FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
Social Engineering Examples·4 sources
In December 2024 (press release dated Dec. 12, 2024; Data Spotlight page timestamped Dec. 11, 2024 UTC), the FTC published "Paying to get paid: gamified job scams drive record losses," an analysis of Consumer Sentinel Network reports quantifying a surge in "task scams," a subtype of job scam in which victims are recruited via unsolicited text messages or WhatsApp messages for supposed remote gig work (marketed with buzzwords like "product boosting" and "app optimization"), then walked through a gamified app that shows a climbing fake-earnings balance before demanding an upfront cryptocurrency deposit to "unlock" further tasks or withdraw the (nonexistent) earnings.
The FTC estimated task-scam reports grew from about 5,000 in all of 2023 to about 20,000 in just the first half of 2024, based on hand-coded random samples of 500 job-scam reports per year (narrative-free reports excluded). Overall job-scam losses reached $223 million in H1 2024 alone, versus $286 million for full-year 2023, $179 million (2022), $131 million (2021), and $90 million (2020); crypto-specific job-scam losses were about $41 million in H1 2024 versus roughly $21 million in all of 2023.
The lure arrives as an unsolicited SMS text or WhatsApp message offering flexible, high-pay-sounding remote "gig" work (e.g., "product boosting," "app optimization," rating products, or liking/reviewing content) with vague details about the employer. Victims who respond are directed to download or log into a task-based app or web platform where they complete simple, repetitive gamified actions.
The platform displays a running balance/dashboard of "earnings" that climbs with each completed task, and often pays out a small real amount early on to establish credibility. Victims are then funneled into group chats populated by fake "experienced" coworkers or coaches who use social pressure and manufactured urgency to encourage bigger commitments.
At a certain point the platform requires the victim to deposit their own money, typically in cryptocurrency, framed as unlocking a "premium" task tier, correcting an "error," or being a prerequisite to withdraw the accumulated (fake) earnings. Once sent, the deposited funds are unrecoverable, and the promised withdrawal never materializes; victims are often prompted to deposit repeatedly, chasing the illusion of an imminent payout ("paying to get paid," per the Spotlight's title).
Lure: an unexpected, low-detail text or WhatsApp message dangling easy, flexible income for tasks like "boosting" an app's ratings or liking/rating products/videos, arriving from a number or contact the recipient never gave to an employer. Tell: any request to pay money, especially in cryptocurrency, to unlock further tasks, fix an "error," or withdraw earnings is definitional to this scam category, since no legitimate employer ever requires an employee to pay to get paid; a dashboard number that only ever goes up but can never actually be withdrawn without another deposit is the core mechanical giveaway the FTC highlights in the Spotlight's title, "Paying to get paid: gamified job scams drive record losses."
The FTC's analysis documents a national-scale consumer-fraud trend rather than a single breach event: job-scam losses reached $223 million in H1 2024 (on pace to roughly match or exceed 2023's full-year $286 million), and task scams specifically grew from an estimated 5.6% of job-scam reports in 2023 (about 5,000 reports) to 38.8% of reports in H1 2024 (about 20,000 reports), a rapid quadrupling in reports that the FTC frames as the fastest-growing subtype it tracks in this category (an inference drawn from the report-share trend rather than a verbatim FTC ranking claim).
The FTC published the Spotlight (Dec. 11-12, 2024), an accompanying press release, and a consumer alert to warn the public, and continues to track the category via its Consumer Sentinel Network Data Book and public Tableau dashboards. No arrests, indictments, or named perpetrator entities were included in these FTC materials; the release is a data/awareness publication, not a law-enforcement action.
This is one of the clearest, most rigorously quantified federal datasets on the smishing-to-task-scam pipeline: it shows the technique's messaging-first delivery (text/WhatsApp, not email), its rapid scaling (a ~4x jump in reports within two quarters), its financial materiality (approaching/matching prior full-year losses in half a year), and its structural reliance on gamification psychology plus cryptocurrency's irreversibility.
Because the FTC data comes from a large, standardized reporting pipeline (Consumer Sentinel Network) rather than a single company's disclosure, it is well-suited as a citable, methodologically transparent baseline for describing this family of scam at scale, useful for illustrating to a general audience how "job offer via text" has become a leading smishing vector distinct from traditional phishing/credential-theft smishing, and why the "pay to get paid" mechanic is the single most reliable tell across the whole category.
