Skip to main content

Fraud: Re: | Fake MacKenzie Scott Foundation Donation of USD 100,800,000

· 29 min read
Jagdish Kumawat
Jagdish Kumawat
Founder @ Dewiride

I am MacKenzie Scott, ex-wife of Amazon CEO and founder Jeff Bezos. A Chinese-language donation fraud promising USD 100,800,000 through a foundation that does not exist, sent from a German online shop's info mailbox under a subject line that is only Re:.

Complete Email

from: MacKenzie Scott info@gewerbe-online-shop.de
date: 09/04/2026 4:44 AM
subject: Re:

Email Body

您好,

我是麦肯齐·斯科特,亚马逊首席执行官兼创始人杰夫·贝佐斯的前妻。我将通过斯科特基金会向您捐赠一笔款项。我已向全球慈善机构、个 154;和教育机构捐赠了190亿美元,旨在为受新冠疫情影响而面临经济困境的人们提供紧急援助。

我很高兴地通知您,您已被选为我捐赠款项的幸运受益人之一。您将获得100,800,000.00美元的资助。如果您对此感兴趣或想了解更多信息,请随时与我ೕ ; 2;系。

此致, 麦肯齐·斯科特

English Translation

The message is written entirely in Simplified Chinese. Translated, it reads:

Hello,

I am MacKenzie Scott, ex-wife of Amazon CEO and founder Jeff Bezos. I will donate a sum of money to you through the Scott Foundation. I have donated USD 19 billion to charities, individuals [the word 个人 is broken in the original, appearing as + 154;] and educational institutions worldwide, in order to provide emergency assistance to people facing economic hardship as a result of the COVID-19 pandemic.

I am pleased to inform you that you have been selected as one of the lucky beneficiaries of my donation. You will receive a grant of USD 100,800,000.00. If you are interested or would like more information, please feel free to contact me [the word 联系 is broken in the original, appearing as ೕ ; 2; + ].

Sincerely, MacKenzie Scott

Those two mangled words are the single most revealing thing in the message, and they are dissected in Red Flag 5.

Attacking email screenshot


Red Flags

This is a donation scam — advance-fee fraud wearing the clothes of philanthropy. The structure is the familiar one: an enormous sum, a famous name, no explanation of why you in particular, and a request that you get in touch. Nothing is asked for in this first message, because nothing needs to be. The fees arrive later, once you have written back.

What distinguishes this specimen is that it borrows a real philanthropist. MacKenzie Scott exists, she is Jeff Bezos's ex-wife, and she has genuinely given away an extraordinary amount of money to organisations that never asked her for it. That last detail is why the impersonation is attractive: her actual practice of surprising strangers with money makes a surprise offer of money feel less impossible than it should. The scam works by borrowing the shape of her giving while getting every single specific about it wrong.

And it gets a lot wrong. Six of the claims below can be checked in a couple of minutes with a search engine, and every one of them fails.

1. There Is No "Scott Foundation"

  • 我将通过斯科特基金会向您捐赠一笔款项I will donate a sum of money to you through the Scott Foundation

This is the load-bearing claim of the whole email, and it is false in the most basic possible way: the Scott Foundation does not exist.

MacKenzie Scott's giving is deliberately, famously, not run through a foundation. She has no private foundation, no public-facing office, and no grant-making bureaucracy. Her giving is announced through a website called Yield Giving, and her stated reason for structuring it that way is to keep overheads and gatekeeping out of the process. This is not an obscure technicality — it is the single most widely reported fact about how she operates, and it has been written about extensively precisely because it is unusual among billionaire philanthropists.

The attacker invented "斯科特基金会" for the same reason every one of these emails invents an institution: a foundation sounds like a process. It implies an application that was considered, a committee that decided, a legal entity that will wire the money, and later on it supplies a letterhead for the fake award certificate and a plausible sender for the fake "transfer fee" invoice. A named body is the scaffolding that all subsequent stages of the fraud will be hung on.

