{"id":10157,"date":"2026-01-27T04:03:33","date_gmt":"2026-01-27T04:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/27\/32650\/"},"modified":"2026-01-27T04:03:33","modified_gmt":"2026-01-27T04:03:33","slug":"32650","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/27\/32650\/","title":{"rendered":"Initial Stages of Romance Scams [Guest Diary], (Tue, Jan 27th)"},"content":{"rendered":"\n<div>Initial Stages of Romance Scams [Guest Diary], (Tue, Jan 27th)<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>[This is a Guest Diary by Fares\u00a0Azhari, an ISC intern as part of the SANS.edu\u00a0<a href=\"https:\/\/www.sans.edu\/cyber-security-programs\/bachelors-degree\/\">BACS<\/a>\u00a0program]<\/p>\n<p>Romance scams are a form of social-engineering fraud that causes both financial and emotional harm. They vary in technique and platform, but most follow the same high-level roadmap: initial contact, relationship building, financial exploitation. In this blog post I focus on the initial stages of the romance scam ? how scammers make contact, build rapport, and prime victims for later financial requests.<\/p>\n<p>I was contacted by two separate romance scammers on WhatsApp. I acted like a victim falling for their scam and spent around two weeks texting each one. This allowed me to observe the first few phases, which we discuss below. I was not able to reach the monetization phase, as that often takes months and I could not maintain the daily time investment needed to convince the scammers I was fully falling for it.<\/p>\n<p>The scammers claimed to be called ?Chloe? and ?Verna?. We use these names throughout to differentiate their messages. Snippets from each are included to illustrate the phases, along with my precursor or response messages.<\/p>\n<h2>Phase 1: Initial contact<\/h2>\n<p>Both conversations began the same way ? the sender claimed they had messaged the wrong person.<\/p>\n<p><strong>Verna:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_1.png?ssl=1\" style=\"width: 624px; height: 53px;\"><\/p>\n<p><strong>Chloe:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_2.png?ssl=1\" style=\"width: 601px; height: 75px;\"><\/p>\n<p>That ?wrong-number? ruse is low effort and high reward. It gives the out-of-the-blue message a plausible reason, invites a short helpful reply, and lowers suspicion. Two small but useful fingerprints appear immediately: random capitalization and awkward grammar. These recur later and help identify when different operators are involved.<\/p>\n<h2>Phase 2: The immediate hook<\/h2>\n<p>If you reply politely, the scammer usually responds with an over-the-top compliment:<\/p>\n<p><strong>Verna:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_3.png?ssl=1\" style=\"width: 757px; height: 78px;\"><\/p>\n<p><strong>Chloe:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_4.png?ssl=1\" style=\"width: 624px; height: 55px;\"><\/p>\n<p>These short flattering lines serve as rapid rapport builders ? they feel personal and disarming.<\/p>\n<h2>Phase 3: Establishing identity and credibility<\/h2>\n<p>After a few messages, both claimed to be foreigners working in the UK:<\/p>\n<p><strong>Verna:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_5.png?ssl=1\" style=\"width: 434px; height: 45px;\"><\/p>\n<p><em>When asked what she does for a living:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_6.png?ssl=1\" style=\"width: 624px; height: 33px;\"><\/p>\n<p><em>When asked to explain her job:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_7.png?ssl=1\" style=\"width: 624px; height: 54px;\"><\/p>\n<p><strong>Chloe:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_8.png?ssl=1\" style=\"width: 624px; height: 41px;\"><\/p>\n<p><em>When asked how COVID affected her life:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_9.png?ssl=1\" style=\"width: 555px; height: 41px;\"><\/p>\n<p><em>When asked about her job:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_10.png?ssl=1\" style=\"width: 388px; height: 51px;\"><\/p>\n<p><em>When asked what made her choose business:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_11.png?ssl=1\" style=\"width: 624px; height: 112px;\"><\/p>\n<p>Both claim the same job ? <strong>Business Analyst<\/strong> ? which later supports credibility when discussing investments. Claiming to be foreigners explains grammatical errors and factual mistakes about the UK. Notably, job descriptions are long and well-written, lacking earlier quirks ? suggesting prewritten, copy-pasted content. This points to a playbook: flatter the target, establish credibility with occupation and location cover, then use scripted replies where legitimacy matters.