Tag: Website

  • The Hotel Message Knows Your Real Booking. It Can Still Be a Scam.

    VERDICT: STRONGLY VERIFIED (V4)

    A scam message can know where you are staying, when you are travelling and which property you booked.

    CLAIM

    Reservation-hijack scams use genuine booking context to send travellers convincing payment or card-verification requests through channels they already associate with their trip.

    EVIDENCE

    Gen Threat Labs reported in May 2026 that it had identified more than 350 accommodation-specific reservation-hijack scam flows across 50 countries. Its dataset included 31 compromised accommodations linked to the United Kingdom. Researchers analysed fraudulent landing pages, URLs, messages and in-app evidence and said victims had received reservation-specific information before being pushed to pages customised around the accommodation.

    Gen uses “compromised accommodation” carefully: it means reservation context associated with that accommodation was compromised and used in an intercepted attack flow. The source of the compromise could vary, including accommodation accounts, partner accounts, email, property-management systems or third-party services.

    TEST

    This evidence establishes the attack model and UK presence, but it does not prove that Booking.com itself was the source of every data compromise or that all attacks used the same malware chain. TVD therefore does not make either claim.

    VERDICT

    V4 — Strongly Verified. The mechanism is strongly supported by detailed threat research with UK cases in the dataset; attribution of individual compromise points varies.

    How to prevent it

    • Do not treat correct booking information as proof that a payment request is genuine.
    • If asked to re-enter card details or make an unexpected payment, open the booking service independently rather than following the supplied link.
    • Contact the accommodation using independently verified details if anything has changed.
    • If you entered card details into a suspicious page, contact your card issuer promptly.

    Warning signs

    • A message knows genuine booking details but unexpectedly asks you to re-enter payment information.
    • You are told the reservation will be cancelled unless you make another payment or verification payment.
    • The link opens a payment page outside the route you normally use to manage the booking.

    What to do if you responded

    Contact your payment provider promptly if you entered payment details or made a payment. Open the booking platform independently, check the reservation and contact the accommodation through independently verified details. Preserve the message and URL.

    Where to report it

    Report the message to the booking platform or accommodation through its genuine channels and report financial loss through the appropriate official fraud-reporting route. See Fraud First Aid.

    Source: Gen Threat Labs, “When Hotel Scams Know Your Booking”, 28 May 2026, plus its March 2026 Reservation Hijack investigation.

    Evidence boundary: TVD does not attribute all reservation-hijack attacks to any single booking platform, accommodation provider or software company.

  • The One-Time Passcode That Adds Your Card to a Criminal’s Digital Wallet

    VERDICT: STRONGLY VERIFIED (V4)

    A genuine one-time passcode can authorise the wrong thing if you misunderstand what it is asking you to approve.

    CLAIM

    Criminals can use card details entered into a fake shopping or delivery page to begin adding the victim’s card to a digital wallet on the criminal’s device, then trick the victim into supplying the OTP needed to complete wallet setup.

    EVIDENCE

    Which? documented the mechanism in 2025 after work involving Cifas, the Cyber Defence Alliance and UK Finance. Its investigation found that many card providers still offered SMS OTPs as one method of approving cards being added to digital wallets.

    In July 2026 Which? documented a victim who lost more than £18,000 after fraudsters persuaded him to provide an OTP which they used to add his Revolut card to an Apple Pay wallet, followed by fraudulent spending.

    TEST

    The evidence establishes the mechanism and documented victim cases. The public evidence used here is principally consumer and industry investigation rather than a national police prevalence dataset, so TVD does not estimate how many UK victims have experienced this specific technique.

    VERDICT

    V4 — Strongly Verified.

    How to prevent it

    • Read the entire OTP message before entering or sharing the code.
    • If the message says the code is for adding a card to Apple Pay, Google Wallet or another wallet when that is not what you are doing, stop immediately.
    • Never assume a genuine bank OTP means the website that triggered it is genuine.
    • If an unfamiliar wallet has been linked to your card, contact your card issuer immediately.

    Warning signs

    • An OTP message refers to adding your card to a digital wallet when you are only trying to make a purchase or delivery payment.
    • A caller or webpage asks you to enter an OTP without clearly explaining the action it authorises.
    • Your banking app shows a new wallet or device you do not recognise.

    What to do if you responded

    Contact your card issuer immediately, explain that your card may have been added to an unauthorised digital wallet, review recent transactions and ask the issuer to secure the card and linked wallet access.

