CCS Scam Watch

September 2026 Scam Watch Report: 8 Scam Stories You Should Know About

· By Canandaigua Computer Service

A protected phone surrounded by scam caller symbols and a security shield, with the CCS logo.

Scams are no longer limited to an occasional suspicious email or a stranger making a questionable phone call. Modern fraud can involve organized call centers, sophisticated phishing campaigns, cryptocurrency laundering, fake government officials, malicious apps, spoofed phone numbers, artificial intelligence, and international criminal networks operating across multiple countries.

September 2026 brought several significant developments in the fight against these schemes, along with new warnings from U.S. authorities about scams consumers should be watching for. In this month's CCS Scam Watch Report, Canandaigua Computer Service takes a look at eight recent scam and cybersecurity stories and, more importantly, what you can learn from them.

1. Delhi Police Bust Alleged Tech-Support Scam Targeting Americans

One of the month's most striking stories came from India.

On September 24, India Today reported that Delhi Police had busted an alleged illegal international call center in Pitampura. Police arrested 11 people and alleged that the operation had defrauded victims in the United States of approximately ₹100 crore, equivalent to roughly $12 million. According to investigators, the alleged operation used tech-support scams and other forms of impersonation to convince victims that something was wrong with their computers or finances. Police also alleged that victims were threatened using forged communications appearing to come from the FBI and other U.S. federal agencies.

The operation reportedly involved malware, fake technical support, people impersonating bankers, and demands for payments including gift cards.

What You Should Know

A frightening warning on your computer claiming that your device has been infected or compromised does not mean you should call the phone number displayed on the screen.

Fake security warnings are frequently designed to create panic and convince victims to contact the scammers themselves.

If a pop-up tells you to immediately call "Microsoft," "Apple," "Windows Support," or another technical-support number, don't call it. Close the page or browser if possible. If you're unable to close it, shut down or restart the computer and have the device inspected if you're concerned.

Source: India Today: Delhi Police arrests 11 in alleged U.S. tech-support scam

2. 212 People Detained in Pakistan Call-Center Crackdown

Another enormous crackdown occurred in Pakistan this month.

On September 22, Pakistan's National Cyber Crime Investigation Agency (NCCIA) announced raids on three alleged illegal call centers in Islamabad.

Authorities took 212 people into custody.

The agency also reported recovering hundreds of devices, including:

  • 306 mobile phones
  • 383 computers or CPUs
  • 299 monitors and laptops

Authorities alleged that the operations were connected with multiple types of international online fraud, including Google-related scams, dating schemes, fake social-media profiles, fraudulent trading offers, and other schemes targeting people online.

The investigation remains ongoing.

What You Should Know

Stories like this demonstrate the scale at which online scams can operate.

That strange phone call, message, investment opportunity, or social-media account you encounter may not necessarily originate from one individual sitting somewhere with a cellphone.

Some scams are supported by large organizations equipped with hundreds of computers, phones, online accounts, scripts, fake identities, and workers communicating with potential victims. Treat unsolicited online financial opportunities and requests for personal information with caution, regardless of how professional the person contacting you appears.

Sources: Dawn: NCCIA arrests 212 in alleged international fraud schemes The Express Tribune: Three alleged illegal call centers raided in Islamabad

3. Indian Authorities Investigate Alleged $6 Million Fraud Targeting U.S. Citizens

A separate investigation in India provides an especially useful example of how a tech-support scam can escalate.

On September 22, the Hindustan Times reported that India's Central Bureau of Investigation had filed a case involving an Ahmedabad resident and unidentified associates. Authorities allege that illegal call centers operating since 2024 targeted more than 20 Americans and caused approximately $6 million in losses.

According to the allegations described by the CBI, victims would receive pop-up messages claiming their computers had been compromised.

After victims called the displayed number, scammers allegedly impersonated officials from U.S. agencies and told victims that their identities had been connected with criminal activity. Victims were then allegedly persuaded to purchase gift cards or gold, sometimes being told that their assets were being protected by the U.S. government.

What You Should Know

This illustrates one of the most important characteristics of sophisticated scams:

A scam might begin with a computer warning.

Then you're transferred to "technical support."

