Stay One Step Ahead: Five Recent Scams That Demand Your Attention

Ever since I was a kid, I had a passion for learning as much as I could about money: saving it, preserving it, growing it, and protecting it. Part of protecting it meant understanding how people try to separate you from your money, valuables, or other precious belongings.

That means that while I hate to hear about the latest scams making the rounds and that some people have been taken, I also can’t wait to help warn others to protect them from these scam artists.

Gone are the days when the infamous Nigerian prince would try to scam you with a poorly worded email to entice you to make a deposit to free up that $1 million waiting for you if you only help him solve his legal troubles. That’s child’s play today.

With the help of artificial intelligence, scammers increasingly use seemingly realistic, high-pressure tactics to steal money, access accounts, and lift personal information, without the obvious spelling or grammatical mistakes.

Five of the most recently reported threats involve:

  1. Reservation hijacks
  2. Fake support pop-ups
  3. Malicious CAPTCHA or QR-code traps
  4. Mobile-device takeovers
  5. Multi-factor authentication (MFA) fatigue attacks that pressure users into approving fraudulent login requests.

I’ll discuss each of the above scams and comment on another scam that targets business owners. Call it a “bonus” scam.

1. Reservation hijacks

The current hotel “reservation hijack” scam grew out of unauthorized access to hotel-partner reservation systems and Booking.com-related guest data, not necessarily credit card theft.

In this scam, a traveler has or makes a legitimate hotel or vacation booking and later receives a text, WhatsApp message, email, or phone call that appears to come from the hotel or booking platform. The message may reference real reservation details and warn that the reservation will be canceled unless payment information is verified immediately.

The result can be stolen credit card information, fraudulent charges, or broader account compromise if the victim also provides other identifying details. These schemes work because criminals exploit trust created by a real booking and combine it with urgency and fear of losing the reservation.

Protection starts with independent verification. Never provide card information, passwords, or payment through a link, phone number, or message you receive unexpectedly; instead, open the travel app directly or call the hotel or platform using a verified number from the original reservation or official website.

2. Fake support pop-ups

Another fast-growing scam involves browser pop-ups claiming an unauthorized charge hit an Apple, Amazon, or similar account. The warning may show a fake support number, a charge amount, and language suggesting the account has been hacked and must be verified at once. Amazon, Apple, and other legitimate e-commerce sites don’t use pop-ups to alert you to an account problem.

Of course, these pop-ups are not real account alerts. They are designed to frighten the user into calling a scammer, disclosing account credentials, sharing one-time security codes, paying for bogus support services, or granting remote access to the device.

The safest response is to close the browser tab or force-quit the browser, if necessary, then verify account activity through the official app or by typing the company’s website directly into the browser. A legitimate company will not use a random browser pop-up to demand immediate action through a phone number embedded in the warning.

3. Malicious CAPTCHA and QR-code phishing

At some point, we have all lamented the sometimes frustrating process of trying to find the hidden motorcycles in a grainy picture so you can get to the website you are there to visit. After all, how hard is it to find the picture of a bus in nine squares?

True to form and banking on our attempts to avoid further frustration, scammers are abusing familiar online habits such as CAPTCHA checks and QR-code scanning.

In one variation, a fake CAPTCHA asks the user to press a key combination, open the Microsoft Windows “run” command or terminal application, paste hidden text, and execute a command under the guise of proving they are human.

That command can download malware and give criminals access to passwords, browser sessions, financial logins, and other sensitive data.

A related threat is QR code phishing or “quishing,” in which a fake QR code stuck to a parking meter, flyer, package, or invoice/payment notice sends the victim to a fraudulent login or payment site.

Remember one simple rule: a legitimate CAPTCHA never asks someone to use keyboard shortcuts, paste commands, or run software.

Treat payment or other QR codes cautiously unless they come from a trusted source. Closing the web page, refusing unusual instructions, and manually visiting the known website are the safest moves.

4. Mobile banking Trojans and device takeovers

A malicious link on a phone can be the beginning of a far more serious problem. Sometimes, you don’t even realize that you clicked on a malicious link until it’s too late.

The link may lead to a phishing page or persuade the user to install a malicious app, fake update, or counterfeit financial app that then requests dangerous permissions such as SMS access, notification access, or Android Accessibility access.

