Case Library / Phishing / FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC Task-Scam / Gamified Job-Scam Data Spotlight (December 2024)

FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In December 2024 (press release dated Dec. 12, 2024; Data Spotlight page timestamped Dec. 11, 2024 UTC), the FTC published "Paying to get paid: gamified job scams drive record losses," an analysis of Consumer Sentinel Network reports quantifying a surge in "task scams," a subtype of job scam in which victims are recruited via unsolicited text messages or WhatsApp messages for supposed remote gig work (marketed with buzzwords like "product boosting" and "app optimization"), then walked through a gamified app that shows a climbing fake-earnings balance before demanding an upfront cryptocurrency deposit to "unlock" further tasks or withdraw the (nonexistent) earnings. The FTC estimated task-scam reports grew from about 5,000 in all of 2023 to about 20,000 in just the first half of 2024, based on hand-coded random samples of 500 job-scam reports per year (narrative-free reports excluded). Overall job-scam losses reached $223 million in H1 2024 alone, versus $286 million for full-year 2023, $179 million (2022), $131 million (2021), and $90 million (2020); crypto-specific job-scam losses were about $41 million in H1 2024 versus roughly $21 million in all of 2023.

How the Attack Worked

The lure arrives as an unsolicited SMS text or WhatsApp message offering flexible, high-pay-sounding remote "gig" work (e.g., "product boosting," "app optimization," rating products, or liking/reviewing content) with vague details about the employer. Victims who respond are directed to download or log into a task-based app or web platform where they complete simple, repetitive gamified actions. The platform displays a running balance/dashboard of "earnings" that climbs with each completed task, and often pays out a small real amount early on to establish credibility. Victims are then funneled into group chats populated by fake "experienced" coworkers or coaches who use social pressure and manufactured urgency to encourage bigger commitments. At a certain point the platform requires the victim to deposit their own money, typically in cryptocurrency, framed as unlocking a "premium" task tier, correcting an "error," or being a prerequisite to withdraw the accumulated (fake) earnings. Once sent, the deposited funds are unrecoverable, and the promised withdrawal never materializes; victims are often prompted to deposit repeatedly, chasing the illusion of an imminent payout ("paying to get paid," per the Spotlight's title).

The Lure & the Tell

Lure: an unexpected, low-detail text or WhatsApp message dangling easy, flexible income for tasks like "boosting" an app's ratings or liking/rating products/videos, arriving from a number or contact the recipient never gave to an employer. Tell: any request to pay money, especially in cryptocurrency, to unlock further tasks, fix an "error," or withdraw earnings is definitional to this scam category, since no legitimate employer ever requires an employee to pay to get paid; a dashboard number that only ever goes up but can never actually be withdrawn without another deposit is the core mechanical giveaway the FTC highlights in the Spotlight's title, "Paying to get paid: gamified job scams drive record losses."

Outcome

The FTC's analysis documents a national-scale consumer-fraud trend rather than a single breach event: job-scam losses reached $223 million in H1 2024 (on pace to roughly match or exceed 2023's full-year $286 million), and task scams specifically grew from an estimated 5.6% of job-scam reports in 2023 (about 5,000 reports) to 38.8% of reports in H1 2024 (about 20,000 reports), a rapid quadrupling in reports that the FTC frames as the fastest-growing subtype it tracks in this category (an inference drawn from the report-share trend rather than a verbatim FTC ranking claim). The FTC published the Spotlight (Dec. 11-12, 2024), an accompanying press release, and a consumer alert to warn the public, and continues to track the category via its Consumer Sentinel Network Data Book and public Tableau dashboards. No arrests, indictments, or named perpetrator entities were included in these FTC materials; the release is a data/awareness publication, not a law-enforcement action.

Why It Matters

This is one of the clearest, most rigorously quantified federal datasets on the smishing-to-task-scam pipeline: it shows the technique's messaging-first delivery (text/WhatsApp, not email), its rapid scaling (a ~4x jump in reports within two quarters), its financial materiality (approaching/matching prior full-year losses in half a year), and its structural reliance on gamification psychology plus cryptocurrency's irreversibility. Because the FTC data comes from a large, standardized reporting pipeline (Consumer Sentinel Network) rather than a single company's disclosure, it is well-suited as a citable, methodologically transparent baseline for describing this family of scam at scale, useful for illustrating to a general audience how "job offer via text" has become a leading smishing vector distinct from traditional phishing/credential-theft smishing, and why the "pay to get paid" mechanic is the single most reliable tell across the whole category.

