Little Black Book of Scams and Frauds
Scams and frauds evolve as quickly as the technology that enables them. Whether youre a seasoned professional, a smallbusiness owner, or simply someone who checks email every day, it pays to stay informed. This guide is a concise reference a little black book that outlines the most common schemes, tells you how they work, and gives concrete steps to protect yourself.
Why a Black Book?
The term black book implies a secret, compact source of essential knowledge. In the world of fraud prevention, knowledge is the single most effective weapon. By keeping the key signs and defensive tactics at hand, you can spot a scam before it takes hold.
1. Phishing & SpearPhishing
Phishing is the broad practice of sending fraudulent messages that appear to be from a trusted source. Spearphishing narrows the focus to a specific individual, using personal details to increase credibility.
- Typical sign: Unexpected urgent request, often about money, passwords or confidential data.
- How it works: Attackers harvest email addresses from public sites or data breaches, then craft a message that mimics a legitimate brand or colleague.
- Defence: Verify the sender through a separate channel, hover over links to view the true URL, and use multifactor authentication (MFA).
2. Business Email Compromise (BEC)
In BEC attacks, cybercriminals impersonate an executive or vendor and request a wire transfer. These scams can cost companies millions.
- Red flag: A finance officer receives a lastminute email from a CEO stating urgent send funds today.
- Prevention: Enforce a policy that any change in payment details must be confirmed by a phone call to a known number.
3. Tech Support Scams
Scammers claim to be from a wellknown tech company, telling victims that their computer is infected and offering to fix it for a fee.
What to watch for: - Unsolicited popups or phone calls.
- Requests for remoteaccess software (TeamViewer, AnyDesk).
- Pressure to pay immediately.
Never grant remote access unless you initiated the session with a verified support agent.
4. Romance & Dating Scams
Scammers build emotional connections on dating platforms, then ask for money for travel, medical emergencies, or investment opportunities.
- Check profile photos with a reverseimage search.
- Never send money to someone you havent met in person.
5. Investment & Cryptocurrency Frauds
Promises of guaranteed returns, insider tips, or exclusive crypto tokens lure investors. Ponzi schemes disguise payouts as profits until the flow collapses.
- Due diligence: Verify registration with securities regulators (e.g., SEC, FCA).
- Red flag: Pressure to invest quickly or disclose little information about the business model.
6. Lottery & Prize Scams
Victims receive messages stating they have won a prize but must pay a fee or provide banking details to claim it.
- Legitimate lotteries never ask for payment upfront.
- Look for spelling errors, generic greetings, and email addresses that dont match the official domain.
7. Identity Theft
Criminals steal personal data to open credit accounts, file tax returns, or commit other fraud.
- Secure personal documents; shred them when no longer needed.
- Monitor credit reports regularly.
- Use strong, unique passwords and a password manager.
8. Charity Scams
After natural disasters or during crises, fraudsters set up fake charities to harvest donations.
- Verify charities through official registries (e.g., Charity Navigator, GuideStar).
- Donate directly via the organizations verified website, not through unsolicited links.
9. Online Marketplace Frauds
Scammers list items that dont exist, or ship counterfeit goods after receiving payment.
- Use platforms with buyer protection.
- Beware of sellers insisting on offplatform payment (e.g., wire transfer, gift cards).
10. Ransomware
Malware encrypts a victims files and demands a ransom, usually in cryptocurrency.
- Maintain regular, offline backups.
- Keep operating systems and software patched.
- Educate employees about suspicious attachments.
Quick SelfCheck Checklist
- Do you recognize the senders address?
- Is there a sense of urgency or threat?
- Are you being asked for money, credentials, or remote access?
- Can the claim be verified through an independent source?
- Is the communication grammatically flawed or oddly formatted?
What To Do If You Suspect a Scam
1. Stop the interaction. Do not click links, open attachments, or reply.
2. Verify. Contact the organization or person through a trusted channel.
3. Report. Forward phishing emails to phish@us-cert.gov, report to local lawenforcement, or use your countrys cybercrime portal.
4. Secure. Change passwords, enable MFA, and run a reputable antivirus scan.
Resources
Scammers continuously refine their tactics, but staying informed dramatically reduces the risk. Keep this Little Black Book bookmarked, share it with friends and colleagues, and revisit it whenever a new type of fraud emerges.
We use cookies to enhance your browsing experience and analyze site traffic. By clicking 'Accept all cookies', you agree to the use of these cookies. You can manage your preferences or learn more in our [Privacy Policy/Cookie Policy.