Why businesses are more vulnerable to cyber scams during the summer holidays

Businesses are being urged to be extra vigilant over the holiday period after new threat intelligence revealed imposter scams surged by 144% during the summer compared with the rest of the year.

Derby-based IT and cyber security specialist PKF Infuse says the figures underline the need for businesses to be particularly alert during August, when annual leave, reduced staffing levels and changes to normal working routines can potentially create opportunities for cyber criminals.

Research published by cyber security company Gen, which analysed threats blocked during June to August in 2024 and 2025 compared with the rest of the year, found imposter scams increased by 144% during the summer.

PKF Infuse is urging businesses to check whether their own email domains are adequately protected and has launched a free online DMARC checker which allows organisations to assess their email authentication status and identify potential weaknesses.

The call follows PKF Infuse’s own cyber security audit of 499 domains across Derby and Nottingham, which found 301 had failures involving DMARC, SPF or both – potentially leaving organisations more vulnerable to spoofed emails designed to impersonate trusted businesses.

DMARC – Domain-based Message Authentication, Reporting and Conformance – is an email authentication standard that helps prevent cyber criminals from impersonating legitimate organisations and sending fraudulent emails in their name.

The PKF Infuse research found that just 14.2% of domains had fully implemented DMARC best practice. A further 127 domains, representing 25.5% of those assessed, were operating under a quarantine policy, meaning some protection measures were in place but had not yet been fully enforced.

Paul Howard, managing director of PKF Infuse and the developer behind the checker, said: “A 144% increase in imposter scams during the summer is a significant figure and should make businesses sit up and take notice.

“August can be a particularly challenging time. People are on holiday, teams are stretched and employees may be covering responsibilities they don’t normally handle.

“Fatigue can also play a part. When people are busy, covering for colleagues or simply dealing with an inbox that has built up while others are away, there is a danger that an unusual request doesn’t receive the scrutiny it normally would.

“That is exactly the environment criminals can try to exploit.”

Impersonation attacks can involve criminals posing as senior colleagues, suppliers or other trusted organisations in an attempt to persuade employees to make payments, disclose sensitive information or hand over login credentials.

An email appearing to come from a managing director asking for an urgent payment, for example, may be more difficult to verify if the people who would normally authorise or question the request are away.

Paul added: “Cyber criminals rely on creating a sense of urgency. They want someone to act before they have had time to stop and question what they are being asked to do.

“If the finance director is on holiday, somebody is covering an unfamiliar role or the business is simply operating with fewer people, normal checks can become more difficult.

“That doesn’t mean businesses should be frightened of opening their inboxes during August. It means they need to make sure the same checks and procedures remain in place regardless of who is on holiday.

“Our research showed there are still businesses whose domains could be better protected against impersonation, and these latest figures demonstrate why that matters.

“There are two sides to this. Businesses need the technical protections that make it harder for criminals to impersonate them, but they also need employees who recognise the warning signs when a suspicious message arrives.

“August is a good prompt for businesses to look at both. Check your domain, make sure your email security is properly configured, make sure holiday cover doesn’t weaken your normal procedures and remind employees that taking an extra minute to verify an unusual request is always worthwhile.”

PKF Infuse is encouraging businesses to independently verify unexpected requests involving payments, changes to bank details, passwords or sensitive information, particularly when they appear to come from senior colleagues or suppliers.

Organisations should also make sure employees covering colleagues during annual leave understand the appropriate authorisation procedures and know who to contact if they are unsure about a request.

Businesses can use PKF Infuse’s free online DMARC checker here: https://pkfinfuse.com/dmarc

You May Also Like

Must Read

Skip to content