Defenses

FTC's own recommended countermeasures, repeated across the Spotlight and consumer alert: treat unsolicited job offers via text/WhatsApp as a red flag regardless of how professional they look; no legitimate job requires paying money (in crypto or otherwise) to "unlock" tasks, boost an app's rating, or withdraw earnings; fake dashboards showing climbing balances are not real money until it actually clears to a bank account, and by the time a withdrawal is attempted the platform typically demands a further deposit; verify any hiring company independently (search "[company] + scam", check for a real business registration, contact via numbers found independently rather than numbers provided in the message); be skeptical of group chats full of enthusiastic "coworkers" that pressure fast deposits; report to FTC at ReportFraud.ftc.gov and to state AG; crypto payments and payments to unfamiliar apps/wallets are effectively unrecoverable once sent. For enterprises and platforms, the broader defense implication is that carriers, messaging platforms (WhatsApp/Meta), app stores, and crypto on/off-ramps are the practical intervention points, since the FTC data shows the fraud is high-volume/low-sophistication-per-victim rather than targeted spear-phishing, meaning traditional employee security-awareness training is a poor fit while consumer-facing warnings, platform-level detection of gamified task-scam apps, and crypto-exchange fraud controls have more leverage.

Sources
  • Paying to get paid: gamified job scams drive record losses. Federal Trade Commission Primary. Primary FTC Data Spotlight; verified live and confirmed as source of the $223M H1 2024 figure (footnote 1: $223M/2024-through-June, $286M/2023, $179M/2022, $131M/2021, $90M/2020), the ~20,000 vs ~5,000 report counts and 38.8%/5.6% task-scam-share figures (footnote 2), and the $41M vs $21M crypto-loss figures
  • New FTC Data Show Skyrocketing Consumer Reports About Game-Like Online Job Scams. Federal Trade Commission Primary. FTC press release accompanying the Spotlight, dated Dec 12, 2024; verified live, content corroborates the report-count quadrupling and loss figures
  • Task scams create the illusion of making money. Federal Trade Commission Primary. FTC consumer alert describing the mechanics (fake dashboards, crypto deposits, group-chat pressure) and giving avoidance guidance; verified live, dated Nov 27, 2024 with a Dec 12, 2024 republish byline
  • Consumer Sentinel Network Data Book 2024. Federal Trade Commission Primary. Underlying 2024 aggregate fraud-report dataset; verified live and confirmed via the linked PDF as the source for the overall median loss ($497) and age-based median-loss figures (20-29 = $417, 70-79 = $1,000, 80+ = $1,650) cited for context
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Bulk contact acquisition: Operators typically obtain large volumes of phone numbers and WhatsApp-reachable contacts, likely sourced from data-broker leak compilations, scraped contact databases, or bulk messaging/SIM-farm services, to enable mass unsolicited outreach rather than individually targeted contact; the FTC's data itself reflects mass, not targeted, victim selection.
Countering Stage 1: Consumer phone numbers circulating via data-broker leaks and scraped contact lists is very hard to prevent at the individual level; the more realistic control sits downstream at carrier and platform level, where carrier smishing filters and WhatsApp's own spam-detection and bulk-account-banning systems can throttle unsolicited mass messaging before it reaches consumers.
2
Fake platform build-out: Operators stand up a task-based web platform or mobile app with a gamified earnings dashboard, consistent with templated task-scam-as-a-service kits or white-label gig/crypto-payment app shells, wired to a backend that can display an arbitrary, manipulable "earnings" balance, plus scripted personas for later group-chat use.
Countering Stage 2: Preempting the stand-up of a fake task app is difficult since these platforms can be spun up quickly and distributed outside major app stores; the practical control is app-store vetting of gig-work apps that request up-front payments, plus fraud-app reporting and takedown processes at app stores, hosting providers, and domain registrars.
3
Mass smishing/WhatsApp lure blast: Automated bulk messaging infrastructure sends unsolicited texts or WhatsApp messages advertising vague, high-pay, flexible remote gig work using buzzwords like "product boosting" or "app optimization," per the FTC's description of the scam's opening move.
Countering Stage 3: FTC guidance calls for treating any unsolicited job offer arriving by text or WhatsApp as a red flag regardless of how professional it looks, and ignoring, blocking, or reporting the message rather than replying.
4
Onboarding and trust-building: Responding victims are walked into the app, complete simple repetitive tasks, watch a climbing fake-earnings dashboard, and often receive a small genuine payout early on, per the FTC, which builds trust and primes the sunk-cost dynamic.
Countering Stage 4: Recognizing that an in-app dashboard balance is not real money until it clears to a bank account, and that an early small genuine payout is a trust-building tactic rather than proof the job is legitimate, per the FTC's consumer alert.
5
Social-proof escalation: Victims are funneled into a group chat staffed by fake "experienced" coworkers or coaches who apply social pressure and manufactured urgency to encourage larger deposits, as described in the FTC's consumer alert.
Countering Stage 5: Treating enthusiastic group-chat "coworkers" who pressure fast deposits as a manipulation tactic rather than social proof, and independently verifying any hiring company or platform through channels not supplied by the message itself.
6
Advance-fee deposit demand: The platform requires a cryptocurrency deposit framed as unlocking the next task tier, correcting an "error," or being a prerequisite to withdraw the (fake) accumulated earnings, the core "pay to get paid" mechanic the FTC's Spotlight is named for.
Countering Stage 6: This is the FTC's highest-leverage intervention point: no legitimate employer ever requires paying money to get paid, unlock tasks, or withdraw earnings, so refusing any such request stops the scam at its definitional mechanic.
7
Cash-out and repeat extraction: Deposited cryptocurrency is moved out through wallets/exchanges and is unrecoverable; the FTC notes victims are often prompted to deposit again chasing an ever-promised withdrawal, with the scam repeating this step until the victim stops paying, completing the objective of direct financial theft.
Countering Stage 7: Once cryptocurrency is sent, the transfer is effectively irreversible, so the practical control shifts upstream to crypto-exchange and on/off-ramp fraud detection flagging deposits tied to known task-scam wallet clusters, and to prompt victim reporting to ReportFraud.ftc.gov and the receiving exchange, though actual fund recovery is rarely possible once money has moved out.
Quick Facts
Victim
U.S. consumers nationwide (aggregate victims who filed reports with the FTC's Consumer Sentinel Network); no individual victims were named in the FTC materials
Location
United States (nationwide; incident data aggregated from consumer reports filed with the FTC's Consumer Sentinel Network, a shared law-enforcement database)
Date
2024-12-12 (FTC press release and Data Spotlight publication); underlying incident data spans H1 2024 (Jan-Jun 2024) with year-over-year comparisons back to 2020
Impact
FTC Consumer Sentinel data show $223 million reported lost to job scams in H1 2024 alone (task scams described as the fastest-growing driver of this category), compared to $286 million for all of 2023, $179 million (2022), $131 million (2021), and $90 million (2020). Cryptocurrency-specific job-scam losses were about $41 million in H1 2024 versus about $21 million in all of 2023, reflecting task scams' reliance on crypto deposits. No task-scam-specific median-loss figure was published; the FTC's broader 2024 Consumer Sentinel Data Book put the overall median fraud loss (all fraud types) at $497, with victims aged 80-and-over showing a much higher median (~$1,650), and victims aged 70-79 showing a median of about $1,000 (versus $417 for ages 20-29)
Status
Confirmed
Case Type
Research / Advisory
Sector
Cross-Sector / Multiple Industries, Government & Public Sector
Threat Actor
Organized Crime
Related

Related Cases

Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)

A mass SMS phishing campaign impersonating dozens of U.S. toll agencies spoofed 'unpaid toll' notices to harvest payment card and…

Incident 2024Read →

Southern California Edison Utility Disconnection Threat Scam (2025)

Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…

Incident 2024Read →

RED (Regional Economic Development Partnership) Wheeling, WV - BEC Solar-Panel Vendor Invoice Fraud

A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…

Incident 2024Read →