Technical support discovers an "identity theft problem."

You're transferred to a "government agent."

The government agent tells you your bank account is compromised.

Finally, you're instructed to purchase gift cards, cryptocurrency, or gold to "protect" your money. Every step is designed to make the next step seem reasonable.

If anyone claiming to represent a technology company, bank, police department, or government agency tells you to buy gift cards, cryptocurrency, or gold, stop communicating with them and independently contact the organization they claim to represent.

Source: Hindustan Times: CBI probes alleged $6 million tech and identity-theft fraud

4. FBI Warns About Government and Law-Enforcement Impersonation Scams

The FBI issued an important public warning on September 17 concerning scammers impersonating government and law-enforcement officials.

According to the FBI's Internet Crime Complaint Center (IC3), between January 2025 and July 2026 it received nearly 61,000 complaints involving law-enforcement or government impersonation scams.

Reported losses exceeded $1.6 billion. Scammers may spoof legitimate telephone numbers, use names or credentials belonging to real officials, send convincing emails, and impersonate government agencies.

The FBI also warns that criminals are beginning to use artificial intelligence and other technology to make impersonation attempts more convincing, including during video calls.

What You Should Know

Caller ID is not proof of identity.

A call displaying the name of a police department, bank, government agency, or other legitimate organization can still be fraudulent.

The FBI specifically warns that government and law-enforcement authorities will not call or text you demanding payment or asking you to pay using prepaid cards, cryptocurrency, or a courier.

If someone claims to represent an agency, hang up and independently locate that agency's official phone number. Do not call a number provided by the person who contacted you.

Official Source: FBI IC3: Scammers Impersonating Law Enforcement and Government Officials

5. U.S. Scam Center Strike Force Restrains Approximately $52 Million in Cryptocurrency

September also brought a major U.S. enforcement action against the infrastructure supporting international scam operations.

On September 9, the U.S. Department of Justice announced coordinated actions involving its Scam Center Strike Force and the Department of the Treasury.

According to the DOJ, approximately $52 million in cryptocurrency involved in scam money laundering was restrained in a single day. The DOJ said the action brought the total amount restrained by the Scam Center Strike Force to approximately $938 million.

The Strike Force also assisted authorities in Madagascar in efforts involving 13 Chinese-run scam compounds.

What You Should Know

The infrastructure behind international scams can extend far beyond the person sending the message or making the phone call.

Modern scam networks can involve fake websites, online marketplaces, cryptocurrency wallets, money laundering networks, social engineering operations, call centers, and individuals responsible for moving stolen funds.

This is one reason cryptocurrency has become attractive to some fraud operations. If someone you met online tells you to move money into cryptocurrency, download an unfamiliar investment application, or transfer cryptocurrency to a wallet they provide, don't rush.

Verify the investment independently before sending anything.

Official Source: U.S. Department of Justice: Scam Center Strike Force restrains $52 million in cryptocurrency

6. Treasury Identifies Nearly $13 Billion Connected With Suspected Overseas Digital-Asset Scams

The scale becomes even clearer when looking at another announcement from the U.S. Treasury Department.

On September 3, the Financial Crimes Enforcement Network, better known as FinCEN, announced that its analysis had identified nearly $13 billion associated with suspected digital-asset investment scams operated by overseas scam centers. These schemes are sometimes described as "romance baiting," cryptocurrency confidence schemes, or "pig butchering" scams.

The basic strategy is frighteningly effective.

Rather than immediately asking for money, scammers may spend considerable time establishing a relationship with the victim.

Eventually, the conversation turns toward investing.

The victim may then be directed toward a fraudulent cryptocurrency investment website or platform where their supposed investment appears to grow. The profits displayed on the screen may be entirely fictitious.

What You Should Know

Be extremely cautious when someone you meet unexpectedly online begins discussing investments.

This is particularly important when the person:

  • Claims to have an unusually successful investment strategy
  • Encourages cryptocurrency investments
  • Directs you toward a specific investment website or app
  • Offers to "teach" you how to invest
  • Pressures you to invest increasingly large amounts
  • Makes it difficult or impossible to withdraw your supposed profits

The person you've been speaking with for weeks may not be the person depicted in their profile at all.

Official Source: FinCEN: Nearly $13 billion linked to suspected digital-asset scams

7. FBI Warns About OAuth Consent Phishing

Not every scam involves convincing someone to send money.

Sometimes the goal is gaining access to an online account.

On September 1, the FBI warned about a technique known as OAuth consent phishing.

Traditional phishing often attempts to steal your username and password through a fake login page.

Consent phishing works differently. A victim may receive a link and eventually see what appears to be a legitimate authorization screen asking permission for an application to access an account.

If the victim clicks Allow, the malicious application may receive permission to access email, files, or other account information.

According to the FBI, this can provide persistent access without the attacker ever learning the victim's password.

Even changing the account password may not automatically revoke the application's authorization.

What You Should Know

We've been trained to protect our passwords.

Now we also need to protect our permissions.

Before clicking Allow, Authorize, Connect, or similar buttons, stop and look at exactly what the application is requesting.

Ask yourself:

Do I recognize this application?

Why does it need access to my email or files?

Did I initiate this request?

Does the amount of access being requested make sense?

If the answer isn't clear, don't approve it. Official Source: FBI IC3: Malicious Cyber Actors Gain Access Through Consent Phishing

8. FTC Warns About Fake QR Codes on Parking Meters

Finally, September brought a scam warning involving something many people now use without thinking twice: QR codes.

On September 3, the Federal Trade Commission warned consumers about reports of scammers placing fraudulent QR codes over legitimate QR codes used for parking payments.

A driver scans what appears to be the parking meter's payment code. Instead of reaching the legitimate parking service, the victim is directed to a fraudulent website designed to steal money, payment information, personal information, or a combination of the three.

What You Should Know

Before scanning a QR code in a public place, physically look at it.

Does it appear to be a sticker placed over another QR code?

Does the sign or meter list an official website or payment application you could use instead?

After scanning the code, check the website address before entering payment information.

QR codes are convenient, but remember what they really are: links you can't visually inspect before scanning them. Treat them with the same caution you would an unexpected link in an email or text message.

Official Source: Federal Trade Commission: See a QR code parked somewhere? Don't scan it yet

The Bigger Picture: Scams Are Becoming More Organized

There is a common thread running through nearly every story in this month's report.

Scammers are increasingly exploiting trust rather than simply exploiting technology.

They pretend to be:

Microsoft. Your bank. The FBI. A government agency. An investment adviser. A new friend. A legitimate application. Even the parking meter standing in front of you.

Technology simply gives criminals more convincing ways to create that illusion. The best defense is often surprisingly simple:

Stop before you act.

Don't let someone on the phone rush you.

Don't install remote-access software because a stranger tells you to.

Don't send money because someone threatens you.

Don't trust caller ID by itself.

Don't purchase gift cards, cryptocurrency, or gold because someone claims they're needed to protect your money.

Don't approve unfamiliar applications requesting access to your accounts. And don't be embarrassed to ask someone you trust for a second opinion.

Scammers deliberately create urgency because urgency prevents people from stopping to think.

Think You May Have Been Scammed?

If you've interacted with a suspicious caller, clicked a questionable link, allowed someone to remotely access your computer, entered your password into a suspicious website, or believe one of your online accounts may have been compromised, acting quickly can make a difference.

Canandaigua Computer Service provides Personal Cybersecurity Services for residents throughout Canandaigua and the surrounding Finger Lakes area. CCS can help you review what happened, check your computer and accounts for potential security issues, identify passwords that may need to be changed, enable multifactor authentication, improve account security, and develop a practical plan for protecting your digital life going forward. If money has already been transferred or stolen, immediately contact your bank or financial institution and report the incident to the appropriate authorities. Cyber-enabled fraud can also be reported to the FBI's Internet Crime Complaint Center.

Report Internet Crime to the FBI IC3

Report Fraud to the Federal Trade Commission

When in doubt, stop, verify, and ask for help before sending money or giving someone access to your technology. CCS Scam Watch is an ongoing cybersecurity awareness series from Canandaigua Computer Service covering current scams, fraud trends, cybersecurity warnings, and practical steps you can take to protect yourself online.