Skip to content
Scamiro
Fraud Prevention9 min read1,258 words

The four questions that identify almost any scam

Scams change their story constantly and their structure almost never. Four questions apply to the delivery driver text, the investment group and the call from your bank alike.

Scamiro
Aspect Tel-set telephone call centre
Aspect Tel-set telephone call centre

Short answer

Almost every scam needs four things: it contacts you rather than the reverse, it creates urgency, it asks for money or access in a form that cannot be reversed, and it discourages you from checking with anyone else. Any one of these is a reason to slow down. Three together is a scam regardless of how plausible the story is.

On this page
  1. 1. Who started this contact?
  2. 2. Why does this have to happen now?
  3. 3. What am I being asked to hand over, and can I get it back?
  4. 4. Am I being encouraged to keep this to myself?
  5. Applying it under pressure
  6. If it has already happened
  7. What makes something a scam rather than a bad deal?
  8. Which payment methods can be recovered?
  9. What should you do in the first hour?
  10. Where to report, and why it is worth 5 minutes

Trying to recognise scams by their content is exhausting and does not work. The stories are rewritten constantly, they are localised, and they now arrive in fluent language with correct logos.

The structure underneath barely changes, because it is dictated by what the scammer needs rather than by what they claim.

1. Who started this contact?

Almost every scam begins with the scammer reaching you: a text, a call, an email, a message in a group, a comment under a post, a match on an app.

This matters because it inverts the normal safety assumption. When you contact your bank using the number on your card, you know who you are talking to. When someone contacts you claiming to be your bank, you know nothing at all — caller ID, sender names and email display names are all trivially forged.

The rule that follows: never continue an unexpected contact on the channel it arrived through. Hang up and call the number printed on your card, type the company's address into the browser yourself, open the app directly. A genuine organisation will have a record of the matter. A scammer will try to keep you on the line, and that resistance is the tell.

2. Why does this have to happen now?

Urgency is not decoration. It is the mechanism. Every deliberation step you take is a step at which the scam can fail, so the story is built to remove them:

  • Your account will be suspended today.
  • The parcel returns to sender in two hours.
  • The investment window closes tonight.
  • A warrant will be issued if you hang up.

Real institutions move slowly. Banks write letters. Tax authorities send assessments you can respond to. Courier companies leave the parcel at a depot for a week. An organisation that will not let you take an hour is telling you something about itself.

3. What am I being asked to hand over, and can I get it back?

Scammers need value in a form that cannot be reversed. Watch for anything in this category:

  • Bank transfer to a new account, especially one described as "safe" or in your own name.
  • Gift cards or vouchers. No legitimate organisation has ever been paid in gift cards.
  • Cryptocurrency. Irreversible by design, which is precisely the appeal.
  • A one-time passcode read out loud. The code is the authentication. Reading it aloud is handing over the account.
  • Remote access software installed so someone can "fix" or "demonstrate" something.

A bank asking you to move money to a new account for safety is not a thing that happens. Neither is a support agent needing your one-time code. Both are the whole scam stated plainly.

4. Am I being encouraged to keep this to myself?

This is the question people skip, and it is the one that most reliably separates a scam from a bad deal.

Scams isolate. Sometimes gently — this offer is only for you, don't share it. Sometimes as part of the story — we suspect a member of staff at your branch, so please don't mention this. Sometimes brutally, in romance and investment scams that spend weeks positioning friends and family as people who "won't understand".

No legitimate process requires you to conceal it from your family, your bank, or the police. Secrecy is not a feature of any real institution's procedure.

If you notice you are being asked not to tell someone, tell them.

Applying it under pressure

The questions work because they can be asked while the story is still running:

  1. Did they contact me?
  2. Why the rush?
  3. Is what they want irreversible?
  4. Am I being told to keep quiet?

Two out of four is enough to stop and verify independently. There is no cost to verifying — a real organisation will still be there in an hour, with the same request, on a number you looked up yourself.

