vialroom

#scam-watch 2025-07-13

Sunday54 messages14 participantstimes are UTC
Highlights from this day
  • quiet.hours — urgency is the product. the discount is the wrapper 21:52
  • step_one_sian — the tell is that every fee is smaller than the amount you have already paid. it is engineered so walking away always feels more expensive than paying 21:59
  • step_one_sian — it is not fraud if they never claimed to make it. it is a markup on a service and i still think it is grubby when they imply the synthesis is theirs 23:58
  • VialBot — scam-watch list updated: +1 impersonation pattern (cold outbound claiming vendor support, off-domain payment address), 41 domains unchanged 23:58
RW

we do not name private individuals in this channel. that is why some lines here are redacted

🎉14
PS

somebody is relabelling and marking up, is that a scam or just retail

PP

tracking number does not resolve on any carrier, is that a fake

thats the pattern

CO

read the domain character by character. that is the entire defence and it works

PP

update from 18 months ago: the domain from that report is still live and still fake

PP

advance payment for a "reservation", has anyone seen this pattern

this certificate has the same chromatogram as one from two years ago

😂6👀1
TY

for the archive this domain is one letter off the real one, adding it to the watchlist

no escrow here

i have never seen a real supplier ask for payment to a personal account, thats one data point

ok so the room holds no money and runs no escrow. anybody offering to is speaking for themselves

15📈10🧊7

is a bad batch ever grounds for calling something a scam

RW

a reply from a different address than the one you wrote to is worth stopping over

🎉5❤️2
FF

the lookalike domains almost always differ by one doubled letter, a swapped letter, or an added hyphen

FM

someone messaged me claiming to be from a vendor support desk offering 25 percent off if i order today

QH

report it and do not reply. unsolicited sales contact is a straight rule break here regardless of who it claims to be

QH

if it were real it would come from an address you already have, in reply to a conversation you started

MP

no established supplier in the log has ever cold-messaged a member. not once in three years

SO

i got the same shape of message in may. it used the real company name, the real logo and a payment address that was nothing to do with them

BR

impersonating a real support desk is the highest-yield version of this because the victim already trusts the name

BR

you do not check with the person messaging you. you go to the vendor through your own bookmark and ask them

BR

if the discount is real they will confirm it in thirty seconds. if it is not, you have just told a real company that someone is wearing their face

CH

i did exactly that with TFC in march. they replied that they never run outbound discounts and asked me to forward the message

which i did, and they thanked me. that is what a real desk does

MP

and the fake desk will pressure you about timing. today only, last three vials, the price goes up tomorrow

QH

urgency is the product. the discount is the wrapper

🎯165
MP

same family. you pay, then there is a customs fee, then a handling fee, then a release fee, and the goods never existed

SO

the tell is that every fee is smaller than the amount you have already paid. it is engineered so walking away always feels more expensive than paying

BR

sunk cost, weaponised. once you see the shape you cannot unsee it

MP

fake tracking is standard in that playbook. a real-looking number that either never scans or belongs to somebody else's parcel

MP

fake tracking, how it usually reads:
  day 0   label created
  day 0   information received
  day 1   in transit
  ...nothing, forever

real tracking has a first physical scan at an origin facility.
"label created" is not a scan. anyone can create a label.
SO

resellers buying a known manufacturer's vials, peeling the label, putting their own on, and charging double

SO

it is not fraud if they never claimed to make it. it is a markup on a service and i still think it is grubby when they imply the synthesis is theirs

BR

the fraud line is the claim, not the markup. relabelling and reselling is a normal business. saying you made it is not

QH

and a bad batch from a real company is not any kind of scam. we keep having to say that and we will keep saying it

QH

removed at the member's request and correctly. we name domains, never private individuals

VB

scam-watch list updated: +1 impersonation pattern (cold outbound claiming vendor support, off-domain payment address), 41 domains unchanged

QH

you asked before you paid. that is the whole point of the channel