{"id":425148,"date":"2026-10-08T08:37:09","date_gmt":"2026-10-08T08:37:09","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=425148"},"modified":"2026-10-08T08:37:09","modified_gmt":"2026-10-08T08:37:09","slug":"nhs-covid-pass-scam-vaccine-passport","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/nhs-covid-pass-scam-vaccine-passport\/","title":{"rendered":"NHS COVID Pass Scam: Fake Vaccine Passport Emails Asking for Card Details"},"content":{"rendered":"<p>The email offers a digital coronavirus passport and a convenient application button. For someone planning a trip, it once looked like paperwork worth getting out of the way.<\/p><div id=\"mwtad3948526481\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The NHS COVID Pass scam used that familiar concern as its opening. The important question is what the supposed application asks you to hand over next.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-425149\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-1.png\" alt=\"Illustrative fictional historical NHS passport email inviting the reader to a sample digital-coronavirus-passport application\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-1.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-1-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-1-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure>\n<div id=\"mwtad564518803\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The documented email impersonated a free public service<\/h3>\n<p>In 2021, fraudulent messages offered a digital coronavirus passport while pretending to represent the NHS. Their links led to imitation application pages seeking personal and payment details.<\/p><div id=\"mwtad1010580408\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The <a href=\"https:\/\/www.nth.nhs.uk\/news\/vaccine-passport-scam-alert\/\" target=\"_blank\" rel=\"noopener\">North Tees and Hartlepool NHS Foundation Trust&#8217;s July 2021 alert<\/a> documented that approach and explained that payment details were not required to obtain the genuine pass.<\/p>\n<p>The scam was the impersonation and false fee, not the NHS itself. A convincing health-service page did not make the payment request legitimate.<\/p>\n<p>The historical case should not be presented as a newly intercepted 2026 email or a current vaccination requirement. Its date matters to understanding the offer.<\/p><div id=\"mwtad2437189902\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>We have not captured a live malicious site or established that every later message uses the same operator. The article explains the documented mechanism.<\/p>\n<h3>England&#8217;s COVID Pass service has since closed<\/h3>\n<p>The live <a href=\"https:\/\/www.gov.uk\/guidance\/nhs-covid-pass\" target=\"_blank\" rel=\"noopener\">GOV.UK COVID Pass guidance<\/a> says the service closed on December 4, 2023. That page expressly applies to England.<\/p>\n<p>Do not follow an old article&#8217;s application instructions as if the former service still operates unchanged. A 2021 helpline or eligibility statement is not current guidance.<\/p><div id=\"mwtad1691102888\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That closure does not settle every country&#8217;s travel rules or every U.K. nation&#8217;s health-record arrangements. Check current official information for your actual question.<\/p>\n<p>This is a phishing investigation, not advice about vaccine eligibility, doses, testing, clinical decisions, or a particular destination&#8217;s entry requirements.<\/p>\n<h3>The fee request is the part you can reject<\/h3>\n<div id=\"mwtad3059250410\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>An unsolicited passport offer does not justify disclosing a card, banking login, or security code. Verify the claimed service independently before sharing anything.<\/p>\n<ul>\n<li>The message offers a passport or certificate through its own link.<\/li>\n<li>The page requests an administrative or processing payment.<\/li>\n<li>Familiar NHS wording is used to support an unfamiliar destination.<\/li>\n<li>A deadline discourages checking the real service.<\/li>\n<li>A later contact says more information is needed to complete the application.<\/li>\n<\/ul>\n<p>The images are fictional interfaces dated to the historical context. They contain no real certificate, patient record, valid QR code, or authentic payment instructions.<\/p>\n<div id=\"mwtad1942575794\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the Passport Offer Once Felt Timely<\/h2>\n<h3>The message arrived during changing travel arrangements<\/h3>\n<p>In the historical period, people were trying to understand how vaccination records, travel plans, and venue requirements fitted together. A simple application link could look helpful.<\/p>\n<p>That context supplied credibility before the sender established identity. The reader might focus on completing a document rather than checking the person offering it.<\/p>\n<p>Do not import those old requirements into the present. A dated government announcement can explain the scam&#8217;s background without becoming current travel advice.<\/p>\n<p>If you need information now, start with the relevant official health or destination guidance. An unsolicited message should not define what document you supposedly require.