Opens in a new tab

Scammers exploit heatwave with fake beach kit giveaways

Friday 26th June 2026 on 20:00 in Lithuania

cybersecurity, internet, scams

Scammers are taking advantage of the current heatwave by offering fake “beach kit” prizes under the guise of travel agency Novaturas, LRT.lt reports.

Posts appeared on Facebook claiming that users could win a beach kit by filling out a survey on a website and selecting three out of several boxes. The posts promised free home delivery of the prize. However, suspicions arose due to the use of non-Lithuanian names in the comments and the website’s content being in Swedish and English.

Official warnings from Novaturas confirmed the scam. The posts, published by a user named “NOVA Vasariškos nuotaikos,” claimed that users could win a large beach kit containing various summer essentials, from cosmetics to clothing. The images attached showed bags filled with prizes, including cosmetics, fans, sun hats, and other summer items, with fake Novaturas logos.

The comments section featured a fabricated dialogue between supposed winners, with some users asking questions about the prizes and others answering to create the impression of a legitimate contest. One Lithuanian user pointed out that Novaturas does not even produce creams with its own brand logo.

Clicking the link in the post redirected users to a website unrelated to Novaturas, belonging to travel agency TUI. The site’s instructions were in Swedish, and when translated to English, users were asked to answer a few simple questions about travel, then open three boxes to try their luck at winning a prize. Finally, users were asked to provide personal data, including name, surname, email address, phone number (only Swedish numbers were accepted), home address, and postal code.

Viktorija Ceizarienė, a Novaturas representative, advised the public to critically evaluate such posts and always check if they are published on official pages. “We announce our contests only on our official Instagram and Facebook pages, and we usually only ask participants for their email address. We never ask for any financial or sensitive data,” she said.

The National Cyber Security Centre (NKSC) representatives noted that social engineering scams remain one of the biggest cyber threats. They recommended that residents always verify if the information is published on the company’s official page or website, critically evaluate posts promising easily obtainable prizes or gifts, avoid clicking on suspicious links, and not provide login or bank details. In case of doubts, they advised contacting the company through official channels. Those who have suffered financial losses are urged to contact the Lithuanian police and their bank as soon as possible.

Source 
(via LRT)