It also creates the one thing an attacker most needs: a channel that only they control. There is no real Scott Foundation, so there is no real Scott Foundation to phone.

2. You Cannot Be "Selected", Because There Is Nothing to Be Selected For

  • 您已被选为我捐赠款项的幸运受益人之一you have been selected as one of the lucky beneficiaries of my donation

Two things about Scott's actual giving demolish this sentence.

Her money goes to organisations, not to individuals. The recipients are non-profits, community colleges, food banks, housing charities, universities, health providers. Not people. Not inboxes. There is no category of gift for which a private individual or a company support desk could ever be a candidate, so there is no list on which anyone could be "one of the lucky beneficiaries".

And you cannot apply. There is no application form, no submission process, and no way to reach her directly. Her team researches organisations quietly and, when a gift is made, the recipient is typically contacted through an intermediary with very little warning — an approach that has been reported on repeatedly, because organisations keep describing the experience of being contacted out of nowhere.

Notice how the attacker has taken that last, genuinely surprising feature of her giving and used it as cover. She really does contact people out of nowhere is the thought this email is engineered to produce. The gap the reader is not invited to notice is that she contacts vetted institutions through verified channels after months of research, not scraped addresses by cold email.

The word 幸运lucky — is doing the rest of the work. It is the standard vocabulary of lottery and prize fraud, and it exists to pre-empt the obvious question. If you were chosen because you were lucky, then there is no criterion to examine, no reason you can fail to satisfy, and nothing to check. "Lucky" is what a message says when it cannot say why.

3. Jeff Bezos Has Not Been Amazon's CEO Since 2021

  • 亚马逊首席执行官兼创始人杰夫·贝佐斯Amazon CEO and founder Jeff Bezos

Bezos founded Amazon; that part is right. But he stepped down as chief executive in July 2021, more than five years before this email was sent, handing the role to Andy Jassy and moving to executive chairman. It is not an obscure corporate detail — it was front-page business news worldwide and remains trivially checkable.

The credential is there to buy authority in the first sentence, before the reader has decided whether to keep reading. It is the only piece of verification the email offers about who is writing, and it is stale by half a decade.

That staleness is the useful part. This template has been in circulation, unmodified, for years. Nobody maintains it, because nobody needs to — the same text is blasted to millions of addresses at effectively zero cost, and a paragraph that convinces one person in a hundred thousand pays for itself whether or not the facts in it are current. An email that cannot be bothered to check whether its own headline claim is still true is not an email written for you.

4. USD 19 Billion Was Roughly True Once. It Is Now Years Out of Date

  • 我已向全球慈善机构、个 154;和教育机构捐赠了190亿美元I have donated USD 19 billion to charities, individuals and educational institutions worldwide
  • 旨在为受新冠疫情影响而面临经济困境的人们提供紧急援助to provide emergency assistance to people facing economic hardship as a result of the COVID-19 pandemic

The USD 19 billion figure is not invented. It is scraped from real news coverage — it was approximately her running total a couple of years ago, and reporting it was everywhere. That is exactly why it is in the email: a number a sceptical reader might actually verify, sitting in a paragraph where everything else is fabricated.

But the real figure has since passed USD 26 billion. She gave away more than seven billion dollars in 2025 alone. The email's headline statistic is around seven billion dollars behind reality, which tells you precisely when this template was written and that nobody has touched it since.

The pandemic framing is stale in the same way and more obviously so. Scott's giving in 2020 was explicitly framed around COVID-19 emergency relief, and that framing is what the template captured. Reading "emergency assistance to people affected by the COVID-19 pandemic" as a live, present-tense rationale in September 2026 is like receiving a letter about the Y2K bug. Her giving has long since moved on to entirely different priorities.

