Module 05Safety

Social Media & General Scam Awareness

Recognise everyday scams, with practical WhatsApp and Telegram lessons on account takeover, fake support, group and crypto traps, privacy, recovery and a messaging safety checklist.

Interactive scam radar

Read the message. Make the call.

These are realistic simulations based on recurring reported patterns. No message is copied from a private victim conversation.

0good calls
WhatsApp messageNew number
1 / 13
Now

Hi Mom, my phone broke. Please EFT R3,800 to my friend's account before the landlord locks me out. Don't call, I'm in a meeting.

Platform names and logos identify the type of simulated message for educational purposes. Stable Circle Academy is not affiliated with or endorsed by these platforms, and third-party trademarks remain the property of their owners.

Manipulation decoder

Learn the pattern behind the story

Select a pressure tactic. The counter-move works even when the scam is completely new.

Scammer's move

Urgency

Act now before you can think or verify.

Your counter-move

Pause for ten minutes and independently contact the real person or organisation.

Confirmed case files

Real reports. Reusable lessons.

Figures are historical reported data from the linked official source. They illustrate patterns, not the probability that any one learner will be targeted.

FTC data$2.7B

Social media was the starting point

The FTC reported $2.7 billion in reported losses from scams originating on social media from 2021 through June 2023. Shopping produced the most reports; financial-opportunity scams produced the largest losses.

Verify: FTC Data Spotlight
FBI IC3 2024$6.57B

Financial fraud dominated reported losses

IC3 recorded about $6.57 billion in related financial-fraud losses in 2024 and about $672 million in confidence and romance-fraud losses. Reports are not the same as all incidents, but they show the scale of harm.

Verify: 2024 IC3 Annual Report
South Africa65.3%

Social engineering, not a bank-platform breach

SABRIC reported that digital banking fraud represented 65.3% of reported incidents in its 2024 crime statistics and stressed that social engineering exploited human behaviour rather than technical compromise of banking platforms.

Verify: SABRIC 2024 statistics
SAPS warningSTOP

Threatening traffic-fine messages have been used to extort payment

The South African Police Service documented SMS messages that claimed a case or warrant existed for a traffic fine and then directed victims to make fraudulent payments. Verify any claimed fine through an independently found official channel.

Verify: South African Government / SAPS warning
1
Lesson 1

Scam psychology and manipulation patterns

What it is

If you can recognise the pressure tactics, you can spot new scams even when the story changes.

Using the internet is like learning to drive: useful everyday freedom comes with hazards you can learn to recognise and navigate. Keep enjoying your devices. These lessons build confidence through practical habits, not fear; no habit removes every risk.

Open guided lesson8 practical steps
How it works

A scammer creates an emotional state, narrows the victim's options, discourages outside advice and then directs payment or disclosure. The story changes; the pressure sequence repeats.

Most scams lean on a small set of forces: urgency, fear, greed, trust-building, isolation, authority, scarcity, secrecy, social proof, pressure and payment. The details may change, but the emotional structure often does not.

A scammer may pretend to be helpful at first, then create urgency, then push for secrecy and fast payment. That sequence is often more important than the exact topic.

A practical rule is simple: slow down when a message tries to rush you.

Realistic example

A supposed trading mentor shows fabricated account gains, says a limited opportunity closes tonight, and insists the learner keep the method secret from family.

Red flags
  • Urgency
  • Secrecy
  • Guaranteed outcomes
  • Isolation from trusted people
  • Unusual payment methods
  • Pressure after reasonable questions
What not to do
  • Do not decide while emotionally activated
  • Do not let the sender control how you verify
  • Do not pay to end pressure
What to do instead
  • Pause
  • Name the emotion being triggered
  • Verify independently
  • Discuss the request with a trusted person
  • Check the payment destination
If already compromised or you interacted
  • Stop further contact and payment
  • Preserve evidence
  • Secure any information already shared
  • Report through official channels
Why this matters

A reusable scam-spotting framework helps learners recognise a new fraud even when they have never seen that exact script before.

