Image of a phone showing parcel not delivered phishing scam

Summer brings longer days, staff annual leave, and a spike in phishing activity.

Scammers know that people are booking holidays, tracking parcels, and checking their phones on the go, often outside their usual routine. That distraction is exactly what attackers are counting on.

Two scams dominate this time of year: fake delivery texts and travel booking fraud. Both are simple, both are effective, and both are increasingly hitting business devices as well as personal ones.

Fake Delivery Texts: Small Message, Big Risk

You’ve probably seen one yourself: a text claiming a parcel couldn’t be delivered, with a link to “reschedule” or “pay a small redelivery fee.” With online shopping at its summer peak, these messages blend in easily.

The link usually leads to a convincing but fake courier site designed to harvest card details, or it prompts a malicious app download disguised as a tracking tool. On a personal phone, that’s bad enough. On a work phone with access to email, Teams, or company apps, it’s a foothold into your business.

Why it works:

  • Genuine delivery notifications are common, so a fake one doesn’t stand out
  • Urgency (“action needed within 24 hours”) pushes people to click without thinking
  • Mobile screens make it harder to spot a spoofed URL

Travel Booking Scams: Targeting the Holiday Mindset

The second summer classic is travel-related phishing – fake booking confirmations, “your flight has changed” emails, or too-good-to-be-true holiday deals shared via email or social media ads. These scams often mimic well-known airlines, hotel chains, or booking platforms convincingly enough to pass a quick glance.

For businesses, the risk isn’t just personal financial loss. If an employee books work travel, or simply checks personal email on a company laptop while researching holidays, one careless click can expose company credentials or install malware on a device that also touches business systems.

Why it works:

  • People expect travel confirmations and are less suspicious of them
  • Scammers often reference real airlines or booking platforms to add legitimacy
  • Employees are frequently multitasking between personal and work devices, especially with staff covering for colleagues on leave

Why Summer Specifically?

It’s not just coincidence. Summer creates the perfect conditions for phishing to succeed:

  • Thinner IT and security cover: with staff on annual leave, suspicious activity may go unnoticed for longer
  • More online activity: holiday bookings, parcel deliveries, and event tickets all increase message volume, making a fake one easier to hide among genuine ones
  • Device blending: personal phones and work devices are used interchangeably more than usual, especially with hybrid and remote arrangements

This seasonal pattern is a good reminder that phishing tactics constantly adapt – as we covered in our look at seasonal phishing tactics, attackers regularly reference trending events and time-of-year context to increase click-through rates.

How to Protect Your Business This Summer

1. Remind staff before they go, not after something happens A short reminder about delivery and travel scams before the summer rush costs nothing and takes two minutes to send round.

2. Reinforce the basics

  • Don’t click links in unexpected delivery or booking texts. Instead go directly to the courier or airline’s official app or website instead
  • Check sender details carefully, not just the display name
  • If in doubt, don’t act on the message at all

3. Make sure multi-factor authentication is switched on everywhere it can be Even if credentials are compromised through a fake site, MFA gives you a critical second layer of defence.

4. Have a clear reporting process Staff should know exactly who to flag a suspicious message to, and feel comfortable doing it, even if they’ve already clicked.

5. Keep an eye on the bigger picture Fake delivery texts and travel scams are just one seasonal example of the wider cybersecurity risks facing SMBs throughout the year. The tactics change with the calendar, but the underlying weak point – a distracted employee clicking too quickly — stays the same.

Get Ahead of It

If you’re not sure how exposed your business is to phishing right now, our free security audit is a straightforward way to find out – no obligation, just a clear picture of where you stand.

For more information on our wider security services, get in touch with the team at Gardner Systems.

If you’ve received a suspicious message, you can report it to Action Fraud or via the NCSC’s Suspicious Email Reporting Service.

Leave A Comment

related news & insights.