    Where to report it

    Report unauthorised transactions to your bank or card issuer first, then use the appropriate official fraud-reporting route. See Fraud First Aid.

    Sources: Which? investigations, August 2025 and July 2026, drawing on industry evidence and a documented victim case.

    Evidence boundary: digital-wallet services themselves are legitimate. The fraud involves criminals abusing card-provisioning and social-engineering processes.

  • The Trademark Email That Says Someone Else Is About to Take Your Business Name

    VERDICT: VERIFIED (V5)

    The message sounds like professional legal correspondence: somebody else is supposedly about to register your business or brand name, but you have one last chance to act first.

    CLAIM

    Businesses are receiving trademark approaches that misuse the identities or regulatory details of genuine solicitors and firms.

    EVIDENCE

    The Solicitors Regulation Authority (SRA) has issued repeated alerts during 2026 describing closely similar approaches. The emails tell recipients that a third party has approached the sender to register the recipient’s UK brand or company name and seek exclusive rights. The recipient is then invited to secure trademark registration first, with the sender offering assistance.

    SRA alerts dated 8 April, 7 May, 13 May, 16 June, 13 July, 16 July, 19 August, 9 September and 10 September 2026 document variants misusing names or details associated with genuine solicitors or firms.

    TEST

    The repetition across separate SRA alerts establishes the recurring method. It does not establish that every approach came from one criminal group, and TVD makes no such attribution.

    VERDICT

    V5 — Verified.

    How to prevent it

    • Do not treat an SRA number or a genuine solicitor’s name as proof that the sender is that person.
    • Look up the solicitor or firm independently using the SRA’s official records and use independently obtained contact details.
    • Do not use the telephone number, email address or website supplied in the unexpected message to perform that verification.
    • If a trademark issue may be genuine, verify it independently before paying or instructing anyone.

    Warning signs

    • An unsolicited legal-looking email says somebody else is about to register your business or brand name.
    • You are pressured to instruct the sender immediately to protect the name.
    • The sender uses genuine-looking solicitor or SRA details but contact information does not match independently verified records.

    What to do if you responded

    Stop further payment or correspondence until the sender has been independently verified. If you paid, contact your bank. If you supplied account credentials, secure them. Preserve the original email, headers, attachments and payment instructions.

    Where to report it

    Check and report suspected solicitor impersonation through the SRA’s official channels and use the appropriate fraud-reporting route if money was lost. See Fraud First Aid.

    Sources: Solicitors Regulation Authority scam alerts published throughout April–September 2026.

    Evidence boundary: genuine solicitors and firms named in SRA alerts are victims of identity/detail misuse; TVD does not suggest they participated in the scam.

  • Your Pension Provider May Be Talking to a Fraudster Who Is Pretending to Be You

    VERDICT: VERIFIED (V5)

    Some pension fraud no longer depends on persuading the saver to make a transfer. The attacker may instead try to convince the pension scheme that they are the saver.

    CLAIM

    Fraudsters are using hacking and impersonation techniques to gain unauthorised access to pension accounts and attempt to bypass scheme security.

    EVIDENCE

    The Pensions Regulator (TPR) published an industry alert after an analyst seconded to the National Fraud Intelligence Bureau examined Action Fraud reports received between October 2024 and March 2025. TPR said almost a third of the reports analysed referenced attempts to bypass pension-scheme defences and exploit security vulnerabilities to gain unauthorised access to members’ accounts.

    Methods identified by TPR included hacking a member’s email to obtain correspondence with the pension scheme, then impersonating the member and attempting to change beneficiary bank details. TPR also identified attempts involving fake pension accounts, poorly secured credentials and diversion of deceased members’ pension funds. Members aged 50–69 represented 55% of reported victims in the analysis.

    TEST

    The finding comes from the pensions regulator and is based on analysed fraud reports. The “almost a third” figure applies to the reports in that specific October 2024–March 2025 analysis; it must not be presented as one third of all UK pension fraud.

    VERDICT

    V5 — Verified. The impersonation/account-takeover technique is directly documented by TPR.

    How to prevent it

    • Turn on two-step verification for your email and pension accounts where available.
    • Use a unique password for the email account connected to your pension.
    • Check that your pension provider holds your correct contact details.
    • Treat unexpected notifications of changed bank or contact details as urgent and contact the scheme through a known route.