Once installed, the malware may read security texts, intercept one-time passcodes, overlay fake login screens, capture credentials, or hide suspicious activity from the user. In practice, this can let criminals bypass SMS-based two-factor authentication and access email, bank, brokerage, payment, or crypto accounts.

The best defense is to install apps only from official stores, keep the phone’s operating system updated, refuse unusual permissions, and never log into financial accounts from a device that may be compromised. If a phone appears infected, stop using it for sensitive logins immediately and shut it off. Then contact financial institutions from a separate, known-clean device, and ask them to temporarily freeze your accounts while you sort things out.

5. Multi-Factor Authentication (MFA) fatigue attacks

Another emerging tactic targets people who already use multi-factor authentication. A criminal who has obtained a compromised password may trigger repeated login prompts on the victim’s phone or computer until the person finally approves one out of annoyance, confusion, or the mistaken belief that it is a legitimate security check. This could come from apps like Microsoft Authenticator, Apple 2FA, or Google Authenticator.

In some cases, the attacker follows up with a fake helpdesk or security call telling the victim to approve the notification to stop the alerts or secure the account. Once the attacker gains approval, they may access email, banking, brokerage, payroll, or other sensitive systems despite MFA.

Never approve an unexpected login prompt. Treat an unrequested MFA push notification like a password request from a stranger: deny it, change the password promptly, and contact the institution or technology provider through a known, trusted channel if you have any questions or concerns.

Bonus Scam: The Online Meeting Invitation

Scammers are increasingly targeting business owners, consultants, and professional-service firms by posing as prospective clients, referral sources, vendors, or investors. They make contact through ordinary channels: email, LinkedIn, website inquiry forms, or phone, and often appear credible because they know enough about the business to ask relevant questions about its products or services.

The contact may provide a name, email address, and phone number, but closer inspection often reveals warning signs: calls go unanswered, the voicemail box is consistently full, details about the prospective engagement remain vague, or the person avoids answering straightforward business questions. The conversation eventually turns to scheduling an online meeting.

The key red flag is an insistence that the meeting occur through their Zoom, Microsoft Teams, GoToMeeting, or other conferencing link. If you offer to host the meeting using your organization’s own account and link, the person may claim they cannot connect, repeatedly encounter supposed technical problems, or press you to use their invitation instead.

The risk is not simply attending a meeting. A malicious link can direct a recipient to a counterfeit sign-in page, prompt the download of a fake “meeting update,” browser extension, document, or remote-access tool, or exploit an unpatched device. The objective may be to steal Microsoft 365, Google Workspace, or financial-account credentials, install malware, or gain remote access to the computer.

A legitimate prospective client may have a platform preference, but should be willing to use a meeting link supplied by your firm or to communicate by telephone instead. Treat insistence on an unfamiliar meeting link, especially when combined with urgency, vague business details, or a request to download software, as a reason to pause.

Best practice: Host the meeting yourself, use your firm’s established conferencing account, and never install software, enter credentials, or grant screen-sharing or remote-control access in response to an unexpected invitation.

A practical defense plan

These scams look different on the surface, but they share the same formula: a believable message, a sense of urgency, and a request to take an unsafe action before the victim has time to think. Whether the prompt says “verify your reservation,” “call support now,” “prove you are human,” or “install this update,” the objective is the same: to obtain credentials, payment information, or device access.

Some simple rules can prevent many losses:

  • Be skeptical of unexpected instructions delivered by text, pop-up, QR code, email, or phone call.
  • Be especially cautious when an unexpected message or caller asks for account information, a password, or a verification code. Sharing a one-time code may be appropriate during a call you initiated or pre-arranged with a trusted firm, but never provide it to an unverified caller, link, pop-up, or message.
  • Never allow remote access to your devices unless you initiated the support request yourself.
  • Treat pressure and urgency as warning signs, not reasons to act faster.
  • If in doubt, ask a friend or loved one for their opinion before taking action

The key to avoiding scams is to pause, slow down, and take a few extra seconds to consider whether that phone call, voice message, text, email, or pop-up is expected given your facts and circumstances at the time.

When in doubt, don’t respond or react through the message. Verify independently using a trusted phone number, app, or website.

