All reports
12 published reports
A scam email impersonating a company called 'Candy TV' falsely informs the recipient they have been shortlisted for a Remote Customer Care Representative role. The email directs the recipient to purchase or access a book from a suspicious third-party website as supposed preparation for an assessment. This is a classic job scam pattern where fraudsters exploit genuine job seekers — the use of a free Gmail address to represent a company's PR or recruitment team is a strong red flag.
Fraudsters are impersonating Hilton Hotels & Resorts UK to trick job applicants into submitting sensitive identity documents including passport copies and degree certificates under the guise of a recruitment process. The 24-hour deadline creates artificial urgency to prevent the victim from verifying the legitimacy of the request. Legitimate hotel chains do not conduct interviews entirely by email or request passport scans before any verified interview stage.
A fraudulent recruitment email impersonating a company called Labmentix invites unsuspecting recipients to an internship orientation session they did not apply for. The scam progresses to an online meeting where candidates are pressured to pay an undisclosed fee to be considered, a classic advance-fee job scam tactic. Victims who question the legitimacy of the process are silenced and removed from the meeting.
A scammer posing as a Jumia representative contacted the victim via WhatsApp offering to pay between ₦50,000 and ₦150,000 per day for simple product screenshot tasks. This is a well-known 'task scam' or 'brushing scam' where initial small payments are made to build trust, before victims are asked to pay upfront fees or deposits to unlock larger earnings they never receive. The use of a legitimate Jumia product URL is a deliberate tactic to appear credible.
An unknown Facebook account using the display name 'Obi Favor' sent an unsolicited message claiming it was their birthday and offering a 20GB mobile data giveaway in exchange for the recipient's phone number. This is a well-documented social engineering tactic used to harvest phone numbers for follow-on fraud including smishing, vishing, and OTP interception. The target correctly declined and shared no personal information.
A fraudster operating under the username 'Coachfavour655' is promoting a fake investment scheme called 'Afrinvestment Platform Services', claiming it can multiply money by 3x within one hour using proprietary trading software. The scammer requests the victim's payment and account number. After extracting the information needed, the scammer blocked the victim — a classic advance-fee or account-harvest fraud pattern.
This email pretends to be from the Federal Road Safety Corps (FRSC) of Nigeria, claiming the recipient has a recruitment account that needs to be activated. It was sent via SendGrid but failed email authentication, meaning the sender could not be verified as the real FRSC. The 24-hour expiry pressure is a classic social engineering tactic to rush the victim into clicking a potentially malicious link.
The victim received a phone call from scammers who already had some of their personal details and used a fake parcel delivery pretext to build trust. The callers then attempted to trick the victim into reading out a one-time passcode (OTP), which was actually a WhatsApp login verification code. The victim recognised the scam, hung up, and used WhatsApp's built-in protection to block the unauthorised login attempt.
A victim signed up for a free trial on a website called 'Creative Fabrica Studio AI Video Generator', entering card details as required. Immediately after sign-up, the cancellation option was disabled and multiple unauthorised transactions began across different currencies (EUR, USD, PKR), resulting in losses exceeding USD 300 within approximately 90 minutes. The victim was only able to stop the fraud by calling their bank's emergency helpline to block the card.
This is a fraudulent text message (smishing) that poses as a loan offer to trick recipients into clicking a malicious link. The link is reported to contain malware, meaning clicking it could compromise the victim's device or steal personal information. This is a common smishing tactic combining a financial incentive with a malware payload.
This is a phishing email impersonating NatWest bank, designed to trick recipients into clicking a fake link and handing over their banking login credentials. It uses urgency, a fabricated account suspension threat, and a convincing NatWest logo to appear legitimate. The sending domain and login link are both fraudulent and unaffiliated with the real NatWest bank.
This message pretends to be from United Bank for Africa (UBA), claiming the recipient's account has been flagged for suspicious activity. It pressures the reader to click a fake link to 'verify' their identity, under threat of account suspension. The link leads to a lookalike website designed to steal banking login credentials.
Page 1 of 1 · 12 total reports