There is a general lesson here worth more than this one email. Check the age of an email's facts, not just their truth. Fraud templates are written once and reused for years, so their details freeze at the moment of composition. A claim that was accurate in 2023 and is quietly wrong today is a fingerprint of a message that has been sent a very large number of times to people who were not you.

5. The Broken Characters Are HTML Entities — This Was Machine-Generated

This is the technically decisive flag, and it is worth going slowly, because it proves something the rest of the email only suggests.

Two Chinese characters in the body did not render. In their place sit these fragments:

WhereWhat is displayedWhat the sentence requires
154; 和教育机构an unrenderable box, then a literal 154;individuals
请随时与我 ೕ ; 2; a stray Kannada mark, then a literal 2;系 — contact

The first of those is easiest to see in the screenshot above, where the mail client draws the undisplayable character as a hollow box; copied out as text it collapses to whitespace, which is why the reproduction earlier in this post shows only a gap before 154;.

Those leftovers are not random corruption. They are the tails of HTML numeric character references, and the arithmetic identifies them exactly:

  • The missing character in the first gap is (person). Its Unicode code point is U+4EBA, which is decimal 20154, so as an HTML entity it is written 人. Break that after the second digit and you get &#20 — an invisible control character with no glyph, which is the box on screen — followed by the literal text 154;. That is precisely what is displayed.
  • The missing character in the second gap is (to connect, as in 联系, to contact). Its code point is U+8054, which is decimal 32852, written 联. Break that after the fourth digit and you get ೕ — which is a perfectly valid entity in its own right, resolving to U+0CD5, the Kannada length mark ೕ — followed by the literal text 2;. Again, exactly what is displayed.

A stray Kannada diacritic in a Chinese business letter is not a coincidence. It is the first four digits of 32852 being decoded as if they were the whole number. The two gaps break at different offsets and produce completely different debris, and both are explained by the same single cause.

So what does that prove? It proves the message body was not typed by a person into a mail client. It was composed as HTML with the Chinese characters escaped into numeric entities — the mechanical output of a template engine or bulk-mailing tool trying to make non-Latin text survive an ASCII-only pipeline — and then pushed through something that corrupted the escaping on the way out.

Which means:

  • This is a template, not a letter. Nobody escapes Chinese characters by hand. A person writing to one recipient types 个人 and 联系 and sees them appear.
  • Nobody proof-read it. The corruption is in the middle of two ordinary words in a four-paragraph message. Any human who glanced at the message before sending would have caught it instantly. Nobody glanced, because it was not sent to a person — it was sprayed at a list.
  • It has been sent a very large number of times. Broken output is only tolerable at a volume where individual copies do not matter.

The world's most-discussed philanthropist, writing personally to inform you of a hundred-million-dollar gift, could not produce four paragraphs of clean text. That is not a rendering hiccup. It is the mass-mailing machinery showing through the letter.

6. Signed by an American Philanthropist, Sent From a German Shop's info@ Mailbox

  • from: MacKenzie Scott info@gewerbe-online-shop.de

Read the display name and the address together and they describe two entirely unrelated things.

gewerbe-online-shop.de is a German domain — Gewerbe is German for a trade or commercial business, and .de is Germany's country code. Whatever it is, it is a German commercial web shop, and info@ is the generic contact mailbox almost every small business publishes on its own website. It is an ordinary trading address belonging to an ordinary trading company.

MacKenzie Scott is American. Her giving vehicle is American. Neither has any connection to a German online retailer, and no arrangement exists under which one would send her correspondence.

The pairing is not an attempt at disguise — it is too obviously wrong to be one. It is economy, the same economy visible in the fake Olena Zelenska investment approach, which was signed by Ukraine's First Lady and sent from a car dealership's mailbox in the United Arab Emirates. The attacker has two separate requirements: a mailbox with enough sending reputation to reach an inbox, and a name with enough pull to be opened. Those requirements have nothing to do with each other, so they are satisfied separately and never reconciled.

