Ctrl+Alt+EliteRESOURCESExplore Ctrl+Alt+Elite ↗
Menu +

Ctrl+Alt+Elite / Community resource

Recognize the pattern.
Choose your next move.

A searchable library of scams, impersonation tactics, and cyber threats. Find the warning signs, learn how a pattern works, and take a more informed next step.

126 entries · 11 categories · Adapted from the June 2026 library; web edition reviewed September 14, 2026. An educational reference, not a live threat feed.

126 of 126 entries · Open an entry for warning signs and next steps.

Phishing / Social Eng.

Email Phishing

Mass or targeted emails impersonating trusted brands to harvest credentials, install malware, or deliver fraudulent invoices.

What you might notice

  • Spoofed sender domain
  • Generic greeting (Dear Customer)
  • Urgent call to action
  • Link URL ≠ brand domain
  • Attachment with macro

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Email / branded lookalike websites

Link to this entry
Phishing / Social Eng.

Spearphishing / Whaling

Highly targeted email using real personal details (name, role, colleagues, recent projects) scraped from LinkedIn and data brokers.

What you might notice

  • Personalized with accurate personal or professional detail
  • References real project, vendor, or colleague
  • Bypasses standard email filters
  • Requests financial action or credential
  • No grammar errors — reads like a real colleague

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Email / LinkedIn InMail

Link to this entry
Phishing / Social Eng.

Smishing (SMS Phishing)

Fraudulent text messages impersonating USPS, FedEx, banks, or toll agencies with links to credential-harvest pages.

What you might notice

  • Impersonates USPS, FedEx, bank, or toll agency
  • Urgency: package held, account locked, toll unpaid
  • Short link or unfamiliar URL
  • Odd area code / no caller ID
  • Asks you to click or reply immediately

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: SMS / RCS messages

Link to this entry
Phishing / Social Eng.

Vishing (Voice Phishing)

Calls impersonate government agencies, banks, employers, or support teams to obtain money, access, or sensitive information. Caller ID and a convincing voice can be spoofed.

What you might notice

  • Government name invoked immediately
  • Arrest or account seizure threat
  • Demands gift cards, wire, or crypto
  • Spoofed caller ID from a real number
  • Urgency: act now or face consequences

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Phone / VoIP / AI voice clone system

Link to this entry
Phishing / Social Eng.

Quishing (QR Code Phishing)

Malicious QR codes embedded in emails, physical flyers, or placed as stickers over legitimate codes (parking meters, restaurant menus, conference signage) redirect victims to credential-harvest pages.

What you might notice

  • QR code in unexpected email context
  • URL after scanning ≠ brand domain
  • Physical sticker placed over original code
  • Asks for credentials or payment immediately after scan
  • No obvious phishing signal — everything looks normal

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Email attachments / physical signage / parking meters / menus

Link to this entry
Phishing / Social Eng.

Calendar Phishing

Unexpected calendar invitations contain fake renewals, urgent meeting requests, or links to credential-stealing pages.

What you might notice

  • Unexpected calendar invite from unknown sender
  • Invite claims account expires or renewal is needed
  • Link in invite goes to unfamiliar domain
  • Appears alongside legitimate calendar events
  • Sent from a Gmail or Google account posing as a service

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Google Calendar / Microsoft Outlook / iCal

Link to this entry
Phishing / Social Eng.

Pharming (DNS Redirect)

Malicious code on your device or a poisoned DNS server silently redirects you to a fake site even when you type the correct URL directly.

What you might notice

  • Site looks right but certificate is wrong or missing
  • Credentials rejected after entry (attacker captured them)
  • Unexpected pop-ups or login prompts post-visit
  • Multiple users on the same network affected simultaneously

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep browser, operating system, and router software updated. Do not bypass certificate warnings. Use trusted network and DNS settings; encrypted DNS alone does not make a malicious destination safe.

Where it can appear: Malware-infected device / compromised home router / poisoned DNS

Link to this entry
Phishing / Social Eng.

AITM / MFA-Bypass Phishing

A phishing site relays a real login and tries to steal credentials or session cookies, potentially defeating some forms of multi-factor authentication.

What you might notice

  • Login page is a pixel-perfect clone of the real one
  • MFA code accepted but you didn't initiate a login
  • Session hijacked while still logged in
  • Often delivered via targeted email or SMS with realistic pretext
  • Standard phishing filters do not block it — it passes SPF/DKIM

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use phishing-resistant passkeys or security keys where supported. Verify the real service domain and report suspicious logins. If a session is stolen, revoke affected sessions as well as changing credentials.

Where it can appear: Email / SMS → reverse proxy phishing kit → legitimate-looking login page

Link to this entry
Phishing / Social Eng.

MFA Fatigue / Push Bombing

Attacker already has your username and password (from a breach or infostealer).

What you might notice

  • Multiple unexpected MFA push notifications you didn't initiate
  • Caller claims to be IT resolving an MFA issue
  • Notifications arrive at unusual hours
  • You're told to "approve just this one" to stop the alerts
  • The push request comes right after the caller's story

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Microsoft Authenticator push / Duo push / any push-based MFA system

Link to this entry
Phishing / Social Eng.

Credential Stuffing

Automated bots take username/password pairs from data breaches and simultaneously try them across hundreds of websites, exploiting password reuse.

What you might notice

  • Account locked after you didn't attempt to log in
  • Login alert from unfamiliar location or device
  • Unusual account activity you didn't initiate
  • Downstream accounts compromised after one site's breach
  • Your password was correct but "suspicious activity" triggered a hold

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use a different strong password for every account and enable multi-factor authentication. Change exposed or reused passwords and review active sessions. These steps reduce risk; they do not eliminate every takeover method.

Where it can appear: Any online account where you reuse passwords from a site that was breached

Link to this entry
Phishing / Social Eng.

Typosquatting / Homograph Attack

Attackers register domains that look identical to real ones using typos (googe.com), character substitution (0 for o, rn for m), or Unicode homoglyphs (Cyrillic "а" visually identical to Latin "a").

What you might notice

  • Domain has an extra letter, transposition, or number substitution
  • Arrives via search ad or embedded link — not a URL you typed
  • HTTPS certificate exists but domain is slightly wrong
  • Homoglyph attack: letters look identical but are different Unicode characters

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Search engine ads / phishing email links / copy-pasted URLs

Link to this entry
Phishing / Social Eng.

Watering Hole Attack

Attackers compromise a website that a specific target audience visits regularly (an industry forum, a government contractor portal, a trade association site) and inject malware that silently infects visitors.

What you might notice

  • Device compromised with no phishing email or suspicious download
  • Malware appeared after visiting a routine, legitimate-seeming site
  • Specific industry or government sector is the target
  • No user action beyond visiting the site was required

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Compromised legitimate websites in target-relevant industries

Link to this entry
Phishing / Social Eng.

Malicious Browser Extension

A browser extension (productivity tool, VPN, ad blocker, tab manager) secretly harvests credentials, session tokens, payment data, or browsing history — often from a legitimate-looking extension that was hijacked after gaining user trust, or purchased and weaponized after the original developer sold it.

What you might notice

  • Extension requests more permissions than its function requires
  • Installed from outside official browser store, or via sideloading
  • Performance or browser behavior changed after install
  • Session hijacks or credential compromises shortly after installation
  • Extension updated silently and behavior changed

These are possible warning signs, not proof of fraud on their own.

A safer next step

Review an extension’s publisher, purpose, and permissions, and remove unused extensions. Ratings alone are not proof of safety. Watch for permission changes after updates.

Where it can appear: Chrome / Firefox / Edge extension stores / sideloaded installs

Link to this entry
Identity / Account

Synthetic Identity Fraud

Criminals combine a real SSN (often a child's or recently deceased person's) with fabricated names and birthdates to create a "Frankenstein" identity.

What you might notice

  • Unfamiliar accounts appearing on your credit report
  • Child's SSN flagged during tax filing as already used
  • Unexpected credit inquiry you didn't authorize
  • Collections calls for accounts you didn't open
  • Accounts at addresses you've never lived at

These are possible warning signs, not proof of fraud on their own.

A safer next step

Review credit records and consider credit freezes through the official credit bureaus, including the process for children when applicable. A freeze reduces some new-account risks but does not prevent all identity misuse.

Where it can appear: Credit bureaus / online lenders / crypto exchanges / neobanks / government benefit systems

Link to this entry
Identity / Account

Account Takeover (ATO)

Attacker uses stolen credentials, phishing, SIM swap, or session token theft to gain access to your account — then locks you out and drains it or uses it to attack others.

What you might notice

  • Password reset email or SMS you didn't request
  • Locked out of your own account suddenly
  • Transactions or changes you didn't make
  • New device or location added to your account
  • Contact list receives messages you didn't send

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use unique passwords and multi-factor authentication, review account activity, and secure recovery methods. Contact the provider through its official recovery process if you suspect unauthorized access.

Where it can appear: Any online account — especially email, banking, crypto, and social media

Link to this entry
Identity / Account

Brand Impersonation / Spoofing

Emails, texts, or websites impersonating Amazon, PayPal, Apple, Netflix, banks, or other trusted brands using nearly-identical logos, sender names, and domain names differing by one character.

What you might notice

  • Sender domain is slightly off (amaz0n.com, paypa1.com)
  • Generic greeting (Dear Customer, Dear User)
  • Link in email goes to unfamiliar domain
  • Urgency: account limited, order issue, payment failed

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use unique passwords and multi-factor authentication, review account activity, and secure recovery methods. Contact the provider through its official recovery process if you suspect unauthorized access.

Where it can appear: Email / SMS / social media ads / search engine ads

Link to this entry
Identity / Account

Government Impersonation

Callers, emailers, or fake websites impersonating the IRS, SSA, FBI, CBP, Medicare, or local police.

What you might notice

  • Arrest or legal action threatened immediately
  • Demands same-day payment
  • Gift cards, wire transfer, or crypto requested
  • Multi-hour video call with "officer" in uniform
  • Caller knows your name and some real personal details

These are possible warning signs, not proof of fraud on their own.

A safer next step

Do not pay or disclose sensitive information because of an unexpected threat. Independently contact the relevant agency using its published official details. Government impersonators often demand gift cards, cryptocurrency, or urgent transfers.

Where it can appear: Phone / email / fake .gov lookalike websites / video call

Link to this entry
Identity / Account

Law Enforcement Virtual Interrogation

A sophisticated government impersonation variant: victims receive a call or video from someone posing as a police officer or customs agent charging them with money laundering, drug trafficking, or identity theft.

What you might notice

  • Multi-hour or multi-day video "interrogation" by fake officer
  • Fake badge, uniform, and official-looking background on video
  • Threats of immediate arrest if you hang up
  • Demands for payment to "resolve" criminal charges
  • Caller knows your name, address, or partial SSN

These are possible warning signs, not proof of fraud on their own.