Try it now

When something feels urgent, ask: what am I being pressured to do, what is the payment method, and who benefits if I rush?

Quick knowledge check

Which clue is most reusable across completely different scam stories?

RememberScams often reuse the same emotions.Pressure is a warning sign.Slow down before acting.
2
Lesson 2

Romance, impersonation and family-emergency scams

What it is

Romance scams and impersonation scams build trust before asking for money, secrets or shame-based compliance.

Open guided lesson8 practical steps
How it works

The scammer builds trust or copies a trusted identity, introduces a crisis, and asks for secrecy, money, documents or participation in a supposed financial opportunity. Grooming may last weeks or months.

Romance scams often begin with friendly contact, then intensify over time until the scammer invents travel problems, emergencies, customs fees or supposed financial opportunities. The relationship is the bait.

WhatsApp 'new number' scams and family-emergency scams rely on urgency and trust. The message may claim to be a child, sibling or friend who lost a phone and needs immediate help.

Once emotion is high, the scammer pushes the victim to keep the conversation secret and act quickly without independent verification.

Realistic example

A WhatsApp message says, 'Hi Mom, this is my new number. My banking app is locked and rent is due in 20 minutes.' The profile photo is copied from social media.

Red flags
  • A new number
  • Refusal to voice or video verify
  • Repeated emergencies
  • Requests for secrecy
  • Money to someone never met in person
What not to do
  • Do not rely on a profile photo
  • Do not send a small test payment
  • Do not share private images to prove trust
What to do instead
  • Call a number already saved
  • Use a family verification phrase
  • Ask a question only the real person can answer
  • Discuss long-distance money requests with someone trusted
If already compromised or you interacted
  • Stop payment and contact the provider
  • Preserve chats and account details
  • Secure intimate images and report threats
  • Warn the impersonated person through a trusted channel
Why this matters

Long-term grooming can make a false request feel emotionally reasonable even when it is objectively suspicious.

Try it now

If someone asks for urgent help from a new number or unfamiliar account, call them back using a number you already trust.

Security warning

Do not rely on the profile picture or the emotional history alone. Verify identity through a separate trusted channel.

Quick knowledge check

A relative on a new number asks for urgent money. What is the best first action?

RememberTrust-building can take weeks or months.Verify identities independently.Urgency plus secrecy is a major red flag.
3
Lesson 3

Marketplace, payment and courier scams

What it is

Marketplace scams often look like ordinary buying and selling until the payment or delivery step goes wrong.

Open guided lesson8 practical steps
How it works

Fake buyers and sellers move the conversation off-platform, provide forged proof of payment, send copied courier pages, request overpayment refunds or collect goods before real funds clear.

Facebook Marketplace and similar platforms are common targets for fake buyers, fake sellers, overpayment tricks and fraudulent proof of payment. A seller may receive a doctored EFT slip or a buyer may be sent a fake courier link.

The scam usually tries to move the conversation off-platform into private messaging where evidence is easier to manipulate. Fake customer support or courier staff may then request fees, remote access or personal details.

Always verify payment through your own banking app or trusted payment record rather than a screenshot sent by the other person.

Realistic example

A Facebook Marketplace buyer sends an EFT screenshot and a courier arrives immediately. The seller's own banking app shows no cleared funds.

Red flags
  • A courier waiting before funds clear
  • Overpayment and refund requests
  • Links claiming a fee unlocks payment
  • Pressure to leave platform messaging
What not to do
  • Do not release goods based on a screenshot
  • Do not refund an overpayment before verifying it
  • Do not log into banking through a buyer's link
What to do instead
  • Verify cleared funds in your own account
  • Use platform protections
  • Meet in a safe public place where practical
  • Use courier sites reached independently
If already compromised or you interacted
  • Contact the bank or payment provider
  • Report the profile and listing
  • Preserve the payment slip, chat and delivery details
  • Change credentials entered into a linked page
Why this matters

A convincing screenshot can be fabricated in minutes. Independent verification is what stops the trick.

