Warning: Tesco voucher scam running riot on Facebook (again)

happygeek 0 Tallied Votes 331 Views Share

I am getting rather fed up of seeing posts in the feeds of my Facebook Friends, including many who really should know better, advertising a supposed £175 value Tesco supermarket voucher giveaway. I say 'should know better' as the culprits have included technology journalists, computer magazine editors and IT consultants; all of whom must surely know that if it looks too good to be true then it's a scam.

dweb-tescoscam And scam it quite patently is. Following on from a similar Tesco voucher scam at the end of last year, this new one adopts the same approach: in order to claim your 'free' voucher, the victim has to first share the 'offer' to their friends on Facebook whilst at the same time posting a comment that says 'Thanks Tesco' in a matey fashion (thus distributing the scam to the widest audience using the trust model - "if my mate is sharing this, and thanking Tesco as well, it must be kosher") and then click on a link to take you to a page where your voucher claim can be completed.

Of course, by this point one would hope that installed and up to date anti-malware protection software would remind the victim that they appear to have left their common sense at the door, and warn them not to be so silly as to load the page in question. Failing that, the victim will be greeted with a page that for all intents and purposes looks like Tesco as it has copied the supermarket giant's branding for just that purpose.

What happens next? Well that very much depends on the whim of the scammers from day to day, but the usual payload is the old survey-filling one-two-three.

One: fill in your personal details (they will come in handy for identity theft and further scams).

Two: complete this survey (these are often genuine third party surveys, but the scammer will get a referral payment for every survey that is completed).

Three: be tempted by the adverts offering more great deals (which will either provide the scammer with click-through revenue, or direct the victim to yet more scams and the potential of drive-by malware installation for good measure).

Interestingly, another UK-based supermarket chain is also the subject of an ongoing and current voucher scam. However, I have not seen a single 'Morrisons voucher' posting within my Facebook newsfeed, but have seen at least a dozen of the Tesco variety so far.

If you think you may have fallen for either of these scams, or any other, please go to your profile page and from there delete the offending posts that advertise them and may lure other people into clicking through.

Oh, and although I shouldn't really have to say this, you will not be getting a discount voucher no matter how many surveys you have completed...

Dani AI

Generated

Good, practical follow-up to the thread: this scam uses social trust to spread, so even technically savvy people can be caught (as observed). ’s isolated check triggering anti‑malware confirms these links often lead to malicious pages. Short, actionable checklist to contain, clean up and report — written so it still helps readers who find this thread years later.

  • If your account posted the offer or you see strange activity: follow Facebook’s account‑recovery and “hacked” flow, change your password, enable two‑factor authentication, and log out unfamiliar sessions. See Facebook’s recovery and login/help pages for exact steps. (Recover a hacked account, Two‑factor authentication, Where you’re logged in).

  • Revoke any suspicious third‑party access and stop apps that can post for you: remove unknown apps under Settings → Apps and Websites. (Remove an app).

  • Delete the scam posts/comments from your timeline (use Activity Log). If you did not enter any personal data, warn friends briefly that your account may have been used to post a scam.

  • If you clicked the link or submitted details: disconnect the device from the network, do not enter more information, then run full antivirus checks (use Microsoft Defender full + offline scan and a second‑opinion scanner such as Malwarebytes). Change passwords from a known‑clean device and consider banking alerts/credit freezes if financial data was given. (Microsoft Defender offline scan).

  • Report the scam: notify the retailer/bank (Tesco Bank has a fraud reporting page), and forward suspicious emails to national reporting services — UK: Action Fraud / report@phishing.gov.uk; US: report to the FTC and the IC3. (Tesco Bank fraud info, GOV.UK reporting advice, FTC phishing guidance).

Note: if an account takeover is severe or financial loss occurred, escalate to your bank and local law enforcement. The few minutes spent on these steps greatly reduce the chance of follow‑on fraud.

DaveMarchant 0 Newbie Poster

As soon as I retweeted this (one of my Facebook/Twitter friends had clearly gone for the voucher) I received a tweet from a totally unknown user with a link in it. On a protected system, I checked the link and all sorts of alarms were set off on the anti-malware software. Coincidence- I think not.

Member Avatar for Member #120589
Member #120589

Chain-gun mail with a hidden handgrenade. You'd think by now, people would've cottoned on. Hah. I can't help but feel that they deserve everything they get. If you're so dopey as to fall for this, then it's clearly Darwinian.

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

That's just the thing though, some of the people that I am seeing who are getting caught are exactly the people I wouldn't think would be so gullible: a tech magazine editor/publisher, a respected IT journalist, an IT consultant etc etc. They all know about scams, and are aware of the do not click mantra. What is happening, I think, is that they haven't transitioned their scam detection awareness from web to social networks, whereas the bad guys clearly have made the move.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.