You will analyse three real scam messages lever by lever and write what each would have asked next.
You probably have a scam message on your phone right now. It might be buried in your SMS inbox, sitting in a WhatsApp chat from an unknown number, or caught in your email spam folder. Most people delete these without a second look, which is a sensible habit. Today you're going to do the opposite and read three of them very slowly.
You'll use the four levers from lesson 1.1 and the stop-and-check rule from lesson 1.3. Taking a few scams apart on paper is slow the first time, but after three or four you start to see the same parts in real messages, often before you've finished reading them.
Three suspicious messages. Use the ones you collected after lesson 1.1. If you didn't find three, the ScamShield website publishes examples of real scam messages and calls, and you can work from those, as screenshots or copied text. Aim for variety. A good set might be a message claiming to come from a bank or agency, a job or investment offer, and a parcel or "hi, is this you?" text.
You also need a breakdown sheet. A notebook page, a spreadsheet or a phone note all work. For each message, make five rows: the levers and the exact words that pull them, the claimed sender, the action the message wants, the likely next step, and one giveaway detail.
Work through one message at a time, and fill in all five rows before moving on.
First, mark the levers. Go through the message line by line and underline every phrase that creates urgency, borrows authority, suggests scarcity or asks for secrecy. Copy the exact words into your sheet next to the lever they pull. Many phrases pull more than one lever, so a line like "final notice from the authorities" counts as both urgency and authority.
Second, write down who the message claims to be from. Be precise. "My bank" is less useful than "claims to be the fraud team of a local bank, signed with a staff name and an ID number". Note whether the sender name, phone number or email address actually matches that claim.
Third, write the action the message wants right now. This is usually small: click a link, reply with your name, add a contact on Telegram, call a number. Check whether that action hits any of the four triggers from lesson 1.3, which are a request for money, a code, an app or your silence.
Fourth, write what the scammer would most likely have asked for next if you had replied. This is the step that takes some thought. The first request is rarely the one that costs money. A link usually leads to a login page that asks for your password and then your one-time password. A friendly job message usually leads to a chat group and an invitation to "top up" for a bigger task. Write the chain as far as you can reasonably guess it.
Fifth, find one detail that gives the message away. Pick the single clue you would want to remember. It might be a link from a bank, a sender that isn't the organisation it claims to be, a deadline counted in minutes, or a request to move to a different app.
Here is an illustration, written in the style of the examples on the ScamShield website. It isn't a real message.
"Dear customer, your account has been temporarily suspended due to unusual activity. To avoid permanent closure, verify your identity within 30 minutes at the link below. Do not share this message for security reasons."
The breakdown sheet for that message would read like this.
Levers: urgency in "within 30 minutes" and "avoid permanent closure". Authority in "dear customer", "account" and "unusual activity", which borrow the tone of a bank. Secrecy in "do not share this message for security reasons". There's no real scarcity here, and that's fine. Not every message uses all four.
Claimed sender: a bank, though the message never names one. It arrived from an unfamiliar mobile number rather than a registered bank sender ID.
Action wanted: click the link. That leads straight towards sharing login details and a one-time password, so it hits the trigger.
Likely next step: the link opens a copy of a bank login page. You enter your username and password, then the page asks for the one-time password that arrives by SMS. With that, the scammer can log in to your real account, add a payee or raise your transfer limit, and move money out.
Giveaway detail: a link in a message claiming to be from a bank. Banks in Singapore no longer send clickable links by SMS or email to retail customers, so any link from a bank should be treated as fake.
Notice how the giveaway is something you can check in two seconds, without needing to judge tone or spelling. That's what you are looking for in each of your three messages: a clue simple enough to spot when you are tired.
Some messages give very little away. A text that just says "Hi, is this Rachel?" has no lever and no request. The scammer is only checking whether the number is live and whether you're the kind of person who replies to strangers. For a message like this, write "none yet" under levers, and put the effort into the likely next step.
Other messages look completely real. If you can't find a giveaway, write down what you would check and how you would check it, using the rule from lesson 1.3, and count that as a finished row.
With the five rows and the worked example in front of you, you're ready for your own messages. Start with the easiest of the three, so the method feels familiar by the time you reach the one that gives the least away.
Fill in the scam breakdown sheet for three messages and write the one giveaway detail you will look for from now on.
Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).