An info@ mailbox on a small business domain is a favourite for a specific reason. It is published on the company's own website, which means it is scraped constantly; it is often protected by a weak or reused password; and it is frequently nobody's personal responsibility, so a takeover can run for weeks before anyone notices the outbound volume. The German shop is a victim here too, and very probably has no idea its contact address is signing letters as an American billionaire.

7. A Subject Line That Is Only "Re:"

  • subject: Re:

Not a short subject. Not a vague subject. An empty one, carrying nothing but a reply prefix.

Re: asserts that this message continues a conversation you started. Search your sent folder and there is nothing — no earlier message, no quoted history, no thread. The prefix is bolted on for two reasons: a busy reader may assume a thread they have lost track of, and reply-prefixed subjects have historically scored slightly better with filters, because the great majority of genuine ones really are replies.

But this one has taken the trick a step too far and left the subject completely blank, which produces something no legitimate correspondence ever looks like. Somebody writing personally to award you a hundred million dollars would give the message a subject. A support desk, a bank, a law firm, a charity — every one of them would. A reply prefix with nothing after it is a message that had no subject and had one bolted on anyway.

8. USD 100,800,000.00 — Down to the Cents

  • 您将获得100,800,000.00美元的资助you will receive a grant of USD 100,800,000.00

Two things are wrong with this number, and they point in opposite directions.

It is wildly out of proportion to the recipient. Gifts of this size do exist in Scott's real giving — but they go to national institutions with the capacity to absorb them, and even then they are usually broken up. Her largest publicly disclosed donation, USD 436 million to Habitat for Humanity in 2022, was split between the international organisation and 84 separate local affiliates, so that no single recipient received anything close to the headline number. What is being offered here is a larger sum than most of those affiliates got, going to one unverified address on a mailing list, with no idea who or what is on the other end. Set against the email's own USD 19 billion figure, this single unsolicited grant would be more than one in every two hundred dollars she has ever given away. The sum is not chosen to be believable. It is chosen to be large enough to override scepticism — a reader who has started imagining what they would do with a hundred million dollars has stopped auditing the story, which is the entire purpose of the paragraph.

And it is far too precise. 100,800,000.00 — a hundred million dollars specified to the cent. Nobody writes a philanthropic gift that way. Grants are announced as round figures, because they are decided as round figures. The trailing .00 is a small, revealing tell: it is what you get when a number is formatted by a currency function in a template, not written by a person deciding how much to give.

The odd 800,000 in the middle is the same instinct, more crudely applied. A suspiciously round hundred million gets dressed up with an arbitrary extra fraction so that it looks calculated rather than invented — the same reasoning that makes fake invoices end in odd cents. False precision is used here as a substitute for evidence, and it is one of the most consistent markers of fabricated financial numbers in fraudulent mail.

9. Chinese Text, an Indian Support Desk, and No Way to Reply

  • to: Dewiride Support
  • 您好Hello — and no name anywhere in the message
  • 请随时与我ೕ ; 2;please feel free to contact me — with no address given

Three separate failures of targeting, all visible at once.

The language is wrong. A Simplified Chinese letter, with no English version, arriving at the support mailbox of an Indian technology company. No attempt at localisation, no acknowledgement that the recipient might not read Chinese. The message was written once and sent to every address on a list regardless of country, language, or industry, which is why it fits none of them.

The recipient is wrong, and anonymous. It is addressed to Dewiride Support — a shared departmental mailbox, not a person. The greeting is a bare 您好 with no name after it. Count the facts about the recipient anywhere in the message: there are none. No name, no organisation, no reason they were chosen, no mention of what they actually do. A benefactor selecting you for a hundred million dollars would, at absolute minimum, know your name.

The shared-mailbox angle deserves a moment. support@, info@, sales@ and contact@ addresses are read by several people in rotation, and the one who happens to open a message like this may not be the one who would recognise it. These addresses are scraped from public websites precisely because they are published, and they are targeted precisely because responsibility for them is diffuse.

