Posted on

Recovery scams that target people already defrauded

Getting scammed once can make a person easier to target again.

Not because the victim somehow became gullible.

Because the first loss created a new, urgent problem: getting the money back.

The Federal Trade Commission warns that refund and recovery scammers specifically seek out people who have already been defrauded. Some buy or obtain lists of victims, then contact them pretending to be government agencies, consumer advocates, law firms, recovery specialists, or other helpers.

See the FTC’s refund and recovery scam guidance.

The second scam sells hope

The pitch usually contains something the victim desperately wants to hear.

Your money has been located. A special investigation recovered the funds. A lawyer can force the payment back. A government program is issuing refunds.

Then comes the condition.

The victim must first pay a retainer, processing fee, administrative charge, tax, or other supposed expense. Or the “helper” asks for bank details or identity information to process the recovery.

The FTC says legitimate government agencies and organizations do not require payment or financial account information in exchange for helping someone obtain a refund.

A guaranteed recovery should be especially suspicious. No legitimate investigator can honestly promise that stolen funds will be returned before examining the case.

Verify the helper independently

If someone contacts you unexpectedly about money you lost, do not use the contact details they provide to confirm their identity.

Look up the agency, law firm, company, or organization independently. Search its name with words such as “scam,” “complaint,” or “review.” If the caller claims to represent a government agency, find that agency’s official contact information yourself and ask whether the outreach was real.

Most importantly, do not send another payment simply because the person seems to know details about the original fraud.

Those details may be exactly how the second scammer found you.

The first scam creates the loss.

The recovery scam tries to monetize the hope of undoing it.

Posted on

Charity impersonation following disasters or public tragedies

A disaster compresses the time between seeing suffering and wanting to help.

That is good for legitimate relief organizations.

It is also useful to scammers.

The Federal Trade Commission warns that fraudsters create fake charities or impersonate established organizations after hurricanes, floods, earthquakes, wildfires, and other emergencies. Familiar names, copied logos, photographs, and urgent appeals can make a new donation page look like part of a real relief effort.

See the FTC’s 2026 guidance on disaster charity scams.

The emotional context does some of the scammer’s work

A donation request tied to a tragedy arrives with a ready-made reason not to delay.

People need food now. Families need shelter now. Recovery costs are immediate.

The scam does not have to invent urgency because the event already supplied it.

That is why the FTC recommends researching the organization independently, especially when the request arrives through social media, text, or a newly created site.

Look the charity up through established evaluators such as Give.org or CharityWatch. Find the organization’s official site on your own. If the request came by text, confirm the donation number through that official site rather than trusting the message.

A familiar name is not enough

Impersonation works by borrowing reputation.

A copied Red Cross logo does not create a Red Cross payment destination. A fundraiser shared by a friend is not automatically verified merely because the friend meant well.

Payment method can also reveal trouble. The FTC warns against supposed charities that insist on cash, gift cards, wire transfers, or cryptocurrency. Legitimate charities generally provide ordinary payment options and clear information about the organization receiving the funds.

The point is not to become suspicious of generosity.

It is to separate the decision to help from the decision about where the money goes.

A disaster may justify acting quickly.

It does not require donating through the first link that appears in front of you.

Posted on

Ticket scams built around scarcity and last-minute urgency

Ticket scams have a built-in timer.

The concert starts Friday. The game is tomorrow. The section is almost sold out. Someone else is supposedly ready to buy the seat if you hesitate.

Scarcity is normal in ticket markets, which makes fake scarcity unusually believable.

The Federal Trade Commission warned fans ahead of the 2026 FIFA World Cup that scammers may use copycat websites, paid search results, and social media to advertise fake tickets or even sell the same seat more than once.

See the FTC’s World Cup ticket scam guidance.

A picture of a ticket is not a ticket

A screenshot can look convincing while proving very little.

Modern event tickets may depend on an official app, rotating barcode, account-based transfer, or other system that determines whether the buyer actually has entry rights. A seller can send an image that resembles a ticket without transferring control of anything usable.

That is why the FTC recommends checking a resale platform’s buyer protections, delivery method, replacement policy, and refund terms before purchasing.

For events that use official electronic transfer, the transfer itself is more meaningful evidence than a PDF, screenshot, or promise that the ticket will arrive later.

Urgency should make verification more important, not less

A scammer wants the buyer focused on losing the opportunity.

The useful question is whether the seller can prove the opportunity exists.

