Skip to Main Content
Online Scams

How to tell if an online scam is real - 15 warning signs

Four of these signs settle it on their own. The other eleven only matter when they stack up. Knowing which is which is what lets you judge a message, a call, a shop or an offer without knowing anything about the particular scam.

Subash Poudel10 min read

The short answer

  1. Four signs are decisive on their own - a demand for gift cards or crypto, a request for a one-time code, being told to move money to a safe account, and remote access after unsolicited contact.
  2. The other eleven signs are cumulative. One is worth noticing, three together mean stop.
  3. Check the payment method before you evaluate the story. Scammers choose payment routes that cannot be reversed.
  4. Spelling, logos, caller ID and a familiar voice have all stopped being reliable signals, and treating them as proof is now the risk.
  5. When you are unsure, the answer is never to judge harder. Contact the organisation on a number or address you found yourself.

Most scam checklists have the same problem. They give you fifteen things to look for and treat them all as equal. So a slightly odd greeting sits next to a demand for gift cards, as though the two carried the same weight.

They do not. Four of the signs below settle the question on their own. The other eleven are only meaningful when several turn up together.

The four that decide it on their own

If any one of these appears, you are looking at a scam. You do not need to work out which part of the story was false, and you do not need to be sure about anything else on the page.

1. You are told to pay by gift card, cryptocurrency, wire transfer or a payment app

This is the single most reliable sign there is, and it is reliable because it is structural. These payment routes are chosen for one property: once the money moves, it is very hard to get back.

The FTC's wording on gift cards leaves no room at all — "Gift cards are for gifts. Only gifts. Not for payments." On cryptocurrency it is equally flat: "Only scammers demand payment in cryptocurrency."

The FBI's 2025 data shows the same pattern from the other end. Cryptocurrency accounted for 86% of the transactions in reported investment fraud.

2. Someone asks you for a one-time code

The six-digit code your bank or email provider texts you exists to prove you are signing in. There is no legitimate reason for another person to want it.

The FTC states it as a rule with no exceptions: "Anyone who asks you for your account verification code is a scammer." If a caller asks you to read one out, the conversation is over regardless of how much they already know about you.

3. You are told to move money to a safe account

No bank has such a procedure. Banks freeze accounts and block cards. They do not ask customers to transfer their balance somewhere for protection.

The FBI has warned about a version that runs in three stages. First a fake tech-support call, then a fake bank, then a fake government official. The money always ends up somewhere "safe" that belongs to the criminals.

4. You are asked to install remote-access software after unsolicited contact

The software itself is real and legitimate help desks use it daily. That is what makes the request plausible.

The rule is about who started the conversation. Installing it because you rang a support line you looked up is normal. Installing it because someone contacted you about a problem you had not noticed is how tech support scams work. The FTC is direct about the premise: legitimate tech companies will not contact you to say there is a problem with your computer, and real security warnings never ask you to ring a number.

The eleven that count when they stack up

None of these is proof by itself. Plenty of honest messages contain one. Three together is a different matter.

5. The contact was unexpected

You did not start it. The message, call, advert, friend request or job offer arrived on its own.

This is where almost every scam begins, and it is why so much official advice starts here. The FTC's first sign is that scammers pretend to be from an organisation you know. The NCSC calls the same thing "Authority" — a message claiming to be from your bank, your doctor, a solicitor or a government department.

6. There is a problem, or there is a prize

The FTC's second sign. Either something is wrong that you must fix, or something good has happened that you must claim. Both create a reason to act, and both require you to do something before you have checked anything.

7. You are being hurried

The FTC's third sign, and the one the FBI built an entire campaign around. Its advice is to "Take a Beat" — "resist pressure to act quickly, pause for a moment, and assess the situation."

The UK banking campaign Take Five is blunter: "Only criminals will try to rush or panic you."

Genuine deadlines exist, but they behave differently. A real one is written down somewhere you can find yourself, is measured in days rather than minutes, and survives you hanging up and ringing back. That last property is the test. See urgency manipulation for why the pressure is there at all.

8. You are asked for information nobody should need

The FTC's line is worth keeping: "Honest organizations won't call, email, or text to ask for your personal information, like your Social Security, bank account, or credit card numbers."

A full card number, a full password, a national insurance or Social Security number, or the answers to your security questions — an organisation that already has a relationship with you does not need any of them from an unexpected message.

9. You are told to keep it secret

Watch for any reason not to tell your bank, your family or a colleague. FINRA puts it in its investment red flags: be extremely sceptical if a salesperson tells you not to tell anyone else.

Secrecy has no legitimate function here. It exists to remove the one thing that most reliably stops a scam, which is another person's reaction.

