You could've applied all 1,449 Oracle patches and still been hit by this attack
An old friend messages you about an incredible crypto opportunity they’ve been using, showing screenshots of impressive returns. The platform looks professional and the interface is slick, so you decide to invest a few thousand dollars to test it. Seeing your money grow daily encourages you to add more. Just when you want to withdraw your funds, the platform vanishes overnight, your friend stops responding, and you realize the entire thing was an elaborate hoax designed to separate you from your savings.
Incidents like these don’t only target tech enthusiasts or risk-seeking traders. The victims also included retirees, first-time investors, and everyday people trying to build financial security who are systematically targeted by criminal operations.
If you are considering investing in cryptocurrency, this guide will help you learn about common types of crypto fraud, recognize their warning signs, and adopt strategies to avoid falling victim to crypto-related cyber threats.
Crypto and NFT scams are fraudulent schemes that exploit the unique characteristics of blockchain-based digital assets to deceive victims and steal their money or tokens. Unlike traditional financial fraud, these scams leverage the irreversible and complex nature of blockchain transactions, the lack of consumer protection mechanisms in an unregulated sector, and the fear of missing out on the next big opportunity.
Cryptocurrency is digital money that uses cryptography for security and is traded on decentralized networks called blockchains. It is digital cash that no single bank or government regulates. On the other hand, non-fungible tokens (NFTs) are unique digital certificates of ownership recorded on a blockchain, commonly used to represent digital art, collectibles, or membership rights. Being non-fungible means each token is one-of-a-kind and can’t be exchanged one-to-one like currency.
The scams targeting these assets take many forms, including fake investment platforms that display fabricated profits, fraudulent token projects where creators disappear with investors’ money, phishing websites that steal your digital wallet credentials, and long-con relationship scams. Unfortunately, transactions related to these scams cannot be reversed by calling your bank or credit card company. Once your crypto or NFTs are gone, they’re almost always gone for good.
In 2024, the Federal Bureau of Investigation’s Internet Crime Complaint Center recorded 859,000+ cybercrime complaints, with total losses of $16.6 billion, a 33% increase over 2023. Of that total, approximately $9.3 billion involved crypto investments or payments, spread across roughly 150,000 complaints.
Losses from global rug-pull scams, which are phony crypto offerings that quickly skyrocket and then plunge to near worthlessness, reached nearly $6 billion in early 2025, despite a decline in incidents.
Scammers now prefer cryptocurrency as the payment method for all kinds of fraud, whether it’s for tech support, romance, phishing, or extortion scams, because it’s difficult to trace and impossible to reverse. The moment someone tells you to download a crypto wallet app or send payment via Bitcoin, Ethereum, or any other digital currency, you’re likely dealing with a criminal.
Because of the decentralized, borderless nature of cryptocurrency, international criminal syndicates are able to operate from jurisdictions with weak enforcement while targeting victims worldwide. This problem isn’t just affecting young, tech-savvy early adopters or risk-seeking day traders. It is also affecting ordinary people worldwide, including first-time investors and victims of other types of scams across all age groups.
Individuals aged 60 and over, who lost a total of $2.8 billion in 33,000 crypto fraud incidents in 2024, face particularly severe financial impact as this amount represents their life savings, retirement funds, or money earmarked for healthcare, housing, or supporting family members. The emotional and financial devastation extends far beyond the dollar figures.
Older adults are so heavily targeted because they’re more likely to have substantial savings available to invest, may be less familiar with how cryptocurrency works, and often have more time to engage with scammers. In some cases, individuals were seeking to financially recover after recent market downturns, making high-return crypto promises particularly appealing.
Younger investors are targeted through different channels, such as social media, but the fundamental vulnerability remains the same: the promise of quick wealth and sophisticated social engineering.
Considered the most devastating category, pig-butchering scams originate from the farming practice of fattening a pig before slaughter, chillingly describing the scammer’s approach. These long cons run for months as criminals build relationships with victims through dating apps, social media, or wrong-number texts that turn into friendly conversations.
Gradually, the scammer will introduce the topic of cryptocurrency, positioning themselves as either a successful investor or someone learning from a knowledgeable mentor. Patiently, they guide the victim onto a fake but professionally designed, fully functional trading platform that shows real-time market data and walk them through making initial deposits and trades. On screen, the victim sees their account balance grow, which encourages them to deposit increasingly larger sums. Many even liquidate retirement accounts, take out loans, or sell property to invest more.
When the victim attempts to withdraw funds, the platform suddenly requires tax payments or verification fees, or threatens frozen accounts unless more money is deposited.
If victims refuse to send additional funds, the scammer ghosts them, the platform shuts down, and they discover that no trading ever occurred. Every dollar they sent went directly into criminal wallets.
Modern rug pull schemes are named for the action of pulling the rug out from under someone and leaving them shocked or helpless. One popular rug-pull method involves memecoins such as Dogecoin and Shiba Inu, which were hype-driven cryptocurrencies inspired by internet trends. Another involves DeFi (decentralized finance) projects, which offer financial services such as trading, lending, and investing outside of traditional banks.
