All posts

UK Scam Alerts — June 2026

14 min read Updated 27 June

June was a rough month for scams. AI voice cloning hit the mainstream, criminals spoofed the phone number of the fraud reporting service itself, shopping account takeovers spiked 323%, and couriers turned up at pensioners' front doors to collect cash. Fourteen scams tracked across the month, newest first.

27 June — Spoofed police numbers and fake Aldi ads

The City of London Police issued an alert this week after receiving more than 260 calls in just a few hours from people who'd been hit by spoofed numbers. That one's the main story, but there are two more doing the rounds right now.

Phone scam

1. Calls spoofing the fraud reporting service itself

You get a call, the caller ID looks official — sometimes it's a police number, sometimes Report Fraud's own number. They tell you your bank account has been compromised and you need to act now. You hang up. You check your missed calls and ring back. You're back through to the same criminals.

This is number spoofing used at its most cynical. The technology to fake a caller ID is cheap and widely available. There's no technical protection stopping a scammer from displaying any number they like on your screen.

Detective Superintendent Anna Rice from the City of London Police said it clearly: if you get an automated message telling you to press a number, hang up immediately. For any call claiming to be from the police or Report Fraud, find the real number yourself on the organisation's official website, then ring that. Not the number in your missed calls. Not the number the caller gives you.

Report Fraud's actual number is 0300 123 2040. If someone rings you claiming to be from them, you can always verify by hanging up and calling that number yourself from scratch.

Online scam

2. A fake Aldi advert appearing in Google search results

Which? flagged this on 25 June: a fraudulent advert is appearing in Google search results that leads to a copycat Aldi website. Once you land on the cloned site, it asks for your payment card details. The branding looks right, the layout looks right, and there's nothing obviously off unless you check the URL carefully.

Google's ad system lets anyone pay to appear at the top of search results. A familiar logo or brand name in the headline doesn't mean the ad is from the real company. Before entering card details on any retail site, look at the address bar. The domain should match exactly — aldi.co.uk, not aldi-discount.co.uk or aldioffer.com or anything else with extra words around it.

If you spot a dodgy Google ad, click the three dots next to it, select "feedback" then "something else" and report it. You can also report copycat websites to the NCSC at ncsc.gov.uk.

Phone scam

3. Automated housing repair calls from spoofed landlines

Also flagged by Which? this week: an automated call from what appears to be a London landline, claiming to be from "housing repairs." The goal is personal information — your name, address, date of birth — which is then used for fraud or sold on to other criminals.

The script varies, but common versions claim to be arranging a repair appointment, or offer compensation for a missed appointment. Say yes to the compensation angle and they'll ask for your bank details to pay you. There's no repair. There's no compensation.

Your council or housing association will always be able to confirm a real appointment through their main switchboard. If you get an unexpected call about a repair you didn't ask for, hang up and ring the council or housing association yourself using the number from your paperwork or their official website.

20 June — Fake festival tickets and bogus Boots survey

It's festival season, and the scammers know it. With Oasis back on tour and Glastonbury about to kick off, social media is awash with people offering tickets that don't exist. The government put out a proper warning about it this week.

Social media scam

4. Fake summer gig tickets

Fraud Minister Lord Hanson has personally warned the public after Action Fraud figures showed £1.6 million lost to gig ticket scams in 2024, more than double the year before. Around 3,700 people reported being caught out, and it's the under-30s getting hit hardest — more than a quarter of all victims were in their twenties.

The pattern is simple. Scammers post tickets for sold-out shows on social media, mostly Facebook Marketplace, at face value or just below. You message them, they ask for payment by bank transfer or crypto, and once the money's gone, so are they. The tickets never existed.

Here's the bit that catches people out: some of these listings come from hacked accounts. The seller might be a name you recognise, a friend of a friend, someone in a local group, because the scammer has taken over their genuine account and is selling from it. The founder of resale site Twickets warned of multiple fake Twickets accounts and websites set up specifically to target Oasis fans. One woman in Rutland lost hundreds of pounds trying to buy four tickets through Facebook Marketplace.

