Gift Card Gone Wrong

A Gift Card Gone Wrong

Elaine didn’t think twice when she got a text one afternoon.

That morning, she’d been so happy and surprised to receive a gift card from her son for her birthday. The gift card arrived tucked inside a floral greeting card with a handwritten note saying to, “treat yourself to something nice.” It was such a thoughtful gesture, and she carried that joy around with her the whole morning.

A few hours later, while she was making tea in the kitchen, her phone buzzed.

An Unexpected Text

The text read: “Your gift card is pending activation. Please confirm your balance information here,” and contained a link.

Elaine almost ignored it. Afterall, she received fraudulent texts all the time and had trained herself to always think twice before clicking on links. But when she pulled the gift card from the envelope, she noticed there actually was a website printed on the back for activation and balance checks.

The text that initially generated suspicion now felt normal. She clicked the link. 

The webpage looked completely legitimate. It matched the gift card’s branding and colors. It was a clean, professional-looking website with a balance checker front and center. Nothing flashy. Nothing broken. Nothing that screamed “scam.”

It simply asked her to enter the card number and security code to complete activation. So, she did.

The page loaded for several seconds before displaying a pop-up message informing her, “Your card is now active.” That was it! No alarms. No suspicious pop-ups. No immediate sign anything had gone wrong.

The Problem

Two days later, Elaine tried using the gift card at a department store and the cashier quietly told her there was no balance remaining.

She apologized, feeling embarrassed, assuming she’d done something incorrectly.

When customer service pulled up the transaction history, the money had already been spent through multiple online purchases less than an hour after she “activated” the card online through the link in the text message.

Elaine quickly called her son and told him the whole story. Together, they examined the text message she received and that’s when they saw it:

The website address was fake. The problem was that it wasn’t obviously fake. In fact, it was only one letter different than the real card activation website.

The real company website used an “i” while the fraudulent one used a lowercase “L.” On a phone screen, they looked nearly identical. At a quick glance, Elaine hadn’t noticed the swap, and her son admitted that if he hadn’t been looking closely, he wouldn’t have either.

The Lesson

Scammers had created a counterfeit version of the gift card company’s website designed specifically to steal card information from recipients before they can use the funds themselves.

Because the site looked polished and familiar, Elaine never questioned it.

That’s what makes scams like these so effective now. They no longer depend on obvious fear tactics or outrageous claims. Instead, they imitate ordinary experiences people already expect, like account alerts, package updates, activation notices and balance confirmations.

Stay Vigilant

This fraud worked because it felt routine. Elaine had no cause for alarm. In the future, never click a link claiming to be from a company you know asking for personal information.

Only use phone numbers, websites and contact information you can verify as legitimate.

SHARE THIS POST
Recent Posts
Recent Posts
Toolbox

Your Fraud Prevention Toolbox

Have you taken steps to protect your personal information lately?  When it comes to stopping fraud and identity theft, staying