Avoiding Economic Impact Payment check scams

The coronavirus has led to a pretty enormous piece of legislation being passed by the federal government. The Coronavirus Aid, Relief, and Economic Security (CARES) Act is a $2.2 trillion package that includes, among other things, direct payments to taxpayers, intended to blunt the impact of the severe, widespread economic fallout caused by the pandemic.

At some point in the near future, qualifying individuals will receive a payment. Those who received their tax refund electronically will probably have the payment directly deposited, while others will receive a check in the mail. (I think they are working on setting up a portal so that people who did not provide direct deposit information for 2019 taxes can set it up in lieu of a paper check, but I don’t know all the details.)

This presents a massive opportunity for scammers. Here are some things you need to know.

The government officially refers to these payments as “Economic Impact Payments.” They are NOT calling it a “stimulus check” or a “stimulus payment.”

If you qualify, you will simply receive it. The direct deposit will show up in your account, or you will get a paper check in the mail. Other than depositing or cashing the paper check, that is where it ends. There will be no additional steps to verify that you received it. If you recall the 2008 stimulus package, it will work a lot like that.

If you get the payment, it’s because you qualify, and the government already has correct personal information for you. You will NOT be asked to call a phone number back to verify anything. Or email, or text.

You will NOT receive emails or text messages about the payments.

Nobody will be going door-to-door handing out the checks or anything else, or asking you to sign anything or provide personal information.

I cannot find a straight answer at the moment as to whether or not the payments will be counted as taxable income for 2020 (every website I checked, including the IRS, only talks about “who is eligible?”); however, I can tell you this with confidence: you will NOT be asked to send money right away to cover taxes. Not by wire transfer, not by purchasing prepaid cards or reloadable gift cards, PayPal, Venmo, or any other method. Any caller who says otherwise (I am predicting this will be a big telephone-based scam) is not telling the truth.

Basically, for the vast majority of people who pay taxes, getting your payment will involve doing nothing more than waiting for it to arrive. Any instructions outside of that are highly suspect.

Don’t Waste Money on COVID-19 Cures

Here is a problem: people are already attempting to steal money by hawking fake cures and/or vaccines for COVID-19, the illness caused by the coronavirus (which is technically named SARS-CoV-2, if you want to be accurate about it).

Here is why that’s an even bigger problem: the key to us (as a species) even attempting to slow down and eventually stop the spread of the virus is for people to avoid contact with other people as much as possible. Until there is an actual cure and an actual vaccine (the kind created by actual scientists in a laboratory and confirmed to be safe and effective through actual clinical trials), social distancing is the best we’ve got.

Now imagine a victim of a fake coronavirus inoculant, who spent money on some herbal concoction or…chromium-infused tube socks…I don’t know, whatever goofy thing you can think of. Believing himself to be immune, this guy now goes back out into the world, slacking off on the handwashing, not keeping a safe distance from others and touching his own face like it’s going out of style (which…it actually has). Eventually, he contracts the virus. Even when he begins showing symptoms, believing himself immune, he writes it off as a cold and continues to show up for his job in one of those critical industries that haven’t shut down.

And then he passes it onto several others, who do the same in turn. Eventually, people die because one person fell for a scam.

And THAT is why it is extremely important to not fall for coronavirus cure or vaccine scams.

Here are some things to not waste your money on (and endanger your health and everyone else’s):

  • At-home coronavirus test kits
  • Vitamin C (you can still take it for other reasons, but it won’t cure or prevent COVID-19)
  • Colloidal silver
  • CBD in any form (for all its potential benefits in other areas, this is one where it’s worthless)
  • Herbal supplements (again, some of these have benefits, but not for the coronavirus)
  • Masks (a lot of the ones you can get are worthless; the real ones should be reserved for medical personnel and people who have tested positive)
  • Garlic (even if you’re not being sold pills or whatever, don’t believe anything you might read that garlic will cure the disease; it will, however, make you happier because it’s delicious)
  • Mineral supplements
  • Hot water
  • Anything with the word “miracle” in it
  • Anything advertised as something “Big Pharma” or “THEY” “don’t want you to know about.”

