This Phishing, Scams and Online Fraud Awareness course is designed for people working in UK health and social care who may encounter suspicious emails, messages, telephone calls, websites or financial requests. It develops practical awareness of how criminals use deception, impersonation and pressure to target staff, organisations and people who use services.
This free course covers phishing emails, smishing and vishing, fake websites, business email compromise, payment fraud and common scams affecting service users. Learners will also explore safe verification methods, workplace reporting procedures, safeguarding considerations and the immediate steps to take after interacting with suspected phishing.
Why Take This eLearning Course?
Phishing and online fraud can affect organisational systems, finances, personal information and the people who rely on health and social care services. This course supports staff to recognise warning signs, question unexpected requests and take proportionate action without attempting to investigate incidents themselves.
This course will help you to:
- Recognise common forms of phishing, scams and digital fraud.
- Check suspicious emails, sender details, links and attachments more carefully.
- Identify pressure tactics involving urgency, fear, authority and secrecy.
- Respond safely to suspicious telephone calls, text messages and QR codes.
- Recognise misleading websites and potentially deceptive domain names.
- Verify unusual payment and supplier requests through trusted routes.
- Support service users who may be experiencing scams or financial exploitation.
- Understand when safeguarding advice or escalation may be appropriate.
- Report suspicious messages promptly through approved workplace procedures.
- Take appropriate action if you have clicked, disclosed information or opened suspicious content.
Learning Outcomes
By the end of this course, you will be able to:
- Define phishing, scams and digital fraud and distinguish between them.
- Explain how phishing can target workplaces and affect health and care organisations.
- Identify common warning signs in emails, messages, telephone calls and online requests.
- Assess sender addresses, links, QR codes, attachments, URLs and websites for suspicious features.
- Describe safe methods for independently verifying unexpected contact.
- Recognise business email compromise, supplier fraud and payment-diversion techniques.
- Identify signs that a service user may be experiencing scam-related pressure or financial exploitation.
- Explain the staff role, professional boundaries and reporting responsibilities when concerns arise.
- Outline appropriate internal and UK external reporting routes for suspicious activity.
- Describe the immediate actions to take after interacting with suspected phishing.
Phishing, Scams and Online Fraud Awareness Course Outline
The course is organised into eight modules, progressing from the fundamentals of phishing and digital fraud through practical recognition, verification, service-user support, reporting and incident response.
Module 1: Understanding Phishing, Scams and Digital Fraud
Learners will explore the meaning of phishing, scams and digital fraud and understand how these forms of deception are connected. The module examines why workplaces, including health and social care organisations, can be attractive targets because of their access to information, accounts, financial systems and operational services. Learners will also consider the possible consequences of a successful attack, including financial loss, compromised personal information, disruption to services and wider cyber incidents.
Module 2: Recognising Suspicious Emails and Phishing Tactics
Learners will develop practical techniques for assessing unexpected emails and digital messages. This includes checking display names, full sender addresses, lookalike domains and external accounts, as well as recognising psychological pressure based on urgency, fear, authority and secrecy. The module also covers suspicious links, misleading link text, QR codes and attachments, together with realistic workplace phishing patterns involving password resets, shared documents and urgent payment requests.
Module 3: Smishing, Vishing and Safe Verification
Learners will examine phishing delivered through SMS, messaging services, telephone calls and voice messages. They will learn to identify warning signs such as unexpected contact, requests for confidential information, unusual payment methods and attempts to discourage independent checking. The module explains how to end suspicious contact and verify the claimed organisation through trusted details, as well as why passwords, one-time security codes and unexpected sign-in approval requests must be protected.
Module 4: Fake Websites, Misleading URLs and Trusted Online Access
Learners will explore how fake and cloned websites imitate legitimate online services using familiar designs, sign-in pages and other visual features. The module explains how domain changes and misleading subdomains can make fraudulent sites appear convincing and why HTTPS or a padlock does not prove that a website is genuine. Learners will also consider how approved applications, verified bookmarks and independently located official pages can reduce the risk of following a deceptive link.
Module 5: Business Email Compromise and Payment Fraud
Learners will examine business email compromise and the ways criminals may impersonate or take control of genuine workplace accounts. The module covers fake supplier invoices, payment-detail changes and impersonation of managers, finance colleagues, suppliers and professional partners. Learners will understand why unusual financial instructions should be paused, independently verified and compared with existing records, and why established purchasing, payment and approval controls should never be bypassed because a request appears urgent.
