Care providers are being urged to stay vigilant following an increase in phishing and scam emails targeting organisations across the care sector.

Recent reports suggest that some fraudulent messages are making their way into inboxes despite existing security measures, often appearing to come from trusted organisations and including attachments or references to grant funding. Opening these emails or attachments can put systems and sensitive information at risk.

The following guidance explains how to spot suspicious emails and what to do if you receive one.

How can you protect your email and other sensitive accounts?

What should you do if your email account is hacked?

The National Cyber Security Centre (NCSC) has a detailed guide on recovering your compromised accounts which can be found here – Recovering a hacked account | National Cyber Security Centre

If you have access to IT or cyber security support, alert them as quickly as possible. The NCSC also provides guidance on recovering compromised accounts.

  1. Contact your account provider. Use the provider’s official website and follow its help or support guidance for recovering the account.
  2. Check your email account. Check email filters and forwarding rules for anything you do not recognise. An attacker may create rules that send them copies of messages.
  3. Change your passwords. Change the password for the compromised account and for any other accounts that use the same or a similar password.
  4. Log all devices and apps out of the account. Once the password has been changed, sign out other devices and active sessions where the service allows you to do so.
  5. Set up MFA/2FA. If it is not already enabled, turn on multi-factor or two-step verification.
  6. Update your devices. Install available operating system, application and security updates.
  7. Notify your contacts. Tell people who may have received messages from the compromised account and advise them to treat recent messages, links and attachments with caution.
  8. Check bank statements and online shopping accounts. Look for unusual transactions or purchases. Contact your bank directly if you have concerns.
  9. Contact Report Fraud. If money has been lost, tell your bank and report the incident to Report Fraud.

Want more bespoke support and guidance?

RCPA offers free support to Somerset care providers around data and cyber security.

  • Data Security and Protection Toolkit (DSPT). This free toolkit is designed for health and social care and supports organisations to understand the data security arrangements they should have in place and how to complete the assessment.
  • Data Security Health Check. These free health checks provide an overview of your organisation’s approach to data and cyber security, helping identify areas for improvement. The process also includes a cyber technical assessment reviewing basic cyber security arrangements.
  • Caldicott Guardian Service. This RCPA member service provides additional support with data governance for providers that are unable to appoint a Caldicott Guardian in-house. RCPA’s Dan Plummer can act as your Caldicott Guardian and support complex data-sharing issues.

For advice about email and account security or RCPA’s data and cyber security services, please contact Dan Plummer: daniel.plummer@rcpa.org.uk

Further guidance: National Cyber Security Centre (NCSC) – Recovering hacked accounts. See the accompanying NCSC infographic.

About this article

September 7, 2026

Michael Wallis

Adults

Social Care