Scams change fast. But the playbook is often familiar. They often work because they create urgency and push you to act before you can think or verify what’s happening. They exploit your emotion and sometimes even impersonate people you already trust.
You can read about common scams in this library. That includes AI voice cloning, fake job offers, SIM swapping, crypto phishing, charity fraud, travel scams, and much more.
Every entry in here explains how the scams work, shows real-world examples, and gives you practical advice on how to reduce your risk.
1. Finfluencer Scams
The Scam:
The rise of crypto and ease of digital trading have modernized the scam of good old fashioned snake oil sales. There’s a social media influencer industry for every topic under the sun, and finance is no exception. As a result, there are many unlicensed financial advisors out there willing to scam naive investors.
Aside from just giving dubious advice, some of these influencers may offer free bonuses for investment commitments, or charge hidden fees if you allow them to manage your money. The people hawking the investments may not disclose their own interest in the token or the stock they’re selling you (which is illegal.) They might sell you outdated research information or charge you for dubious training courses.
It Happened to Them:
Any of you who took investment advice from Kim Kardashian and bought the crypto security EMAX (which she was paid $250,000 to promote on her Instagram, but did not disclose) have been vindicated by the SEC, which made her pay $1.26 million in penalties. You might even say her decision to hawk crypto via social was a bad investment.
Reducing the Threat:
Don’t take investment advice from people whose area of expertise is primarily starring in a reality show and “breaking the internet” seems obvious, but maybe less so if a “finfluencer” looks the part and could pass for an honest broker (in both senses.) In that case, you need to make sure that the person whose advice you’re taking is a registered investment advisor. Credentials actually do matter here.
Beware of easy money promises. There is no ONE SIMPLE HACK to eliminate all of your debt, or make you very wealthy with little money down.
Be aware of your own limitations in understanding what you’re buying. Consider multiple sources and evaluate claims independently via licensed financial advisors.
If a finfluencer insists that you buy something NOW NOW NOW, that is your sign to slow down and be careful. Scammers will use a sense of urgency to prevent targets from fully evaluating their claims.
2. Evil Twin WiFi Scams
The Scam:
The scammer sets up a wifi access point that’s designed to look like a real one–usually a public wifi network. They set up their new access point with the same name and Service Set Identifier (SSID) and so users don’t realize they’re accessing a network other than the one they intended. The user is directed to a login page that looks like the one they’re familiar with from the network they think they’re accessing and then use the credentials to login and capture user data, including sensitive information. The user doesn’t realize that the information has been stolen until much later because the wifi works and nothing seems amiss.
It Happened to Them:
Passengers on a Delta Flight in August of 2026 encountered a wifi network that looked like Delta’s in flight wifi but was created by a passenger. The Delta crew alerted traffic control and it’s unclear exactly what happened, but some of the passengers were en route back from a cybersecurity conference and it’s relatively easy for a moderately tech savvy person to set up an evil twin access point using commercially available devices known as wifi “pineapples” that are used by security professionals to probe security vulnerabilities.
Reducing the Threat:
Use a personal hotspot. Many cellular carriers offer it as a service on your existing smartphone, and you can buy portable hotspot devices if you want dedicated power that won’t drain your phone battery.
If the network is marked “unsecured,” heed the warning and don’t use it.
Don’t allow your devices to autoconnect to the nearest network.
Use multifactor authentication for anything you’re logging into that has sensitive information.
3. Fake Charity Appeals
The Scam:
Scammers create digital charity campaigns with fake appeals that convince users they’re donating to a worthy cause. They may look like a real charity with a slight change in the name or URL, and often use emotional appeals to get people to donate. Natural disasters are particularly ripe for scammers who want to tug at heartstrings to get to wallets.
They may solicit donations via an unfamiliar platform, ask for things like pre-paid cards, or have other non-refundable payment methods that make it difficult for victims to recover their money and difficult for law enforcement to trace.
