The world of fraud is rapidly transforming, moving beyond simple digital tricks to use sophisticated artificial intelligence and emerging payment technologies. Scammers now employ advanced social engineering and deepfakes to launch highly personalized and financially devastating attacks. Countering these threats demands enhanced digital literacy, proactive cybersecurity, and collective vigilance against evolving fraudulent tactics in both digital and physical spaces.
Digital Deceptions and Social Engineering
Scammers frequently use digital channels to initiate their schemes, often starting with seemingly innocuous messages. A common tactic involves text messages claiming to be from a phone company, such as T-Mobile or Verizon. These messages falsely state that a large number of reward points are about to expire, urging recipients to click a link to use them. This link invariably leads to a fake phishing page designed to steal login credentials.
Beyond generic messages, fraudsters now target specific industries and professions with tailored emails. Lawyers, for instance, have received scam emails pretending to be from their state bar association, citing urgent matters that require downloading an attachment or clicking a file-sharing link from services like Dropbox, OneDrive, or Google Drive. These attachments often contain viruses. Similarly, business executives are targeted with emails about supposed awards, also containing malicious files. A particularly deceptive technique, sometimes combined with these emails, is “clickfix.” This scam pretends a browser has an error and instructs the user to click or type a command to fix it, which instead installs malware. A major red flag in these digital communications is the presence of password-protected zip files, which are almost always a scam. Users should also never trust any site that demands running a command or pasting text into a system’s run box.
Another method to bypass spam filters involves sending fake calendar invites. Services like Google Calendar send email notifications for invites, making the scam appear to originate from a legitimate source. These invites often contain scam links or other deceptive content, mirroring tactics previously seen with Google Drive file share invites.
Exploiting Physical Interactions and Supply Chains
Fraudulent activities are not confined to the digital world; they increasingly blend with physical interactions. The “brushing scam,” where an unsolicited package arrives at your address, has evolved. Originally, these packages were sent by third-party sellers on marketplaces like Amazon to generate fake reviews for cheap items. The new twist involves including a card or paper with a QR code inside the package. The card provides an excuse, such as claiming it’s a gift and asking the recipient to scan the code to see who sent it. Scanning the code leads to a phishing link, often mimicking a legitimate retailer’s login page, aiming to steal credentials. It is important to note that scanning the code itself does not hack a phone; it only directs to a site where credentials would need to be entered.
Hotels and their guests are targets of the “I paid twice” scam. Scammers first compromise hotel systems, often by tricking employees into downloading malware through industry-specific phishing emails. With access to guest lists and booking details, they then contact guests with highly convincing phishing emails. These emails include accurate information like real order confirmation numbers, actual stay dates, and the hotel’s name. The scammer then demands a second payment, claiming a previous transaction failed or that an unpaid reservation needs immediate settlement. Victims pay, only to find the hotel has no record of the second charge, and their payment information has been stolen.
Package theft has also seen new methods, such as using ride-sharing services for illicit rerouting. In one instance, a person ordering a laptop noticed unauthorized requests to reroute or delay their package delivery. Shortly after receiving the laptop, two separate Uber Eats drivers arrived, stating they were there to pick up a misdelivered package for redelivery. The scam involves tricking Uber Eats drivers into collecting packages from the legitimate recipient, believing they are correcting a delivery error. Theories on how scammers obtain tracking information include potential insider involvement at distribution warehouses or registering the victim’s address with shipping companies like UPS or FedEx without verification, which grants access to delivery notifications and control over packages. Registering one’s own address with these services might offer some protection.
Local scams also persist, often relying on impersonation. One scheme involves callers pretending to be a local police department, soliciting donations for police merchandise. Another common scam, particularly around holidays, features people impersonating charities and even police departments to raise money for fake toy drives or gift programs. It is important to remember that legitimate police departments and charities typically do not solicit donations in this manner.
New Vulnerabilities in Payment Systems
While tap-to-pay methods are generally considered safe and effective at preventing traditional card skimmers, scammers have found ways to exploit them. “Ghost tapping” involves a scammer using a portable merchant terminal to make a charge to a credit card still in a wallet or pocket, simply by getting very close. This is more of a risk for credit cards, as phone-based payment systems like Apple Pay and Google Pay usually require user confirmation. Using an RFID blocking wallet or being aware of overly close people can help prevent this.
Another tactic is the “forced swipe.” Scammers install a regular credit card skimmer on a payment terminal, then physically disable or block the tap-to-pay panel. This forces users, who might prefer tap-to-pay for its security, to use the less secure magnetic stripe, where the skimmer is waiting. This can involve breaking the panel, applying glue to the chip insert slot, or placing an RFID blocking sticker over the tap-to-pay area. If a tap-to-pay terminal does not work, it should raise suspicion. It is a myth that a simple sticker can intercept a tap-to-pay transaction; any sticker used would be to prevent its use.
A more advanced tap-to-pay scam involves placing a sticker with an embedded NFC (Near Field Communication) tag on a payment terminal. When a phone is held near it for payment, the NFC tag can trigger a prompt on the phone to open a website. Scammers hope users will mistakenly believe they need to visit this phishing site to complete their payment, leading them to enter credentials on a fake page. Again, simply scanning the NFC tag does not compromise the phone; it requires further user action on the linked website.
The Rise of Deepfakes and Counterfeit Operations
The advent of AI-powered deepfake technology has opened new avenues for fraud, particularly in impersonation. Deepfake scam videos are appearing on social media platforms, impersonating content creators. These videos use cloned voices and synchronized lip movements to make it appear as if creators are endorsing fake hacking services or other scams. Despite sometimes having a robotic voice, the visual and auditory mimicry can be highly convincing. These AI-generated videos are created from scratch, meaning the original creators never uttered the advertised words. Platforms like TikTok have seen such deepfakes accumulate millions of likes, highlighting the scale of the problem. Reporting these deepfakes as misinformation is one way users can contribute to combating their spread.
Counterfeit goods also remain a persistent threat. Fake postage stamps, particularly prevalent in the United States, are sold at steep discounts on social media or marketplaces like Facebook. These stamps are not genuine, and using them can lead to mail rejection or worse. Postage stamps are almost never discounted greatly; while legitimate retailers like Costco might offer a minuscule discount of a couple percent, a discount of 10% or more is a clear indicator of a counterfeit product.
Protecting Against Evolving Threats
Staying safe in an environment of escalating fraud requires constant vigilance and an understanding of evolving tactics. Always scrutinize unexpected communications, whether text messages, emails, or calendar invites. Be particularly wary of requests to download attachments, click unknown links, or run commands, especially if they come from unexpected sources or claim urgent action is needed. Password-protected zip files should be treated as a major red flag.
In physical interactions, be cautious of unsolicited packages containing QR codes and avoid scanning them. Verify any requests for additional payments directly with the service provider (e.g., hotel) using their official contact information, not through links or numbers provided in suspicious emails. When using tap-to-pay, be aware of your surroundings to guard against “ghost tapping” and consider using an RFID blocking wallet. If a tap-to-pay terminal seems damaged or doesn’t work, opt for an alternative payment method or a different terminal. Never follow prompts from an NFC tag on a payment terminal to visit an external website to complete a transaction.
Regarding deepfakes, cultivate a healthy skepticism towards videos, especially those promoting dubious services or offering unrealistic claims. Report any deepfake content you encounter on social media platforms. For package deliveries, consider registering your address with major shipping carriers to gain more control and receive direct notifications, potentially preventing unauthorized rerouting. Finally, remember that legitimate postage stamps are rarely sold at major discounts, and genuine police departments or charities do not typically solicit donations for merchandise or toy drives through unsolicited calls.