All posts

UK Scam Alerts — September 2026

6 min read
Woman looking worried at her phone showing an incoming call

Three of the scams doing the rounds at the end of August are all aimed at your phone, and two of them come from someone who already knows a bit about you. That's what makes them work. They don't sound like a stranger fishing, they sound like your network calling about your account.

Here's what's happening, in the order it landed.

28 August — fake Three calls with a 24-hour cut-off threat

Which? flagged a run of calls from people claiming to be Three customer service. The hook is a deadline, and it's a tight one.

Phone scam

1. "Your number stops working in 24 hours"

The caller says there's a problem with your account and your number will stop working within 24 hours, or that your SIM is about to be blocked. Sometimes it's a billing issue. Sometimes it's a security check that's failed. Either way the fix is the same: confirm some details, or pay a small activation fee to keep the line running.

The deadline is the whole trick. Nobody thinks clearly with a clock ticking, and a mobile number going dead is a genuinely frightening prospect if it's attached to your bank's two-factor login, your work, your family. So people answer the questions. Full name, address, date of birth, account password, card number for the fee. All of it handed over inside five minutes to someone who rang you out of the blue.

Three will not phone you with a 24-hour deadline. Networks don't operate that way. If there's a real problem with your account you'll hear about it by text or in the app, and you'll have time.

If you get a call like this, hang up. Then ring Three yourself using the number on their website or the back of your SIM packaging. Use a different phone if you can, or wait a couple of minutes before dialling. And never read out account details or passwords to anyone who has called you.

Reported by Which? on 28 August 2026.

20 August — O2 customers talked into reading out their own passcode

This one is cleverer, and it's the sort I hate seeing because the victim does everything right up until the last second.

Phone scam

2. The one-time passcode account takeover

The scammer already holds part of your O2 account details, probably scraped from an old data breach. They use those details to trigger a genuine one-time passcode, which arrives on your phone from O2's real number, in the same thread as every other legitimate message you've had from them.

Then they ring you. They're from O2 customer service, they're calling about a request on your account, and they need to verify your identity. Can you read back the code that was just sent to you?

The code is real. The message is real. That's why it works.

Once they have it, they own the account. Password changed, calls redirected, international roaming switched on, and you're locked out of the thing that half your other logins depend on. Sorting out a hijacked mobile account takes days.

A passcode sent to your phone is for you to type in, never to say out loud. No legitimate company will ask you to read one back over the phone. Not O2, not your bank, not Amazon, not anybody. If someone asks, that alone tells you exactly who they are. Hang up, and if the code arrived without you asking for it, ring O2 on a number you've looked up yourself and tell them.

Reported by Which? on 20 August 2026.

19 August — fake brand apps that watch your screen

This is the serious one. Report Fraud and the NCSC have both warned about it, which doesn't happen for small campaigns.

Text scam / malware

3. Spyware hiding behind 65 familiar brand names

It starts with a text. A deal, a refund, a delivery, a job offer. More than 65 brands are being impersonated in the campaign, among them Ryanair, Amazon and various government services, so whatever the message says it will look like something you might plausibly be expecting.

The link goes to a convincing enough site that then asks you to install an app. Not from Google Play or the App Store, but directly from the page. And once that app is on the phone it can watch your screen in real time and remotely switch on the microphone and the camera.

Read that again, because it's worse than it sounds at first. Real-time screen access means they see your banking app while you use it, your passwords as you type them, your messages as they arrive. The microphone and camera mean they can listen to and watch whatever is happening around the phone. There's no part of the device left private.

Never install an app from a link in a text message. Genuine apps live on Google Play and the Apple App Store, and nowhere else. If a website is telling you to sideload something, or your phone throws up a warning about installing from unknown sources, that warning is the whole story. Stop there.

If you've already tapped a link and installed something, don't just delete the icon and hope. Apps like this are built to run invisibly and some of them are awkward to remove properly. The phone needs checking, passwords need changing from a different device, and your bank needs telling.

Reported by Which? on 19 August 2026, with an accompanying advisory from the NCSC.

One rule that stops almost every scam: if someone contacts you and asks you to act urgently (move money, click a link, install software, read out a code), it's nearly always a scam. Genuine organisations don't work that way. Hang up, close the email, and contact the real company using a number from their official website or your paperwork.

If it's already happened

If you've clicked something you shouldn't have, installed software on your PC, or given out bank details:

  1. Call your bank right now. The number on the back of your card. Don't wait. Most UK banks have 24/7 fraud lines.
  2. Change your passwords. Email first, because that's usually the one attackers use to reset everything else.
  3. Run a full scan with Windows Defender or your antivirus. See my post on whether you actually need antivirus for what I recommend.
  4. If you installed "support software" (AnyDesk, TeamViewer, something they walked you through), that's a remote-access tool. Get the PC looked at. Anything on it could have been copied or changed while they had access.

How to Report Scams

Reporting is worth the two minutes it takes. Forwarding a scam text to 7726 gets the number blocked across the networks, and the fake app campaign only came to light because enough people passed the messages on. Your report is what stops the next person getting the same message.

Most of the people I see after a scam are sharp, capable and thoroughly annoyed with themselves, and they shouldn't be. These are well-built cons run by people who do this all day. If you think something got onto your machine, my virus removal service in St Helens covers checking it over properly rather than guessing.

Mark — Your Local Computer Guy
Mark

Mark has been fixing computers since the late '90s and went self-employed in 2008. Based in St Helens since 2013, he works evenings and weekends from his home in Laffak — friendly, affordable repairs for PCs, laptops, and Macs. See reviews on Google

Think you've been scammed? Or had someone on your PC?

If you've let someone remote in, installed dodgy software, or just want your PC checked over — get in touch and I'll have a proper look.

★★★★★

"Absolutely fantastic service from Local Computer Guy, I was unable to help my grandparents with their computer issues after an unfortunate issue with a scammer and potential virus being installed on their machine. After a quick call I knew they were in good hands. Arrived on time and quickly wiped the machine and made it safe, also helped investigate what had happened and helped my grandparents get using their computer again."

— Joe Gempton, via Google