UK Scam Alerts — August 2026
August has been busy. Concert ticket fraud hit £150 million in annual losses according to a government and O2 warning, Nottingham Knockers doorstep sellers have picked up a card reader angle, fake energy rebates are running ahead of October's price cap, and HMRC refund scams have moved from email to WhatsApp. Ten scams in all this month.
30 August — Concert ticket fraud and Nottingham Knockers at the door
A government and Virgin Media O2 campaign put a figure on concert ticket fraud this August: £150 million lost to fakes in a single year. Which? flagged the Nottingham Knockers doorstep scam on 17 August, an old trick that has picked up a new card reader angle.
1. Fake concert and festival tickets
Gig-goers in the UK lost £150 million to fake tickets in the past year. That's the figure from a joint campaign between the government and Virgin Media O2, published on 10 August and timed to big tours from Ariana Grande, The Weeknd, and Bon Jovi pushing up demand for sold-out shows.
One in seven people who buy concert tickets has been sold a fake at some point. Younger buyers are hardest hit: 31% of 18 to 24 year olds have been stung, compared to 4% of over-55s. Seventy-seven percent of fake tickets are bought via social media, Facebook Marketplace, Instagram DMs, and informal resale groups in particular.
The setup is always similar. Someone has a spare pair they can't use, at face value, because they're decent like that. The tickets either don't exist or are a screenshot of someone else's booking that won't scan at the door. You find out when you're standing outside the venue.
Only buy from the official venue box office or an authorised ticketing agent: Ticketmaster, SeeTickets, AXS. If you need a resale ticket, use a verified fan-to-fan platform where the ticket is validated before it changes hands. Pay by credit card so you have Section 75 protection if something goes wrong. That covers purchases between £100 and £30,000, and a card dispute is a lot easier to win than chasing a stranger on Facebook.
Facebook Marketplace and Instagram DMs have no ticket verification, no buyer protection, and no way to trace a seller who vanishes. The price looking right is the whole point.
2. Nottingham Knockers: cleaning products, fake ID, and card reader fraud
Young men arrive at the door carrying a holdall of cleaning products: dishcloths, dusters, polish, sprays. Which? flagged a fresh wave of this on 17 August. They claim to be on a government Community Payback rehabilitation scheme. They are not. That scheme doesn't involve selling anything door to door, and these groups have no connection to it.
They produce ID that looks official. It isn't. The products are overpriced and poor quality.
That's the mild version of the problem. The card reader angle is where it gets worse. You agree to pay £15 for a cloth, they hold out the reader, and they've typed in £150 or £1,500. You tap or enter your PIN on a screen you didn't properly look at. By the time you check your bank app, they're long gone and the dispute process is slow.
Some operations running this are linked to burglary networks. The door visit is not just about selling you something. They are working out whether you live alone, what's visible inside, what the entry points look like. Not every group is doing this, but enough are that it's worth being aware of it.
They can turn aggressive if you close the door quickly.
Don't engage and don't open the door wide. You don't owe a stranger on your doorstep a conversation. Never hand your card over or let anyone hold a reader anywhere near it. If they won't leave or the situation feels threatening, call 101. You can report doorstep traders to Trading Standards on 0808 223 1133.
24 August — Fake Royal Mail customs fees and DVLA vehicle tax threats
Two phishing campaigns picked up by Which? in the last week of August, both using the pressure of a fine or a held parcel to push people into handing over card details quickly.
3. Fake Royal Mail customs fee
An email arrives saying a parcel you're waiting for has been held because customs duty hasn't been paid. The amount is usually small — a few pounds — which is exactly what makes it convincing. Royal Mail's branding, colours, a plausible tracking reference. Which? flagged this one on 24 August.
Click the link and you land on a page asking for your card details to pay the fee. Some versions then say the payment failed and ask you to try again.
Royal Mail doesn't collect customs fees by email. When a genuine parcel is held for duty, a paper card comes through your door at the delivery address. You pay at a Post Office counter or on the Royal Mail website after typing the address in yourself. No urgent email, no countdown, no card details entered on a site you clicked through to from a message.
If you're expecting something from abroad, check the tracking number from your original order at royalmail.com. That'll show the real status. Forward the scam email to report@phishing.gov.uk.
4. DVLA vehicle tax expiry threats
An email claims your vehicle tax has expired and that you face a fine of up to £1,000 unless you renew immediately. The link goes to something that looks like a GOV.UK page but isn't. Which? reported a fresh wave of these on 19 August.
The site asks for your registration number, personal details, and card information. The fine doesn't exist. The email goes out to anyone — the sender has no idea whether your tax is actually due.
