Why You Are Getting More Scams Than You Used To

Apr 01, 2026By Jay Kells
Jay Kells

Almost every week now, someone tells me they are getting far more scam messages than they used to, and that the messages are much better than they used to be. They are not imagining it and they are not being singled out. Something genuinely changed in the last couple of years, and it is worth understanding why, because once you know what is driving it you stop taking it personally and start dealing with it properly.

Stormy wave hitting rocks, representing the rising volume of scam messages reaching UK inboxes

Scams Used to Be Expensive to Run

For a long time, the thing that limited fraud was effort.

Someone had to write the message. Someone had to translate it, badly, into a language they did not speak. Someone had to sit on the phone for hours getting hung up on. Every single attempt cost the criminal time, and time is the one thing that stopped this being a bigger industry than it was.

That is why the old scams were so scattergun. The famous foreign prince email was sent to millions of people at once because the sender could not afford to write anything tailored. It was a wide net with big holes in it, and most of us learned to spot it.

What Actually Changed

The tools that write text and generate speech got good, and they got cheap.

A person who could once produce twenty crude emails an hour can now produce two thousand, each one different, each one in fluent English, each one written in whatever tone the target is likely to respond to. The cost per attempt collapsed. When the cost of trying drops to almost nothing, the rational thing for a criminal to do is try far more often.

That is the whole story of why your inbox got busier. It is not that you have been added to some list. It is that the economics tipped, and the volume went up for everybody.

Voice is the part that unsettles people most, and fairly so. A short clip of someone speaking, taken from a video anyone has posted publicly, is enough to produce a convincing imitation of that voice saying something they never said. I have sat with people who were certain they had spoken to their own son. That is not gullibility. It is a fair reaction to hearing a voice you have known for thirty years.

Why the Spelling Mistakes Disappeared

For years the standard advice was to look for bad grammar and odd phrasing. That advice is now close to useless, and I would rather tell you that plainly than let you rely on it.

There is an old theory that scammers wrote badly on purpose to filter out anyone too alert to be worth their time. There is something in it, but it does not matter any more, because writing well now costs nothing. The messages I get shown are clean, correctly punctuated, and often better written than the real ones from the same company.

So the tell has moved. It is no longer in the spelling. It is in the shape of the request. Is someone creating urgency? Are they steering you away from your normal way of doing things? Are they asking you to do something you cannot easily undo? Those three questions still catch almost everything, and they will keep working long after the surface polish gets even better. If you want the practical version of this, it is what I set out in the simple checks I use.

Why It Feels So Personal Now

The other half of the change is data.

Every breach of a company you have dealt with adds a little more to what is publicly known about you. Your email address, an old password, a phone number, the town you live in, where you shop. On its own each fragment is dull. Combined and fed into a system that writes messages, it produces something that sounds like it knows you, because in a limited way it does.

This is why the message about a delivery arrives when you actually are waiting for one, and why the caller knows which bank you use. It is not surveillance in the dramatic sense. It is old leaked data being used efficiently for the first time.

There is a practical consequence. Reused passwords used to be a slow risk. Now they are an immediate one, because matching an old leaked password to your current accounts is trivial to automate. A password manager like NordPass is not a luxury purchase any more, it is the single cheapest way to make all that leaked data useless.

What Still Works Against All of It

None of this means you are helpless. It means the defences that rely on spotting a fake have got weaker, and the defences that rely on process have got stronger. So lean on process.

Verify on a channel you chose. If a message or a call asks for anything that matters, close it and go to the app, the website, or the number on the back of your card. A criminal can imitate a voice, a face and a writing style, but they cannot answer the phone when you dial your bank yourself.

Agree a family question. Something ordinary that only your family would know the answer to, and that is not written down anywhere online. It costs nothing and it defeats a cloned voice in about four seconds.

Turn on two factor authentication on your email first, then your bank, then everything else. This is still the highest value hour you will ever spend on your own security.

Slow down when you are being hurried. Every version of this, old and new, depends on you acting before you think. Urgency is the constant. Take Five to Stop Fraud has said the same thing for years and it has not stopped being true.

That is the honest picture. More attempts, better written, better targeted, and a set of defences that still hold if you use them. If you would like a hand setting any of it up, get in touch and I will walk you through it in plain English.