• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

The Consumer Kill Chain

The anatomy of a scam

A scam isn't a stroke of bad luck — it's a process. Every one moves through the same four phases, from a stranger's research to your bank account. We map that process so we can interrupt it.

PHASE 01 · TARGETING · 1 STAGE

They find you

Scammers don't pick randomly. Before the first call or text ever reaches you, they do reconnaissance — buying lists from data brokers, scraping social media, trawling breach dumps for people who fit a profile. Then comes resource development: burner phones, cloned websites, spoofed caller IDs. By the time you hear from them, you've already been chosen.

PHASE 02 · ENGAGING · 2 STAGES

They hook you

A text from your bank. A LinkedIn message from a recruiter. A voicemail about a package. Initial contact is designed to feel familiar — a logo you recognize, a name you half-remember. Then trust building does the rest: an urgent tone, a detail that only "your bank" would know, a screenshot of other happy customers. None of it is real. All of it works.

PHASE 03 · EXECUTING · 3 STAGES

They exploit you

Trust is the currency; now they spend it. Exploitation is the ask — install this app, read me the code, approve this charge. Collection is what happens next: they drain whatever that access unlocks, whether that's your inbox, your contacts, or your savings. This is the minute you'll replay later.

PHASE 04 · EXTRACTING · 1 STAGE

They take your money

Access is only useful once it turns into cash. Extraction is the laundering step — wire transfers, gift cards, crypto conversions, reshipping, identity resale. By the time it shows up on a statement, the money is usually gone.

The full taxonomy

Every technique, mapped

Grouped by the stage where it shows up. Follow any one to see how it works and what stops it.

Targeting
Engaging
Executing
Extracting
TARGETING6 techniques
DELIVERY22 techniques
MANIPULATION14 techniques
COMPROMISE15 techniques
EXPLOITATION12 techniques
PERSISTENCE10 techniques
MONETIZATION14 techniques
  • Data Breach Harvesting
  • Social Media Reconnaissance
  • Dating Profile Farming
  • Data Brokers
  • Ad Network Tracking
  • ISP Data Harvesting
  • Phishing Email
  • Smishing
  • Vishing
  • Deepfake Voice Call
  • SEO Poisoning
  • Quishing
  • Fake E-commerce Site
  • Pop-up Scareware
  • Package Delivery Scam
  • Employment Scam
  • Rental Scam
  • Lottery Prize Scam
  • Deepfake Video Call
  • Tech Support Scam
  • Malvertising
  • Influence Operation
  • Deepfake Celebrity Endorsement
  • Poisoned Software
  • Lookalike Domain
  • Brand Impersonation
  • Business Email Compromise
  • Fake Captcha
  • Extended Trust Building
  • Off-Platform Luring
  • Urgency Creation
  • Small Win Engineering
  • Isolation Tactics
  • Sunk Cost Exploitation
  • Influence Operation
  • Astroturfing
  • Sock Puppet Network
  • Review Manipulation
  • Group Hijacking
  • Account Repurposing
  • Authority Impersonation
  • Family Emergency Scam
  • Credential Theft
  • SIM Swap
  • MFA Fatigue Attack
  • Clipboard Hijacking
  • Malicious App Installation
  • Overlay Attack
  • Supply Chain Compromise
  • Man In The Middle
  • Infostealer
  • Change of Address Fraud
  • Ransomware
  • Malware
  • Payment Card Theft
  • Session Token Theft
  • Cookie Hijacking
  • Account Takeover
  • Authorized Push Payment Fraud
  • Synthetic Identity Creation
  • Doxing
  • Swatting
  • Identity Theft
  • Criminal Identity Theft
  • Credit File Address Injection
  • Influence Operation
  • Stalkerware
  • Keylogger
  • Pig Butchering
  • Remote Access Tool
  • Email Forwarding Persistence
  • Payment Method Injection
  • MFA Device Registration
  • Stalkerware
  • Cloud Account Persistence
  • Account Recovery Backdoor
  • Secondary Account Creation
  • OAuth Token Persistence
  • MFA Device Registration
  • Fake Crypto Platform
  • Fund Siphoning
  • Wire Transfer Redirect
  • Gift Card Extraction
  • Crypto Wallet Drain
  • Sextortion
  • New Account Fraud
  • Tax Identity Theft
  • Medical Identity Theft
  • Child Identity Theft
  • Identity Theft
  • Extortion
  • Payment Card Theft
  • Invoice Fraud

About this taxonomy

The original kill chain came out of enterprise security — a framework for mapping network intrusions. It didn't describe scams, where the target is a person, not a system. So we built the Consumer Kill Chain: a map of how scams actually move, end to end. The model is adapted from MITRE ATT&CK, reorganized around how consumer scams unfold. Techniques are drawn from Malwarebytes threat research, user-submitted reports across our products, and public threat intelligence.