Join Us

Business Partner News | Festive Season Scam Awareness

3 December 2022

Allan Simpson, Director of Hotel DPO shares some top tips on how to avoid seasonal scammers.

The festive season approaches.  As the hospitality industry collectively breathes a sigh of relief at the prospect of more customers and increased sales of food, drink and accommodation, so online scammers lick their lips and rub their hands with glee at the prospect of making some easy money.

You see there is a new tradition you can add to your turkey dinner and plum duff.  At this time of year it is so much easier to separate the unwary from their own money.  And online scammers have become very, very good at it.

Why is it easier for scammers?

At this time of year people are different.  They are often busier.  They are under more pressure simply because Christmas is getting closer and there is so much to do and organise.  They might be short of cash, especially true nowadays as things cost so much more.  People carry out more transactions at this time of year, which means there is a wider range of purchase activity at risk, often with new or rarely used vendors.  Because of all this, many people are simply paying less attention to their own safety than they might do at other times of the year.

Which is all a scammer needs.  Just that slim opportunity to get access to someone.

You see there are two types of victim scammers like to prey upon:

  1. Those who are vulnerable to online scams, and
  2. Everyone who thinks they aren’t.

How do you protect yourself?

There are lots of different sources of online scams.  The key to protecting yourself and others around you is awareness.

The first thing to be aware of is that scams are carried out by criminals.  Organised crime, even in some cases rogue state activity.  They can also be carried out by enterprising individuals.  Collectively, we call them “cyber criminals”.

In all cases we find that they are good at what they do and have all the skills and resources they need to do their job.  They understand computers and the online world, which means they can automate large parts of their scam attacks.  They also understand people and their vulnerabilities.  Which means that when they do find their way to you as an individual, they know exactly which emotional buttons to press to get the results they want.

They also have one significant factor working in their favour:  They only need to get lucky occasionally.

You need to be vigilant all the time.

Your vigilance, as I noted above, is based on your own, personal awareness.  The next few lines offer some help.

Beware of:

The unexpected call

At this time of year, and especially in the current financial climate, you might receive calls from people claiming to be from any of the businesses you have been dealing with or some you might have been dreading hearing from, such as banks or those you might owe money to.  Alternatively government agencies or healthcare providers.

Were you expecting the call?  If not, be a healthy sceptic.  There is no need to be rude but you can simply terminate the call.  In fact I recommend you don’t get angry and get into an argument on the phone, it can make you vulnerable.  If the caller was legitimate they will find another way to contact you or prove their identity.  Scammers will sometimes try to pretend to be someone you know, or who works in the same place as you.

Scammers are relying on catching you when you are busy doing something else and not paying enough attention to the task of protecting yourself.

The seemingly innocent text message

Watch out for text messages.  If you don’t recognise the sender or the subject seems to be a bit unusual, delete it from your phone.

Anything containing a clickable link

Scam emails and text messages often contain a clickable link.  YOU MUST NOT CLICK LINKS IN MESSAGES if you are at all uncertain of who they come from.

There are quite legitimate reasons for sending links in emails – for example when you need to reset a password for an online account.  However in those cases you will have initiated this by completing a password reset form on a website.  Be sceptical about unexpected email messages or those claiming to be from a colleague or friend.  You can check the “sender” or “from” email address to make sure it’s really from the person you think you know.

If you work for a business with an IT department, you should check the email and link with them before clicking on anything.

Any email message with an attachment

Attachments can contain all sorts of nasty staff which can infect computers and networks.  Often these infections occur silently so you won’t be aware of what is happening until it is too late.

Don’t open attachments until you have verified they are legitimate.

Returning a call

If you are left a message asking you to return a call to a particular number, you should verify the calling entity and make sure you use their official contact details, not the details left in the message.  The same goes for contact information quoted in an email or text message.  When you do return a call try to use a different phone.  Scammers often use a technique where they are still on the line after you think you have hung up. When you think you have called a safe number they pretend to be whoever you thought you had dialled.  Using a different phone defeats this.

Sharing information and verifying your identity

Be very careful if someone calls you and asks you to verify anything other than your name. Don’t part with any of your personal information, even if they appear to know who you are.  If they are a legitimate caller, they ought to already know, they don’t need to ask you.  Don’t share in any call that you did not initiate yourself.

Pressure tactics

A legitimate organisation will never use pressure tactics to get you to do something, such as sharing your information or visiting a website page.  However the tactics scammers use will often mimic marketing promotions you may be used to seeing, such as urgency, scarcity or cut price offers.