Try it now

Before releasing goods, confirm funds in your account and compare the sender details, reference and timing against your own records.

Quick knowledge check

What proves a Marketplace buyer has paid?

RememberScreenshots are not proof.Courier links and payment slips can be forged.Verify money independently before handing over goods.
4
Lesson 4

Jobs, shopping and tech-support scams

What it is

Fake employment, fake stores and fake support are all variants of the same deception pattern.

Open guided lesson8 practical steps
How it works

A fake opportunity or problem creates a reason to pay upfront, disclose identity information, buy equipment, complete endless paid tasks or install remote-control software.

Employment scams may promise easy remote work, ask for a fee to unlock earnings or turn into a task-based scheme that requires more payment to withdraw money. The 'job' is often the lure.

Online shopping scams use fake stores, copied product photos, counterfeit domains and non-delivery. Tech-support scams use phone calls, pop-ups or screen-sharing requests to seize a device.

A common warning sign is any request to install remote-access software or pay a fee before you can receive a promised benefit.

Realistic example

A Telegram recruiter offers simple product-rating work. Early tasks show small profits, then the platform demands a large deposit to unlock earnings.

Red flags
  • Pay to receive wages
  • Interview only by chat
  • Unrealistic pay for simple tasks
  • Remote-access request
  • Store domain created recently or misspelled
What not to do
  • Do not pay recruitment or earnings-release fees
  • Do not install remote-control tools for unsolicited support
  • Do not submit identity documents before verifying the employer
What to do instead
  • Contact the employer through its published website
  • Research the store independently
  • Use protected payment methods
  • Close pop-ups and contact official support yourself
If already compromised or you interacted
  • Stop deposits
  • Remove remote-access software
  • Secure accounts used on the device
  • Monitor identity documents and payment cards
  • Report the listing
Why this matters

These scams target people who are trying to earn, buy or fix something quickly, which makes them especially effective.

Security warning

Never let a stranger control your device or ask you to pay money to unlock wages, refunds or support.

Quick knowledge check

A task platform says one more deposit will unlock all earnings. What should you do?

RememberIf you must pay to receive income, be cautious.Only trust official stores and support pages.Remote access is a high-risk request.
5
Lesson 5

Government, financial-opportunity and charity scams

What it is

Authority and legitimacy are powerful tools for fraud when they are faked.

Open guided lesson8 practical steps
How it works

Fraudsters borrow authority, regulation, celebrity or charitable urgency. They threaten consequences or promise exceptional returns, then route payment to accounts they control.

Government, police, tax, courier and bank impersonation scams use authority to create fear. The scammer may threaten arrest, account closure or a lost package unless payment or verification happens immediately.

Financial-opportunity scams can involve forex, shares, commodities, property, AI bots, crypto, fake trading platforms and Ponzi or pyramid structures. The promise is usually an outsized outcome with little risk.

Charity and disaster scams exploit sympathy after a crisis. They can be especially convincing because the emotional goal is to help, not to profit.

Realistic example

A WhatsApp group impersonates a financial company and promises R6,000 back from R2,500 in a short period, echoing a 2025 FSCA public warning.

Red flags
  • Guaranteed or unrealistic returns
  • Threats of arrest by instant message
  • Payment to personal accounts
  • Pressure not to verify a licence
  • Donation pages reached only through forwarded links
What not to do
  • Do not trust a logo or copied licence number
  • Do not pay a fine through gift cards or crypto
  • Do not treat celebrity media as proof
What to do instead
  • Check the regulator's own register
  • Call the authority through an official number
  • Verify charities independently
  • Understand that every genuine financial opportunity still carries risk
If already compromised or you interacted
  • Contact the financial provider immediately
  • Report the impersonation to the real organisation and regulator
  • Preserve account numbers, wallet addresses and promotional material
Why this matters

The more convincing the authority or opportunity, the more important it is to verify independently.

Try it now

If someone claims to be a bank, tax office or police officer, end the call and contact the organisation using a number from its official website.

