The Anatomy of a Cold Email Scam: What Predators Are Really Sending You
By E L Frederick, CISSP
At 4:39 on a Monday morning, the following email arrived in my inbox:
Hello, Hope you’re doing great. Stumbled on your portfolio online and decided to say hi. I need two short articles and I feel you’d be able to help me put them together. These articles will be featured in a workshop intended to educate and enlighten young adults about significant issues affecting young people of this generation. If you are available, I would be happy to share more details. I prefer to communicate via email for documentation.
Signed: Joan Goldberg. Phone number included. Warm, personable, urgent-adjacent.
I spotted the scam before I finished reading the second sentence. Not because I’m especially clever, but because I’ve been doing cybersecurity risk assessment professionally long enough to recognize a script when I see one. The email isn’t unusual. It’s a template: one of dozens in active rotation targeting freelancers and young professionals building their first careers every day.
The purpose of this article is to walk you through exactly what that email is doing, line by line, and introduce you to a second, more dangerous variant that destroyed a young woman’s finances because nobody had briefed her on what to look for. Both scams are built on the same foundation: manufactured trust, deliberate vagueness, and a single financial transaction designed to leave you holding the loss.
Why Young People Are the Primary Target
Before we get into mechanics, let’s establish why these scams are disproportionately aimed at people under thirty.
Young adults are in a period of maximum financial vulnerability and minimum skepticism calibration. You’re building a career, hustling for freelance income, applying for remote jobs, and doing all of it through digital channels where you have no established baseline for what “normal” looks like. You haven’t yet accumulated the scar tissue that teaches older professionals to slow down when something feels slightly off.
The scammers know this. They study platforms where young people advertise skills (Fiverr, LinkedIn, Upwork, personal portfolio sites) and they build contact lists. Their opening messages are engineered to feel like opportunity, not threat. They’re counting on the fact that when you’re twenty-three and someone says they found your portfolio and want to pay you, your first instinct is excitement, not suspicion.
That instinct is completely human. It’s also the attack surface.
The Freelance Writing Scam: A Line-by-Line Autopsy
Let’s go back to Joan’s email and look at what each element is actually doing.
“Hope you’re doing great. Stumbled on your portfolio online.”
This is the rapport-building opener. It’s warm and casual. Designed to disarm. “Stumbled” implies serendipity: you weren’t targeted, you were discovered. It flatters without specifying anything, because the sender has no idea what’s actually in your portfolio. This same sentence, word for word, goes to hundreds of people.
“I need two short articles and I feel you’d be able to help me put them together.”
Notice what’s missing: topic, word count, deadline, and, critically, rate. A legitimate client contacts you because they have a specific need. They tell you what it is. Vagueness at this stage isn’t modesty; it’s architecture. The scam requires you to ask questions, which creates engagement, which they treat as a soft commitment.
“These articles will be featured in a workshop intended to educate and enlighten young adults about significant issues affecting young people of this generation.”
This sentence is designed to feel compelling while communicating nothing. “Significant issues affecting young people” could mean anything from financial literacy to whatever’s burning on social media this week. It’s built to sound purposeful enough that you lean in and ask what they mean, which is, again, exactly what they want. Real clients tell you what the work is.
“I prefer to communicate via email for documentation.”
This is the tell. This specific phrase, or close variants of it, appears in advance-fee fraud scripts across dozens of categories. It sounds reasonable on the surface: documentation is professional, right? But its actual function is to keep the interaction in a channel they control (away from the inconsistencies that real-time conversation would expose) and establish the paper trail necessary for the next phase: the fake contract and the bad check.
How It Escalates If You Engage
If you respond with interest, here’s the standard pipeline:
You exchange a few emails. They remain vague but enthusiastic. Eventually they send a “contract”: a professional-looking PDF establishing terms and payment. The payment is almost always higher than standard market rate. This is intentional. It bypasses your skepticism because you’re focused on the number.
Then the check arrives. It’s real-looking, drawn on a legitimate bank, and it’s for more than the agreed amount. They contact you, apologetically, a little embarrassed, explaining it was a bookkeeping error. Could you please deposit the check and send the overage via Zelle or wire transfer to their “account team” or “equipment vendor”?
You send the money. Two to three weeks later, the check bounces. The bank reverses the deposit. The money you forwarded is gone. Zelle and Venmo transfers to strangers are effectively irreversible. You are now out both the forwarded amount and any fees the bank assesses.
This is the advance-fee / overpayment scam. It has existed in various forms since the Nigerian Prince emails of the 1990s. It still works because the check looks real and the timeline gap between deposit and bounce is calibrated to give you just enough time to lower your guard. By then, the social engineering has already done its job: the apologetic “bookkeeping error” made the whole thing feel like their mistake, not their plan.
The Fake Job Scam: When They Go After Your Entire Account
The freelance variant is damaging. The job offer variant is potentially catastrophic, and it’s specifically engineered for young adults entering the workforce.
Here’s how it played out for someone I know personally: a young woman in her early twenties, job hunting, sharp, careful with money, and completely unprepared for this.
She received a job offer (sometimes via LinkedIn DM, sometimes via email, sometimes through a job board) for a remote position at a pay rate that was higher than she expected but not absurdly so. The company had a real-looking website. The interviewer was professional. She was hired.
