For education only · Not an official page of any company · We use referral links; signing up through them won't cost you more, and the site owner may earn a commission.

"Pay a release fee first and you'll get the money": that's how it disappearsMoney transfer scams and safety: fake support, phishing and shared devices

An SMS says you have a transfer waiting, just click the link to verify. A caller says pay a small release fee and the money lands. Can you tell which line is real and which is the setup? Most cross-border transfer scams run on the same handful of skeletons. This guide takes the five most common ones apart, then shows you how to check an official domain in three seconds, protect yourself on a shared device, name the few things you must never hand over, and limit the damage fast if you do get caught. Recovering funds after you file a report is a matter for your local police and regulators, so that part is out of scope here.

One iron rule first. Any story that requires you to pay money before you can receive money, whether it's called a release fee, a deposit, a "processing" charge, a tax or an activation fee, is a scam, without exception. A genuine transfer never asks the recipient to pay first. The moment you hear it, stop: don't pay, and don't keep talking.

Why money transfers attract scams

Cross-border money is a favourite target for scammers, for very practical reasons. First, the amounts are usually meaningful; what you send home can be a whole month's pay. Second, the process is unfamiliar to many people, and unfamiliarity makes it easy to be led along by "expert" talk. Third, chasing money across borders is extremely hard: once funds leave the country, and especially once they become cash or a crypto-asset, they are almost impossible to claw back.

Scammers don't win with clever technology; they win by manufacturing urgency and trust. They pretend to be official, pretend to be helping you, pretend the chance is slipping away, so you act before you check. The key to spotting a scam isn't memorising every new variation. It's recognising the shared skeleton underneath them. The five playbooks below cover the great majority of cases.

Five common money-transfer scam playbooks

1. Advance "release fee / deposit" before you can receive

Someone says there's money waiting for you, such as a prize, a refund, a transfer from family, a platform reward or an incoming stablecoin payment, but it's "stuck" at some step, and you must pay first: a release fee, a deposit, a customs charge, a tax. Once you pay, the money either vanishes or a new charge appears under a fresh name. In any legitimate channel the recipient never has to pay first. This is the easiest playbook to spot, and the most common.

2. Impersonating an "official agent / security team"

Someone claims to be from your bank, transfer company or exchange, in support, risk, or a security team, and says your account is "flagged, frozen, or at risk." They ask you to "verify": read out a one-time code, share your password, move money to a "safe account," or screen-share so they can "fix it for you." No legitimate support agent will ask for your password, one-time code, private key or seed phrase, and none will tell you to move money elsewhere "to keep the platform safe." Anyone who contacts you out of the blue, creates panic, and demands you act immediately should be hung up on; then verify by opening the official app yourself or typing the official address by hand.

3. Phishing sites and fake apps

A scammer builds a page that looks almost identical to the real site, on a domain that differs by a letter or two (an "o" swapped for a zero, an extra hyphen, a different ending), then pushes the link at you by SMS, email, a social-media group or a search ad. You log in on the fake page, and your username and password are stolen. The whole trick is getting you to click a link and then type your password on a fake page, so the most effective defence is simple: always type the official domain yourself or use your own saved bookmark, and never log in through a link someone sent you.

4. Private chat and remote control

They pull you off the public platform into a private chat (a direct message, an encrypted group, a messaging app), then guide you to install "remote assistance" software, share your screen, or follow their steps one by one. Once you install remote software or share your screen, they can see your password and one-time codes, and can even operate your account and move money directly. No legitimate support agent needs remote control of your device. The instant anyone asks you to install remote software or share your screen, stop.

5. Fake recipient / changed payout details

This one targets the sender. The recipient's email or account is hacked, and a scammer poses as them to send "new payout details," steering your money to a stranger's account; or in a deal, a rental, or a shopping arrangement, they give you an account that looks reasonable but is really theirs. Treat any "let's change the payout account just this once" request as a major warning. Always confirm with the real recipient through a separate channel you already trust, such as a phone call or an in-person check, before you send a cent.

