Sentinel Vault
← All field notes
Fraud & Crime Trends · May 28, 2026

Three Scams Hitting Families and Small Businesses This Summer

Three Scams Hitting Families and Small Businesses This Summer

Summer brings normal behavior that scammers exploit: graduation parties on every block, kids and recent grads taking entry-level jobs, AP teams running on reduced staff while owners are on vacation. The FTC has issued three consumer alerts in the last few weeks that all ride this energy. They land on different doorsteps, but the pattern underneath is the same.

Here's what we're seeing, what to watch for, and what to do about it.

1. Fake Party Invites That Steal Your Email Password

It's graduation and summer party season. The FTC is getting reports of unexpected "You're invited" texts and emails. The hook is a link or a passcode prompt: enter your email password or a special code to open the invite.

If you do, the scammer captures your login, takes over your email account, and uses it to scam everyone in your contact list. That often includes your own family members and coworkers. Once they're inside your inbox, they reset passwords on other accounts you own. Bank, retirement, social media, the works.

What to watch for:

  • Unexpected invitation from someone you don't recognize
  • The message asks for your email password or a "secret code" to view
  • The sender address looks slightly off or shows up as a random number
  • A sense of urgency: "RSVP today" or "expires in 24 hours"

What to do:

  • Don't click. If you think it might be real, contact the sender directly through a number or address you already had, not anything in the message
  • Forward the suspicious text to 7726 (SPAM) and report it at reportfraud.ftc.gov
  • If you already entered credentials, change your email password immediately and turn on two-factor authentication

Pass this one along to the teenagers and college kids in your life. They're getting more invitations right now than at any other time of year, and they're the most likely to click.

2. The Fake Recruiter Text

Summer is when recent graduates and seasonal jobseekers are most active. Scammers know this. A text shows up offering a remote job that pays surprisingly well, often referencing a company you've heard of. The "recruiter" sounds professional. They ask for an interview that somehow requires you to pay an upfront equipment fee, or to provide banking details "for direct deposit setup."

That fee never gets refunded. That bank account starts seeing fraudulent activity. In some variants we see in our case work, the "job" is a re-shipping or money-mule scheme that puts the victim on the wrong side of a federal investigation before they realize what they signed up for.

What to watch for:

  • You didn't apply for the job
  • The recruiter contacted you by text, not through a legitimate hiring platform
  • The role pays well above market for the experience level
  • They ask for any payment from you, ever
  • They ask for banking, Social Security, or document information before you've had a video interview with a real person

What to do:

  • Verify the recruiter on the company's actual website. Call the company through a number you find independently
  • Never pay anything to a job, ever. Real employers don't charge you to work
  • If you've already provided bank info, contact your bank and tell them to flag the account for fraud monitoring

Small business HR teams should brief their hiring managers too. Fake recruiters sometimes impersonate your company to target your candidates. You may not know until a job applicant calls asking why they were charged $200 by your "onboarding department."

3. The Fake Invoice in Your Mail

A small business gets an invoice, sometimes by mail and sometimes by email, for products or services the business never ordered. The invoice looks legitimate. It has a company name on it, an amount, often a fake purchase order number. The bookkeeper assumes someone in the company ordered the thing and routes it for payment.

The version we see most often targets businesses with 5 to 25 employees. Companies that have an AP person handling invoices but don't yet have a written verification process. By the time anyone catches it, the wire has cleared.

What to watch for:

  • Invoice arrives for something nobody in the company recognizes
  • The vendor name is unfamiliar, or close-but-not-identical to a vendor you do use (Acme Office Supply vs Acme Office Supplies, Inc.)
  • The PO number doesn't match anything in your records
  • The invoice is pressing for payment within a tight window. Net 30 with a "past due" tone
  • The contact phone or remittance address is one you've never used before

What to do:

  • All incoming invoices route to one person who can verify the underlying order existed
  • That person calls back on a phone number they pulled themselves, not the number printed on the invoice
  • Never approve payment for an unfamiliar vendor without that verification step
  • Train your AP team to flag the pattern, not just the individual invoice. Once these hit your business once, they'll be back

The Pattern Behind All Three

The party-invite scam, the recruiter-text scam, and the fake-invoice scam all work the same way underneath. They ride a moment when the target's normal behavior is busier than usual, and they extract one missing verification step.

For families, the verification step is "contact the sender through a channel you already had."

For small businesses, the verification step is "call back on a number you pulled yourself."

In both cases, the loss either happens at that step or it doesn't. Everything else, the convincing graphics, the urgency, the spoofed branding, is theater wrapped around the missing call.

Share this post with the people in your life who'd benefit. The teenager who just opened a Venmo account. The new bookkeeper who hasn't seen the playbook yet. The recent grad on the job hunt. The hiring manager onboarding seasonal staff.

The FTC made the three alerts behind this post freely available at consumer.ftc.gov/consumer-alerts. Forward suspicious texts to 7726 (SPAM). Report fraud at reportfraud.ftc.gov.

About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end: the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Keep pulling the thread
The fiction version

Fleeced Nation is a crime series about industrialized fraud, from the elder-fraud call centers to the quiet machinery that turns dirty cash clean. Same terrain as the case files, minus the parts a report will not hold. I started it as fiction. The case files keep publishing the sequel.

fleecednation.com ↗
Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.