Quick knowledge check

Which promise requires the strongest caution?

RememberAuthority can be faked.High return with low risk is a classic warning sign.Charity requests also need verification.
6
Lesson 6

Fake traffic fine SMS, WhatsApp and email scams

What it is

A threatening traffic-fine message can be a payment-phishing trap, even when it uses official-looking names, logos or legal language.

Open guided lesson8 practical steps
How it works

Criminals impersonate a traffic authority, claim that a fine is overdue, threaten penalties or legal action and push the recipient to a fake payment page. The page may steal card details, banking credentials, a PIN, an OTP or other login information.

Criminals may send an SMS, WhatsApp message or email claiming that you have an unpaid traffic fine. The message may threaten additional penalties or legal action, claim the fine must be paid immediately, or include a link to a copied payment website.

Do not click a suspicious payment link and never provide card details, a banking password, PIN, OTP or login credentials. A professional-looking page does not prove that the payment destination is legitimate.

Verify the fine independently through the official website or contact centre of the relevant traffic authority. Do not use the contact details or payment link contained in the suspicious message.

Realistic example

An SMS says an unpaid traffic fine will trigger legal action today. A short link opens an official-looking payment page that asks for card details and an OTP.

Red flags
  • Immediate-payment deadline
  • Threat of arrest or extra penalties
  • Shortened or unfamiliar payment link
  • Request for a banking PIN, password or OTP
  • Contact details supplied only in the message
What not to do
  • Do not click the payment link
  • Do not reply with personal or banking details
  • Do not disclose a card PIN, banking password or OTP
  • Do not rely on the sender's contact details
What to do instead
  • Close the message
  • Find the relevant traffic authority through an official government source
  • Verify the fine independently
  • Use only an official payment channel reached independently
If already compromised or you interacted
  • Contact your bank immediately if card or login details were entered
  • Block or replace an exposed card
  • Change exposed credentials from a trusted device
  • Preserve the message and report the phishing attempt
Why this matters

Threats and urgency can push a person to pay before checking whether the fine, authority or payment destination is real.

Try it now

Close the message. Find the relevant authority through an independently verified government website, then check the fine using that official channel.

Security warning

Urgency + threats + a payment link = stop and verify first. Legitimate organisations should never require your banking PIN, password or OTP to pay a traffic fine.

Quick knowledge check

A message threatens legal action unless a traffic fine is paid through its link today. What should you do?

RememberDo not use a payment link in a threatening message.Never disclose a PIN, password or OTP.Verify the fine and payment channel independently.
7
Lesson 7

AI, deepfake, sextortion and phishing scams

What it is

Modern scams can use cloned voices, fake videos and malicious links to create pressure quickly.

Open guided lesson8 practical steps
How it works

AI can imitate a voice, face or writing style in real time, while phishing links steal credentials and sextortion uses fear or shame. Deepfake community streams, fake giveaways and poisoned search ads can all look professional without being authentic.

AI-generated images, real-time voice clones and deepfake video calls can make a message seem far more believable than a simple text scam. These tools are used to impersonate family members, managers, influencers and customer support agents, including fake community livestreams and giveaway announcements.

Sextortion and blackmail often combine embarrassment with urgency. The scammer may claim to have compromising images or to know private information and then demand payment or more content.

Phishing, smishing and malicious links remain common entry points because they can steal credentials, reset access or install malware with a single click. Search-engine poisoning adds malicious Google or Bing ads and look-alike results that imitate real wallet tools, bridges and explorers. Type a known address or use a verified bookmark instead of trusting the first result.

Realistic example

A video call that looks like a community leader announces an urgent giveaway and tells viewers to open the first sponsored search result. The result imitates a real explorer but requests a wallet signature.

