Week 10: Old scams in new guise
Scammers are constantly adapting their methods in an attempt to deceive people online. In the past week, the NCSC received reports of two new scams that build on existing schemes or combine different approaches.
One scam involves a deceptively genuine-looking email sent in the name of Amazon. Recipients are told that they are one of "250 selected Swiss customers" who can win attractive prizes such as Amazon vouchers, the latest iPhone or a PlayStation 5.
Scam prize draw and phishing combined in a single attack
The message contains a link to take part in the alleged prize draw. In reality, this is a fraudulent prize draw designed to lure you to a website. There, it is mentioned – more or less clearly – that entering your credit card details signs you up to a multi-year subscription. This is not a typical phishing scam. The operators deliberately exploit legal grey areas in an attempt to avoid the site being taken down or a criminal complaint being filed. What is unusual in this case is that, when the link is clicked, a page opens where the victim is asked to enter their Amazon login details. This information is sent directly to the scammers. Armed with this information, the criminals can access the Amazon account, place orders, view stored payment information, and misuse personal data – classic phishing.
After that, the usual process begins: first, a survey; then, an alleged prize; and finally, a redirect to a subscription trap. In this case, the scammers have deliberately combined two scams. While this increases their potential profits, they also knowingly accept that the site may be taken down more quickly by adding this extra step.
Alleged theft of credit card numbers and other personal information
In scam attempts, the perpetrators aim to frighten and pressure as many potential victims as possible into acting without thinking. However, in the case of fake sextortion emails, this approach appears to be less effective, as people who have never viewed pornographic content are unlikely to fall for it. The situation is different when scammers claim that sensitive information, such as credit card details, has been stolen. Most people have entered their credit card number somewhere online at some point. This makes the threat seem plausible and may lead more victims to pay the ransom. Scammers who previously sent fake sextortion emails appear to have adapted their approach. Last week, the NCSC received numerous emails written in the same style and with very similar wording. The difference was that, instead of threatening to publish compromising images, the messages claimed that the scammers had obtained credit card numbers and other sensitive information and would sell them on the dark web. As reports received by the NCSC show, this caused considerable uncertainty among those who reported the emails.
While most people recognise standard fake sextortion emails as a scam, this wave of emails claiming that credit card data had been stolen triggered numerous reports from concerned individuals. Like fake sextortion emails, these messages often appear to have been sent from the recipient’s own email address in order to increase their credibility. In these cases, however, the sender address is spoofed.
Recommendations
Fraudulent prize draws and phishing
- Be wary of adverts on social media and emails with tempting promises of prizes.
- Be particularly careful if you have to log in or provide your credit card details in order to access a free offer.
- Protect your online accounts with two-factor authentication (2FA) wherever possible.
- Do not forward such competitions to your contacts.
- If you have entered your credit card details, contact your credit card provider immediately.
Alleged theft of credit card numbers and other personal information
- Ignore such emails and report them to your email provider as spam.
- Check your credit card statement and contact your card provider if you notice any irregularities.
- Only enter your credit card details on websites that transmit data in an encrypted form. Such websites can be recognised by the padlock symbol in the address bar of your browser and by the website address (URL), which will begin with «https://».
Current statistics
Last week's reports by category:


