You get a text: someone sent you money, a payment failed, or your account is locked unless you “confirm.” There’s a short link. Real money apps put important actions inside the app you already installed — not a random browser page from SMS. When in doubt, open the real app yourself and ignore the text’s link.
Why money-app scams work
People check PayPal, Venmo, and Cash App for real transfers every day. Scammers copy the tone of a receipt or a security alert. If you log in on their lookalike page, they steal the account — or they convince you to “send back” money that never existed.
5 signs it’s fake
- A payment you weren’t expecting plus a link to “accept” it
- Domains that aren’t the real app site — extra words, odd endings
- Urgency — “expires in 2 hours,” “unusual login, act now”
- Asks you to refund a “wrong transfer” that never showed in the real app
- Poor spelling or odd branding next to a polished logo (still fake)
What to do instead
- Don’t tap the link. Open PayPal, Venmo, or Cash App from your home screen.
- If there’s no matching payment in the real app, delete the text.
- Never “send back” money because a stranger claimed a mistake — verify inside the app first.
- Paste the full SMS into ScamCheck.
- If you only have the URL, paste it into the free payment-app phishing link checker. It looks for misleading domains without opening the site; verify money alerts inside the real app regardless of the score.
FAQ
- Do these apps ever text? Sometimes for login codes or optional alerts. A cold “claim money here” link is still a stop sign — open the app yourself.
- What if I typed my password? Change it in the real app, turn on extra security, and read I clicked a scam link.