FTC's own recommended countermeasures, repeated across the Spotlight and consumer alert: treat unsolicited job offers via text/WhatsApp as a red flag regardless of how professional they look; no legitimate job requires paying money (in crypto or otherwise) to "unlock" tasks, boost an app's rating, or withdraw earnings; fake dashboards showing climbing balances are not real money until it actually clears to a bank account, and by the time a withdrawal is attempted the platform typically demands a further deposit; verify any hiring company independently (search "[company] + scam", check for a real business registration, contact via numbers found independently rather than numbers provided in the message); be skeptical of group chats full of enthusiastic "coworkers" that pressure fast deposits; report to FTC at ReportFraud.ftc.gov and to state AG; crypto payments and payments to unfamiliar apps/wallets are effectively unrecoverable once sent.
For enterprises and platforms, the broader defense implication is that carriers, messaging platforms (WhatsApp/Meta), app stores, and crypto on/off-ramps are the practical intervention points, since the FTC data shows the fraud is high-volume/low-sophistication-per-victim rather than targeted spear-phishing, meaning traditional employee security-awareness training is a poor fit while consumer-facing warnings, platform-level detection of gamified task-scam apps, and crypto-exchange fraud controls have more leverage.
Social Engineering Examples. “FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)”. Accessed 19 September 2026. https://socialengineeringexamples.com/ftc-task-scam-gamified-job-scam-spotlight-2024
Operators typically obtain large volumes of phone numbers and WhatsApp-reachable contacts, likely sourced from data-broker leak compilations, scraped contact databases, or bulk messaging/SIM-farm services, to enable mass unsolicited outreach rather than individually targeted contact; the FTC's data itself reflects mass, not targeted, victim selection.
Consumer phone numbers circulating via data-broker leaks and scraped contact lists is very hard to prevent at the individual level; the more realistic control sits downstream at carrier and platform level, where carrier smishing filters and WhatsApp's own spam-detection and bulk-account-banning systems can throttle unsolicited mass messaging before it reaches consumers.
Operators stand up a task-based web platform or mobile app with a gamified earnings dashboard, consistent with templated task-scam-as-a-service kits or white-label gig/crypto-payment app shells, wired to a backend that can display an arbitrary, manipulable "earnings" balance, plus scripted personas for later group-chat use.
Preempting the stand-up of a fake task app is difficult since these platforms can be spun up quickly and distributed outside major app stores; the practical control is app-store vetting of gig-work apps that request up-front payments, plus fraud-app reporting and takedown processes at app stores, hosting providers, and domain registrars.
Automated bulk messaging infrastructure sends unsolicited texts or WhatsApp messages advertising vague, high-pay, flexible remote gig work using buzzwords like "product boosting" or "app optimization," per the FTC's description of the scam's opening move.
FTC guidance calls for treating any unsolicited job offer arriving by text or WhatsApp as a red flag regardless of how professional it looks, and ignoring, blocking, or reporting the message rather than replying.
Responding victims are walked into the app, complete simple repetitive tasks, watch a climbing fake-earnings dashboard, and often receive a small genuine payout early on, per the FTC, which builds trust and primes the sunk-cost dynamic.
Recognizing that an in-app dashboard balance is not real money until it clears to a bank account, and that an early small genuine payout is a trust-building tactic rather than proof the job is legitimate, per the FTC's consumer alert.
Victims are funneled into a group chat staffed by fake "experienced" coworkers or coaches who apply social pressure and manufactured urgency to encourage larger deposits, as described in the FTC's consumer alert.
Treating enthusiastic group-chat "coworkers" who pressure fast deposits as a manipulation tactic rather than social proof, and independently verifying any hiring company or platform through channels not supplied by the message itself.
The platform requires a cryptocurrency deposit framed as unlocking the next task tier, correcting an "error," or being a prerequisite to withdraw the (fake) accumulated earnings, the core "pay to get paid" mechanic the FTC's Spotlight is named for.
This is the FTC's highest-leverage intervention point: no legitimate employer ever requires paying money to get paid, unlock tasks, or withdraw earnings, so refusing any such request stops the scam at its definitional mechanic.
Deposited cryptocurrency is moved out through wallets/exchanges and is unrecoverable; the FTC notes victims are often prompted to deposit again chasing an ever-promised withdrawal, with the scam repeating this step until the victim stops paying, completing the objective of direct financial theft.
Once cryptocurrency is sent, the transfer is effectively irreversible, so the practical control shifts upstream to crypto-exchange and on/off-ramp fraud detection flagging deposits tied to known task-scam wallet clusters, and to prompt victim reporting to ReportFraud.ftc.gov and the receiving exchange, though actual fund recovery is rarely possible once money has moved out.
Browse by what this case has in common with others in the library.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP…
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
GootLoader operators hijacked Google search rankings for legal-agreement phrases.