# How the Scam Works — full corpus Source: https://howthescamworks.org/ Generated: 2026-08-06 --- ## Celebrity Crypto Giveaway Deepfake: How It Works URL: https://howthescamworks.org/how/celebrity-deepfake-giveaway/ Lure: Celebrity impersonation Published: 2026-08-05 ANSWER: The livestream is real, the channel is stolen and the face was never filmed. Scammers hijack a large YouTube channel, rebrand it as a company, and loop an AI-generated celebrity offering to double any crypto you send. Nothing comes back, and crypto transfers cannot be reversed. KEY FACT: 22,364 complaints, adjusted losses over $893,346,472 — Complaints to the FBI in 2025 that referenced AI-related information (source: FBI Internet Crime Complaint Center, 2025 Annual Report) KEY FACT: over $632 million — Investment-fraud losses in 2025 with a declared AI nexus, inside a category totalling over $8 billion (source: FBI Internet Crime Complaint Center, 2025 Annual Report) KEY FACT: $3.5 billion — Reported losses to imposter scams in 2025, against a record total of about $16 billion in reported fraud (source: Federal Trade Commission, June 2026) KEY FACT: more than $118,000 — Bitcoin taken in hours in the July 2020 takeover of verified accounts, before deepfakes were involved (source: New York State Department of Financial Services, Twitter Investigation Report) KEY FACT: about 12.5 million — Subscribers on the largest hijacked YouTube channel tracked in a stream-jacking study, with the top ten totalling about 62.9 million (source: Bitdefender Labs, Stream-Jacking 2.0) KEY FACT: more than $690,000 — Transferred by an 82-year-old retiree who opened an account with $248 after watching a deepfake endorsement (source: The New York Times, 14 August 2024) KEY FACT: $9.96 — Shipping fee charged by ads using a cloned voice and image to offer 3,000 free cookware sets, which harvested cards and enrolled hidden monthly charges (source: The New York Times, 9 January 2024) KEY FACT: more than 700,000 — Advertiser accounts Google permanently suspended for AI impersonation scams, with reports of that ad type down 90% (source: Google, 2024 Ads Safety Report) KEY FACT: nearly 500,000 — Public figures covered by Meta's facial-recognition protection against celeb-bait ads (source: Meta Newsroom, October 2024) KEY FACT: $40 billion — Projected annual cost of generative-AI-enabled fraud in the United States by 2027, from $12.3 billion in 2023 (source: Deloitte Center for Financial Services, projection, May 2024) The livestream is real, the channel is stolen and the face was never filmed. Scammers hijack a large YouTube channel, rebrand it as a company, and loop an AI-generated celebrity offering to double any crypto you send. Nothing comes back, and crypto transfers cannot be reversed. Every public figure named on this page is named only as a documented victim of impersonation, in cases reported by named sources. None of them ran a giveaway. How it works - The stage is stolen, not built. Bitdefender documented the supply chain: malware steals session tokens and cookies from a channel owner, and the channel is then renamed, re-avatared and re-bannered as a company, with every original video hidden. The largest channel it tracked held about 12.5 million subscribers, and the top ten together held about 62.9 million. - The verified badge stays. So does the subscriber count, the account age and the history. You are not being shown a new channel that looks trustworthy. You are being shown a trustworthy channel that has changed hands. - The room is arranged so nobody can speak. Live chat is disabled. A QR code sits on screen. A countdown implies the offer expires. Bitdefender also tracked waves of these streams timed to real news events, because a big story makes an unscheduled corporate livestream feel plausible. - The face is assembled from real footage. The New York Times documented the method in August 2024: a genuine interview is re-cut, the voice is replaced with an AI replica, and the mouth movements are adjusted to fit the new script. Thousands of these videos were in circulation. - Door two is the endorsement funnel, and it is the expensive one. The deepfake is an advertisement, not the destination. It leads to a professional-looking investment platform. A small deposit performs well. The dashboard climbs. The withdrawal does not arrive, and a fee is required to release it. The Times documented an 82-year-old retiree who opened an account with $248 and transferred more than $690,000 of his retirement over the following weeks. - Door three is retail. In January 2024 the Times reported ads using a cloned voice and image to offer 3,000 free cookware sets, funnelled to pages imitating a television network, with a $9.96 shipping fee that harvested card details and enrolled victims in hidden monthly charges. The brand told the paper there was no partnership. The fee was never the point. - The formula predates the technology. In July 2020, attackers took over verified accounts belonging to public figures and posted a plain offer to double bitcoin. New York’s financial regulator recorded more than $118,000 taken in a few hours, with real accounts and no forgery at all. AI did not invent this scam. It industrialised the only part that used to be hard, which was the face. Key facts - The FBI logged 22,364 complaints referencing AI-related information in 2025, with adjusted losses over $893,346,472. Investment fraud with a declared AI nexus exceeded $632 million, inside an investment category of over $8 billion across 72,984 complaints. The report describes the mechanic directly: “Investment clubs employ AI-generated videos and voices of celebrities, CEOs, or trusted figures to create fraudulent, high-stakes opportunities” (IC3 2025 Annual Report). - The FTC reported $3.5 billion lost to imposter scams in 2025, against a record of about $16 billion in total reported fraud (FTC, June 2026). - Wallets monitored during one stream-jacking campaign received 10 or more ETH and 12 or more BTC, roughly $528,200 to $600,500 (Bitdefender Labs). - Google says it built a team of over 100 experts against deepfake ads and permanently suspended more than 700,000 advertiser accounts for AI impersonation, with reports of that ad type falling 90% (Google 2024 Ads Safety Report). - Meta says its facial-recognition defence against celeb-bait now protects nearly 500,000 public figures, and that user reports of celeb-bait