And there is nowhere to reply. The email ends by inviting you to get in touch and then supplies no contact address at all — no reply-to, no alternative mailbox, no phone number. It is a striking omission, because in most fraud of this kind the contact detail is the one precise thing in an otherwise vague message. Its absence here means any reply travels straight back to info@gewerbe-online-shop.de, the abused German mailbox, which tells you the attacker is either reading mail in that account directly or forwarding from it. Either way, the message that invites correspondence has no correspondent — a letter offering you a hundred million dollars that neglects to say where to write.


How This Scam Works

The first email is bait and nothing more. It carries no link, no attachment, and no request for money or information, which is exactly why it does not read as an attack and why so many gateways let it through. Its only objective is a reply — because a reply turns an address on a scraped list into a human being who has demonstrated interest, and everything expensive happens after that, one message at a time.

  1. The List: Addresses are harvested in bulk from company websites, WHOIS records, business directories, and old breach dumps. info@, support@, and contact@ mailboxes are prized because they are published by design. No targeting is applied and none is attempted — the same text goes to everyone.
  2. The Template: A donation-scam script, years old, is loaded into bulk-mailing software with the Chinese body escaped into HTML numeric entities. The escaping breaks. Nobody checks, because at this volume individual copies do not matter.
  3. The Borrowed Mailbox: A real info@ account at a real German business is taken over — a reused password, a credential from an old breach, an unattended shared mailbox nobody owns. Its mail carries the domain's accumulated sending reputation, so it reaches inboxes that a freshly registered scam domain never would.
  4. The Blast: The same message goes out to enormous numbers of recipients. The overwhelming majority delete it, and that is an intended outcome rather than a cost.
  5. The Reply: Somebody answers. This is the only thing the first email was ever for. From here the attacker stops running a campaign and starts running a conversation, and they will invest real hours in it.
  6. The Paperwork: Trust is manufactured on paper. An award letter on invented "Scott Foundation" letterhead, a fake donation certificate, a beneficiary reference number, a scanned passport page, sometimes a lawyer's or bank officer's engagement letter. All fabricated, and all convincing enough on a phone screen, which is where most of it will be read.
  7. The Third Party: A "foundation trustee", bank officer, or claims attorney joins the thread from a separate address. The arrival of an apparently independent institution is the turning point: the victim is no longer weighing one stranger's word but an apparatus, and the attacker gains a second voice to apply pressure the gracious "benefactor" can seem above applying.
  8. The First Fee: An obstacle appears, and it is always trivial against the prize. A transfer charge, an anti-money-laundering or compliance certificate, a tax clearance, a notarisation, a courier fee for the cheque, an "account activation" cost. A few hundred dollars against a promised hundred million reads as obviously worth paying. This is the entire point of the exercise.
  9. The Escalation: Each fee clears the last obstacle and reveals a new one. The amounts grow as the victim's sunk cost grows, and every payment makes withdrawal psychologically harder — walking away now would mean the earlier payments were wasted, which is exactly the reasoning the sequence is built to produce.
  10. The Data Harvest: Alongside the money, the attacker collects bank details, identity documents, company registration papers, and signatures, all requested "for the transfer paperwork". These have independent resale value and enable identity fraud entirely separately from the fees.
  11. The Mule Risk: In some variants money genuinely does arrive, with instructions to forward most of it onward. That money was stolen from someone else, the victim's account has just laundered it, and the victim is the only traceable party in the chain. People have been prosecuted for this while believing themselves the injured party.
  12. The End: There is no hundred million dollars and there never was. Contact stops, or one final catastrophic fee is demanded and the thread dies. The address is then sold on to other operators, often as part of a "recovery" list — which is why the next email will offer, for a fee, to get the earlier money back.