Red flags
  • A new contact method
  • Refusal of an independent callback
  • Urgent payment or giveaway claims
  • Threats involving private material
  • Sponsored or look-alike links
What not to do
  • Do not pay blackmailers
  • Do not send more intimate material
  • Do not trust voice or video alone
  • Do not enter credentials through a rushed link
What to do instead
  • Use a known number or internal process
  • Agree on a family or team verification phrase
  • Use independently verified bookmarks for wallet tools and explorers
  • Report sextortion without shame
If already compromised or you interacted
  • Preserve evidence
  • Secure affected accounts
  • Tell a trusted person
  • Report threats and fraudulent payment instructions
  • Do not continue bargaining
Why this matters

A realistic voice or video does not prove authenticity. The verification habit matters more than the media quality.

Try it now

When a message is emotionally intense, verify through a second channel you already trust before replying or paying.

Security warning

Do not pay blackmailers, do not click rushed links and do not share private material to prove you are real.

Quick knowledge check

A familiar voice asks for an urgent secret transfer. What proves identity?

RememberAI can copy appearance and voice in real time.Blackmail depends on shame and speed.Search rank and sponsored placement do not prove legitimacy.Verify links and identities before acting.
8
Lesson 8

What to do after you engage with a scam

What it is

If you clicked, replied, paid or shared information, the response should focus on limiting further damage.

Open guided lesson8 practical steps
How it works

Scammers often follow the first loss with account takeover, identity misuse or a fake recovery service. Fast containment and evidence preservation reduce secondary harm.

Stop the conversation, preserve evidence and report the account or number. Change passwords if login details were shared, and contact financial providers quickly if money was sent.

If identity documents, selfies or banking details were shared, watch for account misuse and place fraud alerts where available. If you installed software or granted remote access, remove it and review the device carefully.

The sooner you act, the better your chance of reducing additional harm.

Realistic example

After losing money to a fake trading platform, a supposed law firm offers recovery for an upfront fee. It is a second scam targeting known victims.

Red flags
  • Guaranteed recovery
  • Upfront recovery fees
  • Pressure to delete chats
  • Requests for remote access or more identity documents
What not to do
  • Do not chase losses with another payment
  • Do not delete evidence
  • Do not blame or isolate the victim
What to do instead
  • Stop contact
  • Contact payment providers
  • Change exposed credentials
  • Preserve evidence
  • Report the scam
  • Seek calm support from someone trusted
If already compromised or you interacted
  • Monitor accounts and identity records
  • Revoke remote access and sessions
  • Replace exposed secrets
  • Record dates, amounts, destinations and report numbers
Why this matters

The first mistake does not have to become the final one. Rapid follow-up can still protect other accounts and money.

Try it now

Save screenshots, note dates and times, and move the conversation to a safe record before blocking the scammer.

Quick knowledge check

A recovery agent guarantees your money back for an upfront fee. What is the safest response?

RememberStop contact and keep evidence.Protect the affected accounts immediately.Fast action reduces secondary harm.
9
Lesson 9

WhatsApp takeover, codes and linked-device traps

What it is

An attacker can misuse your WhatsApp identity through registration-code theft or a linked device.

Open guided lesson8 practical steps
How it works

An attacker starts registration with your number, then invents a reason to ask for the six-digit verification code. Another trick asks you to scan a QR login code or approve device linking disguised as a vote, giveaway or support check.

The registration code and the two-step PIN/password are separate secrets. Neither belongs in a chat. QR login codes and linking approvals can grant access while your phone still works. Receiving an unexpected code alone does not prove a takeover.

Encryption cannot make an attacker-controlled account or linked device trustworthy. A real friend's compromised account may send the request.

If locked out, re-register your number using the official WhatsApp app on a trusted phone. Follow its verification and recovery instructions. An unknown two-step PIN/password may require recovery or a waiting period; the official PIN guide describes seven days. Nobody offering paid recovery can legitimately bypass the app's waiting instructions.

Realistic example

A school-group friend says, 'I sent my code to your number by mistake.' Later a vote-for-my-child page asks you to link a device.

