Stay One Step Ahead: Five Recent Scams That Demand Your Attention

Ever since I was a kid, I had a passion for learning as much as I could about money: saving it, preserving it, growing it, and protecting it. Part of protecting it meant understanding how people try to separate you from your money, valuables, or other precious belongings.

That means that while I hate to hear about the latest scams making the rounds and that some people have been taken, I also can’t wait to help warn others to protect them from these scam artists.

Gone are the days when the infamous Nigerian prince would try to scam you with a poorly worded email to entice you to make a deposit to free up that $1 million waiting for you if you only help him solve his legal troubles. That’s child’s play today.

With the help of artificial intelligence, scammers increasingly use seemingly realistic, high-pressure tactics to steal money, access accounts, and lift personal information, without the obvious spelling or grammatical mistakes.

Five of the most recently reported threats involve:

  1. Reservation hijacks
  2. Fake support pop-ups
  3. Malicious CAPTCHA or QR-code traps
  4. Mobile-device takeovers
  5. Multi-factor authentication (MFA) fatigue attacks that pressure users into approving fraudulent login requests.

I’ll discuss each of the above scams and comment on another scam that targets business owners. Call it a “bonus” scam.

1. Reservation hijacks

The current hotel “reservation hijack” scam grew out of unauthorized access to hotel-partner reservation systems and Booking.com-related guest data, not necessarily credit card theft.

In this scam, a traveler has or makes a legitimate hotel or vacation booking and later receives a text, WhatsApp message, email, or phone call that appears to come from the hotel or booking platform. The message may reference real reservation details and warn that the reservation will be canceled unless payment information is verified immediately.

The result can be stolen credit card information, fraudulent charges, or broader account compromise if the victim also provides other identifying details. These schemes work because criminals exploit trust created by a real booking and combine it with urgency and fear of losing the reservation.

Protection starts with independent verification. Never provide card information, passwords, or payment through a link, phone number, or message you receive unexpectedly; instead, open the travel app directly or call the hotel or platform using a verified number from the original reservation or official website.

2. Fake support pop-ups

Another fast-growing scam involves browser pop-ups claiming an unauthorized charge hit an Apple, Amazon, or similar account. The warning may show a fake support number, a charge amount, and language suggesting the account has been hacked and must be verified at once. Amazon, Apple, and other legitimate e-commerce sites don’t use pop-ups to alert you to an account problem.

Of course, these pop-ups are not real account alerts. They are designed to frighten the user into calling a scammer, disclosing account credentials, sharing one-time security codes, paying for bogus support services, or granting remote access to the device.

The safest response is to close the browser tab or force-quit the browser, if necessary, then verify account activity through the official app or by typing the company’s website directly into the browser. A legitimate company will not use a random browser pop-up to demand immediate action through a phone number embedded in the warning.

3. Malicious CAPTCHA and QR-code phishing

At some point, we have all lamented the sometimes frustrating process of trying to find the hidden motorcycles in a grainy picture so you can get to the website you are there to visit. After all, how hard is it to find the picture of a bus in nine squares?

True to form and banking on our attempts to avoid further frustration, scammers are abusing familiar online habits such as CAPTCHA checks and QR-code scanning.

In one variation, a fake CAPTCHA asks the user to press a key combination, open the Microsoft Windows “run” command or terminal application, paste hidden text, and execute a command under the guise of proving they are human.

That command can download malware and give criminals access to passwords, browser sessions, financial logins, and other sensitive data.

A related threat is QR code phishing or “quishing,” in which a fake QR code stuck to a parking meter, flyer, package, or invoice/payment notice sends the victim to a fraudulent login or payment site.

Remember one simple rule: a legitimate CAPTCHA never asks someone to use keyboard shortcuts, paste commands, or run software.

Treat payment or other QR codes cautiously unless they come from a trusted source. Closing the web page, refusing unusual instructions, and manually visiting the known website are the safest moves.

4. Mobile banking Trojans and device takeovers

A malicious link on a phone can be the beginning of a far more serious problem. Sometimes, you don’t even realize that you clicked on a malicious link until it’s too late.

The link may lead to a phishing page or persuade the user to install a malicious app, fake update, or counterfeit financial app that then requests dangerous permissions such as SMS access, notification access, or Android Accessibility access.

