Summer Phishing Surge: Why Scammers Love Holidays

Here we look at how phishing scams spike in summer, including fake travel bookings, delivery text traps and urgent invoice fraud, and why UK businesses and individuals are especially vulnerable during the summer holiday season.

Phishing Peaks in Summer as Risk Awareness Drops

The summer season is increasingly being exploited by cyber criminals as a prime window to launch targeted phishing campaigns. For example, according to Action Fraud, UK consumers lost over £11.6 million to holiday-related scams in 2024 alone, with July and August seeing the highest volume of reports.

Why?

Experts point to a combination of seasonal distractions and increased online transactions, particularly for travel and leisure, as key drivers. With staff taking annual leave and workflows stretched thin, businesses are also becoming easier prey for invoice fraud and impersonation attempts.

Proofpoint, a global cyber security firm, recently warned that over one third of major UK travel booking platforms are failing to implement basic email authentication protections, such as full DMARC rejection policies, leaving customers vulnerable to spoofed messages. “Criminals know people are more likely to be booking trips or awaiting parcels,” said Adenike Cosgrove, cybersecurity strategist at Proofpoint. “That makes them more likely to click without thinking.”

Fake Travel Sites and Booking Confirmations Are Widespread

A common scam involves fake travel booking websites or emails posing as legitimate platforms such as Booking.com, Airbnb or Jet2. In many cases, victims are lured through paid adverts on social media or search engines, where fraudulent domains are made to closely resemble real travel brands.

In one incident recently flagged on Reddit and verified by multiple users, scammers exploited Booking.com’s internal messaging system to pose as hotels, sending follow-up messages asking guests to confirm payment via a malicious third-party link. The impersonators mimicked the platform’s branding and messaging style with alarming accuracy.

Fake Accommodation Offers

According to Action Fraud, 44 per cent of holiday-related phishing reports in 2024 involved fake accommodation offers. For example, many victims were contacted after initially engaging with a legitimate booking site, suggesting criminals are monitoring and hijacking booking journeys to insert phishing attempts at key points.

Delivery Text Scams Continue to Catch Holidaymakers Off Guard

One of the most persistent phishing threats this summer is smishing, where fraudulent text messages impersonate delivery companies such as Royal Mail, Evri or DPD. These scams typically claim a parcel is delayed or requires a small fee to release, directing the recipient to a fake website that harvests card details or personal information.

The problem is growing. According to Proofpoint and UK Finance, fake parcel delivery texts accounted for 67.4 per cent of all reported smishing attempts in the 30-day period to mid-July 2025, up from 53.2 per cent in previous months. Financial impersonation scams, by comparison, made up just 22.6 per cent over the same period.

This reflects a longer-term trend. The National Cyber Security Centre reported a 174 per cent year-on-year rise in smishing attacks as of mid-2024, and industry data indicates that the increase has continued well into 2025. A recent consumer survey by Ofcom found that 42 per cent of UK mobile users had received a suspicious call or SMS in the past three months.

Mobile Scam Filters Still Falling Short

While mobile operators claim that scam filters are improving, independent testing has raised concerns. In one 2025 study by cyber firm MetaCert, every simulated smishing message was successfully delivered to UK phones. These included texts spoofing well-known brands and containing malicious links, suggesting that current filtering systems are still failing to block even basic threats.

Why Summer Timing Makes These Scams More Effective

The seasonal context plays an important role. During the summer, people are more likely to shop online for travel items, gifts or personal deliveries while away from home. This makes messages about missed or rescheduled parcels seem believable and time-sensitive, creating the urgency that scammers rely on.

According to advice published by Age UK Barnet, for example: “scam texts often appear to come from delivery companies, like Evri or Royal Mail, saying that a parcel is on its way and asking for payment.” The charity warns that people may click without thinking, especially when expecting a delivery, and highlights that older users may be particularly vulnerable if they are unfamiliar with digital services or not used to checking links carefully.

The growing sophistication of these scams, including the use of personalised names, postcodes or local courier references, makes them harder to detect. This is especially true on mobile devices, where links and sender details are less visible at a glance.

Fake Invoices and Business Email Scams Surge Before Holiday Deadlines

For UK businesses, the summer period brings another kind of cyber threat. Business Email Compromise (BEC) and invoice phishing scams often spike around end-of-quarter deadlines or during peak holiday handovers, when key personnel may be absent.

