Stop the scam before it works

A free one-page checklist: five rules and four warning signs taken from ten real attacks, straight from the court filings, regulator reports and company post-mortems.

It's yours.Print it, pin it up, or send it to your team.

Download the PDF

We use your email only to send the checklist and new case studies from Pretext Stories. Unsubscribe any time.

Preview of the Scam-Proof Checklist
10 real casesBuilt from primary sources: Justice Department, FBI, regulators, the companies themselvesNo jargon, one page

The five rules

1Check on a channel you chose

Hang up and call back on a number you already have. Verify the person, not just the paperwork.

2Never hand over a login or code

Open the site yourself. Nobody legitimate needs you to read them a code.

3Use a key, not a code

Passwords and codes can be relayed. A hardware security key checks the site's address.

4Two people for big actions

Least access for everyone, so one mistake does not travel far.

5Report fast, make it safe

Minutes matter. Blame the attacker, not the person who clicked.

Four warning signs

Urgency

"Your account is about to be deactivated."

Secrecy

"Don't tell anyone."

A new account

Same supplier, new bank details.

A fee to get paid

Pay a tax, then a late fee, to withdraw your own money.

Where it comes from

Pretext Stories breaks down real cyberattacks and scams: how they started, the lie that made them work, and what would have stopped them.

Every episode is built from primary sources and the sources are in each video's description.

Worth knowing

These are common practices drawn from what the original reports and court documents say. They lower the odds. They are not guarantees, and allegations in the cases are allegations.