A Practical Checklist for the Moment Something Feels Slightly Off
By the end of this lesson, you'll understand:
The previous lesson covered the pattern behind scams conceptually; this lesson turns that into something you can actually apply in the moment, a checklist you can run through quickly when something feels slightly off, before it becomes a costly mistake.
A request for payment via gift cards, wire transfer, cryptocurrency, or a payment app to an unfamiliar person is one of the strongest indicators of fraud. Legitimate businesses and government agencies do not request payment through gift cards, and genuine emergencies rarely require an irreversible payment method sent to a stranger.
What to check: If a payment method is specifically requested because it's "faster" or "more secure," treat that framing itself with suspicion, those are exactly the qualities (speed, irreversibility) that make a payment method attractive to a scammer.
A message claiming to be from your bank, the IRS, or a well-known company arriving by text or a personal social media message, rather than through the official channel that institution normally uses, is a meaningful warning sign. Institutions have established communication patterns, and a sudden shift is worth noticing.
What to check: If an organization typically mails you paper statements and suddenly texts you an urgent link, that channel mismatch alone is worth pausing over.
Scammers increasingly use information from data breaches (covered in a later lesson) to make a message seem credible, referencing a real account, a partial number, or an actual recent purchase. This personal detail can create false confidence that the message is legitimate.
What to check: A scammer knowing one true fact about you doesn't verify the rest of their claim, much of that information may be available through past data breaches, not because the sender is who they claim to be.
Any single element on this list could occasionally have an innocent explanation. But when two or more appear together, an unusual channel plus a gift card request, or urgency plus a request for remote device access, the odds of a legitimate explanation drop sharply.
What to check: Keep a simple mental or written checklist, and treat any combination of two or more red flags as a strong signal to stop and verify independently before proceeding.
This checklist works alongside the anatomy from the previous lesson, the four-part structure explains why scams are built the way they are, while this specific list gives you concrete details to notice in the moment, across phishing, impersonation, romance, and investment scams covered in the lessons ahead.
Hassan receives a text claiming to be from a delivery company, referencing an order he did place recently, asking him to click a link and pay a small "redelivery fee" via a payment app. The message correctly names the retailer he ordered from, which initially makes it feel credible.
Running through the checklist, he notices the unusual channel (a text rather than the retailer's app, where his order history actually lives), and the small, easy-to-dismiss payment request designed to feel low-risk. He navigates to the retailer's app directly instead of clicking the link, and confirms no redelivery fee is actually owed, the text was a scam using a real recent purchase, likely surfaced through a data breach, to appear credible.
If a message correctly knows details about my recent purchase or account, it must be legitimate.
Scammers increasingly source real personal details from data breaches specifically to make fraudulent messages more convincing. One accurate detail doesn't verify the rest of the message.
It's worth a moment of caution and independent verification regardless, but a single sign is less definitive than a combination. When in doubt, verifying costs little compared to the potential loss.
Essentially never for a standard bill, fee, or fine. Gift cards function like cash with no fraud protection or reversal option, which is precisely why they're favored by scammers rather than by legitimate institutions.
Don't use any phone number, link, or contact method provided in the suspicious message itself. Instead, go directly to the organization's official app, website (typed manually, not clicked), or a phone number from a past statement or the back of your card.
Write down or save this lesson's checklist somewhere accessible, so it's ready the next time something feels slightly off.
With a practical checklist in hand, the next lesson, FPS103: Phishing, Smishing, and Impersonation Scams, looks closely at the specific channels these warning signs most often show up in.
That's where Financial Confidence becomes your personal red-flag checklist.
Financial Confidence can help you run a quick check against common warning signs, verify suspicious contacts through official channels, track patterns across messages you've received, and flag combinations worth extra caution.
Explore More LessonsLet us know if this lesson was useful, it helps us know what to keep improving.
Thanks for letting us know!