All posts

UK Scam Alerts — July 2026

12 min read

Eight scams came across my radar in July, and several of them specifically exploit the season. Holiday bookings, heatwave shopping, parking machines, your phone network. Here's everything that hit this month and what you need to know about each one.

31 July — Holiday booking fraud and fake parking QR codes

Two very different scams tied to summer. One empties your bank account before your holiday starts. The other waits for you in a car park. July is the worst month of the year for holiday booking fraud, and the timing here isn't an accident.

Email / website scam

1. Fake holiday bookings

You find a gorgeous apartment or a cheap deal on flights, pay by bank transfer, and hear nothing until you turn up at the destination and there's no booking. That's the shape of it. According to Action Fraud's summer holiday alert, UK victims lost over £11 million to this in 2024 across 6,066 reports, and July alone brought in 647 of them. The average loss was £1,844. That's a proper holiday's worth of money gone.

The way it works is clever. Criminals clone real travel company websites, right down to URLs that are one letter off the genuine one. They post fake listings for apartments and hotels on social media and on sites people already trust. The photos are real, lifted from somewhere else. The property either doesn't exist or was never available. You pay, and the money's gone the second it leaves your account.

There's a nastier version doing the rounds too. Fraudsters break into legitimate hotel accounts on Booking.com and message guests who've already booked, asking for an urgent payment through a new link or the reservation gets cancelled. Action Fraud put out a specific warning about the Booking.com version. Because the message comes through the real platform, from what looks like the real hotel, people pay without a second thought.

The pressure is the giveaway. Countdown timers ticking down. "14 people are looking at this right now." Everything pushing you to pay this minute before you've had a chance to think. Real bookings don't fall apart if you take an hour to check.

Before you pay anything: look for the ABTA or ATOL logos and check they're genuine on the ABTA site, pay by credit card rather than bank transfer so you've got protection, reverse-image-search the property photos to see if they're stolen, and phone the accommodation directly on a number you found yourself to confirm the booking exists.

In-person scam

2. Fake QR codes on parking machines

This one you scan with your own phone. Criminals print a fake QR code sticker and stick it right over the real one on a pay-and-display machine. You scan it, land on a convincing copy of PayByPhone or RingGo, tap in your card details, and pay. The money goes to the scammer. Your parking never registers. Then you get a penalty notice on the windscreen on top of everything else.

It's spreading fast. Between April 2024 and April 2025 there were more than 780 reports and around £3.5 million lost to QR code scams, which now make up over a fifth of all online fraud. The parking version alone is estimated to cost around £10,000 a day. One woman in Thornaby had £13,000 taken after scanning a dodgy code.

Some councils have gone out of their way to make the point clear. Hartlepool Borough Council confirmed their machines have never used QR codes at all, so any code you see stuck on one is fake by definition. That's a useful rule for a lot of places. If a code has appeared where there wasn't one before, treat it as suspect.

It isn't only car parks. The same trick is turning up on EV chargers, bike-share docks, and even QR codes on tables in food courts. Anywhere you'd expect to scan and pay, someone might have got there first. Friends Against Scams has a good rundown of how this "quishing" works if you want more detail.

The fix is simple. Don't scan stickers on machines. Use the keypad on the machine, pay by card, or open the parking app you already know and trust and type the location code in yourself. Never let a sticker send you to a payment page.

22 July — Fake Currys emails and bogus parking texts

One email campaign racked up over 170 reports to Report Fraud in a single day. The other targets drivers. Both are designed around things plausible enough to make you hesitate before deleting.

Email scam

3. Fake Currys email — "You're eligible for a free air conditioner"

An email arrives claiming you've been selected to receive a free portable air conditioner from Currys. With the UK's summer heat doing what it does, the timing is no accident. The email asks you to fill in a short survey to claim your prize. That link goes to a page designed to harvest your personal details, and in some versions, card information too.

Report Fraud flagged this on 20 July after receiving more than 170 reports in a single day. That volume tells you this is a coordinated campaign, not a handful of people getting lucky with a guess.

Currys don't send out unsolicited prize emails. If you haven't entered a competition, you haven't won anything. The link in these emails has nothing to do with Currys.

Forward it to report@phishing.gov.uk, then delete it.

Text scam

4. Fake RingGo texts — "Your parking payment is outstanding"

A text arrives saying you have an unpaid charge from your "latest parking activity." It includes a link that has the word "ringgo" in the URL, which is the bit that makes people hesitate. The website it leads to is fake. If you enter your card details there, they go straight to whoever set it up.