fell 22% in the first half of 2025 (Meta Newsroom). - The FTC’s own words when it proposed extending its impersonation rule to individuals: “Emerging technology – including AI-generated deepfakes – threatens to turbocharge this scourge” (FTC, February 2024). - Deloitte projects that generative-AI-enabled fraud in the United States could reach $40 billion a year by 2027, up from $12.3 billion in 2023 (Deloitte). The defences got better. The forgeries got cheaper. Cheap wins on volume. How to spot it Four questions, in this order. - Does the promise do your arithmetic for you? Send one, receive two. Double your deposit. No market pays a fixed multiple for showing up, and no company gives money to strangers as a marketing exercise. - Check the stage, not the face. This is the twenty-second test that ends the scam. Leave the stream. Search for the company’s official channel or website yourself, without using any link, QR code or handle from the page you were on. If the announcement is real, it will exist there too. It never does. - Look for the tells the FBI actually publishes: distorted hands or feet, unrealistic teeth or eyes, inaccurate shadows, watermarks, lag time, voice matching and unrealistic movements (FBI PSA, December 2024). Treat this as the weakest of the four checks, because it is the one that improves against you every month. For the record, the narration of the documentary on this page is an AI voice clone made with consent. Your ears alone are no longer enough. - The rail is the confession. The FBI’s rule is unconditional: “Do not send money, gift cards, cryptocurrency, or other assets to people you do not know or have met only online or over the phone.” Two structural signs are worth memorising, because they survive any improvement in the forgery: live chat disabled on a channel that has always allowed it, and a QR code as the only way to act. What to do if it already happened - Send nothing more, including any release fee, verification deposit or tax on a balance you can see but cannot move. - Collect the evidence before it disappears. Wallet addresses, transaction hashes, the channel URL and handle, the platform’s URL, screenshots of the dashboard and every message. - Report to the FBI at ic3.gov with those addresses and hashes, and to the FTC at reportfraud.ftc.gov. Blockchain tracing is what forfeiture cases are built on, and those cases start with reports. - If a card was involved, dispute the charge with your issuer and watch for small recurring debits rather than a single large one. - If you gave identity documents, work through identitytheft.gov. - Report the channel or the ad to the platform. Takedowns are slow individually and fast at scale, and the report is the only input you control. - Ignore anyone who offers to recover it for a fee. People who have lost crypto once are a marketing list. Watch the full documentary The stolen channel, the endorsement funnel and the four questions are in the documentary: Don’t Fall for the AI Celebrity Giveaway. FAQ Is the Elon Musk bitcoin giveaway livestream real? No. He is named here only as a documented victim of impersonation. The New York Times reported in August 2024 that scammers edited real interview footage, replaced the voice with an AI replica and adjusted the mouth movements, and that thousands of such videos were circulating. The channel had a verified badge and millions of subscribers. How can it be fake? The badge and the subscribers belong to whoever owned the channel before it was stolen. Bitdefender documented session-token theft used to take channels over, rename them after a company and hide all the original videos. The largest one it tracked had about 12.5 million subscribers. Was the Taylor Swift Le Creuset giveaway real? No. The New York Times reported in January 2024 that ads used a cloned voice and her image to offer 3,000 cookware sets for a $9.96 shipping fee, which collected card details and enrolled victims in hidden monthly charges. Le Creuset said there was no partnership. How do I tell an AI video from a real one? The FBI publishes tells: distorted hands or feet, unrealistic teeth or eyes, inaccurate shadows, watermarks, lag time, voice matching and unrealistic movements. But forgeries improve monthly, so check the stage instead of the face: leave the stream and find the company’s real channel or site independently. Can I get crypto back after sending it to a giveaway address? Usually not. Crypto transfers are not reversible, which is why they are the requested rail. Report it anyway to ic3.gov with the wallet addresses and transaction hashes, and to reportfraud.ftc.gov, because those reports feed the seizure cases that do recover funds. Related The investment platform behind door two is the same machine described in the pig butchering scam, reached through a famous face instead of a months-long friendship. The retail version, minus the celebrity, is the free prize that charges shipping. And when the borrowed identity is a software company rather than a person, it becomes the fake Microsoft security alert. Q: Is the Elon Musk bitcoin giveaway livestream real? A: No. He is named here only as a documented victim of impersonation. The New York Times reported in August 2024 that scammers edited real interview footage, replaced the voice with an AI replica and adjusted the mouth movements, and that thousands of such videos were circulating. Q: The channel had a verified badge and millions of subscribers. How can it be fake? A: The badge and the subscribers belong to whoever owned the channel before it was stolen. Bitdefender documented session-token theft used to take channels over, rename them after a company and hide all the original videos. The largest one it tracked had about 12.5 million subscribers. Q: Was the Taylor Swift Le Creuset giveaway real? A: No. The New York Times reported in January 2024 that ads used a cloned voice and her image to offer 3,000 cookware sets for a $9.96 shipping fee, which collected card details and enrolled victims in hidden monthly charges. Le Creuset said there was no partnership. Q: How do I tell an AI video from a real one? A: The FBI publishes tells: distorted hands or feet, unrealistic teeth or eyes, inaccurate shadows, watermarks, lag time, voice matching and unrealistic movements. But forgeries improve monthly, so check the stage instead of the face: leave the stream and find the company’s real channel