Sam H. Fawaz CFP®, CPA, PFS is the President of YDream Financial Services, Inc., a fee-only investment advisory and financial planning firm serving the entire United States. If you would like to review your current investment portfolio or discuss any other retirement, college, tax, or financial planning matters, please don’t hesitate to contact us or visit our website at http://www.ydfs.com. We are a fiduciary financial planning firm that always puts your interests first, with no products to sell. If you are not a client, an initial consultation is complimentary, and there is never any pressure or hidden sales pitch. We begin with a thorough assessment of your unique personal situation. There is no rush and no cookie-cutter approach. Each client’s financial plan and investment objectives are unique.

Scam Alert: Don’t Answer the Call or Text

Fraudsters are texting fake “Apple Pay fraud alerts” to trick people into authorizing their own transfers—making it almost impossible to recover any lost money.

Forbes reported that Apple is warning iPhone users about a surge in scam calls and texts that impersonate Apple, Apple Support, or Apple Pay security. These messages often claim there’s suspicious activity on your account, a blocked Apple Pay transaction, or a problem that needs “urgent” attention, and then push you to click a link or call a phone number where scammers try to steal passwords, verification codes, or financial details.

Apple’s guidance is simple: if you receive an unexpected call or message claiming to be from Apple, do not answer, do not call back any number in the message, and do not click links or share any codes or passwords. Instead, hang up and contact Apple only through official channels you find yourself (the built‑in Support app, apple.com, or the phone number on Apple’s website), and forward suspicious messages to reportphishing@apple.com.

To reduce the incidence of fake messages reaching your eyes, on your iPhone (sorry, Android users, I’m no help here, but I imagine they’re targeting Google Pay users as well):

1) Go to Settings → Apps → Messages → Unknown Senders and turn on “Screen Unknown Senders”.

2) Enable Filter Spam: Under Text Message Filter, choose Text Message Filter or another spam filtering service you might already subscribe to.

3) Never click suspicious links, even if they look like Apple or your bank/brokerage firm.

4) Keep your iPhone operating system (iOS) up to date to ensure you have the latest security updates: Settings → General → Software Update and turn on Automatic Updates if they’re not already on.

Source: Apple Warns All iPhone Users—Do Not Answer These Calls And Texts-Forbes Article

Sam H. Fawaz CFP®, CPA, PFS is the President of YDream Financial Services, Inc., a fee-only investment advisory and financial planning firm serving the entire United States. If you would like to review your current investment portfolio or discuss any other retirement, college, tax, or financial planning matters, please don’t hesitate to contact us or visit our website at http://www.ydfs.com. We are a fiduciary financial planning firm that always puts your interests first, with no products to sell. If you are not a client, an initial consultation is complimentary, and there is never any pressure or hidden sales pitch. We begin with a thorough assessment of your unique personal situation. There is no rush and no cookie-cutter approach. Each client’s financial plan and investment objectives are unique.

In The Land of Password Management, RoboForm is King

Over the years, I’ve made tens of “Cool Tools” presentations (and the like) around the country and the list of tools has varied widely as time went by.  While many of the tools make it into my presentations once or twice within a span of a few months, one staple that continues to garner the largest audience interest is an inexpensive password manager and form filler known as RoboForm.  It continues to surprise me how many people still aren’t using one of these great productivity boosters.  If you’re not taking advantage of a password manager in this internet age, let me tell you that you’re wasting precious time and probably taking unnecessary security risks.

I’ve been a user of RoboForm for several years now.  In fact, I first reviewed and raved about RoboForm in an article published a few years ago.  RoboForm remains my number one must-have application on every computing platform I own or use regularly and it is the first application I install when I move to a new operating system or get a new device.  While there are several password managers out there, both free and paid versions, nothing I’ve tried comes close to the versatility and power of RoboForm.  It cannot be ignored that, in this day and age of key loggers and identity theft, having a secure repository of personal information is essential.

I decided to review the current beta 7.0 version of RoboForm since it’s the first real upgrade in recent years.  Actually, it’s not a major upgrade; it’s more of a renovation.  I’ve been using the latest version for a couple of months now and I like the new features and enhancements.

Background

For those of you that are new to password management programs and form fillers, here’s a little background on their capabilities:

As time goes by, we accumulate more and more user ID’s, passwords, secret questions and phrases, software installation keys, personal identification information, credit card and bank account numbers, website addresses, secret notes, etc. (need I say more?), all of which we need to store and retrieve securely.  While a variety of methods have been devised and employed to accomplish this task, most are barely secure and totally inconvenient or incompatible with the wide variety of devices and platforms currently available.  RoboForm aims to be your single and most secure repository to store all this information within (yet another) master password protected and encrypted database.  Think of RoboForm as your hardened safe to store all this info which can only be opened with the correct combination (i.e., the master password).

