"Hi. Got a minute? I am stuck, can you send me a quick transfer for 50? I will pay you back tomorrow."
That is your friend writing. From their account, with their photo, in their usual tone. Except it is not them - and to avoid instant payment and text message scams like this one you need a habit rather than software, because these attacks never touch your phone.
They target your hurry, your reflex, and your willingness to help a friend.People lose tens of millions to this every year, and not the people you would assume. Not grandmothers who never used a computer. People like you and me, in a hurry, in the middle of something else.Here are the three most common versions, and the rule at the end.
Scam 1: the friend who needs an instant transfer
You get a message on WhatsApp or Messenger. The photo matches, the name matches, the account is authentic.
"Listen, I have a problem with my bank, I cannot make a transfer. Can you send it and I will pay you back tonight?"
The hook is simple. It is not your friend. Someone seized their account and is bulk messaging their entire contact list. They bet that three out of two hundred people will be distracted enough to help.
You sent the money. Instant payment systems - Zelle, Revolut, Faster Payments, SEPA Instant - clear in seconds and do not reverse. That is the entire reason criminals prefer them to card payments.
What to do: call. Do not write back, call. You hear the voice and within five seconds you know.
And when someone asks you for money because "the bank is down", a red light should come on. Banks work.
The mechanism is not technical at all. Scammers are counting on your hurry, your distraction, and your instinct to help a friend. That is the whole thing.
Scam 2: The delivery text with a tiny fee
When we talk how avoid instant payment and text message scams we can't forget about the most common one, by volume.
"Your parcel has been held, pay 2.49 to release it."
"Your package is waiting, one cent outstanding in customs."
"Underpayment on your electricity account, disconnection pending."
"Your bank account has been blocked. Click here."
Notice the amounts. They are comically small, and that is the point. Two euros is below the threshold at which you stop and think. It costs less than the effort of checking. So you click, and you pay.
The link takes you to a page that looks exactly like your bank or your delivery company. You enter your card details. And you have not handed over two euros - you have handed over the contents of your account.
The rule: no courier and no bank asks you to pay through a link in a text message. Ever.
If you are genuinely unsure about a parcel, open the delivery company's app manually - not from the link - and check whether a problem exists.
Scam 3: "Good morning, I am calling from your bank"
The most dangerous one, because it catches people who already know about the first two.
The phone rings. A pleasant, calm voice: "Good morning, I am calling from your bank's security department. We have detected a suspicious transaction on your account."
The agent knows your name. Sometimes the last four digits of your card. They sound professional, unhurried, and mildly concerned on your behalf. Then comes the line:
"To protect your funds, we need to move them to a secure account."
Stop there. There is no such thing as a secure technical account used for this purpose. That phrase was invented by criminals and it exists nowhere in banking.
A real bank will never ask you over the phone for a password, for a code from a text message, or to move money "for safety".
What to do: hang up. That is the entire instruction. Then take your card, and call the number printed on the back of it yourself. If something is genuinely wrong, you will find out in two minutes. And if it was a scammer, you have just saved your savings.

Why you cannot avoid instant payment and text message scams by being smart
Notice what all three scenarios have in common, because it explains why intelligence offers so little protection here.
They all manufacture time pressure. A friend stuck somewhere. A parcel about to be returned. A suspicious transaction happening right now. Urgency short-circuits the part of your thinking that asks questions, and every one of these scripts is built to create it deliberately.
They all arrive through a channel the criminal chose. They message you, they text you, they call you. In every case, you are responding on their terms, on their timing, with their framing already established. That is why the fix always involves switching channels - it takes the initiative back.
They all borrow trust you already have. Your friend's face. Your delivery company's branding. Your bank's tone of voice. None of these attacks build credibility from scratch. They borrow it from something you already believe in.
And critically, none of them require any technical skill. There is no malware, no exploit, no clever code. The entire attack is social. Which is why security software is largely irrelevant to it, and why a habit is the only defence that works.
What this looks like inside a small company
The same three scripts run against businesses, with the amounts multiplied.
The "friend in trouble" becomes an email from the CEO to the finance team asking for an urgent payment while he is supposedly travelling. The delivery text becomes an invoice from a real supplier with altered bank details, sent at exactly the moment a real payment is expected. The bank call becomes someone claiming to be from your payment provider.
If you run a business, the countermeasure is a written rule rather than a habit: no payment above an agreed threshold gets executed on the strength of one channel. Not one email, not one call, not one message. Somebody verifies on a second channel, using contact details already on file, before the money moves.
That one policy stops the most expensive category of attack small companies face, and it costs nothing to introduce.
How to avoid instant payment and text message scams makes this personal
I work with companies, and I have watched the same mechanism operate inside my own family.
Someone close to me - smart, capable, not the person you would expect to fall for this - got a call "from the bank". The agent was so calm and so businesslike that she nearly read out the code.
One thing saved her. She put the phone down and called me first. All I said was: hang up and call the bank yourself.
This is not a question of technical knowledge. It never was. It is a question of one second of stopping.
Bottom line
If you take one sentence from this article, take this one:
"I hang up and I check for myself."
You do not click the link. You do not read out the code. You do not trust the hurry. You check, on a channel you chose rather than the one they chose.
That single habit stops all three of these scams, and most of the ones that will replace them next year.
The version of this attack that is growing fastest uses a cloned face and voice - see deepfake CEO fraud prevention for small business. And the habits that let attackers reach you in the first place are here: everyday habits that expose your personal data.




0 Comments