or site independently. Q: Can I get crypto back after sending it to a giveaway address? A: Usually not. Crypto transfers are not reversible, which is why they are the requested rail. Report it anyway to ic3.gov with the wallet addresses and transaction hashes, and to reportfraud.ftc.gov, because those reports feed the seizure cases that do recover funds. --- ## Fake Microsoft Security Alert: The Phone Number Is the Scam URL: https://howthescamworks.org/how/fake-microsoft-support-scam/ Lure: Fake tech support Published: 2026-08-07 ANSWER: Nothing is infected. The full-screen alert is a web page delivered through an ad slot, and the phone number is the product being sold. Microsoft states that its error and warning messages never include a phone number. The FTC states that real security pop-ups never ask you to call one. KEY FACT: they never include a phone number — Microsoft's own rule about its error and warning messages (source: Microsoft, Protect yourself from tech support scams) KEY FACT: they will never ask you to call a phone number — The FTC's rule about genuine security pop-ups (source: FTC Consumer Advice, How To Spot, Avoid, and Report Tech Support Scams) KEY FACT: 47,794 complaints and $2,134,675,818 — Tech support fraud reported to the FBI in 2025, the third most expensive fraud category of the year (source: FBI Internet Crime Complaint Center, 2025 Annual Report) KEY FACT: 21,333 complaints and $1,040,730,043 — Share of that category reported by victims over 60 (source: FBI Internet Crime Complaint Center, 2025 Annual Report) KEY FACT: $32,865,655 of the $65,367,648 reported lost — Money frozen by the FBI's Financial Fraud Kill Chain in 2025 incidents involving victims over 60 (source: FBI Internet Crime Complaint Center, 2025 Annual Report) KEY FACT: almost 50% of victims were over 60, and 66% of total losses — Age profile of victims in the FBI's Phantom Hacker alert, where tech support, bank and government personas are layered (source: FBI Internet Crime Complaint Center, Phantom Hacker PSA, 29 September 2023) KEY FACT: approximately 15 million calls — Calls routed to fake support call centres by a single platform charging per call, in a case sentenced in a federal court in North Carolina (source: U.S. Department of Justice, February 2026) KEY FACT: more than $20 million in sales — Pop-up call leads sold to call centres by one broker in the same case, with sentences of 30, 40 and 24 months and $3,711,000 forfeited (source: U.S. Department of Justice, February 2026) KEY FACT: 17 minutes and $290.90 — Average length of a fake support call, and average charge, across 60 calls recorded by researchers (source: Stony Brook University, Dial One for Scam, NDSS 2017) KEY FACT: 8,698 domains — Unique scam-support web domains found in 250 days, with 43% online for three days or less (source: Stony Brook University, Dial One for Scam, NDSS 2017) KEY FACT: 59% of 16,254 adults — Adults surveyed in 16 countries who had an encounter with a tech support scam, of whom 7% lost money (source: Microsoft and YouGov, Global Tech Support Scam Research, 2021) KEY FACT: 12% of 24 to 37 year olds — Age group most likely to lose money in that survey, against 2% of people aged 54 and over (source: Microsoft and YouGov, Global Tech Support Scam Research, 2021) Nothing is infected. The full-screen alert is a web page delivered through an ad slot, and the phone number is the product being sold. Microsoft states that its error and warning messages never include a phone number. The FTC states that real security pop-ups never ask you to call one. Nobody hacks Microsoft to run this. They borrow the name. Microsoft is the company being robbed here too: it publishes the rule that ends the scam and pays an investigations unit to chase the people wearing its brand. How it works - The page arrives through an ordinary website. Malwarebytes found that “malvertising was almost always an element in the chain” — the alert is served through the advertising slot of a site you had every reason to trust. You did not go looking for it, and you did not visit anywhere suspicious. - What you are looking at is a web page, not a virus. Malwarebytes calls it a browser locker and defines it as “a social engineering technique that gives the illusion of a computer virus and scares people into calling a toll-free number for assistance.” Nothing was installed. Nothing was scanned. - The design is built for panic, not information. An alarm sound, a browser that appears completely stuck, a red banner, an error code that means nothing, and one instruction not to shut the computer down. Malwarebytes noted that this combination “triggers panic for many people.” The largest element on the page is the phone number, because that is what the page is for. - The call is patient. Researchers at Stony Brook University recorded 60 of these calls end to end. The average call ran 17 minutes, and the average charge was $290.90. Nobody is in a hurry on the other end. Time is what converts a frightened caller into a paying one. - The caller never asks you to trust him. He asks you to trust the brand already on your screen. He confirms what the page said. He gives a case number. Every sentence borrows credibility from a name he has nothing to do with. - The number is an industry, not a person. A case sentenced in a federal court in North Carolina in February 2026 laid out the layers: publishers who place the pop-ups, a broker who sold the resulting calls as leads and generated more than $20 million in sales, and a platform that routed approximately 15 million calls to call centres overseas, charging per call. Those call centres, the Justice Department said, “misrepresented themselves as Microsoft.” One company in the chain defrauded thousands of victims of more than $7 million. - The pages are disposable and the number is the asset. The Stony Brook team found 8,698 unique scam-support domains in 250 days, with 43% online for three days or less. Taking a page down costs the operation almost nothing. The phone line is the inventory. - Then the impostors stack. The FBI’s Phantom Hacker alert describes the escalation: the tech-support persona hands off to someone claiming to be your bank, who says a foreign hacker has reached your accounts and that the money must be moved to a safe account. The alert notes that this caller instructs the victim not to tell anyone the real reason for moving the money. A