The practice of 'scambaiting', where individuals intentionally engage with online fraudsters, is gaining traction across social media platforms. Participants often document their interactions, aiming to waste scammers' time, gather intelligence on their methods, or even prank them. While seemingly a harmless way to fight back against the pervasive threat of online fraud, cybersecurity experts and law enforcement agencies are issuing strong warnings against the practice, citing significant personal and digital risks.
Scambaiters typically respond to unsolicited emails, messages, or calls from suspected fraudsters, feigning interest in their schemes. They might prolong conversations, ask detailed questions, or even send fake documents to keep the scammer occupied. The perceived objective is to prevent the scammer from targeting other, more vulnerable individuals and to highlight the tactics used by these criminal enterprises. Videos and screenshots of these interactions are frequently shared online, garnering significant views and discussions.
However, the allure of 'fighting back' against fraudsters masks a serious array of dangers. Engaging with scammers directly can expose individuals to sophisticated phishing attempts, malware, and viruses. Criminals often use these interactions to gather personal information, even if seemingly innocuous, which can then be used for identity theft or sold on the dark web. There is also a risk of inadvertently downloading malicious software that can compromise personal devices and financial data.
Furthermore, by engaging with scammers, individuals are effectively confirming that their email address or phone number is active. This can lead to an increase in unsolicited contact, making them a more prominent target for future, potentially more elaborate, fraud attempts. In some extreme cases, scambaiters have reported receiving threats or being subjected to doxing, where their personal information is publicly exposed by frustrated criminals.
Law enforcement agencies, including the National Cyber Security Centre (NCSC) and Action Fraud, consistently advise against any direct engagement with suspected scammers. Their official guidance is to report suspicious communications immediately and then block the sender. This approach ensures that vital intelligence is collected by the appropriate authorities without putting individuals at unnecessary risk. The NCSC’s 'Suspicious Email Reporting Service' (SERS) allows individuals to forward suspicious emails, which are then analysed and acted upon.
Instead of attempting to tackle fraudsters directly, the recommended course of action for UK consumers is to report all suspected scam attempts to Action Fraud, the UK’s national reporting centre for fraud and cyber crime. They can be contacted online or by phone. This ensures that incidents are recorded, intelligence is gathered, and appropriate action can be taken by law enforcement without individuals needing to put themselves in harm's way.
Source: National Cyber Security Centre (NCSC), Action Fraud