Category: Impersonation & Authority Scams

  • The Hotel Message Knows Your Real Booking. It Can Still Be a Scam.

    VERDICT: STRONGLY VERIFIED (V4)

    A scam message can know where you are staying, when you are travelling and which property you booked.

    CLAIM

    Reservation-hijack scams use genuine booking context to send travellers convincing payment or card-verification requests through channels they already associate with their trip.

    EVIDENCE

    Gen Threat Labs reported in May 2026 that it had identified more than 350 accommodation-specific reservation-hijack scam flows across 50 countries. Its dataset included 31 compromised accommodations linked to the United Kingdom. Researchers analysed fraudulent landing pages, URLs, messages and in-app evidence and said victims had received reservation-specific information before being pushed to pages customised around the accommodation.

    Gen uses “compromised accommodation” carefully: it means reservation context associated with that accommodation was compromised and used in an intercepted attack flow. The source of the compromise could vary, including accommodation accounts, partner accounts, email, property-management systems or third-party services.

    TEST

    This evidence establishes the attack model and UK presence, but it does not prove that Booking.com itself was the source of every data compromise or that all attacks used the same malware chain. TVD therefore does not make either claim.

    VERDICT

    V4 — Strongly Verified. The mechanism is strongly supported by detailed threat research with UK cases in the dataset; attribution of individual compromise points varies.

    How to prevent it

    • Do not treat correct booking information as proof that a payment request is genuine.
    • If asked to re-enter card details or make an unexpected payment, open the booking service independently rather than following the supplied link.
    • Contact the accommodation using independently verified details if anything has changed.
    • If you entered card details into a suspicious page, contact your card issuer promptly.

    Warning signs

    • A message knows genuine booking details but unexpectedly asks you to re-enter payment information.
    • You are told the reservation will be cancelled unless you make another payment or verification payment.
    • The link opens a payment page outside the route you normally use to manage the booking.

    What to do if you responded

    Contact your payment provider promptly if you entered payment details or made a payment. Open the booking platform independently, check the reservation and contact the accommodation through independently verified details. Preserve the message and URL.

    Where to report it

    Report the message to the booking platform or accommodation through its genuine channels and report financial loss through the appropriate official fraud-reporting route. See Fraud First Aid.

    Source: Gen Threat Labs, “When Hotel Scams Know Your Booking”, 28 May 2026, plus its March 2026 Reservation Hijack investigation.

    Evidence boundary: TVD does not attribute all reservation-hijack attacks to any single booking platform, accommodation provider or software company.

  • The Digital Landline Switchover Is Real. The Upgrade Fee Is Not.

    VERDICT: STRONGLY VERIFIED (V4)

    The digital landline switchover is genuine. An unexpected demand that you pay to make the switch is not.

    CLAIM

    Scammers are exploiting the UK’s move from analogue landlines to digital services by posing as telecoms representatives and demanding payment or financial details.

    EVIDENCE

    UK government guidance confirms that the technology underpinning the analogue Public Switched Telephone Network is being retired by January 2027.

    Citizens Advice warns that if someone says you need to pay to switch your phone line, it is a scam and says home-phone providers will not ask customers to pay to switch to a digital phone line.

    Bromsgrove District Council warns of criminals posing as BT staff, asking for personal and payment details for an upgrade and threatening to cut off the landline if the resident refuses. Stoke-on-Trent City Council separately warns of callers requesting payment or bank details to renew telecare services.

    TEST

    The scam pretext is documented by consumer and local-government sources. TVD has not identified a national loss total for this specific method and does not claim one.

    VERDICT

    V4 — Strongly Verified.

    How to prevent it

    • Do not pay an unexpected caller for the landline switchover.
    • Contact your provider independently using details from your bill or official website.
    • If you use a personal alarm or telecare device, tell your telecoms and telecare providers so compatibility can be checked.
    • Do not let a threat of immediate disconnection rush you into giving bank details.

    Warning signs

    • An unexpected caller says you must pay for the digital landline switchover.
    • You are threatened with immediate disconnection unless you provide bank details.
    • A caller claims to represent your telecoms or telecare provider but asks you to use unfamiliar payment details.

    What to do if you responded

    Contact your telecoms provider independently using the number on your bill or its official website. If you supplied payment details, contact your bank. If you use telecare or a personal alarm, separately confirm compatibility with the genuine provider.

    Where to report it

    Report the approach to the genuine provider and use the appropriate official fraud-reporting route if money or sensitive information was taken. See Fraud First Aid.

    Sources: GOV.UK digital-landline guidance; Citizens Advice; Bromsgrove District Council; Stoke-on-Trent City Council.

