Verified scam directory
Every public warning, sorted newest first. 17 scams indexed.
Generic
Unsolicited marketing pitch claiming the recipient's website has poor SEO rankings. The sender promises 'Page 1' rankings on Google in exchange for contact details or a reply, a common tactic for lead generation scams or low-quality service solicitation.
NPR (National Public Radio)
Impersonation of NPR host Terry Gross targeting an author/publicist with a fake interview invitation. The scammer uses a generic Gmail address instead of an official NPR domain. This is a common setup for vanity media scams where the author is eventually asked to pay 'broadcast' or 'marketing' fees for a segment that will never air on legitimate NPR programming.
HubSpot
A high-level executive recruitment scam impersonating a recruiter for HubSpot. The scam uses highly specific professional details about the recipient to build rapport (Social Engineering) and offers an incredibly high compensation package ($1M+ total comp) to lure the target into a fake interview process, likely leading to identity theft or a 'pre-employment' fee/background check scam.
Top Class Talent Group
A recruitment scam targeting high-level executives with an unrealistic salary offer (£580k-£840k). The sender uses a free Gmail account and there is a discrepancy between the 'From' name and the signed name. This is likely a phishing attempt or a setup for a 'task' or 'advance fee' scam.
Generic
A 'Headhunter' using a personal Gmail account reaches out with a vague but high-level 'Senior AI Marketing' role. The email uses flattering, AI-generated-style language and lacks specific company details, characteristic of recruitment phishing designed to harvest resumes or transition into 'task' based fraud.
Meta / Facebook
A phishing campaign abusing the Meta Business Manager 'Partner Request' system. Scammers send a legitimate-looking notification but set their business name to a phishing URL (sites.google.com) or a lure ('Your Facebook account is eligible for verification'). The goal is to trick the user into clicking a link that leads to a credential harvesting site or granting an attacker-controlled 'partner' access to their Facebook Business assets.
Aerotek / HubSpot
A phishing attempt impersonating a recruiter from Aerotek for a high-paying CMO role at HubSpot. The scam uses a personal Gmail account and a suspicious google/share link to solicit resumes and conduct 'benchmarking,' likely for identity theft or further social engineering.
StoryGraph (Impersonation)
The sender claims to be a coordinator for a 'StoryGraph reading community' and invites the author to include their book in a reading challenge. This is a common tactic used to eventually solicit 'participation fees' or 'promotional costs' from authors (a form of vanity press or service fraud). The email uses flattery and vague promises of exposure to entice the recipient.
Spencer Stuart
Potential job scam impersonating an executive recruiter from Spencer Stuart. The sender uses a generic Gmail address and provides conflicting names (Robert vs. Olga) while promising 'highly confidential' senior leadership roles. The scammer attempts to deflect suspicion by claiming the communication is being routed through 'administrative channels.'
CryptoVault
Fake crypto wallet security alert urging users to re-verify their seed phrase on a cloned website.
IRS
Impersonation of tax authority demanding immediate payment of overdue taxes via gift cards to avoid arrest.
Meta
Counterfeit Facebook Business verification notice threatening account deletion unless action is taken.
Fake LinkedIn recruiter offering remote work with inflated pay, requesting upfront payment for equipment.
FedEx
SMS claiming a package delivery failed and requesting address confirmation via a phishing link.
Amazon
Bogus Amazon order confirmation for a high-value item the recipient never purchased, with a fake support number.
Geek Squad
Fraudulent Geek Squad auto-renewal invoice demanding phone callback to steal payment details.
Netflix
Fake Netflix account suspension warning with a malicious login link designed to harvest credentials.
