NatWest customers have been warned over scam emails containing malicious links. Those who click run the risk of giving up personal and financial data.

10:47, Tue, Dec 23, 2025 Updated: 10:49, Tue, Dec 23, 2025

Branch of NatWest Bank in Bromley High Street

NatWest customers have been warned about scam emails going around (Image: Getty)

NatWest customers have been warned over malicious emails that put them at risk of giving up personal and financial data. Biometric logins have become commonplace for online banking, allowing customers to log in quickly and simply using facial recognition or fingerprints. But it is never a requirement, despite what scammers are saying in emails sent to NatWest customers. 

The bank has warned against these scam emails that have been sent to Brits in December. Screenshots of these emails show scammers urging customers to click a link to set up a biometric login, claiming that the Financial Conduct Authority (FCA) is making it a legal requirement. However, this is false. The FCA will not make biometric logins mandatory. Customers have been urged to report these emails, as clicking on the link runs the risk of giving up their data. 

The day's biggest headlines in UK and World news Invalid email

We use your sign-up to provide content in ways you've consented to and to improve our understanding of you. This may include adverts from us and 3rd parties based on our understanding. You can unsubscribe at any time. Read our Privacy Policy

FCA requires banks to implement Strong Customer Authentication (SCA), which includes things like verification codes sent to your mobile number. But biometric data is not part of this extra security.

Scam emails can be reported by forwarding them to report@phishing.gov.uk. Meanwhile, scam websites can be reported on the National Cyber Security Centre's website. 

NatWest urges customers to never share personal data over email. The bank does offer a biometric login option on its app, which customers can set up using a smartphone or tablet with a front-facing camera. 

The scam email reads: "Beginning 22 December 2025, biometric login will become mandatory to access your account, in line with the Financial Conduct Authority (FCA) guidelines. This enhanced authentication method represents our new, secure approach to protecting your account."

The NCSC describes these kinds of emails as phishing emails. They are disguised e-mails to people or organisations purporting to be from reputable sources to "influence the reader to click on links to dodgy websites or to give sensitive information away, such as bank details, account passwords or credit card information".

Those who receive these emails should check the display name against the email address, beware of impersonal greetings such as "hello friend", be suspicious of emails that ask for bank details, and never click links if you are at all in doubt.