📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

New Scams to Watch Out For in 2026

ThioJoe23:49

Transcription

Well, it's a new year and there's new scams. So like I do every year, I'm going to talk about a bunch of brand new scams or even ones that are new variations on older scams. All of which you'll want to be aware of and watch out for in 2026. And really for most of these, the best way to defend against them is to simply know about it. So by the end, you should be good. I'm ThioJoe, and let's get into it.

Starting off, we have a scam text that's been going around recently. I actually got this one myself. It claims to be your phone company like T-Mobile or it could be Verizon or anything else. And it says that you have a ton of these reward points that are expiring very soon and you need to use them or lose them. And then it'll have a link to a fake phishing page, of course to steal your login if you try to do that. It's completely made up and don't believe it.

Next up, you'll want to be aware that there's a lot of scams going around in general that are targeting specific industries and professions. For example, there's a recent scam emails going around to lawyers specifically pretending to be the state bar association and that there's some urgent matter that they need to deal with. And it comes in the form of an attachment or file sharing links like to a Dropbox or OneDrive or Google Drive. And it says to download it. It could also be a password protected zip file. But of course, if you run whatever it tells you to do, it'll be a virus. Another example is scam emails targeting business executives specifically about some kind of executive award that they're supposedly receiving. And again, it'll have some kind of malicious files attached. And interestingly with these is they may combine the scam technique with another one called "ClickFix", where it basically pretends that your browser has some kind of error and that you need to click or type in a command somewhere to fix it. But really that command will download and install a virus. So the point is you need to be diligent with all your emails you receive, even if they're very specific to your profession. And also by the way, just so you know, password protected zip files basically almost always are a scam. That is a major red flag. And never trust any site that says that you need to run a command or paste something into the Windows run box. I have talked about that in previous videos, but it's still good to be aware of.

Next, another technique becoming more popular are scammers sending you a calendar invite for a fake event that contains a scam link or something else scammy. They do this because it's less likely to be caught by a spam filter. For example, if it's a Google calendar invite, you would receive a email notification that technically is from Google. You might recall in my last year's video, I talked about scammers doing something similar with Google Drive file share invites. It's the same idea. They might try to use legitimate services and the sharing notifications along with them to send the actual scam text.

Moving on, this is a real life scam, and this involves the so-called "brushing" scam that you may have heard of, but it's a new twist on it. If you're not familiar, quickly, brushing scams are basically where you receive a package out of the blue addressed to you, but you never ordered it. And basically it was some third-party seller on Amazon or some other marketplace who pretended to be you and bought some cheap item, sent it to you. And the idea is to get fake reviews on their product. They make the orders themselves. Seemingly it was ordered by a legitimate person, you, but then they get to write the review on it. So even though it costs them a little bit of money for the product, they still get to write the review. And in the long run, it'll be better for them, they figure. However, what is new and what's changed is scammers decided that they can double dip with the scam. So when they're going to package this fake order that they're sending you, they may put in a card or paper with a QR code on it, and then give some excuse why you should scan it, like saying, "Hey, this is a gift order. And to see who sent you this gift, just scan this code and log in." And it will be a phishing link. Maybe it'll be to Amazon or whatever other retailer supposedly sent it. Now it's not like scanning the code will immediately hack your phone or anything. It would have to take you to a site where you would have to actually type in your credentials for them to steal it, but still be aware that it is something they do.

Next up, here's a new scam that is targeting hotels and their guests kind of separately. And it's called the I paid twice scam. What these scammers do is first they target hotel managers with malware. Maybe again, like we talked about before with emails crafted for that specific industry. And then when they trick the hotel managers or employees into downloading it onto the computer, they then have access to that hotel's system and guest lists and all sorts of stuff. And then with that information, the scammers will next go and contact the guests with even more targeted phishing for them. And because they have access to the actual real information from the system, they can make extremely legitimate and realistic looking phishing emails. They'll have, for example, the real order confirmation numbers, the actual dates that you registered the stay, the name of the hotel, stuff like that. And then what they'll do is when they contact you via email or maybe even some other method that they stole, they'll tell you that for some reason, whatever they say, you need to actually pay again. Or maybe if it's a reservation that you haven't paid for yet, you expect to pay at the desk, they'll say, "oh you need to pay now", that sort of thing. But in any case, they'll give you some excuse why you need to pay something now. So of course, they'll take your payment information, charge you immediately likely, and then also steal your payment information to charge as much as they want in the future if they can. And of course, when you go and ask the hotel, "why did I get charged twice?" They're not going to know what you're talking about, because it was a scam. And they might not even realize that they were compromised until a while later.

