Common Misconceptions: An Introduction to Online Scams

Course | Introductory | Module | 2

“Once we realize that imperfect understanding is the human condition, there is no shame in being wrong, only in failing to correct our mistakes.”

~ George Soros

Introduction: Common Misconceptions

When we think about online scams, we might think about out-of-the-blue emails and texts filled with obvious spelling errors and far-fetched backstories. We might think about the individuals who have gotten caught up in these kinds of scams, and how we would never have fallen for the same tricks. We might even think about a hooded stranger seated in a dark room, writing complicated lines of code on a laptop.

While these are all examples of the ways in which many of us have come to view online scams, they also have another, far more important, similarity: they are all common misconceptions. From the perpetrators behind online scams and the methods they use to trick us to the kinds of individuals they target, we all have certain ideas about online scams that simply do not reflect the reality of this ever-changing industry.

These misconceptions can prevent us from having an active awareness of our online surroundings, making us more likely to fall for the very tricks that we would usually recognise as obvious examples of online scams. So, how can we avoid this?

The answer is simple: we need to address these misconceptions and explore the reality of what online scams look like. By doing this, we can learn to keep an open mind about our online interactions, and ultimately improve our approach to online safety.

Misconception 1: The Perpetrators of Online Scams

We have already hinted that the image of an anonymous hacker does not give us an accurate picture of who the creators of online scams really are. However, it does give us important insight into the two most common misconceptions we tend to have about these perpetrators. The first is that they have extensive IT skills or technical knowledge, and the second is that they operate as individuals. So, why are these misconceptions?

In a digital world where subscription services and artificial intelligence (AI) like ChatGPT are available at our fingertips, it is no surprise that the world of cybercrime has developed its very own versions of these platforms. One of the most notable examples of this can be found in the availability of phishing kits. These kits, which are essentially DIY starter-packs for cybercriminals, provide all the necessary materials and a step-by-step guide on how to conduct online phishing scams for individuals with no experience in this criminal activity.

Another, and more rapidly advancing example, can be found in the likes of FraudGPT. This AI chatbot, which acts as ChatGPT’s criminal counterpart, enables individuals to create convincing scripts for emails and text messages, code malware attacks, and investigate weaknesses in the IT systems of companies – all without the need for any technical skills or scamming experience. As a result, individuals with all levels of IT knowledge can become cybercriminals with the same ease that the rest of the world can stream a show on Netflix or draft an email using ChatGPT.

Importantly, the perpetrators of online scams are not limited to these kinds of amateurs and individuals. Just as the advancement of technology has allowed for legitimate businesses to thrive and expand globally, it has also enabled cybercriminals to create vast digital enterprises. In fact, many online scams are carried out by groups of cybercriminals who work together in company-like structures. These company-like structures often include top positions like Chief Financial Officers (CFOs), various departments and employees – all of which work together to target individuals through online scams.

This means that online scams are no longer the work of lonely hackers in dark rooms. Instead, they are the work of individuals from all over the world, with all levels of technical knowledge, and with the ability to work together with other cybercriminals in large corporations.

Misconception 2: The Role of Technology in Online Scams

Another common misconception we have is that all online scams work by taking advantage of technological weaknesses, like a weak password or a poorly-protected computer system. In reality, however, cybersecurity and software protection services have become more and more robust in recent years. This has made it increasingly difficult for online scammers to exploit these kinds of technological weaknesses.

Instead, online scammers have turned to the next greatest weakness of any security system: the human element. By learning to manipulate our thoughts and feelings, online scammers can bypass even the most secure software system. In fact, the World Economic Forum has found that 95% of all cybersecurity issues are actually caused by human error, rather than any underlying technological weakness. As a result, it is up to us to be mindful of our online activities and to be critical of the communication and resources we view online.

Misconception 3: The Targets of Online Scams

Although the misconceptions above are certainly eye-opening, it is more than likely that we cannot imagine ourselves ever becoming the targets or victims of a serious online scam. We might feel that we are not interesting enough, or that we don’t have enough money or a large enough social media presence to become worthy targets. But this could not be further from the truth.

From phishing emails and text messages to scam phone calls, we have all come across some form of an online scam at some point in our lives. This reflects the fact that online scams are conducted on a massive scale world-wide, with over $1 trillion ($1 000 000 000 000) having been stolen from online scam victims in 2023 alone. The sheer scale of online scams means that we are all potential targets, regardless of how much money we have or how often we use social media. After all, an online scammer wouldn’t know how much money we have saved in our accounts unless they had already gained access to our banking details!

Beyond this, we also need to understand that online scammers often aren’t interested in us as individuals. Instead, they may be looking to use us as stepping stones to steal from larger and more profitable targets, like the companies at which we work. This does not mean that online scammers are only interested in large corporations. In fact, some studies estimate that 43% of all cyberattacks are carried out on small, rather than large, businesses. As a result, it is more important than ever for us to take our online safety seriously, both for ourselves and the communities around us.

Conclusion:

Over the course of this article, we have explored and debunked a number of the most common misconceptions we have about online scams. This included misconceptions about the perpetrators of online scams, the role of technology in the methods they employ, as well as their targets. In the next article, we will continue looking at online safety through the lens of technology by identifying some of the most common types of online scams and how they operate.