Tag: SMS

  • The Hotel Message Knows Your Real Booking. It Can Still Be a Scam.

    VERDICT: STRONGLY VERIFIED (V4)

    A scam message can know where you are staying, when you are travelling and which property you booked.

    CLAIM

    Reservation-hijack scams use genuine booking context to send travellers convincing payment or card-verification requests through channels they already associate with their trip.

    EVIDENCE

    Gen Threat Labs reported in May 2026 that it had identified more than 350 accommodation-specific reservation-hijack scam flows across 50 countries. Its dataset included 31 compromised accommodations linked to the United Kingdom. Researchers analysed fraudulent landing pages, URLs, messages and in-app evidence and said victims had received reservation-specific information before being pushed to pages customised around the accommodation.

    Gen uses “compromised accommodation” carefully: it means reservation context associated with that accommodation was compromised and used in an intercepted attack flow. The source of the compromise could vary, including accommodation accounts, partner accounts, email, property-management systems or third-party services.

    TEST

    This evidence establishes the attack model and UK presence, but it does not prove that Booking.com itself was the source of every data compromise or that all attacks used the same malware chain. TVD therefore does not make either claim.

    VERDICT

    V4 — Strongly Verified. The mechanism is strongly supported by detailed threat research with UK cases in the dataset; attribution of individual compromise points varies.

    How to prevent it

    • Do not treat correct booking information as proof that a payment request is genuine.
    • If asked to re-enter card details or make an unexpected payment, open the booking service independently rather than following the supplied link.
    • Contact the accommodation using independently verified details if anything has changed.
    • If you entered card details into a suspicious page, contact your card issuer promptly.

    Warning signs

    • A message knows genuine booking details but unexpectedly asks you to re-enter payment information.
    • You are told the reservation will be cancelled unless you make another payment or verification payment.
    • The link opens a payment page outside the route you normally use to manage the booking.

    What to do if you responded

    Contact your payment provider promptly if you entered payment details or made a payment. Open the booking platform independently, check the reservation and contact the accommodation through independently verified details. Preserve the message and URL.

    Where to report it

    Report the message to the booking platform or accommodation through its genuine channels and report financial loss through the appropriate official fraud-reporting route. See Fraud First Aid.

    Source: Gen Threat Labs, “When Hotel Scams Know Your Booking”, 28 May 2026, plus its March 2026 Reservation Hijack investigation.

    Evidence boundary: TVD does not attribute all reservation-hijack attacks to any single booking platform, accommodation provider or software company.

  • The One-Time Passcode That Adds Your Card to a Criminal’s Digital Wallet

    VERDICT: STRONGLY VERIFIED (V4)

    A genuine one-time passcode can authorise the wrong thing if you misunderstand what it is asking you to approve.

    CLAIM

    Criminals can use card details entered into a fake shopping or delivery page to begin adding the victim’s card to a digital wallet on the criminal’s device, then trick the victim into supplying the OTP needed to complete wallet setup.

    EVIDENCE

    Which? documented the mechanism in 2025 after work involving Cifas, the Cyber Defence Alliance and UK Finance. Its investigation found that many card providers still offered SMS OTPs as one method of approving cards being added to digital wallets.

    In July 2026 Which? documented a victim who lost more than £18,000 after fraudsters persuaded him to provide an OTP which they used to add his Revolut card to an Apple Pay wallet, followed by fraudulent spending.

    TEST

    The evidence establishes the mechanism and documented victim cases. The public evidence used here is principally consumer and industry investigation rather than a national police prevalence dataset, so TVD does not estimate how many UK victims have experienced this specific technique.

    VERDICT

    V4 — Strongly Verified.

    How to prevent it

    • Read the entire OTP message before entering or sharing the code.
    • If the message says the code is for adding a card to Apple Pay, Google Wallet or another wallet when that is not what you are doing, stop immediately.
    • Never assume a genuine bank OTP means the website that triggered it is genuine.
    • If an unfamiliar wallet has been linked to your card, contact your card issuer immediately.

