Skip to content
Security basics for everyone

Festive-season scams: how attackers exploit Detty December and how defenders catch them

Detty December scams explained for cyber beginners: fake tickets, short-lets and flights, WhatsApp takeovers, and how defenders detect and shut them down.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 8 min read

Detty December scams work because the season concentrates everything a fraudster needs into a few weeks: people spending fast, buying from sellers they’ve never used, travelling, and celebrating in crowds with their phones in their hands. The attacks themselves are old (fake websites, fake sellers, account takeovers); what changes is the volume, the urgency and the bait.

This post is written for people starting a cybersecurity career. For each scam we look at how it is built, the technical traces it leaves, and how defenders at event organisers, payment companies, platforms and banks pick those traces up. All the businesses and domains in the examples are fictional.

Why December is a busy month for fraud

Think of it from the attacker’s side. A scam needs three ingredients:

  1. A believable pretext. In December the pretexts write themselves: sold-out concerts, flights home, beach houses, Christmas promos, “send me money for the owambe outfit”.
  2. Pressure. “Only two tickets left”, “the apartment has another enquiry”, “promo ends tonight”. Pressure stops people verifying.
  3. A payment route that can’t be easily reversed. Direct bank transfer to an individual account is the favourite, because unlike a card payment there is usually no simple chargeback.

Diaspora visitors returning for the holidays add a fourth ingredient: people unfamiliar with current local prices, sellers and payment habits, often carrying foreign currency.

The main Detty December scams, and how each one is built

1. Fake event tickets

How it’s built. The attacker advertises tickets for a popular show on social media or a lookalike website. The “tickets” are either nothing, a screenshot of someone else’s genuine QR code sold to several buyers, or a generated code that was never issued.

What it leaves behind. Lookalike domains, social accounts created recently, the same payment account appearing in complaints, and, at the venue, the same ticket ID scanned more than once or a ticket ID the organiser never issued.

2. Fake short-lets and hotel bookings

How it’s built. Photos are lifted from genuine listings. The “host” moves the conversation off the booking platform to WhatsApp and asks for a deposit by bank transfer “to hold the dates”. Sometimes the listing is real but the person collecting money is not the owner.

What it leaves behind. Reused images (a reverse image search often finds the original), payment requests outside the platform, and new accounts with no history.

3. Fake flight deals and travel agents

How it’s built. A website or social page offers flights home at prices that are just believable. The victim pays by transfer, receives a convincing PDF “e-ticket”, and discovers at the airport that no booking exists.

What it leaves behind. A booking reference that doesn’t exist on the airline’s own “manage booking” page, a newly registered domain, and a payment account unrelated to any airline or registered agency.

4. Christmas giveaways and WhatsApp account takeover

How it’s built. A message arrives from a friend’s WhatsApp: “I entered you for a Christmas giveaway, I’ve sent a code to your phone, please forward it to me.” The code is your WhatsApp registration code. Once you send it, the attacker registers your number on their device and messages all your contacts asking for urgent loans. The friend’s account was taken the same way.

What it leaves behind. A registration code sent by SMS that the owner didn’t request, and a burst of near-identical money requests to the victim’s contacts.

This is the account-takeover pattern we unpack in security fundamentals for beginners. The single most effective fix is turning on WhatsApp’s two-step verification, which adds a PIN or password (follow what your app shows), so a stolen SMS code alone isn’t enough.

5. Payment and transfer tricks at parties and pop-ups

Fake transfer alerts and POS tricks spike when vendors are busy. Pop-up food stalls, drinks vendors and event merchants are serving queues of customers at night, which is perfect for “it has entered, check your phone”. We cover the mechanics and the detections in fake bank alerts and POS scams.

6. Phone theft and what follows

A phone stolen at a crowded event is not just a lost device. If it’s unlocked or has a weak lock screen, the thief may get into email, banking apps and messaging, then reset passwords using SMS codes. The theft is physical; the damage is digital.