A safer next step

End coercive contact and independently verify the claim with the relevant agency. Requests to stay on a video call and send money to avoid arrest are serious warning signs. Seek emergency help if there is an immediate threat.

Where it can appear: Phone / video call (Zoom, WhatsApp, FaceTime, Google Meet)

Link to this entry
Identity / Account

Social Media Account Hijacking

Attacker takes over Instagram, Facebook, LinkedIn, or TikTok via phishing, credential stuffing, or SIM swap — then uses the account to scam contacts, sell the account, or extort the victim with their own content.

What you might notice

  • Friends receive unusual DMs from your account asking for money
  • You're locked out with a changed email or phone number
  • New posts, ads, or stories you didn't create
  • Follower count changes dramatically
  • Account suddenly follows new accounts you didn't select

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use unique passwords and multi-factor authentication, review account activity, and secure recovery methods. Contact the provider through its official recovery process if you suspect unauthorized access.

Where it can appear: Instagram / Facebook / LinkedIn / X (Twitter) / TikTok

Link to this entry
Identity / Account

SIM Swapping (SIM Hijacking)

A criminal tricks or compromises a mobile provider to transfer a phone number to a device they control, potentially intercepting calls and SMS recovery codes.

What you might notice

  • Sudden complete loss of all cellular service
  • Password reset texts or emails you didn't request
  • Locked out of banking, email, or crypto accounts
  • Carrier notification about a SIM or account change you didn't make
  • Friend reports receiving odd calls from your number

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use unique passwords and multi-factor authentication, review account activity, and secure recovery methods. Contact the provider through its official recovery process if you suspect unauthorized access.

Where it can appear: Carrier customer service (social engineering) / compromised carrier employee / carrier portal phishing

Link to this entry
Financial / Investment

Pig Butchering (Romance-Investment Fraud)

An online contact builds trust over time and steers the person toward a fraudulent investment platform. Fake profits and additional withdrawal demands can prolong the deception.

What you might notice

  • Unsolicited contact from attractive stranger on app, LinkedIn, or wrong-number text
  • Investment platform is "exclusive" or "invite-only"
  • Profits shown on dashboard but withdrawal is always blocked by fees
  • Platform not listed on any regulatory database
  • Relationship moves to investment topic after weeks of relationship-building

These are possible warning signs, not proof of fraud on their own.

A safer next step

Do not send more money to unlock a suspicious withdrawal. Independently verify the platform and any investment professional. Registration records are useful but do not guarantee safety. Contact your financial provider and report suspected fraud.

Where it can appear: Dating apps / WhatsApp / LinkedIn / Telegram / "wrong number" texts

Link to this entry
Financial / Investment

Phantom AI Trading Bot

A seller promotes a supposed AI trading bot with guaranteed profits, but the service or results are fabricated to take customers’ money.

What you might notice

  • Guaranteed monthly return percentage promised
  • Black box algorithm you cannot independently verify
  • Requires cryptocurrency deposit to "activate the bot"
  • Pressure to recruit friends or family for bonus returns
  • No verifiable regulatory registration

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat guaranteed high returns as a warning sign. Verify the offering and seller independently through relevant regulators. A claim that AI is involved does not establish legitimacy or reduce investment risk.

Where it can appear: Telegram / WhatsApp / social media ads / email

Link to this entry
Financial / Investment

Fake AI Equity / Pump-and-Dump

Scammers sell pre-IPO shares in fictitious AI startups or use deepfake celebrity videos to hype penny stocks and tokens, then dump their holdings at the peak.

What you might notice

  • Pre-IPO offer with heavy AI/tech branding
  • Celebrity or influencer endorsement (often AI-generated deepfake)
  • Urgency: limited-time investment window
  • No SEC registration or CRD number provided
  • Promises of extraordinary returns in a short timeframe

These are possible warning signs, not proof of fraud on their own.

A safer next step

Stop and verify the person, company, and offer independently before sending money. Do not treat a referral, polished website, claimed AI capability, or apparent profits as proof. Contact your financial provider immediately if money may have been stolen.

Where it can appear: TikTok / Instagram Reels / YouTube / email / text

Link to this entry
Financial / Investment

Advance Fee Fraud (419 / Nigerian Prince)

A promised windfall, inheritance, prize, or business opportunity is used to request an upfront payment; the promised benefit does not arrive.

What you might notice

  • Promise of large sum in exchange for small upfront payment
  • Sender claims foreign legal or banking obstacle requires your help
  • Requests gift cards, wire, or crypto to release the funds
  • Increasingly polished language and official-looking documents

These are possible warning signs, not proof of fraud on their own.

A safer next step

Stop and verify the person, company, and offer independently before sending money. Do not treat a referral, polished website, claimed AI capability, or apparent profits as proof. Contact your financial provider immediately if money may have been stolen.

Where it can appear: Email / WhatsApp / Telegram / social media DMs

Link to this entry
Financial / Investment

Affinity / Community Fraud

Scammers exploit trust within a close-knit community — church, military, veteran, ethnic, or professional group — to pitch fraudulent investments.

What you might notice

  • Investment pitched within a trusted group by a known member
  • Only for "our community" framing — exclusivity appeal
  • Discourages outside verification ("don't tell a broker")
  • Word-of-mouth referral chain with no independent confirmation
  • Consistent, unusually high returns reported by early investors

These are possible warning signs, not proof of fraud on their own.

A safer next step

Stop and verify the person, company, and offer independently before sending money. Do not treat a referral, polished website, claimed AI capability, or apparent profits as proof. Contact your financial provider immediately if money may have been stolen.

Where it can appear: Religious organizations / veteran groups / ethnic communities / professional networks

Link to this entry
Financial / Investment

Real Estate Wire Fraud / Closing Cost Scam

Criminals intercept email communications between homebuyers and their title company or real estate attorney, then send fraudulent wire instructions diverting closing funds to their account.

What you might notice

  • Last-minute change to wire instructions via email close to closing date
  • New bank account or routing number provided at an unusual time
  • Email looks identical to prior legitimate correspondence
  • Sender asks you not to call to verify — says it's urgent

These are possible warning signs, not proof of fraud on their own.

A safer next step

Stop and verify the person, company, and offer independently before sending money. Do not treat a referral, polished website, claimed AI capability, or apparent profits as proof. Contact your financial provider immediately if money may have been stolen.

Where it can appear: Email (real estate transaction communications) / compromised email accounts

Link to this entry
Financial / Investment

Deed / Title Theft

Criminals use forged documents and stolen identity to fraudulently transfer ownership of your property — often a rental property, vacant property, or recently inherited home — then take out loans against it or attempt to sell it.

What you might notice

  • Unfamiliar mortgage statements arriving at your address
  • Notices from a county recorder for documents you didn't file
  • Inability to refinance or sell due to an "existing lien" you didn't know about
  • Neighbor or tenant contacts about a "new owner"
  • Property tax notices going to a different address

These are possible warning signs, not proof of fraud on their own.

A safer next step

Check property records and any available county recorder alerts. If you find an unauthorized filing, contact the recorder, law enforcement, and a qualified lawyer. Monitoring services do not prevent every fraudulent transfer.

Where it can appear: County recorder offices / forged notarization / data broker personal information

Link to this entry
Financial / Investment

Money Mule Recruitment

A fake job, relationship, or business offer recruits someone to receive and transfer money for others. The funds may be stolen, exposing the participant to financial and legal consequences.

What you might notice

  • Job involves receiving money and forwarding a portion
  • Told to keep a percentage as "commission"
  • Asked to use your own personal bank account for "business" transactions
  • Work-from-home job with no clear product, service, or employer identity
  • Employer sends you a check to deposit before your start date

These are possible warning signs, not proof of fraud on their own.

A safer next step

Do not agree to move money for strangers or an unverified employer. If you are already involved, stop transferring funds and contact your bank and qualified legal help. Preserve relevant communications.

Where it can appear: Job boards (Indeed, LinkedIn) / social media / romance scam conversion / direct email

Link to this entry
Financial / Investment

Recovery Scam (Revictimization)

Fraudsters specifically target prior fraud victims — purchasing victim lists or monitoring fraud forums — posing as law firms, FBI agents, or "asset recovery specialists" offering to recover lost funds for an upfront retainer fee.

What you might notice

  • Contacted after a known prior fraud loss
  • Claims government or law firm affiliation
  • Requires upfront retainer or processing fee before recovery begins
  • May have specific details about your original fraud (purchased victim list)
  • Asks you to pay in gift cards or crypto — no legitimate firm does this

These are possible warning signs, not proof of fraud on their own.

A safer next step

Be skeptical of unsolicited recovery offers or guarantees. Verify a professional’s identity and credentials independently. Do not share account access or send additional funds under pressure; legitimate fees alone do not prove or disprove fraud.

Where it can appear: Email / phone / social media targeted at known fraud victims

Link to this entry
Financial / Investment

Crypto Wallet Drainer / NFT Rug Pull

Malicious wallet approvals can allow unauthorized transfers. A separate pattern, a rug pull, involves promoters taking funds and abandoning a token or project.

What you might notice

  • MetaMask or wallet shows "Approve" request with unlimited token spend
  • NFT project with anonymous team and no verifiable development roadmap
  • Promises of massive ROI with little technical explanation
  • Smart contract has not been audited by a reputable firm
  • Discord or Telegram has many members but no substantive discussion

These are possible warning signs, not proof of fraud on their own.

A safer next step

Review wallet permissions and transaction details before signing. Do not connect a wallet to an unverified site. Hardware wallets cannot protect you from every malicious transaction you approve.

Where it can appear: DeFi platforms / NFT marketplaces / Telegram / Discord

Link to this entry
Financial / Investment

Investment Club / Social Media Pump-and-Dump

Fake "investment clubs" on Facebook, Discord, or Telegram recruit members to simultaneously buy specific low-priced stocks or tokens, pumping the price.

What you might notice

  • Private group pushing a single security or token urgently
  • Admins are anonymous or unverifiable
  • Claims of insider information or exclusive access
  • Coordinated timing for entry with specific buy targets
  • All group members seem uniformly enthusiastic

These are possible warning signs, not proof of fraud on their own.

A safer next step

Do independent research and be cautious of coordinated hype, pressure, and promised profits. Do not rely on group administrators as impartial advisers. Report suspected manipulation to the relevant securities regulator.

Where it can appear: Facebook Groups / Discord / Telegram / Reddit / Twitter/X

Link to this entry
Financial / Investment

Courier Cash / Crypto Kiosk Scam

Government impersonators instruct victims to withdraw large amounts of cash for a courier to collect, or direct victims to a Bitcoin ATM to "resolve" a legal issue.

What you might notice

  • Government caller demands immediate cash or crypto payment
  • Courier arrives at your home to collect an envelope of cash
  • Directed to a Bitcoin ATM with instructions on what to type
  • Threats of arrest if you tell family members or hang up
  • Caller stays on the phone the entire time you travel to the ATM

These are possible warning signs, not proof of fraud on their own.

