Stay One Step Ahead: Five Recent Scams That Demand Your Attention


Ever since I was a kid, I had a passion for learning as much as I could about money: saving it, preserving it, growing it, and protecting it. Part of protecting it meant understanding how people try to separate you from your money, valuables, or other precious belongings.

That means that while I hate to hear about the latest scams making the rounds and that some people have been taken, I also can’t wait to help warn others to protect them from these scam artists.

Gone are the days when the infamous Nigerian prince would try to scam you with a poorly worded email to entice you to make a deposit to free up that $1 million waiting for you if you only help him solve his legal troubles. That’s child’s play today.

With the help of artificial intelligence, scammers increasingly use seemingly realistic, high-pressure tactics to steal money, access accounts, and lift personal information, without the obvious spelling or grammatical mistakes.

Five of the most recently reported threats involve:

  1. Reservation hijacks
  2. Fake support pop-ups
  3. Malicious CAPTCHA or QR-code traps
  4. Mobile-device takeovers
  5. Multi-factor authentication (MFA) fatigue attacks that pressure users into approving fraudulent login requests.

I’ll discuss each of the above scams and comment on another scam that targets business owners. Call it a “bonus” scam.

1. Reservation hijacks

The current hotel “reservation hijack” scam grew out of unauthorized access to hotel-partner reservation systems and Booking.com-related guest data, not necessarily credit card theft.

In this scam, a traveler has or makes a legitimate hotel or vacation booking and later receives a text, WhatsApp message, email, or phone call that appears to come from the hotel or booking platform. The message may reference real reservation details and warn that the reservation will be canceled unless payment information is verified immediately.

The result can be stolen credit card information, fraudulent charges, or broader account compromise if the victim also provides other identifying details. These schemes work because criminals exploit trust created by a real booking and combine it with urgency and fear of losing the reservation.

Protection starts with independent verification. Never provide card information, passwords, or payment through a link, phone number, or message you receive unexpectedly; instead, open the travel app directly or call the hotel or platform using a verified number from the original reservation or official website.

2. Fake support pop-ups

Another fast-growing scam involves browser pop-ups claiming an unauthorized charge hit an Apple, Amazon, or similar account. The warning may show a fake support number, a charge amount, and language suggesting the account has been hacked and must be verified at once. Amazon, Apple, and other legitimate e-commerce sites don’t use pop-ups to alert you to an account problem.

Of course, these pop-ups are not real account alerts. They are designed to frighten the user into calling a scammer, disclosing account credentials, sharing one-time security codes, paying for bogus support services, or granting remote access to the device.

The safest response is to close the browser tab or force-quit the browser, if necessary, then verify account activity through the official app or by typing the company’s website directly into the browser. A legitimate company will not use a random browser pop-up to demand immediate action through a phone number embedded in the warning.

3. Malicious CAPTCHA and QR-code phishing

At some point, we have all lamented the sometimes frustrating process of trying to find the hidden motorcycles in a grainy picture so you can get to the website you are there to visit. After all, how hard is it to find the picture of a bus in nine squares?

True to form and banking on our attempts to avoid further frustration, scammers are abusing familiar online habits such as CAPTCHA checks and QR-code scanning.

In one variation, a fake CAPTCHA asks the user to press a key combination, open the Microsoft Windows “run” command or terminal application, paste hidden text, and execute a command under the guise of proving they are human.

That command can download malware and give criminals access to passwords, browser sessions, financial logins, and other sensitive data.

A related threat is QR code phishing or “quishing,” in which a fake QR code stuck to a parking meter, flyer, package, or invoice/payment notice sends the victim to a fraudulent login or payment site.

Remember one simple rule: a legitimate CAPTCHA never asks someone to use keyboard shortcuts, paste commands, or run software.

Treat payment or other QR codes cautiously unless they come from a trusted source. Closing the web page, refusing unusual instructions, and manually visiting the known website are the safest moves.

4. Mobile banking Trojans and device takeovers

A malicious link on a phone can be the beginning of a far more serious problem. Sometimes, you don’t even realize that you clicked on a malicious link until it’s too late.

The link may lead to a phishing page or persuade the user to install a malicious app, fake update, or counterfeit financial app that then requests dangerous permissions such as SMS access, notification access, or Android Accessibility access.

Once installed, the malware may read security texts, intercept one-time passcodes, overlay fake login screens, capture credentials, or hide suspicious activity from the user. In practice, this can let criminals bypass SMS-based two-factor authentication and access email, bank, brokerage, payment, or crypto accounts.

