Posted on

The division of responsibility among hosts, ad networks, payment services, and platforms

A deceptive website is rarely just a website.

It may use one company for the domain, another for hosting or security, a third for advertising, a fourth for payment, and a fifth platform to find victims. The browser may maintain its own phishing blocklist. The victim’s bank may control a dispute process. Law enforcement controls none of those systems directly but may investigate the people behind them.

That makes the obvious question — Who is responsible for taking this down? — harder than it sounds.

Different companies control different levers

An ad network can stop buying traffic for the scam.

Google’s advertising policies prohibit phishing, malicious software, and ads that impersonate trusted entities. Enforcement can therefore remove an advertiser or destination from the ad system even if Google does not host the underlying site.

See Google’s phishing policy and malicious-software advertising policy.

A hosting provider can potentially remove content it actually hosts. A registrar controls the domain registration relationship. A security or CDN provider may only sit between the visitor and an origin server.

Cloudflare’s abuse documentation explicitly notes that what it can do depends on which Cloudflare service the reported site uses. A site merely passing through Cloudflare’s network is a different situation from content hosted on Cloudflare infrastructure or a domain registered through its registrar.

See Cloudflare’s abuse-reporting documentation.

A payment provider or card issuer controls another layer. It may be able to stop a merchant relationship, investigate a transaction, or process a dispute. The FTC advises marketplace buyers who paid by credit or debit card to dispute fraudulent transactions with the card company while also reporting dishonest sellers to the marketplace and regulators.

See the FTC’s online marketplace guidance.

The gaps appear at the handoffs

Each participant can truthfully say it does not control the entire fraud.

That can still leave the victim with a live scam.

The ad network may remove the ad while the site remains online. The host may act while a replacement domain appears. The payment path may close while the scammer switches processors. A marketplace may remove an account while the same operator continues through search ads or social media.

No single intervention is guaranteed to erase the operation.

But that does not mean nobody has meaningful power.

Practical ability is not the same as legal duty

It is useful to separate two questions.

What can this company technically or contractually do?

And what is this company legally required to do?

The first can often be answered from the provider’s service role and published policies. The second depends on jurisdiction, facts, contracts, regulatory rules, and sometimes litigation. It should not be guessed from a company’s ability to press a button.

The distributed web creates distributed responsibility.

That architecture is resilient when no single company can control everything.

It is maddening when a victim discovers that the same decentralization also means the scam can exist in the spaces between companies that each control only one piece.

The practical answer is not to search for one universal sheriff of the internet.

It is to identify every lever the operation depends on — visibility, domain, hosting, account, payment, browser trust, and law enforcement — and make sure the report reaches the party that can actually move that lever.

Posted on

Victim-reporting obstacles that allow deceptive sites to remain operational

A victim can know exactly which website stole their money and still have no single obvious place to report it.

The scam may have arrived through an advertisement, used a domain registered by one company, passed through a security or CDN provider, taken payment through another service, and impersonated a seller on a platform operated by somebody else.

Each company sees a different slice of the event.

The victim sees the whole mess.

The Federal Trade Commission asks consumers to report fraud through ReportFraud.ftc.gov and explains that those reports can help investigators identify patterns and build cases. The FBI separately directs online fraud victims to the Internet Crime Complaint Center at IC3.gov.

See the FTC’s explanation of why fraud reports matter and the FBI’s fraud-reporting guidance.

Infrastructure reports go somewhere else

Law-enforcement reporting does not automatically remove the web page.

A browser-security service may need a phishing report. An ad network may have a separate advertiser-abuse process. A hosting or infrastructure company may require URLs and evidence through its own abuse form.

Cloudflare’s abuse documentation makes the fragmentation unusually visible. Its response depends on which Cloudflare service is involved: pass-through CDN and security service, registrar, or content actually hosted on its platform.

See Cloudflare’s abuse-reporting documentation.

That distinction is technically reasonable. It is also a lot to ask from somebody who just got robbed by a fake store.