    Warning signs

    • An unexpected pension notification says your bank, beneficiary or contact details have changed.
    • You receive password-reset or login alerts you did not initiate.
    • Pension correspondence disappears from or appears unexpectedly in a compromised email account.

    What to do if you responded

    Contact the pension scheme using independently verified details, ask whether any account, beneficiary or payment instructions have changed, secure the linked email account and change reused passwords. Preserve security alerts and correspondence.

    Where to report it

    Tell the pension provider immediately. If fraud or attempted fraud is identified, use the appropriate official fraud-reporting route. See Fraud First Aid if money or account access may already be affected.

    Source: The Pensions Regulator, “Industry alert: impersonation fraud”, published September 2025 and updated January 2026.

    Evidence boundary: the regulator establishes the technique and the characteristics of the analysed reports. TVD is not attributing failures to any particular pension provider.

  • Before You Scan That QR Code

    Before You Scan That QR Code

    A QR code is not evidence of fraud. But fraudulent ones have led to reported losses. Here is what the evidence shows, and a ten-second check to run before you scan.

    Imagine you have just parked. On the payment sign is a QR code, next to a name and logo you recognise. You lift your phone to scan it. Nothing about the moment feels unusual, and millions of legitimate QR codes are used safely.

    This is a hypothetical, not a case study. But it points to a question that fraud can exploit: how do you know the code belongs to the organisation whose name is printed beside it?

    The claim we are testing

    A simple version of this story would say “QR codes are dangerous”. That is not what the evidence shows, so we tested something narrower. Can a fraudulent QR code send a person to a fraudulent destination? And can an ordinary person reduce that risk by checking where a code leads before acting?

    First, the jargon

    “Quishing” combines “QR” and “phishing”. Phishing is fraud that impersonates a trusted organisation to get you to hand over money or information. Quishing does the same job, but the bait is a QR code rather than a link or an attachment. That is all the terminology you need.

    What the evidence shows

    Between April 2024 and April 2025, Action Fraud recorded 784 reports involving fraudulent QR codes, with reported losses approaching £3.5 million.

    That is a documented, measurable harm. It is also easy to over-read, so here is what the figure is not.

    It is not the total cost of QR-code fraud. It counts reports received during a defined period. This evidence cannot tell us how many incidents were never reported.

    It is not a measure of how common the problem is. 784 reports does not tell us how many fraudulent codes exist, how many people scanned them, or how likely any single scan is to end in a loss.

    It is not a trend. The evidence covers one period. It does not show whether this type of fraud is rising, falling or steady, and we make no claim either way.

    Why a QR code is useful to a fraudster

    A QR code is a picture that stores information, very often a web address. The difficulty is that the destination encoded in a QR code is not directly readable by the human eye. A web address printed on a sign can be read and judged before you type anything. A QR code generally requires a device to decode the destination before you can assess it. Many phones now show a preview of the address before opening it, which lets you check first, but that is an extra step and it only helps if you look at it.

    The code is also just an image, so it can be replaced, overlaid or distributed. The general risks include:

    • a fraudulent sticker placed over a genuine code;
    • a fake notice carrying a code of its own;
    • a code redirecting someone away from a legitimate payment system;
    • a message impersonating a legitimate organisation and containing a code.

    Action Fraud’s release said quishing occurred most frequently in car parks, and described criminals using stickers to tamper with QR codes on parking machines. This article does not name any operator, and nothing here should be read as suggesting that any particular organisation’s signs are affected.

    How the scam works

    code → destination → impersonation → request → potential loss

    The code is the doorway, not the room. It points to a destination, which might be a fake payment page, a page built to capture your login details, a site impersonating a genuine organisation, or another malicious address. The page looks like the organisation you expected. Then comes the request: pay here, sign in here, confirm your details.

    Only if that request succeeds is there a loss. The fraud depends on what happens after the scan, not on the act of scanning. This article makes no claim that scanning a code, on its own, installs anything on your phone.

    The test: warning sign or proof?

    Here is where a sceptical reader should slow down, because a lot of consumer advice blurs two different things.

    • A QR code being present does not equal fraud.
    • An unfamiliar QR code does not equal fraud.
    • A QR code on a parking meter does not automatically mean fraud.

