Fraudsters are mimicking NS&I emails to lure UK savers with fake prize claims and urgent requests, using convincing language and lookalike websites. Experts warn to verify communications through official channels and be alert to signs of fraud.
NS&I-themed scam emails are a familiar trick with a fresh coat of paint: they borrow the look and language of the UK government-backed savings provider to lure people into clicking, replying or handing over sensitive details. The messages can promise a Premium Bonds win, warn that access is at risk, or demand that an account update is completed at once, all while using the sort of wording savers expect to see. According to NS&I’s own security guidance, the danger is not the provider itself but criminals impersonating it.
The most effective lure is often a prize. Premium Bonds are a credible hook because holders know winnings are drawn regularly, so an email saying money is waiting can feel plausible for a moment. Fraudsters use that split second of uncertainty to push recipients on to a fake site that can collect login details, bank information or identity documents. NS&I says it will not send a direct login link by email, and it advises customers to check any claim through the official website or app instead.
Other versions of the scam rely on fear rather than excitement. A message may claim that a password has expired, a privacy notice must be accepted or suspicious activity has blocked an account. NS&I warns that similar text-message scams and phone-call scams are also common, with criminals urging people to act quickly or move money to a so-called safe account. The real aim is the same in each case: to create urgency so the target stops thinking and starts complying.
Once the victim clicks, the next step is usually a copied login or claim form on a lookalike website. NS&I says pharming can redirect users from genuine sites to fraudulent ones, sometimes after malware has already been installed. That means a padlock symbol or a polished design is not enough to prove the page is legitimate. A false form may begin with harmless details such as a surname or postcode before asking for passwords, card numbers, passport data or one-time codes that can complete a takeover.
The warning signs are straightforward once you know what to look for. NS&I says legitimate service emails use addresses ending in @nsandi.com, but it also stresses that the safest approach is not to trust an embedded link even when the sender appears familiar. An unexpected request for payment, a demand for a verification fee or pressure to stay on the line while codes are read out are all signs of fraud. A genuine Premium Bonds prize does not require an upfront charge.
Anyone who receives a suspicious message should avoid clicking, replying or calling the number inside it, and instead verify the issue through NS&I’s official channels. The provider says suspicious emails can be forwarded to phishing@nsandi.com, while UK users can also report them to report@phishing.gov.uk. If information has already been entered, the priority is to secure accounts, contact the bank, change exposed passwords and assume that any stolen details could be reused in a follow-up call or message.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