Okay, now moving on, next up I have a few different tap-to-pay related scams. Now to be clear, I don't want to imply that you should stop doing tap to pay to pay for stuff. It's actually very safe and is the best way to avoid skimmers. However, there's ways that scammers have found ways around it to abuse it basically. Let me explain. One of these techniques is called "ghost tapping", where someone will actually get very close to you with some kind of portable merchant terminal, and then they'll basically hold it up to your credit card next to you in your wallet while it's still in your pocket, and then make a charge to it without you even realizing. Of course, they would probably use something smaller, but it's the same idea. And this is going to be mostly a problem for credit cards rather than phones, because with Apple Pay and Google Pay, that usually requires you to use a confirmation to do it, but with a credit card, obviously not. And again, this has nothing to do with whether or not you're personally using tap to pay. This is just when it's still in your pocket. So the way to protect against that would be to use an RFID blocking wallet, or just be aware of people who are getting a little bit too close or bumping into you, and that sort of thing.

Another technique that scammers will use is called a "forced swipe", where the scammer will install a regular credit card skimmer on the payment terminal or the gas station, whatever. And then they'll actually break or block the tap to pay panel in some way, so that when someone does actually try to use tap to pay, because it is safer, it won't work. And then it'll force them to use the magnetic strip, and then they'll have the skimmer ready for that. In the past, scammers have also done something similar with the chip insert slot, where they'll put glue or something, so it doesn't work and you have to swipe. Now, when it comes to the tap to pay thing, it's possible, I guess, that they would completely destroy it. But what's more likely is they would put some kind of RFID blocking sticker on top of it, so that if someone just tries to do it, it won't work, but it'll still look like the tap to pay thing. So if there is a tap to pay terminal on something and it doesn't work, that is one reason to possibly be suspicious. Now, one thing I want to point out is there was some viral videos going around showing how there's a sticker on top of the tap to pay thing, and how that's a scam and stuff like that. That's not necessarily true. Just because there's a sticker on that, it could be that the store owner saw that the tap to pay thing was worn out and just covered it up with a nicer looking one. No sticker alone is going to be able to intercept and steal the tap to pay transaction. That's just a myth. Again, if a scammer was going to put something on there, it would be to prevent you from doing tap to pay so that you would use the weaker method.

Now, that being said, there is one more tap to pay technique where scammers could put a sticker on there that has an embedded NFC tag. And if you're not aware, NFC tags are kind of like little radio things where if you put your phone up to it, it can do stuff, including maybe having an embedded link to a website that will show a little prompt on your phone to open that site. It's not like it's going to hack your phone or anything if you scan it. However, what the scammers might do, is hope that people using their phone specifically, this would only work on your phone obviously, to show the thing. But when you hold it up to pay, it'll pop up a thing saying go to this website to pay, not realizing that that is completely unnecessary. But someone might see that, think they have to pay, and it'll be a phishing site probably targeting that specific retail store. This one seems like it's probably less likely because it requires hoping that the person is going to visit that website link, but it's still possible. And in any case though, again, simply scanning it is not going to steal your info. It would require you to actually go to the site and do something with it.

Alright, moving on. Another scam I've seen are fake postage stamps. This is particularly in the United States, but could be any country where you'll see postage stamps seemingly sold on social media or like Facebook marketplace, and people will be selling rolls of stamps seemingly at huge discounts. However, these are completely counterfeit. They're not real. And if you end up using them, the machines that they use to sort mail and stuff would be able to tell and you could have your letter rejected or worse. The thing to realize is that postage stamps are never discounted. It would be like the US Mint selling dollars for less than a dollar. It would make no sense. Now, one caveat to that is sometimes legitimate retailers like Costco may sell at a minuscule discount, like a couple percent. But again, if you're seeing something like a 10% discount or more, it's counterfeit for sure.

Next up, this is a scam that hits pretty close to home, and it is deepfake scam videos on social media impersonating creators, like myself. I might make a dedicated video about this at some point, but I actually found an account on TikTok with two videos of me that are not actually me where they cloned my voice and video and had it as if I was reading some advertisement for a fake scam hacking service. And it even had synced up lip movements. It was insane. The voice did sound robotic, I could tell it was fake, but it was my voice. And this was even a couple of years ago, apparently. I didn't know about it. And there are tons of similar videos with deepfakes of other creators on this website. At a glance, you might look at it and say, "Oh they're just stealing a bunch of creators videos and making it look like they're advertising the service." But no, they are completely generating these fake AI videos from scratch. The creators never said any of these things. So if you see something like this, it seems to be especially a problem on TikTok. What you can do is report it. There's an option under misinformation for deepfakes. And it seems like TikTok might not care about this unless a ton of people report them, but at least you can do your part if you happen to see it. And realize that these hacking services, complete scams, they're going to steal your money. And I can't believe these accounts have been allowed to exist with literally millions of likes. Crazy.

