Most fraud advice consists of a list of warning signs. The trouble is that the approaches which actually succeed are designed specifically not to display them.
The shift in method
Technical attacks — stealing card details, compromising accounts — have become harder as authentication has strengthened.
Which pushed the activity toward persuading the account holder to make the payment themselves.
A payment authorised by the genuine customer, from their own device, passing every authentication check, is extremely difficult to stop technically.
This category now accounts for a large share of losses in markets that publish the breakdown.
The impersonation structure
The common pattern involves impersonating an organisation the target already trusts and has reason to hear from.
A bank's fraud department. A tax authority. A delivery company. A utility.
The approach works because the context is plausible, not because the target is careless.
Caller ID can be spoofed, message threads can be joined so that a fraudulent message appears alongside genuine ones from the same sender, and websites can be replicated exactly.
Which means the traditional advice to check these details is less useful than it once was.
Why urgency is central
Every successful approach creates time pressure.
An account under attack, a payment that must be stopped, a deadline that has passed.
The purpose is to prevent the target from stopping to verify, because verification defeats the whole thing.
Which makes urgency itself the most reliable signal, more reliable than any technical detail, and the one that generalises across every variant.
The safe account instruction
A specific pattern worth naming because it is so common.
The target is told their account is compromised and their money must be moved to a safe account.
No legitimate institution does this. There is no such thing as a safe account.
It persists because it makes emotional sense — the money is in danger, move it to safety — even though it makes no operational sense.
Purchase and investment fraud
A different structure with a longer timeline.
Goods advertised that do not exist, or investments that do not exist, where the payment is made willingly for something believed to be genuine.
Investment variants frequently run for months, with small withdrawals permitted early to establish credibility, before a larger deposit is solicited.
The professional appearance of the materials is not evidence of anything, since producing convincing materials is trivial.
Checking whether the firm is registered with the relevant regulator, on the regulator's own website rather than through a link provided, is the actual check.
Romance and long-approach fraud
The variant with the highest average loss and the lowest reporting rate, because shame suppresses reporting.
The relationship is established over months before any financial request, which makes every conventional warning sign irrelevant by the time money is discussed.
The structural feature is that a person never met in physical form eventually requires money urgently, and the reason is always compelling.
The reimbursement question
Historically, a customer who authorised a payment had limited recourse, since the payment was genuine.
Rules requiring reimbursement in defined circumstances have been introduced in several markets, generally splitting the cost between sending and receiving institutions.
Which creates an incentive for both to detect and prevent, and that incentive alignment is the point of the design.
Exceptions typically apply where the customer ignored specific warnings, and the boundary of that exception is where disputes concentrate.
The one habit worth building
Never act on a contact you did not initiate. End the interaction and make contact yourself, using a number or address obtained independently.
This defeats essentially every impersonation approach regardless of how convincing it was, and it requires no technical knowledge.
The reason it works is that the entire structure depends on maintaining the channel the fraudster controls, and hanging up breaks it.
Anyone who has lost money should report it to their bank immediately and to the relevant national reporting body, and the speed of that report materially affects the chance of recovery.
Business email compromise
The variant with the largest average loss, aimed at organisations rather than individuals.
An attacker gains access to or convincingly imitates a business email account, then intercepts or initiates correspondence about a payment.
Invoice details are altered, or a supplier's bank details are said to have changed, and the payment goes elsewhere.
The approach succeeds because the transaction was genuine and expected, so nothing about it appears unusual except the account number.
The effective control is verifying any change of bank details through a known contact by a different channel, as a fixed procedure rather than a judgement call.
Recruitment into money laundering
A related harm that people do not recognise as involving them.
Advertisements offering payment for receiving and forwarding money through a personal account are recruiting for money laundering, and participants face account closure and potential prosecution.
Young people and students are targeted disproportionately, and the framing rarely mentions what the activity actually is.