We all like to think we are smart, independent, in full control of our lives, and there is no way any of us would fall for a financial scam, like those lonely old seniors do, because “that happens to them, not to me, because I am smart.”
But the truth is, even smart people fall for it, people with master degrees, people who work in academia, people running large business… Even I could fall for this.
And how did you learn to recognize it?
One of my best friends moms said she knew the guy and it seemed like a legit investment thing. This lady was the CIO of a fortune 100 company so at the time I felt like surely she knew what she was talking about. She did not. She was honestly one of the most financially ignorant people I’ve ever known. Fortunately it was just a few grand.
I’m not sure how much it counts, since its more identity theft than financial scam (tho the end result is basically financial) but I replied to one of those scam jobs postings, they invited me to interview over telegram. That was red flag 1, nobody at all uses that here, so I knew it was probably a scam, and proceeded with that knowledge, mostly out of curiosity for how it would unfold.
They asked me some generic questions too quickly for anyone to have read the replies, so they got generic responses, then they offered me a job on the spot, I’d just need to send my identity documents to their super sus gmail address. Obviously I never sent anything, I contacted the company directly to see if the listing was at all legit and was told no, they weren’t hiring at all (shame too, I’d have loved that job). I also reported the posting, not that it’s likely to have mattered.
If the scammers had been a bit smarter about how they went about it, I might not have really thought anything of a text-based interview, sort of thing some places do for blind-hiring, nor is sending identity documents weird, but a drop box sort of thing would have made that one a lot less obvious… basically I can see how people would fall for it, even if my experience was too sloppy to he effective.
My Mom had a close call. She got an Email “thanking” her for her “purchase”. The amount was ~$500. The Email helpfully included a customer service line to get a refund. Once called, the “customer service” rep tried to get her to install remote-desktop software.
Of course there was no original $500 purchase. The whole point of the scam is to make the target upset that they’ve been charged and get so laser focused on the refund that they don’t question the process.
Scams almost always start by fulfilling something the scammed person is lacking. Long cons might start out as a person being friendly with a lonely old person. Quick cons usually prey on immediate financial needs.
But how you identify cons is usually by being skeptical of everyone’s motivations. You test it by twisting what they want and seeing how they react.
Example: I was selling a car that was just a couple years old. I have a buyer basically agree that everything’s good, they’re ready to buy, just need a carfax report. They claim carfax isn’t reliable but this other report company is who they trust. I buy the report and share it with them, and when it’s clean as I know it will be, they’ll be here the next day with cash. I researched the company a bit and it seemed legit, and I figure the report will help me sell to others as well, so I buy it and the person ghosts me. I research a bit more and while technically the company is legit, they pay referrals to people to sell reports. I immediately contacted them and got a refund, luckily.
Next time I’m selling a car, same thing happens. So I tell them to buy the report themselves and I’ll deduct it from the cost of the vehicle. To keep staking time from them I think I even offered them to buy the report themselves and I’ll deduct 5x the cost from the selling price.
So they were fulfilling my need by buying my car. They made a request that seemed reasonable. My twist that would effectively fulfill the request but by different means was met with arguments. Makes it more obvious that they were never going to fulfill my need.
In the case of someone being friendly to an elderly person. Maybe that person works in a care facility the elder is staring at. Eventually they ask for something. Maybe they’re “short $500 to deal with this painful root canal” and subtly asking for cash. If the elder wants to help, but wants to test, they could offer to come to the dentist with them and swipe their card to pay. All of the sudden that root canal is being handled by a dentist that only takes cash, which is obvious bullshit.
Be skeptical of any new people, even if you like and trust them, and if unlimited to help them in some way find ways of helping them that disrupts their plan to see how they react.
A scammer almost got me recently, saying they were calling from the fraud department of my credit card company. I started talking to them until I remembered I had closed that specific account years ago. It was convincing up until that point. When I questioned it, the caller became irate and said “oh yeah, well if I’m a scammer, how do I have your address???”. She read it off, and it was a place I’d moved from years ago as well.
I’ve had a number of people in my life fall for scams. Its all about people exploiting trust. Victims trusted that what they were saying was true, they didn’t question what was happening enough, and their tactics are designed to stress you out so that you don’t question when they offer you a quick solution.
I believe that everyone needs to be exposed to this betrayal in some way to learn to recognize it. The mechanic that charges you too much for a repair, the person in a game that scams you out of items, the phishing email that needs you to buy gift cards.
Talk about scams with others, learn from the stories you hear, and be skeptical when someone presents both the problem and solution.
I don’t know it is protection enough, but my golden rule is that if something is too good to be true it is usually a scam.
Easy way to make money? Probably a scam. Unbelievably attractive and rich person is into you? Probably a scam.
Etc. etc.
Found out the other day that my aunt responded to one of the phishing scams where they send you a bill and a line for customer support.
She called and allowed them take control of her PC.
There’s no way for a person to learn other than making a lot of errors, or talking to people who got scammed to understand how it happened. As long as we’re alive, until we die, we’ll keep learning.
I was “scammed”: my company sent a phishing email to warn people about scams. I learned never to click links in emails unless you know the sender and that your stored passwords are inserted only when the url is 100% correct. If you don’t get the autocomplete option, the URL might be wrong and it’s a trap
My company does random phishing trials to keep people alert. They collect statistics on how many people click the link and how many report it as a scam.
Fortunately the test mails they send out include a specific header indicating it’s a phishing test, so I just set up a rule in my mail app to automatically move those to a specific mailbox and alert me they’re running another test.
Your rule does kind of defeat the purpose. The goal is to see if you can detect phishing attempts “in the wild”. We all want to claim we never fail at detecting stuff, but we do, so training against it is good practice, even if annoying
We had this, and I created the same rule, but they have since switched to AI generated phishing emails that use information about you (your manager etc) to make a fairly convincing email. If someone gets a lot of email from outside sources, I can totally see them clicking on a link if they’re in a hurry.
The main things that raise my suspicion are:
- telling me it’s urgent
- telling me there will be dire consequences if I fail to comply
- asking me to log in (with a direct link)
- it’s from an external source
- it’s not related to my job (eg, asking me to sign off on a PO)
- telling me to download a file
- including an attachment
I usually just err on the side of reporting it. I’ve only had one false positive so far.
Then there’s also legitimate mail that contain all those red flags.
The same people that made us go through anti-phishimg training sent me an e-mail that read exactly like a phishing attempt net even a week later, which turned out to be totally legit. Like, WTF.
Yep lol. They have a second system that rewrites all links in emails to go through a scanner, but as a side effect that obfuscates them as well.
I got some of those! If ai hadn’t personally known the sender, I would have reported them…
And how did you learn to recognize it?
I would imagine watching scam baiter videos (e.g. Kitboga) and reading scam related news introduces one to know the most common scams.
Of course there can be other/new types of scams, but removing the common scams from the effective ones should be at least beneficial.


