Fake SumUp phishing scam exploits urgency to steal small business data

Scammers mimic SumUp alerts to trick merchants into revealing login and financial details, leveraging urgency and vague messaging to bypass security advice and steal sensitive information.

Small businesses are being warned about a phishing campaign that imitates SumUp and pushes recipients to act on a supposed “transaction problem” without giving any meaningful detail. The message, which has been seen with the subject line “Action required: Transaction with a problem”, uses a vague warning and a prominent button to lure merchants on to a fake website designed to harvest login and financial information.

The scam works because it exploits a merchant’s instinct to protect sales and payouts. According to SumUp’s own phishing advice, the company will not ask for passwords, bank details or other sensitive information through unsolicited email, text message or phone contact. Its security guidance also stresses that users should avoid opening unverified links and should handle account checks only through the official app or website.

What makes the fake alert persuasive is its emptiness. The email offers no transaction amount, date, reference number, card details or explanation of what is supposedly wrong. That lack of context is the point: it creates enough anxiety to make a busy recipient click first and think later. Broadcom has previously warned that similar SumUp-themed phishing emails have been used to drive victims to credential-harvesting pages.

Once the button is clicked, the user is taken to a counterfeit page that can mimic a merchant dashboard or a login screen. Depending on the version, the site may ask for passwords, card data, bank details, identity information or verification codes. SumUp’s support centre says customers should rely on the official service for verification and should treat any unexpected request for sensitive data as suspicious.

The pattern mirrors other small-business scams that rely on urgency and impersonation rather than technical sophistication. SumUp’s security materials advise merchants to use unique passwords, keep support routes official and transparent, and communicate clearly about legitimate transactions so that staff know what a real alert looks like. The company also provides published support channels for customers who need to check whether an issue is genuine.

For anyone who has already clicked, the safest response is to move quickly: secure the affected account, change any reused passwords, review payout settings and contact SumUp through its official support channel. If banking or card details were entered, the bank or card issuer should also be notified. In practice, the simplest rule is still the best one: if a payment alert arrives without enough detail to verify it, do not trust the button.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.