A safer next step

Stop and verify the person, company, and offer independently before sending money. Do not treat a referral, polished website, claimed AI capability, or apparent profits as proof. Contact your financial provider immediately if money may have been stolen.

Where it can appear: Phone calls

Link to this entry
Financial / Investment

Unregistered Investment Solicitor

Individual with a professional-looking website and polished pitch solicits investments without any regulatory registration.

What you might notice

  • Refuses or is unable to provide a FINRA CRD number
  • Claims "exclusive" access not available through registered advisors
  • Vague about their firm name, physical address, or regulatory oversight
  • Guarantees or implies specific return percentages
  • Pressures you to decide quickly before the opportunity closes

These are possible warning signs, not proof of fraud on their own.

A safer next step

Stop and verify the person, company, and offer independently before sending money. Do not treat a referral, polished website, claimed AI capability, or apparent profits as proof. Contact your financial provider immediately if money may have been stolen.

Where it can appear: LinkedIn / cold calls / social media / referrals within a network

Link to this entry
Financial / Investment

Fake Lottery / Prize Scam

Victim is told they've won a sweepstakes, gift card, or cash prize they never entered.

What you might notice

  • You didn't enter any contest
  • Must pay an upfront fee to claim your prize
  • High-pressure deadline to act before the prize is forfeit
  • Requests SSN or banking information to "deposit winnings"
  • Prize is an unusually large or specific amount

These are possible warning signs, not proof of fraud on their own.

A safer next step

Stop and verify the person, company, and offer independently before sending money. Do not treat a referral, polished website, claimed AI capability, or apparent profits as proof. Contact your financial provider immediately if money may have been stolen.

Where it can appear: Email / mail / phone / social media ads / fake contest websites

Link to this entry
Extortion

Sextortion

Someone threatens to share intimate images or fabricated sexual material unless demands are met. Some mass emails use old breached passwords as a scare tactic; threats involving real images also occur.

What you might notice

  • Includes one of your old real passwords in the email
  • Bitcoin or Monero wallet address provided
  • 48–72 hour countdown deadline creates urgency
  • Threatens to send video to your entire contact list

These are possible warning signs, not proof of fraud on their own.

A safer next step

Do not send more images or money. Preserve evidence and report the account through the platform and law enforcement. For images involving minors, seek help from NCMEC through its official site. If anyone is in immediate danger, contact emergency services.

Where it can appear: Email

Link to this entry
Extortion

"I Know Where You Live" Extortion

Email includes your real home address and often a Google Maps screenshot of your street, threatening physical harm or reputation destruction unless you pay crypto.

What you might notice

  • Includes your real home address (from data brokers)
  • Google Maps or satellite image of your home attached
  • Bitcoin or Monero demand with a wallet address
  • Specific physical threat or threat to harm your family
  • Your name, employer, or other personal details included

These are possible warning signs, not proof of fraud on their own.

A safer next step

Preserve the message and verify concerns through trusted channels. Publicly available personal details do not prove surveillance, but do not dismiss credible threats of harm. Contact local authorities when appropriate.

Where it can appear: Email

Link to this entry
Extortion

AI Voice Clone / Virtual Kidnapping

A caller imitates a loved one’s voice or fabricates a kidnapping to pressure someone into paying. A convincing voice alone cannot establish whether an emergency is real.

What you might notice

  • Sudden call with panicked voice of a family member
  • Caller keeps you on the line to prevent verification
  • Demands immediate wire, Zelle, cash, or crypto
  • Voice may have slight synthetic quality under emotional stress
  • Unknown number — but the voice is unmistakably your family member

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use a separate known contact method to reach the person or another trusted contact. Do not rely solely on voice recognition. If you cannot confirm safety and there may be an emergency, contact local emergency services.

Where it can appear: Phone calls / voice messages

Link to this entry
Extortion

Business Email Compromise (BEC)

Attacker — having compromised or spoofed an executive's email — instructs a finance employee to wire funds urgently, often referencing a real vendor or M&A transaction.

What you might notice

  • Unusual payment request via email from a C-suite account
  • Instructs bypassing normal approval process or financial controls
  • Secrecy requested: "Don't discuss this with anyone yet"
  • No paper trail, contract reference, or prior notice
  • New bank account details provided with the request

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause, preserve evidence, and seek help through a trusted channel. Do not rely on the caller’s identity or claims as proof. Contact local emergency services if anyone may be in immediate danger; report suspected extortion to law enforcement.

Where it can appear: Email (compromised or spoofed executive account)

Link to this entry
Extortion

Deepfake CEO / BEC Video Fraud

A video call where the "CEO" or executive appears visually real and instructs a finance employee to wire funds or authorize a transaction.

What you might notice

  • Financial instruction via video call without prior context
  • Subtle glitches: unnatural blink rate, lighting inconsistency, face boundary blur
  • Bypasses normal financial approval channels
  • Meeting not scheduled through normal means
  • Executive asks you not to mention it to others yet

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause, preserve evidence, and seek help through a trusted channel. Do not rely on the caller’s identity or claims as proof. Contact local emergency services if anyone may be in immediate danger; report suspected extortion to law enforcement.

Where it can appear: Video calls (Zoom / Teams / Google Meet)

Link to this entry
Extortion

Ransomware (Extortion)

Attackers encrypt data, steal it, or threaten disclosure to demand payment. Organizations may face several forms of extortion at once.

What you might notice

  • Files suddenly renamed with an unknown extension (.locked, .enc, etc.)
  • Ransom note appears in every folder and on desktop
  • Systems unavailable organization-wide
  • Sudden disk activity spike followed by inability to access files
  • Services unavailable alongside a ransom demand

These are possible warning signs, not proof of fraud on their own.

A safer next step

Maintain tested backups protected from the production environment, patch systems, and restrict access. For an incident, involve qualified responders and law enforcement. Paying does not guarantee recovery or prevent disclosure.

Where it can appear: Phishing email attachment / unpatched VPN or RDP / malicious ad download

Link to this entry
Consumer / Lifestyle

Online Shopping Scam / Counterfeit Goods

Fake e-commerce sites or marketplace listings sell counterfeit, non-existent, or vastly inferior products — especially clothing, electronics, luxury items, and sports merchandise.

What you might notice

  • Price significantly below market rate
  • No physical address, return policy, or customer service contact
  • Reviews look templated or are all 5-star with no detail
  • Site appeared via social media ad — not a known retailer
  • Crypto-only or unusual payment options

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Instagram / Facebook / TikTok ads / search engine ads / fake marketplace listings

Link to this entry
Consumer / Lifestyle

Fake Antivirus / Scareware

Pop-ups, browser tabs, or downloaded programs falsely claim your device is infected with viruses and urge you to pay for "cleanup software" that is itself malware, or to call a number that leads to a tech support scam and remote access compromise.

What you might notice

  • Alarming pop-up claiming a specific number of viruses found
  • Website plays a scary audio alarm
  • Browser tab cannot be closed normally
  • Call-a-number prompt to fix the "infection"
  • Pop-up appears while browsing a legitimate-seeming site

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Browser pop-ups / malicious ads / fake software download sites

Link to this entry
Consumer / Lifestyle

Tech Support Scam

Callers claim to be from Microsoft, Apple, Google, or Norton saying your device has a virus.

What you might notice

  • Pop-up with phone number claiming device is infected
  • Audio alarm playing in browser you can't close
  • Caller knows your name (scraped from data brokers)
  • Asks for remote access via AnyDesk or TeamViewer
  • Demands gift card payment for the "service"

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Browser pop-ups / outbound cold calls / search ad injection

Link to this entry
Consumer / Lifestyle

Ticket Scalping / Fake Event Tickets

Fraudulent ticket listings supply nonexistent, duplicated, or invalid tickets for concerts, sports, and other events.

What you might notice

  • Seller won't meet in person for ticket exchange
  • Requests crypto or Zelle payment with no buyer protection
  • Ticket price far above face value with urgency pressure
  • No official venue or authorized resale platform association
  • Reseller just created their account or profile

These are possible warning signs, not proof of fraud on their own.

A safer next step

Buy through the venue or an authorized seller and read the actual buyer-protection terms. Avoid pressure to pay outside the platform. A screenshot or barcode image is not proof a ticket is valid.

Where it can appear: Facebook Marketplace / Craigslist / StubHub lookalike sites / social media DMs

Link to this entry
Consumer / Lifestyle

Puppy / Pet Scam

Fake listings for purebred puppies or exotic pets at below-market prices.

What you might notice

  • Puppy available immediately at an unusually low price
  • Seller is "overseas," a "missionary," or "deployed military"
  • Requires wire transfer or Zelle as a deposit
  • Escalating fees added after initial payment — always one more charge
  • No in-person viewing or live video of the actual animal offered

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Craigslist / Facebook Marketplace / fake breeder websites / Google search results

Link to this entry
Consumer / Lifestyle

Home Repair / Disaster Recovery Scam

"Storm chasers" or fake contractors appear immediately after natural disasters (floods, hurricanes, hail, tornadoes) offering quick, cheap repairs requiring large upfront payment.

What you might notice

  • Unsolicited door-to-door offer immediately after a storm or disaster
  • Requires large cash payment upfront before any work begins
  • No license, insurance, local address, or verifiable business history
  • Urgency: "other homeowners are booking up fast"
  • Asks you to sign over your insurance claim to them

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify licensing and references, obtain written estimates, and check local rules on deposits. Avoid pressured full upfront payment. Review any assignment of insurance rights carefully before signing.

Where it can appear: Door-to-door solicitation / community Facebook groups / disaster-affected neighborhoods

Link to this entry
Consumer / Lifestyle

Travel Scam (Fake Hotels / Vacation Rentals)

Fake vacation rental listings, cloned hotel booking sites, or fraudulent package tours collect full payment for accommodations that don't exist or are misrepresented.

What you might notice

  • Listing requires payment outside the platform (Zelle, wire, crypto)
  • Price significantly below comparable properties in the same area
  • Listing photos fail a reverse image search — stolen from elsewhere
  • "Owner" is overseas and can't show the property in person or live video

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Airbnb lookalike sites / VRBO clones / Facebook Marketplace / direct email offers

Link to this entry
Consumer / Lifestyle

Student Loan / Debt Relief Scam

A deceptive service charges for promised loan forgiveness or debt relief that it does not provide, misrepresents, or claims only it can obtain.

What you might notice

  • Upfront fee required for "guaranteed" forgiveness
  • Claims government affiliation but has no .gov email or website
  • Asks for your Federal Student Aid (FSA) ID and password
  • Promises immediate or guaranteed forgiveness within a specific timeframe
  • Initiates contact via unsolicited call, text, or social media

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Phone / email / social media ads / online ads

Link to this entry
Consumer / Lifestyle

Tax Identity Theft / IRS Refund Fraud

Criminal files a tax return using your SSN before you do and claims your refund.