Red flags
  • Unexpected verification code
  • A request to forward a code
  • Voting or prize pages asking for device linking
What not to do
  • Never share verification codes, PINs, passwords or recovery codes, even with friends
  • Never send QR login codes, share passkeys or approve device linking for someone else
What to do instead
  • Open WhatsApp yourself to inspect Linked Devices
  • Verify the friend outside the chat using a known channel
  • Enable two-step verification and a protected recovery email
If already compromised or you interacted
  • Re-register your number in the official app if locked out; follow the displayed recovery flow
  • Review Linked Devices and log out unknown devices; if unsure, log out all linked devices
  • Warn contacts through another trusted channel that messages may be fraudulent
  • Secure email, carrier and voicemail; change exposed or reused passwords and the two-step secret
  • Preserve messages, numbers and timestamps; report/block scam accounts
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Find Linked Devices without linking anything. Check you recognise every entry.

Quick knowledge check

A friend needs your WhatsApp registration code to fix their account. What should you do?

RememberOpen WhatsApp yourself to inspect Linked DevicesVerify the friend outside the chat using a known channelEnable two-step verification and a protected recovery email
10
Lesson 10

WhatsApp impersonation, business and group scams

What it is

A scam can imitate family, a boss, a business or support, including from a real contact's hacked account.

Open guided lesson8 practical steps
How it works

The sender borrows trust and adds urgency to redirect money or obtain a login. New-number stories, family emergencies, fake boss requests and changed supplier bank details all try to skip normal checks.

Saved chat history is not proof of who is typing now. Call a previously known number or use an established separate channel. Do not use the new number or callback link supplied in the request. Follow normal family or business verification; a familiar-sounding voice alone is not enough for an unusual payment.

A business-account label, logo or verification badge does not prove a payment request is safe. Fake Meta/WhatsApp support may threaten suspension or offer a badge to steal credentials. Open support from the app yourself.

Unsolicited groups may stage fake testimonials, forwarded claims and giveaways. Verify admins with an independently known organisation contact; leave suspicious groups. Shortened links hide destinations. A QR code can hide a payment destination, phishing page or device-linking request; inspect its purpose instead of trusting its appearance.

Module 4 explains WhatsApp profile-photo, About, Status and Groups privacy. These settings reduce exposure but do not prevent a hacked contact from messaging you.

Realistic example

Your boss's photo appears on a new number asking for R2,500 urgently. A group admin posts testimonials and a QR payment code.

Red flags
  • New numbers or changed banking details
  • Urgency and secrecy
  • Shortened links and staged testimonials
  • Fees to claim a prize or keep a verification badge
What not to do
  • Do not pay based on a photo, badge or forwarded payment proof
  • Do not scan login QR codes or enter bank credentials for giveaways
  • Do not assume a saved contact cannot be hacked
What to do instead
  • Verify through known family/business contact details
  • Check payment purpose and recipient in your own banking app
  • Report/block suspicious senders and leave scam groups
If already compromised or you interacted
  • Contact your bank/payment provider quickly if you paid; ask about stopping or recalling funds without assuming recovery
  • Preserve chats, recipient details and transaction references
  • Warn the impersonated person and genuine admins through trusted channels
  • If you shared codes or linked a device, follow the WhatsApp takeover lesson
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Choose a known callback channel for urgent family and work money requests.

Quick knowledge check

Your friend's existing WhatsApp chat asks for urgent money. What is safest?

RememberVerify through known family/business contact detailsCheck payment purpose and recipient in your own banking appReport/block suspicious senders and leave scam groups
11
Lesson 11

Telegram login-code theft and account recovery

What it is

A stolen login code or session can let someone impersonate you and access cloud chats.

Open guided lesson8 practical steps
How it works

Scammers ask for an SMS or in-app Telegram login code, calling it a group-entry or anti-spam check. Telegram account codes can arrive in the service chat named Telegram. Never forward them to a person, bot or supposed staff member.

Enable Telegram Two-Step Verification with a strong password and confirmed recovery email. Review Settings > Devices / Active Sessions. Changing a password is not a substitute for terminating attacker sessions.

If you retain a trusted session, use it to terminate unknown sessions and change the Two-Step Verification password. Check recovery email. Avoid logging out your last trusted session during recovery.

