Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and in-person threats.
Social Engineering Examples·7 sources
Southern California Edison publicly disclosed, during National Consumer Protection Week (March 1-7, 2026), that scammers impersonating the utility defrauded customers of $131,464 in 2025 (reported in broadcast coverage as "more than $130,000") across 1,750 fraud complaints (reported as "1,700+"), out of more than $806,000 that scammers attempted to demand.
This represented a roughly 72% drop in actual losses compared to 2024. SCE released a recorded phone call as an example, in which the recording captures the victim repeating the scammer's threat back to him: "You're telling me I have 30 minutes to come up with this $300, which is down from $450, or you're going to turn it off and then tomorrow I have to pay all of these connection fees," illustrating the imminent-shutoff pressure tactic and a fake "discount" used to keep the victim negotiating instead of hanging up to verify.
SCE spokesperson Gabriela Ornelas gave on-camera and quoted statements to KBAK/KBFX (Bakersfield) and other outlets describing the scam pattern: scammers call, text, or occasionally show up in person, falsely claim an overdue bill, and threaten to disconnect power or remove the electric meter within minutes unless paid immediately, typically demanding prepaid cards, gift cards, third-party payment apps, or cryptocurrency.
Scammers call SCE customers (sometimes spoofing SCE's caller ID or using a familiar-looking area code) or, in some cases, show up in person at a home or business, and falsely claim the customer has an overdue electric bill. They manufacture urgency by threatening to disconnect power, or to physically remove the electric meter, within a short window.
SCE's shared recording captures a victim repeating the scammer's threat back to him, describing a "30 minutes" ultimatum to pay. The demanded amount is often manipulated in real time to seem like a concession (e.g., dropped from $450 to $300) to make the victim feel they're getting a deal and to keep them engaged rather than hanging up to verify. Scammers instruct victims to pay through channels that are irreversible and hard to trace: prepaid store barcodes redeemable at Walmart, 7-Eleven, CVS or Walgreens, prepaid cash cards, third-party payment apps (Zelle, Cash App, Venmo), or cryptocurrency, none of which are SCE's actual billing channels.
Some variants coach the victim to tell the retail clerk the payment is for something else, to avoid tipping off store staff who might recognize the scam. If a victim pays, scammers frequently call back demanding an additional "reconnection" or "remaining balance" payment, and may bombard the victim's phone with repeated calls to prevent them from pausing to verify.
In-person versions have scammers or door-knockers claim to be SCE technicians responding to a "damaged meter," using SCE's real practice of unannounced meter-repair visits as cover, then attempt to solicit payment or access.
Lure: a call or text using spoofed SCE caller ID, or an in-person visit, asserting the customer has an unpaid balance and framing disconnection as imminent (30-60 minutes) unless payment is made right now, with a "discount" dangled if paid immediately to simulate a fair negotiation and prevent hang-up-and-verify behavior. Tells that SCE and consumer-protection guidance flag: SCE never calls demanding immediate phone payment and has no "disconnection department"; SCE always sends written notice before any non-payment disconnection; legitimate SCE never asks for payment via prepaid cards, gift cards, payment apps, or cryptocurrency; legitimate calls only occur 7 a.m.-9 p.m.; and any in-person SCE representative should be asked for ID before being let onto the property.
SCE reported the financial outcome as a public-awareness success story rather than an unresolved breach: total dollars actually lost to scammers fell from a considerably higher 2024 figure to $131,464 in 2025 (a >70% year-over-year decline), even though total fraud complaints (1,750) and total dollars demanded (over $806,000) remained substantial, indicating most attempted scams in 2025 were unsuccessful or caught before payment.
There is no indication of law-enforcement arrests or prosecutions tied to this specific 2025 wave in the coverage reviewed; SCE's public messaging focused on prevention, reporting channels (sce.com/scamalert, 1-800-655-4555), and continued vigilance, explicitly stating "even one dollar handed to scammers is one too many."
This case is a clean, quantified illustration of classic urgency/authority pretexting that persists at scale against millions of ordinary consumers year after year, not a single breach but a chronic fraud channel utilities must continuously counter with public education. It demonstrates: (1) how attackers manufacture time pressure and fake "concessions" (price drops) to short-circuit victims' instinct to verify independently; (2) why untraceable payment rails (prepaid cards, apps, crypto) are the common enabling thread across nearly all such scams, giving defenders a clear, teachable red flag; (3) that sustained public-awareness campaigns paired with clear "we will never..." policy statements can measurably reduce realized losses (roughly 70%+ drop) even when attempted fraud (complaints, dollars demanded) stays roughly constant, offering an evidence-based case for the effectiveness of proactive consumer education over purely reactive fraud response.
