Don’t Get Scammed: A Few Rules That Could Save You Thousands of Dollars

September 16, 2026

I know this is a long post, but it’s really important you read through all of it. If you're a client, I’m sure we've talked about being a smart computer user and being wary of computer scams. But, the bad guys just don’t quit and they are getting much more sophisticated and less careless. If you don’t have time to read this post right now, please come back to this when you do.

I've spent a considerable amount of time over the years helping clients clean up after they've fallen victim to online scams. Some have lost just the time it took to ask me if something was legitimate (good for them). Some have lost relatively small amounts of money. Others have lost thousands, tens of thousands, and in some cases hundreds of thousands of dollars. Almost all of these situations could have been avoided by following a few simple rules.

I've had clients receive fake invoices and then be instructed to purchase gift cards to pay them. I've had others receive an email supposedly from Microsoft or Google saying they needed to “verify” their email account. They clicked the button, arrived at a website that looked exactly like Microsoft or Google, and entered their email address and password. What they were actually doing was giving the bad guys their login information.

In some of the worst cases I've dealt with, the criminals didn't immediately change the password or do anything obvious. Instead, they logged into the victim's webmail and quietly monitored email conversations for months. They learned who the clients and vendors were, watched invoices and payment discussions, and waited for the right opportunity. They then created a domain that was off by only one letter—or sometimes substituted a Cyrillic character that looked nearly identical to a Roman character—and continued a legitimate-looking conversation (complete with stolen email signatures) with new ACH instructions. Because they already knew the people, invoice, amount, and context, the messages looked completely legitimate. The payment went to the criminal instead. I've seen situations like this result in hundreds of thousands of dollars in losses. This is a well-known type of fraud called Business Email Compromise and the FBI deals with this regularly.

The PayPal Scam Is Particularly Tricky

There's a separate PayPal scam going around that deserves special attention because one of the ways I normally tell you to spot a scam may not work. You receive an invoice from PayPal for something you never purchased. Maybe it's a computer, cryptocurrency, subscription, or some other expensive item. Naturally, you look at the From address to see whether the email really came from PayPal. It may have.
Scammers can use PayPal's legitimate invoice and money-request system to create fraudulent invoices. Because PayPal's system sends the notification, the email itself can legitimately come from PayPal. PayPal warns customers about invoices and money requests for products or services they never ordered, including invoices containing an urgent note telling the recipient to call a telephone number. That number may belong to the scammers, not PayPal.

So in this particular case, seeing a legitimate PayPal From address does not mean you owe the money. If you didn't buy it, don't pay it and don't call the telephone number in the invoice. Open PayPal yourself by using the PayPal app or manually going to PayPal's website and check your account there.

For my clients who don't regularly need PayPal, I would also suggest avoiding it as a purchasing method when there's a reasonable alternative. If you rarely or never make purchases through PayPal, an unexpected “PayPal invoice” becomes much easier to recognize for what it is. If you do regularly use PayPal, remember that an invoice is a request for payment—it isn't proof that you purchased something.

Never Click “Verify Your Account”

This is probably the most important rule in this article. If you receive an unexpected email or text with a button saying “Verify Your Account”, “Sign In to Continue”, “Confirm Your Identity”, “Secure Your Account”, “Restore Account Access” or something similar, DON'T CLICK IT.

These fake websites can look amazingly authentic. They have the right logo (they stole the real one), colors, fonts and login screen. But when you enter your username and password, you're not verifying your account. You're giving your username and password to the criminals!

If Apple, Microsoft, Google, Amazon, your bank, or anyone else says there's a problem with your account, go to the company's website yourself or open its official app. Don't use the link they gave you.

On a computer, get into the habit of moving your mouse over a button or link without clicking it and looking at the address it will actually take you to. An Apple phishing link might contain something such as apple.security.example-scam-site.com. The important part is the actual domain—in this example, example-scam-site.com, not Apple. Scammers also use misspellings and look-alike characters that are very easy to miss. In this example, the scammers own the example-scam-site.com domain and they can add anything they want before it (like apple.security, microsoft.email or even disney.vacation) to try to trick you into thinking it’s coming from the company they’re pretending to be.