Better reports need both evidence and ownership

A useful report should preserve the exact URL, screenshots, timestamps, transaction records, messages, advertiser information when visible, and the method used to pay.

But good evidence is only half of the problem.

Someone also needs to own the next step.

Reporting systems are more effective when they make clear what the receiving organization can actually do, whether the report was accepted, and where to send the complaint if the organization is merely an intermediary.

The web’s anti-fraud machinery is distributed because the web itself is distributed.

That is not automatically a failure.

The failure comes when every participant has a report form and nobody appears responsible for making the harmful thing disappear.

Posted on

Malicious browser extensions promoted as useful everyday utilities

A browser extension can earn installation with a job so ordinary that almost nobody treats it like software with privileges.

Convert a file. Change the new-tab page. Find coupons. Translate text. Take screenshots. Adjust volume.

The function may fit in one sentence.

The permissions may not.

Google’s Chrome documentation explains that extensions can request access ranging from bookmarks and browsing history to data on every website a user visits. Some permission levels can allow an extension to read or modify page data, observe tabs, or interact with information copied by the user.

See Google’s guide to extension permissions.

Convenience does not define the permission boundary

A utility can genuinely perform the advertised task and still ask for more access than that task seems to require.

That is why the install screen matters.

The browser is not merely asking whether the extension sounds useful. It is asking whether the publisher should receive the listed capabilities.

A malicious or compromised extension can abuse broad access after installation, while the visible feature continues working normally enough to avoid suspicion.

Google’s guidance tells users to install extensions only from publishers they trust and to pay attention to requested permissions. Chrome Safe Browsing also checks installed extensions against known unsafe items.

See Google’s extension installation guidance and Safe Browsing documentation.

Evaluate the publisher and the scope

Before installing a browser utility, ask whether its permissions make sense for its function.

A screenshot tool may need access to the current page. A simple calculator should have a much harder time explaining why it needs to read data across every site you visit.

Check the publisher, store history, update history, reviews, and whether the requested permissions changed unexpectedly in a recent update. Remove extensions you no longer use.

The danger is not that browser extensions are inherently untrustworthy.

It is that a tiny convenience can quietly become one of the most privileged pieces of software in the browser.

The icon may occupy sixteen pixels.

The permission grant can cover nearly everything behind it.

Posted on

Shopping refunds used as a pretext to obtain remote access

A refund sounds like money moving toward the customer.

That makes it an effective excuse for asking the customer to cooperate.

Scammers send messages about an unexpected purchase, subscription renewal, overcharge, or refund. The message says to call a number if the charge is wrong. Once the victim calls, the supposed support agent claims remote access is needed to process or verify the refund.

The Federal Trade Commission documents this pattern in tech-support and refund scams. Scammers may impersonate well-known companies, obtain remote access, display a fake refund screen, and then claim an error caused too much money to be returned.

See the FTC’s tech-support scam guidance and its warning about refund impostors requesting remote access.

Remote control is not a normal refund requirement

A real merchant may need an order number, payment method, return authorization, or confirmation that an item was sent back.

It does not need to operate your desktop to put money back on the card that paid for the purchase.

Remote access changes the situation completely. The person on the other end may be able to view information on screen, manipulate what appears to happen, direct the victim through financial websites, or install additional software.

The original shopping problem becomes a pretext for computer access.

Verify the refund through the merchant you already know

If a message says a purchase or refund requires urgent attention, do not use the phone number or remote-access link in that message as proof of legitimacy.

Open the merchant’s app or website independently. Check your actual order history and your real bank or card statement. Contact customer service through information from the merchant’s official site.

The FTC states that it will never require remote access or payment to deliver an FTC refund. The same question is useful with commercial refunds: why would returning my money require control of my computer?

A refund should reduce a customer’s exposure to a bad transaction.

It should not create a much larger one.

Posted on

Fake escrow services that manufacture confidence between strangers

Escrow exists because two strangers have a trust problem.

