"Pay a release fee first and you'll get the money": that's how it disappearsMoney transfer scams and safety: fake support, phishing and shared devices
An SMS says you have a transfer waiting, just click the link to verify. A caller says pay a small release fee and the money lands. Can you tell which line is real and which is the setup? Most cross-border transfer scams run on the same handful of skeletons. This guide takes the five most common ones apart, then shows you how to check an official domain in three seconds, protect yourself on a shared device, name the few things you must never hand over, and limit the damage fast if you do get caught. Recovering funds after you file a report is a matter for your local police and regulators, so that part is out of scope here.
Why money transfers attract scams
Cross-border money is a favourite target for scammers, for very practical reasons. First, the amounts are usually meaningful; what you send home can be a whole month's pay. Second, the process is unfamiliar to many people, and unfamiliarity makes it easy to be led along by "expert" talk. Third, chasing money across borders is extremely hard: once funds leave the country, and especially once they become cash or a crypto-asset, they are almost impossible to claw back.
Scammers don't win with clever technology; they win by manufacturing urgency and trust. They pretend to be official, pretend to be helping you, pretend the chance is slipping away, so you act before you check. The key to spotting a scam isn't memorising every new variation. It's recognising the shared skeleton underneath them. The five playbooks below cover the great majority of cases.
Five common money-transfer scam playbooks
1. Advance "release fee / deposit" before you can receive
Someone says there's money waiting for you, such as a prize, a refund, a transfer from family, a platform reward or an incoming stablecoin payment, but it's "stuck" at some step, and you must pay first: a release fee, a deposit, a customs charge, a tax. Once you pay, the money either vanishes or a new charge appears under a fresh name. In any legitimate channel the recipient never has to pay first. This is the easiest playbook to spot, and the most common.
2. Impersonating an "official agent / security team"
Someone claims to be from your bank, transfer company or exchange, in support, risk, or a security team, and says your account is "flagged, frozen, or at risk." They ask you to "verify": read out a one-time code, share your password, move money to a "safe account," or screen-share so they can "fix it for you." No legitimate support agent will ask for your password, one-time code, private key or seed phrase, and none will tell you to move money elsewhere "to keep the platform safe." Anyone who contacts you out of the blue, creates panic, and demands you act immediately should be hung up on; then verify by opening the official app yourself or typing the official address by hand.
3. Phishing sites and fake apps
A scammer builds a page that looks almost identical to the real site, on a domain that differs by a letter or two (an "o" swapped for a zero, an extra hyphen, a different ending), then pushes the link at you by SMS, email, a social-media group or a search ad. You log in on the fake page, and your username and password are stolen. The whole trick is getting you to click a link and then type your password on a fake page, so the most effective defence is simple: always type the official domain yourself or use your own saved bookmark, and never log in through a link someone sent you.
4. Private chat and remote control
They pull you off the public platform into a private chat (a direct message, an encrypted group, a messaging app), then guide you to install "remote assistance" software, share your screen, or follow their steps one by one. Once you install remote software or share your screen, they can see your password and one-time codes, and can even operate your account and move money directly. No legitimate support agent needs remote control of your device. The instant anyone asks you to install remote software or share your screen, stop.
5. Fake recipient / changed payout details
This one targets the sender. The recipient's email or account is hacked, and a scammer poses as them to send "new payout details," steering your money to a stranger's account; or in a deal, a rental, or a shopping arrangement, they give you an account that looks reasonable but is really theirs. Treat any "let's change the payout account just this once" request as a major warning. Always confirm with the real recipient through a separate channel you already trust, such as a phone call or an in-person check, before you send a cent.
Seven more scam variants to recognise
The five above are the skeletons; what you actually meet is usually one of them in a different costume. The variants below hit people who send and receive money across borders especially often. Each comes with what the pitch sounds like and one question that breaks it. You don't need to memorise them, just learn the smell.
1. Romance-baited transfers ("pig butchering")
They build a relationship with you on a dating or social app, avoid money for weeks or months, and only once you trust them start easing into it: "I have an investment that always wins," "I've hit an emergency," "cover this for me." The pattern is relationship first, money later, and they never video-call or meet, always with a good reason.
The question that breaks it: "Can we video-call, or meet in the city you say you're in?" Real feelings don't fear daylight; someone who only wants money keeps finding excuses.
2. Fake investment / high-return platforms
They (possibly the same "romance," possibly an "investment mentor group") give you a slick-looking platform or app, have you deposit a small amount first, show you "profits" on screen, and even let you withdraw a little to win your trust. Once you scale up, you can't withdraw anymore, or you're told to pay a "tax / deposit" before you can. Being able to deposit but not withdraw, with the number always growing, is the classic tell.