A common situation. Sam got a call from someone claiming to work for a payment platform: "There's an overseas transfer waiting to be paid to you, but it's been frozen in cross-border clearing. Pay a small release fee (call it a tax) and the money lands, refunded to you in full afterwards." To make it look real, they sent over a doctored "funds received, pending release" screenshot for a sizeable amount. Sam nearly walked to a shop to buy prepaid cards to cover the "release fee." One question stopped him: "Who actually sent me this money?" The caller stumbled and couldn't say. That was the tell. There was no transfer waiting at all, and the whole "pay first to unfreeze it" story was invented. Anything that asks you to pay money before you can receive money, dressed up as a tax, a release fee or a deposit, is the same scam.

Seven more scam variants to recognise

The five above are the skeletons; what you actually meet is usually one of them in a different costume. The variants below hit people who send and receive money across borders especially often. Each comes with what the pitch sounds like and one question that breaks it. You don't need to memorise them, just learn the smell.

1. Romance-baited transfers ("pig butchering")

They build a relationship with you on a dating or social app, avoid money for weeks or months, and only once you trust them start easing into it: "I have an investment that always wins," "I've hit an emergency," "cover this for me." The pattern is relationship first, money later, and they never video-call or meet, always with a good reason.
The question that breaks it: "Can we video-call, or meet in the city you say you're in?" Real feelings don't fear daylight; someone who only wants money keeps finding excuses.

2. Fake investment / high-return platforms

They (possibly the same "romance," possibly an "investment mentor group") give you a slick-looking platform or app, have you deposit a small amount first, show you "profits" on screen, and even let you withdraw a little to win your trust. Once you scale up, you can't withdraw anymore, or you're told to pay a "tax / deposit" before you can. Being able to deposit but not withdraw, with the number always growing, is the classic tell.
The question that breaks it: "I'll withdraw my entire balance right now to test it." If you can't, or you're told to pay first, it's a scam.

3. Fake charity / emergency appeals

Using a disaster, an illness, a conflict or a pitiful story, they push you to "donate a little right now," and the payment route is usually a personal account, prepaid cards or a crypto wallet rather than a public, checkable, legitimate channel.
The question that breaks it: "What's the organisation's full name? I'll go to its official site and donate there myself." A genuine appeal survives you checking on the official site; a scammer only wants you to pay this account now.

4. Overpayment / refund-the-difference

Common in second-hand deals, buying-on-behalf, or freelance payments: they "accidentally overpaid," or use a fake transfer screenshot or a bad cheque to make you think the money arrived, then ask you to send back "the extra," or to front the cash to buy and ship something. After you refund or ship, you find their money never landed or was later reversed. Any incoming payment that has you refund or front money first deserves a pause.
The question that breaks it: "Once the money has truly cleared into my account and I can freely use it, then we'll talk; a screenshot doesn't count."

5. Impersonating family: "new number, need money urgently"

A message from an unknown number or a hacked account claims to be your child, parent, boss or a friend: "I changed numbers / lost my phone," followed by an emergency that needs money right now, often with "don't call, I can't talk at the moment" — that instruction exists precisely to stop you from verifying.
The question that breaks it: call back on the number you already had saved, or ask a personal question only the real person could answer. "Can't take a call" is exactly where you should get suspicious.

6. One-time code / OTP harvesting

Anything that, in the name of "verifying your identity / confirming it's you / releasing this transfer / cancelling a suspicious transaction," gets you to read out or forward the SMS code you received is almost always taking that code to log in or move money out of your account. A one-time code exists only to prove "it's really you," so handing it over hands over the key.
The question that breaks it: read the SMS itself — a legitimate code message usually says "do not share this with anyone." Anyone who asks, gets nothing.

7. SIM-swap / phone number hijack

Here the scammer works the carrier's end: using some of your personal details to request a "replacement SIM / number port," they move your number onto their phone, after which every SMS code sent to you lands in their pocket, letting them break into accounts tied to that number one by one. The signal: your phone suddenly loses signal or can't make calls, with no fault you can find.
The question that breaks it (self-check): the instant your phone loses signal for no reason, use another device to log into important accounts and change passwords, and contact your carrier to confirm whether the number was tampered with. For important accounts, prefer an authenticator app or a physical security key over SMS codes alone.