  • The Police Caller Who Tells You to Buy Gold

    VERDICT: VERIFIED (V5)

    A supposed police investigation should never require you to buy gold and hand it to a stranger.

    CLAIM

    Courier-fraud offenders are persuading victims to buy high-value gold or jewellery before arranging for a courier to collect it.

    EVIDENCE

    City of London Police, the national lead force for fraud, said in June 2026 that courier-fraud reports increased from 1,721 in 2024 to 1,891 in 2025. Total losses rose from £19.5 million to more than £21 million.

    Police identified a growing 2025 trend involving jewellery and gold. Victims can be persuaded to visit multiple jewellers, buy expensive items and later hand them to a courier. Police say courier fraud typically starts with an unexpected call from someone claiming to be a police officer or bank employee.

    TEST

    The £21 million figure covers courier fraud as a whole. It is not a loss figure for the gold-and-jewellery variant alone.

    VERDICT

    V5 — Verified.

    How to prevent it

    • Police and banks will not ask you to buy gold or jewellery for an investigation.
    • They will not send a courier to collect your cash, cards, PINs or valuables.
    • End the call and independently contact the organisation using a number you know is genuine.
    • If a caller is keeping you on the phone while directing purchases or travel, treat that as an immediate warning sign.

    Warning signs

    • A supposed police officer or bank employee asks you to buy gold, jewellery or other valuables.
    • You are told a courier will collect cash, cards or valuables.
    • The caller tells you to keep the operation secret or remain on the phone while you travel or make purchases.

    What to do if you responded

    Do not hand anything to a courier. If a collection has already happened, contact police and your bank promptly and preserve receipts, CCTV, caller details and descriptions of the courier or vehicle.

    Where to report it

    Contact police if a collection is imminent or has just occurred. Report the fraud through the appropriate official route and contact your bank if financial information or cards were disclosed. See Fraud First Aid.

    Source: City of London Police / Report Fraud, 15 June 2026.

  • The Trademark Email That Says Someone Else Is About to Take Your Business Name

    VERDICT: VERIFIED (V5)

    The message sounds like professional legal correspondence: somebody else is supposedly about to register your business or brand name, but you have one last chance to act first.

    CLAIM

    Businesses are receiving trademark approaches that misuse the identities or regulatory details of genuine solicitors and firms.

    EVIDENCE

    The Solicitors Regulation Authority (SRA) has issued repeated alerts during 2026 describing closely similar approaches. The emails tell recipients that a third party has approached the sender to register the recipient’s UK brand or company name and seek exclusive rights. The recipient is then invited to secure trademark registration first, with the sender offering assistance.

    SRA alerts dated 8 April, 7 May, 13 May, 16 June, 13 July, 16 July, 19 August, 9 September and 10 September 2026 document variants misusing names or details associated with genuine solicitors or firms.

    TEST

    The repetition across separate SRA alerts establishes the recurring method. It does not establish that every approach came from one criminal group, and TVD makes no such attribution.

    VERDICT

    V5 — Verified.

    How to prevent it

    • Do not treat an SRA number or a genuine solicitor’s name as proof that the sender is that person.
    • Look up the solicitor or firm independently using the SRA’s official records and use independently obtained contact details.
    • Do not use the telephone number, email address or website supplied in the unexpected message to perform that verification.
    • If a trademark issue may be genuine, verify it independently before paying or instructing anyone.

    Warning signs

    • An unsolicited legal-looking email says somebody else is about to register your business or brand name.
    • You are pressured to instruct the sender immediately to protect the name.
    • The sender uses genuine-looking solicitor or SRA details but contact information does not match independently verified records.

    What to do if you responded

    Stop further payment or correspondence until the sender has been independently verified. If you paid, contact your bank. If you supplied account credentials, secure them. Preserve the original email, headers, attachments and payment instructions.

    Where to report it

    Check and report suspected solicitor impersonation through the SRA’s official channels and use the appropriate fraud-reporting route if money was lost. See Fraud First Aid.

    Sources: Solicitors Regulation Authority scam alerts published throughout April–September 2026.

    Evidence boundary: genuine solicitors and firms named in SRA alerts are victims of identity/detail misuse; TVD does not suggest they participated in the scam.

  • Scammed Once? The Next Caller May Pretend the FCA Has Recovered Your Money

    VERDICT: VERIFIED (V5)

    Losing money to fraud can create another vulnerability: somebody offering to get it back.

    CLAIM

    Fraudsters are impersonating the Financial Conduct Authority and telling previous fraud victims that money has been recovered, before trying to take further money or sensitive banking information.