How defenders catch festive-season scams

Here is where the career angle comes in. Each scam above is caught by someone whose job title you could hold in a few years.

Brand and domain monitoring

Event organisers, airlines and large merchants monitor for lookalike domains and fake social accounts. Registering a lookalike domain is so common that MITRE ATT&CK lists it as Acquire Infrastructure: Domains (T1583.001). Defenders watch:

  • Newly registered domains containing the brand name or typos of it.
  • Certificate transparency logs, the public record of TLS certificates issued, because most scam sites get a certificate to show the padlock.
  • Social platforms for pages using the brand’s name and logo.

When something is found, the team gathers evidence and files takedown requests with the registrar, host or platform.

Lab: flag lookalike domains

Here’s a simple version of the logic. Imagine a feed of newly observed domains for the fictional festival “Acme Fest”. Save it as new_domains.txt:

acmefest-tickets.test
acrnefest.test
lagos-weather-today.test
acmefest-official-resale.test
bestjollofspots.test
acme-fest-vip.test

Then lookalikes.py:

from difflib import SequenceMatcher

BRAND = “acmefest”
for line in open(“new_domains.txt”):
    domain = line.strip()
    label = domain.rsplit(“.”, 1)[0].replace(“-”, "")
    score = max(SequenceMatcher(None, BRAND, label[i:i + len(BRAND)]).ratio()
                for i in range(max(1, len(label) - len(BRAND) + 1)))
    if score >= 0.75:
        print(f“{score:.2f}  {domain}”)
$ python3 lookalikes.py
1.00  acmefest-tickets.test
0.75  acrnefest.test
1.00  acmefest-official-resale.test
1.00  acme-fest-vip.test

Look at acrnefest.test: “rn” next to each other reads like “m” at a glance. With a threshold of 0.8 that domain slips through; at 0.75 it’s caught. Lower the threshold further and unrelated domains start appearing. That tension between catching tricks and drowning in noise is exactly what detection engineers tune for a living. Real tools handle many more tricks (homoglyphs, swapped letters, different top-level domains), but the reasoning is the same.

Ticket validation at the gate

A well-run event treats every QR code as a one-time token: the scanner checks it against the list of tickets actually issued and marks it used. Duplicates and never-issued codes are then easy to spot. A small lab, gate_scans.csv, with fictional scans:

scan_time,ticket_id,gate
2026-12-20 18:01:12,AF-000418,G1
2026-12-20 18:01:40,AF-000419,G1
2026-12-20 18:03:05,AF-000731,G2
2026-12-20 18:09:51,AF-000418,G3
2026-12-20 18:12:30,AF-000731,G1
2026-12-20 18:14:02,AF-000731,G2
2026-12-20 18:20:44,AF-009999,G2

Save it as dup_tickets.py:

import csv
from collections import defaultdict

issued = {f“AF-{n:06d}” for n in range(1, 5001)}   # tickets the organiser actually sold
seen = defaultdict(list)

for row in csv.DictReader(open(“gate_scans.csv”)):
    seen[row[“ticket_id”]].append((row[“scan_time”][11:16], row[“gate”]))

for ticket, scans in sorted(seen.items()):
    if ticket not in issued:
        print(f“NOT ISSUED  {ticket}  scanned at {scans}”)
    elif len(scans) > 1:
        print(f“DUPLICATE   {ticket}  {len(scans)} scans: {scans}”)
$ python3 dup_tickets.py
DUPLICATE   AF-000418  2 scans: [(‘18:01’, ‘G1’), (‘18:09’, ‘G3’)]
DUPLICATE   AF-000731  3 scans: [(‘18:03’, ‘G2’), (‘18:12’, ‘G1’), (‘18:14’, ‘G2’)]
NOT ISSUED  AF-009999  scanned at [(‘18:20’, ‘G2’)]

Ticket AF-000731 was presented three times at two gates within eleven minutes: one screenshot, sold to several buyers. The analyst’s next step is to look at where the ticket was originally sold and whether the original buyer reported anything. The genuine buyer, if they came first, got in; the others found out at the gate. This is why organisers tell buyers to purchase only through official channels.

