
'Tis the season to be scammed: five tactics to watch out for this Christmas
Christmas can make familiar scams much easier to believe. From fake delivery messages to supplier fraud and phishing emails, here are five to watch out for.
Christmas gives scammers plenty to work with.
You’re expecting more deliveries. Businesses are processing invoices and end-of-year payments. People are buying gifts and vouchers. And with colleagues taking time off, you may be dealing with unfamiliar tasks and responsibilities.
It’s in this environment that scams become easier to believe, and easier to fall for.
The National Cyber Security Centre (NCSC) warns that criminals use current events and particular times of year to make scams seem more relevant. So, as Christmas approaches, here are five things for your team to stay on the lookout for.
1. Fake parcel delivery messages
Most of us get these messages all year round. But when you’re waiting for Christmas deliveries, a message about a missed parcel is much easier to believe.
It might ask you to confirm your address, rearrange a delivery or pay a small fee. Follow the link and you could end up on a fake website designed to look like the real thing, but set up to collect payment details, passwords or other personal information.
If you get an unexpected delivery message, don’t use the link. Go directly to the courier’s official website or app instead to check your delivery. That’s also the advice from the government’s Stop! Think Fraud festive shopping guidance.
2. Supplier invoices and changed payment details
This one is particularly important for businesses.
An email appears to come from a genuine supplier, telling you that their bank details have changed. The invoice might look completely normal. And the conversation may even appear to follow on from genuine emails you’ve received before. Which is why these scams are so dangerous.
The figures show how common this type of fraud can be. In the Home Office’s Economic Crime Survey 2024, fake invoice fraud was the most commonly experienced type of fraud, affecting 11% of UK businesses with employees. A further 7% had experienced mandate fraud, where criminals trick a business into changing payment details so money is diverted to them.
A request to change supplier payment details should always be checked independently. Call a contact you already know, using a telephone number you already hold. Don’t just rely on contact information in the email you’re trying to verify.
3. A message from the boss that isn’t from the boss
Could you make an urgent payment? Buy some gift cards for the team? Send a document over while someone’s out of the office?
Impersonation scams work because the request looks like it comes from someone you know and trust. And Christmas can make this kind of scam easier to pull off, particularly when people are working different hours, covering for colleagues, and unusual requests don’t seem quite so unusual.
The advice is simple. Don’t judge the request purely on how convincing the email or message looks.
If you get an unexpected request for money or sensitive information, contact the ‘sender’ another way to check. A quick call or message through a channel you normally use could be enough to expose the scam.
4. Microsoft 365 and password phishing
Some phishing emails are less interested in an immediate payment. They want your login details instead.
The message might say your Microsoft 365 password is about to expire (you might get similar messages about other services too), somebody has shared a document with you or there’s been an unusual sign-in. The link then leads to a convincing copy of a genuine login page.
Microsoft says it detected around 8.3 billion email-based phishing threats during the first three months of 2026, with 78% of them using links.
If you receive an unexpected login or security message, don’t use its link. Open Microsoft 365, or whichever service it claims to be from, in the way you normally would and check there.
This is also where multi-factor authentication (MFA) can make a difference. It means a stolen password alone may not be enough to access an account. The NCSC recommends two-step verification as part of its guidance on reducing the impact of phishing.
5. Fake Christmas offers, vouchers and websites
Black Friday deals, Christmas sales and gift vouchers create plenty of opportunities to tempt people with something that looks like a bargain.
Scam adverts can appear on websites and social media. Emails and messages may also lead to fake versions of genuine retail websites.
One thing to keep an eye on is the offer that’s about to ‘end soon’. The urgency they create is designed to make you act before you have time to think.
If it’s a retailer you recognise, visit its website yourself rather than using the link you’ve been sent. And if an unfamiliar website is offering something at a price that seems too good to be true. Well, it probably is. If it’s a retailer you don’t know, take a little time to research it first. Check reviews from sources you trust and look carefully at the web address before you buy.
Stop. Check. Confirm.
Nobody is going to spot every scam. That’s why it’s good to have a system to follow when something unexpected lands in your inbox.
- Stop. Give yourself a moment before acting on an unexpected request, especially if money or login details are involved.
- Check. Were you expecting the message? Does the request make sense? Can you reach the same account or service without using the link you’ve been sent?
- Confirm. For important requests, use another method you already trust. That could mean calling a supplier, messaging a colleague separately or checking with somebody in person. You can make this easier for your business by agreeing some clear rules. Supplier bank details, for example, could always require independent verification before they’re changed.
Where technology can help
Good processes reduce the chance of a scam succeeding. Technology can help catch threats that people miss.
Zen DNS Security can block access to domains associated with phishing and other malicious activity before users or devices connect to them.
Spotted something suspicious?
It’s worth reporting scams, even when you haven’t fallen for them.
As of July 2026, the NCSC says its work tackling reported scams has helped remove 454,800 scam URLs.
What to do next
Suspicious email: Forward it to report@phishing.gov.uk.
Suspicious text: Forward it free of charge to 7726.
Clicked a link or shared login details on a work device: The NCSC advises telling whoever looks after your IT or security as soon as possible. The same applies if you opened something suspicious.
Lost money or shared banking details: Contact your bank immediately. Businesses and individuals in England, Wales and Northern Ireland can also report fraud through Report Fraud. In Scotland, contact Police Scotland on 101.
Help protect your business from online threats
Explore Zen’s security solutions for your business.