    EVIDENCE

    The FCA said it received 4,465 reports of fake-FCA scams during the first six months of 2025. It recorded 480 people who had been duped into sending money. Almost two-thirds of reports came from people aged 56 or over.

    The regulator identified a common method in which fraudsters claimed the FCA had recovered funds from a cryptocurrency wallet opened illegally in the consumer’s name. It also identified approaches to previous loan-scam victims claiming the FCA could recover their losses, followed by attempts to obtain further funds. A separate reported variant falsely claimed that creditors had obtained a County Court Judgment and that money was owed to the FCA.

    TEST

    The figures come directly from the FCA. They cover fake-FCA scams generally, not only the recovered-money variant. TVD therefore does not attribute all 4,465 reports or all 480 payments to recovery fraud.

    VERDICT

    V5 — Verified.

    How to prevent it

    • Do not send money because an unexpected caller says the FCA has recovered previous losses.
    • The FCA says it will never ask you to transfer money to it or provide bank PINs or passwords.
    • End the contact and reach the FCA independently through its official contact details.
    • If you have previously been defrauded, be particularly cautious of unsolicited recovery offers.

    Warning signs

    • An unexpected caller says the FCA has recovered money for you.
    • You are asked to pay a fee, tax or release payment before receiving recovered funds.
    • The contact asks for PINs, passwords or a transfer of money.

    What to do if you responded

    Stop contact, contact your bank immediately if you paid or disclosed banking information, and independently contact the FCA using its official details. Preserve the telephone number, emails, payment details and any names used.

    Where to report it

    Report FCA impersonation to the FCA and report any fraud through the appropriate official fraud-reporting route. See Fraud First Aid for urgent steps after a payment or disclosure.

    Source: Financial Conduct Authority, “Almost 5,000 fake FCA scams reported in first 6 months of 2025”, 27 August 2025.

  • Your Pension Provider May Be Talking to a Fraudster Who Is Pretending to Be You

    VERDICT: VERIFIED (V5)

    Some pension fraud no longer depends on persuading the saver to make a transfer. The attacker may instead try to convince the pension scheme that they are the saver.

    CLAIM

    Fraudsters are using hacking and impersonation techniques to gain unauthorised access to pension accounts and attempt to bypass scheme security.

    EVIDENCE

    The Pensions Regulator (TPR) published an industry alert after an analyst seconded to the National Fraud Intelligence Bureau examined Action Fraud reports received between October 2024 and March 2025. TPR said almost a third of the reports analysed referenced attempts to bypass pension-scheme defences and exploit security vulnerabilities to gain unauthorised access to members’ accounts.

    Methods identified by TPR included hacking a member’s email to obtain correspondence with the pension scheme, then impersonating the member and attempting to change beneficiary bank details. TPR also identified attempts involving fake pension accounts, poorly secured credentials and diversion of deceased members’ pension funds. Members aged 50–69 represented 55% of reported victims in the analysis.

    TEST

    The finding comes from the pensions regulator and is based on analysed fraud reports. The “almost a third” figure applies to the reports in that specific October 2024–March 2025 analysis; it must not be presented as one third of all UK pension fraud.

    VERDICT

    V5 — Verified. The impersonation/account-takeover technique is directly documented by TPR.

    How to prevent it

    • Turn on two-step verification for your email and pension accounts where available.
    • Use a unique password for the email account connected to your pension.
    • Check that your pension provider holds your correct contact details.
    • Treat unexpected notifications of changed bank or contact details as urgent and contact the scheme through a known route.

    Warning signs

    • An unexpected pension notification says your bank, beneficiary or contact details have changed.
    • You receive password-reset or login alerts you did not initiate.
    • Pension correspondence disappears from or appears unexpectedly in a compromised email account.

    What to do if you responded

    Contact the pension scheme using independently verified details, ask whether any account, beneficiary or payment instructions have changed, secure the linked email account and change reused passwords. Preserve security alerts and correspondence.

    Where to report it

    Tell the pension provider immediately. If fraud or attempted fraud is identified, use the appropriate official fraud-reporting route. See Fraud First Aid if money or account access may already be affected.

    Source: The Pensions Regulator, “Industry alert: impersonation fraud”, published September 2025 and updated January 2026.

    Evidence boundary: the regulator establishes the technique and the characteristics of the analysed reports. TVD is not attributing failures to any particular pension provider.

  • Car-Finance Claim Messages: Verify Before You Respond

    Car-Finance Claim Messages: Verify Before You Respond

    A message about a car-finance claim can look plausible, timely and professional. None of those things proves who sent it.