It Happened to Them:
In the wake of Hurricanes Milton and Helene in 2024, the Department of Justice issued a public alert about charity scammers who created fake philanthropies after prior hurricanes to solicit donations, supposedly on behalf of hurricane victims. Lecia E. Wright, Supervisory Assistant United States Attorney wrote, “As we have seen in the wake of previous national disasters, fraudsters will target victims of the storms along with citizens across the country who want to do what they can to assist individuals affected by the storms. Unfortunately, criminals exploit disasters for their own gain by sending fraudulent communications through email or social media and by creating deceiving websites designed to solicit contributions.”
Reducing the Threat:
Real charities are registered as 501(c)(3) organizations with the IRS and you can check the IRS’s search exemption page to see if they’re legitimate.
Venmo, Paypal and many other payment systems offer verification for charities, so be wary if the organization is not verified and using them for payments.
Be wary of any organization that requests unusual payment methods, like pre-paid or gift cards, crypto currency, or anything that would be difficult to recover.
Be extra careful if the appeal is time-sensitive and there’s pressure to donate right now. You should also be able to vet them and ask questions.
4. Political Registration and PAC Scams
The Scam:
Scammers posing as political organizations or pollsters will contact you, unsolicited, offering to register you to vote, to fix your registration, or offer you a gift card in exchange for taking a poll if you give them your credit card information to cover shipping and handling. This coincides with the rise of scam PACs, which purport to be political action committees (PAC), but keep money raised for themselves.
It Happened to Them:
In 2020, scammers sent out an email impersonating the U.S. Election Assistance Commission (EAC) asking voters to add personal information to their registrations that the commission does not track. They did this by spoofing the EAC’s official government domain.
Reducing the Threat:
If the fundraiser claims to be a political action committee, PACs are registered with the FEC. You can get information on their organization and fundraising from the FEC website.
Instead of donating to a PAC, you can donate directly to a candidate or reputable organization.
You cannot register to vote over the phone and will never receive unsolicited requests to “fix” your registration information via email, phone, or text. You can, however, register to vote online or update your existing information yourself.
5. SIM Swapping
The Scam:
Also known as “SIM hijacking,” scammers transfer your phone number to a SIM card in order to gain access to your digital accounts and get around 2-factor authentication methods that use your phone to verify your identity. They do this by contacting your mobile carrier and using available information they have about you to convince the carrier that your number needs to be moved to a new SIM card.
It Happened to Them:
Patricia Escriva of Florida was babysitting one night when she realized her phone was suddenly quiet and had no service. She connected to wifi and was barraged with alerts that money was being withdrawn from her accounts and that a new device had been added. It took her three days to recover her number and begin the arduous process of getting her money back.
Reducing the Threat:
Use multifactor identification, with methods that are not solely reliant on your phone number. (Authentication apps like Google Authenticator are linked to your device, but not your phone number.)
Refrain from using security questions with answers that can be gleaned from information about you online.
Your mobile carrier will not contact you unsolicited asking you to verify personal information, so don’t respond to requests to do so.
6. Travel Reservation Scams
The Scam:
Scammers impersonate airlines, hotels, and other travel and hospitality companies that people actually use. You might, for example, get a notice from a hotel saying that there was a problem with a reservation or payment–information they have about your real reservation because they’ve managed to get into the hotel system via phishing staffers or hacking their systems in some other way.
If you’ve booked a flight, they might send a text notifying you that your flight needs to be rebooked for an additional fee.
It Happened to Them:
In December of 2025, an investigation by Norton Security found that a fake message had been sent to Booking.com users. According to Wired, the message arrived via Whatsapp. It “said it was from a specific hotel and listed the dates of an upcoming reservation, before asking the individual to click a link and confirm their details. The link led to a false website and included a chatbot that would instantly share any entered details, such as credit card information, with the hackers.” Norton also determined that the service Cloudbeds had been hacked in a similar way.
Reducing the Threat:
Instead of responding to links in the reservation message or text, contact the hotel or airline directly.
Familiarize yourself with your airline’s rebooking and cancellation policies ahead of time.
Smaller hotels with fewer cybersecurity precautions in place may be more vulnerable to these kinds of attacks, so be especially careful about digital communication from boutique venues.