The buyer does not want to send money before receiving the goods. The seller does not want to release the goods before payment is secure. A genuine intermediary can hold funds until agreed conditions are met.

That sounds safe enough that scammers sometimes imitate the intermediary itself.

The FBI has warned people selling items online to be suspicious when a supposed buyer pushes an unfamiliar online escrow service. In those scams, the service that appears to protect both sides is actually controlled by the fraudster or exists only to receive the victim’s money.

See the FBI’s guidance on online-sale fraud.

A neutral middleman is valuable only if it is actually neutral

A polished escrow site can manufacture confidence quickly.

It may display transaction numbers, status screens, customer-service contacts, legal-looking terms, or logos suggesting professional payment handling. None of those things independently establish that the company exists or is holding funds as claimed.

The scam works because the victim thinks verification has already been outsourced to the intermediary.

But the intermediary is the part that still needs verification.

Check the safety mechanism itself

Do not accept an escrow service simply because the other party supplied the link.

Research the company independently. Type the address yourself rather than following a seller or buyer’s link. Check whether the business has a real history, contact information, and regulatory or licensing information appropriate to the service it claims to provide.

For ordinary marketplace transactions, the FTC recommends staying inside the marketplace’s own payment system because moving outside it can eliminate protections the platform offers.

See the FTC’s online marketplace buying guidance.

A safety layer is useful when it separates the buyer and seller from unilateral control of the money.

A fake escrow service does the opposite.

It adds a reassuring third party to the transaction while quietly making that third party the scammer.

Posted on

Deepfake voice and video used as false identity evidence

For most of the telephone era, recognizing someone’s voice was useful evidence of identity.

It is weaker evidence now.

The FTC has warned that scammers can use short audio clips to clone a family member’s voice and place convincing emergency calls. The FBI has separately documented campaigns using AI-generated voice messages while impersonating senior U.S. officials.

See the FTC’s warning about AI voice-cloning emergency scams and the FBI’s 2025 impersonation alert.

Resemblance is no longer authentication

A convincing voice, face, or video can still be useful context.

It just cannot carry the entire burden of proof when the request matters.

If a familiar-looking executive suddenly requests a confidential transfer, or a relative’s voice asks for emergency cryptocurrency, the audiovisual resemblance is part of the claim being tested. It is not independent confirmation of that claim.

This is an awkward change because human recognition is fast and deeply practiced. We are used to treating “I heard her voice” or “I saw him on video” as the end of the identity question.

Synthetic media turns those observations into one signal among several.

Move verification outside the suspicious interaction

The FBI recommends independently confirming a claimed identity when something unexpected or consequential is requested. That can mean calling a known number, using an established organizational channel, or checking with another person who can verify the request.

For families, a previously agreed word or question can add another signal, but the broader principle matters more: do not let the suspicious call define the only path for confirming itself.

Deepfakes do not make identity unknowable.

They make passive recognition less sufficient.

A voice can sound right. A face can look right. A video call can feel immediate and personal.

The decision still deserves evidence that did not come from the same channel asking for the money, credentials, secrecy, or access.

Posted on

Fake prize notifications that require a processing payment

A fake prize scam begins by making the victim feel richer before any money has changed hands.

The message may announce cash, a car, electronics, or a sweepstakes win. It may borrow the name of a familiar company. The important part comes next: before the prize can be released, the supposed winner must pay taxes, shipping, handling, customs charges, or a processing fee.

The Federal Trade Commission’s rule of thumb is pleasantly simple: real prizes are free.

See the FTC’s guide to prize and sweepstakes scams and its 2026 prize-scam warning.

The fee changes the meaning of the prize

A legitimate prize gives value to the winner.

A scam prize first asks the winner to send value in the opposite direction.

That payment may be described as a small administrative step compared with the promised reward. A person who believes millions are waiting may see a few hundred dollars in fees as trivial.

