The one rule
If you remember nothing else
No legitimate organisation is ever paid in gift cards. Not the IRS or HMRC. Not a utility company. Not a court, a bailiff or a debt collector. Not your bank’s fraud department. Not the police. Not an employer asking you to buy cards for clients. Not a delivery company holding a parcel.
There is no exception, no special circumstance and no department that works differently. Applied without judgement, this rule defeats nearly every gift card scam in existence, which is precisely why the scripts are built to make you doubt it.
The power of the rule is that it requires no assessment of how plausible the caller sounds. Scammers are persuasive; that is the job. But nothing they say can make a tax authority start accepting Apple codes. You do not have to win the argument. You just have to stop.
Why gift cards specifically
Understanding why fraudsters converged on this instrument makes the pattern easier to spot in unfamiliar variations.
Availability. Gift cards are on a rack in every supermarket and pharmacy. A victim can be directed to one within minutes, without a bank visit that might prompt questions.
Value moves with the code alone. No account, no name, no transfer to trace. Reading sixteen digits down a phone line transfers the money completely.
Irreversibility. Once redeemed, the value is spent. There is no chargeback, no recall and no dispute process.
Speed. Codes are drained within minutes of being read out, often automatically. By the time anybody thinks to check, the balance is zero.
The same four properties are what make gift cards useful for legitimate purposes. That is the uncomfortable symmetry at the heart of this category, and it is why bank staff and retail workers in many countries are now trained to intervene when somebody buys several high-value cards at once. If that happens to you, they are not being obstructive.
The six patterns
Almost everything in this space is a variation on six structures. The surface story changes constantly; the mechanics do not.
| Pattern | How it opens | The tell |
|---|---|---|
| Authority impersonation | Tax office, police, immigration; a debt or a warrant | Payment demanded in cards, and you must stay on the line |
| Tech support | Your device is infected; a refund was overpaid | Remote access requested, then cards to “return” money |
| Boss or colleague | An urgent message from a superior, often by text | Buy cards for clients, expense it later, keep it quiet |
| Romance or friendship | Weeks of contact, then a crisis | Cards or crypto only; never a bank transfer |
| Fake marketplace trade | Buying or selling codes peer to peer | Send first, move off-platform, rate near face value |
| Counterfeit checkout | An advertised site selling cards for crypto | You arrived via an ad; the domain is subtly wrong |
Three behavioural signals run through all six. Urgency exists to stop you thinking. Isolation — stay on the phone, do not tell anyone, this is confidential — exists to stop anybody else thinking on your behalf. Secrecy exists because a single sentence said out loud to a family member ends the whole thing.
When any of those three appear, the correct response is to hang up and call back on a number you looked up yourself. A genuine organisation will be entirely comfortable with that.
Counterfeit checkout sites
This one deserves separate treatment because it targets exactly the people reading this site: buyers acting deliberately, not victims of a phone call.
The setup is simple. A site clones the appearance of a well-known crypto gift card platform. It buys search advertising so it sits above the genuine one. You search, click the first result, browse a convincing catalogue, pay in crypto, and receive nothing. There is no chargeback because there is no card, and the company behind the domain does not exist.
Type the domain. Every time.
Never reach a crypto checkout from an advertisement, an email, a social post or a message. Type the address yourself, or use a bookmark you created from a typed address.
You cannot evaluate a site by looking at it. The clone is pixel-accurate, because copying a front end is trivial. The URL is the only thing that cannot be faked.
Two supporting checks. Prices below face value are a reliable indicator: legitimate platforms charge above face because that is where their margin is. And a checkout that pressures you to pay within a very short window, beyond the ordinary quote lock, is manufacturing urgency for the same reason a phone scammer does.
If you already sent a code
Speed is everything, and the window is measured in minutes rather than hours. Work through this in order and do not pause to feel foolish — these scripts are professionally designed and they succeed against careful people constantly.
Call the card issuer’s fraud line immediately
Not the retailer you bought it from: the brand on the card. Have the card number and the receipt ready. If the code has not been redeemed, some issuers can freeze the balance.
Tell the shop where you bought it
Larger retailers have fraud processes for exactly this and can sometimes assist with the issuer. Keep the receipt regardless.
Report it formally
Your national consumer protection body and the police. In the US that is the FTC. Reports drive enforcement even when an individual case cannot be resolved.
Cut contact completely
Block every channel. Anybody who contacts you afterwards offering to recover the money is the same operation running the second stage — recovery fraud targets previous victims specifically.
Worth saying directly
The people who fall for these are not careless. They are people caught at a bad moment by a script refined over thousands of attempts, delivered by somebody doing it full time. Embarrassment is the mechanism that keeps victims quiet, and silence is what lets the same script keep working.
If it happens to you, report it and tell somebody. That is the part that actually helps, and it helps more people than yourself.