As Which? reported on 14 July, these texts use URLs that contain "ringgo" within a longer fraudulent domain, specifically to pass a quick glance. The real RingGo site is myringgo.co.uk. Anything else isn't them.

RingGo doesn't text you about unpaid fines. If you've paid through the RingGo app, the Receipts section in the app is the definitive record. That's what to check, not a text you weren't expecting.

If you clicked the link and entered any details, call your bank straight away. Forward the text to 7726 to report it to your mobile network.

12 July — Digital wallet theft and fake mobile upgrade calls

Two scams that barely existed a year ago are now near the top of the fraud figures. One of them worried me the moment I read about it.

Card / digital wallet

5. Your card, added to a stranger's phone

UK Finance flagged digital wallet fraud in their 2026 annual report as the second biggest source of card losses. Santander said it was their second biggest card fraud type last year, and HSBC has seen cases climbing for eighteen months. Which? put it near the top of their most convincing scams of 2026. So this isn't a fringe thing.

Here's how it goes. It starts with a text or email you weren't expecting: a parcel that needs a small redelivery fee, or an alert that looks like it's from your bank. You tap the link, you land on a site that looks right, and you type in your card number. Then it asks for the one-time code your bank has just texted you. You enter that too.

That code was the whole game. With your card details and that single passcode, the criminal adds your card to Apple Pay or Google Pay on their own phone. Now they can pay with a tap, anywhere contactless is accepted, and there's no £100 limit like there is on a physical card. Digital wallets don't cap the amount. They can spend, and spend, and spend.

The nasty part: cancelling the card doesn't always fix it. Banks use something called Automatic Billing Updater so your saved card details refresh automatically when you get a new number. Some fraudsters ride that. The new card lands on their device too, and the spending carries on.

Treat a one-time code from your bank exactly like your PIN. You would never read your PIN out to anyone, and you should never type an OTP into a website you reached from a text or email. If a code turns up on your phone and you didn't ask for one, that's a warning sign in itself. Someone may be trying to add your card right then. Ring your bank on the number from your card and tell them.

Turn on transaction alerts too, if you haven't. Getting a ping the second money leaves your account is the fastest way to catch this early.

Phone scam

6. The mobile upgrade that leaves you with the bill

Action Fraud has a dedicated warning out on this one, which tells you how common it's become. You can read it straight from them at actionfraud.police.uk/upgradescam.

The call sounds completely normal. Someone rings claiming to be from EE, O2, Vodafone, Three or Lebara. You're due an early upgrade, they say, or there's a cracking deal on a new contract. To sort it out, they need to confirm a few things: your account login, your address, your bank details. It all sounds like the sort of admin a phone company would do.

Then they hang up and use those details to log into your real account and order an expensive handset in your name, sent to your address. When it turns up, you get a second call, or a knock at the door. Wrong phone, they say, dispatch error, our courier will come and collect it. Or hand it back at this address instead. You do the decent thing and give it back.

You gave it back to them. The real network never sees it. You're left holding a contract for a phone that's now in a criminal's pocket.

The rule here is simple. Your network will not ring you out of the blue to offer an upgrade. If you're genuinely due one, you'll see it when you log into your own account. Never give login details or bank details to someone who rang you, however smooth and official they sound. And if a phone shows up that you didn't order, do not hand it to anyone who comes to collect it. Ring your network on the number from your bill or their real website and let them deal with it.

9 July — Fake O2 texts and Aldi air-con sites

Scammers watch what people are worried about and push on exactly that. This week: a fake text pretending your O2 SIM is about to be switched off, and a network of fake shopping sites aimed at anyone melting in the heatwave and trying to buy a fan.

Text scam

7. The "Your O2 SIM is about to be deactivated" text

A text lands claiming to be from O2. The wording is designed to make you panic slightly: "O2UK: IMPORTANT: Your SIM Card(s) will be inactive on 04/06/2026, because you have NOT signed our Terms and Conditions. Logon to sign." There's a link. Tap it and you land on a page that looks exactly like the MyO2 login. Enter your details and you've just handed your account to a stranger.

Once they're in, they can take over the account, and because your mobile number is the thing a lot of banks and email providers use to verify you, it doesn't stop at your phone bill.