In addition, many applications, web sites and other secure network gateways require us to change our passwords periodically and utilize strong replacements with a variety of formats and requirements.  Thinking of and remembering these changing passwords can drive one crazy and, as a result, many of us resort to easy-to-hack passwords and storage methods just to keep us sane.  RoboForm steps up here with a powerful password generator that meets a variety of criteria required by the site or the application.

Getting Started and Working with RoboForm

Downloading and installing RoboForm version 6.x (a free trial version good for storing up to 10 passwords is available at http://www.roboform.com) is quick and quite easy.  Whether you’re using Internet Explorer, Firefox, Google Chrome or one of the many available mobile platforms, RoboForm integrates nicely and stands ready to store your user ID’s, passwords and other personal data each time you access a site.  The only thing you need to get started is to specify the master password to be used to lock all of your secret information once RoboForm starts memorizing.  Naturally, with a variety of military strength encryption schemes (no fewer than five encryption algorithms are available) to secure your database, you don’t want to forget the master password once you’ve specified it.  Even RoboForm technical support will not be able to figure out your password if you forget it.  And of course, your master password should be very strong and long because it unlocks your most valuable data: your personal information and passwords.  RoboForm stores all of this securely and locally, unless you decide to use RoboForm online (discussed below.)

Visit a web site, enter your user ID and password and, depending on the options you specify, RoboForm will pop up and offer to store them in what’s called a “passcard.”  The passcard is capable of storing numerous fields.  So, if you need to enter more than just two pieces of information to log in, RoboForm can handle the job.  If you are setting up your online access for the first time, RoboForm helps you generate and store a password based on a variety of security criteria, characters, length, etc.  Thereafter, whenever you visit that site, RoboForm will offer to fill in the user ID, password and other information assuming that you’ve unlocked the database with the master password.  One available setting determines how much time you have before the master password “times out” and is required to be re-entered.  This way you don’t have to enter it each time you summon RoboForm to populate your login information or web-based form.  Since you don’t have to subsequently type in the secure information, key loggers installed without your knowledge cannot capture your valuable data.

The other powerful capability of RoboForm is an online form filler.  When you set up RoboForm, you have the option to set up profiles with your name, address, phone numbers, credit card numbers, banking information, etc.  Anytime you encounter an online form for e-commerce or other sites, RoboForm will pop up and offer to populate the relevant information on the form.  If you set up multiple profiles (e.g., one for home, one for work, one for your spouse), you can choose amongst them, choose amongst credit cards to use or choose which address to use.  This is a huge time saver since RoboForm’s built-in intelligence is programmed to recognize and remember the most common field types used on the web.  To the extent that it doesn’t, you can right-click on the form and have RoboForm save the form information for future use.  I find this capability quite handy for repetitive surveys over time, forms that require shipping and billing data, and sites that request recurring demographic data.

Have you ever been frustrated after spending a lot of time on a site completing an online form or long text box and then find out that the site timed out or couldn’t save your info?  You’ll find that saving the data in RoboForm first before submitting it can save you quite a bit of aggravation.  Just bring up the page again and let RoboForm re-populate it.

RoboForm can also securely save and store free-form bits of information known as “safenotes.”  I’ve used safenotes to store software installation keys, combinations for safes and locks, Wi-Fi network names and keys, PIN’s, frequent flier numbers, and other confidential personal or financial information.

As mentioned above, RoboForm is available on most computing and mobile platforms including the PC, iPhone, Windows Mobile, Palm, BlackBerry, Android, and Symbian.  A version known as RoboForm2go works on a USB thumb drive and enables you to plug in and out of any PC without having to install the program and move your passwords onto someone else’s PC.  Another available piece of software, known as GoodSync, keeps your RoboForm information synchronized between different platforms and locations.

RoboForm Online

Over the past year, RoboForm has been beta testing a version of RoboForm online which optionally allows you to synchronize your passcards and safenotes to a secure server.  Accessing these very secure items online requires you to register with and to log into the site (free) with a secure password.  Actually opening the secure items prompts for your RoboForm master password to be entered, thereby enabling two levels of password security.  This service has been a godsend for me on numerous occasions where I was away from my PC and didn’t have my laptop or RoboForm2go USB thumb drive with me when I needed a login ID and password.  The site functions much like the desktop version of RoboForm and assists you with automatically logging into sites that you’ve saved in RoboForm.