    Warning signs

    • An OTP message refers to adding your card to a digital wallet when you are only trying to make a purchase or delivery payment.
    • A caller or webpage asks you to enter an OTP without clearly explaining the action it authorises.
    • Your banking app shows a new wallet or device you do not recognise.

    What to do if you responded

    Contact your card issuer immediately, explain that your card may have been added to an unauthorised digital wallet, review recent transactions and ask the issuer to secure the card and linked wallet access.

    Where to report it

    Report unauthorised transactions to your bank or card issuer first, then use the appropriate official fraud-reporting route. See Fraud First Aid.

    Sources: Which? investigations, August 2025 and July 2026, drawing on industry evidence and a documented victim case.

    Evidence boundary: digital-wallet services themselves are legitimate. The fraud involves criminals abusing card-provisioning and social-engineering processes.

  • Scammed Once? The Next Caller May Pretend the FCA Has Recovered Your Money

    VERDICT: VERIFIED (V5)

    Losing money to fraud can create another vulnerability: somebody offering to get it back.

    CLAIM

    Fraudsters are impersonating the Financial Conduct Authority and telling previous fraud victims that money has been recovered, before trying to take further money or sensitive banking information.

    EVIDENCE

    The FCA said it received 4,465 reports of fake-FCA scams during the first six months of 2025. It recorded 480 people who had been duped into sending money. Almost two-thirds of reports came from people aged 56 or over.

    The regulator identified a common method in which fraudsters claimed the FCA had recovered funds from a cryptocurrency wallet opened illegally in the consumer’s name. It also identified approaches to previous loan-scam victims claiming the FCA could recover their losses, followed by attempts to obtain further funds. A separate reported variant falsely claimed that creditors had obtained a County Court Judgment and that money was owed to the FCA.

    TEST

    The figures come directly from the FCA. They cover fake-FCA scams generally, not only the recovered-money variant. TVD therefore does not attribute all 4,465 reports or all 480 payments to recovery fraud.

    VERDICT

    V5 — Verified.

    How to prevent it

    • Do not send money because an unexpected caller says the FCA has recovered previous losses.
    • The FCA says it will never ask you to transfer money to it or provide bank PINs or passwords.
    • End the contact and reach the FCA independently through its official contact details.
    • If you have previously been defrauded, be particularly cautious of unsolicited recovery offers.

    Warning signs

    • An unexpected caller says the FCA has recovered money for you.
    • You are asked to pay a fee, tax or release payment before receiving recovered funds.
    • The contact asks for PINs, passwords or a transfer of money.

    What to do if you responded

    Stop contact, contact your bank immediately if you paid or disclosed banking information, and independently contact the FCA using its official details. Preserve the telephone number, emails, payment details and any names used.

    Where to report it

    Report FCA impersonation to the FCA and report any fraud through the appropriate official fraud-reporting route. See Fraud First Aid for urgent steps after a payment or disclosure.

    Source: Financial Conduct Authority, “Almost 5,000 fake FCA scams reported in first 6 months of 2025”, 27 August 2025.

  • The £100 Oil Voucher Message: Check Before You Click

    The £100 Oil Voucher Message: Check Before You Click

    A message offering help with heating costs can arrive at exactly the moment a household wants it to be genuine.

    On 9 September 2026, the Police Service of Northern Ireland warned the public about cost-of-living scams. PSNI said possible approaches include false offers of energy refunds, energy discounts, tax rebates and cost-of-living payments.

    Among the examples identified were text messages containing malicious links and claiming that recipients must pay a fee or enter bank details to “unlock” or claim a £100 oil voucher.

    CLAIM

    A text offering a £100 oil voucher or energy-support payment can be trusted if it appears to refer to a genuine cost-of-living issue.

