The Different Kinds of Cybercriminals I've Learned to Watch For
The Different Kinds of Cybercriminals I've Learned to Watch For
For years I thought about online crime as one big blur, a vague sense that "scammers" were out there and I should be careful. That framing never actually helped me spot anything, because the people behind these messages aren't one type of person running one type of operation. Once I started paying attention to who was actually on the other end, patient researcher, mass-message opportunist, professionalised call centre, or someone playing a long relationship game, I got noticeably better at spotting what was coming before it fully landed. These aren't official categories from a textbook, they're just the patterns I've come to recognise in the messages, calls, and situations I deal with regularly.
The Opportunist Playing a Numbers Game
This is the one most people picture when they hear "scammer," and it's the easiest to spot once you know what you're looking at. The opportunist isn't targeting you specifically, they're sending the same generic message to thousands of people at once and counting on a tiny percentage responding. A fake delivery text, a "your account has been suspended" email, a too-good voucher offer, none of it is personalised because personalising it isn't worth their time at that scale. The tell is almost always genericness dressed up as urgency, a message that could apply to literally anyone, paired with pressure to act immediately. I've stopped treating these as a personal attack and started treating them as background noise, because that's genuinely what they are, spam that happened to land in front of me rather than someone else. One small habit that's caught more than a few of these for me without any real effort on my part, NordPass simply won't autofill my login details on a fake copy of a site, because it checks the actual web address rather than how convincing the page looks.
The Patient One Who Researches You First
This is a different category entirely, and it's the one that actually worries me more. Someone running a targeted approach has looked at your public profile, your job title, who you work with, maybe even a recent post about a project or a holiday, before ever sending that first message. The result doesn't feel generic at all, it feels specific and plausible, referencing a real colleague's name or a real event you actually attended. That specificity is exactly what makes it dangerous, because it borrows the same trust signal that makes a genuine message feel genuine. I've learned that the more tailored something feels, the more worth double-checking it becomes, not less, because tailoring takes effort that only pays off against a real target, not a random one.

The Organised Operation Behind a Single Text Message
What surprised me most once I started reading into this properly is how much of what looks like an amateur scam is actually the output of a genuinely organised operation, scripts, shift patterns, escalation paths for when a target pushes back. A convincing bank-fraud call rarely comes from one person freelancing, it comes from a team that has run that exact script hundreds of times and knows precisely how to sound calm, official, and reassuring under pressure. That professionalism is why so many otherwise careful people get caught out, the caller genuinely sounds like they know what they're talking about, because in a narrow sense they do, they've just rehearsed it against real victims before you. Knowing that a call center might be running the show, rather than one chancer, changes how I treat any unexpected call asking me to act fast, whoever it claims to be from.
The Long Con Built on a Relationship, Not a Click
This is the category that takes the longest to unfold and does the most damage when it works, because it isn't built around one message at all, it's built around weeks or months of genuine-feeling contact before any ask ever appears. A romance approach, a fake investment mentor, a new online friend who happens to know a great opportunity, all of these work by establishing trust slowly enough that the eventual request doesn't feel like a stranger asking for money, it feels like a friend needing help. I've learned that the length of a relationship isn't itself proof of anything, plenty of genuine friendships also take time to build, but a relationship that consistently steers toward money, urgency, or secrecy is worth examining regardless of how long it's been running or how real it's started to feel.
Why the Category Matters Less Than What They're Asking For
Naming these categories has helped me spot the early signals faster, but I've noticed the actual decision that matters most is always the same regardless of which type I'm dealing with, what is this message or call actually asking me to do. Send money, share a code, click a link, move to a different platform, every category above eventually arrives at some version of that request, and that request is the moment worth pausing on more than any earlier detail about who's asking or how they found me. I still find it useful to think about which category I might be facing, because it shapes how much scrutiny I apply to the early stages, but I don't let correctly identifying the type replace checking the actual ask when it finally arrives. If you want a more detailed breakdown of the actual verification habits I rely on once I suspect something's off, I've written about that process separately, and my free Safety Toolkit covers the wider set of practical protections I'd recommend putting in place regardless of which of these you end up facing. If you're ever unsure whether something you've received fits one of these patterns, Action Fraud is the right place in the UK to report it and get it looked at properly.