The DVLA doesn't threaten large fines by email out of the blue. Genuine reminders come by post to your registered address. When your tax is due, you renew at gov.uk/renew-vehicle-tax or at a Post Office — not via a link in an unexpected email. To check your current status in ten seconds, go to gov.uk/check-vehicle-tax and enter your reg. If it's showing as valid there, the email is a scam.
Forward to report@phishing.gov.uk.
9 August — Fake TV Licensing emails and the Nationwide Fairer Share con
Action Fraud received 6,307 reports about fake TV Licensing emails in the space of two weeks. Which? flagged the wave on 4 August, and a second one three days later aimed at Nationwide members. Both scams bolt a payment page onto the end of something real and true.
5. The fake TV Licensing email
The subject lines vary. Some say your licence expires today. Some say there's a problem with your payment. Some go the other way and tell you you're owed a refund, which catches people who'd never fall for a threat but will happily click for money back.
Click through and you land on a copy of the TV Licensing site that wants your name, date of birth, address, account number, sort code, card number and CVV. That is not a payment form. That is a shopping list.
The tell is the greeting. Genuine TV Licensing emails include your name and part of your postcode, because they have both on file. Scam emails have neither, because all the sender bought was your email address. If the email opens with something generic and never once uses your name, close it.
Real emails come from donotreply@tvlicensing.co.uk or donotreply@spp.tvlicensing.co.uk. Tap the sender name on your phone to see the actual address behind it, not the display name, which anyone can set to anything. The standard colour licence is £180 a year for 2026-27, so a demand for some odd figure you don't recognise is worth a second look on its own. The Star covered the warning in more detail.
If you're genuinely unsure, sign in to your TV Licensing account by typing the address in yourself. Your licence status is right there. It takes thirty seconds and it settles it.
6. The Nationwide "Fairer Share" payment scam
Nationwide paid £100 to over four million eligible members this year. It was in the papers, people talked about it, and plenty of members are still not sure whether they got theirs. Perfect conditions for a scam.
So the emails have started. Claim your Fairer Share Payment. Confirm your details to release your payment. Verify your account before the deadline. All of it fake, all of it pointing at a page that wants your banking login or card details.
There is no application process for the real thing. Nationwide works out who qualifies and pays the money into the account. No form, no claim, no confirmation step, no deadline. Any message asking you to do something to receive it is a scam, full stop. You don't need to check anything else about the email. That one fact is enough.
There's a phone version too, with someone claiming to be from Nationwide's fraud team. If you're on a call and it feels off, open the Nationwide app while still on the line. The Call Checker tile tells you whether you are actually speaking to Nationwide. If it says you're not, hang up mid-sentence. You owe a scammer nothing, least of all politeness.
Nationwide's own guidance on this is at nationwide.co.uk, and Which? has been tracking both waves on its scam alerts page.
6 August — HMRC Self Assessment refund scams, now on WhatsApp
HMRC posted a scam alert on 2 August. Reports are up of fake emails telling people they're due a Self Assessment tax refund, and a newer version is arriving as direct WhatsApp messages. August is when people start pulling paperwork together for the 2024-25 return, so the timing is not an accident.
7. The fake HMRC refund email
It arrives looking right. HMRC green, the crown logo, the same slightly stiff wording the real letters use. Usually it mentions an overpayment on your 2024 to 2025 Self Assessment, or a credit sitting on your record waiting to be released.
Then the deadline. Claim within 24 hours. Respond before the refund expires. That pressure is the whole trick, because it stops you doing the one thing that ends the scam instantly, which is checking.
Click the link and you land on a copy of the HMRC sign-in page, or a claim form wanting your name, address, date of birth and bank account details so the refund can be paid in. There is no refund. What you've handed over is enough to take money out rather than put it in.
HMRC will never email you about a refund with a deadline attached. If you are genuinely owed money it sits in your HMRC account, and it will still be there next week. Log in yourself at tax.service.gov.uk or open the HMRC app and look. Type the address in rather than clicking through from anything.
Forward the email to phishing@hmrc.gov.uk and delete it. HMRC's guidance on genuine contacts lists what real messages from them do and don't do. Worth a bookmark.
8. WhatsApp messages pretending to be from HMRC
This version catches people who have already learned to be careful with email.
HMRC does use WhatsApp, which is exactly what makes it work. It's a broadcast channel: general reminders about deadlines and forms, sent one way, to everyone who signed up. Nobody at the other end reads replies, and nothing about your personal tax account ever goes through it.