third persona claims to be from a federal agency, with letterhead to match. This article stops at the phone call, which is where the decision is still yours. Key facts - The FBI logged 47,794 tech-support fraud complaints and $2,134,675,818 in losses in 2025, making it the third most expensive fraud category of the year, behind investment fraud and business email compromise (IC3 2025 Annual Report). - Victims over 60 filed 21,333 of those complaints and reported $1,040,730,043 — close to half the money in the whole category (IC3 2025). - The FBI’s Phantom Hacker alert states that “almost 50% of the victims reported to IC3 were over 60 years-old, comprising 66% of the total losses” (FBI PSA, 29 September 2023). - In Microsoft’s 2021 global survey with YouGov, across 16,254 adults in 16 countries, 59% had some encounter with a tech-support scam and 7% lost money. The age split is not what people expect: 12% of 24 to 37 year olds who continued the interaction lost money, against 2% of people aged 54 and over. And 79% said it was unlikely a reputable company would contact them that way (Microsoft, July 2021). Knowing is not the same as recognising it while the alarm is sounding. - Microsoft’s Digital Crimes Unit alerted national law enforcement to one of these operations, which searched 19 locations, made 6 arrests and shut down two illegal call centres. Around 90% of the roughly 200 affected people identified were over 50 (Microsoft, June 2025). - In the North Carolina case, the three defendants received sentences of 30, 40 and 24 months and forfeited $3,711,000 (DOJ, February 2026). Enforcement can take the room. It cannot take the name, because the operators never owned it. They rent it, for the price of an advertising slot. How to spot it One sentence does most of the work, and two organisations publish it. Microsoft: “Microsoft error and warning messages never include a phone number.” FTC: “Real security pop-up warnings and messages will never ask you to call a phone number.” A warning with a phone number on it is not a warning. It is an advertisement. Four more checks: - Unsolicited contact about your computer is the tell, whatever the channel. The FTC: “Legitimate tech companies won’t contact you by phone, email, or text message to tell you there’s a problem with your computer.” Microsoft’s version: if you did not ask them to, they will not call you. - The payment method is the diagnosis. Gift cards, wire transfers, bank transfers, cryptocurrency and payment apps are requested because, as the FTC puts it, paying that way is “like using cash — once you pay, it’s hard to get your money back.” - Any instruction to move money to protect it is the scam. The FTC’s rule is three words long: “Don’t move money to ‘protect it.’” The FBI adds that the US government will never ask you to send money by wire transfer to foreign accounts, in cryptocurrency, or on gift or prepaid cards. - Secrecy is a symptom. A real bank never asks you to hide the reason for a transfer from your family or from the teller. Getting off the screen. Nothing on that page needs to be clicked, including anything shaped like a close button, because those belong to the page. Close the browser itself. If the window will not close, make your operating system force the browser to quit, then reopen it without restoring the previous session. And the FTC’s simplest instruction, which works before any of the technical ones: “Talk to someone you trust — a friend, a family member, a neighbor.” What to do if it already happened - Hang up. Ending the call mid-sentence costs you nothing. - Do not move money to protect it, whoever the next caller claims to be. - Call your bank on the number printed on your card, not one you were given, and tell them the calls were fraudulent. Ask them to review and hold anything pending. - Report immediately, because speed is measurable here. In 2025 the FBI’s Financial Fraud Kill Chain helped freeze $32,865,655 of the $65,367,648 reported lost in incidents involving victims over 60. Report to the FBI at ic3.gov and to the FTC at reportfraud.ftc.gov. - Report the impersonation to Microsoft at microsoft.com/reportascam. It is the company’s own channel for this, and it feeds the unit that works with law enforcement. - If you paid, contact the card issuer or bank straight away. If you bought gift cards, call the card’s issuer immediately and keep the receipts and the card numbers, because some funds are recoverable while they are unspent. - If you handed over personal information, work through identitytheft.gov and set a fraud alert with the credit bureaus. - Tell someone. In Microsoft’s survey, 59% of people had met one of these. Being targeted is a statistic, not a character flaw, and the entire script exists to keep one person alone on a phone line for seventeen minutes. Watch the full documentary The alert, the industry behind the number and the one sentence that ends it are in the documentary, publishing this week on the How the Scam Works channel. FAQ Is the Microsoft security alert pop-up with a phone number real? No. Microsoft states that its error and warning messages never include a phone number, and the FTC states that real security pop-ups will never ask you to call one. A warning with a number on it is an advertisement wearing a warning’s clothes. Does that page mean my computer is infected or hacked? The page proves nothing about your computer. Malwarebytes defines what you are looking at as a browser locker, a technique that gives the illusion of a computer virus in order to make people phone a number. It is a web page, not a scan result. Does Microsoft ever call you about a virus? No. Microsoft’s support pages state that the company does not make unsolicited phone calls or send unsolicited emails to offer technical support or request personal or financial information, and that if you did not ask them to, they will not call you. I called the number. What should I do now? Hang up. Do not move money to protect it, which is the FTC’s own instruction. Call your bank using the number printed on your card, then report to ic3.gov, reportfraud.ftc.gov and microsoft.com/reportascam. Speed matters: in 2025 the FBI’s kill chain froze $32,865,655 of the $65,367,648 reported lost by victims over 60. Why would my bank tell me to move money into a safe account? It would not. The FBI’s Phantom Hacker alert describes a second caller posing as your