Once installed, the malware may read security texts, intercept one-time passcodes, overlay fake login screens, capture credentials, or hide suspicious activity from the user. In practice, this can let criminals bypass SMS-based two-factor authentication and access email, bank, brokerage, payment, or crypto accounts.

The best defense is to install apps only from official stores, keep the phone’s operating system updated, refuse unusual permissions, and never log into financial accounts from a device that may be compromised. If a phone appears infected, stop using it for sensitive logins immediately and shut it off. Then contact financial institutions from a separate, known-clean device, and ask them to temporarily freeze your accounts while you sort things out.

5. Multi-Factor Authentication (MFA) fatigue attacks

Another emerging tactic targets people who already use multi-factor authentication. A criminal who has obtained a compromised password may trigger repeated login prompts on the victim’s phone or computer until the person finally approves one out of annoyance, confusion, or the mistaken belief that it is a legitimate security check. This could come from apps like Microsoft Authenticator, Apple 2FA, or Google Authenticator.

In some cases, the attacker follows up with a fake helpdesk or security call telling the victim to approve the notification to stop the alerts or secure the account. Once the attacker gains approval, they may access email, banking, brokerage, payroll, or other sensitive systems despite MFA.

Never approve an unexpected login prompt. Treat an unrequested MFA push notification like a password request from a stranger: deny it, change the password promptly, and contact the institution or technology provider through a known, trusted channel if you have any questions or concerns.

Bonus Scam: The Online Meeting Invitation

Scammers are increasingly targeting business owners, consultants, and professional-service firms by posing as prospective clients, referral sources, vendors, or investors. They make contact through ordinary channels: email, LinkedIn, website inquiry forms, or phone, and often appear credible because they know enough about the business to ask relevant questions about its products or services.

The contact may provide a name, email address, and phone number, but closer inspection often reveals warning signs: calls go unanswered, the voicemail box is consistently full, details about the prospective engagement remain vague, or the person avoids answering straightforward business questions. The conversation eventually turns to scheduling an online meeting.

The key red flag is an insistence that the meeting occur through their Zoom, Microsoft Teams, GoToMeeting, or other conferencing link. If you offer to host the meeting using your organization’s own account and link, the person may claim they cannot connect, repeatedly encounter supposed technical problems, or press you to use their invitation instead.

The risk is not simply attending a meeting. A malicious link can direct a recipient to a counterfeit sign-in page, prompt the download of a fake “meeting update,” browser extension, document, or remote-access tool, or exploit an unpatched device. The objective may be to steal Microsoft 365, Google Workspace, or financial-account credentials, install malware, or gain remote access to the computer.

A legitimate prospective client may have a platform preference, but should be willing to use a meeting link supplied by your firm or to communicate by telephone instead. Treat insistence on an unfamiliar meeting link, especially when combined with urgency, vague business details, or a request to download software, as a reason to pause.

Best practice: Host the meeting yourself, use your firm’s established conferencing account, and never install software, enter credentials, or grant screen-sharing or remote-control access in response to an unexpected invitation.

A practical defense plan

These scams look different on the surface, but they share the same formula: a believable message, a sense of urgency, and a request to take an unsafe action before the victim has time to think. Whether the prompt says “verify your reservation,” “call support now,” “prove you are human,” or “install this update,” the objective is the same: to obtain credentials, payment information, or device access.

Some simple rules can prevent many losses:

  • Be skeptical of unexpected instructions delivered by text, pop-up, QR code, email, or phone call.
  • Be especially cautious when an unexpected message or caller asks for account information, a password, or a verification code. Sharing a one-time code may be appropriate during a call you initiated or pre-arranged with a trusted firm, but never provide it to an unverified caller, link, pop-up, or message.
  • Never allow remote access to your devices unless you initiated the support request yourself.
  • Treat pressure and urgency as warning signs, not reasons to act faster.
  • If in doubt, ask a friend or loved one for their opinion before taking action

The key to avoiding scams is to pause, slow down, and take a few extra seconds to consider whether that phone call, voice message, text, email, or pop-up is expected given your facts and circumstances at the time.

When in doubt, don’t respond or react through the message. Verify independently using a trusted phone number, app, or website.