Payment monitoring

Most of these scams end in a bank transfer to an account that passes the money on quickly. Banks and payment providers look for accounts receiving many small credits from unrelated people over a short period, especially when the transfer narrations mention tickets, deposits or bookings, and for accounts that show up in multiple customer complaints. The fake bank alerts post includes a small lab rule for spotting money that passes straight through an account.

Account security teams

Messaging and email providers watch for signs of takeover: a new device registration followed by mass messages, a password reset followed by changed recovery details, sign-ins from unusual places. Banks watch for a new device enrolling a banking app shortly after a SIM change. These are correlation problems: no single event is suspicious, but the sequence is.

Reporting

Every report feeds the system. Victims should report to the platform where the scam was advertised, to their bank (using the number in the app or on their card), and, for readers in the UK, through the routes the NCSC lists for reporting scam websites. In Nigeria, start with your bank and the platform involved, then report to the Nigeria Police Force National Cybercrime Centre (NPF-NCCC) through its e-reporting portal.

A defender’s checklist for a fictional event organiser

If you were the security lead for “Acme Fest”, a sensible December plan looks like this:

When Action Owner
Six weeks out Publish the only official ticket sources on the website and social bios Marketing + security
Six weeks out Start lookalike domain and fake-page monitoring; prepare takedown templates Security
Four weeks out Make sure every ticket is a unique, one-time QR code checked against the issued list Ticketing
Two weeks out Brief gate staff on duplicate and invalid-ticket handling Operations
Event week Monitor duplicate scans live; keep a log for each incident Security + ticketing
After the event Review incidents, report payment accounts involved, update the playbook Security

Personal safety for the season

The defender’s view also gives you the best personal advice:

  • Buy through official channels listed on the organiser’s, airline’s or platform’s own website. Check the address carefully; the NCSC’s guide to shopping online securely is a good general checklist wherever you live.
  • Keep bookings and payments on the platform. The moment a host or seller pushes you to WhatsApp and a personal account, treat it as a red flag.
  • Confirm flight bookings on the airline’s own site using the booking reference before you relax.
  • Never forward a code sent to your phone, whoever asks. Turn on WhatsApp two-step verification (a PIN or password; follow what your app shows).
  • Lock your phone properly (a PIN or passcode, not a simple swipe), set a SIM PIN if your network supports it, and know how to remotely lock or wipe it.
  • For vendors: goods leave only after the money shows in your app.

What a beginner can practise this December

  • Run both labs above, change the thresholds, and write down what you’d expect to miss.
  • Find the certificate transparency search tools and look up a domain you own, to see what the public record shows.
  • Write a one-page incident runbook for “duplicate ticket at gate”.
  • Map the six scams to MITRE ATT&CK techniques and list the control that breaks each.
  • Compare these patterns with the Black Friday scams a few weeks earlier. You’ll notice how much of the infrastructure carries over.

Questions

What are Detty December scams?

They are the fraud schemes that spike during Nigeria's busy December season of concerts, parties, travel and returning visitors: fake tickets, fake short-lets and flights, giveaway messages that hijack WhatsApp accounts, and payment tricks aimed at busy vendors.

How do I know if an event ticket is genuine?

Buy it from the organiser's listed official channels. A screenshot of a QR code proves nothing, because the same screenshot can be sold many times; only the first person to scan it gets in.

Why do scammers ask for bank transfers instead of card payments?

Transfers to individual accounts are usually harder to reverse than card payments, and the money can be moved on within minutes.

Is fraud detection a good way into cybersecurity?

It's a genuine route. Fraud analysis, brand protection and SOC work share core skills: reading logs, writing detection rules, investigating patterns and documenting cases clearly.