How to stay safe: buy from the artist's official site or an official ticket vendor, nowhere else. Never pay by bank transfer for a ticket. Use a credit card, because if it goes wrong you've got a route to your money back. And if someone's offering a sold-out show at a tempting price on social media, treat that as the warning sign it is. There's more detail in the government's announcement.

Email scam

5. The fake Boots "free sample" survey

This one is clever, and it's huge. Security firm Huntress uncovered a campaign aimed at nearly 9 million UK email addresses (8,894,920 to be exact) impersonating Boots. So many were going out at once that Huntress blocked almost 30,000 outbound email connections in 104 seconds.

The email uses real Boots branding and offers a free beauty sample pack in exchange for filling in a quick customer survey. The link takes you to a page that looks exactly like Boots, because the scammers copied the design straight off the real site. It isn't on Boots' servers though. The fake page was hosted on a hijacked Bolivian government website. Boots themselves were never breached — the attackers just borrowed someone else's server to run it.

You enter your name, address, date of birth, phone and email. Then a second form asks for your card details to cover a £2.95 delivery fee. That tiny charge is the whole trick. It sounds like nothing, so people don't think twice, and in handing it over they give away their full card number, expiry and CVV. Once it's done, you're bounced through to the real Boots website, which makes the whole thing feel like it worked.

How to stay safe: if a well-known shop emails you out of the blue offering a freebie for a survey, don't click anything. Go to the company's actual website yourself if you want to check. And no legitimate retailer needs your card number, expiry and security code just to post you a free sample. Huntress wrote up the full technical detail here if you're curious.

17 June — Courier fraud targeting over-70s

Report Fraud (the national fraud reporting service, which replaced Action Fraud in December 2025) issued an urgent alert this week about courier fraud. The numbers are bad: £21 million lost by UK victims in 2025 alone, with the average victim losing just over £15,000.

Phone / door scam

6. The courier fraud call

It starts with a phone call from someone claiming to be a police officer, a bank fraud investigator, or both. They tell you your account has been compromised, or that someone was arrested using your details and they need your help with an ongoing investigation. They sound calm, professional, and completely believable.

Then they ask you to do something: withdraw a large amount of cash, or go to a jeweller and buy gold. They'll tell you to keep it quiet — not to tell family, not to tell the branch staff what it's for, because "the bank might be involved." In some cases reported by Leicestershire Police, victims visited multiple jewellers over several days while staying on the phone to the scammer the entire time.

Once you have the cash or gold, a courier (or sometimes a "police officer" or taxi driver) arrives at your front door to collect it. They might show what looks like a badge. You hand everything over. That's it — the money or jewellery is gone.

People aged between 76 and 96 make up around 62% of all reports. The scammers know exactly who they're targeting.

The rule: no police officer or bank fraud team will ever ask you to withdraw cash, buy gold, or hand anything over to a courier. Not ever, for any reason. If that's what someone is asking, hang up immediately. Wait a few minutes before calling anyone back — scammers can hold a line open — then use a different phone or call 159 (the Stop Scams UK line) to speak to your bank safely.

Browser scam

7. The "your iPhone has been hacked" pop-up

This one showed up in Which?'s latest scam tracker this week. You click a link — often from social media or a dodgy email — and a pop-up fills your screen claiming your device has been hacked, your data is being stolen, and you need to act immediately. Some versions play an alarm sound. Some lock the browser so you can't easily close it.

If you press any of the buttons it presents, you'll either be taken to a phishing site that asks for personal details, or prompted to download something that installs malware.

Apple never communicates security warnings through your browser. This is not a real alert from anyone. Close the tab. On a phone, force-quit the browser if it won't close normally. That's all you need to do — no call, no download, no form to fill in.

If the pop-up won't close and is playing audio, put your phone face-down, take a breath, and then force-close the app from the app switcher. Nothing on that screen is real.

11 June — Fake Netflix emails bypassing spam filters

Spam filters do a lot of quiet work in the background. Most of the junk never reaches you. So when something dodgy lands in your actual inbox, looking the part, it carries a bit more weight. Three new ones this week, and the Netflix one has found a clever way past the filters.