Alright next up, another very interesting scam I saw talked about on Reddit recently, is scammers are apparently using Uber Eats to steal packages. In this recent Reddit thread, the person talked about how they had just ordered a laptop from Apple. And when they were watching the delivery tracking, the day it was supposed to be delivered, they saw notifications that there had been a request to reroute or delay the package in some way. And the person had obviously not made that requested change. Now, as for how exactly the scammers did this, I'll go over some theories in a second. It's not really clear. But in any case, the would-be victim here was pretty persistent with customer service and he noticed it. And eventually he got them to tell the driver to go back and deliver it because the package had been requested diverted. So they weren't going to deliver it, but he had them deliver and sign for it anyway. And he did get the package. However, the person said that very shortly after receiving the package, two separate times, different Uber Eats drivers showed up saying that they were there to pick up a package to deliver somewhere else. Because if you're not aware, Uber or Uber Eats does have a service where you can give a Uber driver a package and they'll drive it point A to point B directly to someone else. And then when the other person receives it, they confirm it and then you pay. So what the scammers did is basically tricked the Uber drivers and said, "oh yeah, go to this address. There's a package that was misdelivered and you need to go and deliver it to the correct person." Anyway, when the Uber driver showed up, he apparently was still on the phone with the scammer. The scammer wanted to keep him on the phone, I guess, to give him instructions. So when the Uber driver got there, the scammer was probably expecting the package to still be on the porch, but it wasn't. So the Uber driver knocked on the door and explained what was going on. And the person said, "I did not do this. I got my laptop, I'm not giving it to you." And apparently the scammer on the other end was trying to give some kind of excuse, and both the driver and obviously the person realized, "yeah, this is a scam." So the Uber driver canceled the delivery and then went about their business. But it turns out that maybe the scammer didn't realize that they both figured it out. So he actually had another Uber driver go and try the same thing, telling them the same thing. And of course that didn't work either.

Now like I said, it's not exactly clear how the scammers got the tracking info in this case, because usually with the tracking info, you have some level of control in terms of requesting redelivery dates. But anyway, some theories that people have said in the comments is that someone at the UPS distribution warehouse was in on it. Like maybe they were scanning boxes and sending them to the scammers so they could make requests. But someone else had an interesting theory where they speculated that the scammer actually signed up for a UPS account and said that they had the person's address when they signed up for it, which apparently UPS doesn't verify at least according to one person. And you can do this with your own address and then you have more control over it. And you get notifications and stuff when there's incoming deliveries. So someone said maybe they just did that on a whole bunch of houses, waited for someone to get a delivery from a high value retailer, and then did what they did. And they were likely going to try and reroute the package maybe to a more convenient place to send the delivery driver to steal it from. So in any case, it might be worth going on UPS and FedEx websites. They both have something similar and registering your address. I'm not sure if that prevents anyone from registering it in addition, but it's not a bad idea.

Alright now next up are some less widespread scams that are more local that I've seen, but still are good to be aware of because they could happen anywhere. The first one is interesting. And it's a police merch scam where someone was calling around local residents, pretending to be that local police department. And then we're asking for donations saying that, "yeah it's for some merch for the police department. You're going to get shirts and stuff." The police department didn't exactly give many specific details other than that, but I thought it was unique enough to at least mention.

Next, another one that was probably more common during the past holiday season is scammers pretending to be charities and doing fake calls where they pretend to be raising money for a toy drive specifically in this case. And they would call around asking residents for donations saying that they were doing a fake toy drive or a gift program for kids, stuff like that. And interestingly, these scammers as well were pretending to be another police department, different from the first one. So I guess scammers think that if they impersonate the police, people are less likely to think it's a scam, but realize that yes, scammers are willing to stoop that low.

Now this next one I think is especially evil. And it's where scammers are contacting pet owners who posted about their lost pet. And they're pretending to be the humane society or some other animal organization saying that they found the person's pet, but it needs emergency surgery and it's going to cost money. And they try to get money out of these people who are looking for their lost pet. It's really just evil. And it can even go further than that. In a second, I'll talk about how scammers are using AI generated images. And one Reddit user said that they got a fake image of their lost pet that was AI generated as if it was in surgery. And again, they were asking for money. So just realize that no legitimate vet or organization is going to call you asking for money. So just be aware.

Okay, moving on. This one is pretty unusual in that it actually targets family members of people who were arrested and are in jail. So unlike other scams where they fake being the police saying that your family member was arrested when they haven't, this is kind of like the reverse. And in this case, they'll look up public arrest records for people who have actually been arrested and are in jail, and then call family members, pretend to be the police saying that the family can pay for an ankle monitor to get that person released on bail or whatever. And if a lot of times the family is willing to pay that, obviously, and they probably do it at a point where the family knows that the person legitimately was arrested. So again, it's an example of hyper targeted scams that a lot of people don't realize is something they'll do.

