September brings fresh starts. Children are back at school, families are checking timetables and buying supplies, and many workers are returning to the office after the quieter summer months.
That change in routine is useful to scammers.
When people are busy, they’re more likely to click quickly, trust a familiar-looking name or approve a request without checking it first. That’s why September can be a particularly active time for phishing emails, fake offers and payment scams.
The good news is that a few calm, practical checks can make a real difference. Here’s your friendly September security reset for home and work.
Why September Attracts Scammers
Scammers look for moments when people expect important messages. September provides plenty of them.
You might be waiting for:
- A school email about term dates, clubs or trips
- A message about uniform, books or device purchases
- A timetable or online learning account
- An HR update or mandatory workplace training email
- A payroll, benefits or tax-related message
- An invoice from a supplier or service provider
- A request from a manager to make an urgent payment
A scammer can copy the wording, colours and logo of a real organisation. They may even know your child’s school, your employer or one of your suppliers.
That doesn’t mean you’ve done anything wrong. It simply means you should pause before acting, especially when a message involves money, passwords, personal information or urgent deadlines.
Common Scams to Watch For
Fake school emails and offers
Parents may receive messages appearing to come from a school, club or education provider. These might ask you to:
- Pay an overdue fee
- Confirm your child’s details
- Complete a “required” form
- Buy discounted uniforms, tablets or laptops
- Sign in to view a timetable or school document
- Make a payment for a trip, meal account or activity
Some fake offers arrive through social media or online marketplaces rather than email. A very cheap laptop or uniform bundle may be designed to collect your payment details or personal information.
Check through the school’s usual app, website or telephone number. Don’t use the link or phone number provided in a message you’re unsure about.
Return-to-work phishing
Workers returning to the office may see emails claiming to be from HR, IT, payroll or senior management.
Common examples include:
- “Please confirm your new bank details”
- “Your password will expire today”
- “Complete mandatory security training”
- “Review the updated staff handbook”
- “Your benefits or salary information needs updating”
- “Call this number to prevent your account being suspended”
The message may look professional. It may use your manager’s name. It could still be fake.
If you’re unsure, open your normal work portal directly or speak to your IT team using a known contact method. Never rely only on the details in the suspicious email.
Invoice and CEO fraud
Businesses should be particularly careful with payment requests in September, when projects restart and suppliers, staff and customers are busy again.
A scammer may pretend to be:
- Your managing director or finance director
- A regular supplier
- A landlord or service provider
- A training company
- A new customer
- A solicitor handling a confidential matter
They may ask for a payment to be made quickly or request that a supplier’s bank details are changed.
Create a simple rule: verify every new bank detail or unusual payment request using a known telephone number or an agreed internal process. A short conversation can prevent a costly mistake.

The Warning Signs Are Often Small
Scam messages aren’t always full of spelling mistakes. Some are carefully written and look very convincing.
Look for these warning signs:
- Unexpected urgency , You’re told to act immediately or face a penalty.
- Requests for secrecy , You’re asked not to tell colleagues, family members or anyone else.
- Unusual payment instructions , You’re asked to use a new bank account, gift cards, cryptocurrency or an unusual payment method.
- A strange sender address , The display name looks right, but the actual email address is unfamiliar.
- A link that doesn’t look right , Hover over it without clicking, or avoid it and visit the official website yourself.
- Requests for passwords or codes , Genuine organisations should not ask you to share your password or one-time security code.
- Unexpected attachments , Don’t open files you weren’t expecting, even if the message appears to come from someone you know.
- A request to approve a login , Never approve a two-step verification prompt you didn’t start.
When a message creates panic, slow down. That is exactly what scammers don’t want you to do.
Your Simple September Security Reset
You don’t need to be highly technical. Work through these steps at your own pace.
1. Review your important passwords
Start with your email account, online banking, shopping accounts and social media.
Use a different password for every important account. If one website suffers a breach, a unique password helps protect your other accounts.
A password manager can create and remember strong passwords for you. If that sounds complicated, start with your email account first. Your email is especially important because it may be used to reset your other accounts.
If you’ve reused a password across several websites, change it wherever it has been used.
2. Turn on two-step verification
Two-step verification, sometimes called multi-factor authentication, adds another check after your password. This might be a code, an approval on your phone or a security key.
Turn it on for:
- Online banking
- Microsoft or Google accounts
- Social media
- Shopping accounts
- Business systems
- Cloud storage
It may take a little longer to sign in, but it gives your accounts an important extra layer of protection.
Never approve a login request you didn’t initiate. If an unexpected prompt appears, deny it and change your password.
3. Check for known breaches
You can check whether your email address has appeared in a known data breach using Have I Been Pwned.
Finding your email address there does not automatically mean someone can access your account. It means that information connected with that address may have been exposed by a website or service.
If your email appears in a breach:
- Change the affected password.
- Change it anywhere else you reused it.
- Turn on two-step verification.
- Review recent account activity and logged-in devices.
- Be extra careful with follow-up emails pretending to offer help.
4. Install updates
Updates often include security fixes, not just new features.
Check that your:
- Laptop and desktop
- Phone and tablet
- Router
- Web browsers
- Antivirus or security software
- Office and school applications
are all up to date.
Turn on automatic updates where possible. If a device is too old to receive updates, it may be time to ask for advice about safe options.

