Scam Library

Search the scams behind most digital payment losses worldwide — how each one works, the warning signs, and the steps to take. No technical background needed.

Last reviewed 01 Aug 2026 · 21 case studies across 3 regions

3 of 21 case studies

Full case studies

Phishing Global Medium risk

Parcel Delivery Fee Phishing

A text says your parcel is held and asks for a tiny fee — which harvests your card details.

Who scammers target
Anyone who shops online — a large share of people are expecting a parcel
Typical reported loss
$50 – $1,500 per case
Why people fall for this
The tiny fee feels too small to be worth a scam, so people pay without checking the sender.

How it works

  1. 1You receive an SMS or email from a courier: "Your package is on hold, unpaid customs fee."
  2. 2The link opens a convincing copy of the courier's site.
  3. 3A small fee is charged to capture the full card number, expiry, CVV and a one-time code.
  4. 4Your card is then used for large purchases or added to a mobile wallet.

Real-world example

Ana pays a $1.99 "redelivery fee" on a page that looks exactly like the courier's. Two days later a $1,400 electronics purchase appears on her card.

  • You are not expecting a delivery, or the message has no real tracking number.
  • The web address is a lookalike domain with extra words or hyphens.
  • A trivial fee page asks for CVV plus a code sent by your bank.

  • Track parcels only in the courier's official app or by typing their address yourself.
  • Never enter card details on a page reached from an unexpected message.
  • If you entered details, freeze the card in your banking app immediately.
  • Report the message as phishing and forward it to your national reporting service.

What it looks like

Messages · +91 90XXX 41288
USPS: parcel on hold. Pay $1.99: usps-redelivery.help
Today · 11:42
Illustration of a fake message — recreated for teaching, not a real notice.
Phishing United States High risk

Bank Fraud Alert Text (Smishing)

A text asks you to confirm a suspicious charge — then a "fraud agent" calls to walk you through it.

Who scammers target
Everyone with a bank account — sent in bulk to millions of numbers
Typical reported loss
$300 – $8,000 per case
Why people fall for this
The message warns of fraud, so acting fast feels like the safe choice rather than the risky one.

How it works

  1. 1You get a text: "Did you authorize a $612 purchase? Reply Y or N."
  2. 2Replying N triggers a call from a spoofed bank number.
  3. 3The "fraud agent" already knows your name and last four digits, which builds trust.
  4. 4They ask for the one-time code, or tell you to transfer money to a "secure account" — often via Zelle to yourself.

Real-world example

Jordan replies N to a Chase fraud alert. The agent who calls sounds professional and asks him to read a code to cancel the charge. That code authorises a $3,000 transfer out of his account.

  • The bank asks you for a one-time code — real banks never do.
  • Instructions to send money to yourself to "reverse" fraud.
  • The caller creates a countdown: act now or lose the money.

  • Do not reply to the text. Open your banking app or call the number on your card.
  • Never read out a verification code, even to a caller claiming to be your bank.
  • Sending money to yourself is never how fraud gets reversed.
  • Forward the text to 7726 (SPAM) and report at reportfraud.ftc.gov.

What it looks like

Messages · +91 90XXX 41288
FreeMsg: Did you authorize $612.00 at BESTBUY? Reply N
Today · 11:42
Illustration of a fake message — recreated for teaching, not a real notice.
Phishing India High risk

KYC Phishing Link

An SMS says your account will be blocked unless you re-do KYC on a fake bank page.

Who scammers target
Bank and wallet customers, sent in bulk by SMS and email
Typical reported loss
$200 – $5,000 per case
Why people fall for this
Verification requests are a real part of banking, so a deadline to complete one feels ordinary.

How it works

  1. 1You receive an SMS or WhatsApp message warning your account will be suspended today.
  2. 2The link opens a page that looks exactly like your bank's website.
  3. 3It asks for your card number, CVV, PIN and the OTP — all on one screen.
  4. 4The fraudster uses those details to empty the account within minutes.

Real-world example

Arjun gets an SMS: "Dear customer, your KYC expires today. Update now: bit.ly/kyc-verify". The page carries his bank's logo. He fills in his card details and shares the OTP. ₹62,000 is transferred in three transactions before he realises.

  • The web address isn't the bank's official domain (extra words, hyphens, or a shortened link).
  • One form asks for PIN, CVV and OTP together — real banks never do this.
  • The sender is a 10-digit mobile number instead of the bank's registered SMS header.

  • Never open KYC links from SMS or WhatsApp. Type the bank's address yourself or use its app.
  • Never share OTP, CVV or PIN with anyone, including "bank staff".
  • If you clicked, change your net-banking password and block your card from the app.
  • Report the message as spam and forward it to your bank's official fraud channel.

What it looks like

Messages · +91 90XXX 41288
Your KYC expires TODAY. Update: bit.ly/kyc-verify
Today · 11:42
Illustration of a fake message — recreated for teaching, not a real notice.

Where to report, by country

Already lost money? Report it immediately — the first few hours give the best chance of freezing the funds.

Think you can spot these in the wild?

Take the quiz