Case Library / Pretexting & Impersonation / Southern California Edison Utility Disconnection Threat Scam (2025)

Southern California Edison Utility Disconnection Threat Scam (2025)

Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and in-person threats to extract $131,464 from customers in 2025, a documented 72% drop from 2024 that SCE publicly credited to customer awareness and its recurring scam-education campaigns.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Southern California Edison publicly disclosed, during National Consumer Protection Week (March 1-7, 2026), that scammers impersonating the utility defrauded customers of $131,464 in 2025 (reported in broadcast coverage as "more than $130,000") across 1,750 fraud complaints (reported as "1,700+"), out of more than $806,000 that scammers attempted to demand. This represented a roughly 72% drop in actual losses compared to 2024. SCE released a recorded phone call as an example, in which the recording captures the victim repeating the scammer's threat back to him: "You're telling me I have 30 minutes to come up with this $300, which is down from $450, or you're going to turn it off and then tomorrow I have to pay all of these connection fees," illustrating the imminent-shutoff pressure tactic and a fake "discount" used to keep the victim negotiating instead of hanging up to verify. SCE spokesperson Gabriela Ornelas gave on-camera and quoted statements to KBAK/KBFX (Bakersfield) and other outlets describing the scam pattern: scammers call, text, or occasionally show up in person, falsely claim an overdue bill, and threaten to disconnect power or remove the electric meter within minutes unless paid immediately, typically demanding prepaid cards, gift cards, third-party payment apps, or cryptocurrency.

How the Attack Worked

Scammers call SCE customers (sometimes spoofing SCE's caller ID or using a familiar-looking area code) or, in some cases, show up in person at a home or business, and falsely claim the customer has an overdue electric bill. They manufacture urgency by threatening to disconnect power, or to physically remove the electric meter, within a short window. SCE's shared recording captures a victim repeating the scammer's threat back to him, describing a "30 minutes" ultimatum to pay. The demanded amount is often manipulated in real time to seem like a concession (e.g., dropped from $450 to $300) to make the victim feel they're getting a deal and to keep them engaged rather than hanging up to verify. Scammers instruct victims to pay through channels that are irreversible and hard to trace: prepaid store barcodes redeemable at Walmart, 7-Eleven, CVS or Walgreens, prepaid cash cards, third-party payment apps (Zelle, Cash App, Venmo), or cryptocurrency, none of which are SCE's actual billing channels. Some variants coach the victim to tell the retail clerk the payment is for something else, to avoid tipping off store staff who might recognize the scam. If a victim pays, scammers frequently call back demanding an additional "reconnection" or "remaining balance" payment, and may bombard the victim's phone with repeated calls to prevent them from pausing to verify. In-person versions have scammers or door-knockers claim to be SCE technicians responding to a "damaged meter," using SCE's real practice of unannounced meter-repair visits as cover, then attempt to solicit payment or access.

The Lure & the Tell

Lure: a call or text using spoofed SCE caller ID, or an in-person visit, asserting the customer has an unpaid balance and framing disconnection as imminent (30-60 minutes) unless payment is made right now, with a "discount" dangled if paid immediately to simulate a fair negotiation and prevent hang-up-and-verify behavior. Tells that SCE and consumer-protection guidance flag: SCE never calls demanding immediate phone payment and has no "disconnection department"; SCE always sends written notice before any non-payment disconnection; legitimate SCE never asks for payment via prepaid cards, gift cards, payment apps, or cryptocurrency; legitimate calls only occur 7 a.m.-9 p.m.; and any in-person SCE representative should be asked for ID before being let onto the property.

Outcome

SCE reported the financial outcome as a public-awareness success story rather than an unresolved breach: total dollars actually lost to scammers fell from a considerably higher 2024 figure to $131,464 in 2025 (a >70% year-over-year decline), even though total fraud complaints (1,750) and total dollars demanded (over $806,000) remained substantial, indicating most attempted scams in 2025 were unsuccessful or caught before payment. There is no indication of law-enforcement arrests or prosecutions tied to this specific 2025 wave in the coverage reviewed; SCE's public messaging focused on prevention, reporting channels (sce.com/scamalert, 1-800-655-4555), and continued vigilance, explicitly stating "even one dollar handed to scammers is one too many."