    EVIDENCE

    PSNI’s warning describes several methods being used by fraudsters in Northern Ireland:

    • fake application texts containing malicious links;
    • calls impersonating the Department for Communities or local councils;
    • phishing emails designed to resemble official NI Direct or government portals;
    • requests for personal details, banking information or payment.

    The common feature is not the exact wording of the approach. It is the attempt to move the recipient from an unsolicited message into a process controlled by the sender.

    TEST

    If you receive an unexpected message about an oil voucher, energy refund or cost-of-living payment:

    1. Do not click the supplied link.
    2. Do not pay a fee to “unlock” support.
    3. Do not provide banking details in response to the message.
    4. Check the offer through an official government or council channel reached independently.
    5. Preserve the message if you believe it may be fraudulent, including the sender details and URL.

    VERDICT: V1 VERIFIED

    PSNI has expressly warned Northern Ireland consumers about fake £100 oil-voucher application texts and related cost-of-living impersonation approaches. The existence of that warning is verified from a primary law-enforcement source.

    A particular message still has to be assessed on its own evidence. The warning does not prove that every reference to energy support is fraudulent.

    ACTION

    If you receive an unexpected offer, leave the message and verify the scheme independently before providing anything. If you have already supplied banking information or sent money, contact your bank or payment provider promptly using a trusted channel and follow the appropriate fraud-reporting route.

    Primary source: PSNI: Public advised to be on guard against fraudsters, 9 September 2026.


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • Car-Finance Claim Messages: Verify Before You Respond

    Car-Finance Claim Messages: Verify Before You Respond

    A message about a car-finance claim can look plausible, timely and professional. None of those things proves who sent it.

    On 22 September 2026, the Financial Conduct Authority added www.approvedcarclaim.com and www.pcp.ashley-howard.co.uk / www.ppi.ashley-howard.co.uk to its Warning List. In each warning the FCA states that the firm is not authorised by it and may be targeting people in the UK.

    The important consumer lesson is broader than any one website: when a subject is already receiving widespread public attention, a message that appears topical can feel credible before its identity has actually been checked.

    CLAIM

    If a message correctly refers to car-finance compensation or PCP claims, the sender is probably a legitimate claims or financial-services business.

    EVIDENCE

    The FCA’s Warning List shows that unauthorised firms can operate in the same subject areas consumers are actively searching for. The regulator also warns that firms may provide contact details belonging to another business or individual so that an approach appears genuine.

    TEST

    Before clicking, replying or providing personal details, separate the subject of the message from the identity of the sender.

    1. Do not use the link in the message to verify the sender. Search independently.
    2. Check the exact legal or trading name. Similar names are not the same identity.
    3. Use the FCA Firm Checker where regulated activity is involved. Compare the contact details shown there with the ones used to approach you.
    4. Do not assume an existing car-finance relationship authenticates a new claims company.
    5. Be cautious with requests for identity documents, bank details, fees or authority to act. Establish who you are dealing with first.

    VERDICT: V1 VERIFIED

    The FCA added car-finance and PCP-related websites to its Warning List on 22 September 2026. That is verified primary-source evidence that consumers should independently check the identity and regulatory status of businesses approaching them about this subject.

    It does not follow that every unsolicited car-finance claim message is fraudulent. The correct response is verification, not assumption.

    ACTION

    If you receive a car-finance compensation message, preserve it before deleting anything. Record the sender, telephone number, email address, website and any company or FCA reference numbers supplied. Then verify those details independently.

    If the approach involves a firm on the FCA Warning List, follow the FCA’s guidance and avoid dealing with it.

    Primary sources: FCA Warning List; FCA warning: www.approvedcarclaim.com; FCA warning: www.pcp.ashley-howard.co.uk / www.ppi.ashley-howard.co.uk.


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. Mention of a website or firm reflects the cited FCA warning and is not an independent finding of criminal conduct. This publication provides general information, not legal or financial advice.