Fraud is endemic to marketplaces. The scams du jour are organized around the specific characteristics of the banks and the platform. These also manipulate the psychological tendencies that tend to play in many scams. The specific mechanics and goals of different scams will vary, and so too must the actual defense you apply against them. Like in security, the approach continually fills gaps and closes on regularly shifting goalposts. It’s exhausting but doable.
Why Your Phone Number is the First Thing You Should Protect
Many people readily provide their personal cell phone number. It seems routine. It shouldn’t.
A personal cell number is a shockingly powerful piece of personal information. Enter it into a reverse lookup service and they’ll return your home address, linked social media profiles, and sometimes even the names of immediate family members. Scammers cross-reference all this to build your profile before they’ve even messaged you. They know where you live, which site(s) you’re using, and in many cases, they know enough intimate details of your life to make their social engineering especially convincing.
To avoid this, the solution is a concept people rarely consider: don’t give the other side your number. Using this online SMS tool, they can still call you and send verification codes while this intermediary number handles all the messages from potential fraudsters, meaning your real cell stays off the site, off their computer, and out of any reverse lookup databases they’d have access to.
The Verification Code Scam, Broken Down
This scam has cost people real money and is still going around because it preys upon intelligent, wary folks.
The scam begins: you post an item for sale. A “buyer” responds quickly and engages with your listing. Then they say something like, “I just want to confirm you’re real and not a bot, here’s a six-digit code for you to confirm.” The code is sent via SMS. You confirm the code. The buyer vanishes.
What actually happened: the scammer submits your phone number in the process of creating, say, a Google Voice account, which is a service that requires verifying that you own a given phone number by sending a text message to it. The text message sent is the six-digit code you confirmed for them, verifying that you “own” the phone number. They now have a verified use of your phone number associated with their account their software can now use to appear more legitimate, and your phone number is entangled in their operation.
Never read a verification code to anyone. A legitimate buyer will never send one to you. If a code arrives on your phone that you didn’t request, it’s a direct signal that someone is attempting to use your phone number to verify their ownership of something. Hang up the phone or cease the conversation immediately.
The Illusion of Cleared Funds
The overpayment scam is successful because the vast majority of people have no idea how the banking system actually operates when it comes to clearing funds, and banks aren’t motivated to enlighten them.
Here’s how it works: a buyer either mails you a counterfeit cashier’s check or initiates a payment for more than your requested price. They have a plausible excuse; “This is a gift for my mother and my assistant made an error in sending the payment, could you please directly wire the overage?” Your bank “deposits” the check and, in 1-3 business days, makes the funds available. You wire the overage. 2-4 weeks later, the check is proven to be counterfeit and your bank reclaims the full amount of the counterfeit check. You are out the real money you wired back to the scammer and the full amount of the bogus deposit.
The key: just because the funds show up as available does not mean the check has cleared. Banks are required to make funds available within a certain period even before verifying the check. That in-between period is the scam. If you’re being asked to wire back overpayment, it’s this hustle, no matter how official the letterhead.
It’s happening using P2P and Zelle/Venmo/Cash apps as well: those act like cash, once it’s gone, it’s gone. Many people have no idea of this.
What Moving Off-Platform Actually Means
Scammers will do everything in their power to urge you to switch from a marketplace’s internal messaging system to WhatsApp, regular SMS, or email. And here’s why.
These marketplace sites often have automated fraud monitoring running on their chat interface. Certain key phrases, behaviors, or links may trigger a security alert or temporary ban of the user’s account. By moving the conversation offsite, all of that is circumvented. There’s no tamper warning, no algorithm looking for possibly fraudulent interactions, and no evidence in the message archives of the site you’re using if things go bad and you decide to file a charge.
Being pushed onto a text conversation you’ve not had the chance to vet is therefore a warning sign. A real customer will be happy to use whatever the app already comes with. Scammers very much won’t be.
The Fake Tracking Number Exploit
If you’re making a purchase from an unfamiliar seller and they provide you with a tracking number, that number doesn’t mean anything by itself.
A typical ploy: the seller sends a letter-sized envelope, either empty or with a piece of paper, to a different address in your postal code. The envelope is scanned as delivered by the carrier. The automated conflict resolution system detects a delivered notice to your zip code and marks the dispute as resolved in the seller’s favor. You’re cheated out of the item and your money, and you can’t do anything because according to the platform’s system it was delivered.
The solution for this is easy. Ensure that the full destination address in the tracking record is verified before the dispute window closes, not just the status. If the address doesn’t match yours exactly, submit that as evidence of foul play immediately and push the dispute resolution forward. Don’t wait for the status to change, the resolution will most likely have been locked by then.
For high-value buys purchased from unfamiliar sellers, consider setting up an escrow. An actual escrow will keep the money until you confirm that you’ve received the as-advertised goods. It’s cumbersome but it also makes it almost impossible for scammers to rip off either party in the transaction.
Locking Down Your Marketplace Accounts
Although SMS two-factor authentication is convenient, it is susceptible to a SIM swapping cyberattack, rendering it ineffective. SIM swapping is a type of account takeover that’s particularly difficult to protect against and very financially damaging. It’s easy for a hacker to convince a mobile provider to transfer your phone number to a SIM card they control, so when a 2FA code is sent via SMS, they receive it. The victim may not know about the SIM card transfer until it’s too late.
To keep your online accounts safe, switch to a 2FA method that doesn’t rely on text messages. Authenticator apps use a secret key that only you and the service know to generate a time-based code. The app is not connected to the internet so it can’t be hacked. Google Authenticator and Duo are free, good options for getting started, and supported by an increasing number of service providers. This form of 2FA is the most effective and convenient to use, as it is not sent via mobile.
Most platforms allow for recovery via SMS by default. During the recovery process, hackers can attempt a SIM swap and resubmit an SMS code to bypass your 2FA protection. Always make sure to change your recovery method to another device or application that is not associated with your phone number to protect against this attack.
In-Person Transaction Protocols
Meeting a stranger to exchange cash for goods carries its own risk profile, and the protocol here is specific.
Many local police departments now designate parking areas as Safe Exchange Zones, monitored, well-lit areas with camera coverage where marketplace transactions can happen safely. These locations are publicly listed and cost nothing to use. If your local precinct offers one, default to it for any cash transaction above a threshold you’re comfortable with.
Some rules that don’t flex: never let a buyer come to your home address. Never complete a transaction in a private location. Don’t go alone for anything valuable. And for cash payments, a counterfeit detector pen costs a few dollars and takes three seconds to use in front of the buyer, most legitimate buyers won’t object.
If a buyer insists on a location you didn’t suggest, pushes back on the idea of a public place, or wants to come to your house specifically, treat that as a hard stop on the transaction.
Building a Default Security Posture
The scams we’re talking about here, verification code hijacking, overpayment fraud, fake tracking exploits, account takeovers, they rely on contiguous beaches of low consumer knowledge and market function that the operators have grown dependent on. They’re not particularly imaginative, they simply require those seams to stay open.
Be more careful with your real phone number, enough that you don’t list it publicly. Understand that cleared funds aren’t the same as guaranteed funds. Keep hands off-platform until a transaction has closed. Use an authenticator app for account protection rather than SMS. Move meetings to monitored public spaces. None of this is an overreaction, it’s just the entry cost for engaging with a world where the threats are real and there is no magic reset button. Run these scripts in 100% of cases and these scams largely disappear.