<\/p>\n<h3>An official-looking form makes a false fee seem routine<\/h3>\n<p>A neat header and familiar health-service terminology can make personal questions feel like ordinary administration. The page then introduces payment as another field to complete.<\/p>\n<p>The label administrative fee can sound modest and unavoidable. It does not explain why an unverified page is entitled to receive your money or card details.<\/p>\n<p>A small charge would not make the request harmless. The information entered to pay it can expose more than the amount displayed.<\/p>\n<p>Equally, not every health-related payment is fraudulent. The documented warning concerns a false fee for this pass, not every service associated with the NHS.<\/p>\n<div id=\"mwtad4234678754\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the NHS COVID Pass Scam Works<\/h2>\n<h3>Step 1: A message invites the reader to obtain a passport<\/h3>\n<p>The email or text presents the document as available or necessary. An application button turns a broad concern into a clear task.<\/p>\n<p>The sender may display NHS wording without proving any connection to the health service. A copied name or signature block is not authentication.<\/p>\n<p>Receiving the message does not establish that your health records were accessed. The investigation provides no evidence of an agency breach behind the historical contact.<\/p>\n<p>If a message reaches you today, compare it with the current service and your own situation. Do not assume an old program has returned because an email says so.<\/p>\n<p>Keep the subject and date for reporting. There is no need to start an application just to determine what the message claims.<\/p>\n<h3>Step 2: The link supplies an imitation official application<\/h3>\n<p>The destination can look like a health-service page while being controlled by someone else. The historical NHS alert described convincing fake sites, not official applications.<\/p>\n<p>Government or NHS terms inside an address do not prove ownership. The actual host and the independently verified route matter more than the page&#8217;s heading.<\/p>\n<p>Start with the official website or app you locate yourself. Do not let the message supply both the service and the evidence that it is authentic.<\/p>\n<p>A closed or changed historical scam site would not make the original email genuine. It only changes what is available at that old address now.<\/p>\n<p>Do not try archived malicious links to compare them with an illustration. Reporting can rely on the message and information safely available to you.<\/p>\n<h3>Step 3: Personal questions prepare the reader for payment<\/h3>\n<p>The fake application may request a name, date of birth, or other identifying information before the payment screen. That sequence can make the fee feel part of an established process.<\/p>\n<p>Some identifying questions are legitimate in verified health-service interactions. Their presence does not authenticate this particular application or an unrelated payment request.<\/p>\n<p>Ask which service you are actually using and how you reached it. An ordinary field becomes risky when its recipient has not been established.<\/p>\n<p>The fictional form below shows this combination of personal and card information. It is not an actual NHS login screen or a patient record.<\/p>\n<p>No real information should be entered to test such a page. A submission can expose details even when the promised certificate never appears.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-425150\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-2.png\" alt=\"Illustrative fictional digital-passport application combining identity fields with an administrative-payment card form\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-2.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-2-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/nhs-covid-pass-scam-vaccine-passport-image-2-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure>\n<h3>Step 4: An administrative charge replaces the free pass<\/h3>\n<p>The historical warning identified a payment demand for a service that was free. The supposed administration did not turn the impostor into an authorized provider.<\/p>\n<p>A card form can collect account information whether or not a visible charge occurs. Keep information exposure separate from any completed transaction.<\/p>\n<p>If a banking prompt appears, read its actual purpose. A payment or login approval is not made safe by the website calling it passport verification.<\/p>\n<p>The image deliberately quotes no fee. It should not create a false fixed amount, currency conversion, or current application price for readers.<\/p>\n<p>A request to pay for reactivating the former English COVID Pass service should not be accepted through an unsolicited route. Check the present official information instead.<\/p>\n<h3>Step 5: The promised document can become a reason for further contact<\/h3>\n<p>The recipient may receive an application confirmation, an error, or a request for another step. None of those screens verifies that the NHS received the details.<\/p>\n<p>A contact can use information already supplied to sound more credible. Knowing your name or application attempt does not establish an official support relationship.<\/p>\n<p>Do not upload identification or grant remote access to resolve the supposed processing problem. Stop using the sender&#8217;s route for advice.