A holiday scam is a fraud attempt that exploits seasonal shopping, giving, or travel behavior to pressure people into sharing money, credentials, or personal data. Attackers often impersonate delivery firms, merchants, or charities and use urgency to reduce scrutiny. The core risk is social engineering, not the holiday itself.
Expanded Definition
A holiday scam is a fraud pattern that uses seasonal context to make a deceptive request seem normal, timely, or emotionally compelling. The scam may arrive by email, text, phone call, social post, fake storefront, or delivery notice, but the security issue is the same: the attacker tries to override scrutiny by borrowing the trust people place in gifts, travel, charities, and urgent logistics.
The term covers impersonation, payment diversion, credential theft, and data harvesting. It excludes genuine seasonal promotions and ordinary customer service contact. A common boundary mistake is treating the holiday setting as the threat itself, when the real mechanism is social engineering plus a believable pretext. That distinction matters because the same fraud techniques appear outside holiday periods, and the controls should therefore focus on verification, payment hygiene, and response discipline rather than the calendar alone.
Guidance vs consensus: there is broad agreement that holiday scams are a social engineering problem, but organisations differ on whether the term should include only consumer fraud or also workplace-targeted deception during seasonal activity. NHI Management Group uses the broader security interpretation when the scam targets money, identity data, or access credentials.
Examples and Use Cases
Holiday scams show up in several repeatable forms that exploit seasonal attention, rushed decision-making, and higher transaction volume. The practical signal is not the holiday theme by itself, but the combination of urgency, spoofed authority, and an ask that bypasses normal verification.
- A fake delivery notice asks the recipient to pay a small fee or confirm details through a link that leads to credential theft or card fraud.
- A spoofed charity appeal uses emotional pressure and a familiar seasonal cause to divert donations away from the real organisation.
- A travel-related message claims a booking problem or refund delay and pushes the victim to open an attachment or re-enter account details.
- A fake merchant site advertises a limited-time seasonal deal, then collects payment data without delivering goods.
- An internal impersonation attack uses year-end workload and holiday absence to request a rushed payment change or gift-card purchase.
These patterns often trade on speed over inspection: the more the message asks the recipient to act immediately, the less time there is to verify the sender, the domain, or the payment destination.
Security Implications
Holiday scams matter because they convert ordinary seasonal activity into a higher-yield deception channel. When people expect more parcels, more charity appeals, and more travel updates, suspicious messages blend into normal behaviour and are more likely to be acted on quickly. The consequence can be direct financial loss, credential compromise, identity theft, or secondary account abuse if the scam captures login details or payment information.
They also create operational friction for organisations. Support teams may see spikes in reporting, disputed transactions, refund queries, and account recovery requests. If a scam imitates a business process, staff may approve a payment or data request that would normally fail scrutiny. The observable symptom is often not a technical alert but an unusual pattern of user confusion, duplicate messages, or external requests that look just plausible enough to slip past routine checks.
For security teams, the practical failure condition is reliance on message content alone. Seasonal lures are effective because they mimic legitimate timing, not because they use novel malware. That means filtering, user awareness, and transaction verification all need to work together.
Domain and Governance Relevance
Holiday scams sit primarily in fraud, consumer protection, and social engineering, but they also matter to cybersecurity governance because they test how well an organisation verifies high-pressure requests. The issue is broader than email security: the same pretext can be used to redirect payments, harvest customer data, or coerce staff into bypassing normal approval paths.
Where identity is involved, the governance question becomes whether the organisation can distinguish a genuine seasonal interaction from a spoofed one. That affects account recovery, help-desk scripts, payment approval, and customer support workflows. The risk is especially visible when a scam tries to capture credentials first and monetise them later, because the initial fraud may look like a routine customer interaction.
For seasonal campaigns, the strongest control posture is one that treats the holiday context as a pressure amplifier, not as the root cause. That keeps focus on identity validation, payment verification, and user reporting rather than on holiday-specific assumptions that disappear as soon as the season ends.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 14 — Security Awareness and Skills Training | Holiday scams succeed through social engineering and urgency. |
| 5 — Account Management | Credential harvesting is a common holiday-scam objective. | |
| Recommendation — Train users to verify urgent seasonal requests before paying or sharing data. Harden account recovery and reset paths against impersonation-driven abuse. | ||
| NIST CSF 2.0 | PR.AT — Awareness and Training | Addresses user readiness against phishing and fraud pretexts. |
| PR.AC — Access Control | Scams often aim to capture credentials or trigger unauthorized access. | |
| Recommendation — Use PR.AT to reinforce recognition of spoofed seasonal lures and impostor requests. Apply PR.AC to require stronger verification before account recovery or payment changes. | ||
| MITRE ATT&CK | T1566 — Phishing | Seasonal scams commonly use phishing, smishing, or social pretexts. |
| Recommendation — Map holiday scam lures to T1566 and hunt for spoofed delivery, charity, and refund campaigns. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org