Why It Matters

This case is a clean, quantified illustration of classic urgency/authority pretexting that persists at scale against millions of ordinary consumers year after year, not a single breach but a chronic fraud channel utilities must continuously counter with public education. It demonstrates: (1) how attackers manufacture time pressure and fake "concessions" (price drops) to short-circuit victims' instinct to verify independently; (2) why untraceable payment rails (prepaid cards, apps, crypto) are the common enabling thread across nearly all such scams, giving defenders a clear, teachable red flag; (3) that sustained public-awareness campaigns paired with clear "we will never..." policy statements can measurably reduce realized losses (roughly 70%+ drop) even when attempted fraud (complaints, dollars demanded) stays roughly constant, offering an evidence-based case for the effectiveness of proactive consumer education over purely reactive fraud response.

Defenses

SCE's stated countermeasures and consumer-education points: (1) SCE has no "disconnection department" and never calls to demand immediate payment under threat of shutoff; (2) SCE always sends written notice before any disconnection for non-payment and never disconnects without proper notification; (3) SCE does not accept prepaid cash cards (MoneyPak, Green Dot), payment apps (Zelle, Cash App, Venmo), or cryptocurrency (Bitcoin); it accepts payment only through sce.com/billpay and other verified channels; (4) SCE only calls during business hours (7 a.m.-9 p.m.) except for customer-requested outage updates; (5) customers told to hang up and call the verified number printed on their bill or 1-800-655-4555 rather than any number given by the caller; (6) customers told to demand ID from anyone claiming to be an SCE representative who shows up in person before allowing entry, even though legitimate SCE techs may arrive unannounced to service a damaged meter (at no cost); (7) SCE operates a dedicated reporting channel at sce.com/scamalert and encourages parallel reports to local law enforcement; (8) SCE publishes recurring public-awareness campaigns (Utility Scam Awareness Day each November, National Consumer Protection Week each March) with real victim-call recordings to build pattern recognition. SCE credits these efforts, plus "savvy customers who avoided becoming victims," for the greater-than-70% year-over-year drop in dollars lost.