10. The returns are guaranteed

"Only scammers will guarantee profits or big returns," says the FTC, "nobody can make those guarantees." FINRA's version is to be suspicious of anyone who guarantees a certain performance or promises a lofty return, and of an investment that goes up month after month without variation.

Investment fraud is the largest single source of losses in both US datasets, so this sign is worth more than its position on the list suggests. See investment scams.

11. They already know things about you

This one is counter-intuitive, because knowing your details feels like proof.

The FTC warns that government impersonators "might have information about you, like your name or home address," and may give an employee ID number to sound official. Scamwatch lists unexpected contact from organisations that have had a data breach as a red flag in its own right.

Personal details circulate from breaches and are sold by data brokers. Someone knowing them is evidence they bought a list, not evidence they work where they say they do.

12. The address or domain is nearly right

CISA describes the technique plainly: attackers use an address "that closely resembles one from a reputable company by altering or omitting a few characters", and a malicious site "may look identical to a legitimate site, but the URL may use a variation in spelling or a different domain (e.g., .com vs. .net)."

Read what sits immediately before the first single slash. That is the real domain. Anything in front of it was chosen freely by whoever registered it.

Hovering a link on a computer shows its true destination. On a phone, press and hold for a preview rather than tapping. CISA's guidance is that if the links do not match the text shown when hovering, the link may be spoofed.

A shortened link is not automatically bad, but it hides the destination, which means the check cannot be run. In an unexpected message that is reason enough to stop. The same applies to a QR code.

14. You are moved to another channel

Watch for a push to continue somewhere else — an encrypted messaging app, a personal number, a chat off the marketplace or dating site you started on.

Scamwatch lists moving communication to encrypted messaging apps among its red flags. The motive is consistent across scam types: platforms have reporting tools, buyer protection and moderation, and none of those follow you off the platform.

15. The offer only makes sense if you do not look

A price far below every other retailer. A job with a good salary, no interview and no specifics. A rental below market rate from a landlord who cannot show you round. A profile whose photos do not match the person's story.

Almost 30% of people who reported losing money to a scam in 2025 said it started on social media, with $2.1 billion in reported losses. Adverts get in front of you while you are scrolling rather than while you are shopping, which is exactly when this check does not get run.

What has stopped being a warning sign

This section matters as much as the list. Several signals people were taught to rely on have expired, and treating them as proof is now the risk.

Old signalWhy it no longer works
Bad spelling and grammarFluent scam text is standard. Poor spelling still suggests a scam; good spelling suggests nothing
A convincing logo or designThe FTC notes phishing messages use the real company's logo. Copying a website is free
The caller ID shows the real number"Caller ID can be faked", says the FTC. The number displayed is supplied by the caller
It is a familiar voiceThe FBI describes criminals generating short audio clips of a loved one's voice from recordings
They appeared on videoReal-time deepfakes are used in video calls. See AI scams
The site has good reviewsReviews hosted on the seller's own site are content the seller wrote
It came from a friend's accountCompromised accounts are used to message the people who trust them

The FBI's 2025 report recorded 22,364 complaints mentioning artificial intelligence, with roughly $893 million in reported losses, and named voice clones and believable video of public figures and loved ones among the tools. The point is not that everything is fake. It is that looking right has stopped being evidence.

The check that settles it

When the signs are mixed and you genuinely cannot tell, the answer is not to analyse harder. A well-built scam is designed to survive analysis. The answer is to step outside the conversation.

  1. Stop. Do not reply, click, pay or install while you decide.
  2. Verify on a channel you chose. Ring the number on the back of your card, or type the organisation's address into your browser. Never use a number, link or address that came with the message.
  3. Search the name plus "scam" or "complaint" and read the results that are not on the company's own site. This is the FTC's own first recommendation for online shopping.
  4. Tell one other person. The FTC lists this as a step: "Before you do anything else, tell someone — a friend, a family member, a neighbor — what happened."

How big the problem actually is

~$16bnreported lost to fraud in the US in 2025, the highest on recordFTC, June 2026
1,008,597complaints to the FBI's IC3 in 2025, with $20.9bn in reported lossesFBI IC3, 2025 Internet Crime Report
£1.28bnstolen through payment fraud in the UK in 2025UK Finance, Annual Fraud Report 2026

The figures come from different reporting systems and cannot be added together, but they agree on direction. US reported fraud losses rose about 25% in a year. UK payment fraud rose 4%, with authorised push payment losses up 19% to £576.4 million — and 66% of that starting online. Australia recorded AUD $2.18 billion in reported losses, up 7.8%.

The reassuring part is in the composition. A small number of patterns account for most of the money, and they reuse the same handful of signs. That is what makes a general framework worth learning at all.