O2 put out an official warning about this on 30 June 2026. They've blocked over a billion scam messages already, which tells you the scale of it. Murray Mackenzie, their Director of Fraud Prevention, put it plainly: "Scammers are becoming more sophisticated, using increasingly believable and urgent requests to target victims alongside convincing fake websites, demonstrating just how clever their tactics can be."

The one thing to hold onto: O2 never texts you asking you to sign terms and conditions to stop your SIM being switched off. Never. That message doesn't exist as a real thing.

Don't tap the link. If you want to check your account, open the MyO2 app or dial 202 from your phone. Forward the dodgy text to 7726. And if you already put your login in, change your MyO2 password straight away. Similar texts go out pretending to be EE, Vodafone and Three too, so the same rule applies whoever your network is.

Online shopping scam

8. Fake Aldi air-con sites cashing in on the heat

Air conditioning units and portable coolers have sold out at the real shops this week. Scammers noticed. Security firm Kaspersky has found a whole network of fake websites built to look exactly like Aldi's, right down to the logo, the colours and the layout, all selling AC units at prices that are too good to walk past.

One listing offered an "energy efficient cooling system" at £28.13, marked down from £64.44, with a "only 5 left" warning ticking away. Another had a "premium 3-in-1 portable air conditioner" at £149.99, supposedly down from £474.99. Countdown timers. Fake live viewer counts. Discounts about to expire. All of it engineered to get you to type in your card number before you've had a proper think.

You pay. Nothing arrives. Your card details are now theirs. IBTimes UK reported the Kaspersky research, and Aldi has confirmed it actively hunts down and reports these copycat domains.

Kaspersky's Olga Altukhova summed up why it works: "Artificial pressure is a primary weapon for online thieves. When demand spikes, warnings about low stock or expiring discounts compel people to act before they think. The heat makes buyers impatient, and impatience leads to mistakes."

The fix is boring but it works: never buy through a link in an email or a social media ad. Get to the shop yourself. Type the address in, or search for it and check the domain properly before you go anywhere near the checkout. If the deal only exists behind a link someone sent you, that's your answer.

One rule that stops almost every scam: if someone contacts you and asks you to act urgently (move money, click a link, install software, read out a code), it's nearly always a scam. Genuine organisations don't work that way. Hang up, close the email, and contact the real company using a number from their official website or your paperwork.

If it's already happened

If you've clicked something you shouldn't have, installed software on your PC, or given out bank details:

  1. Call your bank right now. The number on the back of your card. Don't wait. Most UK banks have 24/7 fraud lines.
  2. Ask them to check for digital wallet tokens. This is the bit people miss. Ask the fraud team whether any "tokens" have been set up against your card on Apple Pay or Google Pay, and get any you don't recognise wiped. Otherwise a new card can just inherit the problem.
  3. Change your passwords. Email first, because that's usually the one attackers use to reset everything else. Then any account you reused the same password on.
  4. Run a full scan with Windows Defender or your antivirus. See my post on whether you actually need antivirus for what I recommend.
  5. If you installed "support software" (AnyDesk, TeamViewer, something they walked you through), that's a remote-access tool. Get the PC looked at. Anything on it could have been copied or changed while they had access.

How to report scams

Reporting is worth the two minutes it takes. The scam filters on mobile networks and the NCSC's Suspicious Email Reporting Service both work off volume. The more people report, the faster the fraud gets shut down.

I've written separately about keeping your PC safe for online banking and how to tell real virus warnings from fake ones, both worth reading if this stuff worries you.

If a scammer has already had remote access to your machine, get it checked. I handle virus and malware removal in St Helens and can make sure nothing nasty got left behind.

Mark — Your Local Computer Guy
Mark

Mark has been fixing computers since the late '90s and went self-employed in 2008. Based in St Helens since 2013, he works evenings and weekends from his home in Laffak — friendly, affordable repairs for PCs, laptops, and Macs. See reviews on Google

Think you've been scammed? Or had someone on your PC?

If you've let someone remote in, installed dodgy software, or just want your PC checked over — get in touch and I'll have a proper look.

★★★★★

"Absolutely fantastic service from Local Computer Guy, I was unable to help my grandparents with their computer issues after an unfortunate issue with a scammer and potential virus being installed on their machine. After a quick call I knew they were in good hands. Arrived on time and quickly wiped the machine and made it safe, also helped investigate what had happened and helped my grandparents get using their computer again."

— Joe Gempton, via Google