RoboForm Online gives you the added flexibility of synchronizing your passcards and safenotes over the internet across multiple devices.  This is a very powerful and much needed capability, though I can understand many people’s hesitation to surrender and trust their most sensitive passwords and personal information to a third party server.  My only comment is that RoboForm has the highest levels of security and encryption implemented and, with two levels of password protection, I feel reasonably secure about putting my data out there.  Besides, your online ID’s and passwords are by definition already stored on many servers in the cloud which can be equally hacked by determined thieves, albeit one at a time.

Version 7 Enhancements

One of the most significant enhancements in this version 7.0 beta is the capability to save and fill ID’s and passwords in Windows (WIN32) applications, not just online passwords.  In addition, when saving an online form, the details are now displayed for you so you know exactly what is being saved.  Furthermore, this occurs in a non-obtrusive tool-bar rather than the old pop-up box, thereby streamlining the web browsing experience.  Logging into widely known and popular websites automatically downloads site icons to make the related passcards more visually appealing and easier and faster to recognize.

Another significant enhancement for devices equipped with a fingerprint reader is the capability to enter the master password via a finger swipe.  The fingerprint device stores your master password in a secure area on the device.  This secure area becomes accessible to RoboForm only after you slide your finger and it is then authenticated against the fingerprint stored on the device.

A release date for version 7 has not yet been announced.

RoboForm Criticisms

RoboForm is not without its shortcomings and share of quirks.  For example, more and more sites are switching to an Adobe Flash version of their login screen to raise security.  RoboForm cannot currently handle most of these sites.  On those sites, you have to perform a manual RoboForm lookup and type in your ID and password yourself.

On some sites, such as American Express, RoboForm inexplicably stops working properly. This requires you to have RoboForm fill out the form (but not submit it) and then you manually click on the submit button.  In this case, you can re-memorize the site information in RoboForm and fix the problem for future visits.

As sites become more sophisticated with additional levels and types of authentication (e.g., captchas, pointing and clicking your PIN on an onscreen keyboard à la ING Bank, rotating challenge questions, etc.), this renders RoboForm unable to do anything more than show you your credentials to be manually entered.  I’m not sure how or if RoboForm can be enhanced to overcome and automatically populate these additional safeguards, but it sure would be nice if they figured out a way to do so.

Whenever you change the master password, your passcards and safenotes should inherit and respond only to the new password.  However, I’ve had a few occasions where a passcard would only open up with the old password.  Finally, I’ve had occasions where I’ve had to inexplicably remind RoboForm where my data directory resided.  Fortunately no data has ever been lost.

Options & Recommendations

The paid version of RoboForm, known as RoboForm Pro, is about $30 for the first license and less for additional licenses.  An enterprise version is available and significant discounts are available for large license purchases.  During various holidays throughout the year, a 20% discount can be found on the website.  Even without the discount, for this price, you can count on saving yourself tons of frustration and aggravation compared to using manual or spreadsheet password management and form filling.  Buying multiple licenses at the same time (whether or not on the same platform) will likely save you money compared with buying them over time.

I also highly recommend the powerful GoodSync software if you plan to sync your data or files across multiple platforms or devices.  GoodSync is one of the most powerful file synchronization tools available and is also one of my most frequently used cool tools to keep data in sync.

For those who prefer free versions of password management tools, of course the Internet Explorer and Firefox password stores are available, though they are significantly less capable than RoboForm.  The popular open-source password manager applications KeePass and LastPass are also free but, in my opinion, not as convenient as RoboForm.  If you’d like additional information about password managers including the five most popular ones, visit http://lifehacker.com/5042616/five-best-password-managers.

I welcome your feedback and questions about RoboForm or other password managers. Please feel free to write me at shf@ydfs.com.

Sam H. Fawaz, CFP®, CPA works with Y.D. Financial Services in Canton Michigan and Franklin Tennessee and has been helping clients with financial planning and financial planners with technology solutions for over 20 years. He has been writing about tax, financial planning and technology solutions for over fourteen years.  He can be reached via e-mail at shf@ydfs.com or at (734) 447-5305 with any questions.  You can follow Sam on Twitter at http://twitter.com/themoneygeek or at his blog at http://themoneygeek.com.  His company website is at Y.D. Financial Services, Inc.