Sam H. Fawaz CFP®, CPA, PFS is the President of YDream Financial Services, Inc., a fee-only investment advisory and financial planning firm serving the entire United States. If you would like to review your current investment portfolio or discuss any other retirement, college, tax, or financial planning matters, please don’t hesitate to contact us or visit our website at http://www.ydfs.com. We are a fiduciary financial planning firm that always puts your interests first, with no products to sell. If you are not a client, an initial consultation is complimentary, and there is never any pressure or hidden sales pitch. We begin with a thorough assessment of your unique personal situation. There is no rush and no cookie-cutter approach. Each client’s financial plan and investment objectives are unique.

Investment Scams Are Getting Smarter-How to Protect Yourself

Here’s How Retirees, Active Investors, and Traders Can Stay Protected

You’d think that after decades in the financial services industry, I would have heard of most of the investment scams out there. First in the internet age, and now in the age of artificial intelligence (AI), there are few weeks that pass without me hearing or reading about someone who was scammed out of thousands, if not hundreds of thousands of dollars. I’ve even heard from clients and relatives of clients who have been victims of clever social engineering and grooming. It breaks my heart when I hear about them losing money, especially when there’s nothing they or I can do to help.

Investment scams today are more sophisticated, more personalized, and more convincing than ever. Fraudsters now use impersonation, social media, text messages, and even AI-generated content to create trust before they ever mention an investment. The result is a steady stream of investors being drawn into schemes that often end in pump-and-dump losses, frozen accounts, emotional distress, and, in some cases, follow-on recovery scams.

For retirees, the danger is especially serious because the stakes are often long-term savings and income. For active investors, the risk is different but just as real: scammers know how to mimic market language, trading ideas, and “hot” opportunities well enough to sound credible. Traders face yet another layer of risk because scams often borrow the language of momentum, catalysts, and short-term opportunity.

How these scams begin

Many of today’s investment scams start in a way that seems harmless. You may receive a misdirected text from an unknown number, a friendly message on social media, or an invitation to join an investment group. The message may not even mention investing at first. It may simply ask, “Are you home?” or make another innocent-sounding comment designed to get you to respond.

Once you reply, the scammer begins building a relationship. Over time, the conversation becomes more familiar and more personal. Then, almost naturally, the topic turns to investing. The scammer might mention a relative who trades foreign stocks, a special market opportunity, or a group that shares profitable ideas. The goal is not to make the first message look suspicious. The goal is to create a long enough interaction that trust develops before the pitch arrives.

That trust-building phase is critical. Scammers know that people are far more likely to ignore a warning sign once they feel they know the person on the other end of the conversation. This is why many of these frauds are less about one dramatic lie and more about a slow, carefully managed relationship. It is not surprising that older adults who are lonely, recently widowed, or worried about outliving their savings can be especially vulnerable.

Why retirees are targeted

Retirees are often targeted because they tend to be careful, financially responsible, and interested in protecting capital or generating income. That makes promises of steady returns or “safe” opportunities especially appealing. Fraudsters know how to dress up a pitch so it sounds like a conservative income strategy rather than a speculative gamble.

The language matters. If someone promises guaranteed returns, “risk-free” profits, or unusually consistent gains, that should be treated as a warning sign. No legitimate investment is free of risk, and any claim that something is safe, certain, or protected from loss deserves immediate skepticism.

Retirees can also be more vulnerable to secrecy and urgency. A scammer may say the opportunity is exclusive, limited, or only available for a short time. That kind of pressure is designed to prevent a second opinion from a spouse, adult child, advisor, or friend. The less time you have to think, the more likely you are to act emotionally. Some scammers insist that sharing the information with their spouse or significant other would disqualify them from the investment scam; this is a big red flag.

Why active investors need to be careful

Active investors are not immune just because they understand the markets. In fact, scammers often use market language to appear legitimate. They may talk about small-cap stocks, catalysts, foreign issuers, or breakout potential in ways that sound familiar to people who follow the market closely. They may even reference themes like FDA approvals, short squeezes, or momentum moves.

The danger comes when the story becomes more important than the fundamentals. Pump-and-dump schemes typically center on thinly traded stocks that are easy to move with hype. Fraudsters promote the stock aggressively, drive attention and buying interest, then sell their own shares into the strength. Once the promotional pressure fades, the stock can fall sharply and become difficult to exit.