The question that breaks it: "I'll withdraw my entire balance right now to test it." If you can't, or you're told to pay first, it's a scam.
3. Fake charity / emergency appeals
Using a disaster, an illness, a conflict or a pitiful story, they push you to "donate a little right now," and the payment route is usually a personal account, prepaid cards or a crypto wallet rather than a public, checkable, legitimate channel.
The question that breaks it: "What's the organisation's full name? I'll go to its official site and donate there myself." A genuine appeal survives you checking on the official site; a scammer only wants you to pay this account now.
4. Overpayment / refund-the-difference
Common in second-hand deals, buying-on-behalf, or freelance payments: they "accidentally overpaid," or use a fake transfer screenshot or a bad cheque to make you think the money arrived, then ask you to send back "the extra," or to front the cash to buy and ship something. After you refund or ship, you find their money never landed or was later reversed. Any incoming payment that has you refund or front money first deserves a pause.
The question that breaks it: "Once the money has truly cleared into my account and I can freely use it, then we'll talk; a screenshot doesn't count."
5. Impersonating family: "new number, need money urgently"
A message from an unknown number or a hacked account claims to be your child, parent, boss or a friend: "I changed numbers / lost my phone," followed by an emergency that needs money right now, often with "don't call, I can't talk at the moment" — that instruction exists precisely to stop you from verifying.
The question that breaks it: call back on the number you already had saved, or ask a personal question only the real person could answer. "Can't take a call" is exactly where you should get suspicious.
6. One-time code / OTP harvesting
Anything that, in the name of "verifying your identity / confirming it's you / releasing this transfer / cancelling a suspicious transaction," gets you to read out or forward the SMS code you received is almost always taking that code to log in or move money out of your account. A one-time code exists only to prove "it's really you," so handing it over hands over the key.
The question that breaks it: read the SMS itself — a legitimate code message usually says "do not share this with anyone." Anyone who asks, gets nothing.
7. SIM-swap / phone number hijack
Here the scammer works the carrier's end: using some of your personal details to request a "replacement SIM / number port," they move your number onto their phone, after which every SMS code sent to you lands in their pocket, letting them break into accounts tied to that number one by one. The signal: your phone suddenly loses signal or can't make calls, with no fault you can find.
The question that breaks it (self-check): the instant your phone loses signal for no reason, use another device to log into important accounts and change passwords, and contact your carrier to confirm whether the number was tampered with. For important accounts, prefer an authenticator app or a physical security key over SMS codes alone.
Verify the official domain: the single best anti-phishing move
Almost every stolen account starts with a password typed on a fake page. Learn to check a domain in three seconds and you block most of the risk. Read the address bar right-to-left and run these steps:
- Read the domain from right to left. What actually decides a site's identity is the "main name + ending" pair (in example.com, that's example.com). Scammers pad the front with reassuring words, like login-example-secure.com, where the real main domain is example-secure.com, not example.com at all.
- Compare letter by letter. Swapping "o" for a zero, "l" for a "1," adding a hyphen, or changing the ending (.com to .co, .net, .xyz) are all common tricks. Hold it against the official domain you know for certain, and not a single character may differ.
- Don't reach a login page through a link someone sent. Links in SMS, email, group chats and even search ads can all be phishing. To log in, type the domain yourself or use a bookmark you saved earlier.
- Stick to the official app. Searching your phone's official app store, checking the developer name, then installing, is harder to fake than hunting for an entry point in a browser.
sponsored tag; make sure you're on Binance's official page and don't arrive via a strange link before you type anything.
Staying safe on shared and public devices
Many people working abroad use an internet café, a shared dorm computer, or a friend's phone to send money, and those devices carry more risk. If you have no choice:
- Prefer your own device and your own mobile data; log in and move money on public computers or unknown Wi-Fi as little as possible.
- Use the browser's incognito / private mode, log out immediately when done, and never tick "remember password" or "stay signed in."
- Afterwards, clear the browsing history and cookies; if you lent your own phone to someone, check whether any unfamiliar app was installed.
- Watch for shoulder-surfing: shield the screen while typing a password or one-time code, and mind who is behind you and any cameras.
- Turn on two-step verification for your phone and important accounts; if a password leaks on a public device, that extra step buys you time.
- Never save or screenshot any password, private key or seed phrase on a public device.
What you must never hand over
Hold this boundary and you sidestep almost every "fake support" and "fake helper": these things go to no one, for no reason, through no channel.
- Your login password: no legitimate support agent needs your password.
- SMS / app one-time codes: a one-time code exists to prove "it's really you," so handing it over is handing over the account.