“For GDPR”

Data protection legislation is often used as a reason for trying to trick you to reveal personal information.  If any caller uses the phrase, “for GDPR”, when asking you to verify any personal information, be very sceptical.

Too good to be true

If you receive a message or call containing an offer which appears to be too good to be true, it probably is.  Decline and delete.

Cute kittens

I have seen more scams start with a clickable picture of something cute on social media than any other source.  Don’t click on these images.  Don’t “like” them.  Don’t comment on them and definitely don’t share them!  Yes I know that makes you look really boring to all your social media pals but people get parted from their cash far too easily after they clicked on a cute picture.  It’s the equivalent of raising your hand and shouting “scam me!”.

What you can do: The Art of Self Defence – Data Protection Jiu Jitsu

Publishing your information

Be careful about publishing personal information on social media and the internet in general.  If you represent an organisation think carefully before publishing details of officials and office bearers on your website.  Criminals can use this data to mount a targeted attack on people they think might have access to resources such as bank accounts.  Or they can simply use a contact name, job title and email address to make their attack more plausible to their intended victims.

Sharing your information

Try to share less information whenever you are buying something or asking for information online.  What do organisations really need to know in order to sell you something? 

Be a healthy sceptic

Be sceptical if you are being asked for too much information.  Ask yourself, “why do they need this?”, “does this sound right?”, “why the hurry?”.  If in doubt, stop the process.  You can always start it again once you have convinced yourself all is well.  Or sought the advice of others.

Use verifiable contact information

If an organisation wants you to call them back, for example by clicking a link or calling a number contained in an email or text message.  Don’t use the details they provided.  Instead you should use contact information from a reliable source you can verify yourself.  For example, if you receive an email which says it’s from your bank, go and find the last letter or statement you received from them and use the contact details noted there.  Or go onto their website and verify contact information yourself.

Only provide information when you have initiated the enquiry yourself

Once you have made sure you are using the correct, safe, contact information and you have initiated the enquiry yourself, should you consider sharing your personal information.  There is less need to be sceptical in this case, however you should still keep the amount of data shared to a minimum.

Use the Santa Clause – Check it twice

Particularly at this time of year, do what Santa does, check everything twice.  Introduce a delay and breathing space into any interaction you are unsure of.  Check what is happening.  Ask a friend if it sounds “right”.  If you are in a business, check with someone who knows about these things, such as your IT department, or (if you have one) your DPO or data protection champion.

Reporting the incident

If you suspect you have either been targeted by, or have fallen victim to, a scam you should report the matter straight way to the appropriate authorities or departments.  You can find details online.  Do not try to tackle the problem all on your own.

Click ye not!

If you are not sure about a message, link or attachment, don’t click on it!

Be less of a target than the person next to you

Sometimes protecting yourself is as simple as being just that bit less attractive than those around you.  Taking simple steps to improve your online security helps.  If two-factor or multi-factor authentication is available for your online accounts, you should switch it on.  If you do nothing else as a result of reading this article, this is something you can do today.  It’s not foolproof but it does make you that bit harder to attack.

Slow down “Faster Payments”

Online banking and smartphone apps now offer ways to make payments instantly.  Most banks now have prompts which ask you to be sure you are making a safe payment.  You should be slowing down any payment request yourself long before you log into your online banking.  Ask yourself, “what is this for?” and “why am I doing this?”  Be wary of any need for urgency.

Use the Telephone Preference Service

To cut down on the number of unexpected sales calls you receive you can join the Telephone Preference Service (TPS).  This is a free service run by the Data & Marketing Association (the DMA) and all reputable companies are obliged to clean their databases against the TPS list.  It prevents unwanted sales calls.  Of course, scammers don’t care about this, however if your telephone number is TPS registered you will know that when you receive a call it is either from someone who knows you or a scammer.  Then you can decide what to do.

In conclusion

That last point is important. It is up to you. You have a choice, you can decide what to do in order to protect yourself.  I will admit that if you take up all of the actions I recommend here it will make you appear to be something of a social media and online killjoy.  Yet the alternative can be nasty.  I have been involved with many cases with online scams, some where people have lost thousands of pounds.  They are all unpleasant and each started with one innocuous call or a careless click.

Share this Article
Become a Member

Be part of our well-respected network, get trusted advice and take a positive approach to your learning and development.

Log in to your account

[nextend_social_login login=1]
Not A Member Yet? Join Us

Your business card may take a moment to be generated. You can save your business card by right clicking -> save image as, or holding down on the image on your phone.