SCE's stated countermeasures and consumer-education points: (1) SCE has no "disconnection department" and never calls to demand immediate payment under threat of shutoff; (2) SCE always sends written notice before any disconnection for non-payment and never disconnects without proper notification; (3) SCE does not accept prepaid cash cards (MoneyPak, Green Dot), payment apps (Zelle, Cash App, Venmo), or cryptocurrency (Bitcoin); it accepts payment only through sce.com/billpay and other verified channels; (4) SCE only calls during business hours (7 a.m.-9 p.m.) except for customer-requested outage updates; (5) customers told to hang up and call the verified number printed on their bill or 1-800-655-4555 rather than any number given by the caller; (6) customers told to demand ID from anyone claiming to be an SCE representative who shows up in person before allowing entry, even though legitimate SCE techs may arrive unannounced to service a damaged meter (at no cost); (7) SCE operates a dedicated reporting channel at sce.com/scamalert and encourages parallel reports to local law enforcement; (8) SCE publishes recurring public-awareness campaigns (Utility Scam Awareness Day each November, National Consumer Protection Week each March) with real victim-call recordings to build pattern recognition.
SCE credits these efforts, plus "savvy customers who avoided becoming victims," for the greater-than-70% year-over-year drop in dollars lost.
Social Engineering Examples. “Southern California Edison Utility Disconnection Threat Scam (2025)”. Accessed 20 September 2026. https://socialengineeringexamples.com/southern-california-edison-utility-disconnection-scam-2025
Scammers likely work from bulk phone-number and area-code lists covering SCE's roughly 15-million-person service territory rather than individually profiled victims, consistent with the campaign's mass-targeting pattern and SCE's own description of realtor-listing and new-service-signup scam variants that piggyback on publicly visible customer touchpoints.
Bulk exposure of customer phone numbers and area codes is effectively unavoidable at utility scale; the realistic control is not preventing this sourcing but hardening the verification behavior it gets used against downstream, at Stage 3.
Scammers configure commercial or consumer VoIP/caller-ID spoofing tools to display SCE's name or a locally familiar area code, per SCE's own description of how these "spoofing" calls are made to look legitimate before any contact occurs.
Consumer-side caller ID spoofing is very difficult to block directly; carrier-level call-authentication standards reduce some spoofed-call delivery, but SCE's practical guidance treats caller ID as unverifiable and tells customers never to rely on it as proof of identity.
The scammer places a call, sends a text with a prepaid-store barcode, or shows up in person, falsely claiming the customer has an overdue bill and asserting authority as an SCE representative or technician.
SCE's published, repeated messaging that it has no "disconnection department" and never demands phone payment under shutoff threat trains customers to treat any such contact as inherently suspect regardless of what the caller ID shows; in-person visits are countered by SCE's instruction to always demand ID before allowing entry.
The scammer manufactures a short countdown (commonly 30 to 60 minutes) to imminent disconnection or meter removal, and dangles a fake "discount" (e.g., $450 down to $300) in real time to keep the victim negotiating rather than hanging up to verify independently.
SCE publishes real recorded examples of the urgency-and-fake-discount pattern specifically so customers recognize it as a scam tactic; the taught response is to hang up and call the verified number on the bill rather than continue negotiating on the scammer's terms.
The scammer directs the victim to pay through irreversible, hard-to-trace channels including prepaid store barcodes, prepaid cash cards, third-party payment apps, or cryptocurrency, sometimes coaching the victim to misrepresent the payment's purpose to the retail clerk to avoid detection.
SCE's clear published list of payment methods it never accepts (prepaid cards, payment apps, cryptocurrency) gives customers a bright-line red flag before paying; retail-clerk awareness of prepaid-card scam patterns is a secondary control point, though scammers explicitly coach victims to lie to clerks to defeat it.
After an initial payment, the scammer often calls back demanding an additional "reconnection" or "remaining balance" fee, and may place repeated follow-up calls to keep the victim off-balance and prevent them from pausing to verify.
Reporting the first fraudulent contact to SCE (sce.com/scamalert) and local law enforcement, and then refusing to engage with or pay any follow-up call, stops the repeat-extraction loop before additional losses occur.
The scammer converts the prepaid-card, app-transfer, or cryptocurrency proceeds into usable funds through the same irreversible, low-traceability rails used to collect payment, completing the theft with little realistic prospect of clawback.
Once funds move through prepaid cards, payment apps, or cryptocurrency, recovery is generally not realistic for the victim or the utility; the effective countermeasure is entirely upstream prevention at Stages 3 through 5, with law-enforcement and payment-processor reporting serving mainly to disrupt scammer cash-out infrastructure at the network level rather than to recover this victim's funds.
Browse by what this case has in common with others in the library.
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
During an internal OpenAI benchmark run with safety refusals deliberately lowered.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…