7. Brushing Scams
The Scam:
You get a package that looks like it’s coming from Amazon or a similar company, but you didn’t order anything. Inside is usually something cheap. A scammer is sending it to you in order to get validation of delivery so they can use your name to write fake reviews to “brush” up their sales, so the FTC refers to it as a “brushing scam.” Is this a lot of trouble for a fake review? Yes. But it might be worth it for the scammer if they can use you as a reviewer repeatedly or get you to scan a QR code to find out where your surprise “gift” came from.
It Happened to Them:
Michael and Kelly Gallivan of Massachusetts found themselves with a humidifier, a computer vacuum, a portable speaker, and some LED lights–all of which would have made for a cheery and clean home office–but neither had ordered any of those items. The sender, who was located in China, appeared to be running a brushing scheme, so if you notice a “Michael and Kelly Gallivan” leaving enthusiastic reviews under a humidifier you’re considering buying from Amazon, you should be aware that the actual Michael and Kelly might not be quite so excited about it.
Reducing the Threat:
The law says you don’t have to return anything you didn’t order, so you’re in the clear there, but use common sense about whether what you were sent is safe to use.
As always, beware of QR codes that lead to mystery destinations and don’t click on unfamiliar links.
Amazon asks that you contact customer service if you receive a mystery package you’ve determined is not coming from friends or family. You can report them at this link. Be sure to note the tracking number.
8. Job Recruitment via WhatsApp
The Scam:
You get a job offer, completely unsolicited over Whatsapp from a professional recruiter. How nice. Flattering, even. In this economy? Amazing!
Not so fast. Aside from the fact that professional recruiters rarely if ever make first contact via a messaging app, they certainly don’t offer jobs without so much as an interview or discussion.
What scammers do, however, is offer a gig that involves simple tasks or data entry, usually billed as a “work from home” gig. In order to get paid, you must pay them first some minimum or offer up personal information that could be of use to part you with your hard earned money.
It Happened to Them:
Seven people in the UK paid a total of 200,000 pounds after being recruited for jobs as “data optimizers,” a real sounding job that was, of course, a fiction created by a scammer. Victims were asked to “match” their supposed earnings with their own money. One thing was certainly optimized: scammer profits!
Reducing the Threat:
If you’re actually being contacted by a recruiter, you should be able to respond to them via traditional channels: the firm’s office number or an email from the company’s domain.
There is no reason for any potential employer to ask you for money, under any pretense. That is a big red flag.
Block and report messages that you’ve determined are fake.
9. Fake Interview Apps
The Scam:
For better or worse, more job interviews are happening digitally these days, some of them conducted entirely by AI. This is a rich opportunity for scammers to convince victims who are job hunting to download software or documents as part of the supposed interview process. Many of these scams are initiated via LinkedIn messages and the company issued a warning to users in a 2026 safety report.
It Happened to Them:
A LinkedIn user lost £18,000 worth of cryptocurrency after downloading a seemingly normal looking document as part of a supposed recruitment process. The user may have been targeted because they indicated on their profile that they were looking for work.
Reducing the Threat:
If you’ve never heard of the company, research to make sure it exists in the real world outside of a LinkedIn profile.
If you have heard of the company, look at the careers section of their website to confirm that the job listing is real, and verify the recruiter’s connections to other people who work there.
Think twice if you’re asked for money or bank details or to provide sensitive personal information up front.
If you’re communicating via LinkedIn, look for verification badges for companies and recruiters.
10. Retargeting Scams Impersonating the IC3
The Scam:
Scammers impersonate the FBI’s Internet Crime Complaint Center (IC3) to re-target people who have already been victimized. They may offer help to victims in recovering funds and in the process. This may occur via email, or messaging, and recently scammers have used AI to create fake videos from supposed FBI personnel encouraging reporting. When them the victim contacts them, they may direct them to malicious code, or collect more personal and financial information.
It Happened to Them:
An FBI alert from July of 2026 described a recent scenario: “After the victim of a scam begins to realize they are being defrauded, the victim informs the scammers they will report them to the FBI and file an IC3 report. The victim is later contacted by an individual impersonating an FBI agent on Facebook Messenger (FM). The impersonator communicates via Telegram and FM and sends a link to update the submitted IC3 report. The link may contain malicious code or may be used to collect more financial data to revictimize the person.”