That comparison is part of the trap. The large imaginary balance makes the smaller real payment feel reasonable.

Scammers also use urgency because verification is dangerous to them. The victim may be told the offer expires today or that the claim will be forfeited unless payment is made immediately.

Verify the award outside the notification

If you did not enter the contest, that is an obvious reason to be skeptical. Even if you did enter something, do not use the phone number, link, or payment instructions in the winning message as your proof that the message is real.

Find the organization independently and contact it through information you located yourself.

Do not send money, gift-card numbers, cryptocurrency, or account information to obtain a prize.

A prize notification should survive independent verification.

If the entire reward disappears the moment you refuse to pay a “processing fee,” there was never much of a prize to process.

Posted on

Counterfeit software update notices that exploit routine maintenance habits

Software updates have trained users to do something useful: when a trusted program says it needs a security update, install it.

That routine is valuable enough to steal.

Mozilla documents fake Firefox update pages that interrupt browsing with warnings about an “important,” “urgent,” or “critical” update. Some arrive through advertisements or redirects. Others claim Firefox requires a manual download and try to convince the user to install malware or a malicious extension.

See Mozilla’s warning about fake Firefox updates.

The scam borrows authority from maintenance

The page does not need to explain why the user should trust an unknown executable.

It presents the file as something the browser itself already needs.

That collapses two separate decisions into one. The user thinks, Should I update Firefox? The actual question is, Should I run a file offered by this unrelated webpage?

Those are not the same transaction.

Mozilla notes that Firefox normally updates through its own automated mechanism. A random webpage demanding that the user manually download and execute an update is therefore a warning sign, even if the page uses the correct logo, browser name, and security language.

Check from inside the real product

The safest verification route is usually boring.

Ignore the page. Open the application’s own update function, operating-system package manager, official app store, or publisher website that you reached independently. If an update is genuinely required, the trusted channel should be able to confirm it.

Do not save or run an unsolicited installer merely because a webpage says the situation is urgent.

The important distinction is where the update instruction originated.

Real software maintenance is part of the relationship between the user and the software publisher.

A counterfeit update notice inserts a stranger into that relationship and hopes the user will not notice the handoff.

Posted on

Bait-and-switch offers that substitute a different product after engagement

Bait-and-switch is older than the web.

The web simply made the bait clickable.

A customer sees an attractive product, price, plan, or condition and begins the transaction because of that representation. After engagement, the advertised option turns out to be unavailable, unsuitable for reasons the seller already knew, or replaced by a different product or more expensive condition.

The Federal Trade Commission defines classic bait-and-switch advertising as promoting a product without a genuine intention to sell it in order to establish contact with the customer and induce the purchase of something else.

See the FTC’s Advertising FAQs.

The bait matters because it starts the transaction

By the time the switch appears, the customer may have already spent time comparing options, created an account, entered personal information, traveled to a store, begun an application, or progressed through several checkout screens.

That investment creates pressure to continue rather than restart the search.

The FTC’s dark-pattern taxonomy uses bait and switch more broadly for interfaces where a choice or interaction leads to an unexpected and undesirable outcome. One example is a user clicking what appears to be a close control and getting software downloaded instead. Another is receiving something materially different from what was originally advertised.

See the FTC’s Bringing Dark Patterns to Light.

Not every substitution is deception

Products genuinely sell out. Inventory changes. A customer may discover that another model fits better. A seller can recommend alternatives.

The key question is whether the original offer was honestly available on the represented terms and whether the customer is clearly told when those terms change.

A legitimate substitution says, in effect: the thing you wanted is no longer available; here are alternatives, and you are free to walk away.

A bait-and-switch strategy uses the original offer mainly to get the customer committed enough that walking away becomes less likely.

That distinction is why the first representation matters even if the final product is technically acceptable.

The customer did not begin evaluating the final offer from a neutral starting point.

They were pulled into the transaction by a different one.

A fair sales process can change course.

It should not need a decoy to get the customer through the door.