Check the event organizer’s official ticketing page to learn which sales and resale channels are authorized. If buying through a third-party marketplace, inspect its guarantee and dispute process. Avoid payment methods that remove ordinary purchase protections simply because the seller says the deal must happen immediately.

Be especially wary of sellers who insist the ticket cannot be transferred through the platform normally used for the event.

The event really may be nearly sold out.

The seat really may disappear while you check.

That still does not make an unverifiable ticket worth buying.

Scarcity changes the price of hesitation.

It does not change the need for proof.

Posted on

Rental listings that collect deposits for unavailable properties

A rental scam does not need to invent a convincing apartment.

It can simply steal one.

The Federal Trade Commission warns that scammers copy real property photos, descriptions, and virtual tours, replace the legitimate contact information with their own, and repost the listing somewhere else.

The apartment exists.

The person collecting the deposit does not control it.

See the FTC’s rental listing scam guidance.

The pressure appears before verification

The fake landlord may claim to be traveling, living overseas, unavailable for an in-person showing, or dealing with so much interest that a deposit is needed immediately to reserve the property.

That urgency is useful to the scammer because normal rental verification takes time.

The victim may be asked for an application fee, security deposit, first month’s rent, or even identity documents before anyone has established that the supposed landlord owns or manages the property.

The FTC recommends searching the property address independently and comparing other listings. If the same address appears with a different owner, management company, or price, that is a serious warning sign.

It also recommends checking the actual rental company’s website and, when possible, seeing the property before paying.

Verify the property and the person separately

A real address does not prove the contact is real.

A real landlord name does not prove the person messaging you is that landlord.

Check county or city property records where available. Contact the property-management company through contact information found independently. Compare the listing against the company’s own site. If a private owner is involved, verify that identity against public ownership records rather than trusting a name copied into an email.

Payment method matters too. Requests for wire transfers, gift cards, cryptocurrency, or other difficult-to-reverse payments deserve extra suspicion.

The scam works because housing searches create natural pressure. Good rentals disappear quickly, moving dates are real, and applicants expect to hand over significant money.

The fraudulent listing borrows all of that legitimate urgency.

The safest response is to make the property wait long enough to prove that the person asking for the deposit has the right to rent it.

Posted on

Task scams that require deposits to unlock supposed earnings

Task scams begin by making earning money feel almost embarrassingly easy.

Rate a product. Like a video. Click through a set of listings. Perform some vague “optimization” task.

The supposed work happens inside an app or website that displays a growing commission balance. That balance is important because it makes the victim feel they are no longer evaluating a job offer.

They are protecting money they believe they have already earned.

The Federal Trade Commission has documented exactly this pattern. Task scams show users increasing supposed earnings, sometimes pay a small amount at first to build trust, and then require the user to deposit personal funds—often cryptocurrency—to unlock more tasks or withdraw the displayed balance.

See the FTC’s guide to task scams.

The deposit changes the direction of the job

A real job sends money toward the worker.

A task scam eventually reverses the flow.

The platform says the worker must cover a negative balance, unlock a premium task, complete a batch, recharge the account, or make some other deposit before the accumulated earnings can be released.

The displayed balance makes that request feel temporary. If the screen says $2,000 is waiting, sending $300 may feel like paying a small toll to recover a much larger amount.

But the FTC says the earnings displayed in these apps are fake.

There is no pile of commissions waiting behind the deposit requirement.

Never pay to get paid

That is the simplest useful test.

If an online job requires you to send money so that wages or commissions can be released, stop.

Do not send another payment because the platform says one final task, tax, fee, or account upgrade will unlock everything. That is how the loss grows.

The FTC recommends ignoring unexpected job messages through text, WhatsApp, Telegram, or social media and warns that legitimate employers do not require people to pay money to get paid.

A task scam is built around a psychological accounting trick.

The victim sees the fake balance as money already belonging to them.

The scammer sees it for what it actually is:

A number on a screen designed to make the next real deposit feel reasonable.

Posted on

Fake job offers that demand fees or sensitive information

A fake job offer works because the victim wants the thing being offered.

That sounds obvious, but it changes how the scam feels.

The message is not framed as a threat. It is framed as relief: remote work, better pay, flexible hours, or finally getting hired after a long search.

The Federal Trade Commission warns that scammers impersonate legitimate employers on job sites and social networks, sometimes sending professional-looking interview invitations and offer letters before asking for money or sensitive information.

See the FTC’s job scam guidance.

The suspicious request arrives after the offer feels real

One version asks the new “employee” to pay for equipment, training, certifications, background checks, or some other supposed onboarding expense.