Where to go next

The signs above work across categories. Each of these explains how one category puts them together:

And if you have already replied, paid or handed something over, work through I gave a scammer my password or I clicked a phishing link depending on what happened — then report it, which sets out the order to do things in and what each agency does with the report.

Test the signs under pressure

Reading a list and applying it mid-conversation are different skills. Our drills put you inside real scam scenarios and ask you to call it.

Try it free

Frequently asked questions

How can I tell if an online scam is real?
Start with how you are being asked to pay and what you are being asked to hand over, not with how convincing the story is. Any demand for gift cards, cryptocurrency, a wire transfer or a payment app to someone you have not met is fraud in essentially every case. So is any request for a one-time code. If neither applies, look for a stack of softer signs - unexpected contact, pressure, secrecy, a payment route with no recourse - and verify through a channel you chose yourself.
What are the four signs of a scam?
The FTC puts it in four words. Scammers pretend to be from an organisation you know, they say there is a problem or a prize, they pressure you to act immediately, and they tell you to pay in a specific way. Almost every scam of every type contains at least three of the four, which is what makes it a useful test across scams you have never seen before.
Is bad spelling still a sign of a scam?
No, and relying on it now works against you. Fluent, well-written scam messages are standard, and the FBI's 2025 report describes criminals using fake profiles, voice clones, identification documents and believable video of public figures or loved ones. Poor spelling still suggests a scam. Good spelling no longer suggests anything at all.
They knew my name and address. Does that mean they are real?
No, and it slightly increases the odds that they are not. The FTC warns that government impersonators may already have information about you like your name or home address, and may quote an employee ID number to sound official. Personal details are widely available from breaches and data brokers, so knowing them is evidence of a purchase, not of legitimacy.
How do I check whether an online shop is genuine?
Search the shop's name plus the word scam or complaint and read the results that are not on the shop's own site. Look for a real company name, a postal address and a working phone number. Read the domain carefully, since lookalike spellings are the norm. Ignore reviews hosted on the site itself. Then pay by credit card, which the FTC says best protects you if something goes wrong.
What should I do if I am still not sure?
Stop and verify independently. Hang up and call the number on the back of your card, or type the organisation's address into your browser yourself. Then tell one other person what happened before you act - the FTC lists talking to someone you trust as a step in its own right, because saying it out loud is often when it stops sounding plausible.
Do scams always involve urgency?
Not always, but pressure is the most common single feature and it is the one both the FBI and UK banks built their advice around. The FBI asks people to Take a Beat and resist pressure to act quickly. Take Five puts it more bluntly - only criminals will try to rush or panic you. Long-running romance and investment scams are the exception, and they replace urgency with patience.

Sources

  1. How To Avoid a Scam Federal Trade Commission, 2023
  2. FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025 Federal Trade Commission, 2026
  3. New FTC Data Show People Have Lost Billions to Social Media Scams Federal Trade Commission, 2026
  4. 2025 Internet Crime Report FBI Internet Crime Complaint Center (IC3), 2026
  5. Cryptocurrency and AI Scams Bilk Americans of Billions Federal Bureau of Investigation, 2026
  6. FBI Announces Nationwide Take A Beat Campaign to Increase Awareness of Frauds and Scams Federal Bureau of Investigation, 2024
  7. Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud FBI Internet Crime Complaint Center (IC3), 2024
  8. Phantom Hacker Scams FBI Internet Crime Complaint Center (IC3), 2023
  9. How to spot a scam email, text message or call UK National Cyber Security Centre, 2022
  10. Take Five to Stop Fraud UK Finance, 2026
  11. Annual Fraud Report 2026 UK Finance, 2026
  12. Avoiding and Reporting Gift Card Scams Federal Trade Commission, 2023
  13. What To Know About Cryptocurrency and Scams Federal Trade Commission, 2022
  14. How To Avoid a Government Impersonation Scam Federal Trade Commission, 2023
  15. Online Shopping Federal Trade Commission, 2023
  16. Avoiding Social Engineering and Phishing Attacks Cybersecurity and Infrastructure Security Agency, 2021
  17. Watch for Red Flags FINRA, 2026
  18. Help to spot and avoid scams ACCC Scamwatch, 2026
  19. Continued action critical to combat fraud as annual scam losses exceed $2 billion Australian Competition and Consumer Commission, 2026

About the author

Subash Poudel

Cybersecurity & Digital Literacy

Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.

  • Founder and engineer, SafeSurf IQ
  • Writes and reviews the platform's phishing, scam and privacy curriculum
  • Works from primary incident and fraud reporting, cited on every article

Last reviewed . Figures are checked against the primary sources listed above at each review.