Cyber Scams Spike During Staff Holidays: Here’s How to Stay Safe

Annual leave season is prime time for scammers. Here’s why “urgent” requests spike while your team’s away, and five simple checks to close the gap.

Your team's on annual leave. Is your business still covered?

It’s that time of year. Out-of-office replies are going up faster than the temperature, the office is half empty on a Friday, and everyone’s counting down to their next long weekend.

It’s also, unfortunately, prime time for scammers.

We’ve noticed it every summer for years: the same week half your team heads off, “urgent” emails start landing in inboxes. Not spam-folder-obvious ones either — convincing, well-timed messages that ask someone to act fast, right when there’s nobody around to double-check.

Whatever size your business is, this is worth five minutes of your time before the next wave of annual leave requests hits your calendar

Why scammers love annual leave season

It’s not a coincidence. Fewer people in the office means fewer people available to catch something before it becomes a problem.

Think about how your business normally works. Someone senior usually signs off on payments, password changes, or anything involving sensitive data. There’s a rhythm to it: a second pair of eyes, a quick “does this look right to you?” conversation across the office.

Take that person out for two weeks, and that rhythm breaks. Requests that would normally get a raised eyebrow instead get actioned by whoever’s covering, because nobody wants to be the person who held up something “urgent” while the boss is on a beach in Portugal.

Scammers know this. It’s why Business Email Compromise attacks, where a fraudster impersonates someone senior or a trusted supplier, consistently spike over summer. 

What this actually looks like

It doesn’t look like a scam. That’s what makes it work.

A message comes in claiming to be from your MD, your finance lead, or a supplier you’ve dealt with for years. It isn’t really them, the sender’s address is spoofed, or made to look almost identical to the real one. But nothing about the message itself stands out. The tone is right, the signature’s right, it reads like any other email your team gets on a normal day.

The catch only comes with the ask: send a payment today, reset a password, update some bank details, grant access to something time sensitive.

And here’s the part that makes summer a prime target: the real MD or finance lead is genuinely on annual leave. So when the request lands with whoever’s covering, there’s no quick “hey, did you actually send this?” over the desk. The one person who could instantly say “that’s not me” isn’t around to say it.

Nobody wants to be the reason something urgent got held up. So it gets actioned. It’s only once the real MD or finance lead is back, and asks “what payment?”, that anyone realises something was wrong.

Five things worth checking before the next round of leave

None of this needs a big IT overhaul. It’s mostly about making sure the right habits are in place before people head off, not after something’s gone wrong.

1. Agree who’s covering approvals, and make sure people know it. If your usual approver is away, someone else needs to be clearly responsible for sign-off, not just “whoever’s free.”

2. Never approve anything solely because it’s marked urgent. Urgency is the oldest trick in the book. A genuine request can wait five minutes for a phone call to confirm it.

3. Pick up the phone for anything involving money, passwords, or access. A quick call to a known number beats replying to an email that might not be who it claims to be.

4. Make sure staff know exactly who to flag a suspicious message to, even if IT support isn’t at their desk. If the answer is “I wasn’t sure who to tell,” that’s a gap worth closing.

5. Check multi-factor authentication is switched on everywhere it can be. It’s the single easiest thing to fix, and it stops a huge number of these attempts dead.

Business owner checking laptop

The bit that actually matters

None of this is about distrusting your team. It’s the opposite: it’s giving them a clear, simple way to slow down and check, without feeling like they’re causing a fuss or holding things up.

Most people who fall for these scams aren’t careless. They’re busy, trying to be helpful, and dealing with a message designed to look completely normal. The fix isn’t “be more vigilant.” It’s building small checks into how your business runs, so vigilance isn’t the only thing standing between you and a costly mistake.

Cyber criminals don’t take annual leave. If your business hasn’t looked at this before the next round of summer holidays, now’s a good time.

Protect Your Business Today