Both can be legitimate, but their fast-moving, lightly regulated nature also makes them prime targets for scams, especially rug pulls where creators suddenly drain funds and disappear. However, these schemes do not offer a clear utility or roadmap, relying entirely on hype, memes, and community without articulating a specific use case, technical innovation, or development path.
To build credibility before they exit, scammers might:
Targeting NFT holders and crypto traders, this evolving scam includes:
The common thread across all these attacks is social engineering combined with the irreversible nature of blockchain transactions. Your confusion, an urgent email, one click, and your assets are gone with no way to reverse the transaction.
From 2020 to 2022, many of these early crypto and NFT scams consisted of poorly designed websites, unrealistic promises, and little effort to hide criminal intentions. Today, crypto criminals have become more efficient and effective. As an example, the number of rug-pull incidents declined by about 66% in early 2025, yet the total value stolen still exploded to $6 billion, up from roughly $90 million the year before.
Organized crypto scam operations are characterized by:
Protecting yourself from modern crypto scams requires more than awareness; it demands consistent habits, smart decision-making, and the right tools. As threats continue to evolve, building strong security practices today is the best way to stay ahead of increasingly sophisticated attacks.
Given that investment fraud is now the top fraud category by value in the U.S. and crypto-enabled fraud accounts for the majority of those losses, you will need to critically evaluate whether investing in cryptocurrency or NFTs aligns with your financial goals and risk tolerance.
This space combines extreme price volatility, complex technical requirements, irreversible transactions, minimal consumer protection, and a target-rich environment for criminals. If any of the following apply to you, your wisest choice is to proceed with extreme caution or avoid crypto investment entirely:
Choosing not to invest in crypto isn’t missing out, but making a risk-aware decision. Traditional, regulated investment vehicles may offer lower potential returns, but they come with legal protections, regulatory oversight, and mechanisms for recovering from fraud.
If you decide to invest in cryptocurrency or NFTs anyway, adopt these fundamental security practices to dramatically reduce your vulnerability:
If someone reaches out to you through any medium who steers the conversation to cryptocurrency investment opportunities, you’re almost certainly being targeted for fraud. Legitimate investment opportunities don’t find you this way.
Similarly, any communication that promises guaranteed returns, uses urgency, or pressures you before you can independently verify information is a red flag.
Before depositing funds anywhere, verify the platform’s legitimacy through multiple independent sources. Look for:
If you’re holding cryptocurrency or NFTs yourself rather than on an exchange, you’re personally responsible for security. Essential practices include:
Discovering you’ve been scammed is devastating, but taking immediate action could limit the damage and help law enforcement track and stop criminal operations:
Scammers often follow successful scams with additional pitches: recovery services usually run by the same criminals, tax payments supposedly required to unlock frozen funds, or claims that you’re so close to breaking even if you just invest a bit more. Every additional dollar you send is stolen money. Stop entirely.
Before anything disappears or times out, make sure to save:
This documentation is essential for law enforcement investigations and any potential recovery efforts.
While full recovery is rare, rapid reporting has occasionally allowed exchanges to freeze funds or helped international task forces seize assets before they’re fully laundered. Don’t expect miracles, but don’t assume recovery is impossible either.
Make formal reports to the:
If you’ve lost large sums, consider consulting with lawyers who specialize in cryptocurrency fraud or employing blockchain forensics firms that can trace funds across chains.
After a crypto scam, many victims are approached by fake recovery specialists who claim they can get your money back for an upfront fee in, you guessed it, cryptocurrency. These are almost always the same criminals or their associates running a second scam. Legitimate legal professionals work on contingency or retainer, and will not ask victims to send cryptocurrency for recovery services.
Comprehensive cybersecurity solutions may not be a guaranteed shield against all fraud, but they serve as a critical layer that catches threats you might not spot in that moment. Solutions such as McAfee+ help block known phishing sites and warn you before you enter credentials or connect wallets to fraudulent platforms. They also help detect malware and keyloggers that capture your password and seed phrase keystrokes, take screenshots when you open wallet applications, or even replace destination addresses in your clipboard when you copy-paste. Antivirus and anti-malware tools continuously monitor for threats and help remove them before they can compromise your security.
A secure virtual private network (VPN) can protect your connection on public Wi-Fi networks or compromised routers, preventing man-in-the-middle attacks that might intercept your login credentials or transaction data.
Since many crypto scams begin with or lead to broader identity theft, identity monitoring services can alert you if your personal information, passwords, or financial details appear in data breaches or on dark web marketplaces. This early warning allows you to change compromised credentials before they’re exploited.
The rising number of crypto-related fraud incidents and losses represents a grim milestone. As long as these scams promise high returns and operate with minimal oversight, criminal organizations will continue developing new tactics to steal from investors.
Going forward, your effective defense strategy will combine healthy skepticism, technical hygiene, continuous education, and practical tools. Approach any crypto investment opportunity with a questioning eye until you’ve independently verified that it is legitimate.
Maintain strong security practices, including using hardware wallets for significant holdings, storing seed phrases offline, enabling two-factor authentication everywhere, and carefully verifying transactions before approving.