Conclusion and Recommendations

There is no Scott Foundation, no grant, and no hundred million dollars. There is a German online shop's contact mailbox that somebody else is using, a philanthropy template so old it still blames the pandemic and still calls Jeff Bezos the CEO of Amazon, and a mass-mailing tool that could not get four paragraphs of Chinese out of the door without breaking two of the words.

The instructive part is how much of this collapsed without any technical skill at all. Six claims, six searches, six failures — the foundation that does not exist, the CEO who left in 2021, the total that is seven billion dollars stale, the pandemic that ended years ago, the gifts that go to organisations rather than people, and the application process that has never existed. The one genuinely technical finding, the broken HTML entities, only confirmed what the fact-checking had already established.

It is also worth noting what worked. The mail client flagged the message as junk, disabled its links, and tagged it as external before anyone read a word of it. Those controls did their job. They are not the reason to relax, though, because the next copy of this template will come from a mailbox with a cleaner reputation and will land in the inbox. The durable defence is the one that does not depend on a filter: when a message offers you money you did not earn from a person you have never met, the story is the attack, and the story is the part you can check.

Immediate Actions:

  • Do Not Reply, Not Even to Decline: A reply is the only thing this email wants. Any response — a refusal, a question, an insult, a request to be removed — confirms a live, human-attended mailbox and raises the value of your address on the lists it is traded on. There is no version of engaging that costs the attacker anything.
  • Never Pay a Fee to Receive Money: No genuine gift, grant, prize, or inheritance requires you to pay first. Not a transfer charge, not a tax, not a compliance certificate, not a courier fee, not an activation cost. The advance fee is the entire fraud, and every stage of the conversation exists only to reach it.
  • Do Not Send Identity or Banking Documents: A passport scan, an ID card, a bank statement, or a company registration certificate has resale value on its own and enables fraud in your name long after this thread is dead.
  • Report and Delete: Use your mail client's phishing or spam report rather than plain deletion, so the sending address is scored and, on a corporate system, your security team sees the campaign. The junk classification already applied here is a good sign that reporting works.
  • Warn Everyone Who Reads the Shared Mailbox: support@, info@, and sales@ are read by several people, and the one who opens the next one may not be the one who would recognise it. Thirty seconds of heads-up is worth more than a policy document.
  • If Anyone Has Already Engaged, Stop and Escalate Now: Cease contact, do not send the "final" payment that will supposedly release the funds, preserve every message and receipt, and report to your national cybercrime authority — in India, the National Cyber Crime Reporting Portal at cybercrime.gov.in or the 1930 helpline. If money has moved, tell your bank immediately; the first hours are the only realistic window for a recall.
  • Treat Any Offer to Recover Lost Money as the Next Scam: Victim lists are traded, and follow-up fraud aimed at people who have already paid is a specialised business. A lawyer, agency, or "recovery service" that finds you by email and asks a fee to retrieve earlier losses is the same criminal or a colleague.

Verification Steps:

  • Search the Institution Before the Person: "Scott Foundation" takes five seconds to check and is the fastest way to end this analysis. Invented organisations are the most common single element in donation and prize fraud, because a named body is what makes an unbelievable offer sound administered.
  • Check How the Real Organisation Actually Gives: Every genuine grant-maker publishes its process — who is eligible, how recipients are found, whether applications are accepted. Compare that published process against what the email describes. Here the mismatch is total: real gifts go to vetted non-profits through verified channels, not to individuals by cold email.
  • Check the Age of the Facts, Not Just the Truth: A stale CEO, a stale donation total, and a stale pandemic all point the same way. Fraud templates freeze at the moment they were written and are reused for years. A detail that was accurate three years ago and is quietly wrong today is the signature of a message sent to millions.
  • Read the Display Name Against the Address: They should describe one person or organisation. "MacKenzie Scott" at a German online shop's info@ mailbox is two unrelated answers to "who sent this?", visible before the message is even opened.
  • Ask What the Sender Knows About You: A real benefactor knows your name, your organisation, and why they approached you. A bare 您好 and a shared support address prove the sender holds nothing but a scraped string.
  • Notice Where You Are Asked to Reply — Or That You Are Not: A message that directs replies to a free webmail account elsewhere is describing its own disposability. A message that invites contact and gives no address at all, as this one does, is not corresponding with you either.
  • Treat Rendering Errors as Evidence: Stray entity fragments, replacement boxes, unfilled merge fields such as {{FirstName}}, and mismatched character sets are the mass-mailing machinery becoming visible. No organisation sends a personal, life-changing message with the words broken in the middle.
  • Verify Through a Route You Already Had: If a message claims to come from a well-known person or organisation, contact them through channels you found yourself — a website you navigated to directly, a published switchboard number, an official press office. Never a detail supplied by the message.