- Private key and seed phrase (wallet recovery words): this is the master key to a crypto wallet, and anyone who gets it can move every asset you hold. No legitimate platform, agent or staff member will ever ask you for a seed phrase.
- The full combination of card number + the security code on the back + the expiry date, and any one-time password your bank sends.
Red flags vs normal: a side-by-side checklist
Burn this table into memory. If any one row matches, stop and verify. Better slow than sorry, and never rush the money.
| Red flag (be on alert) | What's normal |
|---|---|
| Asks you to "pay a release fee / deposit / tax" before you can receive | A recipient never has to pay first |
| Claims to be an official agent, asks for your password / code / seed phrase | Legitimate support never asks for these |
| Rushes you: "right now, or it will be frozen / expire" | Genuine matters survive you checking slowly |
| Sends a link for you to click and log in | Type the domain yourself or use a bookmark |
| Wants you to install remote software or screen-share | No legitimate support needs to control your device |
| Pulls you into private chat or an encrypted group for "guidance" | Real business runs on official, public channels |
| Recipient suddenly "switched to a new account" | Confirm with the person through a separate channel |
| Promises sure wins, no losses, protected high returns | No such deal exists; most likely a scam |
| Domain off by a letter or two, odd ending | Compare letter by letter with the official domain |
If you've been scammed: step by step
When something feels wrong, don't panic and don't delay. The faster you act, the more you can limit the loss. Work through this in order, and don't skip steps:
- Stop paying, cut contact. First stop every payment and every action they've asked for: don't send more, don't click more. Above all, never pay any "recovery fee / release fee / deposit" to "get the earlier money back" — that only digs the hole deeper. If they have remote control of your device, go offline and close the remote software.
- Save the evidence; don't delete anything. Before any fix, preserve what proves this happened: the full chat history (don't delete it or block them so far that you lose the record), transfer receipts / transaction IDs / the recipient's account or wallet address, screenshots of the URLs and pages they sent, and the caller's number and times. Screenshot or photograph it somewhere else; you'll need it for the platform and for the police.
- Contact your transfer platform / bank / exchange fast, and try to recall it. Find support through the official app or an address you typed by hand (never any contact the scammer gave you), explain you've been scammed, quote the transaction ID, and ask them to stop or reverse the payment. Timing is everything: a wire or app transfer that hasn't reached their account yet may be caught or returned; cash pickups and completed crypto transfers usually can't be reversed, but you should still report it at once, ask the platform to freeze the accounts involved, and flag it as fraud.
- Report it to local police / a cybercrime reporting channel. Bring the evidence from the last step and file with your local police or an official anti-fraud / cybercrime reporting channel, and get a report receipt or reference number. Cross-border recovery really is hard, but a formal report is what banks and platforms lean on to cooperate later, helps the investigation, and keeps others from being caught.
- Change passwords, turn on two-step verification, isolate accounts. If a password or code leaked, on a separate, clean device change the affected passwords one by one, sign out of all sessions, and enable two-step verification (prefer an authenticator app or a physical security key over SMS alone). If you reused that password elsewhere, change those too. If a crypto wallet is involved and the seed phrase may be exposed, move the assets to a brand-new wallet with a seed phrase only you know.
- Watch out for the "we'll recover it for you" second scam. After being scammed, you may well be contacted by people claiming to be "cyber police / a recovery firm / a claims lawyer / a platform specialist" saying "pay a fee / deposit and we'll get your money back," and they may even name the exact amount you lost (that info can come from a list the first scammers sold on). Anyone who wants you to pay again before they'll "help you recover" is almost always the second wave, targeting people freshly scammed and desperate to undo it. Pursue recovery only through channels you've verified yourself, and send nothing to anyone who approaches you.
- Warn the people around you. The same playbook is usually run in bulk, so tell family and friends, especially anyone on the same remittance corridor or platform, so they're forewarned.
Teaching family (especially older relatives) to stay safe
Often it isn't you, out earning and sending, who gets scammed, but the parents and elders receiving at home. They're less comfortable with phones, they worry about you working far away, and one line — "your child is in trouble," "there's money for you but it's stuck" — sends them into a panic. Rather than chasing it afterwards, make a few things clear in advance:
- Set one household rule: anything about "sending money / paying a fee" means hang up first and call me to confirm. Agree on the few fixed numbers and channels you'll trust; treat unknown callers as a reason to stop and check with you first.
- Turn "you never pay to receive money" into one easy line they'll remember: money that's truly for you never asks you to pay first. Anything demanding a release fee, tax or deposit up front is fake.
- Agree on a family code word or a private question. If someone impersonates you with "new number, need money urgently," the elder can test them with the code word or a question an outsider couldn't answer.