Email scam

8. The fake "Netflix payment failed" email

This one is nasty because of how it gets to you. Normally a phishing email like this would be binned by your spam filter before you ever saw it. Not this batch. The scammers attach a hidden file stuffed with random gibberish text, and that junk confuses the filter into deciding the email looks legitimate. So it lands in your actual inbox alongside the real post.

The email uses your real email address (scraped from an old data breach), Netflix's actual logo and colours, and tells you your payment has failed or your account is on hold. Click the button and you hit a fake Netflix login that grabs your password, then a fake payment page that grabs your card details. The whole thing is multi-step and polished enough to fool people who know to be careful.

Which? flagged this on 10 June. Netflix never emails you a link to fix a payment. If there's a genuine problem with your account, open the app or type netflix.com in yourself. Don't use anything in the email.

Text scam

9. The fake FCA "data breach" text

A text arrives claiming to be from the Financial Conduct Authority, the body that regulates UK banks. It says your personal details were caught up in a fraud report and gives you a number to ring.

Call it and they start gently: your name, which bank you're with, your current balance. Some people are then handed a 5-digit reference code to quote when a "manager" calls back. A while later the same gang rings again, this time pretending to be your bank, and they quote that code back at you. Sounds official. It isn't.

The FCA does not text the public about data breaches. It will never ring you asking for your balance or account details. If you get one of these, forward it to 7726 and delete it. This has been flagged by the Report Fraud Alert service.

Email scam

10. The fake NatWest "biometric login" email

This email claims to be from NatWest and says the FCA is about to make fingerprint or face login mandatory, so you need to click a link and set it up now. It's a lie. The FCA does require banks to use Strong Customer Authentication, but biometric checks have never been made compulsory.

The whole thing is built on a rule that sounds plausible enough that people don't question it. The link goes to a fake NatWest page designed to harvest your banking login. Your bank will never force a security change through a link in an email.

7 June — Online shopping account fraud up 323%

On 4 June, Report Fraud put out an urgent warning. Reports mentioning Argos shot up 323% in a single month, from 154 in April to 652 in May. Criminals have found an easy way into people's shopping accounts, and it's spreading.

Online shopping scam

11. The account takeover

When a website gets hacked and its passwords leak, those email-and-password combinations end up for sale. Criminals take those lists and try them, by the thousand, on completely different sites. If you used the same password on, say, an old forum that got breached and on your Argos account, they're now in. This is called credential stuffing, and according to the Report Fraud alert it's exactly what's behind this spike.

Once they're in your account, they place click-and-collect orders for expensive stuff and walk into a store to pick it up. In some cases they pay with card details stolen from somebody else entirely, so the first you know about it might be an order confirmation for something you never bought.

Watch for emails confirming orders you didn't place, click-and-collect codes you didn't ask for, or your saved address suddenly changing. Argos is contacting affected customers directly, so a genuine warning from them is possible right now. Just don't click links in it. Log in to your account by typing the address yourself.

The root of all this is password reuse. Most people have one or two favourite passwords they use everywhere, and I completely understand why. Remembering forty different ones is impossible. But that's the exact weakness these criminals rely on. One old breach somewhere you've forgotten about, and every account sharing that password is exposed.

2 June — AI voice cloning, fake FCA texts, and WhatsApp hijacking

Three active scams to start the month. One of them is new enough that a lot of people haven't heard of it, and convincing enough that even people who think they'd never fall for a scam are getting caught.

Phone scam

12. The AI voice call — "It's me, I'm in trouble"

This has been building for a few months but escalated significantly in May. Criminals take short clips of someone's voice from social media videos, voicemails, or Facebook posts — sometimes just three seconds is enough — and use AI to generate a convincing copy. They then call a family member pretending to be that person in an emergency.

The call sounds like your son, daughter, or grandchild. The message is usually urgent: they've been in an accident, they've been arrested, they've lost their wallet abroad. Please send money now. And — this is the detail that should ring alarm bells — please don't tell anyone else just yet.

