Copy article

Warning for online shoppers after spike in criminals gaining unauthorised access to retailer accounts

ended 10. June 2026

Report Fraud is urging online shoppers to stay alert for unusual activity on their accounts following a rise in criminals gaining access to buy expensive goods.

Recent reporting highlights Argos as a key trend in this activity. Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands. Argos is actively working with authorities and its customers to identify suspicious activity and strengthen safeguards.

Criminals are using login details obtained from data breaches to gain unauthorised access to retailer accounts. This is possible due to the practice of reusing the same password across multiple online accounts. Once they have control of the account, criminals will place online orders and then collect the good in-person at a physical store. In some instances, the goods are paid for using payment details not connected to the victim of the compromised account.

These fraudulent orders are frequently fulfilled through ‘click and collect’, allowing offenders to retrieve goods in person.

In May, Report Fraud received 652 reports which mention Argos, a 323 per cent increase compared to April, when 154 reports mentioning the retailer were made. Since the start of 2026, there have been 1,175 reports mentioning the retailer, with May seeing the highest number to date.

Detective Chief Inspector Steven Kettle, Head of Crime Services at Report Fraud, said: “Report Fraud urges anyone with online retail accounts to remain vigilant and be alert to any unusual or suspicious activity.

“It is essential to take appropriate steps to protect your accounts by following Report Fraud’s guidance. If you believe you have been a victim of fraud, please report it to Report Fraud via reportfraud.police.uk or by calling 0300 123 2040.”

  • How dangerous are these scams?
  • How can people protect themselves against scams like this?
  • Is it common that scams use famous companies as bait?

Responses today please.

2 responses from the Newspage community

Copy all

Copy

These scams can be surprisingly dangerous because victims often don’t realise their account has been compromised until after expensive purchases have been made. The financial loss may be limited if payment details aren't stolen, but the wider risk is that criminals can use compromised accounts as a gateway to gather more personal information or attempt further fraud.

The simplest protection is also the most effective- use a unique password for every online account and enable two-factor authentication wherever it’s available. Password reuse is the fuel that keeps these attacks running.

It’s extremely common for fraudsters to use trusted household brands as bait. Consumers are naturally less suspicious of communications or account activity linked to well-known retailers. Criminals understand that trust is valuable, which is why they frequently hide behind familiar names rather than obscure websites.
Copy

This is credential stuffing. Criminals buy leaked logins in bulk, try them on major retailers, and when yours works because you've reused the password, they order big-ticket items on click and collect and walk out with them.

The fix is free and takes one evening. Check haveibeenpwned.com to see if your email's already in a breach. If it is, every account sharing that password is exposed.

Set up Bitwarden, a free password manager that does the hard work for you. For passwords you need to remember, make them a phrase something like "IPlayF00tieFridays_!". Long, odd, and personal. Use a different phrase for every account. Turn on two-factor authentication wherever it's offered, (although this can be exploited too).

Retailers need to answer for their end too. A dormant account ordering high-value goods from a new device should trigger a check before anything leaves the shelf.

Data resilience is a pain. A cleaned-out bank account is worse.