The scam version turns up as a direct message. There's a penalty on your account, or a refund waiting, and there's either a link or a number to ring. Ring the number and you get someone patient and helpful who talks you through handing over your details.
HMRC will never send you a direct WhatsApp message about your tax account. Not about a penalty, not about a refund, not to confirm your details. If it's a one-to-one chat, it isn't HMRC.
Screenshot it, forward the screenshot to phishing@hmrc.gov.uk, report the contact inside WhatsApp, then delete the chat.
3 August — Fake energy rebate texts and bogus app ads
The Ofgem price cap for October gets announced at the end of this month. Without fail, scammers start sending fake rebate texts and emails before the news lands. Action Fraud has an active alert for this specific scam. Separately, Which? reported a new social media scam on 29 July where ads look like standard app promotions but deliver something else entirely.
9. The fake Ofgem energy rebate
Comes as a text or email. The subject line on the emails is typically "Claim your bill rebate now," and that exact wording turned up in 752 reports to Action Fraud in just four days during a previous price cap cycle. The message says you're eligible for a payment, usually between £200 and £500, tied to the change in energy prices. It uses Ofgem's name, logo, and official colours. The deadline is tight: 24 hours, or before the end of the week.
Click the link and you land on a fake website asking for your bank details to pay the rebate in. Some versions ask you to set up a direct debit. Either way, there's no rebate.
Ofgem does not contact individual customers. Not by text, not by email, not ever. Any genuine energy support payment comes through your supplier automatically. There is nothing to apply for, no form to fill in, and no bank details required to receive it. A countdown or deadline in a rebate message is always a pressure tactic.
If you get one: forward the text to 7726 or the email to report@phishing.gov.uk, then delete it.
10. Fake app ads leading to unlicensed casinos
Which? flagged this one at the end of July. Ads are running on Facebook and Instagram that look identical to standard app promotions for apps people already recognise and trust: Google Authenticator, Disney+, Duolingo, Airbnb. Tap through and you end up at an unlicensed online casino, not a legitimate app.
The problem isn't just losing money on a dodgy bet. The casino behind these ads is not registered with the Gambling Commission. That means UK consumer protections don't apply. If you deposit money, there is no regulated route to recovering it.
The sign something's wrong: the ad routes you somewhere other than the official app stores. Genuine apps are always installed through Google Play or the Apple App Store. If a social media ad is pointing you to install from a website or a third-party link, stop.
When in doubt, open your phone's app store and search for the app directly. Skip the ad entirely.
If it's already happened
If you've clicked something you shouldn't have, installed software on your PC, or given out bank details:
- Call your bank right now. The number on the back of your card. Don't wait. Most UK banks have 24/7 fraud lines.
- Change your passwords. Email first, because that's usually the one attackers use to reset everything else.
- Run a full scan with Windows Defender or your antivirus. See my post on whether you actually need antivirus for what I recommend.
- If you installed "support software" (AnyDesk, TeamViewer, something they walked you through), that's a remote-access tool. Get the PC looked at. Anything on it could have been copied or changed while they had access.
How to Report Scams
- Scam text → forward to
7726(spells SPAM, free on all UK networks) - Scam email → forward to
report@phishing.gov.uk - HMRC scam → forward to
phishing@hmrc.gov.uk - Scam website → report at ncsc.gov.uk
- Fraud of any kind → Action Fraud on
0300 123 2040or actionfraud.police.uk
Reporting is worth the two minutes it takes. The scam filters on mobile networks and the NCSC's Suspicious Email Reporting Service both work off volume. The more people report, the faster the fraud gets shut down.
I've written separately about keeping your PC safe for online banking and how to tell real virus warnings from fake ones, both worth a read if this stuff worries you.
If a scammer has already had remote access to your machine, get it checked. I handle virus and malware removal in St Helens and can make sure nothing nasty got left behind.
Mark has been fixing computers since the late '90s and went self-employed in 2008. Based in St Helens since 2013, he works evenings and weekends from his home in Laffak — friendly, affordable repairs for PCs, laptops, and Macs. See reviews on Google
Think you've been scammed? Or had someone on your PC?
If you've let someone remote in, installed dodgy software, or just want your PC checked over — get in touch and I'll have a proper look.
★★★★★"Absolutely fantastic service from Local Computer Guy, I was unable to help my grandparents with their computer issues after an unfortunate issue with a scammer and potential virus being installed on their machine. After a quick call I knew they were in good hands. Arrived on time and quickly wiped the machine and made it safe, also helped investigate what had happened and helped my grandparents get using their computer again."
— Joe Gempton, via Google