National Trading Standards have been tracking this specifically. Through an operation called Derdap, they've blocked over 21 million scam calls and shut down 2,000 numbers linked to this kind of fraud in the past six months. It is not a niche threat.

The way to beat it: hang up and call the person back on the number already in your phone. If it was genuinely them, they'll pick up and you can help properly. If the "emergency" caller says don't call them directly or you can't reach them, that's the tell. You can also set up a family safe word — a phrase only your household knows — that anyone can ask in a suspicious call to confirm they're talking to a real family member.

Email / text scam

13. Fake FCA texts

Text messages claiming to be from the Financial Conduct Authority appeared in late May. The message says your personal details were found in a "Report Fraud" database (they've deliberately borrowed the name of the real crime reporting service) and your accounts are at risk. There's a number to call.

If you call, you're asked for your name, your bank, and your current account balance. Some people are then transferred to a "case handler" who tries to get them to move funds to a "protected account."

The FCA is the UK's financial regulator. They don't text individuals. They don't run fraud investigation lines that cold-call members of the public. If you receive one of these, do not call back. Forward the text to 7726 instead.

Social media scam

14. WhatsApp account hijacking

The six-digit code scam has been around for years, but a 2026 variant called GhostPairing is worth knowing about. You receive what looks like a photo link from someone in one of your WhatsApp groups. Clicking it starts a linked-device session without any visible sign on your phone. The attacker can read your messages and impersonate you silently.

The original version still catches people too. Someone in a group messages you, chats normally for a bit, and at the same moment you get a text from WhatsApp with a six-digit verification code. They claim they sent you "their code by accident" and ask you to pass it on. You do. They're in your account.

Two things stop both. First: never share a WhatsApp code with anyone, ever — WhatsApp says in the text message itself "never share this code." Second: enable two-step verification in WhatsApp (Settings, Account, Two-step verification). If that's on, a stolen code alone isn't enough to get in.

One rule that stops almost every scam: if someone contacts you and asks you to act urgently (move money, click a link, install software, read out a code), it's nearly always a scam. Genuine organisations don't work that way. Hang up, close the email, and contact the real company using a number from their official website or your paperwork.

If it's already happened

If you've clicked something you shouldn't have, installed software on your PC, or given out bank details:

  1. Call your bank right now. The number on the back of your card. Don't wait. Most UK banks have 24/7 fraud lines.
  2. Dial 159. This connects directly to your bank's fraud team and works with most major UK banks.
  3. Change your passwords. Email first, because that's usually the one attackers use to reset everything else.
  4. Turn on two-factor authentication where it's offered, so a stolen password on its own gets nobody anywhere.
  5. Run a full scan with Windows Defender or your antivirus. See my post on whether you actually need antivirus for what I recommend.
  6. If you installed "support software" (AnyDesk, TeamViewer, something they walked you through), that's a remote-access tool. Get the PC looked at. Anything on it could have been copied or changed while they had access.

How to Report Scams

Reporting is worth the two minutes it takes. The scam filters on mobile networks and the NCSC's Suspicious Email Reporting Service both work off volume. The more people report, the faster the fraud gets shut down.

I've written separately about keeping your PC safe for online banking and how to tell real virus warnings from fake ones, both worth a read if this stuff worries you.

If a scammer has already had remote access to your machine, get it checked. I handle virus and malware removal in St Helens and can make sure nothing nasty got left behind.

Mark — Your Local Computer Guy
Mark

Mark has been fixing computers since the late '90s and went self-employed in 2008. Based in St Helens since 2013, he works evenings and weekends from his home in Laffak — friendly, affordable repairs for PCs, laptops, and Macs. See reviews on Google

Think you've been scammed? Or had someone on your PC?

If you've let someone remote in, installed dodgy software, or just want your PC checked over — get in touch and I'll have a proper look.

★★★★★

"Absolutely fantastic service from Local Computer Guy, I was unable to help my grandparents with their computer issues after an unfortunate issue with a scammer and potential virus being installed on their machine. After a quick call I knew they were in good hands. Arrived on time and quickly wiped the machine and made it safe, also helped investigate what had happened and helped my grandparents get using their computer again."

— Joe Gempton, via Google