What you might notice

  • IRS rejects your return: "a return with this SSN was already filed"
  • Unexpected IRS notice for income from an employer you didn't work for
  • Refund is smaller than expected or arrives at an address you don't recognize
  • IRS notice about a return you didn't file

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Stolen SSN / dark web purchased credentials / data breaches feeding fraudulent filing

Link to this entry
Consumer / Lifestyle

Medicare / Medicaid / Hospice Fraud

Fraudulent providers bill Medicare for services never rendered, unnecessary equipment, or patients not actually terminally ill (hospice fraud).

What you might notice

  • Unsolicited hospice enrollment offer with "no cost to you" framing
  • Request for Medicare or Medicaid number by phone or door-to-door
  • Explanation of Benefits showing services or equipment you didn't receive
  • Unfamiliar provider billing Medicare for your care

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Phone / door-to-door / fraudulent healthcare referrals / fake Medicare card offers

Link to this entry
Consumer / Lifestyle

Elder Fraud / Senior Targeting

Scammers may target older adults through impersonation, investment, romance, prize, or support schemes. Anyone can be affected by these tactics.

What you might notice

  • Multiple scam attempts in rapid succession
  • Increased social isolation from family
  • Unusual large cash withdrawals or gift card purchases
  • New "friend," "romantic interest," or "grandchild" making financial requests
  • Reluctance to discuss new financial decisions with family

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Phone / email / door-to-door / social media / in-person at banks

Link to this entry
Consumer / Lifestyle

Task Scam / Fake Micro-Job

Victims are recruited via WhatsApp or Telegram to complete "simple tasks" (liking YouTube videos, rating products, writing reviews) for pay.

What you might notice

  • Recruited via unsolicited WhatsApp or Telegram message
  • Tasks are simple: rating, reviewing, liking content
  • Small initial earnings paid promptly to build trust
  • Asked to "deposit" funds to unlock access to the next task level
  • Platform claims you need to pay more before you can withdraw your earned balance

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: WhatsApp / Telegram / social media DMs

Link to this entry
Consumer / Lifestyle

Subscription Trap / Dark Patterns

"Free trial" signups with buried auto-renewal terms charge full price after a trial period.

What you might notice

  • "Free trial" requires credit card before you can try anything
  • Cancel button is buried, non-functional, or requires calling a phone number
  • Full price disclosed only in fine print or after sign-up
  • Charges appear under an unfamiliar or generic company name on your statement

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Online signup flows / mobile app onboarding / streaming services

Link to this entry
AI-Native Threats

ChatGPhish / AI Chatbot Phishing Surface

Untrusted content supplied to an AI assistant can cause misleading links or credential requests to appear in its response.

What you might notice

  • Phishing link appears inside an AI assistant's response
  • You only asked the AI to summarize what appeared to be a normal page
  • Auto-fetched images from attacker server capture your IP address
  • No traditional phishing indicators visible — everything looked normal until the AI spoke

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat links in AI output as unverified. Check a destination against an independently known official address; copying an attacker’s URL into the address bar does not make it safe.

Where it can appear: ChatGPT / Gemini / Claude / any AI assistant with web-browsing or Markdown rendering capabilities

Link to this entry
AI-Native Threats

Grokking / AI Bot Phishing Amplification

A social-platform AI assistant may repeat a malicious link from an untrusted post, making the recommendation appear more credible.

What you might notice

  • Phishing link appears in a platform AI bot's reply
  • Post is a paid video ad with high impressions
  • Link is buried in a non-obvious field (caption, description) of the post
  • Bot endorses the link as part of a trusted-seeming summary

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat AI-generated messages, recommendations, voices, and images as unverified. Confirm sensitive requests through an independent channel. Limit agent access and require human approval before payments, data sharing, or other consequential actions.

Where it can appear: X (Twitter) / any social platform with an embedded LLM bot

Link to this entry
AI-Native Threats

Prompt Injection / Agentic AI Hijack

Instructions hidden in untrusted content attempt to redirect an AI assistant away from the user’s task, including toward unauthorized data sharing or tool use.

What you might notice

  • AI agent takes unexpected financial or data action
  • AI reports completing tasks you didn't request
  • Unusual output from a normally reliable AI tool
  • Hidden text visible only when highlighting page content

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat AI-generated messages, recommendations, voices, and images as unverified. Confirm sensitive requests through an independent channel. Limit agent access and require human approval before payments, data sharing, or other consequential actions.

Where it can appear: AI coding assistants / agentic browsers / AI email clients / LLM-connected applications

Link to this entry
AI-Native Threats

Autonomous Scam Agent

Fraudsters can use automation and AI agents to draft messages, sustain conversations, or coordinate parts of a scam campaign.

What you might notice

  • Conversation feels unnaturally patient and perfectly personalized
  • Responds at any hour with zero delay and no inconsistencies
  • No grammar errors or cultural awkwardness
  • Pivots naturally when trust is established, introducing investment or request for money
  • Switches from email to SMS to DM if you go quiet

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat AI-generated messages, recommendations, voices, and images as unverified. Confirm sensitive requests through an independent channel. Limit agent access and require human approval before payments, data sharing, or other consequential actions.

Where it can appear: All digital channels simultaneously — email, SMS, dating apps, LinkedIn, social media

Link to this entry
AI-Native Threats

Deepfake Job Candidate / HR Fraud

Candidates submit AI-generated hyper-tailored resumes and pass video interviews using real-time face-swap deepfake technology — while physically located elsewhere.

What you might notice

  • Video interview shows subtle lag or unnatural blinking patterns
  • Face appears unusually smooth or inconsistently lit across the call
  • Candidate answers every question perfectly but avoids off-script spontaneous moments
  • Resume is perfectly tailored to every single requirement
  • References are difficult or impossible to independently verify

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use an established, proportionate identity and employment verification process. Independently verify references and restrict access until onboarding checks are complete. Visual tricks or a single detection tool are not conclusive.

Where it can appear: Remote video interviews (Zoom / Teams / Google Meet)

Link to this entry
AI-Native Threats

AI-Generated Fake Customer Service Chatbot

A fake brand website features an AI-powered "live chat" agent that looks and responds exactly like a real customer service bot.

What you might notice

  • Chatbot on a lookalike or misspelled domain
  • Conversation is fluid, contextually aware, and convincing
  • Asks for credentials, PIN, OTP, or account number mid-chat
  • Site reached via search ad or phishing email link
  • No phone callback option — only the chatbot

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat AI-generated messages, recommendations, voices, and images as unverified. Confirm sensitive requests through an independent channel. Limit agent access and require human approval before payments, data sharing, or other consequential actions.

Where it can appear: Fake brand websites / search engine ads / phishing email links

Link to this entry
AI-Native Threats

LLM Hyper-Personalized Phishing

Phishing messages use gathered personal information and AI-generated wording to sound unusually relevant or familiar.

What you might notice

  • Email contains specific, accurate personal or professional detail you wouldn't expect
  • No grammar errors, awkward phrasing, or off-brand formatting
  • References a real project, vendor, colleague, or company news item
  • Sender domain is close but not exact (one character off)
  • Personalization seems designed to create instant trust

These are possible warning signs, not proof of fraud on their own.

A safer next step

A personalized message can be legitimate or malicious. Evaluate what it asks you to do and verify unexpected sensitive requests through an independent, known channel.

Where it can appear: Email / LinkedIn InMail / SMS

Link to this entry
AI-Native Threats

AI-Cloned Website at Scale

AI tools generate pixel-perfect clones of legitimate websites in minutes.

What you might notice

  • Domain is a minor variation of the real one
  • Site looks visually identical to the legitimate brand's official website
  • HTTPS padlock is present (this is no longer a sign of legitimacy)
  • Slightly different contact information, about page, or footer
  • Found via search ad rather than a bookmark or direct URL

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat AI-generated messages, recommendations, voices, and images as unverified. Confirm sensitive requests through an independent channel. Limit agent access and require human approval before payments, data sharing, or other consequential actions.

Where it can appear: Search engine paid ads / phishing email links / typosquatting domains

Link to this entry
AI-Native Threats

AI KYC Bypass / Synthetic Document Forgery

AI tools generate photorealistic fake passports, driver's licenses, selfies, and face-swap kits that pass automated Know Your Customer (KYC) identity verification checks at financial institutions and crypto exchanges.

What you might notice

  • Unfamiliar credit or loan accounts opened in your name post-breach
  • Fraudulent loans applied for using your SSN but a different face
  • Organization targeted: crypto exchanges, neobanks, online lenders, gig platforms
  • KYC passed on accounts with your personal info but unfamiliar activity patterns

These are possible warning signs, not proof of fraud on their own.

A safer next step

Treat AI-generated messages, recommendations, voices, and images as unverified. Confirm sensitive requests through an independent channel. Limit agent access and require human approval before payments, data sharing, or other consequential actions.

Where it can appear: Crypto exchanges / neobanks / online lenders / gig economy platforms requiring identity verification

Link to this entry
Technical Attacks

Supply Chain / Software Update Attack

A trusted software package, library, or update channel is compromised to distribute malicious code to downstream users.

What you might notice

  • Security incident with no obvious initial entry point
  • Malware appeared after a routine, trusted software update
  • A widely used open-source library or tool is the vector
  • Multiple unrelated organizations are affected simultaneously

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: Software update mechanisms / open-source package registries (NPM, PyPI) / build pipelines

Link to this entry
Technical Attacks

DNS Hijacking / BGP Hijacking

Unauthorized DNS changes can redirect users; BGP hijacking abuses internet routing announcements to misdirect traffic. The mechanisms and defenses differ.

What you might notice

  • Users report being directed to wrong or unusual pages from correct URLs
  • Certificate errors on your own organization's domain
  • Traffic unexpectedly routed through unusual countries or ISPs
  • Widespread "wrong site" complaints from multiple unrelated users

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: DNS registrar compromise / ISP-level attacks / routing infrastructure vulnerabilities

Link to this entry
Technical Attacks

Formjacking

Malicious code on a website captures information entered into a form, such as checkout payment details, without the visitor’s knowledge.

What you might notice

  • Legitimate-looking site, but card charged fraudulently days after purchase
  • Multiple fraud victims from the same e-commerce site reported simultaneously
  • No indication during the transaction — everything appeared normal
  • Breach eventually disclosed by the retailer weeks or months after the fact

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: E-commerce checkout forms / any website accepting direct credit card input

Link to this entry
Technical Attacks

ATM Jackpotting

An attack manipulates an ATM to dispense cash without an authorized customer withdrawal, using malware or other access to its systems.