If locked out, regain control of your number through your carrier and follow the official app's login/password-recovery flow. A fresh login may temporarily be unable to end older sessions: use an existing trusted session or follow the app's waiting instructions. Without your number or any session, recovery may not be possible through the normal route. Read warnings before an account reset/deletion, which can lose data.

Realistic example

After Kabelo posts in a group, 'Telegram Safety' DMs him asking for the code in his Telegram service chat to prevent a ban.

Red flags
  • A bot asks for a login code
  • An unknown active session
  • Threats of immediate deletion unless you verify in a DM
What not to do
  • Never share SMS/Telegram login codes or recovery secrets
  • Do not scan a login QR supplied by support
  • Do not pay a recovery agent or delete an account in panic
What to do instead
  • Enable Two-Step Verification and secure recovery email
  • Inspect Devices / Active Sessions
  • Reach help through official Telegram settings or its FAQ
If already compromised or you interacted
  • Terminate unknown sessions and change the two-step password from a trusted session
  • Secure email/carrier access and change exposed or reused passwords
  • Warn contacts and genuine group admins through a trusted channel
  • Preserve profile links, usernames, messages and timestamps; report/block impersonators
  • If you installed a suspicious app, secure accounts from another trusted device and have the affected device checked
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Locate Active Sessions and recovery settings without sharing private screenshots.

Quick knowledge check

A verification bot requests a code from the Telegram service chat. What does sharing it risk?

RememberEnable Two-Step Verification and secure recovery emailInspect Devices / Active SessionsReach help through official Telegram settings or its FAQ
12
Lesson 12

Telegram fake admins, bots and crypto traps

What it is

Fake helpers exploit group conversations to offer private support, airdrops or investment access.

Open guided lesson8 practical steps
How it works

After you post, an attacker DMs you with an admin's cloned photo and similar name. Compare the exact @username against an independently verified source. Basic Telegram usernames use Latin letters, digits and underscores: l/I lookalikes or added characters can deceive. Display names and linked domains can use Unicode character substitutions. A photo, display name or admin badge alone is not identity proof.

Legitimate admins should not ask for seed phrases, private keys, OTPs, wallet-connect signatures, remote access or upfront recovery fees to help you. Even a genuine admin account can be compromised. Reach the project's known website independently and refuse unknown wallet requests.

Malicious bots, fake airdrops and verification pages may gather details or ask for a wallet connection followed by a signature/approval. A signature can authorise asset movement even if described as verification or requiring no gas.

Fake support may ask for screen sharing, AnyDesk, TeamViewer or an APK/app. APKs are Android installation packages; malicious files can steal sessions or control a phone. Do not install files sent through Telegram. Use official stores, verify publishers, limit automatic downloads and avoid unexpected executable files.

Fake investment/earnings groups manufacture testimonials and withdrawal screenshots. Pump-and-dump organisers promote buying to raise a token's price, then sell into the demand. A dashboard balance does not prove funds can be withdrawn. Another scammer may offer recovery for an upfront fee.

Realistic example

You ask a wallet question. An admin lookalike DMs an airdrop bot, then says AnyDesk and a wallet signature will unlock your withdrawal.

Red flags
  • Unsolicited support after a group post
  • A near-matching username or cloned photo
  • Wallet verification, remote access or unknown APK requests
  • Guaranteed earnings and withdrawal/recovery fees
What not to do
  • Never share seed phrases, private keys or OTPs
  • Never sign unknown wallet requests or pay upfront recovery fees
  • Never install remote-access software or unknown APKs at someone's request
What to do instead
  • Verify admins and websites independently
  • Decline unsolicited wallet connections and signatures
  • Use official stores and verify publishers
If already compromised or you interacted
  • Stop remote access/screen sharing and isolate a possibly infected device; use a trusted device for recovery
  • Terminate Telegram sessions and secure email and two-step credentials
  • If you signed a wallet request, review/revoke affected permissions through verified tools; disconnecting a site does not revoke on-chain approval
  • If keys or seed words were exposed, stop using that wallet and follow trusted Academy recovery guidance
  • Preserve hashes and chats, warn genuine admins and report/block impersonators
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Compare fictional @circle_help with @circIe_help. Notice the capital I replacing lowercase l; do not contact either.

