Moanv
โ† All posts

6 July 2026 ยท 4 min read

The scams targeting Perthshire trades right now

Fake domain invoices, bogus directory listings, dodgy CIS refund texts. What they look like, and the one habit that stops nearly all of them.

Every one of these has landed on somebody local in the past year. None of them are clever. They work because they arrive on a busy day and look like a bill.

The domain renewal letter

You get a letter or invoice saying your web address is about to expire, usually for something like ยฃ95, often from a company with an official-sounding name.

It isn't from your registrar. It's either a straight scam or a "transfer offer" dressed up as a renewal โ€” the small print sometimes admits it's a solicitation, in type you'd need glasses for.

Your actual domain renewal is usually ยฃ10โ€“ยฃ20 a year, and it comes from whoever you registered with.

What to do: never pay a domain invoice that arrives by post. Log into your registrar and check the real renewal date yourself.

The directory listing that renews itself

A call or email asking you to "confirm your details" for a trade directory. You say yes to being listed. Six weeks later there's an invoice for a few hundred pounds and a contract you apparently agreed to on the phone.

What to do: never confirm details on an inbound call. "Send it to me in writing and I'll look at it" ends the conversation, and the genuine ones will happily do that.

The CIS refund text

A text or email saying you're due a tax refund, with a link. HMRC does not text you about refunds with a link.

If you're in the Construction Industry Scheme you probably are owed something, which is exactly why this one works โ€” it lands on a true thought.

What to do: never use the link. Go to your HMRC account directly, or ring your accountant.

The changed bank details email

The nastiest one, and the one that costs most.

You're doing work for a business. You get an email that looks like it's from your customer's accounts department, saying their bank details have changed. Or the reverse โ€” your customer gets an email that looks like it's from you, giving different details, and pays a stranger.

This is why it works: it's a real invoice, a real job, and the amounts are right. Someone has been reading the email chain.

What to do: any change of bank details gets verified by phone, on a number you already had. Not the number in the email. Every time, no exceptions, even when it's awkward.

The "we found a problem with your website" call

Someone rings claiming your website has a security issue, is about to be delisted from Google, or isn't compliant. They can fix it for a fee.

Google doesn't ring people. Neither does anyone else who found a genuine problem with your site.

What to do: hang up. If you're worried, ask whoever built your site.

The deposit that never turns into a job

Less common but it does the rounds: an enquiry for a big job, usually from out of the area, with a story about why they need to pay by cheque or transfer up front and then need some of it back.

If the money-in-money-out is more interesting to them than the job, it's not a job.

The one habit that stops nearly all of it

Never act on the contact details in the message.

Not the link, not the phone number, not the bank details. Go to the account you already have, or ring the number you already had.

That single rule handles the domain letters, the refund texts, the bank detail changes and most of the phone calls. It costs you two minutes and it's the closest thing there is to a general defence.

If one gets you

Report it to Action Fraud, and tell your bank straight away โ€” speed matters more than anything else with a payment that's gone the wrong way.

And tell somebody. There's no shame in it; these things are designed by people who do it full-time. The only thing that makes them less effective is other trades knowing what they look like.


Pass this on if you know someone who'd fall for the domain one. Almost everybody nearly has.