What you might notice

  • ATM dispenses large amounts of cash with no apparent user interaction
  • Machine is taken offline or out of service unexpectedly
  • ATM located in an isolated position with no security cameras nearby
  • Physical evidence of cabinet tampering, drill marks, or panel damage

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: Standalone ATMs in retail locations / non-bank ATMs / off-premise ATM deployments

Link to this entry
Technical Attacks

Malicious Traffic Distribution / Redirect Chains

A legitimate-looking ad or search result silently routes victims through multiple invisible redirect domains before landing on a credential-harvest or malware-delivery page.

What you might notice

  • URL changes multiple times in the browser address bar after clicking
  • Arrives via a paid search engine advertisement
  • Final page mimics a trusted brand's login or download page
  • Fast redirect — difficult to use the back button effectively
  • May silently install stealer malware without further user action

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: Search engine paid ads / compromised legitimate websites / malvertising networks

Link to this entry
Technical Attacks

Zero-Day Exploit Delivery

Attacker uses a previously unknown, unpatched software vulnerability to compromise a device or system — often with no user action beyond visiting a website or opening a file.

What you might notice

  • Compromise occurred with no phishing email or suspicious download
  • Security tools report unexplained malicious behavior on an up-to-date device
  • System compromise detected on a device that had all available patches installed
  • Nation-state or sophisticated threat actor targeting of a specific individual or sector

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: Web browser / PDF reader / OS / any unpatched software component

Link to this entry
P2P / Payment App

Penny Phishing / Micro-Deposit Scam

A micro-deposit of $0.01–$0.14 appears in your bank account or PayPal with an alarmist transaction memo — "Your account was compromised, call [phone number] to reverse this charge." If you call, the scammer harvests your credentials or takes remote control of your computer.

What you might notice

  • Tiny unexpected deposit in your account
  • Alarmist message in the transaction description or memo field
  • Phone number embedded in the transaction note with urgency to call
  • Memo claims unauthorized purchase, account compromise, or needed refund

These are possible warning signs, not proof of fraud on their own.

A safer next step

Check activity in the official payment app, not a message or screenshot. Do not send a separate payment to reverse an unexpected transfer. Contact the platform or bank through its official support channel.

Where it can appear: PayPal / Venmo / Zelle / bank ACH transfers

Link to this entry
P2P / Payment App

Overpayment / Accidental Payment Scam

A stranger sends you money, then claims it was a mistake and asks you to send it back.

What you might notice

  • Unexpected large payment received from a complete stranger
  • Urgent, emotional request to return the money immediately
  • Pressure to use Zelle, Cash App, or Venmo for the "refund"
  • Sender becomes aggressive or threatening if you hesitate
  • Payment came from an account with no profile picture or history

These are possible warning signs, not proof of fraud on their own.

A safer next step

Ask the payment platform to investigate the original transfer. Do not send a new payment as a refund to someone who contacted you unexpectedly. A displayed balance does not guarantee final settlement.

Where it can appear: PayPal / Cash App / Zelle / Venmo

Link to this entry
P2P / Payment App

P2P Money Flip / Fake Giveaway

"Send me $50 and I'll flip it to $500 — I do this for people all the time." Often comes with fabricated screenshots showing prior "flips." Sometimes impersonates the platform's official accounts offering cash prizes.

What you might notice

  • Promise to multiply your money by a specific amount
  • Screenshots of prior successful flips provided as "proof"
  • Small return sent first to build trust, then larger request follows
  • Impersonates Cash App, Venmo, or celebrity accounts claiming giveaways

These are possible warning signs, not proof of fraud on their own.

A safer next step

Check activity in the official payment app, not a message or screenshot. Do not send a separate payment to reverse an unexpected transfer. Contact the platform or bank through its official support channel.

Where it can appear: Instagram / TikTok / Cash App / Venmo / Twitter/X

Link to this entry
P2P / Payment App

Fake Invoice / Money Request (Payment App)

You receive a PayPal, Venmo, or Cash App money request — not an actual charge, just a request you must accept — claiming you owe for a purchase you didn't make, with a phone number to call to "dispute" it.

What you might notice

  • Unexpected payment request for a purchase you don't recognize
  • Phone number embedded in the request with instruction to call
  • Urgency: "Respond within 24 hours or face late fees"
  • Request is from an account you don't recognize
  • Amount is a large, round number

These are possible warning signs, not proof of fraud on their own.

A safer next step

Check activity in the official payment app, not a message or screenshot. Do not send a separate payment to reverse an unexpected transfer. Contact the platform or bank through its official support channel.

Where it can appear: PayPal / Cash App / Venmo

Link to this entry
P2P / Payment App

P2P Platform Impersonation

Scammers pose as Cash App, Venmo, Zelle, or PayPal customer support via phone, text, or social media claiming your account is compromised and requesting your PIN, sign-in code, or a "verification payment" to unlock your funds.

What you might notice

  • Platform support contacts you first — via DM, phone, or text (not in-app)
  • Asks for your PIN, sign-in code, or any payment to "verify" your account
  • Claims your funds will be locked or seized unless you act immediately
  • Contact appears in a social media DM or unsolicited phone call

These are possible warning signs, not proof of fraud on their own.

A safer next step

Check activity in the official payment app, not a message or screenshot. Do not send a separate payment to reverse an unexpected transfer. Contact the platform or bank through its official support channel.

Where it can appear: Social media DMs / phone / unsolicited text messages

Link to this entry
Physical / Proximity

Card Skimmer / Overlay (ATM & Gas Pump)

A device attached to a payment terminal captures card information, sometimes alongside a camera or keypad overlay that captures a PIN.

What you might notice

  • Card reader feels loose, raised, or misaligned compared to the machine housing
  • Keypad feels thicker or spongier than usual
  • Tap-to-pay slot has been drilled out or deliberately disabled
  • Unfamiliar Bluetooth device showing up near the pump on your phone
  • Card reader color or material slightly mismatches the machine

These are possible warning signs, not proof of fraud on their own.

A safer next step

Avoid visibly tampered terminals, cover your PIN, and monitor transactions. Contactless payments can reduce some card-data exposure but do not eliminate payment fraud.

Where it can appear: ATMs / gas pumps / parking meters / unattended kiosks

Link to this entry
Physical / Proximity

Deep-Insert Shimmer (Chip Card Attack)

A thin device inserted into a card reader attempts to capture data during chip-card use. Risk and feasibility depend on the payment system and its controls.

What you might notice

  • No external signs — the shimmer is entirely hidden inside the terminal
  • Card inserts normally but may feel very slightly stiffer than usual
  • Fraudulent charges appear days or weeks after the compromised transaction
  • Often paired with a pinhole camera hidden on or near the terminal to capture the PIN

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use trusted, untampered terminals, protect your PIN, and monitor statements. Contactless options can reduce some risks. Report unexpected transactions promptly to the card issuer.

Where it can appear: Gas pumps / ATMs / transit kiosks / any unattended chip card terminal

Link to this entry
Physical / Proximity

Evil Twin / Rogue WiFi (Fake Hotspot)

Attacker sets up a WiFi network with the same or a very similar name as the legitimate one, with a stronger signal positioned nearby.

What you might notice

  • Two networks with the same or very similar name appear in your device's list
  • Network requires an email address to "register" for access
  • SSL certificate warnings appear when browsing — tempting you to "accept anyway"
  • Connection works normally but you're logged into an attacker-controlled network

These are possible warning signs, not proof of fraud on their own.

A safer next step

Confirm the network with the venue, disable automatic joining, and avoid certificate warnings. HTTPS and a reputable VPN can protect parts of traffic but do not make phishing sites safe. Use trusted cellular service when appropriate.

Where it can appear: Airports / hotels / coffee shops / stadiums / conferences / hospitals / any public WiFi venue

Link to this entry
Physical / Proximity

AirTag Stalking / Covert GPS Tracking

A small location tracker is placed among someone’s belongings or in a vehicle to monitor them without consent.

What you might notice

  • iPhone alert: "AirTag Found Moving With You" appearing on your phone
  • Faint chirping or beeping sound from your belongings you can't locate (AirTag plays audio after 8–24 hours separated from owner)
  • Android users receive no automatic alert — must install Apple's Tracker Detect app manually
  • Suspicious person you know recently had access to your vehicle, bag, or coat

These are possible warning signs, not proof of fraud on their own.

A safer next step

If you suspect unwanted tracking, use a trusted device to seek safety advice. Moving, disabling, or removing a tracker may affect evidence or alert another person. Contact local authorities or a domestic violence support organization when appropriate.

Where it can appear: Vehicle wheel wells / bag pockets / coat linings / under seats / luggage

Link to this entry
Physical / Proximity

Stalkerware / Hidden Tracking App

Monitoring software is installed or misused to track someone’s location, communications, or device activity without appropriate consent.

What you might notice

  • Battery drains unusually fast for no apparent reason
  • Phone runs warm when not in active use
  • Unexpected data usage spike you can't account for
  • Phone feels sluggish or apps behave oddly
  • Abusive partner or person with prior device access seems to know private conversation content

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use a separate trusted device to seek help from a domestic violence support organization or the Coalition Against Stalkerware. Plan for safety before changing settings or removing software, which may alert an abuser.

Where it can appear: Any smartphone — requires brief physical access to install (approximately 60–120 seconds)

Link to this entry
Physical / Proximity

AirPod / Live Listen Eavesdropping

Apple's built-in "Live Listen" accessibility feature turns any iPhone into a remote microphone streaming live audio directly to paired AirPods up to approximately 50 feet away.

What you might notice

  • An attendee's iPhone is left behind or screen-up in the meeting room when they step away
  • The "ear" icon appears in Control Center on the device (indicates Live Listen is active)
  • Private meeting content is subsequently known by someone who wasn't present
  • Feature is native to iOS — antivirus and security tools will not flag it

These are possible warning signs, not proof of fraud on their own.

A safer next step

Watch for tampering and unexpected devices, protect your PIN, and review account or device alerts. Avoid interacting with suspicious equipment and report concerns to the venue, service provider, or appropriate authority.

Where it can appear: Any in-person meeting, office, or private space within approximately 50-foot Bluetooth range

Link to this entry
Physical / Proximity

Shoulder Surfing

Attacker observes you entering a PIN, password, or sensitive information in a public space — at an ATM, on public transit, in a coffee shop, or at a check-in kiosk.

What you might notice

  • Person standing or sitting unusually close when you use an ATM or POS terminal
  • Someone on public transit angling their phone screen toward your device
  • Crowded location where shielding your screen or keyboard is difficult
  • Distraction-plus-observation team working together in busy transit hubs

These are possible warning signs, not proof of fraud on their own.

A safer next step

Watch for tampering and unexpected devices, protect your PIN, and review account or device alerts. Avoid interacting with suspicious equipment and report concerns to the venue, service provider, or appropriate authority.

Where it can appear: ATMs / POS payment terminals / airports / coffee shops / public transit

Link to this entry
Physical / Proximity

Dumpster Diving / Mail Theft

Criminals retrieve financial statements, pre-approved credit offers, tax documents, Medicare cards, and other identity documents from unshredded trash or mailboxes to enable identity theft and fraud.

