WELCOME TO the official blog of
Bexley Borough Neighbourhood Watch Association (BBNWA),
Bexleyheath Police Station,
2 Arnsberg Way,
Bexleyheath, Kent
DA7 4QS.
Mobile Tel: 07496 385471
bexleynw@outlook.com
Charity No: 1072368
A local resident recently reached out on Nextdoor following a distressing incident in our community. On Wednesday 19th August at around 12:30 pm, a flat was burgled by two men posing as electricians.
Personal items were taken, and the victim is appealing to the neighbourhood for any information or CCTV footage that might help identify those involved.
Details of the Incident
Date & Time: Wednesday, 19th August at 12:30 pm
Suspect Descriptions: Two men dressed in dark clothing, masquerading as tradesmen.
Key Distinguishing Feature: One suspect captured on a doorbell camera entering the block is described as 5ft 6in to 5ft 8in, slim build (around 10–11 stone), with a visible bite mark or scar on the left side of his face.
How You Can Help
Check Security Footage: If you live nearby, please review your doorbell cameras, home CCTV, or dashcam footage from around 12:30 pm on Wednesday 19th August for anyone matching this description.
Report Information: If you recognize the man described or saw anyone acting suspiciously around the block at that time, please report it to the police via 101 or submit an anonymous tip through CrimeStoppers on 0800 555 111.
Crime impacts the whole neighbourhood, and sharing relevant footage or information can make a significant difference in helping the victim recover lost items and ensuring our streets stay safe. Please keep an eye out and share this appeal with nearby residents.
If you have recently seen a warning circulating on Nextdoor, WhatsApp, or Facebook about fake "Home Affairs Officers" collecting fingerprints and photos for an upcoming census, you are not alone. The notice warns residents that thieves with laptops and biometric readers are posing as officials to break into homes.
However, you can rest easy: this viral post is a hoax.
Where Did the Hoax Come From?
This message first surfaced around 2017 in South Africa, where the national government does indeed include a "Department of Home Affairs". Over the years, the exact text has been copy-pasted across North America, Australia, and the UK without modification.
How to Spot Why It Doesn't Apply to the UK:
Incorrect Terminology: The UK government uses the Home Office, not the "Home Affairs Department".
No Biometric Census: Official UK censuses are managed by the Office for National Statistics (ONS). Government field officers will never ask to capture your fingerprints or take your photograph on your doorstep.
Chain Mail Dynamics: The post ends with classic viral chain-letter phrases urging you to "Send this to all your community groups."
How to Handle Doorstep Safety
While this specific message is fake, staying vigilant about genuine doorstep callers is always sensible practice:
Always check ID: Genuine officials carry official photo identification and will never mind waiting outside while you verify their details.
Use a door chain: Speak to unknown callers through a window or with a door chain engaged.
Report suspicious activity: If someone is acting suspiciously at your door, report it to Action Fraud or call 101 (or 999 in an emergency).
Instead of forwarding the hoax warning, feel free to share this article with your local neighborhood groups to set the record straight!
Securing your online accounts with strong, unique passwords is key to
protecting yourself, but those passwords won't help much if they're
stored somewhere criminals can easily access.
From a cluttered inbox to shared cloud storage folders you might have
forgotten about, we reveal where you need to avoid storing your
passwords – and where to keep them instead.
If you'd prefer 1-2-1 technical advice from Which? experts, including
advice on online security and scams, you can join Which? Tech Support.
Our friendly team is there to chat on the phone or by email as often as
you need. Find out more about the support on offer.
Scam calendar invites are a form of phishing designed to manipulate you
into responding, confirming to scammers that your email is active and
making you a target.
Using urgent messages, fake alerts and flashing warnings, scam pop-ups
are designed to cause panic and persuade you into handing over personal
information or downloading malicious software.
If you use WhatsApp regularly, a brand-new security feature has just been released that fundamentally changes how your privacy and personal data are protected online.
