A text arrives with the kind of promise many households would welcome: a £100 oil payment is ready, and the application takes only a minute.
The message may mention winter costs, energy support, or a government deadline. It can even say the process is free while quietly steering you toward a small “processing” charge.
The amount sounds believable because it is tied to a real support program. The link is where the genuine payment and the scam part company.

Overview
The text borrows a real cost-of-living payment
Police in Northern Ireland are warning about messages that claim recipients must unlock or claim a £100 oil voucher. The offer sounds timely, especially to households concerned about heating expenses.
The confirmed scam also appears through calls and email. Criminals imitate the Department for Communities, local councils, NI Direct, and other official-looking services to obtain banking and identity information.
The official application does not require a fee
The Police Service of Northern Ireland says the legitimate application process through NI Direct is free. A message asking for an upfront processing, release, verification, or activation fee is not part of that process.
Government bodies will not unexpectedly text, email, or call to request a bank PIN, card details, or an advance payment before providing the oil support.
The fake form is built to steal more than £1
A tiny fee makes the form feel low risk. The real value lies in the name, address, National Insurance number, bank details, card number, security code, and one-time password entered around it.
- A text announces that the £100 payment is waiting.
- A shortened or unofficial link hides the destination.
- The page copies a public-service design.
- Eligibility questions collect identity details.
- A small fee captures card information.
- A follow-up screen or call requests a bank code.
- Stolen details support unauthorized payments and identity fraud.
The program name may change with the season, budget, or news cycle. The mechanism remains the same: a public benefit becomes bait for a private data-collection page.
How the £100 Oil Voucher Scam Works
Step 1: A mass text reaches likely households
The campaign does not need to know who uses heating oil. A large blast across Northern Ireland will reach enough relevant households, while other recipients may assume the support applies more broadly than they realized.
The sender label may read Energy Support, NI Payments, Local Council, DfC Support, or something similarly generic. A name chosen by the sender is not proof of origin.
Step 2: Urgency replaces an eligibility check
The message says the payment is ready, reserved, expiring, or awaiting verification. That wording skips the question of whether the recipient applied and moves attention directly to the deadline.
Some texts claim that every household qualifies. Others say the recipient was pre-approved from council records. Either version is designed to make the link feel like the final step rather than an unsolicited application.
Step 3: A lookalike portal copies government language
The page may use crowns, flags, departmental colors, accessibility links, and formal phrases such as “check eligibility” or “secure application.” Those visual elements can be copied in minutes.
The address bar matters more. NI Direct and other government services use official gov.uk domains. Added words before .com, .org, .support, or another ending do not become government addresses because the page looks official.
Step 4: The form builds an identity profile
Early fields ask for name, date of birth, address, postcode, email, phone number, and National Insurance number. Each request can be explained as an eligibility check.
Together, those details create a useful identity package. The operator can use it in bank impersonation calls, credit applications, account recovery attempts, and later benefit scams.
Step 5: A token fee captures the card
The form introduces a small processing or delivery fee, often low enough to escape careful thought. The oil payment is supposedly worth £100, so paying £1 or £1.50 can feel like a reasonable administrative cost.
The card fields capture the number, expiry date, and security code. The page may then claim that the payment failed, encouraging the victim to try a second card.
Step 6: A security code completes the theft
A bank may send a one-time password because the criminal is already attempting a card transaction, adding the card to a mobile wallet, or signing into online banking.
The fake page labels the code as voucher verification. Entering it can authorize the criminal’s action, not the promised government payment.
Step 7: The victim receives more tailored scams
Even when no immediate charge succeeds, the data remains valuable. A caller can quote the address, application time, and bank name to sound like a fraud investigator following up on the failed claim.
A second message may offer a tax rebate, energy refund, council grant, or payment correction. The story changes, but the operator now knows which subject produced a response.

The Police Warning Confirms a Wider Campaign
The PSNI alert, published September 9, 2026, does not describe one isolated complaint. It warns the public about cost-of-living scams using several approaches.
Fake application texts contain malicious links and say a fee or bank details are needed to unlock the £100 oil voucher. Impersonation calls claim to come from the Department for Communities or local councils. Phishing emails copy NI Direct or government portals.
Other offers in the same family include energy refunds, energy discounts, tax rebates, and cost-of-living payments. Every version aims to obtain personal or banking information.
Police emphasize that the official oil-payment application is free. They also say government bodies will not cold call or send unsolicited messages asking for account details, PINs, or upfront processing fees to grant the payment.
That evidence is important because the genuine existence of support can confuse a simple online search. Finding a real program does not authenticate the link that arrived in a text.
Company, Address, and Fulfillment Checks
The address must end in the official government domain
Do not judge a URL by words such as NI, direct, energy, oil, support, or government. Read the registered domain immediately before the ending.
The safest route is to close the message and type nidirect.gov.uk yourself. Search the official site for the program and start there if an application is genuinely available.
The program rules must match the official page
Confirm the amount, eligibility, dates, application method, and documents required. A scam page may copy the benefit name while inventing a universal deadline or fee.
If the real process says no cold texts and no payment, a text claiming the opposite does not create a special exception.