Module 6: Protecting Service Users from Scams and Financial Exploitation
Learners will consider common telephone and online scams that may affect people who use services, including bank impersonation, fake public-service messages, technology-support scams, delivery fraud, shopping scams and contact impersonation. The module explores possible indicators of financial exploitation, including unusual payments, repeated unwanted contact and visible pressure. Learners will also examine how to respond supportively and respectfully, maintain professional boundaries and recognise circumstances in which safeguarding or management advice should be sought.
Module 7: Reporting Suspicious Messages and Concerns
Learners will understand why suspicious content should not be clicked, scanned, opened, replied to or investigated independently. The module covers workplace reporting processes, preserving relevant information and providing factual details for authorised teams. It also introduces appropriate UK external reporting routes, including services for suspicious emails, scam texts and fraud or cyber crime, while emphasising that organisational procedures and confidentiality requirements take priority where workplace information is involved. Learners will also understand how prompt reporting can help protect colleagues, service users and organisational systems.
Module 8: Responding After a Suspected Phishing Interaction
Learners will explore the immediate actions required after clicking a suspicious link, visiting a QR destination, opening an attachment, entering credentials or installing unexpected software. The module explains when passwords should be changed, why approved recovery processes should be used and what information should be provided when reporting an incident. Learners will also understand why rapid, accurate and no-blame reporting helps specialist teams contain incidents, assess possible data exposure and coordinate any wider organisational response.
Target Audience
This course is suitable for:
- Health and social care staff using workplace email, messaging or online systems.
- Care workers, support workers and other frontline employees.
- Administrative, finance and office-based staff within care organisations.
- Managers, supervisors and team leaders.
- Staff who support people who may experience scams or financial exploitation.
- New starters and existing employees requiring awareness of phishing and online fraud.
No previous specialist knowledge is required.
FAQ
Who is this course suitable for?
The course is suitable for people working across health and social care who use digital systems, communicate by email or telephone, handle organisational information or support people who may be affected by scams. It is relevant to frontline, administrative, finance and management roles.
Do I need any previous experience?
No. The course introduces the subject from an awareness level and does not require previous cybersecurity or fraud-prevention knowledge.
What will I learn on this phishing and online fraud course?
You will learn how to recognise phishing emails, suspicious links, QR codes, scam calls, deceptive text messages, fake websites, business email compromise and payment fraud. You will also learn how to verify unexpected requests, report concerns and respond appropriately after a suspected phishing interaction.
Will this course help with day-to-day practice?
Yes. The course focuses on situations staff may encounter during ordinary work, such as unexpected password requests, supplier emails, urgent messages from apparent managers, suspicious telephone calls and concerns raised by people who use services.
Does the course cover practical skills?
The course develops practical recognition and decision-making skills, including checking sender details and website addresses, identifying pressure tactics, verifying requests independently and knowing what action to take if suspicious content has already been opened or used.
Does it cover relevant responsibilities or good practice?
Yes. The course explains the importance of following organisational security, payment, reporting and incident procedures. Where fraud may overlap with financial abuse, coercion or exploitation, it also covers the staff role, professional boundaries and the need to follow safeguarding or management procedures where appropriate.
What should I do if I accidentally click a phishing link?
The course explains why further interaction should stop and why the incident should be reported promptly through the organisation’s approved route. Staff should provide factual information about what happened and follow instructions from authorised IT, security or management staff rather than attempting their own investigation.
Does the course explain how to protect service users from scams?
Yes. It covers several common scam patterns, possible signs of pressure or financial exploitation and how staff can respond respectfully while supporting the person’s rights, wishes and communication needs. It also explains when concerns may need to be passed through safeguarding or management procedures.
How long does the course take?
The course is self-paced and usually takes around 1 hour to complete.
Will I receive a certificate?
Yes. A certificate is issued after successful completion.
Phishing, scams and online fraud can begin with a single unexpected message, telephone call or online request. This course gives health and social care staff a clear framework for recognising suspicious contact, verifying information through trusted routes, supporting service users appropriately and reporting concerns so that authorised teams can respond.
Enrol now to build your understanding of phishing, scams and online fraud awareness.