Reducing the Threat:
If you have ever filed an IC3 complaint or are preparing to do so, familiarize yourself with the agency’s process and methods of communication. They do not use social media, so any supposed contact via Facebook or video platforms is fake.
The legitimate URL for the IC3 is www.ic3.gov. Any other URL is not IC3 affiliated.
IC3 will never ask for payment of any kind, so beware of anyone claiming to need payment to recover lost funds.
Communication from actual IC3 personnel is handled through local FBI field offices, so disregard messages from anyone claiming to be IC3 affiliated that arrive via digital methods.
11. Voice Cloning
The Scam:
Scammers use voice cloning technology (often powered by AI) to create facsimiles of a person’s voice in order to impersonate them to friends or family. They’ll often claim to be a loved one who’s having an emergency and needs money.
Voice cloning is increasingly common, and instances of it were up 1,210% in 2025 according to Fox News. A research study from McAfee reported one in four people they surveyed had been voice cloned themselves or knew someone who’d been scammed.
Scammers don’t need to be technically sophisticated to execute this scam. With as little as three seconds of a person’s voice, they can use freely available–and free–technology to produce a voice clone. Many of us send voice notes and post audio to social media, and this is often source material for scammers.
It Happened to Them:
California mom Deborah Del Mastro received a call from a man claiming to have kidnapped her daughter and demanding money. Del Mastro wired over $5000 to Mexico after hearing a voice recording that sounded like her daughter, distressed and panicking. She only realized it was a hoax when she arrived to pick up her daughter and no one showed. She called her daughter’s phone to find that her daughter was perfectly safe, and at work.
Reducing the Threat:
Security experts at McAfee recommend having a codeword for family members so you can all identify each other if you get any suspicious phone calls. It may sound like something out of a spy movie, but it can’t hurt.
The most likely place a scammer will find audio of your voice is on social media so making sure you’re not publicly exposed on social media platforms is one way to avoid having your voice cloned. (And it may not be your social media; a family member or friend could post audio of your voice.)
Once scammers have a clone of your voice, they will look for personal information: your phone number, address, relatives. Much of this information may be available in data broker databases. They are required to take down your information at your request, and you can use services like Delete Me to manage the process.
12. Celebrity Deepfake Ads
The Scam:
Scammers use AI to create deepfakes of celebrities, politicians, or other public figures in order to spread disinformation or lure victims to click on malware links. These are images or video that appear to be authentic but are generated by AI.
It Happened to Them:
Tom Hanks, Taylor Swift, Kim Kardashian, and Oprah have all been made into deepfakes to sell products including dental plans and cookware. More insidiously, they are sometimes used to manipulate individuals, as some golf fans discovered when they were lured into romance scams by digital deepfakes impersonating well known female professional golfers.
Reducing the Threat:
Some common sense applies here. It’s not likely that celebrities are messaging strangers for dates, or that incredibly famous and successful celebrities are selling cheap off brand products. (Unfortunately, several a-listers have actually promoted questionable crypto schemes, so we can’t rule that out.)
Political advertisers in the U.S. are now often required under state law to disclose whether they’re using AI to create images or video of candidates. There isn’t a federal law yet, so it’s worth being skeptical of ads that depict candidates in a negative light. If the information the ads are purporting to deliver is true, you should be able to find a news source for it.
13. Crypto Phishing
The Scam:
This scam works like many other phishing scams: the target receives a link, usually in an email, that appears to direct them to a login page for their crypto wallet, and once they have the target’s private keys, they steal the money in the wallet.
It Happened to Them:
Direct access to crypto wallets are disproportionately responsible for multi-million dollar losses, but even if you don’t have a lot of money in crypto, losses can be extremely difficult to recover. Crypto isn’t insured the way your bank accounts are, nor do they have the protections you’d have as an investor in securities.
This can happen even to sophisticated crypto investors. Take the story of Glen, for example, who lost $180,000 after responding to a fake customer service support alert.
Reducing the Threat:
Take a look at links before you click. Are the URLs unrelated to the crypto wallet company you’re using?