5. Check your backups
A backup gives you a way back if your device is lost, damaged or affected by malware.
Make sure important documents, family photographs and work files are backed up somewhere separate from your main device. Cloud storage can help, but check that it is actually syncing. For especially important files, keep an additional backup that isn’t permanently connected.
Try opening a backed-up file occasionally. A backup is only useful if you can restore it.
6. Remove what you no longer use
Delete old apps and browser extensions. Remove accounts you no longer need. Review which apps can access your location, contacts, camera and microphone.
For children, review privacy settings and discuss the simple rule: don’t share passwords, codes, school details or photographs with people you only know online.
What If You’ve Already Clicked?
First, don’t panic. Many people click a suspicious link before realising what it is. Acting quickly and calmly can reduce the risk.
If you entered a password
- Change it immediately using the genuine website or app.
- Change it anywhere else you used the same password.
- Turn on two-step verification.
- Sign out of other sessions or devices if the option is available.
If you shared bank details or made a payment
Contact your bank or card provider immediately using the number on your card or official statement. Explain what happened and follow their instructions.
If you’re in the UK, report fraud through Action Fraud. Keep the email, message, payment details and any screenshots as evidence.
If you downloaded a file or installed software
Stop using the device for sensitive activity until it has been checked. Don’t enter further passwords or payment details. Disconnect it from the internet if you believe malware may be active, and ask for professional help.
For a suspicious email that you haven’t acted on, you can report it through the National Cyber Security Centre’s phishing guidance. You can also forward suspicious texts to 7726.
If it happened on a work device
Tell your manager or IT support team straight away. Reporting a mistake quickly helps protect your colleagues and business. You won’t be the first person this has happened to, and there’s no benefit in keeping it quiet.
You Don’t Have to Sort It Out Alone
Security can feel like a lot, particularly when you’re trying to get children back into school routines or settle into work again.
At EB IT Support, we’re here to make technology easier. Our friendly local team supports homes, families, home workers and businesses across Boston and Lincolnshire, with plain-English advice, no jargon and no judgement.
You can visit our Boston location for free drop-in technology advice any weekday, Monday to Friday from 9am to 5pm. Repairs are charged separately, but the initial advice is free. Please contact us or call 01205 627240 before travelling, just to confirm we’re not out on a callout.
If remote help suits you, our remote support is available from £55 per hour. For issues that need someone to visit your home or workplace, on-site support is available from £79.99 per hour.
We’ll explain what’s happening, what needs doing and what it will cost before work begins. You can choose the support method that works best for you.

Ready for a Safer September?
You don’t need to fix everything today.
Start with your email password. Turn on two-step verification. Install your pending updates. Then remind your family or team to pause before clicking unexpected links or approving unfamiliar requests.
A little preparation now can help you stay connected, work confidently and enjoy the new routine with less worry.
Need a hand? Get in touch with EB IT Support for friendly, local advice from one familiar team.