What you might notice

  • Financial mail you expected does not arrive
  • Unexpected accounts appear on your credit report
  • A check you sent is returned as altered or deposited for a different amount
  • Pre-approved credit card offers consistently going missing from your mailbox

These are possible warning signs, not proof of fraud on their own.

A safer next step

Watch for tampering and unexpected devices, protect your PIN, and review account or device alerts. Avoid interacting with suspicious equipment and report concerns to the venue, service provider, or appropriate authority.

Where it can appear: Physical mailbox / home recycling or trash / USPS collection boxes

Link to this entry
Physical / Proximity

Juice Jacking (Malicious USB Charging)

A tampered USB port or cable may attempt unauthorized data transfer or exploit a connected device. Modern device protections affect the risk; this is not proof that every public charger is unsafe.

What you might notice

  • Used a public USB charging port at an airport, hotel, or mall
  • Unexpected device behavior, new apps, or configuration changes after charging
  • Data usage spike after using a public charge point
  • Device prompts for "Trust This Computer?" when plugged into what appeared to be just a charger

These are possible warning signs, not proof of fraud on their own.

A safer next step

Watch for tampering and unexpected devices, protect your PIN, and review account or device alerts. Avoid interacting with suspicious equipment and report concerns to the venue, service provider, or appropriate authority.

Where it can appear: Airport / hotel / mall / conference / stadium USB charging stations

Link to this entry
Physical / Proximity

NFC Relay / Tap-to-Pay Intercept

Specialized relay attacks attempt to extend contactless communication for unauthorized transactions. Terminal tampering is a related but distinct payment risk.

What you might notice

  • Unexplained tap-to-pay transaction at a merchant you weren't near
  • Tap-to-pay option is disabled or physically damaged on an otherwise functional terminal
  • Kiosk or gas pump shows signs of physical tampering around the contactless reader area

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use trusted payment terminals and investigate signs of tampering. Review transaction alerts and report unauthorized payments to your issuer. No wallet accessory is a complete defense against all relay or payment attacks.

Where it can appear: NFC-enabled payment terminals / public spaces where device is close to strangers

Link to this entry
Telecom Attacks

SS7 Attack / IMSI Catcher (Stingray)

Weaknesses in telecom signaling or rogue cellular equipment may expose location or communications metadata and, in some circumstances, communications content. Capabilities vary by network and device.

What you might notice

  • No visible device-side indicators — completely silent interception
  • OTP codes intercepted and used without your action
  • Calls redirected or dropped in otherwise good-coverage areas
  • Used primarily against high-value targets: executives, journalists, politicians, government officials
  • Battery drain may increase slightly when IMSI catcher is active nearby

These are possible warning signs, not proof of fraud on their own.

A safer next step

Protect your carrier account with a strong password and available port-out protections. Prefer passkeys or an authenticator over SMS where available. Verify unexpected account changes directly with your carrier.

Where it can appear: Telecom SS7 protocol vulnerabilities / specialized law enforcement and criminal hardware

Link to this entry
Telecom Attacks

eSIM Hijacking

As physical SIM cards are replaced by software-based eSIMs, attackers exploit digital eSIM transfer processes — using social engineering of carrier support or compromised account credentials to remotely reassign your eSIM to their device without visiting a physical store.

What you might notice

  • Loss of cellular service after an eSIM profile transfer you didn't initiate
  • Carrier notification about an eSIM or device profile change you didn't make
  • Accounts linked to your phone number become inaccessible
  • Carrier account portal shows a new device or eSIM profile you don't recognize

These are possible warning signs, not proof of fraud on their own.

A safer next step

Protect your carrier account with a strong password and available port-out protections. Prefer passkeys or an authenticator over SMS where available. Verify unexpected account changes directly with your carrier.

Where it can appear: Carrier account portal / social engineering of carrier customer support

Link to this entry
Telecom Attacks

OTP Interception / SIM Swap Enablement Bot

An automated call or message impersonates a service and tricks a person into disclosing a sign-in or recovery code.

What you might notice

  • Unexpected OTP code received that you didn't request
  • Immediately followed by a call or text asking you to "confirm" the code you just received
  • Caller claims to be your bank verifying a suspicious transaction
  • Real-time urgency: "The code expires in 30 seconds" or "I need it immediately"
  • After providing the code, you're locked out of your account within minutes

These are possible warning signs, not proof of fraud on their own.

A safer next step

Protect your carrier account with a strong password and available port-out protections. Prefer passkeys or an authenticator over SMS where available. Verify unexpected account changes directly with your carrier.

Where it can appear: Phone call / SMS / automated OTP relay bot service

Link to this entry
Telecom Attacks

Vishing via AI Voice Clone (Carrier-Level)

A caller uses voice synthesis and possibly spoofed caller ID to impersonate a specific person and request money or sensitive action.

What you might notice

  • Call appears to come from a phone number you have saved as a trusted contact
  • Voice is convincing but may have slight artifacts under stress or with unusual phrasing
  • Request is for an unusual action: urgent wire transfer, immediate decision, sensitive information
  • The real person denies making the call when you follow up independently

These are possible warning signs, not proof of fraud on their own.

A safer next step

Protect your carrier account with a strong password and available port-out protections. Prefer passkeys or an authenticator over SMS where available. Verify unexpected account changes directly with your carrier.

Where it can appear: Phone calls with spoofed caller ID + AI voice synthesis

Link to this entry
Malware Types

RAT (Remote Access Trojan)

Gives an attacker silent, full remote control of your device — keyboard, screen, webcam, microphone, files, and network traffic.

What you might notice

  • Device unusually sluggish or warm when apparently idle
  • Webcam indicator light activates without you opening a camera application
  • Unknown processes running in Task Manager or Activity Monitor
  • Unexplained outbound network connections to unfamiliar IP addresses
  • Mouse cursor moves on its own

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Phishing email attachment / fake software download / malicious ad / exploit kit

Link to this entry
Malware Types

Keylogger

Malicious software or hardware records keystrokes to capture information such as passwords and messages.

What you might notice

  • Credentials compromised across multiple sites simultaneously
  • Unfamiliar USB device connected to the back of a computer
  • Slight and persistent input lag when typing
  • Detected by EDR or antivirus as a "monitoring tool" or "spyware"
  • Bundled in a macro-enabled Office document or cracked software

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use unique credentials and multi-factor authentication, but do not assume autofill makes a compromised device safe. Avoid sensitive logins on untrusted devices and seek help to investigate suspected malware.

Where it can appear: Phishing email / macro-enabled Office document / physical access to device

Link to this entry
Malware Types

Infostealer

Malware steals valuable device data such as saved credentials, browser sessions, documents, or wallet information.

What you might notice

  • Multiple accounts compromised without any phishing link clicked
  • Session hijacked while you were still logged in (session token theft)
  • Dark web monitoring service alerts you to your credentials appearing
  • Infostealers often delivered via fake software cracks, YouTube install guides, or malicious ads

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use a separate trusted device to reset affected credentials and revoke sessions. Investigate and remediate the compromised device before trusting it again. Passkeys do not protect an already stolen session.

Where it can appear: Piracy sites / malicious ads / fake software download pages / cracked game installers

Link to this entry
Malware Types

Ransomware

Malware encrypts data to support an extortion demand. Attackers may also steal information and threaten to release it.

What you might notice

  • Files suddenly renamed with an unknown extension (.locked, .enc, .encrypted)
  • Ransom note text file appears in every folder and on the desktop
  • Desktop wallpaper replaced with a ransom demand
  • Systems unavailable organization-wide
  • Sudden, unexplained spike in disk read/write activity

These are possible warning signs, not proof of fraud on their own.

A safer next step

Maintain tested, isolated backups and a response plan. Seek qualified incident support and report to the appropriate authorities. Paying an attacker does not guarantee recovery.

Where it can appear: Phishing email attachment / unpatched VPN or RDP / malicious advertisement / drive-by download

Link to this entry
Malware Types

Cryptojacker / Cryptominer

Secretly commandeers your CPU and GPU to mine cryptocurrency for the attacker while you pay the electricity bill and suffer the performance degradation.

What you might notice

  • Device fan runs constantly at high speed even when apparently idle
  • System performance is dramatically slower than normal
  • Battery drains abnormally fast on a laptop
  • Electricity bill is higher than expected at organizational scale

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Malicious websites with embedded mining scripts / browser extensions / compromised servers

Link to this entry
Malware Types

Botnet / Bot Malware

Silently recruits your device into a criminal network (botnet) controlled by a command-and-control server.

What you might notice

  • Unusual network traffic spikes — especially at night or when device is "idle"
  • Internet connection mysteriously slower than usual
  • Router or IoT device has unknown outbound connections
  • Email contacts report receiving spam from your email address
  • Device reboots unexpectedly or at unusual times

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Unpatched IoT devices (routers, cameras, smart TVs) / phishing email / exploit kits

Link to this entry
Malware Types

Trojan / Banking Trojan

A Trojan disguises itself as legitimate software to trick you into installing it.

What you might notice

  • Downloaded from an unofficial source, piracy site, or prompted by a pop-up
  • Bank asks for extra verification steps or fields you haven't seen before
  • A transaction appears on your bank's side that didn't appear in your session view
  • Mobile app requests permissions that don't match its stated function

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Piracy and cracked software sites / unofficial app stores / macro-enabled documents / email

Link to this entry
Malware Types

Spyware

Software covertly collects device activity, location, communications, or other information. Capabilities depend on permissions and the particular software.

What you might notice

  • Battery drains fast with minimal visible activity
  • Phone is warm when idle with no apps running
  • Microphone or camera appears active when no application should be using them
  • Location information reaching people it shouldn't — you've been tracked

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Zero-click OS exploit / malicious app installation / brief physical device access

Link to this entry
Malware Types

Rootkit

A rootkit hides malicious activity at a privileged level of a system. Some affect boot components or firmware, making removal more complex.

What you might notice

  • Antivirus and security tools behave erratically or suddenly stop functioning
  • Compromised state persists after a full OS reinstall
  • Processes exist on the network that aren't visible in Task Manager
  • BIOS/UEFI firmware acts unexpectedly or shows unauthorized changes

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep firmware and software supported and updated; use Secure Boot where supported. Seek qualified help for suspected boot or firmware compromise rather than attempting unverified repair instructions.

Where it can appear: Delivered by other malware after system compromise / nation-state supply chain attack

Link to this entry
Malware Types

Fileless Malware / Living off the Land (LotL)

Attackers abuse legitimate tools or memory-based execution to avoid simple file-signature detection. These techniques can still leave evidence and may use files as part of the attack.