Look at Who REALLY Sent the Email

Don't just look at the name displayed at the top of an email. Click or tap on it and look at the actual From address. I've seen messages labeled “Apple Support,” “Microsoft Support,” and other well-known companies that actually came from completely unrelated domains—and sometimes even from a Gmail address!

That's a huge red flag, but remember the PayPal example: a legitimate From address doesn't necessarily mean the request itself is legitimate. A real account or service can be abused, and a legitimate person's email account can also be compromised.

Don't Let the Scammer Tell You How to Contact the Company

If an unexpected email, text, phone call or pop-up tells you something urgent has happened, you should be the one to initiate the next contact. Don't click their link and don't call the telephone number in the message. If it's supposedly your bank, call the number on the back of your card. If it's Apple, Microsoft, Amazon or another company, go to the company's website yourself and get the number there.

And don't trust Caller ID. A call that appears on your iPhone as “Apple,” “Amazon,” your bank, or even a familiar local number can be spoofed.
The same rule applies to businesses receiving new payment instructions. If a vendor suddenly emails you saying, “We've changed banks—please send this $75,000 payment to our new ACH account,” call the person using a telephone number you already know and verify it verbally. Don't use a new phone number supplied in that email.

Gift Cards, Passwords and Remote Access

If someone tells you that you need to buy gift cards to pay a bill, fine, tax, debt or other obligation, it's a scam. Don't do it.

Never give anyone your password, Social Security number, PIN or a security code that was just sent to your phone. In particular, if someone asks you to read them the six-digit verification code you just received, don't give it to them. That code may be the last thing they need to get into your account.

And this one is particularly important: NEVER allow an unexpected caller to connect remotely to your computer. Microsoft isn't calling because it discovered a virus on your Mac or PC. Apple isn't calling because your computer has been hacked. Don't install software for them, don't give them a connection code and don't share your screen.

Of course, legitimate remote support is different. I regularly connect remotely to my clients' computers when providing support, but you contacted me, you know who I am and you know why I'm connecting to your computer. An unexpected stranger asking for remote access is an entirely different situation. Don’t ever do this.

Please Start Using Two-Factor Authentication

Passwords alone aren't enough anymore. I strongly recommend that everyone use two-factor authentication (2FA) on every important account that supports it.

At the very least, use your mobile phone number so that signing in requires both your password and a code sent to your phone. Even better, use an authenticator instead of SMS whenever the service supports it. An authenticator generates temporary codes that typically change every 30 seconds and doesn't depend upon your cellular phone number.
If you're using 1Password, this capability is built in. Apple also has authentication-code support built directly into the Passwords app on your Mac, iPhone and iPad. You don't necessarily need another application.

I really want my clients to move toward this type of authentication. If you don't know how to set it up, contact me. I'll be happy to teach you how to use it and help you get your important accounts protected.

When in Doubt, Contact Me BEFORE You Do Anything

The scams keep changing, but the basic defense doesn't: slow down. Scammers depend on urgency. They want you worried about the $799 computer you supposedly just purchased, the anti-virus subscription that “just expired”, the bank account that's supposedly been compromised, or the email account that's supposedly about to be disabled. They want you to act before you have time to think.

If you're a Goodman Consulting client and receive an email, text, phone call, invoice, account-verification request, payment request or computer warning that you're unsure about, contact me before you do anything. Send me a screenshot, forward me the email or call me and ask, “Phil, is this legitimate?”

Don't worry about bothering me. I'd much rather spend five minutes looking at something and tell you it's legitimate than spend hours or days (which I have had to do) trying to recover a compromised email account, stolen passwords, fraudulent payments or identity theft.

I've spent enough time helping clients clean up after these scams. I'd much rather help you avoid becoming the next victim.

The rules are really pretty simple: Don't click “Verify Your Account.” Don't call the number in a suspicious message. Don't give anyone your password or verification code. Don't pay bills with gift cards. Don't accept changed banking instructions without independently verifying them. Don't allow an unexpected caller to connect to your computer. Use two-factor authentication. And when you're not sure, ask me first.

Photo by Markus Winkler: https://www.pexels.com/photo/scrabble-tiles-spelling-scam-on-wooden-table-30885932/