bank, telling you a foreign hacker has reached your accounts, instructing you to move the money to a safe account, and telling you not to explain the real reason to anyone. That instruction is the scam identifying itself. Is this only a scam that catches older people? No, and the data splits in two directions. In Microsoft’s 2021 global survey with YouGov, 12% of 24 to 37 year olds who continued the interaction lost money, against 2% of people aged 54 and over. But the dollars concentrate in older victims: the FBI recorded $1,040,730,043 of the 2025 category total from people over 60. Related The persona ladder that follows the first call, support to bank to government, is the same borrowed-authority trick used at scale in the celebrity crypto giveaway deepfake. The fee that unlocks nothing appears again in the pig butchering scam and, at pocket-money prices, in the free prize that charges shipping. Q: Is the Microsoft security alert pop-up with a phone number real? A: No. Microsoft states that its error and warning messages never include a phone number, and the FTC states that real security pop-ups will never ask you to call one. A warning with a number on it is an advertisement wearing a warning’s clothes. Q: Does that page mean my computer is infected or hacked? A: The page proves nothing about your computer. Malwarebytes defines what you are looking at as a browser locker, a technique that gives the illusion of a computer virus in order to make people phone a number. It is a web page, not a scan result. Q: Does Microsoft ever call you about a virus? A: No. Microsoft’s support pages state that the company does not make unsolicited phone calls or send unsolicited emails to offer technical support or request personal or financial information, and that if you did not ask them to, they will not call you. Q: I called the number. What should I do now? A: Hang up. Do not move money to protect it, which is the FTC’s own instruction. Call your bank using the number printed on your card, then report to ic3.gov, reportfraud.ftc.gov and microsoft.com/reportascam. Speed matters: in 2025 the FBI’s kill chain froze $32,865,655 of the $65,367,648 reported lost by victims over 60. Q: Why would my bank tell me to move money into a safe account? A: It would not. The FBI’s Phantom Hacker alert describes a second caller posing as your bank, telling you a foreign hacker has reached your accounts, instructing you to move the money to a safe account, and telling you not to explain the real reason to anyone. That instruction is the scam identifying itself. Q: Is this only a scam that catches older people? A: No, and the data splits in two directions. In Microsoft’s 2021 global survey with YouGov, 12% of 24 to 37 year olds who continued the interaction lost money, against 2% of people aged 54 and over. But the dollars concentrate in older victims: the FBI recorded $1,040,730,043 of the 2025 category total from people over 60. --- ## Free Prize Scam: Why 'Just Pay Shipping' Is the Scam URL: https://howthescamworks.org/how/free-prize-scam/ Lure: Free prize or giveaway Published: 2026-08-05 ANSWER: A free prize that asks you to pay shipping, taxes or insurance is not a prize. The FTC states it in one line: real prizes are free. The fee is the product, and the checkout page behind it usually harvests your card number, address and identity data as well. KEY FACT: $2.1 billion, eight times the 2020 figure — Reported losses to scams that started on social media in 2025 (source: Federal Trade Commission, Data Spotlight, April 2026) KEY FACT: nearly 30% — Share of people who reported losing money to fraud in 2025 who said it started on social media (source: Federal Trade Commission, Data Spotlight, April 2026) KEY FACT: $503,373,587 across 56,478 complaints — Losses in the FBI category this scam falls under, non-payment and non-delivery, in 2025 (source: FBI Internet Crime Complaint Center, 2025 Annual Report) KEY FACT: 87.5%, and 30.3% of all 2024 reports — Share of people who reported an online purchase scam to the BBB and lost money (source: BBB Institute, 2024 Scam Tracker Risk Report) KEY FACT: 73 in 2019 to 783 by the end of 2023, more than tenfold — Rise in New York account-takeover complaints cited by 41 state attorneys general in a letter to Meta (source: 41 state attorneys general, letter to Meta, 5 March 2024) KEY FACT: over 159 million ads and 10.9 million accounts — Scam ads Meta says it removed in 2025, and accounts it linked to criminal scam centres (source: Meta Newsroom, March 2026) KEY FACT: Real prizes are free — The FTC's rule for every prize offer (source: FTC Consumer Advice, Fake Prize, Sweepstakes, and Lottery Scams) KEY FACT: not covered by Purchase Protection — Cover for Friends and Family payments (source: PayPal, official help centre) A free prize that asks you to pay shipping, taxes or insurance is not a prize. The FTC states it in one line: real prizes are free. The fee is the product, and the checkout page behind it usually harvests your card number, address and identity data as well. The version that spreads fastest carries no link, no price and no request for money in the post itself. It is missing everything a scam is supposed to have. That is the design. How it works - The post arrives without an offer. A parent in a local buy-and-sell group writes that their child has died and that the console bought as a gift is still boxed. No link. No price. Comments are turned off. Interested people are asked to send a private message. - The words are not theirs. Malwarebytes documented the template in 2022, down to the sentence structure, replicated account to account with only the child’s gender changed. The post is a script in circulation, not a person in mourning. - The photographs are not theirs either. AAP FactCheck traced pictures used in these posts to a US childhood-cancer charity, Strong Little Souls, which said it had them removed many times. This industry does not fake grief. It shoplifts it. - The account may not be theirs. In March 2024, 41 state attorneys general wrote to Meta about account-takeover complaints. In New York alone they rose from 73 in 2019 to 783 by the end of 2023, more than tenfold. A stolen profile with real friends and years of history is the cheapest trust available. - The private message builds an obligation. The item is promised to you. You are asked not to resell it, out of respect. Now backing out feels like