Support must exist outside the incoming message
Do not use the callback number, live chat, or email address supplied by the sender. Locate the department or council through an official directory and ask whether it sent the communication.
A scammer may answer quickly and professionally. Speed and politeness are not verification when every contact route remains under the same operator’s control.
The payment request must make sense
A public payment should not require the applicant to send money to receive money. A £1 authorization, courier charge, anti-fraud deposit, and refundable release fee all serve the same purpose: getting a usable payment method.
Never provide a one-time banking code to claim a benefit. Read the bank’s message carefully, including the merchant, amount, device, or wallet action the code actually authorizes.
Why the Small Fee Is the Most Dangerous Part
People often focus on the amount and conclude that losing £1 would be annoying but harmless. That calculation ignores what the checkout collects and what the bank verification step may approve.
A card can be tested with a small authorization before larger attempts follow. The same data can be sold, reused at other merchants, or paired with personal details gathered earlier in the form.
The fee also changes the victim’s mental state. Once the application appears complete, an unexpected one-time code feels like a routine final confirmation rather than a fresh security decision.
This is why a polished checkout is not reassuring. Payment processors and browser padlocks only indicate that data travels to the site securely. They do not prove that the site is entitled to collect it.
MalwareTips has documented the same code-stealing pattern in Smishing Triad campaigns, where fake mobile pages move from a small payment to card details, credentials, and one-time passwords.
Warning Signs in Oil Voucher Messages
- You did not start an application, but the text says a payment is ready.
- The sender uses a generic name instead of a verifiable government channel.
- The link is shortened or does not end in gov.uk.
- The page asks for a fee to release public support.
- A countdown claims the payment expires within hours.
- The form requests more identity data than the official process.
- You are asked for a bank PIN, full password, or one-time code.
- The message discourages visiting NI Direct independently.
- A call follows immediately after the form is submitted.
- A failed payment prompts you to enter another card.
Do not reply “STOP” to an obvious criminal message if doing so merely confirms that your number is active. Use the device’s report-junk feature and the reporting routes recommended by your carrier and local authorities.
If You Opened the Link but Entered Nothing
Opening a page is not the same as submitting the form, but it is still worth closing it and checking the device. Do not return to study the site. Save the URL from browser history if investigators need it, then clear any download the page started without your approval.
Modern browsers isolate ordinary web pages reasonably well, so a simple visit often ends when the tab closes. Risk rises if you allowed notifications, installed an app or profile, downloaded a file, granted remote access, or typed a password. Revoke those permissions and scan the device when any of those events occurred.
The site may also mark your number or browser as responsive. Expect another benefit, refund, tax, delivery, or bank message. Treat the next contact as part of the same campaign even if it uses a different sender name and domain.
What to Do if You Have Fallen Victim to This Scam
- Leave the page. Do not retry the form, supply another card, or answer a follow-up call claiming to fix the application.
- Call the bank immediately. Use the number on the card or official app. Explain that card and bank details were entered on a government-benefit phishing page.
- Replace exposed cards. Ask the issuer whether the card should be blocked and reissued. Review pending and completed transactions rather than watching only for a £1 charge.
- Protect online banking. Change any credentials entered, remove unknown mobile-wallet tokens or devices, and enable strong multifactor authentication.
- Secure your identity. Record which personal fields were submitted. Take appropriate steps if a National Insurance number, date of birth, or identity document was exposed.
- Save evidence. Keep screenshots, sender details, the full URL, timestamps, bank messages, transaction records, and call numbers. Do not continue visiting the phishing page to collect more.
- Report the campaign. Contact PSNI on 101 or through its online reporting service, notify the bank, and file with Action Fraud where applicable.
- Remove suspicious downloads. If the page installed an application, configuration profile, or file, remove it and run a complete Malwarebytes scan.
- Reduce repeat exposure. AdGuard can block some known phishing pages and malicious advertising, but it cannot turn an unofficial benefit link into an authentic one.
- Warn the household. Tell relatives or neighbors who may use heating oil. Criminals often send the same campaign across a geographic area.
Frequently Asked Questions
Is the £100 oil payment itself fake?
No. The warning concerns criminals exploiting a real support offer. The fake text and unofficial application link are the scam.
Do I need to pay a fee to claim the voucher?
No. PSNI says the official process through NI Direct is free. A processing or release fee is a strong sign of fraud.
Can the government text me a link for bank details?
The police warning says government bodies will not cold text, email, or call asking for bank details, PINs, or upfront fees to grant this payment.
What domain should I trust?
Start by typing nidirect.gov.uk yourself. Do not trust a domain merely because it contains words such as energy, oil, NI, direct, or support.
What if I entered my card but no charge appeared?
Call the issuer anyway. The data may be tested later, used with a mobile wallet, or sold to another criminal operation.
Why did the bank send me a one-time code?
The criminal may have started a transaction, account login, or wallet enrollment. The code authorizes what the bank message describes, not what the phishing page claims.
The Bottom Line
The £100 oil voucher text scam succeeds because its bait is grounded in a real concern and a real public payment. The fake page then reverses the purpose of the program by asking the household to pay and expose banking data.
Close the message, type the official NI Direct address yourself, and compare the rules. A legitimate oil payment does not need a hidden link, a surprise fee, or your one-time banking code.