Scammers typically insert themselves into existing email threads by using a near-identical address to impersonate suppliers, contractors or internal staff. They then request urgent payments to altered bank accounts, citing things like updated banking details or changes to invoice terms.

With this in mind, the North East Business Resilience Centre (NEBRC), for example, has issued multiple alerts this summer urging firms to verify payment details verbally before transferring funds. “Organisations should treat every payment change request—no matter how routine it seems—with extreme caution, especially when staff are away,” said the NEBRC’s cyber lead. “We see companies lose tens of thousands of pounds in a single transaction.”

According to UK Finance, invoice and mandate scams cost UK businesses over £56.7 million in a single year, with construction, legal and property sectors among the most targeted.

Quishing Attacks Using QR Codes Are Also on the Rise Too

Perhaps a less familiar but growing trend is the use of malicious QR codes in phishing campaigns, often referred to as “quishing”. These codes may appear in emails, event posters, parking meters or travel itineraries, and lead to malicious websites once scanned.

Security researchers at Check Point have identified a significant increase in such attacks since spring 2025, with many targeting travellers by mimicking airline boarding passes or local information portals.

The real danger lies in the perception of safety associated with QR codes, particularly when presented in a printed or semi-official context. In several recent cases, scammers have replaced public QR codes on transport signage or tourist maps with fake stickers that lead to credential-harvesting sites.

UK businesses operating physical locations or QR-based digital services are being urged to regularly check signage, validate their own codes, and educate staff on the risks of scanning unknown links.

Criminals Exploit Social Context and Emotional Cues

What links all of these attacks is timing and emotional manipulation. For example, summer, with its relaxed atmosphere, frequent purchases and disrupted routines, creates ideal conditions for social engineering.

For example, as cyber security firm Barracuda reports, seasonal phishing emails tend to use more emotionally charged language, including urgency, fear of missing out or appeals to customer service or refunds. Phrases like “Your booking is at risk”“Re-delivery needed today” or “Outstanding invoice requires attention” are designed to provoke rapid reactions.

The NCSC encourages UK users to follow its “Stop, Challenge, Protect” guidance—pausing before clicking or paying, questioning the legitimacy of the request, and reporting suspicious messages to the Suspicious Email Reporting Service (SERS) (at report@phishing.gov.uk).

Many Attacks Are Enabled by Gaps in Email Security

A report by Proofpoint revealed that as of summer 2025, only 61 per cent of the UK’s top 50 travel websites had enforced full DMARC rejection policies, which is a basic email authentication setting that helps prevent domain spoofing. This leaves both individual travellers and business clients exposed to fake emails that appear to come from trusted brands.

Similarly, smaller organisations often lack the cyber hygiene measures to filter out high-risk attachments or check for lookalike domains. In phishing simulations conducted by KnowBe4, UK companies saw click rates of over 33 per cent during peak summer periods, compared to 24 per cent in winter, suggesting seasonal distractions increase user vulnerability.

Also, the British Chambers of Commerce has called on smaller firms to step up basic security practices, especially during holiday periods when decision-making may be rushed or decentralised.

Cybercriminals Are Adapting Faster Than Users Can React

The final concern raised by many experts is the speed with which scammers adapt. While businesses and individuals may learn to spot one kind of scam, attackers quickly switch tactics, changing domain names, targeting new seasonal trends or using AI tools to personalise their phishing lures.

Check Point’s threat intelligence team recently found that Google, Microsoft and Apple were the top three brands impersonated in UK phishing campaigns during Q2 2025. These impersonations often come in the form of bogus security alerts, fake travel subscriptions or seemingly legitimate service confirmations.

The summer of 2025 is no exception. As more people head off on breaks, and companies operate with skeleton crews, phishing attacks are exploiting every opportunity to slip through the cracks.

What Does This Mean For Your Business?

What emerges from this summer’s phishing surge is a clear pattern of opportunism that cuts across both consumer and business behaviour. It seems that cyber criminals are not relying on sophisticated infrastructure or zero-day exploits. Instead, they seem to be exploiting timing, familiarity and human distraction. For UK businesses, especially smaller firms, this creates a persistent operational risk that does not end with the holiday season.

Attacks linked to fake bookings, delivery texts and invoice fraud are not only rising in volume but also in precision. Social engineering tactics have become more convincing, and the tools behind them more accessible. As the examples in this report show, scammers no longer need to breach systems to steal money or data, but they just need to catch someone at the wrong moment with the right message. This is particularly dangerous in summer when staff changes, out-of-office patterns and dispersed decision-making leave more gaps than usual.