<\/p>\n<p>Work through your bank, account provider, and appropriate reporting channels if exposure occurred. A fake passport agent is not a safe recovery adviser.<\/p>\n<div id=\"mwtad1518124827\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Historical Advice Must Not Become Today&#8217;s Instructions<\/h2>\n<h3>The old pass and current health records are different questions<\/h3>\n<p>The COVID Pass had a particular purpose during the pandemic period. A present request for vaccination records should be checked through the appropriate current health service.<\/p>\n<p>This article does not promise that a particular app, letter, or certificate is available to everyone. Processes can depend on the country, service, and individual record.<\/p>\n<p>Do not send clinical or identity information to an email claiming it can restart an old passport application. Confirm the genuine request through a channel you select independently.<\/p>\n<p>If you have a real healthcare enquiry, pursue it normally. Rejecting the phishing offer does not require ignoring legitimate messages about that separate matter.<\/p>\n<h3>Country and jurisdiction limits matter<\/h3>\n<p>The cited closure notice applies to England. It should not be used to declare every Scottish, Welsh, Northern Irish, or overseas vaccination document invalid.<\/p>\n<p>For travel, check the official requirements of the places you plan to visit or pass through. A random health-service email should not be your source.<\/p>\n<p>Do not buy an unverified certificate to resolve uncertainty. Payment would not establish that a document is genuine, accepted, or connected to your medical record.<\/p>\n<p>Health and entry questions need current official answers. The scam investigation identifies an unsafe route; it does not make those decisions for you.<\/p>\n<h3>The NHS name is not a universal payment verdict<\/h3>\n<p>The historical pass was free. That fact does not mean every product, appointment, document service, or transaction associated with healthcare is free in every circumstance.<\/p>\n<p>Evaluate the particular service and recipient. A legitimate account check should not be confused with an unverified card collection page just because both mention personal details.<\/p>\n<p>The safe boundary is independent verification before a sensitive disclosure. You can take a genuine health-service request seriously while refusing the unsolicited passport link.<\/p>\n<h2>What Your Information-Exposure Record Should Include<\/h2>\n<h3>Separate viewing, submitting, and approving<\/h3>\n<p>Record whether you merely saw the email, opened a link, filled a form, shared a password, or approved a transaction. Those are different levels of interaction.<\/p>\n<p>Do not assume that an error after submission means nothing was received. Equally, opening a page without providing information does not prove card theft.<\/p>\n<p>Keep any separate file download or device permission in the record. That may need a technical response in addition to financial or account protection.<\/p>\n<h3>Protect the evidence from becoming another disclosure<\/h3>\n<p>A screenshot can contain dates of birth, addresses, card fragments, or health information. Redact that material before sharing a public warning.<\/p>\n<p>Give necessary unredacted evidence only to verified providers or reporting services. A person offering to investigate in a comment is not an official support route.<\/p>\n<p>You can explain the fraudulent request without circulating a medical record or identification document. Keep the helpful warning narrower than the private evidence.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>Stop the passport application and follow-up conversation.<\/strong> Decline further payments, documents, or account approvals requested by the unverified sender.<\/p>\n<p>Save the original email or text and any existing confirmation. Avoid reopening the page solely to finish a screenshot or collect a certificate.<\/p>\n<\/li>\n<li>\n<p><strong>Tell your bank about card or banking exposure.<\/strong> Use the bank&#8217;s real app or established contact details, not a refund number supplied afterward.<\/p>\n<p>State which details were entered and whether a transaction or prompt was approved. Ask about protective measures and any applicable dispute options.<\/p>\n<p>An exposed card and an authorized payment under deception may require different handling. Describe both accurately rather than assuming a guaranteed charge reversal.<\/p>\n<\/li>\n<li>\n<p><strong>Secure passwords and account recovery details that were shared.<\/strong> Use the actual provider&#8217;s process on a device you trust.<\/p>\n<p>If the password was reused, replace it on the affected accounts too. Review unexpected recovery-contact changes and relevant access alerts.<\/p>\n<p>Do not let a supposed passport helper supervise the reset. A new unsolicited support link can recreate the same exposure.<\/p>\n<\/li>\n<li>\n<p><strong>Document personal or health information submitted.<\/strong> Keep a private list of fields, document images, and dates involved.<\/p>\n<p>Tell the appropriate verified provider or authority about specific misuse if it appears. A health-service logo alone does not establish which real organization received the data.