Another asks for a Social Security number, driver’s license, bank account, or other identity information unusually early in the process.

The FTC’s advice is blunt: honest employers do not make candidates pay to get a job. It also warns against giving personal information before independently researching the employer and position.

A legitimate company may eventually need tax forms, identification, or direct-deposit information after hiring.

That does not make every request for those details legitimate.

Context matters.

If the recruiter has skipped normal interviewing, refuses to answer questions, uses an unrelated personal email account, or immediately turns the conversation toward money or banking details, the job itself deserves verification before anything else continues.

Confirm the employer through a route the recruiter did not provide

Do not use the phone number, email address, or website supplied by the suspicious recruiter to verify the recruiter.

Find the company’s official website independently. Check its careers page. Contact its human-resources department through known contact information and ask whether the role and recruiter are real.

The FTC also recommends searching the company and recruiter names with terms such as “scam,” “review,” or “complaint.”

A recognizable logo proves almost nothing. Logos are among the easiest parts of a company to copy.

The harder evidence is whether the actual company knows about the job.

Job seekers are already being asked to prove themselves.

A scam reverses that relationship and quietly avoids proving that the employer exists.

Posted on

Crypto wallet-draining sites disguised as ordinary participation opportunities

A fake crypto site often does not begin by asking someone to hand over coins.

It begins by asking them to participate.

Claim this reward. Join this mint. Connect your wallet. Verify eligibility. Receive an airdrop.

The page frames the action as ordinary participation in a project. The dangerous part is that the wallet may be asked to approve something broader than the user thinks they are doing.

The FBI has warned about malicious NFT airdrops advertised through social media, third-party sites, and phishing messages. Victims are directed to fraudulent pages that ask them to connect a wallet or provide information. The resulting action can allow criminals to move cryptocurrency out of the victim’s wallet.

See the FBI’s warning about fraudulent NFT airdrops and wallet theft.

The story and the permission are different things

A page can say the action is for one harmless purpose while the wallet is actually being asked to approve something else.

That is why the site’s wording is not the final authority.

The wallet prompt is.

Users should slow down and inspect what the wallet says will happen before approving a transaction or permission. If the request appears broader than the activity requires, cancel it.

A free token does not need mysterious authority over unrelated assets. A simple sign-in should not quietly become an asset-transfer approval.

Verify the opportunity outside the link

The FBI advises users who receive unexpected token or reward offers to verify the promotion directly with the cryptocurrency provider before connecting a wallet or supplying information.

That means finding the project’s official site independently rather than trusting a link from a post, direct message, email, or advertisement.

The same rule applies to urgency. A countdown, limited mint, exclusive whitelist, or disappearing reward is not evidence that the offer is genuine. It is evidence that the page wants the user to act before thinking.

If a suspicious wallet action has already been approved, review and revoke permissions using trusted wallet or network tools and move quickly if assets are at risk.

The important distinction is simple.

A wallet connection is not just a login button with a fox icon.

It can carry real authority.

The site tells a story about why it wants that authority. The wallet action reveals what authority is actually being requested.

Posted on

Investment scams that display fabricated account gains

A number on a screen can feel like proof.

That is exactly why fake investment platforms use one.

The scammer does not merely promise that an investment is doing well. The victim may receive access to a polished website or app showing account balances, charts, trades, and profits that appear to update like a real brokerage account.

The FBI has documented cryptocurrency investment schemes in which victims were directed to realistic-looking platforms controlled by scammers. Those platforms displayed false account balances and impressive returns. In some cases, victims were even allowed to withdraw a small amount early so the system would appear legitimate.

See the FBI’s Operation Level Up explanation of cryptocurrency investment fraud.

The balance is part of the sales pitch

A genuine account balance represents assets held somewhere under enforceable rules.

A fake balance can be whatever the operator wants it to be.

If the scammer controls the website, the scammer also controls the numbers displayed on the website. A reported gain of 18 percent may be no more substantial than changing a value in a database.

Investor.gov warns that relationship-investment scammers can manipulate online accounts, show fake trading information, or send fake screenshots to make supposed earnings look legitimate.

See Investor.gov’s relationship investment scam guidance.

The fraud often becomes obvious only when the victim tries to withdraw. Suddenly there is a tax, verification fee, liquidity requirement, account upgrade, or additional deposit required before the supposedly available money can be released.

Real money went in.

The profits existed only on the screen.

Verify the institution, not the dashboard

Before trusting an investment service, verify the company independently of the person who introduced it. Check whether the investment professional or firm is registered where registration is required. Search for enforcement actions, complaints, and the actual corporate identity behind the website.