Historically, sharing your WhatsApp details meant giving out your actual mobile phone number. Because your mobile number is often linked to sensitive personal accounts—such as online banking, email logins, and government services—handing it over to strangers, new acquaintances, or online sellers carried inherent security risks. Once cold callers, spammers, or fraud syndicates got hold of your number, your handset could easily be bombarded with unwanted calls and phishing texts.
WhatsApp's latest update fixes this major flaw by introducing usernames and an optional security PIN system, removing the need to share your primary phone number ever again.
Key Features Explained
Custom Usernames: Instead of revealing your personal mobile number, you can now create a unique username to share with people you wish to connect with on WhatsApp. Anyone who has your username can message or call you on the app, while your real phone number remains completely hidden.
Easy Username Management: Unlike a phone number—which is difficult and inconvenient to change if compromised—you can update or edit your WhatsApp username at any time if you want to block unwanted contact.
PIN Protection ("Contact Me by Username"): For an additional layer of crime prevention, you can restrict who can initiate a conversation using your username by enabling a PIN. Even if a scammer discovers your username, they will be unable to contact you unless you have provided them with this specific security PIN.
Step-by-Step Setup Guide
Open WhatsApp on your smartphone.
Tap the three dots in the top right-hand corner (or go to your app options) and select Settings.
Tap on Account, then look for the new Username option.
Select Create Username, choose a unique and memorable name, and check its availability. Once selected, save it to reserve your handle.
To restrict unknown contacts further, tap Contact Me by Username and select People who know my key.
WhatsApp will generate a secure PIN code. Share this PIN alongside your username only with people you explicitly wish to permit to contact you. You can review or change this PIN in your Settings whenever needed.
Security, Privacy & Crime Prevention Advice
Minimise Phone Number Exposure: Your main mobile number is key identity data. Keep it strictly private and restrict its use to trusted institutions (like your bank or healthcare providers). Use your WhatsApp username for day-to-day networking, online marketplaces, and new acquaintances.
Enable Two-Step Verification: In addition to setting up a username PIN, ensure you have enabled WhatsApp’s built-in Two-Step Verification (found under Settings > Account > Two-step verification). This prevents account takeover attacks if someone attempts to register your phone number on another device.
Watch Out for Phishing & Impersonation Scams: Scammers frequently use WhatsApp for "Hi Mum/Dad" impersonation frauds or malicious link sharing. Never share security PINs or verification codes with anyone, even if they claim to be from WhatsApp support or a family member in distress.
Keep the App Updated: Cyber threats evolve constantly. Always update WhatsApp via the official Google Play Store or Apple App Store to ensure you have the latest security patches and privacy features.
By taking a couple of minutes to set up your username and security PIN today, you significantly reduce your risk of targeted spam, identity theft, and messaging scams.
Mobile banking apps have made managing our money simpler than ever, but cybercriminals are constantly finding clever ways to exploit our devices. As highlighted in a security guide by The Phone Guardian (watch the video on YouTube), fraudsters are no longer relying solely on tricking you into giving away your online banking passwords.
Instead, they trick users into installing malicious apps or granting dangerous permissions on Android phones. These hidden "spyware" apps can record your login details as you type them, monitor your screen, and siphon funds straight out of your account—often while you are fast asleep.
To help protect your hard-earned cash, follow these 5 essential crime prevention steps to secure your phone today.
Step 1: Audit Your Accessibility Permissions
Malicious apps rely on elevated system access (such as Accessibility Services) to read what is on your screen or log keystrokes.
How to check: Go to Settings > Search for Accessibility > Tap Installed apps (or Downloaded apps).
What to look for: You will see legitimate tools listed here, but watch out for everyday utility apps (such as a flashlight, PDF scanner, or calculator app).
Action: A standard calculator or flashlight has no legitimate reason to require full accessibility control. If you see any unfamiliar or unexpected apps on this list, tap them and select Disable or Uninstall immediately.
Step 2: Turn Off SMS Autofill Features
When your bank sends you a One-Time Passcode (OTP) via text message to verify a transaction, the message usually contains critical details—such as the payee name and transfer amount. Enabling autofill features bypasses this crucial line of defence.