When there is a (real) vaccine available, and when and if there is a (real) drug that cures or curtails the disease, it will very literally be one of the biggest news stories in recent memory. “Big Pharma” will most definitely WANT you know about it, because whichever company develops it will be looking at a potentially unprecedented windfall. Every doctor, hospital and health insurance provider will also very much WANT you to know about it. When it happens, it will be huge.

Coronavirus Scams (March 2020)

Like clockwork, any time a major event, disaster or emergency occurs, scams proliferate.

The coronavirus situation is no different. Already, the worst people in the world are using people’s (completely understandable) confusion and fear to steal money and personal information.

Here is a look at some scams that have already been reported, and some that will likely start to show up in your inbox, your text messages or even your doorstep.

Email scams are already happening. Some attempt to mimic a message from the Centers for Disease Control and Prevention (CDC) or the World Health Organization (WHO), instructing recipients to click a link or open a file attachment to access new information about the virus. This leads the victim either to a website designed to harvest personal information, or a malware infection on the victim’s computer.

Remember that these organizations are not going to email you out of the blue because they do not have your email address on file. You can sign up for email updates about the coronavirus from the CDC by visiting https://www.cdc.gov/coronavirus/2019-nCoV/index.html, but the messages they send will never contain attached files or instructions to turn over personal information.

The CDC and WHO will also not be sending offers for you to purchase vaccines or cures, or asking for donations, and they especially won’t be asking you to send cash, wire money or load up prepaid credit cards and relay the card information to them. Neither will any legitimate organization soliciting donations for anything related to the virus. If you want to help, use established charities you’ve already heard of, and contact them directly.

Apart from fake emails imitating the CDC or WHO, do not believe any offer of a cure, vaccine or preventative being sold online, whether through email, a website or social network. There is no FDA-approved drug or treatment for COVID-19 right now, and there is not likely to be one for quite some time. Of course, this may change at any time (and hopefully sooner than later), but when a treatment and/or vaccine become available, you will hear about it from official sources.

The economic fallout from the coronavirus situation has already begun. It’s impossible to predict what will happen, but there are entire industries whose entire business model hinges on getting people to leave their homes and go to a different location, whether to vacation, to eat, or to be entertained. Manufacturing will also be impacted, as social distancing practices force cutbacks. Many job losses and layoffs will result.

This means work-at-home scams will likely start showing up. These probably won’t be anything new, just versions of old scams that have been circulating for decades. Remember that job opportunities are not going to simply show up out of the blue via email or text message. But you also must be wary of jobs you find by searching online; any offer that involves “processing” payments or shipments is an attempt to rope you into a “money mule” scheme or money laundering operation.

There have also been reports of text messages promising a free iPhone 11 because of the virus. These contain a link to a website set up to do everything BUT put a free phone in your hands.

There have also been reports of people knocking on doors, claiming to be testing for the virus. This is a distraction-type burglary scheme. Even if they appear to be dressing the part, do not be taken in. At least in the U.S., door-to-door testing is not being performed by any official entity at this time, and it is highly unlikely that it will be at any point. Don’t be fooled. In addition to avoiding being burglarized, you want to avoid close contact with anyone outside your immediate household as much as possible.

Avoiding Real Estate Wire Fraud

If you’re in the process of buying a home, or plan to be, you need to be aware of real estate wire fraud.

The goal of this scam is to convince the victim to move the money for a down payment—usually tens, if not hundreds, of thousands of dollars—into an account controlled by the scammer, via wire transfer. And the problem with money sent by wire transfer is that it’s effectively impossible to retrieve. You could lose your down payment and the house.

In some cases, the thieves will use phishing techniques or malicious software to gain access to a realtor’s email accounts, then monitor communications for pending sales. In others, they may use publicly available online tools to identify pending sales, then set up a fake email account that will appear to come from the actual realtor (if the victim doesn’t examine it too closely).

When a sale is approaching its closing date, the thief will send an urgent email to the victim informing them that the instructions for making the down payment have changed—either a check is no longer acceptable and the victim will have to wire the funds, or if the payment was originally going to be made via wire, that they need it to be sent to a different account.