Additional Protection Tips

  • Recognise the Shape, Not the Story: The cover changes constantly — a lottery, an inheritance, a dying philanthropist, a compensation fund, a crypto airdrop, a billionaire's foundation. The skeleton never does: large sum, famous or foreign benefactor, you were selected, contact me for details. Learn the skeleton and every future variant is recognisable in the first paragraph, whatever name is in fashion.
  • Expect the Names in the News to Be the Names in the Fraud: Impersonation follows publicity. MacKenzie Scott is impersonated because her real giving is famous, surprising, and unsolicited — the attacker is borrowing a story the reader has already half-heard and believes. Any philanthropist, lottery winner, or disaster-relief fund that trends will be in an inbox within days.
  • Understand That the Absence of a Link Is Not Safety: This email contains nothing to click and nothing to open, which is why it survives filters tuned largely for URLs and attachments. The payload of an advance-fee approach is the conversation, and no gateway can scan for that. A clean message is not a safe one.
  • Treat Unsolicited Good News as the Warning Sign: Money you did not earn, from a person you do not know, for work you have not done, is the most reliable single indicator of fraud in email. The 4,800,000 Euro donation and the Faith Isabella investment corporation messages in our archive are the same offer with different scenery.
  • Lock Down Shared and Forgotten Mailboxes: This campaign is flowing through somebody's real info@ account. Generic departmental addresses, legacy mailboxes, and accounts belonging to staff who left are exactly what gets taken over, because nobody is watching them. Give every shared mailbox a named owner, enable multi-factor authentication, and audit for accounts nobody claims.
  • Never Reuse a Password on a Mailbox: A mailbox is not one account among many — it is the reset mechanism for all the others and the identity your customers and suppliers trust. Unique credentials and a password manager are the whole defence against the takeover that put this message in flight.
  • Watch Your Own Outbound Mail: The German shop in the from: line is a victim who almost certainly does not know. Alerting on unusual sending volume, logins from unexpected countries, and new forwarding or auto-reply rules is how a compromised mailbox gets caught in hours rather than months.
  • Adopt a Two-Person Rule for Money Leaving the Business: Any payment to a new beneficiary, any change to bank details, and any fee attached to an unexpected windfall should require a second person's approval and a voice call to a number from your own records. Fraud of this kind depends on one person acting alone and slightly excited.
  • Say Out Loud What You Are About To Do: These schemes rely on isolation. Describing the situation to one uninvolved colleague, friend, or family member breaks the spell more reliably than any technical control, because the absurdity is obvious to everyone except the person inside the conversation.
  • Make It Safe to Own Up: Donation and advance-fee fraud is unusually humiliating for its victims, and shame is what turns a small loss into a large one — people keep paying rather than admit the earlier payments. A workplace where somebody can say I think I have been caught by this without consequence recovers money that a workplace built on blame never sees.

Remember: Real philanthropists find you after months of research and tell you through channels you can verify; they do not find you in a scraped address list and announce it in a message whose own words are broken. When an unearned fortune arrives by email, the fortune is the bait and the fee is the point.


Share this post