FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages, showing reports quadrupled from about 5,000 in 2023 to an estimated 20,000 in just the first half of 2024, with total job-scam losses hitting $223 million in H1 2024 alone.
Reviewed by the Social Engineering Examples team.
In December 2024 (press release dated Dec. 12, 2024; Data Spotlight page timestamped Dec. 11, 2024 UTC), the FTC published "Paying to get paid: gamified job scams drive record losses," an analysis of Consumer Sentinel Network reports quantifying a surge in "task scams," a subtype of job scam in which victims are recruited via unsolicited text messages or WhatsApp messages for supposed remote gig work (marketed with buzzwords like "product boosting" and "app optimization"), then walked through a gamified app that shows a climbing fake-earnings balance before demanding an upfront cryptocurrency deposit to "unlock" further tasks or withdraw the (nonexistent) earnings. The FTC estimated task-scam reports grew from about 5,000 in all of 2023 to about 20,000 in just the first half of 2024, based on hand-coded random samples of 500 job-scam reports per year (narrative-free reports excluded). Overall job-scam losses reached $223 million in H1 2024 alone, versus $286 million for full-year 2023, $179 million (2022), $131 million (2021), and $90 million (2020); crypto-specific job-scam losses were about $41 million in H1 2024 versus roughly $21 million in all of 2023.
The lure arrives as an unsolicited SMS text or WhatsApp message offering flexible, high-pay-sounding remote "gig" work (e.g., "product boosting," "app optimization," rating products, or liking/reviewing content) with vague details about the employer. Victims who respond are directed to download or log into a task-based app or web platform where they complete simple, repetitive gamified actions. The platform displays a running balance/dashboard of "earnings" that climbs with each completed task, and often pays out a small real amount early on to establish credibility. Victims are then funneled into group chats populated by fake "experienced" coworkers or coaches who use social pressure and manufactured urgency to encourage bigger commitments. At a certain point the platform requires the victim to deposit their own money, typically in cryptocurrency, framed as unlocking a "premium" task tier, correcting an "error," or being a prerequisite to withdraw the accumulated (fake) earnings. Once sent, the deposited funds are unrecoverable, and the promised withdrawal never materializes; victims are often prompted to deposit repeatedly, chasing the illusion of an imminent payout ("paying to get paid," per the Spotlight's title).
Lure: an unexpected, low-detail text or WhatsApp message dangling easy, flexible income for tasks like "boosting" an app's ratings or liking/rating products/videos, arriving from a number or contact the recipient never gave to an employer. Tell: any request to pay money, especially in cryptocurrency, to unlock further tasks, fix an "error," or withdraw earnings is definitional to this scam category, since no legitimate employer ever requires an employee to pay to get paid; a dashboard number that only ever goes up but can never actually be withdrawn without another deposit is the core mechanical giveaway the FTC highlights in the Spotlight's title, "Paying to get paid: gamified job scams drive record losses."
The FTC's analysis documents a national-scale consumer-fraud trend rather than a single breach event: job-scam losses reached $223 million in H1 2024 (on pace to roughly match or exceed 2023's full-year $286 million), and task scams specifically grew from an estimated 5.6% of job-scam reports in 2023 (about 5,000 reports) to 38.8% of reports in H1 2024 (about 20,000 reports), a rapid quadrupling in reports that the FTC frames as the fastest-growing subtype it tracks in this category (an inference drawn from the report-share trend rather than a verbatim FTC ranking claim). The FTC published the Spotlight (Dec. 11-12, 2024), an accompanying press release, and a consumer alert to warn the public, and continues to track the category via its Consumer Sentinel Network Data Book and public Tableau dashboards. No arrests, indictments, or named perpetrator entities were included in these FTC materials; the release is a data/awareness publication, not a law-enforcement action.
This is one of the clearest, most rigorously quantified federal datasets on the smishing-to-task-scam pipeline: it shows the technique's messaging-first delivery (text/WhatsApp, not email), its rapid scaling (a ~4x jump in reports within two quarters), its financial materiality (approaching/matching prior full-year losses in half a year), and its structural reliance on gamification psychology plus cryptocurrency's irreversibility. Because the FTC data comes from a large, standardized reporting pipeline (Consumer Sentinel Network) rather than a single company's disclosure, it is well-suited as a citable, methodologically transparent baseline for describing this family of scam at scale, useful for illustrating to a general audience how "job offer via text" has become a leading smishing vector distinct from traditional phishing/credential-theft smishing, and why the "pay to get paid" mechanic is the single most reliable tell across the whole category.
FTC's own recommended countermeasures, repeated across the Spotlight and consumer alert: treat unsolicited job offers via text/WhatsApp as a red flag regardless of how professional they look; no legitimate job requires paying money (in crypto or otherwise) to "unlock" tasks, boost an app's rating, or withdraw earnings; fake dashboards showing climbing balances are not real money until it actually clears to a bank account, and by the time a withdrawal is attempted the platform typically demands a further deposit; verify any hiring company independently (search "[company] + scam", check for a real business registration, contact via numbers found independently rather than numbers provided in the message); be skeptical of group chats full of enthusiastic "coworkers" that pressure fast deposits; report to FTC at ReportFraud.ftc.gov and to state AG; crypto payments and payments to unfamiliar apps/wallets are effectively unrecoverable once sent. For enterprises and platforms, the broader defense implication is that carriers, messaging platforms (WhatsApp/Meta), app stores, and crypto on/off-ramps are the practical intervention points, since the FTC data shows the fraud is high-volume/low-sophistication-per-victim rather than targeted spear-phishing, meaning traditional employee security-awareness training is a poor fit while consumer-facing warnings, platform-level detection of gamified task-scam apps, and crypto-exchange fraud controls have more leverage.
A mass SMS phishing campaign impersonating dozens of U.S. toll agencies spoofed 'unpaid toll' notices to harvest payment card and…
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling, WV economic development nonprofit into…