How to check: Go to Settings > Google (or your Google Account settings) > All services > Autofill and passwords > Verification codes by SMS.
Action: Switch off both "Autofill codes in apps and sites" and "Autofill codes in your default browser". Manually reading and entering passcodes ensures you actually see and double-check any transaction warnings.
Step 3: Remove Saved CVV / Security Codes
While storing card numbers in your browser is common, saving the 3-digit CVV/CVC code from the back of your bank card gives fraudsters everything they need to make unauthorized purchases if your device is compromised.
How to check: Open Google Chrome > Tap the 3 dots (top-right) > Settings > Payment methods.
Action: Turn off "Save security codes". Additionally, ensure "Verify autofill payment methods" is turned ON. This ensures that using any saved card details always requires your fingerprint, facial recognition, or screen lock password.
Step 4: Restrict SMS Permissions
Your text inbox receives sensitive verification messages and security alerts from your bank. You should strictly limit which applications can read your SMS messages.
How to check: Go to Settings > Search for Permissions > Tap Permission Manager > Select SMS.
Action: Review the list of apps with access to your text messages. Revoke permission for any app that does not strictly require text functionality to operate.
Step 5: Run a Password Safety Checkup
Data breaches occur frequently across the web. If a password you reuse for mobile accounts has been leaked online, criminals can use automated tools to break into your profiles.
How to check: Go to Settings > Google > Manage your Google Account > Security > Password Manager > Tap Checkup.
Action: Review any Compromised passwords flagged by Google and change them immediately. Ensure you use strong, unique passwords for every online service, particularly for your primary email and banking accounts.
Taking a few minutes to complete these checks can drastically improve your phone’s security and protect your bank account from fraud. Share this advice with family and friends to ensure their devices remain secure as well!
Ever opened Google Drive only to find it claims you are running out of space, even though your folders look completely empty? You are not alone.
Your total Google Account storage (for example, 28 GB used out of 102 GB) is shared across Google Drive, Google Photos, and Gmail. The storage indicator in the sidebar shows your overall account usage, not just the files saved in your Drive folders.
Common Reasons for Hidden Storage Usage
Google Photos & Gmail: Large photo libraries, high-resolution videos, or old emails with heavy attachments consume space from the exact same quota.
WhatsApp & App Backups: Hidden app backups (such as WhatsApp device backups) store hidden data on Google Drive without showing up as regular files.
Items in the Bin / Trash: Deleted files, emails, or photos remain stored in your Bin for 30 days unless manually emptied.
Orphaned / Unorganised Files: Files you uploaded into shared folders that were deleted by the owner lose their folder directory and become orphaned in your account.
How to Find and Clean Up Space
Check Storage Allocation: Go to one.google.com/storage in a web browser to see an exact breakdown of how many GBs are taken up by Drive, Photos, and Gmail.
Sort Drive Files by Size: Open drive.google.com/drive/quota to view all files owned by you, sorted from largest to smallest.
Check Hidden App Data: On the web version of Google Drive, click Settings (gear icon) > Settings > Manage Apps to check for app backups (like WhatsApp) and delete hidden app data if needed.
Search for Orphaned Files: Type is:unorganized into the Google Drive search bar to reveal lost files that still take up storage space.
Empty Your Bins: Head to the Bin in Drive, Gmail, and Google Photos, then click Empty bin to permanently remove those files.
Pro Tip: Save Space in Google Photos with "Storage Saver"
If Google Photos is eating up most of your quota, enabling Storage Saver (formerly known as High Quality) can free up massive amounts of storage.
What is Storage Saver?
Photos: Compressed and capped at 16 MP (large images are stored as standard high-resolution JPEGs).
Videos: Compressed to 1080p Full HD resolution (anything shot higher, like 4K, is automatically scaled down).
Quality Impact: For standard viewing, social media sharing, and standard printing, the visual difference is virtually unnoticeable.
How to Enable It:
For Future Uploads (Mobile App): Open the Google Photos app > tap your Profile icon > Photos settings > Backup > Backup quality > select Storage saver.