Most importantly, build a network of trusted advisors, such as family members, friends, or financial professionals, who can offer guidance when you’re evaluating opportunities. Share what you’ve learned from this article and other McAfee guides with people in your life who might be exploring crypto investments, especially those who may be more vulnerable to relationship-based scams.
The post How to Spot a Crypto Scam: The Top Red Flags to Watch For appeared first on McAfee Blog.
A data breach doesn’t have to hit the company you shopped with directly to put your information at risk.
That’s the lesson from this week’s Pokémon Center breach. Customers in the United Kingdom and Germany are being notified that personal and order information was exposed after attackers compromised CEVA Logistics, the third-party company used to fulfill and ship Pokémon Center orders.
The good news: Pokémon Center says CEVA did not have access to customers’ payment-card information.
The bigger concern is what criminals could potentially do with the information that was exposed, particularly when it can make a phishing message look unusually convincing.
According to breach notifications reviewed by BleepingComputer, attackers may have obtained Pokémon Center customers’ full names, mailing addresses, phone numbers, email addresses, and information about the products they ordered. The affected customers were in the UK and Germany.
The intrusion occurred at CEVA Logistics rather than Pokémon Center itself. Reporting indicates attackers accessed CEVA systems between late July and August 1, disrupting operations at eight European warehouses and affecting multiple retailers. Valve previously notified European Steam hardware customers that their information had also been exposed through the CEVA incident.
A name and email address may not seem as sensitive as a credit-card number. But when criminals also know your address, phone number, and what you recently bought, they have something valuable: context.
Context helps scammers make phishing messages believable.
Phishing is when a criminal pretends to be a trusted company or person to persuade you to click a malicious link, hand over a password, share personal information, or send money.
After a breach like this, criminals could potentially impersonate Pokémon Center, a delivery company, or another retailer and reference details that make their message feel legitimate.
They might claim an order needs to be rescheduled, a delivery fee must be paid, or a refund is waiting. Knowing that you really placed an order can make the bait much harder to spot.
Importantly, there is currently no evidence that the stolen Pokémon Center information is being used in such a campaign. But personalized phishing is a common reason breached contact and transaction information deserves attention.
Pokémon Center says the breach occurred at its logistics provider, CEVA, not its own shopping platform.
Names, addresses, phone numbers, email addresses, and order details may have been exposed.
Pokémon Center says payment-card information was not available to CEVA.
Real order details could make future phishing or delivery scams appear more credible.
Customers should independently verify unexpected messages about refunds, cancellations, or deliveries.
Getting a breach notification doesn’t necessarily mean someone has already misused your information. It does mean you should take a few steps to make that information harder to use against you.
1) Find out exactly what was exposed. Read the company’s breach notice carefully. An exposed email address calls for different precautions than a stolen password, Social Security number, financial information, or medical record.
2) Secure the accounts that could be at risk. Change any exposed or reused passwords, use a unique password for every account, and turn on multi-factor authentication where it’s available. If sensitive financial or identity information was stolen, consider a credit freeze or fraud alert as well.
3) Be extra skeptical of messages that know something about you. Breached information can help scammers create convincing emails, texts, and calls. A message that knows your name, address, recent purchase, or other real details isn’t necessarily legitimate. Go directly to the company’s website or app to verify unexpected requests rather than clicking a link or calling a number in the message.
Before a breach
Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.
Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.
During a breach
Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.
Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.
After a breach
Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information.
FBI warns about callers impersonating federal agents. The FBI’s Boston Division is warning about scammers who spoof its real phone number, pretend victims are connected to crimes, and then try to move conversations onto encrypted messaging apps. The key reminder: caller ID can be faked, and the FBI says it will not call private citizens to demand payment, threaten arrest, or request sensitive information.
CareCloud breach grows to more than 3.75 million patients. Healthcare technology company CareCloud has confirmed with federal regulators that hackers stole personal and medical information belonging to more than 3.75 million people, including Social Security numbers, health information, government-issued ID numbers, and some financial data. Because medical and identity information cannot simply be replaced like a password, affected people should take breach notifications particularly seriously.
Hacker claims millions of corporate directory records were stolen. A cybercriminal known as “TheHatman” is offering databases allegedly taken from the Microsoft Azure and Entra environments of several major companies, although some named organizations dispute that their current systems were breached and say portions of the information appear old. Even older employee information can still be useful for impersonation and targeted phishing, so the claims are worth watching without treating every advertised dataset as independently confirmed.
✓ Treat unexpected delivery messages with caution. Open the retailer or carrier’s official app or website instead of following a link in a text or email.
✓ Don’t trust caller ID alone. Scammers can spoof a legitimate organization’s real phone number.
✓ Use unique passwords and multi-factor authentication. Stolen personal information becomes more dangerous when criminals can also get into your accounts.
✓ Pay attention to breach notices. Knowing exactly what information was exposed helps you recognize the scams criminals may try next.
And we’ll be back next week with more cybersecurity news and scam alerts.
The post Pokémon Center Breach Shows Why Your Delivery Data Matters: This Week in Scams appeared first on McAfee Blog.