Look at the email sender. Is the email coming from a sender at the company’s email or a private address on another platform like Gmail?
Be skeptical of unsolicited requests for wallet information. If you receive an unexpected notice purporting to be from the company whose wallet you’re using, don’t respond and contact customer service directly.
And, of course: use multifactor authentication so that a scammer would need more than your password to access your account.
14. Romance Scams
The Scam:
This is a broad category, and includes but is not limited to many different digital scam tactics (phishing, catphishing, use of deepfakes, etc.) In short, the scammer approaches their target as a potential romantic interest and develops the relationship over time in order to extract money and goods from their target.
It Happened to Them:
Where to start? True crime shows are full of stories about people victimized by charming strangers who go on to exploit them in insidious ways. A 66 year old woman from Montana named Rita lost $90,000 over several months after someone contacted her on a social media platform claiming to be a celebrity. The imposter convinced her that he needed money to help pay for events he was doing and insisted that she pay in bitcoin.
Reducing the Threat:
If you have not met your romantic interest in person and cannot yet verify who they are, do your research. Googling a potential romantic interest isn’t stalking; it’s looking out for your own safety.
Beware if they refuse to talk to you on video or meet in person.
If you’ve never met your romantic interest in person, and they ask you to send them money for any reason, consider it a red flag.
If someone you’re seeing asks for money in the form of cryptocurrency or gift cards, that is also a red flag.
If the romantic interest is trying to isolate you from friends and family who express skepticism, that’s another warning sign. If they have no friends and family for you to interact with in the process of getting to know each other, that may be another sign. Scammers will attempt to maintain and control one-on-one communication and discourage communication with others.
Do not give out personal information that could be used to take over any of your digital accounts, especially if they are connected to your financial accounts.
15. Tax Impersonation Scams
The Scam:
The most common form of tax scam involves a scammer calling a victim and pretending to be the IRS. They will demand payment for money owed and may threaten the victim with arrest or deportation if the fee isn’t paid immediately. They may also promise a refund and ask for sensitive bank information so they can deliver it.
It Happened to Them:
A 2023 NPR report noted that victims of this sort of scam have lost more than $28 million since 2018. People anxious to comply with the IRS may panic, thinking they owe money and fail to be sufficiently skeptical. But the IRS does not contact taxpayers via phone, or email, or text. They communicate via the postal service, and will not initiate anything via other channels unless a taxpayer has failed egregiously to respond to other letters.
Reducing the Threat:
The IRS will not call you, so even if you receive a phone call from a number that looks legitimate (it may be spoofed) and the person on the phone gives you a badge number, don’t reveal sensitive information. Call the IRS directly if you have a special situation where a call might be warranted.
Needless to say, the IRS does not want to be paid in gift cards or bitcoin. Anyone claiming they do is a scammer.
16. Toll Payment Scams
The Scam:
The target receives a text or other type of message from a scammer claiming to be a toll payment company, like E-ZPass or FasTrak, claiming that the victim has a toll payment due, and threatening suspension if the balance isn’t paid immediately via a link provided.
It Happened to Them:
Virginia Beach resident Eric Moyer received a blizzard of texts, purportedly from E-ZPass, telling him he had unpaid tolls and could have his license suspended if he didn’t pay them. Unfortunately for the scammer, Moyer was immediately suspicious–largely because he hadn’t used a toll road in months. Security experts say many of the scams are run by groups of Chinese criminal gangs who buy phone numbers in bulk and spam them with demands for small amounts of money, and the personal information they acquire from the victim is worth more than the money they demand.
Reducing the Threat:
Don’t click on links in the message. Log in to your account directly to see if you have any balances.
Note whether the message is generically addressed–i.e., “Dear Customer”. Many companies (including E-ZPass) address the customer by name.
When you receive a scam text, block and report the number.
17. Fake Job Scams
The Scam:
Scammers send targets emails or texts offering jobs (often work from home jobs that are well compensated) that pay a certain amount a week or small amounts of money for small tasks. Once engaged, the targets are asked to provide bank information and / or deposit money in order to receive higher payouts.
