Evidence-based scam-awareness research from EverydaySecurity — definitions, comparisons, real evidence, and step-by-step guidance for the scams we investigate.
Adaptive phishing kits inspect the visiting device, location, and time before deciding how to attack — the same link can steal a password on one device and install malware on another.
Scammers are using consumer AI app-builders to stand up convincing brand-impersonation sites in hours instead of weeks, then pairing them with paid social ads to borrow the impersonated brand's trust.
Government-filing impersonation scams use a business's own public filing data — LLC registration numbers, trademark serial numbers — to send fake compliance notices that look official enough to pay.
Scam infrastructure relies on the same anonymity and evasion techniques regardless of the scam on top of it — CDN-based anonymity and bot-detection evasion are two distinct hiding techniques worth recognizing separately.
Some fake trading-platform sites aren't after your deposit at all — the platform itself is the delivery mechanism for malware that steals banking credentials and government ID.
Recruiting scams increasingly run through compromised legitimate recruiter accounts, and the follow-up messages often carry statistical tells of AI-generated text worth learning to spot.
Reverse-proxy phishing kits don't clone an exchange's frontend — they transparently proxy the real one, intercepting only credentials while every other system, including the exchange's own fraud detection, runs exactly as it would for a legitimate session.
Not everything that looks like a scam is one. This page documents how we verify before we call something a scam — including a case where we retracted an earlier call, and a false-positive detection from the technical side.
Send it to us and we'll investigate it for free — the findings help build pages like this one.