top of page

Stay Ahead of Emerging Threats

Thanks for submitting!

Common types of scams: how to spot them and what to do next

Writer: ESET Expert
ESET Expert
10 hours ago
9 min read

Scams are increasingly convincing and easier to mass produce. Learn how to avoid them.



Scams can reach a user by email, text message, phone call, social media post, ad or website. Their stories differ, but the pressure tactics are familiar: urgency, fear, secrecy, an unexpected prize or a deal that seems too good to be true.


This guide helps you recognize common scam patterns, pause before acting and know what to do next if you have already clicked a link, made a payment, installed something, or shared information.

Before you respond, pause and check:


  • Was this unexpected? Be cautious with unprompted messages and calls, as well as unexpected ads and offers.

  • Are you being rushed, threatened or promised an unusually good deal? Treat pressure, threats and unusually good offers as warning signs.

  • What does the sender want? Stop and check if you are being asked to click a link, share a login code or personal information, or grant remote access.

  • Can you verify it independently? Use the organization’s official app, website or known phone number,not the contact details provided to you. A familiar voice, face or brand is not a guarantee of authenticity: AI can make calls, videos and messages look convincing.


Common types of online scams: what to look for



What are common types of online scams? Phishing, fake shops, delivery and marketplace scams, investment fraud, impersonation and romance scams are common examples. The guide below can help you quickly identify which warning signs to look for.


Start with how you encountered the scam:


  • Email: Check for signs of phishing, including the sender address and domain, and avoid opening unexpected or suspicious attachments.

  • Text message: Watch for common text message scam. These messages concern deliveries, payments and account activity, especially those that create a sense of urgency. Read ESET’s guide to vishing, smishing and phishing for more signs to be cautious of.

  • Phone or video call: For common phone scams, be wary of unexpected tech-support, bank, family emergency or impersonation calls; end the call and use a known number to verify the caller or their claims independently.

  • Social media post, ad or marketplace: Watch for fake offers, investment pitches, suspicious job offers, and romance scams.

  • Website: Be cautious with unfamiliar online stores, login and payment pages. Check the web address carefully and verifythe domain and the seller  through a trusted source where applicable.


Phishing


Phishing scams trick individuals into downloading malware or giving away sensitive details like passwords, banking information, or other personal data. Scammers often impersonate trusted sources, creating a sense of urgency - like fake alerts about expired accounts or unpaid fees - to prompt quick action. Variations include QR-code phishing (quishing), SMS phishing (smishing), and voice phishing (vishing).


When an email, text or website asks you to sign in, pay, download a file or share a one-time code, do not use its link or phone number to check it. Open the organization’s official site or app yourself, inspect the sender’s address and domain carefully, and use an independently found contact route if you are unsure.


Description: Phishing email impersonating ESET.
Description: Phishing email impersonating ESET.


Description: Example of a QR code phishing email detected by ESET telemetry (screenshot redacted)
Description: Example of a QR code phishing email detected by ESET telemetry (screenshot redacted)

Watch out for homoglyph and typosquatting


Homoglyphs use similar-looking characters to mimic legitimate URLs or email addresses. Typosquatting involves registering domain names that closely resemble popular websites—often with minor spelling errors. These two methods are commonly used in phishing and shopping scams. For example, "℮s℮t.com" uses two "estimated" symbols—"℮," instead of the letter "e"— imitating "eset.com."


Advance-fee scams: fake prizes, loans and 419 offers


An old, infamous type of phishing attack in which scammers promise large sums of money in return for the victim’s assistance. A swindler typically poses as a high-ranking official or prince from an exotic country, needing help transferring a head-spinning amount of money. They ask the victim to provide personal information or make an advance payment to facilitate the transfer.


The same pattern can now appear as a fake prize, loan, inheritance, charity request or investment opportunity. Do not pay a fee or share identity documents to claim money that you were not expecting.


Description: The sender of this email fraudulently claims that he is a U.S. Army sergeant deployed in Afghanistan. He requests assistance transferring 15kg (33.069 lbs.) of gold bars and $1 million cash in exchange for a reward.  
Description: The sender of this email fraudulently claims that he is a U.S. Army sergeant deployed in Afghanistan. He requests assistance transferring 15kg (33.069 lbs.) of gold bars and $1 million cash in exchange for a reward.  

Online shopping scams


Here, scammers pose as legitimate online sellers using fake websites or even deceptive ads on real retail platforms. Promising huge discounts or too-good-to-be-true deals, they trick shoppers into purchasing fake or nonexistent products. Some scams also target personal information and banking details.

Before paying, look for independent reviews, clear contact details and a credible return policy. Be cautious when a new store asks for an unusual payment method, pressures you to act quickly, or offers a price far below those of comparable sellers.


