‘Tis the Season to be Wary

’Tis the Season to Be Wary

As we wrap up another year and head into the festive break, we’re all looking forward to time with family, a slower pace, and maybe even a wine (or three). It has been a busy couple of months at DPAS. You may have noticed that our CEO, Melanie, has gone on maternity leave after welcoming a beautiful little girl not long ago. That has seen a bit of a shift internally, with me taking on Mel’s role in the interim, and the wonderful Lauren stepping up as Head of Consultancy. We are also in the midst of recruiting another member of our consultancy team (exciting!), organising our 2026 conference, and of course putting together the staff party — so there’s not much winding down at DPAS just yet!

So, whilst many of us are full of festive cheer and excited for the end of the month, it seems like an apt time to remind you that this is also the time of year when scammers work overtime. With people distracted, busy, and shopping more than usual, cybercriminals see Christmas as the perfect opportunity to catch people off guard.

Losses to festive fraud exceed £11.5 million every Christmas in the UK, according to Action Fraud. TSB warns of a 35% spike in online shopping scams, and Experian reports a clear uptick in fraud at this time of year. All statistics that should make us hyper-vigilant, especially during the Christmas period. So, what should you look out for?

 

Online Shopping Fraud

A festive favourite. ITV recently reported on this: https://www.itv.com/news/2025-12-08/festive-fraudsters-targeting-retail-shops-with-ai-designed-fake-websites. Criminals set up professional-looking sites offering “too good to be true” deals on toys, game consoles, tech, clothing and designer goods (or whatever happens to be on trend).

Red flags:

  • Big brands at heavily discounted prices
  • No reviews or only newly-created ones
  • No physical address or returns policy

Tip: Stick to reputable retailers, check website age, and always look for https:// and a valid padlock symbol. Avoid following social media ad links; only access websites through trusted sources.

 

Delivery / Courier Scams

A big one at this time of year, and technically a type of phishing. These often appear as texts or emails claiming to be from a trusted delivery company, asking you to pay an unexpected fee or rearrange a delivery.

Red flags:

  • Being asked to follow a link
  • Requests for unexpected payment
  • A sense of urgency designed to make you act quickly

Tip: If you are ever in doubt, contact the delivery company directly — but do so by searching for a legitimate number or email address. Do not use the details included in the message.

 

Charity & Donation Scams

Another regular contender. This is a form of social engineering where scammers ‘tug on your heartstrings’, encouraging you to make fast payments or donations (PayPal links, vouchers and gift cards are all big red flags).

Red flags:

  • Street collectors without ID
  • Fake websites with similar names to real charities
  • Urgent emotional pleas
  • Pressure to donate “now”
  • Mentions of PayPal, gift cards, or even cryptocurrency

Tip: Look up the charity on the official register before donating. Only donate via approved routes – trusted websites, official platforms, and if you’re unsure, contact customer services.

Action Fraud have put together a handy article which includes more examples and some general advice on how to keep yourself protected this Christmas. Read here.

It is also worth mentioning that this time of year is when we are most likely to share cute photos, work events, gift details, and location information on social media. I have written before about the risks of over-sharing here.

So, as we wind down for the year, and look forward to some well earned rest, remember that there are scrupulous individuals that see our down time as vulnerability. Don’t let them be the reason you can’t enjoy the January sales!

Picture of Nat Bennett

Nat Bennett

Nat is our Head of Consultancy. She leads our internal and external consultants, supporting with project delivery, mentoring, and development. Nat also delivers some of our BCS and CPD accredited training courses, bringing her experience in teaching to the DPAS training programme.

related posts

Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »

Get a Free Consultation