Craigslist Camera Scam Squeezed for More Money

Hacker Noon Cybersecurity · Low sophistication
Last updated August 5, 2026

A buyer hunting for a bargain Sony camera on Craigslist was scammed during a “ship the item” transaction. The scammer kept everything in text messages, pushed payment to multiple random Hotmail addresses, and used manipulated shipping screenshots to ask for more money. The victim ultimately filed police and FTC reports and documented warning signs others can use to avoid similar losses.

Key findings

  • The scam happened during a Craigslist purchase once shipping was introduced: “as soon as you consider shipping the item, the guardrails are gone, and fraud quickly enters the picture.”
  • All communication stayed in text messages, avoiding voice verification and making it easier to fake identity and location.
  • The scammer used manipulated evidence: “The scammer sent me screenshots of shipping costs… It turns out they were digitally manipulated.”
  • Payment was routed to multiple randomized Hotmail addresses, a common sign of fraud and money-mule style collection.
  • The victim’s payment provider flagged the transaction: “My initial attempt to pay failed and resulted in my account being locked… warned of potential fraud.”
  • After payment, the scammer attempted to extract additional funds: “started trying to squeeze me for more cash.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/AP (expense and reimbursement approvers), Procurement/purchasing, Executives (high-value purchase approvers).
  • Affected industries: Online marketplaces and classifieds, Consumers/individual buyers, Retail/e-commerce.
  • Attack channels: smishing.
  • Impersonated: Craigslist seller (individual).

Awareness takeaways

  • For any marketplace purchase involving shipping, verify the seller with a real-time voice call (or don’t proceed).
  • Treat screenshot-based ‘proof’ (shipping quotes, invoices, payment confirmations) as untrusted, verify independently.
  • Random email addresses and frequent changes to payment details are strong fraud indicators, stop and escalate.
  • If your bank/payment provider flags a transaction, take it seriously and pause, don’t push through because you want the deal.

Red flags to watch for

  • Seller refuses/avoids a real phone call or voice verification
  • Payment requested to a randomized email address that doesn’t match a real person/business
  • Pressure to move quickly because it’s a “deal”
  • Screenshots used as “proof” instead of verifiable carrier links/quotes
  • Multiple payment addresses used in the same transaction
  • Claims that calls “aren’t going through” to avoid verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You find a Sony camera on Craigslist, crazy good price, seller says, “I’ll ship it.” That’s where this scam starts. They keep everything in text: “I only communicated with this person via text.” To pay, they send a random Hotmail like gosewischgeel384@hotmail.com, then new ones for “shipping” with fake screenshot proofs. The payment provider even locks the account, warns of potential fraud, but the buyer pushes through… and then the seller starts squeezing for more cash with “updated shipping” screenshots. Here’s the move: if a marketplace deal involves shipping and random emails or screenshots, stop. Don’t send a cent until you’ve spoken to the seller on a real-time voice call.

Categories

Similar attacks

Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Real-Time ‘JWR’ Smishing Steals Cards and OTPs

Real-Time ‘JWR’ Smishing Steals Cards and OTPs

Cisco Talos reported a real-world SMS phishing campaign using a framework called “JWR” that impersonates toll agencies and postal/courier services to lure victims to fake payment and login pages. Unlike basic phishing pages, the operator can actively steer the victim through fake checkout/login…

August 13, 2026