How to protect yourself from online scams has barely changed in a decade. Where scams reach people has changed completely, and that is the part worth updating. The suspicious email in a spam folder is no longer the main event — the costliest contact method is now a social feed you scroll every day.
What follows uses the US Federal Trade Commission’s reported figures, because it is the best public dataset anyone publishes. The totals are American; the patterns are not.
Three habits cover most of it. Verify on a channel you started — hang up, look the number up yourself, type the address in. Refuse irreversible payment: bank transfer, crypto, gift cards and payment apps to strangers have no recourse, and that is exactly why you are being steered there. And slow down, because manufactured urgency is the one ingredient every scam needs.
Table of Contents
Toggle
Where scams actually come from now
People reported losing about $16 billion to fraud in 2025 — the highest total on record and a 25% rise on the year before. That is only what was reported, so the real figure is higher.
The striking part is where it started. Nearly 30% of people who lost money said the scam began on social media, accounting for $2.1 billion — eight times the 2020 figure, and enough to make social media the costliest contact method of the year.

Within that, Facebook produced the most losses, followed at a distance by WhatsApp and Instagram — Facebook alone accounting for more than text and email scams combined. Investment scams took $1.1 billion of the social media total, more than half. Shopping scams were the most frequently reported, with over 40% of those who lost money saying they bought from an advert in their feed. And close to 60% of romance scam victims said it started on social media.
Most people have learned to treat an unexpected email with suspicion. Very few have transferred that instinct to a familiar feed, where the advert sits between a friend’s holiday photos and looks like everything else there. The context does the persuading before the scammer says a word.
The impersonation pattern, which is one report in three
Imposter scams were the most reported category of 2025, close to one in three fraud reports, with $3.5 billion in losses. Business impersonators took nearly $1 billion of that, with banks the most impersonated. Government impersonators took around $920 million, up from $789 million a year earlier.
The FTC is specific about this: some of the most expensive impersonation scams begin with a fake security alert, often appearing to come from your bank. It is an efficient opening. The alert manufactures urgency, and it recasts the scammer as the person helping you rather than the person robbing you — so every instruction that follows sounds like rescue.
The counter-move is mechanical and it does not require you to spot anything. Never act on the channel the contact arrived through. Hang up, then call the number printed on your bank card. Close the message, then type the address in yourself. A genuine institution loses nothing when you do this; a scammer loses everything, which is why they will press you not to.
The rule that beats knowing every scam type
You cannot memorise a taxonomy fast enough to keep up. You can watch how you are being asked to pay, and that single question catches most of it.
The FTC found that people lost more to bank transfers and cryptocurrency than to all other payment methods combined. That is not because those methods attract scams by accident. It is because they are irreversible. Gift cards, wire transfers, crypto and payment apps sent to strangers all share the property that once it is gone, it is gone.
Your bank does not ask for gift cards. A tax authority does not take payment in cryptocurrency. A utility company does not need a wire transfer this afternoon. The moment the payment method is both unusual and unrecoverable, you have identified the scam without needing to understand the story wrapped around it.
How to protect yourself from online scams in about a minute
Most of this article is judgement. This part is a procedure, which is more useful when you are rattled and judgement is the first thing to go. Run it on anything unexpected that mentions money, accounts or urgency.
- Do not tap anything yet. Not the link, not the button, not the number in the message. Everything below happens outside it.
- Ask what it wants you to do in the next ten minutes. If the answer involves moving money, installing something, or reading out a code, treat it as hostile until proven otherwise.
- Reach the organisation yourself. The number on your bank card, the app you already have installed, the address you type in. If the message was genuine, this costs you two minutes.
- Search the exact wording. Paste a distinctive sentence into a search engine. Mass-sent scams are usually already documented by someone.
- Ask one other person. Saying it out loud is remarkably effective, which is precisely why so many of these instruct you to keep it to yourself.
Any six-digit code that arrives by text is the last thing standing between someone and your account. No genuine caller from a bank, a delivery firm or a support desk needs you to read one back. If someone on a call asks for a code that just arrived, the call is the attack — there is no benign version of that request.
What has changed with AI
Cheap voice cloning has made one old scam considerably better. The distressed relative calling from an unfamiliar number used to rely on a bad line and panic; now it can arrive in a voice you recognise. Video calls are heading the same way.
There is no reliable way to detect this by listening, and trying to is the wrong instinct anyway. The defence is the same one as everywhere else on this page: end the call and reach the person on the number you already have for them.