Do not treat an early successful withdrawal as proof. The FBI has documented scammers allowing small withdrawals specifically to build confidence before asking for much larger deposits.

And do not send more money merely because the platform says money already in the account will otherwise be lost.

A legitimate investment can lose value.

A fraudulent investment can display any value it likes.

The dangerous moment is when the victim begins treating the display as evidence instead of asking whether the assets behind it can be independently verified.

Posted on

Romance scams that build trust before introducing a financial request

Romance scams are not usually built around one brilliant lie.

They are built around time.

The scammer creates a relationship first: regular messages, attention, shared plans, concern, affection, and a story explaining why meeting in person is difficult. Only after trust has accumulated does the financial problem appear.

The Federal Trade Commission describes the pattern plainly. A scammer may meet someone through a dating service or social platform, move the conversation elsewhere, claim to live or work far away, communicate frequently, and eventually ask for money for travel, medical expenses, emergencies, or another urgent need.

See the FTC’s guide to romance scams.

The money request arrives after the relationship feels real

That ordering is the mechanism.

A random stranger asking for hundreds or thousands of dollars has little leverage. Someone who has spent weeks or months acting like a partner has much more.

The emotional investment can make each new explanation easier to accept because rejecting the story also means reconsidering the relationship built around it.

Modern versions do not always ask for an emergency wire transfer. The FTC has also warned about online love interests who steer victims toward supposed cryptocurrency or investment opportunities. The request may be framed as something the couple is doing together rather than a simple loan.

See the FTC’s 2025 romance-scam warning.

Patterns matter more than embarrassment

The useful response is not to blame someone for believing a person who spent substantial effort becoming believable.

Look at the pattern instead.

The person cannot meet in real life. Communication moves off the original platform quickly. The story repeatedly creates reasons money is needed. Payment methods may be difficult to reverse, such as cryptocurrency, gift cards, wires, or money-transfer services.

The FTC recommends talking to someone you trust, searching the person’s claimed job or story alongside the word “scammer,” and performing a reverse-image search on profile photos when something feels wrong.

Most importantly, do not send money or gifts to an online romantic interest you have never met in person.

If money has already been sent, contact the payment company or financial institution quickly and ask whether the transaction can be stopped or reversed. Report the account to the platform and the fraud to the FTC.

Romance scams succeed by making the eventual payment request feel like a small chapter in a much larger relationship.

That is why the relationship itself can feel completely real to the victim.

The scammer spent time making sure it would.

Posted on

Security-alert fatigue exploited by repeated fraudulent notifications

Security warnings are supposed to interrupt routine behavior.

The problem begins when interruption becomes routine behavior.

Microsoft describes “push-bombing” or MFA-fatigue attacks in which an attacker repeatedly triggers authentication requests to a victim’s device. The victim is expected to deny the requests. The attacker is betting that enough buzzing, tapping, and confusion will eventually produce one accidental or exhausted approval.

See Microsoft’s security guidance on push-bombing and credential attacks.

Microsoft later reported observing roughly 6,000 MFA-fatigue attempts per day by the end of June 2023 and described repeated notifications as a social-engineering technique that can overwhelm or distract users.

See Microsoft’s guidance on protecting credentials from social engineering.

The attacker turns a safeguard into noise

An unexpected authentication prompt is useful because it tells the user that someone is attempting to sign in.

Twenty unexpected prompts create a different psychological problem.

The user may start treating them as background noise, assume the system is malfunctioning, or approve one simply to make the interruption disappear. That is alert fatigue: the warning remains technically visible while its ability to command careful attention declines.

This is not limited to authenticator apps. Fraudulent security emails, password-reset notices, browser warnings, and fake account alerts can all benefit from the same exhaustion if users are conditioned to click through warning after warning.

Do not resolve an unexpected alert through the alert itself

If you receive an authentication request you did not initiate, deny it.

Then open the account or security dashboard through a known route and inspect recent sign-in activity. Change a compromised password if appropriate, review active sessions, and use stronger authentication options the provider supports.

Microsoft has pushed number matching and phishing-resistant authentication partly because a simple Approve button is easier to abuse through repeated prompting.

See Microsoft’s phishing-resistant MFA guidance.

The important habit is to separate notification from action.

A warning can tell you something may be wrong.

It should not automatically decide what you click next.

The scammer wants the hundredth alert to receive less thought than the first.

Security only works if the hundredth one still gets checked.