The ongoing failure to implement email authentication standards such as DMARC, and the unreliable performance of mobile scam filters, suggest that many organisations are still relying on outdated or partial defences. Without investment in basic technical controls and regular user awareness training, UK businesses will continue to see preventable losses from phishing, whether in the form of misdirected invoice payments, stolen credentials or damaged trust.

For individuals, especially those booking holidays or expecting deliveries, the lesson is equally pressing. The presence of a recognisable brand or a plausible message is no longer a guarantee of safety. Personal vigilance, combined with public reporting and institutional support, will remain critical.

Looking ahead, the challenge is not just seasonal. Cyber criminals will continue to adapt their tactics to whatever events, platforms or behaviours dominate public attention. However, the summer phishing spike is a useful case study in how quickly attackers can exploit simple human habits, and how slow many defences still are to catch up. For both UK organisations and their customers, tackling phishing will require more than just summer warnings. It demands consistent, year-round resilience.

Security Stop-Press: Scammers Exploiting Landline Switchover to Steal Payments

Consumer champion Which? has warned that telephone fraudsters posing as BT are exploiting the UK’s digital landline switchover, tricking consumers into sharing payment details under false threats of disconnection.

Which? says the scam callers have been telling victims the switchover requires immediate payments or confirmation of financial details, using the now-defunct January 2025 deadline to create urgency. Victims report receiving calls where they are being pressured with threats of service termination. Which? also reports that the scammers have targeted both landline and mobile users and are often armed with personal details to appear credible.

BT has confirmed that the switchover to Voice over Internet Protocol (VoIP) involves no charges, and customers will only be contacted via official channels. Legitimate providers will never request payment information for this process.

To avoid falling victim, the advice is to never share personal or payment information during unsolicited calls, verify any claims directly with your provider, and use call-blocking services. Businesses can educate employees, implement secure protocols, and promptly report scams to Action Fraud to help combat these threats.

Featured Article : Realtime Deepfake Dating Scams

Here we look at how scammers are now reportedly using face-swapping technology to change their appearance in real-time to conduct video-based romance scams.

Yahoo Boys 

Recently, tech news site ‘Wired’ featured a story about romance scammers dubbed ‘Yahoo Boys,’ a slang term for a Nigeria-based collective of scammers who are now using deepfakes and real-time face-swapping technology so they can take on any appearance in their video feed to the targets of their romance scams. They are also known to be involved in phishing, and other cybercrimes.

Romance Scams 

A romance scam is a type of fraud where someone creates a fake identity to form a relationship with their target, often online, to deceive them into sending money or revealing personal or financial information.

How Big Is the Problem?  

According to the US FBI’s 2023 ‘Internet Crime Report’, the category of ‘confidence fraud/romance’ led to the theft of $652,544,805 from victims (which was actually down by a little over $83 million on the previous year).  This is clearly a significant problem and the real-time component of it will doubtless be factor in making this more prevalent.

How? What Tech Have They Been Using? 

As highlighted by the research of David Maimon, Head of Fraud Insights at SentiLink and a professor at Georgia State University, who has been monitoring the ‘Yahoo Boys’ on Telegram for more than four years, they use phones, laptops and several different types of popular face-swapping software and apps to create their deepfakes.

Also, it’s been noted (by Wired) that the so-called Yahoo Boys post videos of themselves online doing so, often showing their faces in the videos, and the videos and photos of their activities and recruitment are posted across many popular social media channels, including TikTok and Facebook.

Professor Maimon has also noted that the Yahoo Boys started using deepfakes for their scams as far back as 2022, meaning that they have gained quite a lot of experience around using these tools and tactics.

Deepfake Call Types 

It’s also been observed (and highlighted by Wired) that the Yahoo Boys scammers use two different types of live deepfake calls to trick their targets. For example:

Using two phones and a face-swapping app. One phone is used to call the target (via Zoom), using the rear camera to record the screen of the second phone (which is pointing at the scammer’s face) and uses a face-swapping app. In this way, the person’s face the target sees on the real-time video call is completely different from the scammer’s real face.

The second method swaps a laptop for the phone, using a webcam and face-swapping software on the laptop to change the face of the scammer. It’s also been reported that videos made by the scammers of them using this method show that they are able to see their real face displayed alongside their deepfake face although it’s only the deepfake face that’s shown to the target in the video call.