Either way, the message will include wiring instructions that lead to an account held by the scammer, not the realtor.

Losses from real estate wire fraud are growing, with hundreds of millions lost (and that number may be far lower than the actual total—many cases go unreported due to the potential for reputation damage). If you’re buying a house, know that you may very well be targeted. If you receive any new wiring information via email, or a message instructing you to e-sign documents or log in to a website, verify that with a call to the realtor to make sure it’s legit. Double-check everything in that email—is it coming from the correct email address; has the realtor’s command of English grammar suddenly changed?—and slow down instead of reacting quickly in the moment.

Going through extra steps can be a pain, but nothing compared to the pain of sending your entire down payment to a criminal.

Who is at Greatest Risk for Identity Theft?

Identity theft is a ubiquitous crime that comes in many forms and can affect anyone, but some groups of people are at an increased risk.


Children who are too young to have a credit history established are targeted by identity thieves for several reasons. With no history (and therefore no negative history), children represent a ‘clean slate’ for thieves to work with. Also, unless the parents are checking their child’s credit report—essentially to make sure there isn’t one yet—the theft may go unnoticed for years, at least until the victim becomes an adult and begins applying for student loans, credit cards or housing. If you’re a parent, be sure to check your kids’ credit reports whenever you check your own.


Seniors are often targeted for identity theft (and scams in general) over the phone and through online phishing attacks. Seniors are perceived to be most trusting, less savvy and wealthier, making them attractive targets for identity thieves. Some are also reluctant to report that they have been victimized, whether out of pride or shame, or fear that family members will think they are incapable of taking care of themselves.

College Students

College students are at higher risk for identity theft, especially theft is carried out by someone they know. Many are applying for credit cards for the first time, so their credit histories are relatively clean, plus they may not yet be aware of how important it is to keep personal information safe.

Military Personnel

Military service can include significant stretches of time away from home, where collection calls from creditors doesn’t actually owe anything to (one of the warning signs of identity theft) go unanswered, bills from credit cards the victim never applied for go unseen (another red flag), and where the nature of the job can push things like checking a credit report for discrepancies to the back burner.

Higher Income Households

Identity theft takes many forms, but it’s usually financial in nature, so it makes sense that members of higher-income households would be at increased risk. The promise of larger account balances and higher credit ratings makes them a tempting target.


You probably knew this part was coming: even if none of the above categories apply to you, you don’t get to coast. Everyone is a potential victim, and some of your information is almost certainly already out there being bought and sold. Check your credit reports, don’t ignore unexpected collections calls or bills, place credit freezes, and stay informed so you know what to watch out for.

How to Avoid Fake Coupons

Have you ever heard of a little company called Walmart?

What about Costco? Amazon? Target?

Of course you have. They’re all huge corporations. A couple are beyond huge.

But with all the fake coupons circulating over social networks, you’d think they were obscure little startups in need of a gimmick—somethin’ real splashy!—to get people to notice them.

The pitch usually involves taking a short survey to get a coupon for 50% off your entire purchase, or a large discount—often $100 or more—from some large retail chain. What actually happens is that you’ll take an anything-but-short (and usually pretty-darned-long) survey that harvests personal information, including your email address so you can get plenty of spam sent to you, and then a fake coupon that you will be unable to redeem at whichever retailer the scammers have decided to use. In the most egregious cases, the survey website will make you install a program or app to get the fake coupon, which will turn out to be malicious software.

If you see a coupon being shared on a social network like Facebook, right away you should be suspicious. Be even more suspicious if it promises a significant discount from a large, universally-known retailer—newer companies that are trying to build a brand usually offer 10% off (listen to just about any podcast popular enough to have sponsors and you’ll hear at least one such offer). What could Walmart possibly hope to accomplish by giving millions of people (most of whom already shop at Walmart anyway) half off their entire bill, except to make less money? There would be zero upside. The same goes for Target and Amazon, and Costco isn’t going to give anybody a coupon worth more than the membership costs.