Compress Existing Uploads (Web Browser): Go to photos.google.com/settings > click Manage storage > scroll to Recover storage > select Convert existing photos & videos to Storage saver.
Note: After clearing large files, emptying the bin, or compressing photos, Google Storage can take up to 24–48 hours to update your overall account balance.
As controls to prevent authorised push payment (APP) scams improve,
criminals are changing tactics and increasingly tricking people into
approving card payments instead. This leaves victims without the refund
protections they expect.
Our team of fraud experts is always on the lookout for scams targeting people across the UK.
This week, watch out for an email that's impersonating Nationwide, and a TV Licensing scam.
Check out the full list, based on your reports to our Which? Scam Action Alerts Facebook community and scam sharer tool.
We spoke to an Amazon customer whose account was hacked by a fraudster
on TikTok Shop. She discovered 26 unauthorised Amazon orders had been
placed without her knowledge, totalling £1,418.
Planning your next getaway? Be on high alert for a sophisticated scam currently targeting travellers who use Booking.com.
How the Scam Works
Fraudsters are exploiting security breaches at the individual hotel level to access legitimate reservation details. Because the scammers know your full name, booking dates, hotel location, and reference number, their communications can appear remarkably convincing.
Here is how the fraud typically unfolds:
Direct WhatsApp Messages: Victims are contacted on WhatsApp by someone claiming to represent their booked accommodation.
Artificial Urgency: You will be told there is an issue with your payment card details and warned that your reservation will be cancelled within 24 hours unless you re-verify them.
Cloned Web Links: You are sent a link to a website designed to look identical to the official Booking.com payment portal, where your bank and card details are stolen.
2FA Code Theft: In some cases, scammers may even phone you directly, posing as customer support, and ask you to read out a two-factor authentication (2FA) text code to compromise your accounts.
How to Protect Yourself and Outsmart the Fraudsters
Many genuine hotels do use WhatsApp to communicate with guests, so you shouldn't ignore messages automatically—but you must verify them using these quick checks:
Check the Country Code: Verify that the sender’s phone number matches the country code of your holiday destination. A message regarding a hotel in Spain sent from a South American country code is a major red flag.
Inspect the Link: Look carefully at any web address provided. Phishing links often feature extra hyphens, misspellings, or random sequences of letters attached to the domain name.
Cross-Reference Details: Search the telephone number on the hotel’s official site to see if it matches their contact information.
Phone the Hotel Directly: If in any doubt, do not click the link or reply on WhatsApp. Call the hotel directly using the telephone number provided on your original confirmation email or official website.
Never Share Verification Codes: No legitimate company will ever phone you and ask you to read out a security or two-factor authentication code sent to your mobile phone.
Bottom line: Always pause before acting on urgent payment demands, double-check web addresses, and contact your accommodation directly through verified channels if something feels amiss. Safe travels!
An alert has been posted on the Barnehurst Gossip Facebook page regarding potential catalytic converter thefts in the area.
Incident Details
Location: Barnehurst / Bexley area
Activity: Masked individuals targeted for catalytic converter theft
Vehicle Involved: Black Volkswagen Golf
Registration: GL67 NXB (reported as potential cloned/fake plates)
Prevention & Action Advice
Park Securely: Whenever possible, park in a garage or well-lit, busy area close to fences, walls, or other vehicles to restrict access underneath your car.
Etch or Mark Your Converter: Consider getting your catalytic converter marked with a unique serial number or fitting an approved anti-theft device/cage.
Report Suspicious Behaviour: If you see anyone acting suspiciously around parked vehicles or attempting a theft in progress, call 999 immediately. Do not confront the individuals yourself. Non-urgent reports or information can be submitted to the Metropolitan Police via 101 or online.
Four fire engines and around 25 firefighters tackled a grass fire near Martens Avenue in Bexleyheath.
Around 400 square metres of woodland was damaged by the fire.
Control Officers took the first of nine calls at 0751 and mobilised
crews from Plumstead, Sidcup, Bexley and East Greenwich fire stations to
the scene. The fire was extinguished by 0959.