Description: Cheap bags commonly available on Chinese online marketplaces presented as premium handmade products offered on sale.
Description: Cheap bags commonly available on Chinese online marketplaces presented as premium handmade products offered on sale.


Marketplace scams


These schemes often rely on advance-fee fraud, charging users up front for nonexistent goods and services. Making matters worse, bots and toolkits are available on the dark web, helping scammers create fake item listings, phishing websites, fake payment gateways, text message notifications, and even translate chats with victim in real time - essentially giving them the tools to scale up their scam campaigns.


Job and money-mule scams can use similar marketplace-style tactics. A legitimate employer will not ask a new hire to move money, forward goods, pay for equipment through a questionable link, or use a personal account to receive customer payments.


Description: Interface of Telekopye bot used to run marketplace scams—scammer can generate phishing pages, payment gateways, delivery notifications and send the links to victims with only a few clicks.





Investment Scams


Investment scams can take many forms - venture businesses, cryptocurrencies, nonexistent financial products or properties, etc. - but the underlying characteristic is the same. Despite investment opportunities promising breathtaking returns, victims end up with empty pockets. Sometimes, they are encouraged to make financial contributions over a long period of time, resulting in even bigger losses. Investment scams are among the most widespread, misusing social media platforms, deepfakes of well-known personalities, fake reviews, and ads abusing brand logos to appear more trustworthy. 



Description: Examples of cryptocurrency-themed scam websites seen in ESET phishing feeds.





Fake lottery scams 


In this type of fraud, scammers pose as lottery officials, claiming you’ve won a prize. To collect it, you’re asked to pay fees, taxes, or share personal info - often leading to fraud or identity theft.




Description: 

A fake lottery win notification that uses the 2022 World Cup as bait. The scam requests a variety of personal information. To receive the “ATM card,” the victim is instructed to contact an agent, who then requests an advance fee before the winnings can be claimed.


Impersonation scams, including business email compromise


Impersonation scams exploit trust in a familiar person or organization. A scammer may pose as an employer, colleague, family member, financial institution or service provider and demand an urgent payment, confidential information, or request a change in payment instructions. Business email compromise (BEC) is the workplace version of this tactic.


With AI and deepfake technology now being increasingly used in audio, video, and live calls, these scammers are becoming even more convincing. In one case reported by Hong Kong police, scammers used a deepfake conference call to trick an employee of an international firm into transferring $25 million.


If an unexpected request involves money, codes or sensitive information, verify it with the person or organization through a known, independent contact method - even if the message or call seems familiar.



Tech support scam


Scammers pose as tech support agents from trusted companies, claiming there is a technical problem with your device. To “help,” they request remote access, which they then use to steal data, install malware, or carry out other malicious activities. They may also ask for payment for these fake services.


Description: A fake security alert manipulating the targeted user to call fake technical support. 
Description: A fake security alert manipulating the targeted user to call fake technical support. 

Delivery scams 


Common during peak shopping seasons, these scams involve fake messages about package delivery issues. Victims are tricked into sharing personal information, installing malicious apps, or paying bogus fees to “resolve the problem”.


Verify the delivery status through the retailer’s or carrier’s official app or website rather than using a link in the message. Unexpected delivery fees and requests to install an app are warning signs.


Description: Delivery scam email reported by ESET telemetry. It claims that the delivery attempt has failed and requests shipping address verification.
Description: Delivery scam email reported by ESET telemetry. It claims that the delivery attempt has failed and requests shipping address verification.


Romance scam


Scammers pose as potential romantic partners, building trust over time before asking for money to handle fake emergencies like medical bills, blocked bank accounts, or threats from criminals.

With deepfake technology, these scams can become even more convincing, for example, by generating a realistic video of Brad Pitt professing his love for your grandmother. Another variation of this scam involves impersonating family members in need.


Description: Romance scams can start with a seemingly innocent "wrong number" message.
Description: Romance scams can start with a seemingly innocent "wrong number" message.

Sextortion and fake sextortion scams


Sextortion occurs when someone is tricked into sharing private images and then blackmailed with the threat of their release. In fake sextortion scams, attackers claim to have such material - even when they don’t - and demand payment, often in cryptocurrency. These scams may use deepfakes or mass spam campaigns, falsely accusing victims of engaging in illegal activity or viewing inappropriate or embarrassing pornographic content, then threatening to expose them unless they pay.


Description: This sextortion email utilizes the hype around Pegasus spyware.    
Description: This sextortion email utilizes the hype around Pegasus spyware.    

Snakeoil scams


These scams offer fake or nonexistent drugs or medical devices, promising miraculous health benefits. They spread through social media, malicious ads, chats, text messages, and forums, often mimicking ads of trusted brands such as Viagra or Ozempic. A popular variation involves noninvasive glucose monitors, even though the technology is still in its infancy.


