How Scams Work
Most scams are not about breaking a computer. They are about getting a person to click, install, sign in, send money or approve something. The story changes. The pattern does not.
You don't need to memorise dozens of scam names. Learn the four steps, then you can recognise new versions as they appear.
Scams usually work in two ways: they are either generic messages sent to everyone, or highly targeted attacks that use your leaked personal info to trick you.
The four steps
1. The Lure → 2. The Trap → 3. The Action → 4. The Loss
1. The lure
Something is built to get your attention. It usually uses impersonation plus pressure.
They pretend to be someone you already trust: a bank, HMRC, PayPal, Amazon, Microsoft, a delivery firm, a wallet company, or even your workplace.
Then they add urgency, fear, greed, curiosity or familiarity:
-
“Your account has been compromised”
-
“Payment overdue - act now”
-
“Your parcel could not be delivered”
-
“You have won a prize”
-
“Hi Dad, new number”
-
"We will leak your browsing history to your contacts"
-
a free token or NFT sitting in a wallet
A note on AI
Poor spelling is no longer a reliable warning. Many scam emails and messages are now written in clear, natural language. Judge the request, not the grammar.
2. The trap
It's designed to make you click before you think. The lure sends you somewhere that's not what it appears to be: a look-alike website, a cloned login page, a QR code, a chat thread, a phone call, or a fake app or browser extension.
The trap is there to collect details, push a malicious download, or get you ready to approve a payment.
Do not use the link, number or QR code in an unexpected message. Open the official app or type the address yourself. Do not use sponsored search results - fake sites often sit at the top with almost the same name. Check the full web address.
Hovering to read where a link goes is useful. Clicking it is the risk. Do not open unexpected attachments.
3. The action
This is the moment that matters. You are asked to click, sign in, install something, share a code, type a recovery phrase, send money, or approve a wallet request.
Nothing has been “hacked” yet. The attacker needs you to do this part.
4. The loss
Once that action is taken, money can move, an account can be taken over, or a wallet approval can drain funds. After that, recovery is often difficult.
How this shows up in everyday life
Emails
Deceptive emails try to make you act before you think.
-
The urgent alert: An email claims your account is locked, a delivery failed, or a tax refund is waiting. The danger is not opening the email; the danger is clicking the link inside.
-
The helpful sender: The email may look exactly like it comes from a real company, a coworker, or a friend. Scammers use familiar names and logos to make you trust a link or attachment.
-
The unexpected attachment: A receipt or invoice you do not recognize is sent to confuse you. Opening the document or enabling files inside it installs software you do not want.
-
The prize notification: You receive a message claiming you won a lottery or a gift. The trap is scanning the QR code or clicking the link to claim it, which hands over your personal details.
Phone calls
If your number has been leaked, calls and texts often follow.
-
A ring, then hang-up - checking the number is live
-
They use your name, then hang up - checking their data
-
They use your name, then pitch an investment, refund or “problem” with an account
Voice cloning
A short clip of someone’s voice from a video, voicemail or social post can be used to make a call that sounds like a family member in distress. If you get an unexpected call like that, hang up. Call that person back on a number you already have. Do not trust the number that rang you.
Text messages
Common examples include a “new number” from a relative, a failed delivery link, or a prize. Treat unexpected texts the same way as unexpected emails.
Digital wallets
The same four steps apply. The lure may be a free drop, a fake support chat, or an unknown token in the wallet. The trap is often a clone site or a malicious approval. Receiving an unexpected token is not the danger. Interacting with it can be.
How to break the pattern
-
Slow down when something feels urgent. That feeling is the signal to pause.
-
Do not use links, phone numbers or QR codes from unexpected messages.
-
Go to the official app or website yourself.
-
Never type a seed phrase or private key into a website, pop-up, email or chat. No genuine bank, exchange or support team will ask for it.
-
Use strong, unique passwords and extra sign-in protection. Prefer an authenticator app over codes sent by text.
-
Install apps and extensions only from the official source, and check the permissions.
-
If a wallet prompt asks for unlimited access to your tokens, deny it and close the tab.
When in doubt, do nothing. A genuine organisation will not punish you for pausing to check.
If you've already been targeted
Reporting still helps even if you lost nothing. Official routes for the UK, US and Europe are listed on the Stay Safe page.
Next
See a specific tactic → Threat directory
About to click, install or send → Check first and DYOR
Back to Stay Safe