a betrayal rather than a decision. - The fee is small on purpose. Courier costs. Around fifty dollars. Paid through a payment app, to an account whose name does not match the person in the post. The FBI has a term for that account holder: a money mule. - Then the fee has children. Insurance, refundable on delivery. Customs. A release charge. Each payment invents the next one, and the sunk cost does the arguing for them. - The second door is worse than the first. Instead of a fee, some versions send a courier tracking link with a checkout page. Bitdefender documented what those pages collect: full card numbers including the CVV, names, addresses, phone numbers, even Social Security numbers, plus recurring charges the victim never authorised. Key facts - The FTC counted $2.1 billion in reported losses to scams that started on social media in 2025, eight times the 2020 figure, and reported that nearly 30% of people who lost money to fraud that year said it began on social media. More money was lost to scams that started on Facebook than on any other platform (FTC Data Spotlight, April 2026). - The FBI’s official category for paying and never receiving, non-payment and non-delivery, accounted for $503,373,587 across 56,478 complaints in 2025 (IC3 2025 Annual Report). - Online purchase scams were 30.3% of everything reported to the BBB Scam Tracker in 2024, and 87.5% of the people who reported one lost money (BBB Institute 2024 Risk Report). Engaging is not a neutral act. It is close to nine in ten. - Meta says it removed over 159 million scam ads in 2025 and took down 10.9 million accounts associated with criminal scam centres, with 92% of the ads removed before anyone reported them (Meta Newsroom). Enforcement at that scale mows the lawn. It does not pull the roots: the losses reported to the FTC still climbed to eight times the 2020 figure while it was happening. How to spot it - Free that charges is not free. The FTC’s language is exact: “Real prizes are free.” Shipping and handling, taxes, insurance, processing, customs. Any of them ends the conversation. - Comments off, messages only. Disabled comments are not privacy. They stop the neighbour who has seen the post before from typing so under it. - The payment method is the confession. Friends and Family, gift card, wire transfer, crypto or cash all share one property: no dispute to open. PayPal states plainly that Friends and Family payments are not covered by Purchase Protection. - The name on the payment does not match the name on the post. That is not sloppiness. That is a mule account, and the FBI describes the role in its own material. - Run the search test. Copy one full sentence from the post, put it in quotation marks, and search it. The same bereaved parent appears in dozens of towns. It takes twenty seconds. - Run the picture back. A reverse image search on the photo usually finds the child, the room or the boxed console somewhere it was taken from. - Never type card details into a page you reached from a message. Legitimate delivery never needs your CVV, and it never needs your Social Security number. What to do if it already happened - Stop paying. The insurance charge, the customs charge, the last one before delivery. None of them ends the ladder. - Call your bank or card issuer today and say the words fraud and dispute. If you paid by card, you have a chargeback path. If you paid through a payment app, report it in the app and to the bank behind it. - Report it. The FTC at reportfraud.ftc.gov, the FBI at ic3.gov, and the BBB Scam Tracker. Reports are what produced the numbers above. - If you gave out personal data, including your Social Security number, work through identitytheft.gov and place a fraud alert with the credit bureaus. - If your card touched a courier checkout page, treat the card as compromised and have it replaced, then watch for small recurring charges rather than one large one. - If the post came from someone you know, contact them another way. Their account was probably taken over, and they are being used as the mask. - Report the post and the profile to the platform. It costs you nothing and it is the only signal that reaches the takedown pipeline. Watch the full documentary The full case, the money trail and the four fingerprints are in the documentary: Don’t Take the “Free” PS5 from a Grieving Stranger. FAQ Is the free PS5 giveaway on Facebook real? No. Malwarebytes documented the post as a fixed template, copied account to account with only the child’s gender changed, and classed it as advance-fee fraud. The console does not exist. The shipping fee does. Why would a stranger give away an expensive console to someone they have never met? They are not giving anything away. The grief story exists to make the fee feel like a courtesy rather than a purchase, and to make questions feel rude. The FTC’s test cuts through it: if you have to pay to get your prize, it is a scam. Is it safe to pay a small shipping fee for something that is free? No, and the size is deliberate. A small fee is easier to approve than to interrogate. The FTC lists shipping and handling, taxes and processing fees as the standard demands of a fake prize offer, and the payment rails requested, gift cards, wire transfers, cash or crypto, are the ones with no dispute process. The seller only accepts Friends and Family, Cash App or Zelle. Is that a red flag? It is the confession. PayPal states that Friends and Family payments are not covered by Purchase Protection, so there is no dispute to open. Insisting on that method is a choice about what you will be able to do afterwards. The photos looked real, so how can the post be fake? The photos usually are real, just stolen. AAP FactCheck traced images used in these posts back to a US childhood-cancer charity, Strong Little Souls, which said it had them taken down repeatedly. The grief in the picture belongs to somebody else. Related When the free gift is offered by a famous face instead of a grieving stranger, it is the celebrity crypto giveaway deepfake. When the borrowed trust is a brand rather than a person, it is the fake Microsoft security alert. And the same fee-to-release trick, scaled into the billions, is how the pig butchering scam closes. Q: Is the free PS5 giveaway on Facebook real? A: No. Malwarebytes documented the post as a fixed template, copied account to account with only the child’s gender changed, and classed it as