Ofcom’s New Scam-Text Rules Are Helpful — But They Do Not Replace Phishing Hygiene
Ofcom has finalised rules to make UK mobile providers block, limit and disrupt scam messages. Here’s what changes, what consumers should still do, and why a VPN is not a phishing cure.
Quick takeaways
- Ofcom says mobile providers must do more to block, limit and disrupt person-to-person and business-message scams.
- The new package includes scam-intelligence processes, number blocking, malicious-link detection, PAYG SIM volume limits and stronger checks on business messaging senders.
- Network filtering can reduce scam volume, but users should still report suspicious messages to 7726 and avoid entering details after tapping urgent links.
What happened?
Ofcom has finalised new rules and guidance requiring UK mobile providers to do more to block, limit and disrupt scam messages. The package targets both person-to-person scams, such as fake emergency messages from a “new number”, and business-message scams that impersonate delivery companies, government services or other trusted organisations.
Ofcom says providers will need to collect scam intelligence from customers and anti-fraud organisations, block numbers used by scammers, detect and block scam messages containing malicious links or phone numbers, and set volume limits for pay-as-you-go SIM cards. The rules also require stronger Know Your Customer and Know Your Traffic checks for business-message senders and aggregators.
The regulator says fraud accounted for an estimated 45% of reported crime incidents in England and Wales, with £1.28 billion lost to criminals in 2025. It also says 40% of UK mobile users reported receiving at least one suspicious mobile message in the previous three months.
Why this matters for VPN Rocks readers
Scam texts are one of the most common ways ordinary people are pushed into risky online decisions. They arrive on a trusted device, use familiar sender names, and create urgency around parcels, banks, parking fines, tax, account security or family emergencies.
Network-level blocking is useful because it can stop some scam messages before they reach you. But no filter catches everything, and criminals adapt quickly. The safest habit is still to treat unexpected links as untrusted, navigate to official websites yourself, and report suspicious messages so providers can improve their blocking data.
What you can do now
Forward suspicious texts to 7726. If you clicked a link but did not enter anything, close the page and navigate to the real organisation through your browser or app. If you entered card details, call your bank using the number on your card or in your banking app. If you entered a password, change it on the real service and anywhere else you reused it.
Use a password manager, enable multi-factor authentication, keep your phone and browser updated, and be especially cautious with messages that demand immediate payment or ask you to move the conversation to another channel. NCSC guidance remains a good starting point for spotting and reporting phishing.
Where a VPN helps — and where it does not
A VPN can help when you are on public Wi-Fi by encrypting traffic between your device and the VPN server and reducing what the local hotspot can observe. That is useful in airports, hotels, cafes and train stations.
A VPN does not verify a sender ID, prove that a payment link is genuine, block every malicious page, recover stolen money or stop you typing details into a fake form. For scam texts, VPN privacy is secondary to phishing hygiene: check the URL, avoid urgent links, use official apps, and report suspicious messages.
VPN Rocks view
Ofcom’s rules should make large-scale text scams harder, but users still need realistic defences. Treat a VPN as network privacy, not a scam detector. The best protection is layered: provider blocking, 7726 reports, cautious link handling, password managers, MFA and quick bank contact if money or card details are at risk.
Sources and further reading
VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.