What you might notice

  • No malicious file found despite a confirmed security breach
  • PowerShell or WMI running unexpectedly or at unusual times
  • Behavioral EDR alerts on legitimate system tools performing anomalous actions
  • Attack leaves minimal forensic trace in system logs
  • Often delivered via phishing macro or browser exploit, then executes entirely in memory

These are possible warning signs, not proof of fraud on their own.

A safer next step

Organizations should monitor behavior, limit unnecessary script and administrative privileges, and investigate unusual use of legitimate tools. A PowerShell execution policy alone is not a security boundary.

Where it can appear: Phishing email macro / browser exploit / valid credential abuse with system tool misuse

Link to this entry
Malware Types

Dropper / Loader

"First stage" malware that lands on your device appearing innocent, then downloads and installs the real payload (RAT, ransomware, or infostealer) from an external server.

What you might notice

  • Security tool detects a "dropper" or "downloader" but struggles to identify what it delivered
  • Suspicious child processes spawned from Office applications or web browsers
  • Malicious NPM or PyPI packages: 15,000+ published to open-source registries in 2025

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Phishing attachment / malicious open-source package / infected software installer / supply chain

Link to this entry
Malware Types

Wiper Malware

Malware deliberately destroys or corrupts data. Recovery depends on the damage and the availability of unaffected backups or other recovery options.

What you might notice

  • Mass deletion or overwriting of files across systems — no ransom note appears
  • Systems fail to boot following the attack
  • Targets industrial control systems (ICS) or OT networks alongside IT systems
  • Often deployed simultaneously with DDoS attacks to maximize disruption and delay response

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep tested backups isolated from routine access, restrict privileges, and prepare a response plan. Involve qualified responders before making changes that could destroy recovery evidence.

Where it can appear: Nation-state APT campaigns / advanced persistent threat actors targeting critical infrastructure

Link to this entry
Malware Types

Mobile Malware / Banking Overlay

Draws a convincing fake banking interface over your real bank app to capture credentials as you type them into what appears to be your legitimate bank.

What you might notice

  • Banking app looks slightly different — new fields, different layout, unusual color
  • Phone battery drains fast with screen off and no active use
  • Accessibility Service is enabled for an app that has no legitimate reason to need it
  • Unexpected OTPs or 2FA codes arriving for accounts you didn't access
  • Unexplained charges or financial activity you didn't initiate

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Unofficial app stores / sideloaded APK files / versioning attack on initially clean Play Store app

Link to this entry
Malware Types

Polymorphic / AI-Enhanced Malware

Malware changes its code or behavior to complicate detection. AI may assist parts of development or evasion, but a specific sample’s capabilities require evidence.

What you might notice

  • Antivirus scan returns clean despite confirmed suspicious behavioral indicators
  • Security tools give inconsistent results across scans of the same file
  • Malware behaves differently across different target systems (evasion logic)
  • EDR behavioral alerts trigger even when file-based scans show clean results

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use layered protection, current software, behavioral monitoring where appropriate, limited privileges, and tested backups. Do not assume any single tool catches every variant.

Where it can appear: All standard malware delivery channels — identical delivery, fundamentally different detection evasion

Link to this entry
Malware Types

Scareware / Fake Security Software

Pop-ups, browser alerts, or downloaded programs falsely claim your device is infected with a specific number of viruses or has been "hacked," urging you to purchase fake "cleanup software" that is itself malware — or to call a number that leads to a tech support fraud chain and remote access compromise.

What you might notice

  • Alarming pop-up claiming a specific number of infections detected
  • Difficult or impossible to close the browser window or tab normally
  • Urgent countdown timer pressuring you to act before "infections spread"
  • "FREE scan" that always finds critical infections and requires paid software to fix them

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Malicious ads / compromised websites / fake software download portals

Link to this entry
Malware Types

ATM Jackpotting Malware

Malware or unauthorized control of an ATM causes cash to be dispensed outside a legitimate withdrawal.

What you might notice

  • ATM dispenses cash without any user inserting a card or entering a PIN
  • Machine taken offline or displays "Out of Service" immediately following cash dispensing
  • Standalone ATM in a low-security location — convenience store, hotel lobby, or gas station
  • Physical evidence of cabinet door tampering, drill marks, or panel damage

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep devices and security software updated. Install software from trusted official sources, limit privileges, and maintain tested backups. If compromise is suspected, use a separate trusted device to seek qualified help and protect affected accounts.

Where it can appear: Standalone ATMs with weak physical security / off-premise non-bank ATM deployments

Link to this entry
Consumer / Lifestyle

Tariff Rebate / Economic Relief Scam

Messages claim a government rebate or relief payment is available and direct people to fake claim pages or requests for personal information.

What you might notice

  • Text or email claims a government rebate or relief payment is available for you
  • Link requests SSN, bank account info, or debit card to receive the funds
  • Urgency: Your claim expires within 48 hours or another deadline
  • Government agencies do not distribute money via text message links

These are possible warning signs, not proof of fraud on their own.

A safer next step

Check any government payment claim directly on the responsible agency’s official site. Do not rely on a message, advertisement, or news headline as proof of eligibility.

Where it can appear: SMS / email / social media ads

Link to this entry
Identity / Account

Jury Duty Scam

Calls, texts, or emails threatening arrest for missing jury duty — often accompanied by fake warrant documents or official-looking court notices.

What you might notice

  • Call or message claims you missed jury duty and a warrant has been issued
  • Demands immediate payment of a fine to avoid arrest today
  • Provides a fake warrant document or official-looking court notice
  • Payment must be made via gift card, wire, or cryptocurrency to clear the warrant

These are possible warning signs, not proof of fraud on their own.

A safer next step

Independently contact the court through its published official details. Do not pay a caller demanding immediate gift-card, cryptocurrency, or wire payment to avoid arrest.

Where it can appear: Phone / text / email

Link to this entry
Extortion

Digital Arrest Scam

An impersonator uses a video call, threats, or fake legal documents to pressure a person to stay connected and send money or reveal information.

What you might notice

  • Video call from someone posing as a police officer, judge, or customs official
  • Deepfake warrant, court order, or official government seal shown on screen
  • Told you must remain on the call or you will be arrested immediately
  • Interrogation lasts hours or days — sustained pressure designed to break down resistance

These are possible warning signs, not proof of fraud on their own.

A safer next step

End coercive contact and verify claims independently with the relevant authority. Do not transfer money or disclose credentials under threat. Seek emergency help if there is immediate danger.

Where it can appear: Video call (WhatsApp / FaceTime / Zoom) / phone

Link to this entry
Financial / Investment

"AI Washing" Investment Scam

Fraudsters falsely claim their trading platform uses proprietary AI to guarantee superior returns — complete with AI-generated performance charts, fabricated track records, and fake renderings of investment properties.

What you might notice

  • Platform claims a proprietary AI algorithm delivers guaranteed or market-beating returns
  • AI-generated charts show consistent gains with no losing periods
  • Photorealistic AI renderings of investment properties or developments that do not exist
  • No verifiable independent track record or regulatory registration can be found

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the company and offering independently. AI branding is not evidence of returns or legitimacy. Be cautious of guarantees and pressure, and consult relevant regulator resources.

Where it can appear: Social media ads / Telegram / investment webinars / LinkedIn

Link to this entry
Consumer / Lifestyle

Fake Airline Customer Service Scam

Scammers create fake airline customer service numbers that appear prominently in Google search results — often above the real airline number.

What you might notice

  • Phone number found via Google search — not from the airline official website or ticket
  • Agent asks for credit card to rebook or protect your reservation
  • Unauthorized charges appear during or after the call
  • Call center has no record of your actual booking details

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use contact details from the airline’s official website or your booking. Review applicable fare and service terms; do not accept an unsolicited caller’s payment demand as proof of a legitimate fee.

Where it can appear: Google Search paid ads / SEO manipulation of airline customer service search results

Link to this entry
Consumer / Lifestyle

Health Insurance Search Ad Impersonation

Misleading search advertisements impersonate health coverage services or direct people to deceptive enrollment offers.

What you might notice

  • Search result for Medicare or health insurance leads to a non-.gov site
  • Enrollment advisor asks for Medicare number, SSN, or banking information
  • Claims to offer better plans than the official marketplace can provide
  • URL is healthcare-marketplace-help.com or similar — not healthcare.gov or medicare.gov

These are possible warning signs, not proof of fraud on their own.

A safer next step

Start with Medicare.gov, HealthCare.gov, or your state’s official program site and use their listed assistance channels. Verify an adviser before sharing personal details.

Where it can appear: Google Search paid ads appearing above official government results

Link to this entry
Physical / Proximity

EBT / SNAP Card Skimming

Criminals place overlay skimming devices on grocery store card readers specifically targeting SNAP/EBT (Electronic Benefit Transfer) cards, stealing government food assistance benefits from low-income households.

What you might notice

  • Unusual device overlaying the card reader at a grocery store checkout
  • Text message claiming your EBT card has been locked or your account suspended
  • Benefits missing from your account without corresponding purchases you made
  • Request for PIN via phone or text — no legitimate agency ever does this

These are possible warning signs, not proof of fraud on their own.

A safer next step

Watch for tampering and unexpected devices, protect your PIN, and review account or device alerts. Avoid interacting with suspicious equipment and report concerns to the venue, service provider, or appropriate authority.

Where it can appear: Grocery store card readers / SMS phishing targeting SNAP recipients

Link to this entry
Identity / Account

Brushing Scam (Unsolicited Packages)

An unsolicited package may be connected to fabricated purchase reviews or misuse of personal details. It does not by itself prove an account was compromised.

What you might notice

  • Packages arrive from unknown senders with items you never ordered
  • Items are typically cheap: phone cases, small electronics, jewelry, USB drives
  • Package has your correct name and address but no return address or invoice
  • Accounts you hold on shopping platforms may have unauthorized review activity

These are possible warning signs, not proof of fraud on their own.

A safer next step

Check your shopping accounts for unauthorized activity and report suspicious packages or fake reviews through official channels. Do not scan an unexpected package’s QR code or provide payment to an unsolicited sender.

Where it can appear: E-commerce platforms / stolen address and account data from breaches

Link to this entry
Telecom Attacks

WhatsApp Account Takeover via OTP Forwarding

A contact whose WhatsApp was already hijacked messages you saying they accidentally sent a verification code to your number and asks you to forward it.

What you might notice

  • A contact asks you to forward a 6-digit verification code you just received
  • Message claims it was sent to you by mistake and they need it urgently
  • Sense of urgency: the code expires in 30 seconds
  • After forwarding, you immediately lose access to your WhatsApp account

These are possible warning signs, not proof of fraud on their own.

A safer next step

Do not forward sign-in or recovery codes. Independently verify unusual requests from contacts and use the platform’s official recovery process if locked out.

Where it can appear: WhatsApp / SMS

Link to this entry
Consumer / Lifestyle

Ghost Broker / Fake Insurance Policy

A fraudster sells a fake auto, home, renters, health, or business insurance policy at a below-market rate.