<\/p>\n<h2>Phase 4: The hand-off<\/h2>\n<p>After a few days of texting, both explained they were using a business number and asked to move to a ?personal? one:<\/p>\n<p><strong>Verna:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_12.png?ssl=1\" style=\"width: 624px; height: 52px;\"><\/p>\n<p><em>After I said it didn?t bother me to switch:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_13.png?ssl=1\" style=\"width: 624px; height: 130px;\"><\/p>\n<p><strong>Chloe:<\/strong><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_14.png?ssl=1\" style=\"width: 624px; height: 98px;\"><\/p>\n<p><em>After the switch:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_15.png?ssl=1\" style=\"width: 624px; height: 151px;\"><\/p>\n<p>The excuse is plausible and low-friction. Once texting the new number, writing style often changes ? a strong sign of a hand-off to a different operator or team focused on long-term grooming.<\/p>\n<h2>Phase 5: The grooming phase (signs of a different operator)<\/h2>\n<p>The writing style shift is clear on the new numbers:<\/p>\n<p><strong>Verna:<\/strong><\/p>\n<p><em>When asked if she made friends at work:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_16.png?ssl=1\" style=\"width: 624px; height: 50px;\"><\/p>\n<p><em>When asked to share a steak recipe:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_17.png?ssl=1\" style=\"width: 624px; height: 64px;\"><\/p>\n<p><strong>Chloe:<\/strong><\/p>\n<p><em>When asked what languages she speaks:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_18.png?ssl=1\" style=\"width: 624px; height: 62px;\"><\/p>\n<p><em>When asked about her studies:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_19.png?ssl=1\" style=\"width: 624px; height: 98px;\"><\/p>\n<p><em>When asked about work stress:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_20.png?ssl=1\" style=\"width: 624px; height: 51px;\"><\/p>\n<p>Responses show weaker English: more basic grammar errors, shorter sentences, quicker replies, daily ?Good morning? routines, and frequent (likely stolen or AI-generated) photos. These changes strongly indicate a hand-off.<\/p>\n<h2>Phase 6: Credibility building<\/h2>\n<p>By the second week both began describing financial success and sent images of cars, apartments, gym visits, and meals to build trust:<\/p>\n<p><strong>Verna:<\/strong><\/p>\n<p><em>Pictures sent when asked about her side hustle:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_21.png?ssl=1\" style=\"width: 308px; height: 347px;\"> <img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_22.png?ssl=1\" style=\"width: 272px; height: 477px;\"><\/p>\n<p><em>When asked if investments are high risk:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_24.png?ssl=1\" style=\"width: 624px; height: 114px;\"><\/p>\n<p><em>When asked how she chooses investments:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_25.png?ssl=1\" style=\"width: 624px; height: 57px;\"><\/p>\n<p><em>Photo sent saying she finished work (face covered):<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_26.png?ssl=1\" style=\"width: 936px; height: 952px;\"><\/p>\n<p><strong>Chloe:<\/strong><\/p>\n<p><em>When asked about plans for her 30s:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_27.png?ssl=1\" style=\"width: 873px; height: 277px;\"><\/p>\n<p><em>When asked about foundations\/programs:<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_28.png?ssl=1\" style=\"width: 624px; height: 179px;\"><\/p>\n<p><em>Property photo (Australia):<\/em><\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/isc.sans.edu\/diaryimages\/images\/Fares_Azhari_29.png?ssl=1\" style=\"width: 624px; height: 415px;\"><\/p>\n<p>Both positioned themselves as successful investors with diversified portfolios ? building trust for future proposals. The wealth, charity, and expertise narratives emotionally prime the target. Direct money requests usually come much later, after deep emotional commitment.<\/p>\n<h2>Practical advice for readers<\/h2>\n<ul>\n<li>If you receive a random ?wrong number? message, be cautious ? do not share personal information.<\/li>\n<li>Be suspicious if someone quickly asks to move off-platform or to a new number. Stay on the original platform until identity is verified.<\/li>\n<li>Ask for a live video call ? repeated refusal is a major red flag.<\/li>\n<li>Reverse-image search any profile photos or images received.<\/li>\n<li>Never send money, gift cards, or personal documents to someone you only know online.<\/li>\n<\/ul>\n<p> (c) SANS Internet Storm Center. https:\/\/isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.<\/p><\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/isc.sans.edu\/diary\/rss\/32650\">Go to isc.sans.edu<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Initial Stages of Romance Scams [Guest Diary], (Tue, Jan 27th) [This is a Guest Diary by Fares\u00a0Azhari, an ISC intern as part of the SANS.edu\u00a0BACS\u00a0program] Romance scams are a form of social-engineering fraud that causes both financial and emotional harm. They vary in technique and platform, but most follow the same high-level roadmap: initial contact, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[69],"class_list":["post-10157","post","type-post","status-publish","format-standard","hentry","category-isc-sans-edu","tag-isc-sans-edu"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10157"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10157"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10157\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}