Verify the official domain: the single best anti-phishing move

Almost every stolen account starts with a password typed on a fake page. Learn to check a domain in three seconds and you block most of the risk. Read the address bar right-to-left and run these steps:

  1. Read the domain from right to left. What actually decides a site's identity is the "main name + ending" pair (in example.com, that's example.com). Scammers pad the front with reassuring words, like login-example-secure.com, where the real main domain is example-secure.com, not example.com at all.
  2. Compare letter by letter. Swapping "o" for a zero, "l" for a "1," adding a hyphen, or changing the ending (.com to .co, .net, .xyz) are all common tricks. Hold it against the official domain you know for certain, and not a single character may differ.
  3. Don't reach a login page through a link someone sent. Links in SMS, email, group chats and even search ads can all be phishing. To log in, type the domain yourself or use a bookmark you saved earlier.
  4. Stick to the official app. Searching your phone's official app store, checking the developer name, then installing, is harder to fake than hunting for an entry point in a browser.
Where our referral link points: our referral link points straight to Binance's official sign-up page with a sponsored tag; make sure you're on Binance's official page and don't arrive via a strange link before you type anything.

Staying safe on shared and public devices

Many people working abroad use an internet café, a shared dorm computer, or a friend's phone to send money, and those devices carry more risk. If you have no choice:

  • Prefer your own device and your own mobile data; log in and move money on public computers or unknown Wi-Fi as little as possible.
  • Use the browser's incognito / private mode, log out immediately when done, and never tick "remember password" or "stay signed in."
  • Afterwards, clear the browsing history and cookies; if you lent your own phone to someone, check whether any unfamiliar app was installed.
  • Watch for shoulder-surfing: shield the screen while typing a password or one-time code, and mind who is behind you and any cameras.
  • Turn on two-step verification for your phone and important accounts; if a password leaks on a public device, that extra step buys you time.
  • Never save or screenshot any password, private key or seed phrase on a public device.

What you must never hand over

Hold this boundary and you sidestep almost every "fake support" and "fake helper": these things go to no one, for no reason, through no channel.

  • Your login password: no legitimate support agent needs your password.
  • SMS / app one-time codes: a one-time code exists to prove "it's really you," so handing it over is handing over the account.
  • Private key and seed phrase (wallet recovery words): this is the master key to a crypto wallet, and anyone who gets it can move every asset you hold. No legitimate platform, agent or staff member will ever ask you for a seed phrase.
  • The full combination of card number + the security code on the back + the expiry date, and any one-time password your bank sends.
About the seed phrase, once more. A seed phrase is not a "password": it is the wallet itself. Typing it into any page that promises to "verify / sync / recover / unlock," or sending it to any "agent," is handing the wallet over whole. In normal use, a seed phrase is written down only when you first create the wallet, kept offline, and never typed into any site or given to any person again. Anyone telling you to "enter your seed phrase to verify" is running a scam, full stop.

Red flags vs normal: a side-by-side checklist

Burn this table into memory. If any one row matches, stop and verify. Better slow than sorry, and never rush the money.

Red flags vs normal · quick checklistspot it fast
Red flag (be on alert)What's normal
Asks you to "pay a release fee / deposit / tax" before you can receiveA recipient never has to pay first
Claims to be an official agent, asks for your password / code / seed phraseLegitimate support never asks for these
Rushes you: "right now, or it will be frozen / expire"Genuine matters survive you checking slowly
Sends a link for you to click and log inType the domain yourself or use a bookmark
Wants you to install remote software or screen-shareNo legitimate support needs to control your device
Pulls you into private chat or an encrypted group for "guidance"Real business runs on official, public channels
Recipient suddenly "switched to a new account"Confirm with the person through a separate channel
Promises sure wins, no losses, protected high returnsNo such deal exists; most likely a scam
Domain off by a letter or two, odd endingCompare letter by letter with the official domain
These are general signals, not aimed at any specific company. When unsure, go by the official channel you have verified yourself.