What you might notice

  • Policy premium is significantly below market rate for comparable coverage
  • Broker cannot be verified through your state insurance commission website
  • Policy documents reference an insurer with no AM Best rating or published contact info
  • Agent requests payment via cash, Zelle, Venmo, or money order — not standard methods

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: Social media / door-to-door sales / community referrals / fake broker websites

Link to this entry
Financial / Investment

Non-Delivery / Non-Payment Ecommerce Fraud

In non-delivery fraud, a buyer pays but receives nothing. In non-payment fraud, a seller supplies goods but the promised payment is missing, fraudulent, or reversed.

What you might notice

  • Seller or buyer has no verifiable history, reviews, or physical address
  • Payment method is irreversible: Zelle, crypto, wire transfer, or money order
  • Item price is far below market rate — especially electronics or luxury goods
  • For sellers: payment confirmation arrives before funds actually clear in your account

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify payment status directly with the platform or financial provider. Review seller and buyer protection rules; a screenshot, pending payment, or available balance does not guarantee a transfer cannot be reversed.

Where it can appear: Facebook Marketplace / Craigslist / eBay / social media shopping posts / P2P sales

Link to this entry
Physical / Proximity

Check Washing

Stolen checks are altered to change the payee or amount before being deposited or cashed.

What you might notice

  • A mailed check deposited for an amount significantly higher than written
  • Payee name or amount on a cleared check appears uneven, smeared, or chemically altered
  • Check cleared to someone you do not recognize
  • A payment you mailed never arrived at the recipient who expected it

These are possible warning signs, not proof of fraud on their own.

A safer next step

Watch for tampering and unexpected devices, protect your PIN, and review account or device alerts. Avoid interacting with suspicious equipment and report concerns to the venue, service provider, or appropriate authority.

Where it can appear: USPS blue collection boxes / home and office mailboxes / stolen mail

Link to this entry
Identity / Account

Fake Government Service / Passport Renewal Scam

Misleading sites imitate government services, hide fees, or collect money and data without providing the promised service. A clearly disclosed legitimate assistance service is different.

What you might notice

  • Site looks official but URL is not a .gov domain
  • Charges a processing fee for a service that is free or much cheaper at the official site
  • Appears above travel.state.gov or ssa.gov in search results
  • Application takes weeks and ultimately never arrives or requires additional unexpected fees

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use unique passwords and multi-factor authentication, review account activity, and secure recovery methods. Contact the provider through its official recovery process if you suspect unauthorized access.

Where it can appear: Google Search paid results / paid ads mimicking official government sites

Link to this entry
Identity / Account

Immigration / ICE Officer Impersonation

Scammers posing as ICE agents, CBP officers, or immigration court officials contact immigrants, international students, and visa holders — threatening immediate deportation, visa revocation, or arrest unless a fine is paid immediately.

What you might notice

  • Caller claims to be ICE or CBP and states your visa is revoked or deportation is imminent
  • Demands immediate payment to suspend the removal order or avoid arrest
  • Threatens that officers will arrive within hours if you do not comply immediately
  • Asks for payment via gift card, wire, or cryptocurrency to clear your immigration status

These are possible warning signs, not proof of fraud on their own.

A safer next step

Use unique passwords and multi-factor authentication, review account activity, and secure recovery methods. Contact the provider through its official recovery process if you suspect unauthorized access.

Where it can appear: Phone / text / email targeting immigrant and international student communities

Link to this entry
Consumer / Lifestyle

Fake Online Auction Scam

Fraudulent auction listings on eBay clones, Facebook Marketplace, or standalone auction sites accept winning bids and payment — then ship nothing, ship obvious counterfeits, or disappear entirely.

What you might notice

  • Seller insists on payment outside the platform via wire transfer, Zelle, or crypto
  • No verifiable seller history, reviews, or physical business location
  • Item photos appear to be stock photos or are stolen from legitimate listings
  • Winner is asked to pay shipping insurance or customs fees separately before the item ships

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the business or agency through independently found official contact details. Read payment and cancellation terms and avoid pressure to pay outside a trusted platform. Contact your payment provider promptly about suspected fraud.

Where it can appear: eBay / Facebook Marketplace / standalone auction sites / social media auction groups

Link to this entry
Consumer / Lifestyle

Funeral / Obituary Scam

Scammers monitor public obituaries and contact grieving families with fabricated claims: debts the deceased allegedly owed, inflated funeral billing disputes, fake life insurance policies requiring processing fees to claim, or posing as long-lost relatives seeking an inheritance share.

What you might notice

  • Contact arrives within days of an obituary being published online
  • Claims the deceased owed money on an account with no supporting documentation
  • Offers a life insurance policy the family was unaware of — but a fee is required to claim it
  • Pressure to resolve the matter quickly before the estate is legally settled

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify debt or insurance claims with the relevant institution and estate representative before paying. Avoid disclosing unnecessary personal details in public notices.

Where it can appear: Phone / email / mail — triggered by information in publicly posted obituaries

Link to this entry
Phishing / Social Eng.

Rewards Points / Miles Expiring Phishing

Fake texts and emails claiming your airline miles, hotel points, credit card rewards, or loyalty program balance is about to expire and you must click a link within 24-72 hours to save them.

What you might notice

  • Urgent message claiming your points will expire imminently or have already started expiring
  • Sender domain is airline-points-expiring.com style — not the real loyalty program domain
  • No specific account balance or flight history mentioned — the template works for any recipient
  • Click-to-save link leads to a credential-harvest page styled to match the real program

These are possible warning signs, not proof of fraud on their own.

A safer next step

Pause before opening unexpected links or attachments. Use a saved official website or app and verify sensitive requests through a separate, known contact method. Report suspicious messages and enable multi-factor authentication.

Where it can appear: Email / SMS

Link to this entry
Technical Attacks

RCS Smishing (Rich Communication Services)

Scam messages use RCS features such as images, rich formatting, or buttons to make an impersonation more convincing.

What you might notice

  • Message includes professional images, interactive tap buttons, and rich formatting beyond SMS
  • Sender appears to have a verified brand name or logo displayed
  • Interactive Tap to verify or Tap to confirm payment buttons embedded in the message
  • Appears in the same conversation thread as legitimate prior messages from the spoofed brand

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: Android Messages / Google Messages / cross-platform RCS (the new standard replacing SMS)

Link to this entry
Financial / Investment

LinkedIn Pig Butchering (Professional Network Variant)

A distinct variant of pig butchering using fake high-credential professional profiles — investment bankers, M&A advisors, hedge fund managers, fintech founders — to connect with business professionals and pitch exclusive deal flow, private equity co-investments, or pre-IPO opportunities.

What you might notice

  • Connection request from a highly credentialed finance professional you have never met
  • Quickly pivots to pitching an exclusive investment unavailable through normal licensed channels
  • Platform or opportunity is invite-only or available only to select LinkedIn connections
  • High minimum investment with a short window to participate — FOMO pressure applied early

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the person, firm, and offer independently using appropriate regulator resources. A polished professional profile does not prove a legitimate investment opportunity.

Where it can appear: LinkedIn / professional networking / email follow-up after initial LinkedIn contact

Link to this entry
Financial / Investment

AI-Generated Fake Real Estate Development Scam

Investment scammers now use AI image generation to create photorealistic renderings of completely fake real estate developments — apartment complexes, mixed-use buildings, commercial properties — to support fraudulent real estate investment offerings that are unregistered securities.

What you might notice

  • Investment pitch includes stunning photorealistic architectural renderings of a development
  • Project has no verifiable building permits, zoning filings, or municipal planning records
  • Developer has no verifiable history of completed and delivered projects
  • Investment minimum is designed to seem accessible to attract non-accredited investors

These are possible warning signs, not proof of fraud on their own.

A safer next step

Verify the developer, property, permits, and offering through independent records and qualified advisers. A rendering is not evidence that a development exists; registration requirements and exemptions vary.

Where it can appear: Investment webinars / social media / email campaigns / real estate investment forums

Link to this entry
Technical Attacks

Malvertising (Malicious Advertising)

Malicious advertisements lead people to deceptive websites or attempt to deliver malware. Some attacks exploit software vulnerabilities; others rely on a click or installation.

What you might notice

  • Ad loads on a trusted website and immediately triggers a redirect or download
  • No user click required — malware executes on page load via the ad script
  • Often targets popular news sites, weather sites, and high-traffic content platforms
  • Security scanner shows a clean website but the ad network it relies on is compromised

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep supported software and devices updated, limit privileged access, use multi-factor authentication, and maintain tested backups. Organizations should involve their security team in investigating suspected compromise.

Where it can appear: Legitimate high-traffic websites running third-party ad networks / programmatic display advertising

Link to this entry
Technical Attacks

Website Defacement

An attacker gains unauthorized access to a website and replaces or alters its content — typically with hacktivist messaging, political propaganda, or intimidation material.

What you might notice

  • Website displays unexpected content — political messages, foreign language text, or attacker branding
  • Organization logo replaced with a threat actor signature or flag
  • Legitimate site content completely replaced or overlaid
  • Organization reports receiving no notification of the change — it was discovered by the public

These are possible warning signs, not proof of fraud on their own.

A safer next step

Keep the website platform and plugins updated, restrict administrative access, monitor unexpected changes, and maintain recoverable backups. Investigate the scope of compromise before simply restoring the visible page.

Where it can appear: Web servers with unpatched CMS platforms (WordPress, Drupal, Joomla) / exposed admin panels / stolen credentials

Link to this entry
Phishing / Social Eng.

Email Domain Spoofing (Header Forgery)

An attacker forges sender information so an email appears to come from a trusted address. Authentication controls help receiving systems evaluate whether the message is authorized.

What you might notice

  • From: field displays an exact legitimate address (ceo@yourcompany.com) but the email fails authentication
  • Email client shows a discrepancy between the display name and the actual sending address when expanded
  • Reply-To address differs from the From: address — replies go to the attacker
  • Passes basic visual inspection but fails SPF or DKIM when headers are examined

These are possible warning signs, not proof of fraud on their own.

A safer next step

Organizations should configure SPF and DKIM for authorized senders and carefully roll out DMARC enforcement. Users should verify sensitive requests independently; a visible From address alone does not authenticate a message.

Where it can appear: Email — targets organizations that have not implemented DMARC / SPF / DKIM or whose partners have not

Link to this entry

Keep learning. Verify what matters.

Some entries overlap because a scam can combine several methods. Warning signs need context, and technical capabilities vary. This page does not establish that a particular message or person is fraudulent. It omits unverified prevalence statistics from the original reference.

For current guidance, visit FTC Consumer Advice, CISA Secure Our World, and FBI IC3. For concerns involving intimate images of minors, use NCMEC’s help resources. Report a correction through Ctrl+Alt+Elite; do not include passwords, financial credentials, or sensitive incident evidence.