Onboarding included the standard paperwork: direct deposit information and tax forms. She filled it out because that’s what onboarding requires.
Then came the equipment requirement. The company explained they had a preferred vendor for remote employee setups, but the vendor required direct payment from the employee, which would be reimbursed. They would send her the funds via Venmo.
The money appeared in her Venmo account. She was instructed to purchase a specific laptop and peripherals and send the vendor information confirming the order. In some variants of this scam, they ask you to forward a portion to a “procurement account.” In her case, the damage came through the banking connection: her Venmo account was linked to her primary checking account, and the access they gained through that connection, combined with the direct deposit paperwork she’d completed, gave them sufficient access to initiate withdrawals.
By the time she understood what had happened, her checking account had been drained.
The mechanics vary slightly by operator, but the structure is consistent: get you into an onboarding process that collects banking information, then introduce a financial transaction that requires you to move money through a linked account. The access that creates is what they came for. The “job” is not real. The company website was built in an afternoon. The interviewer is running the same conversation with dozens of other applicants simultaneously.
The Shared Architecture
Both scams are built on the same three-phase structure.
Phase One: Manufactured Legitimacy. They contact you through a channel you use professionally. They reference something real about you: a portfolio piece or a job application you forgot you submitted. They present as a normal person or company with a normal need. Nothing about the initial contact is alarming because it’s designed not to be.
Phase Two: Deliberate Vagueness. They withhold specifics until you’re engaged enough to ask for them. Each exchange requires you to invest more time and interest. By the time they introduce the financial element, you’ve been in conversation long enough that the relationship feels real, even if you’ve never spoken to a live person.
Phase Three: The Transaction. Everything has been building toward a single moment: a financial transaction that benefits them at your expense. Whether it’s forwarding an overpayment or completing direct deposit paperwork, the scam lives or dies on this step. If you complete the transaction, they win. If you pause here and verify independently (not using contact information they’ve provided), the scam collapses.
The Red Flag Reference
Learn these. Run them as a checklist when something feels slightly off.
Unearned enthusiasm. They found you and they’re already excited about working with you, despite knowing nothing specific about your work.
Vague deliverables. A real client tells you what they need. Vagueness at the outset means there is no real project.
Above-market compensation. Pay that seems unusually high for the work described is not good luck. It’s calibrated to override your caution.
“I prefer to communicate via email for documentation.” This phrase is in the script. It exists in dozens of documented fraud cases. Treat it as an automatic flag.
No voice contact. They resist phone or video calls. Inconsistencies are harder to maintain in real time.
Overpayment with forwarding request. No legitimate transaction requires you to deposit funds and forward a portion elsewhere. None.
Equipment purchase through you. Real employers send equipment. They do not ask you to purchase it and reimburse you through Venmo.
Onboarding before verification. If a company asks for direct deposit information before you’ve verified their physical address and spoken to a real human being independently: stop.
Urgency. Pressure to move quickly exists to prevent you from thinking.
How to Kill It in One Reply
You don’t need to be clever. You don’t need to expose them. You just need to ask the questions a real client can answer and a scammer cannot.
Two questions end most of these:
1. How did you find me specifically? 2. What exactly are you looking for?
A real client found you through a specific referral, or a specific piece of work they actually looked at. Not “stumbled on your portfolio.” They can answer the first question with a sentence. A scammer found you through a scraped list and will give you something generic: “stumbled on your portfolio,” “saw your profile online,” “was referred by a colleague” with no colleague named.
A real client wants a specific deliverable. A scammer needs to maintain vagueness until they’ve built enough rapport to introduce the financial element. They will answer the second question with enthusiasm that circles back to nothing.
You don’t owe them a confrontation. No reply at all is a complete response. If you’ve given them nothing (no banking information, no commitment, no forwarded funds), there is nothing to recover.
If You’re Already In
Check received, not yet deposited. Do not deposit it. Contact your bank directly (using the number on your card, not any number provided by the sender) and describe what you’ve received.
Check deposited, funds already forwarded. Call your bank immediately. Dispute the transaction. Recovery is unlikely but not impossible, and speed is the only variable you control.
Direct deposit information handed over. Call your bank the same day and request account number changes. Flag the account for monitoring. The paperwork has your routing and account number; assume they will use it.
Social Security number submitted in fake onboarding. File an identity theft report with the FTC at IdentityTheft.gov and place a fraud alert on your credit.
Document everything before you do anything: screenshots of all communications, the check, any contracts, all email headers.
A Note on the Joan Email Specifically
The email that opened this article was sent to me, a CISSP-credentialed cybersecurity professional, at 4:39 on a Monday morning, unsolicited, with a warm greeting and a vague workshop story. The “documentation preference” appeared in the second paragraph.
I recognized it immediately. I asked two questions.
I’m still waiting for the answers.
The scam doesn’t care how sophisticated you are. It goes to everyone. The only question is whether you recognize it before the transaction.
If this has already happened to you: you weren’t naive. You were targeted by professionals running a script older than the internet. Reply if you want to talk through it.
This is E L Frederick. I’m a CISSP-certified cybersecurity professional with 30 years in enterprise and DoD environments. I write here about fraud mechanics and digital risk: the gap between what people are told and what’s actually happening. No jargon. No vendor pitch.
Subscribe if that’s useful to you.
You may also like: - Not All Data Is Created Equal - Consensus Does Not Science Make