advance-fee fraud. The console does not exist. The shipping fee does. Q: Why would a stranger give away an expensive console to someone they have never met? A: They are not giving anything away. The grief story exists to make the fee feel like a courtesy rather than a purchase, and to make questions feel rude. The FTC’s test cuts through it: if you have to pay to get your prize, it is a scam. Q: Is it safe to pay a small shipping fee for something that is free? A: No, and the size is deliberate. A small fee is easier to approve than to interrogate. The FTC lists shipping and handling, taxes and processing fees as the standard demands of a fake prize offer, and the payment rails requested, gift cards, wire transfers, cash or crypto, are the ones with no dispute process. Q: The seller only accepts Friends and Family, Cash App or Zelle. Is that a red flag? A: It is the confession. PayPal states that Friends and Family payments are not covered by Purchase Protection, so there is no dispute to open. Insisting on that method is a choice about what you will be able to do afterwards. Q: The photos looked real, so how can the post be fake? A: The photos usually are real, just stolen. AAP FactCheck traced images used in these posts back to a US childhood-cancer charity, Strong Little Souls, which said it had them taken down repeatedly. The grief in the picture belongs to somebody else. --- ## Pig Butchering Scam: How the Wrong-Number Text Works URL: https://howthescamworks.org/how/pig-butchering-scam/ Lure: Investment fraud Published: 2026-08-05 ANSWER: A pig butchering scam opens as a wrong-number text or a dating match, never as an investment pitch. After weeks of ordinary conversation, the stranger moves you onto a fake trading platform where your balance is typed in by hand. The scam only reveals itself when you try to withdraw. KEY FACT: $5.8 billion across 41,557 complaints — Crypto investment fraud reported to the FBI in 2024 (source: FBI Internet Crime Complaint Center, 2024 Annual Report) KEY FACT: nearly one-third — Share of 2024 investment-fraud losses reported by people over 60 (source: FBI Internet Crime Complaint Center, 2024 Annual Report) KEY FACT: 77% of 8,103 victims notified; $511,511,288 saved — Victims contacted by the FBI mid-scam who did not know they were being defrauded (source: FBI, Operation Level Up) KEY FACT: $1,996 — Median reported loss to a romance scam (source: Federal Trade Commission, March 2025 release on 2024 data) KEY FACT: 127,271 bitcoin, roughly $15 billion — Bitcoin sought in the largest forfeiture action in Justice Department history, tied to Cambodian forced-labour scam compounds (source: U.S. Department of Justice, October 2025) KEY FACT: $225.3 million — Separate civil forfeiture complaint against crypto traced to investment-fraud victims (source: U.S. Department of Justice, June 2025) KEY FACT: up 210%, while the average deposit fell 55% — Change in the number of deposits into pig-butchering wallets, year on year (source: Chainalysis, 2025 Crypto Crime Report) KEY FACT: at least 300,000 people from 66 countries — People documented inside South-East Asian scam compounds (source: UN Human Rights Office, via UN News) KEY FACT: more than 60 — Countries where scam-centre victims have been identified (source: INTERPOL, 2025) A pig butchering scam opens as a wrong-number text or a dating match, never as an investment pitch. After weeks of ordinary conversation, the stranger moves you onto a fake trading platform where your balance is typed in by hand. The scam only reveals itself when you try to withdraw. The U.S. Secret Service publishes the name the operators use: sha zhu pan, pig butchering. It describes three phases, and it is the business plan, not a metaphor. Find the pig. Fatten the pig. Butcher the pig. How it works - First contact looks like an accident. A text to the wrong number. A dating app match. A friendly reply to a comment. There is no offer and no link. The opening is designed to survive suspicion because there is nothing yet to be suspicious of. - The conversation moves to a private app. Usually WhatsApp or Telegram. This takes the relationship out of any platform that could flag it, and out of reach of anyone who could warn you. - Weeks pass with no mention of money. The CFTC calls this phase grooming in its own advisory. Photos, routines, a voice note, a video call that is somehow always cut short. The asset being built is not affection. It is your assumption that you already know this person. - Investing arrives as a detail, not a pitch. An uncle who works at a fund. A method the family uses. Something they were already doing before they met you. You are never sold to. You are allowed to ask. - The first deposit is small and it works. Often on a real exchange, so the paper trail looks normal. Then the money is moved onto a private platform or app that only they can show you. - The dashboard is theatre. The number on your screen is a number on their screen, editable. Gains appear. Small withdrawals may even be honoured early on, because a withdrawal that works is the most expensive advertisement they can buy. - The butchering happens at the withdrawal. A fee. Then a tax. Then a compliance hold, an anti-money-laundering charge, a deposit to unlock the account. Each payment produces a new obstacle, because the obstacles are the product. - The money leaves in minutes. Crypto moves out through laundering networks and offshore accounts. Chainalysis measured the shape of the industry directly: revenue rose about 40% year on year, the number of deposits rose 210%, and the average deposit value fell 55%. That is a business taking smaller bites from far more people. Key facts - The FBI’s Internet Crime Complaint Center logged $5.8 billion in crypto investment fraud across 41,557 complaints in 2024, and reported that nearly one-third of investment-fraud losses came from people over 60 (IC3 2024 Annual Report). - The Federal Trade Commission puts the median reported romance-scam loss at $1,996 (FTC, March 2025). The median is small because most victims are stopped early. The scam’s economics live in the tail. - Under Operation Level Up, the FBI notified 8,103 victims while the fraud was still running. 