A word that never gets written down or texted, known only inside the family, asked for whenever a call involves urgency and money. It costs one conversation over dinner and it defeats a voice clone entirely, because the technology can reproduce a voice but not something it has never heard.
Recognising scams by shape rather than by type
New variants appear constantly, but they reuse a small number of shapes. These are worth knowing better than any list of named scams:
- Urgency plus secrecy. Something must happen now, and you should not discuss it with anyone. Both halves are there to stop you getting a second opinion.
- A stranger who becomes a friend, then mentions an investment. Often weeks of genuine-feeling conversation first. The investment is the point; the friendship was the setup.
- An unsolicited alert about a problem with your account. Especially one offering to help you move money somewhere safe.
- A job that asks you to pay, or to receive money and forward it. The first is a fee scam, the second makes you a money mule and is a criminal problem as well as a financial one.
- A price well below the market on a social advert. The most reported category of all, and the easiest to check by searching for the seller independently.
Protections that actually pay off, in order
- Unique passwords in a manager. Removes the credential-stuffing route entirely, so one breach stops becoming six.
- Two-factor authentication on email and banking first. Email resets everything else, which makes it the account attackers actually want.
- Automatic updates on. Unglamorous, and it closes the holes that malware and fake support pages rely on.
- Independent verification as a habit. Not a skill to deploy when suspicious — a reflex you use when you are not.
- A pause before anything financial that arrived unsolicited. Ten minutes dissolves most of these.
Which second factors genuinely resist phishing, and which only appear to.
If you have already paid
Speed matters more than anything else here. Contact your bank or card issuer immediately and say the word “fraud” — some transfers can be recalled inside a narrow window, and card payments carry protections that bank transfers do not. Then change the password on any account involved, and on your email if it shares that password.
Then report it. In the US that is ReportFraud.ftc.gov, and the FBI’s IC3 for internet crime; elsewhere it is your national consumer protection body or cybercrime unit, and your bank can tell you which.
Millions of reports a year are what make these patterns visible in the first place — every figure on this page exists because people filed one. And the volume is worth sitting with if you feel foolish: this is happening to an enormous number of careful people, using techniques built specifically to work on careful people.
Common mistakes to avoid
- Calling the number in the message. It reaches the scammer, however official the message looks.
- Trusting caller ID or a sender address. Both are trivially spoofed.
- Assuming a padlock means a site is honest. It means the connection is encrypted, nothing more — scam sites have certificates too.
- Believing this only happens to the inattentive. Losses are dominated by people who thought exactly that.
- Staying quiet out of embarrassment. Silence helps only the person who took the money.
- Paying a “recovery service” that contacts you afterwards. Victim lists get resold, and the second scam targets people already proven to pay.
Keeping the device itself clean, since some of these end in malware rather than a payment.
Online Scams: Frequently Asked Questions
What is the most common online scam?
Impersonation. Imposter scams were the most reported category in 2025, close to one report in three, with $3.5 billion in reported losses. Banks are the most impersonated business, and the costliest versions typically open with a fake security alert about your account.
Where do most scams start now?
Social media. Nearly 30% of people who reported losing money said the scam began there, totalling $2.1 billion — eight times the 2020 figure and the costliest contact method of the year. Facebook accounted for the most, ahead of WhatsApp and Instagram.
Can I get my money back after a scam?
It depends almost entirely on how you paid. Card payments carry the strongest protections, bank transfers are sometimes recallable if you act within hours, and cryptocurrency and gift cards are effectively unrecoverable. Contact your bank immediately rather than waiting to see what happens.
How do I check whether a seller or website is genuine?
Verify independently, never through the message or advert itself. Search for the company separately, look for contact details that exist outside its own site, and be wary of a price well below everyone else’s. Shopping scams are the most frequently reported type, and over 40% of those who lost money bought from a social media advert.
Should I report a scam if I did not lose any money?
Yes. Reports are what make new patterns visible while they are still spreading, and a near miss you report can be what flags a scam before it reaches someone who would not have spotted it. It takes a few minutes and requires no proof of loss.
The short version
Assume anything arriving unsolicited might not be who it says, and verify on a channel you chose. Refuse payment methods that cannot be reversed. Treat urgency itself as the warning sign, because it is the one thing every version of this needs.
None of that requires keeping up with new scams as they appear, which is fortunate, because nobody can.