If you've been scammed: step by step

When something feels wrong, don't panic and don't delay. The faster you act, the more you can limit the loss. Work through this in order, and don't skip steps:

  1. Stop paying, cut contact. First stop every payment and every action they've asked for: don't send more, don't click more. Above all, never pay any "recovery fee / release fee / deposit" to "get the earlier money back" — that only digs the hole deeper. If they have remote control of your device, go offline and close the remote software.
  2. Save the evidence; don't delete anything. Before any fix, preserve what proves this happened: the full chat history (don't delete it or block them so far that you lose the record), transfer receipts / transaction IDs / the recipient's account or wallet address, screenshots of the URLs and pages they sent, and the caller's number and times. Screenshot or photograph it somewhere else; you'll need it for the platform and for the police.
  3. Contact your transfer platform / bank / exchange fast, and try to recall it. Find support through the official app or an address you typed by hand (never any contact the scammer gave you), explain you've been scammed, quote the transaction ID, and ask them to stop or reverse the payment. Timing is everything: a wire or app transfer that hasn't reached their account yet may be caught or returned; cash pickups and completed crypto transfers usually can't be reversed, but you should still report it at once, ask the platform to freeze the accounts involved, and flag it as fraud.
  4. Report it to local police / a cybercrime reporting channel. Bring the evidence from the last step and file with your local police or an official anti-fraud / cybercrime reporting channel, and get a report receipt or reference number. Cross-border recovery really is hard, but a formal report is what banks and platforms lean on to cooperate later, helps the investigation, and keeps others from being caught.
  5. Change passwords, turn on two-step verification, isolate accounts. If a password or code leaked, on a separate, clean device change the affected passwords one by one, sign out of all sessions, and enable two-step verification (prefer an authenticator app or a physical security key over SMS alone). If you reused that password elsewhere, change those too. If a crypto wallet is involved and the seed phrase may be exposed, move the assets to a brand-new wallet with a seed phrase only you know.
  6. Watch out for the "we'll recover it for you" second scam. After being scammed, you may well be contacted by people claiming to be "cyber police / a recovery firm / a claims lawyer / a platform specialist" saying "pay a fee / deposit and we'll get your money back," and they may even name the exact amount you lost (that info can come from a list the first scammers sold on). Anyone who wants you to pay again before they'll "help you recover" is almost always the second wave, targeting people freshly scammed and desperate to undo it. Pursue recovery only through channels you've verified yourself, and send nothing to anyone who approaches you.
  7. Warn the people around you. The same playbook is usually run in bulk, so tell family and friends, especially anyone on the same remittance corridor or platform, so they're forewarned.
A note: this site can only offer general safety knowledge. It can't judge your individual case, doesn't give legal advice, and can't help you recover funds. For a specific scam, go by the guidance of your local police, bank and regulators.

Teaching family (especially older relatives) to stay safe

Often it isn't you, out earning and sending, who gets scammed, but the parents and elders receiving at home. They're less comfortable with phones, they worry about you working far away, and one line — "your child is in trouble," "there's money for you but it's stuck" — sends them into a panic. Rather than chasing it afterwards, make a few things clear in advance:

  • Set one household rule: anything about "sending money / paying a fee" means hang up first and call me to confirm. Agree on the few fixed numbers and channels you'll trust; treat unknown callers as a reason to stop and check with you first.
  • Turn "you never pay to receive money" into one easy line they'll remember: money that's truly for you never asks you to pay first. Anything demanding a release fee, tax or deposit up front is fake.
  • Agree on a family code word or a private question. If someone impersonates you with "new number, need money urgently," the elder can test them with the code word or a question an outsider couldn't answer.
  • Set their phone up for them: turn on two-step verification for important accounts, switch off "remember password," install official apps with the developer checked, and bookmark the real support entry points, so they don't have to search on the spot and land on a fake page.
  • Spell out that a one-time code goes to no one, including anyone claiming to be you, the bank or a platform. Code SMS messages usually say "don't tell anyone" — point that out to them.
  • Make it feel safe to ask. Many older people, once scammed, are too ashamed to speak up and miss the window to limit the loss. Tell them again and again: when unsure, ask; if scammed, tell the family first — the sooner said, the easier to handle.

Who to report to: a channel-by-channel guide

After a scam or a suspicion, you usually need several parties at once, each able to help with something different. The table below is by channel, in general terms — for exact contact details, go by an official channel you've verified yourself, and never use any number a scammer or a strange link gave you.