If it has already happened

Speed matters more than embarrassment.

  • Contact your bank immediately and say the words "authorised push payment fraud" if you sent a transfer. Many banks have a reimbursement process, and some transfers can be recalled if reported fast.
  • Change the password on any account you gave credentials or a passcode for, and check its recovery email and phone number for changes the attacker made.
  • Uninstall any remote access software and treat the device as compromised until you have checked it.
  • Report it. In the UK that is Action Fraud; in the US the FTC and the FBI's IC3. Reports are what let banks and platforms see patterns across victims.

Being scammed is not a comment on your intelligence. These operations are staffed, scripted and iterated against thousands of people. The defence is a structure you apply every time, not being clever once.

What makes something a scam rather than a bad deal?

A scam is a deception designed to obtain money or access, built so that the transfer cannot be reversed once you agree to it. That last clause is what separates it from a poor purchase: a bad deal leaves you with something disappointing and a receipt, while a scam leaves you with neither.

Which is why the four questions target structure rather than story. The story changes weekly; the structure cannot, because it is dictated by what the scammer needs rather than by what they claim.

Which payment methods can be recovered?

MethodRecoverableRealistic window
Card paymentOften, via chargebackWeeks, but report immediately
Bank transferSometimesHours — many countries now have reimbursement rules
Gift cards or vouchersAlmost neverMinutes, before the code is spent
CryptocurrencyNoNone — a confirmed transfer is final
Cash to a courierNoNone
Direct debitYesCan be recalled through your bank

A scam steers you toward the bottom half of that table, every time. If someone insists on a method from rows 3 to 5, that insistence is the answer regardless of how the request was explained.

What should you do in the first hour?

  • Contact your bank on the number on your card, not one you were given.
  • Change the password on any account where you shared a code or credentials, and check its recovery email and phone for entries you did not add.
  • Uninstall any remote access software and treat the device as compromised until checked.
  • Report it — Action Fraud in the UK, the FTC and IC3 in the US.

Being caught by a scam is not a comment on intelligence. These operations are staffed, scripted and iterated against thousands of people; the defence is a structure you apply every time rather than being sharp once. More in fraud prevention, digital safety and phishing.

Where to report, and why it is worth 5 minutes

Reporting rarely recovers money and reliably shortens a campaign. The FTC's reporting site feeds the data that identifies an operation across thousands of victims, and in the UK Action Fraud performs the same role.

Banks also act on patterns rather than individual cases. A scam reported on day 2 rather than day 9 is the difference for everyone contacted in between, which is the only realistic argument for doing it — and it is enough of one.

Frequently asked questions

How can a scam call show my bank's real number?
Caller ID is not verified end to end on most telephone networks, so the displayed number can be set by the caller. The same is true of SMS sender names and email display names. None of them are evidence of identity.
Is it rude to hang up and call back?
No, and any legitimate organisation expects it. Fraud teams at banks actively recommend it. If someone objects to you verifying independently, that objection is the answer.
What if the caller already knows my details?
Names, addresses, dates of birth and even recent transactions circulate in breach data and are sometimes bought. Knowing things about you is not proof of who they are; it is a reason the story sounds convincing.
Can money sent by bank transfer be recovered?
Sometimes, if you report it within hours. Many countries now have reimbursement rules for authorised push payment fraud. Cryptocurrency and gift cards are effectively unrecoverable, which is why scammers prefer them.

Sources

  1. How to Avoid a ScamUS Federal Trade Commission
  2. Report a scamAction Fraud (UK)
  3. Internet Crime Complaint CenterFBI

Published by

Scamiro

Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.

About the publication

Related reading

Keep going

A search results page with a sponsored listing above the organic results

Social Media Scams9 min read

When the scam is the advert

Nearly a third of people who lose money say it started on social media, and a growing share of the rest started with a search. The result you clicked was bought, not earned.