The best defense is to install apps only from official stores, keep the phone’s operating system updated, refuse unusual permissions, and never log into financial accounts from a device that may be compromised. If a phone appears infected, stop using it for sensitive logins immediately and shut it off. Then contact financial institutions from a separate, known-clean device, and ask them to temporarily freeze your accounts while you sort things out.

5. Multi-Factor Authentication (MFA) fatigue attacks

Another emerging tactic targets people who already use multi-factor authentication. A criminal who has obtained a compromised password may trigger repeated login prompts on the victim’s phone or computer until the person finally approves one out of annoyance, confusion, or the mistaken belief that it is a legitimate security check. This could come from apps like Microsoft Authenticator, Apple 2FA, or Google Authenticator.

In some cases, the attacker follows up with a fake helpdesk or security call telling the victim to approve the notification to stop the alerts or secure the account. Once the attacker gains approval, they may access email, banking, brokerage, payroll, or other sensitive systems despite MFA.

Never approve an unexpected login prompt. Treat an unrequested MFA push notification like a password request from a stranger: deny it, change the password promptly, and contact the institution or technology provider through a known, trusted channel if you have any questions or concerns.

Bonus Scam: The Online Meeting Invitation

Scammers are increasingly targeting business owners, consultants, and professional-service firms by posing as prospective clients, referral sources, vendors, or investors. They make contact through ordinary channels: email, LinkedIn, website inquiry forms, or phone, and often appear credible because they know enough about the business to ask relevant questions about its products or services.

The contact may provide a name, email address, and phone number, but closer inspection often reveals warning signs: calls go unanswered, the voicemail box is consistently full, details about the prospective engagement remain vague, or the person avoids answering straightforward business questions. The conversation eventually turns to scheduling an online meeting.

The key red flag is an insistence that the meeting occur through their Zoom, Microsoft Teams, GoToMeeting, or other conferencing link. If you offer to host the meeting using your organization’s own account and link, the person may claim they cannot connect, repeatedly encounter supposed technical problems, or press you to use their invitation instead.

The risk is not simply attending a meeting. A malicious link can direct a recipient to a counterfeit sign-in page, prompt the download of a fake “meeting update,” browser extension, document, or remote-access tool, or exploit an unpatched device. The objective may be to steal Microsoft 365, Google Workspace, or financial-account credentials, install malware, or gain remote access to the computer.

A legitimate prospective client may have a platform preference, but should be willing to use a meeting link supplied by your firm or to communicate by telephone instead. Treat insistence on an unfamiliar meeting link, especially when combined with urgency, vague business details, or a request to download software, as a reason to pause.

Best practice: Host the meeting yourself, use your firm’s established conferencing account, and never install software, enter credentials, or grant screen-sharing or remote-control access in response to an unexpected invitation.

A practical defense plan

These scams look different on the surface, but they share the same formula: a believable message, a sense of urgency, and a request to take an unsafe action before the victim has time to think. Whether the prompt says “verify your reservation,” “call support now,” “prove you are human,” or “install this update,” the objective is the same: to obtain credentials, payment information, or device access.

Some simple rules can prevent many losses:

  • Be skeptical of unexpected instructions delivered by text, pop-up, QR code, email, or phone call.
  • Be especially cautious when an unexpected message or caller asks for account information, a password, or a verification code. Sharing a one-time code may be appropriate during a call you initiated or pre-arranged with a trusted firm, but never provide it to an unverified caller, link, pop-up, or message.
  • Never allow remote access to your devices unless you initiated the support request yourself.
  • Treat pressure and urgency as warning signs, not reasons to act faster.
  • If in doubt, ask a friend or loved one for their opinion before taking action

The key to avoiding scams is to pause, slow down, and take a few extra seconds to consider whether that phone call, voice message, text, email, or pop-up is expected given your facts and circumstances at the time.

When in doubt, don’t respond or react through the message. Verify independently using a trusted phone number, app, or website.

Sam H. Fawaz CFP®, CPA, PFS is the President of YDream Financial Services, Inc., a fee-only investment advisory and financial planning firm serving the entire United States. If you would like to review your current investment portfolio or discuss any other retirement, college, tax, or financial planning matters, please don’t hesitate to contact us or visit our website at http://www.ydfs.com. We are a fiduciary financial planning firm that always puts your interests first, with no products to sell. If you are not a client, an initial consultation is complimentary, and there is never any pressure or hidden sales pitch. We begin with a thorough assessment of your unique personal situation. There is no rush and no cookie-cutter approach. Each client’s financial plan and investment objectives are unique.

Leave a comment