Active investors should also be cautious with social media groups that promise hot tips or “research communities.” These are often just marketing funnels leading people into private chat rooms where the real manipulation happens. If an opportunity is being framed as an inside track or a limited-circle advantage, that is exactly the kind of setup scammers use to create urgency and exclusivity.

A note for traders

Traders can be especially vulnerable because scams often borrow the language and tempo of short-term trading. A message may talk about a breakout setup, a catalyst trade, a pre-news move, or an “early entry” before the crowd finds out. That language sounds familiar to traders, which is exactly why it works.

The danger is that the scam is not really about trade selection. It is about control of the narrative. Fraudsters may tell you which ticker to buy, when to buy it, and even ask for screenshots of your order confirmation so they can keep the story moving. In some cases, they may add you to a chat room with other people who appear to be active traders, creating the illusion of a real trading community. It’s not.

For traders, the red flags are often behavioral rather than analytical. Be careful if a supposed opportunity requires secrecy, moves exclusively through encrypted apps, or pushes low-liquidity names with a lot of hype and no verifiable research. A real trading idea can withstand scrutiny. A scam depends on speed, emotion, and group pressure.

Traders should also be wary of any “mentor,” signal service, or chat group that claims unusually high consistency with very little drawdown. That is not how real trading works. No one has a perfect system, and anyone promising one is selling something other than market insight. Some might call it snake oil.

Social media, impersonation, and AI

One of the most troubling developments is how well scammers now impersonate trusted names. They may use a celebrity face, a well-known market commentator, or a fake representative from a legitimate firm to create instant credibility. The image alone can be enough to lower a person’s guard before the details are examined.

Artificial intelligence has made the problem worse. Scammers can now generate polished messages, remove obvious grammar mistakes, clone voices, and create realistic-looking images or video. That means the old warning signs, like awkward language or obvious typos, are no longer enough by themselves. A scam can now look and sound much more professional than it did a few years ago.

This is why investors should pay more attention to the structure of the pitch than the polish of the presentation. If the message is built around secrecy, urgency, guaranteed returns, or a move to an encrypted app, the presentation quality does not matter. The red flags are already there.

The biggest warning signs

The same warning signs appear again and again across investment scams. The more of these you see, the more cautious you should become.

Watch for:

  • Guaranteed or “risk-free” returns.
  • Pressure to act immediately.
  • Requests to keep the opportunity secret.
  • Unsolicited investment offers.
  • Pushes to move conversations to WhatsApp, Telegram, WeChat, or another encrypted app.
  • Requests for personal information, money, or cryptocurrency before verification.
  • Celebrity endorsements that cannot be confirmed independently.
  • Advance fees to recover money.

If a stranger is pushing an investment, asking for secrecy, and moving the conversation off the platform, that combination alone should stop the process. You do not need to prove it is a scam in order to step away.

How to verify before you act

The best defense is to verify everything independently. Do not use the contact information, click on the links, or call the phone number contained in the message itself. Go directly to the firm’s website by manually typing it in, via a known app, or a trusted database to confirm credentials and contact details.

For financial professionals and firms, check FINRA BrokerCheck, the SEC’s Investment Adviser Public Disclosure database, and your state securities regulator. If the person or firm cannot be verified, or if the details do not match what you were told, treat that as a serious warning.

It is also wise to confirm legitimacy by calling a known number from an account statement or official website. If a supposed firm representative asks you to click a link in a text, download a new app, or send sensitive information through an unofficial channel, stop and verify first.

If a stranger insists on using their own Zoom or Teams link, be cautious: it could expose your device to malware that may give criminals access to your private information, passwords, or financial accounts. If you cannot reach the person directly through a U.S. phone number, or if their voicemail is always full and their messages keep steering you to a website, do not proceed.

Why talking to someone helps

One of the most effective protections is also one of the simplest: tell someone else you know and trust before you act. Scam artists depend on emotion, speed, and isolation. They want you to decide quickly and privately. The moment you explain the opportunity to a trusted person, you slow the process down.

That pause is powerful. It gives you time to think more clearly, and it gives someone else a chance to hear what you may be overlooking. Many bad decisions sound reasonable in your own head until you say them out loud.

This matters especially for retirees making decisions about income, capital preservation, or distribution strategy. It also matters for active investors and traders who may feel pressure to move fast on what looks like a market opportunity. Good investing is not just about being informed. It is about having a disciplined process.

