AI3Radar
AI3Radar OfficialAI3Radar update

Identifying fake AI support and refund scams: a signal-recognition method

A method for recognizing fake support agents and refund scams targeting AI subscribers, built around the specific signals legitimate support never exhibits and the recovery steps if information was already exposed.

The threat: scammers advertise 'cheap renewals,' 'internal refunds,' 'account unblocks,' or 'subscription recovery' to AI subscribers. The method is not to memorize every scam script but to recognize the signals that legitimate support never exhibits. This signal-based approach works against new variations without needing to update the list.

The signals legitimate support never exhibits: asking for your password, SMS code, two-step verification code, recovery code, full card number, or remote-control access to your device. Any request to send money to a personal account, buy gift cards, send cryptocurrency, or hand over account credentials is an immediate red flag. Legitimate support starts from the provider's official site, in-product help center, verified domain email, or the store order page—not from search ads, group chats, or unsolicited direct messages.

The verification method: check the domain spelling carefully and open the official site manually in the browser rather than clicking a link from a message. If you are unsure whether a support interaction is real, end it and re-initiate from the provider's official domain. Do not let urgency ('act now or lose your account') override the verification step—that urgency is itself a scam signal.

If information was already exposed, the recovery steps are: change the email and product passwords, enable two-step verification, end all sessions, revoke API keys, inspect bills for unauthorized charges, and contact the payment provider to flag the card. Preserve messages and transaction evidence and report the incident to the appropriate local authority. The limitation: some scams are sophisticated enough to mimic official domains closely, so domain verification must be exact, not approximate.