This website uses cookies

Read our Privacy policy and Terms of use for more information.


In This Issue

Scam of the Week: The parking meter that steals your card

You pull into a spot, see a QR code on the meter, and scan it to pay for parking. Thirty seconds later, your card number belongs to someone else.

On September 3 the FTC warned that scammers are sticking their own QR codes on parking meters. Scan one and it opens a fake payment page dressed up to look like the city's, built to grab your money, your personal information, or both. Your phone gives you one chance to catch it: the little link preview that appears when your camera reads the code. Scammers count on you not reading it, so look for misspellings or swapped letters before you tap.

The rule: Preview the link before you tap, and if anything looks off, pay at the meter or open your city's official parking app yourself. Already scanned one? Change any passwords you entered, watch your card statement, and report it at ReportFraud.ftc.gov.

A hand scans a QR code sticker on a city parking meter at sunset; headline reads The Parking App That Isn't

RED FLAG DECODER
🚩 The dealership with nothing but five-star reviews

You finally find the exact car you have been hunting, priced to sell, at a dealership with wall-to-wall five-star reviews. The whole lot is fake.

On September 1 the FTC warned that scammers are using AI to copy real dealership websites, logos, photos, and inventory included, then baiting them with rare, hard-to-find cars and glowing fake reviews. The giveaway comes at checkout: they want a wire transfer, up front, for a car you have never seen. And they will always have a reason you can't visit the lot or send an independent inspector.

The rule: Search the dealer's name plus "scam" or "complaint" before you pay a cent. Insist on seeing the car in person or hiring a mobile inspection service, and walk away from anyone who only takes wire transfers. Report fakes at ReportFraud.ftc.gov.

MARKETPLACE SCAM ALERT
The payment company that ran the register for scammers

Ever wonder how a fake tech support line actually charges your credit card? Someone has to run the cash register. This week, the register keeper got the bill.

On September 4 the FTC announced that Nuvei, a payment processor, will pay $4.85 million over charges that it knowingly moved more than $30 million in payments for scammers, including an offshore tech support operation and a company posing as a government tax service. Nuvei is now banned from processing payments for tech support telemarketers at all. The lesson for the rest of us: those scam charges ran through the same card networks as your groceries, which means they can be disputed.

The rule: If you paid a pop-up or cold-call "tech support" service, call your card company and dispute the charge, then have your computer checked by a shop you chose yourself.

INBOX DANGER ZONE
The "Allow" button that hands over your inbox

The message looks like it is from a journalist, an event planner, or even a government official. The login page it opens is Microsoft's or Google's real one. That is exactly what makes this scam work.

On September 1 the FBI warned about consent phishing. Instead of stealing your password, the scammer builds an app and gets you to approve it. You sign in on the genuine login page, then a permission box asks to let the app read your email and files. Click Allow and the scammer is inside. Here is the nasty part: changing your password does not kick them out. Only removing the app in your security settings does.

The rule: Treat any unexpected permission or "approve access" screen as a stop sign. This week, open your Google or Microsoft account security page and remove any connected app you don't recognize.

What to do this Week

  • Pay for parking with your phone? Read the link preview before you tap a scanned QR code, and when in doubt use the meter or the city's official app.

  • Car shopping online? Search the dealer's name plus "scam," see the car in person or send an inspector, and never wire money for a vehicle sight unseen.

  • Ever paid a pop-up "tech support" line? Dispute the charge with your card company. The FTC just showed those charges run through ordinary card processors, and disputes work.

  • See a surprise "Allow access" box? Close it, then take two minutes to remove unfamiliar connected apps in your Google or Microsoft security settings.

  • Spotted a scam? Don't just delete it. Report it at ReportFraud.ftc.gov. Your report is how investigators spot patterns and warn everyone else.

  • Run any suspicious text, email, or pop-up through ScamRank before you act on it. Paste the message in, get a Trust Signal back in seconds. Try it at scamrank.com.

  • Forward this issue to anyone who pays for parking with their phone or is shopping for a used car. Both are on a scammer's list this week.

Until next week,
The ScamBrief Team

ScamBrief is part of the Echo Safe family | Helping families stay ahead of scams | echosafe.co

2 minutes. Your URL. A customer profile worth using.

Most founders can describe their product. They can't describe their customer. Not in a way that actually changes how they sell.

HubSpot for Startups built a free tool to fix that. Paste in your URL, answer a few quick questions, and it generates a structured profile of your best-fit customer. Firmographics, buying triggers, the works.

Takes 2 minutes. No spreadsheet required.

Share ScamBrief

{{rp_personalized_text}}

Or copy and paste this link to others: {{rp_refer_url_no_params}}

Keep Reading