Description: A fake ad for a noninvasive glucose monitoring device, despite there being no such solution on the market. 
Description: A fake ad for a noninvasive glucose monitoring device, despite there being no such solution on the market. 


These scams often target victims of other scams. Cybercriminals pose as law enforcement agents or legal professionals, reaching out to victims through calls, text messages, or chats, or targeting them with malicious ads, and offering help for a fee.


They may promise to recover lost funds, provide legal advice, offer consultations, or enroll victims in fake class-action lawsuits. Scammers often pose as representatives of Europol or Interpol, or as lawyers from fictitious firms, to appear legitimate. No legitimate authority will guarantee the recovery of lost money in exchange for an upfront fee. Be especially wary of anyone who contacts you unexpectedly after a scam and promises to recover your money quickly.


Description: Examples of fraudulent ads as listed in the Meta Ad Library. These now-inactive ads were detected by ESET engine as HTML/Nomani and described in detail in the ESET H2 2024 Threat Report. Ironically, they targeted people who were previously scammed.
Description: Examples of fraudulent ads as listed in the Meta Ad Library. These now-inactive ads were detected by ESET engine as HTML/Nomani and described in detail in the ESET H2 2024 Threat Report. Ironically, they targeted people who were previously scammed.

Description: Fraudulent EUROPOL webpage promising the recovery of money lost to scammers. 
Description: Fraudulent EUROPOL webpage promising the recovery of money lost to scammers. 

AI scams


AI scams are traditional fraudulent schemes like phishing, tech support scams or sextortion that use artificial intelligence to make the deception more convincing, scalable, and difficult to detect. Cybercriminals use AI to generate realistic emails, clone voices, create deepfake videos, build professional-looking fake websites, and automate conversations with victims through chatbots. 


How to avoid scams - and what to do if you fall for one


Scams come in many forms, so there is no single check that can detect them all. The safest response is to slow down and verify independently before acting, and act quickly if you think you have already shared information, sent money, or installed something.


If you think you have been scammed


  1. End all contact and do not send any more money. Do not reply, click any further links, or grant remote access.

  2. Contact the payment provider immediately. Call your bank, card issuer, payment app provider or crypto exchange using their respective official contact channels; ask whether the transaction can be stopped or reversed and what steps you need to take to secure your account.

  3. Secure exposed accounts. Change passwords from a trusted device, sign out of other sessions and turn on multi-factor authentication. If you used the same password for other accounts, change it on those accounts as well.

  4. Scan and update the device. Remove any unknown apps or unfamiliar remote access tools, update the operating system and browser, and run a security scan.

  5. Perform a factory reset. If nothing else works, a factory reset can remove malware from your phone. Before doing so, back up any important data, as the reset will erase your personal information from the device. Be careful when restoring data afterward, as you could reinstall malware if it was included in the backup.

  6. Preserve evidence and report the scam. Save messages, URLs, receipts and account details. Report the scam to the impersonated platform and the appropriate local fraud or cybercrime authority.

  7. Watch for recovery scams. A second scammer may claim that they can recover your money for a fee.


Be skeptical: Be cautious about unsolicited messages and offers. Don’t click on links or provide personal data just because you are told to act quickly. If an offer, discount, or prize seems too good to be true, it probably is.


Verify sources: Always double-check the legitimacy of messages or offers. Look closely at email addresses, URLs, domain names, and product reviews. If in doubt, contact the company directly using contact information listed on its official website.


Instantly check any URL for malware, phishing, fraud, or scams. Protect yourself from malicious websites with ESET’s free, easy-to-use link checker.

Use strong passwords: Create strong passwords and use unique passwords for each account; free ESET free Password Generator can help. Use a password manager to keep track of your passwords and to avoid password fatigue.


Enable Multi-Factor Authentication (MFA): Wherever possible, add an extra layer of security to your accounts with MFA.


Use a reliable cybersecurity solution: The right security solution can stop scams at multiple stages—by filtering spam, blocking phishing messages and websites, and securing payment processes.

Protect your Android smartphone with ESET Mobile Security, or protect the entire household with an ESET HOME Security plan that fits your needs.



Update your software: Regularly update your operating system, browser, and security software to protect against vulnerabilities.


Educate yourself: Stay informed about common scams and how they work - knowledge is your best defense.


Stay alert, act early

Scams keep changing, but the core defenses stay practical: pause, verify independently, and ask for help before you act. If you have already acted, contact the appropriate provider quickly, secure your accounts, and preserve the evidence. Knowing the warning signs makes it harder for scammers to pressure you into a decision.

 
 
 

Comments


bottom of page