- Set their phone up for them: turn on two-step verification for important accounts, switch off "remember password," install official apps with the developer checked, and bookmark the real support entry points, so they don't have to search on the spot and land on a fake page.
- Spell out that a one-time code goes to no one, including anyone claiming to be you, the bank or a platform. Code SMS messages usually say "don't tell anyone" — point that out to them.
- Make it feel safe to ask. Many older people, once scammed, are too ashamed to speak up and miss the window to limit the loss. Tell them again and again: when unsure, ask; if scammed, tell the family first — the sooner said, the easier to handle.
Who to report to: a channel-by-channel guide
After a scam or a suspicion, you usually need several parties at once, each able to help with something different. The table below is by channel, in general terms — for exact contact details, go by an official channel you've verified yourself, and never use any number a scammer or a strange link gave you.
| Who | What they can help with | How to find the right entry |
|---|---|---|
| Transfer platform / exchange support | Try to stop or reverse a transfer not yet landed, freeze accounts, flag fraud, preserve records | Support inside the official app, or the official site you typed by hand |
| Your bank / card issuer | Stop or recall a bank transfer, freeze or cancel the card, watch for further suspicious charges | The support number on the back of the card / the official app / an address typed by hand |
| Local police / anti-fraud line | File a formal report, issue a receipt, open an investigation (police handle cross-border cases) | The official police or anti-fraud reporting channel published in your country / region |
| Cybercrime / consumer-protection reporting channel | Take online-fraud reports, aggregate cases, publish scam alerts | The public entry point of your country's official cybercrime or consumer-protection body |
| Your mobile carrier | Freeze and restore a hijacked number / swapped SIM, investigate the change | The carrier's official store, official app, or the support number on your bill |
| The impersonated platform / merchant | Report fake support, fake accounts and phishing domains, help take them down | The "report / security centre" entry on that platform's official site or app |
The most common mistakes
- Believing it because "they sounded so professional." A scammer's script is designed to sound professional. Judge by what they're asking you to do, not by how smoothly they say it.
- Acting under pressure without checking. "Now, or it's frozen" is the most common pressure line. Real official business doesn't mind you taking ten minutes to verify.
- Clicking a login link someone sent, to save effort. Even if it looks identical, type the domain yourself to get there.
- Paying more to "recover what's already lost." "Pay a little and we'll get it back" is usually a second scam, aimed at people who were just caught and are desperate to undo it.
- Treating a seed phrase like an ordinary password. It's the master key to the wallet; any page asking you to type your seed phrase is a trap.
Common questions
How do I quickly tell whether a "support agent" is real or fake?
Watch what they ask you to do. The moment they want your password, a one-time code or a seed phrase, or tell you to transfer money "for safety," install remote software, or click a link to log in, treat it as a scam no matter what company they claim to be. Hang up and verify through support inside the official app yourself.
The link they sent looks exactly like the official site. What now?
A page can be cloned perfectly, but the domain can't lie. Compare the main domain in the address bar letter by letter; if anything differs, close it. The safest move is not to click the link at all: type the official domain yourself or use a bookmark.
I've already given them a code or password. Is it too late?
Change the password on a separate device right away, sign out of every session, turn on two-step verification, and contact the platform to freeze the account. The faster you move, the better your chance of holding the account before they act. If a crypto wallet's seed phrase is exposed, move the assets to a new wallet at once.
They keep pushing me: "pay now or the money is gone." How do I hold firm?
"Limited time, act now, or it expires" is the scammer's favourite pressure line, built to leave you no time to check. Genuine official business doesn't mind you being slow. Treat the rush as a warning sign, not a reason: end the call or stop the chat, then verify yourself through the official app or a domain you typed by hand. Better to miss a fake "opportunity" than to move money in a panic.
Where to verify: methods for spotting scams can be cross-checked against the "security centre / fraud tips" pages on the official sites of banks, transfer companies and exchanges, and against the public guidance of your own country's anti-fraud and consumer-protection bodies. This article is education, not aimed at any specific company, and is not investment or legal advice.
Published 18 Jun 2026: starts from the most common trick, the advance "release fee," then takes apart the shared skeleton behind all five scams, with a domain-check method, shared-device self-defence, a post-scam order of actions, and a red-flags checklist.
Updated 2 Jul 2026: added seven scam variants (romance-baited transfers, fake investment, fake charity, overpayment, family impersonation, OTP harvesting, SIM-swap — each with one question that breaks it), expanded "if you've been scammed" into seven steps (saving evidence, trying to recall, avoiding the recovery second-scam), added a section on teaching family and older relatives to stay safe, and a channel-by-channel "who to report to" table.