Who to report to · by channelGeneral terms · verify officially
WhoWhat they can help withHow to find the right entry
Transfer platform / exchange supportTry to stop or reverse a transfer not yet landed, freeze accounts, flag fraud, preserve recordsSupport inside the official app, or the official site you typed by hand
Your bank / card issuerStop or recall a bank transfer, freeze or cancel the card, watch for further suspicious chargesThe support number on the back of the card / the official app / an address typed by hand
Local police / anti-fraud lineFile a formal report, issue a receipt, open an investigation (police handle cross-border cases)The official police or anti-fraud reporting channel published in your country / region
Cybercrime / consumer-protection reporting channelTake online-fraud reports, aggregate cases, publish scam alertsThe public entry point of your country's official cybercrime or consumer-protection body
Your mobile carrierFreeze and restore a hijacked number / swapped SIM, investigate the changeThe carrier's official store, official app, or the support number on your bill
The impersonated platform / merchantReport fake support, fake accounts and phishing domains, help take them downThe "report / security centre" entry on that platform's official site or app
These are general channel descriptions, not aimed at any specific body, and no phone numbers are listed; contact through an official entry you've verified, and be wary of anyone who approaches you and wants payment before they'll "help."

The most common mistakes

  • Believing it because "they sounded so professional." A scammer's script is designed to sound professional. Judge by what they're asking you to do, not by how smoothly they say it.
  • Acting under pressure without checking. "Now, or it's frozen" is the most common pressure line. Real official business doesn't mind you taking ten minutes to verify.
  • Clicking a login link someone sent, to save effort. Even if it looks identical, type the domain yourself to get there.
  • Paying more to "recover what's already lost." "Pay a little and we'll get it back" is usually a second scam, aimed at people who were just caught and are desperate to undo it.
  • Treating a seed phrase like an ordinary password. It's the master key to the wallet; any page asking you to type your seed phrase is a trap.

Common questions

How do I quickly tell whether a "support agent" is real or fake?
Watch what they ask you to do. The moment they want your password, a one-time code or a seed phrase, or tell you to transfer money "for safety," install remote software, or click a link to log in, treat it as a scam no matter what company they claim to be. Hang up and verify through support inside the official app yourself.

The link they sent looks exactly like the official site. What now?
A page can be cloned perfectly, but the domain can't lie. Compare the main domain in the address bar letter by letter; if anything differs, close it. The safest move is not to click the link at all: type the official domain yourself or use a bookmark.

I've already given them a code or password. Is it too late?
Change the password on a separate device right away, sign out of every session, turn on two-step verification, and contact the platform to freeze the account. The faster you move, the better your chance of holding the account before they act. If a crypto wallet's seed phrase is exposed, move the assets to a new wallet at once.

They keep pushing me: "pay now or the money is gone." How do I hold firm?
"Limited time, act now, or it expires" is the scammer's favourite pressure line, built to leave you no time to check. Genuine official business doesn't mind you being slow. Treat the rush as a warning sign, not a reason: end the call or stop the chat, then verify yourself through the official app or a domain you typed by hand. Better to miss a fake "opportunity" than to move money in a panic.

Where to verify: methods for spotting scams can be cross-checked against the "security centre / fraud tips" pages on the official sites of banks, transfer companies and exchanges, and against the public guidance of your own country's anti-fraud and consumer-protection bodies. This article is education, not aimed at any specific company, and is not investment or legal advice.
Published 18 Jun 2026: starts from the most common trick, the advance "release fee," then takes apart the shared skeleton behind all five scams, with a domain-check method, shared-device self-defence, a post-scam order of actions, and a red-flags checklist.
Updated 2 Jul 2026: added seven scam variants (romance-baited transfers, fake investment, fake charity, overpayment, family impersonation, OTP harvesting, SIM-swap — each with one question that breaks it), expanded "if you've been scammed" into seven steps (saving evidence, trying to recall, avoiding the recovery second-scam), added a section on teaching family and older relatives to stay safe, and a channel-by-channel "who to report to" table.


ZL

Zhou Lan

Worked in remittance support and has seen savings lost to “pay a release fee first.” Lays out the common scams so you can spot them.About the author →