It Happened to Them:
Californian Dawn Furseth thought she’d received a part-time job offer from Facebook and lost $176,000 to a scammer. Furseth was a contractor who had worked for software companies and was approached by a scammer who only communicated with her over Whatsapp. The scammer convinced her that she had a job involving posting facebook ads and Furseth was instructed to put money from her own account into a digital wallet.
Reducing the Threat:
Beware of offers from companies or recruiters that will only communicate via text and use personal emails instead of emails from company domains.
Another red flag: jobs that pay well but require little or no experience. (In this economy?)
You should not be asked to fund anything with your own money. In a real job, the company pays you. You don’t pay the company.
If it’s a real company, you can always verify the job posting by inquiring directly.
18. Tech Support Renewal / Geek Squad Scam
The Scam:
An oldie, but a goodie. (Or a baddie?) Scammers impersonate a tech support company, usually Best Buy’s Geek Squad, confirming a payment the victim didn’t make, then redirect them to communicate with the scammer. Then they often ask for remote access to the victim’s computer. This one is so pervasive that Best Buy has a whole notice page warning customers and noting that the Geek Squad doesn’t make unsolicited calls to customers.
It Happened to Them:
You probably already have this kind of scam email sitting in the spam folder of your inbox. But they’re still squeaking by in the inboxes of less tech savvy and more vulnerable users. (Think about who typically does need routine tech support for personal computer use.) Scammers use fearmongering to convince these more vulnerable users that they will lose access to their technology if they don’t pay up, and convince them to pay fast before they might notice any red flags.
Reducing the Threat:
Best Buy notes that they never ask customers to reveal or verify personal information online.
Only use official channels to communicate with tech support (i.e., the company’s publicly listed support number.)
Check sender email addresses to make sure they’re coming from the company.
Do not click on URLs in unsolicited support emails.
Do not give anyone who contacts you unsolicited remote access to your computer.
19. Bank Smishing Scam
The Scam:
Scammers impersonate the target’s bank via text, and begin a chain of communication where they convince the target to give up their bank information. This is a “smishing” scam–phishing over SMS.
A typical text might look like one of the victim’s bank’s real fraud alerts and the scammer will ask them to call a number to contest a fraudulent purchase. The scammer may then impersonate a customer service rep, using scripts that are similar or identical to those used by the bank, in order to get the customer to “verify” their personal information.
It Happened to Them:
CBS journalist Matt Guttman nearly fell for this scam, even though he has covered scams in his capacity as a reporter. He got a call from what was supposedly the fraud department of his bank and the scammer, impersonating a bank professional, seemed to already know a lot about Guttman and his bank account. But his daughter had recently been scammed in a similar fashion and he double-checked with the bank.
Reducing the Threat:
If you believe you have a real fraud alert, call the bank at the customer service number on the back of your bank card. Do not provide verification information in response to someone who has called or messaged you.
Check your online banking account directly for any suspicious purchases.
No bank will ask you to withdraw money from your account.
Check caller ID for the bank’s number. (Numbers can be spoofed, so this isn’t foolproof but an odd phone number may be a warning sign.)
20. Party Invite Scam
The Scam:
This is a phishing scam where targets receive an invitation to a party that looks like it comes from prominent digital invite companies like e-Vite or Paperless Post. The initial message looks identical to actual invites that would arrive via text or email, inviting the recipient to “view the card” or event. Upon clicking the link, targets are asked to provide login credentials and scammers may use that access to install malware. They can also use access to your address book on the platforms to target your contacts.
It Happened to Them:
This scam exploits FOMO (fear of missing out). Who doesn’t want to go to a great party? As a result, victims may be extra curious when the invite comes from an old friend, an ex, a colleague, or someone unexpected.
Andrew Smith, a grad student in Manhattan received a message from an ex-girlfriend while he was at a bar. “The choice of sender was super clever,” he told The New York Times. “This was somebody that would probably get a reaction from me.”
Reducing the Threat:
Check the sender email or phone number.
Hover over the link to see the URL and whether it directs to the invite company domain.
Use 2 factor authentication on invite platforms.
Check the platforms before clicking on any links. If the invite is real, it will show up in your account.