When you recognize a fake coupon offer, let whoever shared it know that it’s a scam and a potential security threat, and to delete their post. If the fake coupon originated from a page (such as a Facebook business profile), you can report the page as a scam and hopefully get it removed. The most important thing is to not click the link and to not follow through with any surveys or requests for personal information.

Should You Worry About Writing Out “2020” on Documents?

The warnings are dire and deadly-serious, and by now, you’ve heard it at least once: make sure you write out the year “2020” when you date checks and legal documents, because if you just write the year as “20,” some scammer is going to change it to “2019” or “2018” or “2021” and…do something or other to you.

The primary anxiety seems to be that someone could backdate a loan agreement and make it look as though you initiated the loan in 2017 (for example) instead of 2020, and then sue you for payments and interest, using the signed document as evidence that you didn’t pay for three years.

However, mainstream, trustworthy lenders aren’t going to resort to this kind of thing because getting caught could result in the entire financial institution being shut down for fraud, plus the growing trend of electronic applications and e-signatures renders the point moot anyway.

(Also, you’re not going to borrow from any shady, greasy, fly-by-night under-the-table lenders in the first place, are you? “If it sounds too good to be true…”)

The scenario for writing out the full year on checks usually goes like this: if you just write “20,” but the check never gets cashed, some scammer is going to find it a year later, change the date to “2021,” then cash it.

Okay. And how likely is it that all these circumstances will line up in exactly this way? Most people don’t even write that many paper checks anymore, and very few of those go uncashed. Most payees want to be paid. Of course, anything is possible but even so, now this theoretical-scammer-from-a-year-from-now has a non-staledated check…made out to someone else. At some point, it would be easier to earn his own money, especially since any check that did remain unused long enough to go stale is probably not for an amount large enough to be worth the hassle.

I can’t think of an obvious benefit to this theoretical scam in any other scenario. If you give someone a check dated 2/13/20 and they change it to 2/13/2019, they have now rendered the check void because most financial institutions won’t honor a check past 180 days. And if they change it to 2/13/2021, all they’ve done is make themselves wait another year to cash it. Not exactly the work of a criminal mastermind.

fAll that said, go ahead and write out “2020” on checks and documents anyway. And next year, write “2021,” and after that “2022.” Why? It takes zero effort and it’s more accurate. It’s always good to strive for accuracy. And it eliminates the (ludicrously unlikely) situations above.

Do You Need to Change Your Passwords Regularly?

For years, the conventional data security wisdom has been to change all your passwords every three months. Or sometimes you would hear six months. At least once a year, they would tell you.

But is this necessary in every case?

The short answer is: it depends.

If you know or suspect a password has been compromised (examples: a major data breach has happened, or you fell victim to a phishing scheme), log in to the affected site immediately and change your password.

If you have been using a weak password (a single word, or a word-plus-a-number, or “password” or “abc123”), go change that immediately because that type of password is far too easy to crack. You don’t have to change your password to a string of gibberish (like “iu3r54!#hr3uHCE&@Eibi84f87*^CE” or whatever), but make them long. A long password constructed from random words, such as “vinestumpaxelclownboat,” is more secure than a short one made of uppercase and lowercase letters, digits and special characters, like “hJe4j#x.”

If you’ve been reusing one password for multiple accounts, go ahead and change those. When a database is compromised, cybercriminals will try the hacked email/password combinations at other sites. Example: you’re a member of some online discussion forum you’re not too serious about. If that database gets hacked (or simply downloaded…plenty of websites have been revealed to be keeping member login information in plain text) you can be sure that the people who did it aren’t interested in disrupting discussions about methods for making D.I.Y. tofu (or whatever your hobby is). They’re going to try that email/password at every major credit card, bank, retailer, and social network app. If you’ve reused it anywhere important, nothing good will come of it.

But what if you’re already using a strong password, there hasn’t been a data breach or a hack, and you haven’t fallen victim to phishing or any other tricks? The current advice is to just let that password ride. If it’s impossible for a human to guess and would take a computer script a trillion years to crack, changing it every three or six or twelve months doesn’t really do anything to provide any additional protection.