Sources
  • Southern California Edison warns customers of scam calls demanding immediate payment. KBAK/KBFX BakersfieldNow (Eyewitness News) Secondary. Local news report including the recorded audio excerpt (victim repeating the scammer's threat back) and direct quotes from SCE spokesperson Gabriela Ornelas. Verified by direct fetch: content matches exactly, including the $300/$450/30-minute quote and the >70% drop figure.
  • SCE Issues Fraud Warning, Guidance To Protect Ratepayers. Patch (Temecula, CA) Secondary. Quotes SCE's own public statement verbatim with exact figures: 1,750 complaints, $806,000+ demanded, $131,464 collected, ~72% drop from 2024. Verified by direct fetch: all figures match exactly.
  • Southern California Edison warns customers about scams. Fontana Herald News Secondary. Corroborates exact 2025 figures (1,750 complaints, $131,464 paid) tied to National Consumer Protection Week SCE messaging. Verified by direct fetch.
  • Stay Safe from Scams. Southern California Edison (SCE / Edison International) Primary. SCE's own first-party scam-awareness page detailing urgency-scam, spoofing, in-person, and barcode-scam tactics and official countermeasures. Verified by direct fetch: all countermeasures listed in the case (no disconnection department, no prepaid/app/crypto payments, 7am-9pm calling window, ID-check guidance) match exactly.
  • SCE On National Consumer Protection Week. Sierra Wave (Eastern Sierra News) Secondary. Additional regional pickup of SCE's National Consumer Protection Week statement with matching 2025 figures. Verified by direct fetch.
  • Utility Bill Phone Scammers Hit Customers Hard in 2021. Energized by Edison (SCE / Edison International) Primary. Newly added source. SCE's own first-party recap confirming the historical baseline figures cited in this case: more than $667,000 lost to phone scams in 2021, a 57% jump from more than $426,000 in 2020. Verified via search result content matching exactly.
  • How to Avoid Becoming a Scammer's Next Victim. Energized by Edison (SCE / Edison International) Primary. Newly added source. SCE's own first-party recap confirming more than 2,700 scam reports and $229,000 in losses from January through October 2023. Verified via search result content matching exactly; this pinned down the previously vague 'earlier year' reference to 2023.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target sourcing: Scammers likely work from bulk phone-number and area-code lists covering SCE's roughly 15-million-person service territory rather than individually profiled victims, consistent with the campaign's mass-targeting pattern and SCE's own description of realtor-listing and new-service-signup scam variants that piggyback on publicly visible customer touchpoints.
Countering Stage 1: Bulk exposure of customer phone numbers and area codes is effectively unavoidable at utility scale; the realistic control is not preventing this sourcing but hardening the verification behavior it gets used against downstream, at Stage 3.
2
Pretext infrastructure setup: Scammers configure commercial or consumer VoIP/caller-ID spoofing tools to display SCE's name or a locally familiar area code, per SCE's own description of how these "spoofing" calls are made to look legitimate before any contact occurs.
Countering Stage 2: Consumer-side caller ID spoofing is very difficult to block directly; carrier-level call-authentication standards reduce some spoofed-call delivery, but SCE's practical guidance treats caller ID as unverifiable and tells customers never to rely on it as proof of identity.
3
Initial contact: The scammer places a call, sends a text with a prepaid-store barcode, or shows up in person, falsely claiming the customer has an overdue bill and asserting authority as an SCE representative or technician.
Countering Stage 3: SCE's published, repeated messaging that it has no "disconnection department" and never demands phone payment under shutoff threat trains customers to treat any such contact as inherently suspect regardless of what the caller ID shows; in-person visits are countered by SCE's instruction to always demand ID before allowing entry.
4
Urgency and pressure escalation: The scammer manufactures a short countdown (commonly 30 to 60 minutes) to imminent disconnection or meter removal, and dangles a fake "discount" (e.g., $450 down to $300) in real time to keep the victim negotiating rather than hanging up to verify independently.
Countering Stage 4: SCE publishes real recorded examples of the urgency-and-fake-discount pattern specifically so customers recognize it as a scam tactic; the taught response is to hang up and call the verified number on the bill rather than continue negotiating on the scammer's terms.
5
Payment channel steering: The scammer directs the victim to pay through irreversible, hard-to-trace channels including prepaid store barcodes, prepaid cash cards, third-party payment apps, or cryptocurrency, sometimes coaching the victim to misrepresent the payment's purpose to the retail clerk to avoid detection.
Countering Stage 5: SCE's clear published list of payment methods it never accepts (prepaid cards, payment apps, cryptocurrency) gives customers a bright-line red flag before paying; retail-clerk awareness of prepaid-card scam patterns is a secondary control point, though scammers explicitly coach victims to lie to clerks to defeat it.
6
Repeat extraction and harassment: After an initial payment, the scammer often calls back demanding an additional "reconnection" or "remaining balance" fee, and may place repeated follow-up calls to keep the victim off-balance and prevent them from pausing to verify.
Countering Stage 6: Reporting the first fraudulent contact to SCE (sce.com/scamalert) and local law enforcement, and then refusing to engage with or pay any follow-up call, stops the repeat-extraction loop before additional losses occur.
7
Cash-out and objective completion: The scammer converts the prepaid-card, app-transfer, or cryptocurrency proceeds into usable funds through the same irreversible, low-traceability rails used to collect payment, completing the theft with little realistic prospect of clawback.
Countering Stage 7: Once funds move through prepaid cards, payment apps, or cryptocurrency, recovery is generally not realistic for the victim or the utility; the effective countermeasure is entirely upstream prevention at Stages 3 through 5, with law-enforcement and payment-processor reporting serving mainly to disrupt scammer cash-out infrastructure at the network level rather than to recover this victim's funds.
Quick Facts
Victim
Southern California Edison (SCE) customers across its ~15 million-person service territory (Central, Coastal, and Southern California); disproportionately elderly customers, non-native English speakers, and small-business owners (restaurants, salons, auto shops, dental offices, churches, retail) per SCE's own risk profiling
Location
Central, Coastal, and Southern California (SCE service territory of approximately 15 million people); local news coverage centered on Bakersfield/Kern County via KBAK/KBFX, with additional regional coverage in Temecula, Fontana, and the Eastern Sierra
Date
2024-2025 (statistics covering calendar year 2025 vs. 2024 baseline); publicly disclosed by SCE during National Consumer Protection Week, March 1-7, 2026, with local news coverage March 3-6, 2026
Impact
SCE reported that in 2025, customers filed 1,750 fraud complaints (rounded to "1,700+" in some coverage) involving over $806,000 in total funds demanded by scammers, of which fraudsters actually collected $131,464 (rounded to "$130,000+" in broadcast coverage), a decline of nearly 72% (reported as "more than 70%") compared to 2024 losses. This continues a multi-year pattern SCE has publicly tracked: prior disclosures cited more than $667,000 lost in 2021 (a 57% jump from more than $426,000 in 2020, per SCE's own energized.edison.com recap) and $229,000 lost from January through October of 2023 across more than 2,700 reports (also per SCE's own recap), indicating losses have fluctuated but trended down sharply into 2025 even as complaint volume (1,750) stayed comparable to prior years.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Critical Infrastructure, Energy & Utilities
Related

Related Cases

Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025)

A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America, with a…

Incident 2024Read →

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…

Incident 2024Read →

Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance

Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology…

Incident 2024Read →