77% of them had no idea. The programme reports $511,511,288 saved (FBI). - In October 2025 the Justice Department filed a civil forfeiture complaint against 127,271 bitcoin, roughly $15 billion, tied to forced-labour scam compounds in Cambodia. The Department describes it as the largest forfeiture action in its history (DOJ). - Four months earlier the Department filed a separate complaint against $225.3 million traced to investment-fraud victims (DOJ, June 2025). - The UN Human Rights Office has documented at least 300,000 people from 66 countries inside these compounds (UN News). INTERPOL has tracked scam centres far beyond South-East Asia, with victims in more than 60 countries (INTERPOL). The person messaging you is frequently working under coercion. That does not make the loss smaller. It does explain why the messages never stop arriving. How to spot it The consumer-protection regulator for derivatives markets, the CFTC, publishes the warning signs for exactly this fraud. Four of them do most of the work. - Unsolicited contact that steers you off-platform. A stranger who reaches you by accident and needs the conversation to continue somewhere private. - The conversation always arrives at money, and the money has no risk. Real markets have losses. The pitch that has none is not a market. - You never meet in person or on unbroken video. The camera fails. The trip is cancelled. The emergency is real enough to be unanswerable. - The problem appears when you try to take money out, not when you put it in. Deposits are frictionless. Withdrawals require one more payment. Two more checks are quick and decisive: - Look up the platform in the official registries — the SEC, FINRA and the CFTC all publish them. A firm that holds your money and appears in none of them is not regulated anywhere. - Try to withdraw a small amount early. Not as a test of good faith, but as a test of the plumbing. What to do if it already happened - Stop sending money today. Including the fee that supposedly releases everything else. Especially that one. - Report it to the FBI at ic3.gov and to the FTC at reportfraud.ftc.gov. Speed is the variable you still control. Operation Level Up exists because interruption works. - Keep everything. Wallet addresses, transaction hashes, the platform’s URL, the app, the full chat history, and the phone numbers. Screenshots before you delete anything. - Tell your bank or exchange. Ask them to flag the destination addresses and freeze anything pending. - If you handed over identity documents, work through identitytheft.gov. - Refuse the second scam. Anyone who contacts you offering to recover the funds for an upfront fee is running the follow-up. Recovery fraud targets people who have already been robbed once, because that list is for sale. - Tell one person you trust. The isolation was engineered. Ending it is part of the fix. Watch the full documentary The full case, the money trail and the four fingerprints investigators use are in the documentary: How a Text Message Becomes a $15 Billion Scam. FAQ Is a wrong-number text always a scam? Not always, but both the FBI and the U.S. Secret Service list the unsolicited wrong-number text as a standard opening move of crypto investment fraud. A genuine wrong number ends when you say they have the wrong person. A scam keeps the conversation going. Why can’t I withdraw my profits from the trading platform? Because the profits are a number typed into a page the scammer controls. The CFTC lists withdrawal problems among its official warning signs for these frauds. Every fee, tax or compliance charge you are asked to pay to release the money is another payment, not a step toward release. What does pig butchering actually mean? It is a translation of sha zhu pan, the term the U.S. Secret Service uses for this fraud. The Secret Service describes three phases: find the pig, fatten the pig, butcher the pig. The fattening is the friendship, and the butchering is the withdrawal request. Can I get my money back after a pig butchering scam? Sometimes, and speed decides it. The Justice Department filed forfeiture actions over $225.3 million in June 2025 and roughly $15 billion in October 2025, and the FBI’s Operation Level Up says early notification saved victims $511,511,288. Report to ic3.gov immediately, and never pay a company that promises recovery for a fee. Who is actually typing the messages? Often someone who is also a victim. The UN Human Rights Office has documented at least 300,000 people from 66 countries inside scam compounds, many held against their will. INTERPOL has tracked victims of these operations in more than 60 countries. Related The same withdrawal-fee machinery is bolted onto a famous face in the celebrity crypto giveaway deepfake. The same advance-fee logic, at a fraction of the price, drives the free prize that charges shipping. And when the opening move is a borrowed brand instead of a borrowed friendship, you are looking at the fake Microsoft security alert. Q: Is a wrong-number text always a scam? A: Not always, but both the FBI and the U.S. Secret Service list the unsolicited wrong-number text as a standard opening move of crypto investment fraud. A genuine wrong number ends when you say they have the wrong person. A scam keeps the conversation going. Q: Why can't I withdraw my profits from the trading platform? A: Because the profits are a number typed into a page the scammer controls. The CFTC lists withdrawal problems among its official warning signs for these frauds. Every fee, tax or compliance charge you are asked to pay to release the money is another payment, not a step toward release. Q: What does pig butchering actually mean? A: It is a translation of sha zhu pan, the term the U.S. Secret Service uses for this fraud. The Secret Service describes three phases: find the pig, fatten the pig, butcher the pig. The fattening is the friendship, and the butchering is the withdrawal request. Q: Can I get my money back after a pig butchering scam? A: Sometimes, and speed decides it. The Justice Department filed forfeiture actions over $225.3 million in June 2025 and roughly $15 billion in October 2025, and the FBI’s Operation Level Up says early notification saved victims $511,511,288. Report to ic3.gov immediately, and never pay a company that promises recovery for a fee. Q: Who is actually typing the messages? A: Often someone who is also a victim. The UN Human Rights Office has documented at least 300,000 people from 66 countries inside scam compounds, many held against their will. INTERPOL has tracked victims of these operations in more than 60 countries. ---