Of course, you can change any password any time if it helps you feel safer, but make sure to keep them strong, and don’t get into the habit of just changing one digit at the end (changing “vinestumpaxelclownboat1” to “vinestumpaxelclownboat2” for example); this could make your new password guessable if thieves obtained an old database and figured out your pattern.

Another Way They Can Get Your Personal Information

If somebody made a pie chart of every article I’ve ever written about fraud prevention, a very large slice of that pie would be “how to avoid giving away your own personal information to people who shouldn’t have it.”

But victims revealing their data directly isn’t the only way this information falls into the wrong hands. “Of course!” you might say. “There are those big data breaches.”

And that’s true. But there is yet another route that doesn’t get talked about as often: other people being tricked into revealing your data on an individual basis.

Let’s say you’ve got a non-private Instagram account under your actual name, where you post photos of the things you do and the places you go. You go on vacation and post a “check-in” at the hotel at which you are staying.

Eventually, somebody you don’t know sees this post and decides you look like you might have some extra money sitting around. So they call the hotel after you’ve gone home and start asking for details about your stay, pretending to be you. Maybe they’ll say, “I was there on business, so I need to know what card I used, and what email address the information was sent to because I can’t find it,” or maybe they’ll concoct some other way to find out where you bank and harvest some contact information.

Now, maybe the person answering the phone knows about social engineering and cares about keeping people’s information safe. But then again: have you ever checked into a hotel and had to deal with a front desk person whose name might as well have been Yeah Whatever? What if that eyeroll-come-to-life answers the phone? They might not be too bothered about whether or not the person they’re talking to is really you, and just answer the questions to get the caller to go away faster.

Armed with your name (from your Instagram account) and some information about where you bank (and perhaps the last four digits of a card number) and how to contact you, the scammer can then call or email you, pretending to be your financial institution. The premise of this contact? Easy. “There were some charges made in [wherever you just vacationed], and we wanted to make sure it was you,” and from there he or she can attempt to gain access to your account.

Granted, this kind of multi-level, personalized social engineering isn’t extremely common, but it illustrates an important lesson: that you’re not the only potential target for people trying to obtain your personal information. It is vital to watch for the signs of unauthorized access, to be aware of social engineering tactics, and to be extremely wary of any contact that appears to come from your financial institution, even if they seem to already have some of your personal data.

The Pigeon Drop Scam

I’ve been trying for a while to figure out a clear, concise way to explain the Pigeon Drop Scam, but I’ve had trouble keeping the article length reasonable. There are a lot of variations on this very old scam.

The basics are pretty much the same across the board. A stranger approaches you, claiming to have found a large sum of money. Sometimes the money is in a bag, or a box, or a duffel. Sometimes it’s made to look like evidence of a crime, with a note or some other indicator (so the victim thinks whoever it belonged to isn’t likely to come looking for it through legal means). Some scammers work alone, some use an accomplice. At some point, you will be asked to hand over some of your own cash. But there are so many variables to the scheme that it’s hard to even identify what the “classic pigeon drop” scam would look like, to use as an example to write about.

Therefore, it’s probably best to just point you to a video where somebody shows you instead of tells you how this thing works. I found a couple decent ones where a couple pigeon drop scenarios are acted out (in one case on an unsuspecting “victim” who is later let in on the scam and has his cash returned by the crew making the video):

The common thread: a stranger who claims to find money, then asks you to give him or her some of your own for some reason.

The point is this: as soon as a stranger approaches you claiming to have found cash, regardless of how many people you find yourself talking to, regardless of the pitch (whether it’s “hey let’s divvy it up!” or “hold this while I report it” or something else entirely), you are not going to end up a winner if you go along with what that person asks you to do.

Given that this is an in-person scam, I would not recommend letting on that you’re suspicious. Politely suggest they report the find to the police, then walk away. As soon as it is safe to do so, call the police yourself with as good a description of the crook as you can give. You might help someone else avoid being a victim, and you might even help a terrible person run headlong into some well-deserved terrible luck.