
If you are unsure whether a linked website is a copycat, our guide on Is This Website a Scam? A Practical Checklist Before You Buy walks through the checks.
If you clicked or entered details
If you typed credentials, card numbers, or a passcode into that page, call Santander at once on the number on your card or through 159, and say plainly that you may have been phished so it is handled as an account compromise. Change the Santander password from inside the app or an address you typed, and everywhere else you reused it. Run a security scan if you opened an attachment.
Our scam recovery checklist covers the rest in sequence: cards, payments, passwords, identity details, and what to do once money has gone.
How to report a fake Santander email (UK)
Send the email to the NCSC at report@phishing.gov.uk and to Santander at phishing@santander.co.uk. Santander handles suspicious texts separately: forward those to 7726 and email them to smishing@santander.co.uk.
If you lost money, shared sensitive information, or were hacked, report it to Report Fraud at reportfraud.police.uk or on 0300 123 2040 if you are in England, Wales, or Northern Ireland. In Scotland, report to Police Scotland on 101.
Frequently asked questions
Does Santander send emails with links?
Some genuine Santander emails contain links, so a link alone is not proof. Never use an unexpected email link to enter banking or security details. Santander's app may tell you to expect an email-verification link during a process you initiated; only follow it when the app itself has confirmed the step on the same device. Otherwise open the app or type santander.co.uk yourself.
How can I tell who really sent a Santander email?
Often you cannot, from the message alone. Display names are trivial to forge and link text can hide its real destination, so treat sender inspection as a hint. The answer comes from the Santander app, a typed santander.co.uk, or the number on your card.
I clicked the link and entered my details - what now?
Ring Santander now on 159 or the number on your card and say you may have been phished. Then change the password from the app, have the card stopped if its details were shared, and work through our scam recovery checklist.
Can I get my money back after a Santander email scam?
Possibly. Report it to Santander immediately. APP reimbursement rules may cover eligible UK bank transfers over Faster Payments or CHAPS made on or after 7 October 2024, subject to the PSR rules, limits, and exclusions. Card payments have different protections, such as chargeback.
How do I report a fake Santander email?
Forward it to report@phishing.gov.uk and phishing@santander.co.uk. If it also came by text, forward the text to 7726 and email it to smishing@santander.co.uk.
Sources checked
- Santander — How to report fraud
- Santander — Our top security tips
- Santander — Fraud updates
- Santander — Trouble logging on to Online Banking
- NCSC — Report a scam email
- Stop Scams UK — Get help now (159)