What to do if you’ve been targeted

If you suspect a scam, gather documentation immediately. Save messages, screenshots, websites, account details, transaction records, and any names or numbers used in the conversation. If cryptocurrency is involved, preserve wallet addresses and transaction details as well.

Then report it as quickly as possible. Notify your broker or financial institution, the SEC, FINRA, your state securities regulator, and the FBI’s Internet Crime Complaint Center. If money has already been sent, timely reporting may improve the chances of tracing the fraud and helping regulators identify related cases.

Be especially careful with follow-on messages that claim they can help you recover your money. Recovery scams often target people who have already been victimized and are emotionally exhausted. If someone asks for a retainer, processing fee, or other upfront payment to return your funds, that is a major red flag.

Final perspective

The biggest mistake many investors make is assuming scams only work on careless people. In reality, these schemes are designed to exploit normal human reactions: trust, curiosity, urgency, fear, and the desire not to miss out. That is why even experienced retirees, active investors, and traders can be targeted successfully. Some well-seasoned financial advisors have been targeted and victimized.

The solution is not paranoia. It is a process. Verify independently, slow down, avoid isolation, and never let secrecy or pressure drive an investment decision. If an opportunity is real, it will still be there after you check it carefully.

Of course, the old adage applies and is always worth remembering:

“If something seems too good to be true, it probably is.”

Sam H. Fawaz CFP®, CPA, PFS is the President of YDream Financial Services, Inc., a fee-only investment advisory and financial planning firm serving the entire United States. If you would like to review your current investment portfolio or discuss any other retirement, college, tax, or financial planning matters, please don’t hesitate to contact us or visit our website at http://www.ydfs.com. We are a fiduciary financial planning firm that always puts your interests first, with no products to sell. If you are not a client, an initial consultation is complimentary, and there is never any pressure or hidden sales pitch. We begin with a thorough assessment of your unique personal situation. There is no rush and no cookie-cutter approach. Each client’s financial plan and investment objectives are unique.

Source: American Association of Individual Investors

Scam Alert: Don’t Answer the Call or Text

Fraudsters are texting fake “Apple Pay fraud alerts” to trick people into authorizing their own transfers—making it almost impossible to recover any lost money.

Forbes reported that Apple is warning iPhone users about a surge in scam calls and texts that impersonate Apple, Apple Support, or Apple Pay security. These messages often claim there’s suspicious activity on your account, a blocked Apple Pay transaction, or a problem that needs “urgent” attention, and then push you to click a link or call a phone number where scammers try to steal passwords, verification codes, or financial details.

Apple’s guidance is simple: if you receive an unexpected call or message claiming to be from Apple, do not answer, do not call back any number in the message, and do not click links or share any codes or passwords. Instead, hang up and contact Apple only through official channels you find yourself (the built‑in Support app, apple.com, or the phone number on Apple’s website), and forward suspicious messages to reportphishing@apple.com.

To reduce the incidence of fake messages reaching your eyes, on your iPhone (sorry, Android users, I’m no help here, but I imagine they’re targeting Google Pay users as well):

1) Go to Settings → Apps → Messages → Unknown Senders and turn on “Screen Unknown Senders”.

2) Enable Filter Spam: Under Text Message Filter, choose Text Message Filter or another spam filtering service you might already subscribe to.

3) Never click suspicious links, even if they look like Apple or your bank/brokerage firm.

4) Keep your iPhone operating system (iOS) up to date to ensure you have the latest security updates: Settings → General → Software Update and turn on Automatic Updates if they’re not already on.

Source: Apple Warns All iPhone Users—Do Not Answer These Calls And Texts-Forbes Article

Sam H. Fawaz CFP®, CPA, PFS is the President of YDream Financial Services, Inc., a fee-only investment advisory and financial planning firm serving the entire United States. If you would like to review your current investment portfolio or discuss any other retirement, college, tax, or financial planning matters, please don’t hesitate to contact us or visit our website at http://www.ydfs.com. We are a fiduciary financial planning firm that always puts your interests first, with no products to sell. If you are not a client, an initial consultation is complimentary, and there is never any pressure or hidden sales pitch. We begin with a thorough assessment of your unique personal situation. There is no rush and no cookie-cutter approach. Each client’s financial plan and investment objectives are unique.