Realistic … and Getting Better

In a LinkedIn post from Professor Maimon, showing an example of one of the scammer’s videos, he notes how “Yahoo boys are getting better using AI tools to bring stolen images of social dating users to live” and that the video example he posted “has piqued my interest due to its remarkably natural head movements, overshadowing the only noticeable flaw—the voice, which could be rectified with relative ease.” 

How To Spot Deepfake (Video Calls) 

On her X feed, Rachel Tobac, who describes herself as a ‘Hacker & CEO at SocialProof Security,’ offers some tips on how to help spot a deepfake video call, based on the latest deepfake calls available.  These are:

– Get the person to stick out their tongue and move it around (tongue will look odd).

– Have the person move their head to the right & left or up & down to a large degree (it will look angular and boxy).

– Ask the person to get close to the camera and turn their head through a wide-angle (see angular boxy side of head).

– Ask the person to add another person next to them in the call and have the original person walk away and come back to see if a deepfake ‘flops-over’ to a second face.

– Look for discoloration around the scalp or circumference of the face (it may look like unblended makeup).

– Look for light flickering in their hair when they move.

Meeting In Person

As noted by contributor ‘Ally A’, to the LinkedIn post about the Yahoo Boys from Matt Burgess of Wired, a key piece of advice to people who may be involved in these kinds of romantic video calls is: “You can’t trust your eyes and ears anymore. If you can’t meet the person you are talking to online IN PERSON within 2-3 weeks of meeting, you have to assume that they are a scammer.” 

AI Advances Helping Scammers

The proliferation of AI technologies and their integration into various applications has inadvertently facilitated the activities of online scammers, including those involved in romance scams. AI-driven tools can now generate realistic and engaging text or images, enabling scammers to create convincing fake profiles and carry out sustained, personalised interactions without much effort – just as the Yahoo Boys have been doing. These sophisticated (but now widely available) tools can help scammers tailor their messages and responses based on the victim’s preferences and responses, making the deceit more believable. As a result, the barrier to entry for conducting such scams is lowered, allowing even those with minimal technical skills to now execute complex and convincing scams, thereby increasing the potential for exploitation and harm to unsuspecting individuals.

How To Protect Yourself 

In addition to Rachel Tobac’s tip for spotting deepfakes (such as those used by the Yahoo Boys), some of the key ways people can protect themselves from falling victim to romance scammers, include:

– Verify profiles. Conduct reverse image searches of profile pictures to check if they appear elsewhere on the internet, which can indicate a stolen image.

– Slow down. Be cautious with individuals who escalate the relationship too quickly or profess love unusually early!

– Keep personal information private. Avoid sharing sensitive personal information such as your address, financial details, or social security number.

– Be very skeptical of requests for money. Be highly suspicious if the person you are communicating with requests money, especially if it is for an emergency or a seemingly urgent matter.

– Use secure communication channels. Stick to the platform’s messaging services and avoid switching to less secure or private communication methods too soon.

– Seek second opinions. Discuss your online relationship with friends or family to gain outside perspectives, especially if something feels off.

– Report suspicious behavior. Report any suspicious profiles or messages to the dating platform and consider filing a complaint with relevant authorities if you suspect a scam.

What Does This Mean For Your Business?

For businesses, understanding the dynamics of the evolving scam landscape, as demonstrated by the techniques employed by the “Yahoo Boys”, is crucial. These scammers, using readily available AI technologies such as deepfakes and real-time face-swapping, underscore a growing trend in cybercrime that leverages cutting-edge technology to exploit vulnerabilities in human psychology, particularly through emotional engagement.

The decentralised nature of these scam networks (where individuals or small groups operate in loose associations while sharing tactics and tools), presents a significant challenge to traditional cybersecurity measures. They operate with a brazen openness, often flaunting their capabilities on social media, which shows a troubling confidence in their ability to evade detection.

The ease of access to AI tools means that the sophistication of scams can evolve as quickly as the technology develops. For businesses, this represents a clear and present danger not just in the form of romance scams targeted at individuals, but as a harbinger of more advanced AI-driven threats that could target companies directly. Phishing scams, impersonation, and business email compromise are just a few examples where similar technologies could be used to deceive employees or manipulate systems for fraudulent purposes.

To safeguard against these threats, businesses need to enhance their defensive strategies by incorporating advanced detection systems that can identify anomalies in communication patterns, authenticate digital identities more robustly, and monitor for signs of emerging threats such as deepfakes. Training employees to recognise and report potential scams is also vital. Creating a culture of security awareness and providing tools to verify information independently can act as a crucial barrier against deception.