Alright now next up, there are some scams that I have made dedicated videos about in the past, but I thought are worth reiterating here. The first one is because it's so serious. It's the so-called "pig butchering" scam. This one is getting way worse. The name comes from the fact that the scammers basically fatten you up, the victim, over the course of months before taking all your money. And this is the one you may have seen, but didn't really know what it was, where you'll get often a random text pretending to be a wrong number. But then if you ever respond, they'll say, "Oh haha, wrong number." And then continue the conversation and basically try to be friends with you. And the short version of the scam is they'll basically pretend to be really rich, drop subtle hints that they have a lot of money. And then when the victim inevitably asks, "Hey by the way, what do you do to have all this money?" They'll always say that they do some kind of crypto investing and they have a system. And then when the victim asks for more information about it, they'll say, "Oh yeah, you know what? I can help you do it too. Here's this website that I use." And it's actually a fake website though. So the victim will deposit all this money and the entire thing is set up to make it look like you're investing in making these major returns, but it's all fake and you'll never be able to withdraw the money again. And by the time the person tries to withdraw anything, the scammer disappears. And this may be over the course of months where people lose their entire life savings. This could happen via text message, like I said, just randomly, or a lot of times it'll also target people on dating apps. So just be aware that this is a thing.

Next, another one that I talked about recently involved scammers using legitimate actual Apple support ticket emails, where the email would actually come from Apple to trick people into resetting their password basically. The scammers reach out pretending to be Apple in the first place, and then they'll submit a support ticket with the person's information so they get it, not realizing that anyone could do that. And then they eventually convince the user that they are actually Apple. And then at the end, they'll send one final phishing link text message saying, "Oh yeah, you just got to confirm this one last thing to close out the ticket." And it doesn't actually ask for your password, rather it asks for a confirmation code. But in reality, that code is a password reset code that the scammers triggered knowing that the victim would get it. But the website, the phishing website that the scammers directed the user to said that it was for something totally innocuous. Like, "Oh yeah, this is just to close the ticket. Don't worry about it." And the person puts in the code that they just received, not realizing they basically just told Apple, "Yes, I was just trying to reset my password." And then scammers take over your whole account and you can't get it back.

And then the one I touched on before is scammers are now realizing they can use AI generated images that are extremely realistic to basically stage kidnapping scams of family members or even pets, like I described before. Where not even is it anymore where they can clone your voice and pretend to be the person. They can actually send a supposed picture of this person being kidnapped and extort you saying, "We're going to do all these bad things." And the person will obviously be more likely to believe that, especially with AI generated images becoming way more easy to do. With just one picture, I gave an example in my other video, I was able to get an AI image generator to generate somewhat passing photos of me in jail. So just be aware of that and especially warn people who might not realize how fast AI is progressing, because I bet in the near future, they'll even be able to do AI videos in the same way.

Now finally, I do want to mention some general tips you can use to avoid scams, like I mentioned last year. The first one is on iOS, at least, you can actually enable to automatically silence callers that are not in your contact list. This is just a setting that is right in your phone settings. And I actually made a iOS shortcut that makes it easy to toggle this on and off. You can put it right in your control center or whatever to swipe down from. I'll put a link to that in the description. So you literally can just press it from an iOS device and add it yourself. I don't believe there's any equivalent built-in feature on that for Android, but you might be able to find some third-party apps.

Now, some tips for web browsers that I've talked about before. On Google Chrome, consider enabling the "Enhanced Protection" option. This is under privacy and security. This basically makes it so it does a more thorough check on all websites that you visit, and it's a more up-to-date list. So you can read what it does and decide whether or not you prefer the privacy trade-off for that, but it's at least good to be aware of. On Microsoft Edge, there's a similar setting. It's going to be called "Enhance my security on the web." This is under privacy search and services. And I would personally recommend just setting it to Balanced that enables additional protections on websites that you don't visit often, which are probably going to be the ones that are potentially dangerous anyway. There's another setting in Microsoft Edge. It might be on by default but you can check, called "scareware blocker." I would definitely enable that as well.

So at this point, congratulations, you are now way more equipped to handle these scams in particular, and ones that might be variations in the future. And I would be curious to know if you've come across any of these scams, or maybe you're from the future watching this and you came across an interesting variation. We can all talk about that down the comments. And of course, if you enjoyed the video, be sure to give it a big giant thumbs up, it helps out. Now, if you want to keep watching next up, here's a couple of videos you might like. One is my last year's scams to watch out for video. They're still very relevant as well as the video where I talked about the AI generated scams. I go into a lot more detail about those. So I'll put both of those links right there you can click on. Anyway, thanks so much for watching. Be diligent and I'll see you in the next one.