    On 22 September 2026, the Financial Conduct Authority added www.approvedcarclaim.com and www.pcp.ashley-howard.co.uk / www.ppi.ashley-howard.co.uk to its Warning List. In each warning the FCA states that the firm is not authorised by it and may be targeting people in the UK.

    The important consumer lesson is broader than any one website: when a subject is already receiving widespread public attention, a message that appears topical can feel credible before its identity has actually been checked.

    CLAIM

    If a message correctly refers to car-finance compensation or PCP claims, the sender is probably a legitimate claims or financial-services business.

    EVIDENCE

    The FCA’s Warning List shows that unauthorised firms can operate in the same subject areas consumers are actively searching for. The regulator also warns that firms may provide contact details belonging to another business or individual so that an approach appears genuine.

    TEST

    Before clicking, replying or providing personal details, separate the subject of the message from the identity of the sender.

    1. Do not use the link in the message to verify the sender. Search independently.
    2. Check the exact legal or trading name. Similar names are not the same identity.
    3. Use the FCA Firm Checker where regulated activity is involved. Compare the contact details shown there with the ones used to approach you.
    4. Do not assume an existing car-finance relationship authenticates a new claims company.
    5. Be cautious with requests for identity documents, bank details, fees or authority to act. Establish who you are dealing with first.

    VERDICT: V1 VERIFIED

    The FCA added car-finance and PCP-related websites to its Warning List on 22 September 2026. That is verified primary-source evidence that consumers should independently check the identity and regulatory status of businesses approaching them about this subject.

    It does not follow that every unsolicited car-finance claim message is fraudulent. The correct response is verification, not assumption.

    ACTION

    If you receive a car-finance compensation message, preserve it before deleting anything. Record the sender, telephone number, email address, website and any company or FCA reference numbers supplied. Then verify those details independently.

    If the approach involves a firm on the FCA Warning List, follow the FCA’s guidance and avoid dealing with it.

    Primary sources: FCA Warning List; FCA warning: www.approvedcarclaim.com; FCA warning: www.pcp.ashley-howard.co.uk / www.ppi.ashley-howard.co.uk.


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. Mention of a website or firm reflects the cited FCA warning and is not an independent finding of criminal conduct. This publication provides general information, not legal or financial advice.

  • A Company Number Is Not Proof: How to Verify a Business Website

    A Company Number Is Not Proof: How to Verify a Business Website

    A company number can be genuine while the website displaying it is not.

    On 23 September 2026, the Financial Conduct Authority published a warning about MyCarSecurity.com. The FCA stated that the unauthorised firm had no association with Tide Group Holdings Ltd and was falsely claiming the genuine UK company’s registered number.

    That example demonstrates an important verification principle: finding a real company number is only the beginning of a check, not the end of it.

    CLAIM

    If a website displays a company number that exists at Companies House, the website has proved that it belongs to that company.

    EVIDENCE

    The FCA warning provides a current example where a genuine registered company number was, according to the regulator, being used by an unauthorised firm with no association to the genuine company.

    A registration record can establish that a company exists. It does not automatically establish that the website, email address, telephone number or bank account you are dealing with is controlled by that company.

    TEST

    When a website gives you a company number, cross-check the identity rather than merely confirming that the number exists.

    1. Search the number independently. Enter it yourself into Companies House rather than following a supplied link.
    2. Compare the legal name. Does the registered company name match the business identity being presented?
    3. Compare contact details. Check addresses, telephone numbers and email domains against reliable independent sources.
    4. Check regulatory status where relevant. For financial services, use the FCA Firm Checker or Financial Services Register independently.
    5. Verify payment instructions separately. A matching company number does not authenticate a bank account.

    VERDICT: V1 VERIFIED

    The proposition that a company number alone proves the identity of a website is unsupported. The FCA’s 23 September warning provides primary-source evidence of a genuine registered number allegedly being used by an unrelated unauthorised firm.

    The correct conclusion is narrower: a company number can help identify a registered entity, but the connection between that entity and the website or person contacting you must be verified separately.

    ACTION

    If a website is asking for money, financial information or identity documents, do not treat a Companies House number, padlock icon or polished website as authentication. Cross-check the business through independent sources and contact it using details obtained independently.

    Primary sources: FCA: MyCarSecurity.com warning; FCA: How to check a firm or individual is authorised.


    The FCA warning concerns the entity and website identified in the FCA notice. The Verification Desk has not independently determined the conduct of any individual. This publication provides general information, not legal or financial advice.