<\/p>\n<p>Do not publish unredacted patient or identity records in a warning post. Protecting evidence and publicly describing the scam are separate tasks.<\/p>\n<\/li>\n<li>\n<p><strong>Investigate device exposure only where relevant.<\/strong> If the interaction led to software installation, remote access, or persistent suspicious behavior, seek trusted technical help.<\/p>\n<p>Malwarebytes can assist with suspicious downloads or device threats. AdGuard can reduce malicious advertising, but it cannot authenticate an application or refund a fraudulent charge.<\/p>\n<p>A received email by itself does not establish infection. If the device is managed by your employer, report the actual interaction to its IT team.<\/p>\n<\/li>\n<li>\n<p><strong>Report suspicious messages using current guidance.<\/strong> The <a href=\"https:\/\/www.ncsc.gov.uk\/section\/respond-recover\/phishing\" target=\"_blank\" rel=\"noopener\">NCSC&#8217;s phishing-response page<\/a> covers evidence, message reporting, and exposure-specific actions.<\/p>\n<p>Current instructions include forwarding suspicious texts to 7726 where supported. Use verified reporting details rather than a contact supplied in the fake passport email.<\/p>\n<p>Keep the message date in the report. Historical examples and a message received now should not be described as the same intercepted incident.<\/p>\n<\/li>\n<li>\n<p><strong>Report financial fraud through the appropriate national route.<\/strong> In Scotland, contact Police Scotland. Use Report Fraud for England, Wales, and Northern Ireland.<\/p>\n<p>Preserve bank and authority reference numbers together. A report can support an investigation, but it does not guarantee an immediate recovery or identify the operator.<\/p>\n<p>Do not accuse a real NHS employee solely because their name was copied into a message. Report the identity claim and deceptive conduct.<\/p>\n<\/li>\n<li>\n<p><strong>Verify any present health or travel question separately.<\/strong> Use the relevant current official service, not the old passport agent or historical application instructions.<\/p>\n<p>Do not pay a follow-up recovery specialist to obtain a pass or reverse the loss. Continue through the genuine providers you reached yourself.<\/p>\n<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is this warning about a newly discovered NHS email?<\/h3>\n<p>No. It explains a documented 2021 passport-phishing pattern. It does not claim to have intercepted a new campaign or verified an active malicious destination.<\/p>\n<h3>Was payment needed for the genuine NHS COVID Pass?<\/h3>\n<p>The historical NHS warning said obtaining that pass did not require payment details. The false administrative charge was part of the impersonation.<\/p>\n<h3>Can I still use England&#8217;s old COVID Pass application route?<\/h3>\n<p>The live GOV.UK page says the service closed on December 4, 2023 and applies to England. Do not treat historical application steps as current instructions.<\/p>\n<h3>Does that closure settle all vaccination-document or travel rules?<\/h3>\n<p>No. Different jurisdictions and current travel requirements need their own official checks. This phishing article does not determine what documentation a particular destination requires.<\/p>\n<h3>Does every NHS message asking personal questions count as fraud?<\/h3>\n<p>No. Genuine verified healthcare interactions can require identifying information. The issue is an unsolicited passport route whose identity and payment request have not been established.<\/p>\n<h3>What if I only opened the link?<\/h3>\n<p>Close it and record any additional action. Opening alone does not establish card theft; details submitted, files downloaded, or permissions granted can change the response.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The NHS COVID Pass scam used a once-familiar document to justify an unverified application and payment request. Neither the NHS name nor a neat form established authenticity.<\/p>\n<p>Reject the unsolicited passport route and check current official information for genuine questions. If information or money was exposed, contact the relevant provider and report the incident accurately.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The email offers a digital coronavirus passport and a convenient application button. For someone planning a trip, it once looked like paperwork worth getting out of the way. The NHS COVID Pass scam used that &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"NHS COVID Pass Scam: Fake Vaccine Passport Emails Asking for Card Details\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/nhs-covid-pass-scam-vaccine-passport\/#more-425148\" aria-label=\"Read more about NHS COVID Pass Scam: Fake Vaccine Passport Emails Asking for Card Details\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":425149,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-425148","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=425148"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425148\/revisions"}],"predecessor-version":[{"id":425151,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425148\/revisions\/425151"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/425149"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=425148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=425148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=425148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}