Local councils and public service bodies are increasingly being impersonated by fraudsters seeking to exploit public trust. Fake text messages about parking fines, energy rebates, or council tax refunds now appear regularly in residents’ inboxes. Behind each one is a criminal attempt to harvest personal information, install malware or steal money.

Fraud targeting councils is not new, but the scale and sophistication have evolved dramatically. In recent years, our Fraud Intelligence Function has tracked numerous scam campaigns impersonating local authorities, often using official logos, similar domain names and familiar language. These campaigns exploit both technology and emotion - and without continuous awareness, residents can easily fall victim.

Why councils are high-value targets

Councils handle a vast range of citizen interactions: benefits, payments, waste collection, housing support, and public health. Fraudsters know that people are more likely to trust a message from their local authority than from a private company.

Scams now range from small-scale “energy rebate” messages to more sophisticated impersonation of official portals. In several cases, entire fake council websites have been set up to collect payment information or personal data under the guise of service renewals.

How impersonation works

A typical scam might begin with an SMS reading:

  • “City Council: You are eligible for a council tax refund. Claim your £150 rebate before midnight here: [link].”

The link then leads to a cloned website. Once victims enter their details, the fraudster harvests bank information and may later attempt further scams. These messages appear convincing because they align with real government initiatives, such as cost-of-living payments or local refunds.

Fraudsters have also started targeting council employees directly with phishing emails, often disguised as system updates or supplier invoices. These attacks can compromise internal networks, giving scammers access to sensitive data and in some cases has been linked to ransomware attacks.

Building resilience through awareness

At PORGiESOFT Security, we work with councils across the UK to strengthen their defences through a Fraud Awareness & Protection Service. The approach includes:

  • Quarterly Fraud Intelligence Packs outlining new scam tactics targeting local areas.
  • AI-powered awareness videos to educate both staff and residents.
  • Incident response plans that councils can deploy within 72 hours of detecting a scam with a local footprint.
  • Fraud OS integration, enabling councils to benchmark their fraud resilience and connect awareness with operational response.

These proactive steps ensure that public-facing communication stays ahead of criminals’ tactics.

What councils can do today

  1. Educate residents regularly. Awareness campaigns should be ongoing, not one-off.
  2. Standardise communication channels. Publish clear information about what genuine council messages look like.
  3. Collaborate regionally. Share insights with neighbouring councils to identify cross-border fraud patterns.
  4. Encourage reporting. Simplify how residents report suspicious messages.
  5. Protect staff. Provide training to identify phishing and impersonation attempts targeting council inboxes.

Key takeaway

Fraudsters thrive on familiarity and trust. By combining proactive intelligence with continuous education, councils can protect both residents and staff while maintaining confidence in public services.