Rogue advertisers can camouflage their ads on your favourite websites to
trick you into adding your card details. You might see a prompt urging
you to 'Verify and Continue' or 'Download' a file, but it's actually a
disguised ad designed to blend in seamlessly with a website’s normal
content.
It can be difficult to spot a fake or scam website, and artificial
intelligence tools have made it easier than ever for criminals to set up
a convincing-looking site in minutes.
However, there are often telltale signs that a website is a scam. Our fraud expert, Faye Lipson, has pulled together
some straightforward checks to work out whether an online retailer is legitimate.
Fake holidays can be an effective way for fraudsters to lure you in with
tempting deals to harvest your data and steal large sums of money. Some
holiday scams can be incredibly hard to spot, too.
When we think of Neighbourhood Watch, our minds naturally jump to physical home security: locking front doors, fitting window latches, and keeping an eye on our streets. However, cybercrime is now one of the fastest-growing threats facing UK households. From online banking scams to email account takeovers, keeping your digital identity secure is just as critical as bolting the back gate.
Most of us rely on passwords combined with Two-Factor Authentication (2FA)—usually a 6-digit code sent via SMS text message. While text codes are better than passwords alone, criminals can easily trick you into typing those codes into fake websites (phishing) or steal them by intercepting your mobile number (SIM swapping).
To upgrade your digital security, hardware security keys (such as a YubiKey) offer simple, physical, and phishing-resistant protection.
What Is a Security Key and Why Use One?
A security key is a small USB device that plugs into your computer or taps against your smartphone using NFC (Near Field Communication). Instead of typing a text code, touching the key proves to a website that you are physically present and own the device.
1. Phishing Resistance
The biggest advantage of a security key is that it checks the exact web address (URL) in your browser. If a scammer tricks you into visiting a fake website designed to look like your bank or email provider, the security key detects the fraud and refuses to log in. Even if a criminal steals your password, they cannot access your account without your physical key.
2. Simple Physical Verification
There are no 6-digit numbers to read, memorize, or type out before they expire. You simply insert the key into a USB port or tap it to the back of your mobile phone.
5 Steps to Set Up Your Key Safely
Setting up a security key is straightforward, but following these steps ensures you stay protected without risking locking yourself out:
1.Get Two Keys (Primary & Backup):Prevents accidental account lockout.
Buy two matching keys. Register both to your online accounts at the same time. Keep one on your keyring for daily use, and lock the secondary backup key away somewhere safe at home.
2.Secure Your Email Account First:Protect your master account first.
Start by securing your main email address. Because email accounts are used to reset passwords across all other services, securing your inbox stops fraudsters from taking over your digital life.
3.Add the Key in Account Security Settings:Find the 2FA settings on your online services.
Log into your account (such as Google, Apple, or Microsoft), go to Settings > Security, and choose Add Security Key or Passkeys.
4.Plug In, Tap, and Set a PIN:Add an extra layer of defence.
Follow the on-screen prompts to insert or tap your key. Set a personal PIN code when asked—this ensures that even if someone physically steals your key, they cannot use it without your secret PIN.
5.Print and Store Backup Recovery Codes:Essential for emergency account access.
During setup, websites will generate offline emergency recovery codes. Print these out and keep them locked away with your backup key. If both keys are lost, these codes are your only way to regain access.
Quick Community Safety Checklist
Lock your screens: Always lock your computer (Windows Key + L, or Command + Control + Q on Mac) if you step away with a key plugged in.
Keep backup keys safe: Never leave secondary keys or printed recovery codes near your computer; treat them like passport documents.
Prioritise your accounts: Focus on securing your main email, password managers, and financial services first.
Taking a few minutes to upgrade your digital authentication helps protect not just your personal data, but our wider community from online financial scams.
For a full walkthrough on choosing and configuring hardware keys, watch the complete tutorial on YouTube:YubiKey 101 – What It Is, How It Works, and How to Set It Up. Taking a few minutes to upgrade your digital authentication helps protect not just your personal data, but our wider community from online financial scams. This is a beginner friendly guide to hardware security keys and phishing resistant MFA.
BBNWA security keys infographic - click image to view enlarged