    The risk rises where the code looks physically added or replaced; the web address does not correspond with the organisation you expected; the site asks for information you did not expect to give; payment or login details are requested unexpectedly; urgency discourages checking; or you were pointed to the code by unsolicited contact.

    Each of these is a risk indicator. None is proof of fraud. An indicator tells you to slow down and verify. Equally, the absence of indicators does not prove a code is safe.

    THE 10-SECOND QR CHECK

    A warning check, not a guarantee. It will not catch every fraudulent code.

    1. LOOK. Before scanning a public code, inspect it. Does it look like a sticker placed over another code? Does the sign look altered? Does anything clash with the surrounding branding?

    2. PREVIEW. Use your phone’s built-in camera or QR function. Where your device shows a preview, read the destination address before you open it.

    3. CHECK THE DOMAIN. Ask: is this actually the organisation I meant to visit? A familiar logo is not enough. The web address is what matters.

    4. WHEN MONEY IS INVOLVED, VERIFY INDEPENDENTLY. For parking, bills, deliveries, accounts or similar payments, reach the organisation another way: its official app, a website you type in yourself, or another verified contact method.

    5. STOP IF SOMETHING CHANGES. If a code that seemed to exist for one purpose suddenly asks for banking credentials, passwords, unusual personal information, cryptocurrency or unexpected authentication details, stop and verify before going further.

    Already scanned one?

    Scanning a code does not automatically mean you have been defrauded or infected. What matters is what happened next.

    WHAT TO DO IF YOU’VE ALREADY SCANNED ONE

    You only opened the page. If it looks suspicious, close it. Do not enter credentials or make a payment.

    You entered a password. Change it through the genuine website or app. If you use the same password elsewhere, change it there too.

    You entered card or bank details, or sent money. Contact your bank or payment provider promptly, using a contact method you have verified independently.

    You downloaded software. Use your device’s security processes and get reputable technical help where needed.

    Then report it. In England, Wales and Northern Ireland, use Report Fraud online or call 0300 123 2040. In Scotland, contact Police Scotland on 101.

    Where to report

    The figures in this article come from Action Fraud, which operated the reporting service when the cases were recorded. On 4 December 2025, Action Fraud was replaced by Report Fraud for England, Wales and Northern Ireland.

    If you need to report fraud or cybercrime now, use Report Fraud online or call 0300 123 2040. If you live in Scotland, or the crime happened there, contact Police Scotland on 101.

    If you are in Northern Ireland: the evidence here does not show that Northern Ireland has a particular QR-code problem, and we are not suggesting it does. The national fraud-reporting system behind these figures includes Northern Ireland, and the protective steps in this article apply here exactly as they do elsewhere.

    What remains unresolved

    Action Fraud’s release does not provide an exact breakdown of the 784 reports between physical locations and codes delivered in messages. We also do not know how common fraudulent codes are compared with legitimate ones, or whether reports are rising or falling. A verified threat is not the same as a measured epidemic, and this article does not claim one.

    VERDICT

    VERIFIED THREAT: VERIFY BEFORE ACTING

    Action Fraud recorded 784 reports involving fraudulent QR codes between April 2024 and April 2025, with reported losses approaching £3.5 million.

    But a QR code is not suspicious merely because it exists. The important point is where the code sends you, and whether that destination is genuinely connected to the organisation you meant to deal with.

    Evidence grade: V2, Strongly Supported

    Sources

    1. Action Fraud, “New quishing alert: £3.5 million lost last year to fraudulent QR codes”, 20 June 2025.
    2. Report Fraud, “Report Fraud service goes live”, 4 December 2025.
  • The £100 Oil Voucher Message: Check Before You Click

    The £100 Oil Voucher Message: Check Before You Click

    A message offering help with heating costs can arrive at exactly the moment a household wants it to be genuine.

    On 9 September 2026, the Police Service of Northern Ireland warned the public about cost-of-living scams. PSNI said possible approaches include false offers of energy refunds, energy discounts, tax rebates and cost-of-living payments.

    Among the examples identified were text messages containing malicious links and claiming that recipients must pay a fee or enter bank details to “unlock” or claim a £100 oil voucher.

    CLAIM

    A text offering a £100 oil voucher or energy-support payment can be trusted if it appears to refer to a genuine cost-of-living issue.

    EVIDENCE

    PSNI’s warning describes several methods being used by fraudsters in Northern Ireland:

    • fake application texts containing malicious links;
    • calls impersonating the Department for Communities or local councils;
    • phishing emails designed to resemble official NI Direct or government portals;
    • requests for personal details, banking information or payment.

