UK Scam Intelligence Report — September 2026
This is CyberAware UK's monthly threat briefing, produced from DarkWatch dark-web monitoring, verified phishing intel feeds, and human editorial review. Figures below are as of early September 2026 (data last updated 6 September 2026, 17:00 UTC).
Executive summary
- Phishing remains the overwhelming threat to UK consumers: 97% of all items logged in the past 31 days were phishing-related, and feed-wide severity is dominated by high-risk items.
- Scammers are impersonating banking, telecoms, retail and public-service brands in near-equal measure — BT and Sky lead the brand list, closely followed by Amazon, the major banks, PayPal and Vodafone.
- The DarkWatch dark-web monitoring network is running normally, with five live monitoring targets polled hourly and no mass-impact incident detected. The three currently open public alerts are routine medium-risk "site live" notices.
Key numbers this month
As of early September 2026:
- 21,067 intelligence items were logged in the 31 days from 7 August to 6 September 2026.
- 20,458 (97%) were phishing; 20,553 (98%) were rated high severity, with a further 222 rated critical.
- The full verified intelligence feed now holds 33,957 items spanning mid-July to 6 September — 33,227 high severity, 262 critical, 247 medium and 221 low.
- 33,065 items (97%) have direct UK relevance, with a further 432 flagged as indirectly relevant to the UK.
- DarkWatch has recorded 448,449 dark-web captures and tracks 7,456 entities across its monitoring targets.
- More than 1,400 alerts have been logged to date; the 3 currently open public alerts are routine "site live" monitoring notices rated medium risk — none indicates an active mass-impact UK incident.
Top threat categories
Breakdown of the full 33,957-item feed:
- Phishing — 33,135 items (97.6%). Phishing URLs, lookalike pages and credential-harvesting campaigns dominate everything else combined.
- Dark-web intelligence — 340 items. Forum chatter and market activity collated from monitored .onion sources.
- Vulnerabilities — 232 items. Software flaws with exploitation potential, largely from CISA and vendor advisories.
- Malware — 80 items, data breaches — 78 items, ransomware — 37 items, credential leaks — 22 items.
- Fraud networks — 8 items and scam alerts — 5 items: the smallest but most directly consumer-relevant categories, and the ones CyberAware UK prioritises for human review.
Brands and sectors impersonated
Tagged brand data across the feed shows the most impersonated brands in UK-targeted phishing this month:
- Telecoms: BT (4,005 items), Sky (4,004), Vodafone (1,886)
- Retail & marketplaces: Amazon (3,143), PayPal (2,581), Royal Mail (833)
- Banking: Nationwide (3,015), Barclays (2,943), Lloyds (2,939), HSBC (2,758), TSB (1,210), NatWest (1,048), Halifax (552)
- Public services: NHS (956), gov.uk (408), DVLA (369)
The pattern is consistent with what our editorial team sees in consumer reports: billing threats from telecoms brands, delivery-fee texts from couriers, and fraud-team calls from banks. The NHS and DVLA figures are a reminder that scammers also weaponise public services to create urgency. Specific phishing domains rotate constantly and are not listed here because they change within hours — the brands stay the same, the URLs don't.
What CyberAware UK recommends
- Couriers, banks and government-style threats follow the same script — unexpected contact, urgency, and a request for money, codes or card details. Treat any unsolicited request for payment or personal data as a scam until verified on an official channel.
- Never click links in unexpected texts or emails. Track parcels via the courier's official app or website, and log in to banking only through your bank's app or site.
- Phone scams: if someone claims to be your bank, hang up and call back on 159 — the industry's verified banking number. Police and banks never send couriers to collect your card.
- Forward scam texts to 7726 (free) and scam emails to [email protected] — every report helps takedown and network blocking.
- Report losses to Action Fraud at actionfraud.police.uk or 0300 123 2040, and report to your bank first if money or card details are involved.
- Individuals and businesses: if you appear in a data breach, change that password immediately and enable two-factor authentication everywhere it's available. Check our breach and recovery guidance if your data may have been exposed.
Methodology
This report combines three sources:
- DarkWatch dark-web monitoring: hourly automated sweeps of CyberAware UK's monitored dark-web targets — ransomware leak sites, forums, search indexes and service mirrors. Monitoring has logged 448,449 captures and tracks 7,456 entities to date. See the live board at cyberawareuk.co.uk/darkwatch.
- Verified threat feeds: 33,957 items collated from URLScan.io (33,058 phishing URL scans) and editorial security sources including The Hacker News, BleepingComputer, Dark Reading, CISA Advisories, SANS ISC, Recorded Future, Krebs on Security and NCSC news.
- Human editorial verification: every figure quoted above has been reviewed by CyberAware UK's editorial team, and automated feed items marked verified are cross-checked against consumer scam reports before they inform recommendations.
All figures are as of early September 2026 and reflect data captured up to 6 September 2026, 17:00 UTC. We publish this briefing monthly; in between, the CyberAware UK Scam Checker and common UK scams guide cover day-to-day threats.
