The old version of this scam was easy to laugh off: a stranger, a wildly implausible story, a message riddled with mistakes. The newer version skips all of that. It opens with your actual first name, mentions the delivery you're actually expecting, or references the company you actually work for. That accuracy does something a generic message never could — it makes the story feel pre-verified before you've verified anything at all.

Why a familiar detail isn't proof of anything

A message that knows a true thing about you feels earned, like the sender must be legitimate to know it. But personal details travel through far more channels than most people realize: data breaches at companies you've done business with, public records, information you've posted yourself, and smaller earlier scams that quietly harvested a name and a phone number to sell to the next one. None of that requires the person contacting you now to be who they claim.

The useful reframe is this: a familiar detail tells you something leaked somewhere. It doesn't tell you who's actually on the other end of this message. Treat it as neutral information — interesting, worth being annoyed about, but not evidence of legitimacy.

The four ingredients every version of this scam is mixing

Strip away the personalization and almost every version of this scam is built from the same four parts, just recombined:

  • Urgency — a deadline, a threat of loss, an account about to be suspended.
  • Borrowed authority — impersonating an employer, a government office, a delivery service, or even a family member in trouble.
  • A request to skip your normal verification step — "don't tell anyone," "use this link instead," "reply here rather than calling the number you already have."
  • A payment method that's hard to reverse — gift cards, wire transfers, cryptocurrency, or a peer-to-peer payment app.

The personal detail is the wrapper, not the mechanism. It's bolted onto one of these four to make the wrapper more convincing — the underlying ask hasn't actually changed in years.

The one habit that beats every version

Call it the callback rule: never verify a message using contact information the message itself gave you. If something claims to be your employer, your delivery carrier, or your financial institution, stop responding inside that channel and reach the organization a different way — a number on a card you already have, an app you already installed, a website you already had bookmarked, a phone number you looked up yourself rather than one that was texted to you.

This single habit defeats the scam regardless of how convincing the personalization is, because it removes the attacker's control over what happens next. A legitimate organization will always survive you hanging up and calling back through a channel you trust. A scam depends on you never taking that detour.

A close-up of a hand hovering over a phone screen beside a stack of unopened mail
A familiar detail doesn't verify the channel. Checking through a number you already trust does.

Red flags that don't change no matter what the story is

Regardless of the disguise — a delivery notice, a job offer, a family emergency, an account warning — the same tells tend to show up:

  • Urgency paired with secrecy, especially a push to not mention it to a partner, a coworker, or your bank.
  • Resistance to you calling back through a number or app you already had before the message arrived.
  • A request to move the conversation to a new app or a "private" channel mid-conversation.
  • A payment method you could never claw back once it's sent.
  • Small mismatches once you look closely — a reply-to address that doesn't match the organization, or a caller ID that doesn't line up with who's supposedly calling.
  • An unusually helpful offer to walk you through steps on your own device or screen, step by step, in real time.

A short playbook for the moment you're not sure

  1. Pause. This kind of scam is built to outrun your thinking. Sitting with it for even a few minutes defeats most versions of it.
  2. Don't respond inside the same channel. Hang up, close the message, or navigate away instead of replying where you are.
  3. Verify independently using contact information you already had before this message showed up — never a number or link it supplied.
  4. If money has already moved, contact your financial institution through its normal channels immediately; speed genuinely matters here.
  5. Report it to the appropriate consumer-protection or fraud-reporting body, and tell someone else about it. Saying it out loud tends to surface the parts that don't add up.
A message that knows your name is telling you about a data breach somewhere, not about who's actually on the other end. Verify the channel, not the detail.

Questions to ask before you act

  1. Did I initiate this contact, or did it arrive out of nowhere?
  2. Is anything so urgent it can't wait for me to verify independently?
  3. Am I being asked to keep this from someone who'd normally help me decide?
  4. Could I hang up right now and reach this same organization through a number or app I already had?
  5. Is the requested payment method something I could ever get back if this turns out to be wrong?
The bottom linePersonalization is the newest disguise, not a new kind of scam. The mechanics underneath — urgency, borrowed authority, a channel you can't verify, and a payment you can't undo — haven't changed. When a message gets your real details right, treat that as a reason to verify through a separate channel, never as a reason to skip the step.