    The common feature is not the exact wording of the approach. It is the attempt to move the recipient from an unsolicited message into a process controlled by the sender.

    TEST

    If you receive an unexpected message about an oil voucher, energy refund or cost-of-living payment:

    1. Do not click the supplied link.
    2. Do not pay a fee to “unlock” support.
    3. Do not provide banking details in response to the message.
    4. Check the offer through an official government or council channel reached independently.
    5. Preserve the message if you believe it may be fraudulent, including the sender details and URL.

    VERDICT: V1 VERIFIED

    PSNI has expressly warned Northern Ireland consumers about fake £100 oil-voucher application texts and related cost-of-living impersonation approaches. The existence of that warning is verified from a primary law-enforcement source.

    A particular message still has to be assessed on its own evidence. The warning does not prove that every reference to energy support is fraudulent.

    ACTION

    If you receive an unexpected offer, leave the message and verify the scheme independently before providing anything. If you have already supplied banking information or sent money, contact your bank or payment provider promptly using a trusted channel and follow the appropriate fraud-reporting route.

    Primary source: PSNI: Public advised to be on guard against fraudsters, 9 September 2026.


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • Car-Finance Claim Messages: Verify Before You Respond

    Car-Finance Claim Messages: Verify Before You Respond

    A message about a car-finance claim can look plausible, timely and professional. None of those things proves who sent it.

    On 22 September 2026, the Financial Conduct Authority added www.approvedcarclaim.com and www.pcp.ashley-howard.co.uk / www.ppi.ashley-howard.co.uk to its Warning List. In each warning the FCA states that the firm is not authorised by it and may be targeting people in the UK.

    The important consumer lesson is broader than any one website: when a subject is already receiving widespread public attention, a message that appears topical can feel credible before its identity has actually been checked.

    CLAIM

    If a message correctly refers to car-finance compensation or PCP claims, the sender is probably a legitimate claims or financial-services business.

    EVIDENCE

    The FCA’s Warning List shows that unauthorised firms can operate in the same subject areas consumers are actively searching for. The regulator also warns that firms may provide contact details belonging to another business or individual so that an approach appears genuine.

    TEST

    Before clicking, replying or providing personal details, separate the subject of the message from the identity of the sender.

    1. Do not use the link in the message to verify the sender. Search independently.
    2. Check the exact legal or trading name. Similar names are not the same identity.
    3. Use the FCA Firm Checker where regulated activity is involved. Compare the contact details shown there with the ones used to approach you.
    4. Do not assume an existing car-finance relationship authenticates a new claims company.
    5. Be cautious with requests for identity documents, bank details, fees or authority to act. Establish who you are dealing with first.

    VERDICT: V1 VERIFIED

    The FCA added car-finance and PCP-related websites to its Warning List on 22 September 2026. That is verified primary-source evidence that consumers should independently check the identity and regulatory status of businesses approaching them about this subject.

    It does not follow that every unsolicited car-finance claim message is fraudulent. The correct response is verification, not assumption.

    ACTION

    If you receive a car-finance compensation message, preserve it before deleting anything. Record the sender, telephone number, email address, website and any company or FCA reference numbers supplied. Then verify those details independently.

    If the approach involves a firm on the FCA Warning List, follow the FCA’s guidance and avoid dealing with it.

    Primary sources: FCA Warning List; FCA warning: www.approvedcarclaim.com; FCA warning: www.pcp.ashley-howard.co.uk / www.ppi.ashley-howard.co.uk.


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. Mention of a website or firm reflects the cited FCA warning and is not an independent finding of criminal conduct. This publication provides general information, not legal or financial advice.

  • A Company Number Is Not Proof: How to Verify a Business Website

    A Company Number Is Not Proof: How to Verify a Business Website

    A company number can be genuine while the website displaying it is not.

    On 23 September 2026, the Financial Conduct Authority published a warning about MyCarSecurity.com. The FCA stated that the unauthorised firm had no association with Tide Group Holdings Ltd and was falsely claiming the genuine UK company’s registered number.

    That example demonstrates an important verification principle: finding a real company number is only the beginning of a check, not the end of it.

    CLAIM

    If a website displays a company number that exists at Companies House, the website has proved that it belongs to that company.

    EVIDENCE

    The FCA warning provides a current example where a genuine registered company number was, according to the regulator, being used by an unauthorised firm with no association to the genuine company.

    A registration record can establish that a company exists. It does not automatically establish that the website, email address, telephone number or bank account you are dealing with is controlled by that company.

    TEST

    When a website gives you a company number, cross-check the identity rather than merely confirming that the number exists.

    1. Search the number independently. Enter it yourself into Companies House rather than following a supplied link.
    2. Compare the legal name. Does the registered company name match the business identity being presented?
    3. Compare contact details. Check addresses, telephone numbers and email domains against reliable independent sources.
    4. Check regulatory status where relevant. For financial services, use the FCA Firm Checker or Financial Services Register independently.
    5. Verify payment instructions separately. A matching company number does not authenticate a bank account.

    VERDICT: V1 VERIFIED

    The proposition that a company number alone proves the identity of a website is unsupported. The FCA’s 23 September warning provides primary-source evidence of a genuine registered number allegedly being used by an unrelated unauthorised firm.

    The correct conclusion is narrower: a company number can help identify a registered entity, but the connection between that entity and the website or person contacting you must be verified separately.

    ACTION

    If a website is asking for money, financial information or identity documents, do not treat a Companies House number, padlock icon or polished website as authentication. Cross-check the business through independent sources and contact it using details obtained independently.

    Primary sources: FCA: MyCarSecurity.com warning; FCA: How to check a firm or individual is authorised.


    The FCA warning concerns the entity and website identified in the FCA notice. The Verification Desk has not independently determined the conduct of any individual. This publication provides general information, not legal or financial advice.

  • Debt Help or Sales Funnel? Four Red Flags Before You Agree

    Debt Help or Sales Funnel? Four Red Flags Before You Agree

    Debt problems create urgency. That urgency can also make people easier to pressure.

    On 22 September 2026, the Financial Conduct Authority warned consumers to watch for red flags when seeking debt advice. The regulator said some people are being steered towards fee-paying debt solutions that may not suit their circumstances, sometimes through high-pressure sales tactics, misleading information or advisers without the appropriate permissions.

    CLAIM

    A persuasive debt-help advert, telephone call or WhatsApp conversation is enough to show that the advice is legitimate and suitable.

    EVIDENCE

    The FCA’s warning lists four red flags. The first is pressure tactics: being hassled or repeatedly contacted, particularly after an online enquiry or unexpected phone call, and being pushed to agree quickly over the phone or WhatsApp. The second is changing details: being asked or encouraged to alter income or outgoings on a form, or being coached on what to say. The third is failing to disclose, or discouraging, fee-free alternatives: being steered towards a fee-charging solution, such as an Individual Voluntary Arrangement or some debt management plans, without other options being properly explained first. The fourth is unclear identity: the person contacting you does not say who they work for, or their details do not match the firm’s official details.

    The FCA’s separate consumer guidance adds that firms which direct people to IVA websites are known as lead generators, and that they are not authorised to provide debt advice. It also says that adverts for IVAs do not always make clear that large fees are involved.

    TEST

    Before agreeing to a debt solution, run five independent checks.

    1. Identify the firm. Get its full legal name and contact details. Do not rely on the name displayed in a message or advert.
    2. Check authorisation independently. Use the FCA Firm Checker rather than a link supplied by the person contacting you.
    3. Ask what alternatives exist. A recommendation should not become a one-option sales pitch.
    4. Do not alter facts to qualify. If you are encouraged to change income, expenditure or other answers to fit a product, stop.
    5. Slow the decision down. Urgency is not evidence that a solution is right for you.

    VERDICT: V1 VERIFIED

    The FCA warning is current primary-source evidence. Pressure, coached answers, unclear identity and failure to explain alternatives are recognised red flags. Their presence does not by itself prove fraud, but it is sufficient reason to stop and verify independently before entering a debt solution.

    ACTION

    If you need debt help, use an independent route to find assistance. The FCA directs consumers to MoneyHelper for information on free, impartial debt advice and recommends checking firms through the FCA Firm Checker.

    If you believe you have been pressured into an unsuitable solution, preserve the advert, messages, telephone numbers, dates and documents you received. Do not rely only on screenshots: retain the surrounding context wherever possible.

    Primary sources: FCA: Debt advice warning: spot the red flags; FCA: Unauthorised or unsuitable debt advice.


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal or financial advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.