Scam Detective
Scam wave report · Edition 5 · August 15, 2026

This Week's Scam Wave, in Numbers

Scam Detective's research desk documented 10 net-new scam patterns this week — every one deduplicated against our August 12 edition, the August 9 edition, the August 2 edition, and the July 30 edition before it. The shape of the wave, in numbers:

Scam Detective research desk · Published
Got one of these in your hand right now?
Paste the link, number, or sender into the instant check — free risk signal in 60 seconds, the full 0–100 report for $2, one-time.
Check a suspicious link — $2
10
Net-new scam patterns documented by our research desk this week
7 of 10
Trade on trust you already hold — a brand, an agency, your boss, or a familiar face
2 of 10
Put a synthetic face on the pitch — deepfake video of your boss or a famous doctor
2 of 10
Start inside a dating-app or marketplace conversation you began yourself
2 of 10
Promise money coming to you — a prize or an exit — then charge a fee first
The data

The wave, pattern by pattern

01
Crypto-exchange “withdrawal alert” texts
Arrives via text message · The costume: Your crypto exchange's security team
No — scamFull verdict →
02
“Password expiring” emails with a QR code
Arrives via email · The costume: Your company's IT department
No — phishingFull verdict →
03
Deepfake “boss” video-call payment orders
Arrives via video meeting · The costume: Your own executive
Verify it yourselfFull verdict →
04
Medicare “verify your number” cold calls
Arrives via phone call · The costume: Medicare or your health plan
Yes — scamFull verdict →
05
Fake “your computer is infected” popups
Arrives via browser popup · The costume: Microsoft or Apple support
Yes — scamFull verdict →
06
Deepfake “famous doctor” supplement ads
Arrives via social video ad · The costume: A trusted physician
No — scamFull verdict →
07
Timeshare “exit specialist” upfront fees
Arrives via cold call / mailer · The costume: A timeshare exit firm
Verify it yourselfFull verdict →
08
Dating-app “safety verification” sites
Arrives via dating app chat · The costume: A cautious match
Yes — scamFull verdict →
09
Marketplace “payment pending” screenshots
Arrives via marketplace dm · The costume: An eager buyer
Yes — scamFull verdict →
10
“You won” prize notices with fees first
Arrives via phone call / email · The costume: A prize or lottery organization
Yes — scamFull verdict →
Analysis

What stands out

01
The costume is no longer a stranger — it's your own circle.
Your boss on a video call, a match you've been chatting with for weeks, a buyer inside your own listing thread, a doctor whose face you know — seven of this week's ten patterns trade on trust the victim already holds. The pitch doesn't break in anymore; it was invited.
02
AI video crossed from the ad break into the meeting room.
Deepfakes used to mean a celebrity shilling an investment in a sponsored post. This week they are your executive ordering a wire transfer on a live call — a con that has already cost one firm $25 million — and a white-coated “doctor” selling supplements. Verification has to move from “does this look real” to “did I confirm it on a second channel.”
03
The QR code went to work.
After parking meters and doorstep packages, the QR code's latest posting is the workplace inbox: an “MFA expiring” email whose code opens a credential-harvesting login on your phone, beyond the reach of your organization's email filters. Security researchers now rank it among the fastest-growing email attack types.
04
Every entitlement grows a skimmer.
Medicare coverage, a prize payout, a way out of a timeshare — wherever money or benefits are owed to you, a middleman appears offering to “help” for a fee, and takes the fee, or the identity, or both. The legitimate version of every one of these is free and starts with you calling them.
05
A screenshot is not a system of record.
The marketplace “payment pending” image and the dating “verification” page both fake a receipt. Money and identity are only real inside the platform's own app — a picture of a payment is proof of nothing but the sender's graphics skills.
For businesses · $29, one-time
Is someone impersonating your brand?

The costume in these scams — a lookalike domain, a copied storefront, a spoofed sender — is exactly what the brand impersonation audit researches for your company: lookalike domains, typosquats, and copycat sites trading on your name, each with evidence and a risk rating, plus a ready-to-send takedown-request template.

Audit my brand — $29
Free brand scan first — you only pay for the full audit.
For your readers

What to do now

1
Verify on a second channel you initiate. An urgent payment order from your boss, an alert from your exchange, a call from “Medicare” — hang up or leave the meeting and confirm through a number or app you already have. No real institution objects to being double-checked; every scammer does.
2
Never pay a fee to receive money. Prizes, benefits, exits, and compensation that are truly yours never require upfront payment by card, wire, crypto, or gift card — a fee-first demand isn't a step in the process, it is the entire scam.
3
Check the link before you tap, scan, or pay. Paste it into Scam Detective's instant check ($2, one-time) before entering card or bank details anywhere new — and treat screenshots, QR codes, and “verification” pages sent in a chat as unproven until the platform's own app confirms them.
Methodology

This report is published by Scam Detective's research desk. The figures describe the mix of distinct scam scripts newly documented during the week of August 13–15, 2026: they are counts of scam patterns our desk verified and published as verdict pages at scam-detective5.acoco.ai/answers, not victim counts, loss estimates, or scans of customer-submitted URLs. Patterns are identified from the exact questions people search when a scam reaches them, cross-checked against public warnings from law-enforcement and consumer-protection agencies, including the FBI, the FTC, HHS-OIG, and state attorneys-general and consumer-protection offices. This edition is deduplicated against our July 30, 2026, August 2, 2026, August 9, 2026, and August 12, 2026 editions — every pattern below is net-new, and no entry repeats a pattern already covered in any earlier report.

Each pattern links to its full verdict page. Verdicts are educational, based on documented scam patterns — they are not live Scam Detective reports on specific URLs. Scam Detective does not run continuous monitoring or real-time threat feeds, and nothing in this report is legal advice.

For journalists

Using these figures

You may quote this report with attribution to Scam Detective and a link to this page:

https://scam-detective5.acoco.ai/reports/scam-wave-2026-08-15

Each pattern above links to its full verdict page for background, and the August 12 edition covers the ten patterns documented the prior week (with the August 9, August 2, and July 30 editions before that). To check a specific URL mentioned in your coverage, the instant check is $2, one-time — no subscription.

About Scam Detective: Scam Detective is pay-per-use scam intelligence — an instant $2 URL risk check and a $29 brand impersonation audit, delivered in minutes, with no subscription. Spot the scam before it spots you.

Got a link that matches this week’s wave?

Paste it into the instant check — free risk signal in seconds, the full 0–100 report for $2, one-time.

Check a suspicious link — $2Browse all verdict pages