Quick knowledge check

A Telegram admin says a gas-free signature verifies you for support. What should you do?

RememberVerify admins and websites independentlyDecline unsolicited wallet connections and signaturesUse official stores and verify publishers
13
Lesson 13

Telegram privacy, normal chats and Secret Chats

What it is

Privacy settings reduce exposure; encryption does not prove the other person is honest.

Open guided lesson8 practical steps
How it works

Normal Telegram private chats, groups and channels are cloud chats, not end-to-end encrypted Secret Chats. Secret Chats are device-specific one-to-one conversations with end-to-end encryption. They do not protect against a dishonest recipient, a compromised device or someone photographing the screen.

In Settings > Privacy and Security, review phone-number visibility and who can find you by number, profile photos, group invitations and calls. Choose the narrowest useful audience and review exceptions. People who already know your number may still recognise you.

Forwarded Messages privacy can limit a forwarded message linking back to your profile; it does not prevent copying or screenshots. Public group/channel posts can be seen widely. Private invite-only groups still have members who can copy posts. If you administer a group/channel, review its visibility, admins and invite links.

Realistic example

A stranger moves support to a Secret Chat and claims you can safely send your private key there.

Red flags
  • Claims that encryption makes sharing keys safe
  • Unexpected invitations and calls
  • Requests for sensitive identity records in public channels
What not to do
  • Never send wallet keys, even in a Secret Chat
  • Do not assume a private group prevents copying
  • Do not use encryption as identity proof
What to do instead
  • Restrict phone, photo, forwarded-message, group and call privacy
  • Keep sensitive information out of posts
  • Verify people separately from chat security
If already compromised or you interacted
  • Remove exposed personal details where possible but assume copies may remain
  • Preserve evidence before deleting messages
  • Report/block impersonation and warn contacts
  • If secrets were exposed, follow account or wallet recovery guidance promptly
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Review phone number, group/call invitations, profile photos and Forwarded Messages settings.

Quick knowledge check

A Telegram group says it uses Secret Chats so keys are safe to post. Which is correct?

RememberRestrict phone, photo, forwarded-message, group and call privacyKeep sensitive information out of postsVerify people separately from chat security
14
Lesson 14

Messaging App Safety Checklist

What it is

Use these twelve checks for WhatsApp and Telegram, and repeat the device review every month.

Open guided lesson8 practical steps
How it works

This is a practical routine, not a guarantee against scams. Make changes in the official apps, never through a helper's link. These practice checkboxes reset on reload and are not saved to your Academy profile.

Realistic example

Naledi checks both apps before joining a community and agrees to call family on known numbers before urgent payments.

Red flags
  • Unexpected login/linking prompts
  • Pressure to skip verification
What not to do
  • Do not enter real secrets into this lesson
  • Do not assume two-step verification makes payments safe
What to do instead
  • Work through all twelve checks
  • Set your own monthly session-review reminder
  • Use independent contact for money requests
If already compromised or you interacted
  • Stop interaction and secure accounts from a trusted device
  • Follow the app-specific recovery lessons
  • Preserve evidence and report/block quickly; contact the payment provider if money was sent
Why this matters

Combining account controls with independent verification helps protect your conversations, contacts and money.

Try it now

Tick each item after checking it in the relevant app. Ticks reset on reload.

Messaging App Safety Checklist

Practice ticks reset on reload; they do not change saved lesson progress.

Quick knowledge check

Both apps have two-step verification. An urgent money request arrives. What next?

RememberWork through all twelve checksSet your own monthly session-review reminderUse independent contact for money requests
Primary-source references

Verify the learning material

The Academy uses authoritative primary sources wherever practical and converts them into beginner-friendly explanations.