How to defend the full social engineering attack chain | Register for the webinar to learn more

General

What Is a Romance Scam?

A concise guide on romance scams, their types, how they operate, and effective defense strategies for individuals and businesses.

Doppel TeamSecurity Experts
September 23, 2026
5 min read

What Is a Romance Scam?

A romance scam is a confidence scheme in which a criminal builds a fabricated personal relationship with a target, usually through a fake online identity, then uses the trust that relationship creates to extract money, financial information, valuables, or help moving stolen funds.

The scheme falls under the FBI's confidence fraud (opens in new tab) classification, which covers romantic, friendly, and familial ties alike. It sits in the same social engineering (opens in new tab) category as business email compromise, sextortion, and investment scams.

How a romance scam works

Weeks or months of grooming (opens in new tab) precede the first request for money, though cases rarely run in a fixed order (opens in new tab). Contact opens on dating or networking sites (opens in new tab) or by text (opens in new tab), and the scammer uses that initial outreach to build an ongoing conversation before money is requested (opens in new tab).

Early on, the scammer moves the conversation to WhatsApp messaging, Telegram, or WeChat, off the dating platform (opens in new tab) and beyond its moderation. Grooming runs on daily messages, love declarations (opens in new tab), marriage talk, visits that collapse through a manufactured emergency, and pressure to keep the relationship from friends and family (opens in new tab).

The first request arrives one of two ways: a foot-in-door approach (opens in new tab) uses gifts or small sums to test compliance before amounts climb, or manufactured crisis pretexts (opens in new tab), such as a medical emergency, legal fees, or customs charges, jump straight to a large ask. Scammers then compound payments through sunk-cost exploitation, a defining characteristic (opens in new tab) of the crime.

In the crypto variant, the contact walks the target through buying coins on a legitimate exchange and moving them to a fake trading site; when the victim tries to withdraw, a fake "customer service" team demands fees or taxes, and once the money stops, communication stops (opens in new tab).

Why romance scams are hard to stop

Attackers build romance personas from real brands and real people. Clone firms copy the name, address, and Firm Reference Number of authorised companies (opens in new tab), and seized domains such as tickmilleas.com belonged to a compound that impersonated a legitimate firm (opens in new tab). The impersonated company can then face victim complaints (opens in new tab) and regulatory notifications (opens in new tab) it never caused.

AI weakens familiar red flags. Attackers now run fake profiles on scripts AI chat generators produce (opens in new tab), which removes the poor-grammar tell (opens in new tab), while synthetic profile photos make image-based verification less reliable. Southeast Asian scam centers run "AI rooms" where real-time face-swap (opens in new tab) video calls answer any request to appear on camera.

An industrial operation sits behind each persona: the Chinese Sha Zhu Pan model relies on specialized teams (opens in new tab), with separate crews for talking to victims, sourcing targets, building fake apps and sites, and laundering the proceeds.

When crackdowns disrupt compounds, operations reappear in other purpose-built parks (opens in new tab), and victims underreport out of shame, the main reason reporting stays low (opens in new tab).

Types of romance scams

Several variants recur across law enforcement, regulator, and research reporting, and they can overlap within campaigns (opens in new tab):

How to defend against romance scams

Platforms can intervene early (opens in new tab), but romance-scam infrastructure otherwise sits outside a company's own systems, so defense has to combine platform controls, clear internal ownership, and law-enforcement reporting.

Because this infrastructure and these personas rotate after every takedown or report, these controls only hold when they run continuously, not case by case.

How Doppel helps

Doppel is the Frontier AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM) to detect romance scams that borrow your brand or executives and dismantle the attacker infrastructure they run on. Brand Protection detects the lookalike domains, fake profiles, and scam ads behind a persona.

The Doppel Threat Graph links a wrong-number SMS sender to a WhatsApp handle, then connects those identifiers to a cloned investment site in one campaign view.

The same agentic AI correlates and prioritizes threats, then executes multi-channel takedowns across registrars, hosts, social platforms, and ad networks. Doppel's Executive Protection removes executive personal data from broker sites and dismantles deepfake content and impersonation accounts tied to leadership. Coordinated enforcement across every channel makes the campaign too costly to keep rebuilding.

Request a demo to get started.

Frequently asked questions about romance scams

What is a romance scam?

A romance scam is a confidence scheme in which a criminal invents a romantic or friendly relationship with a target, or claims a familial tie, usually through a fake online profile, and uses that trust to obtain money, financial details, valuables, or help laundering funds, conduct that falls under the FBI's confidence fraud (opens in new tab) classification. They typically begin on dating apps or social media, sometimes on messaging platforms, and commonly move to encrypted chat (opens in new tab) before the scammer requests any money. Scammers ask some victims for direct payments, steer others into a fake investment platform (opens in new tab), and use others to move stolen funds (opens in new tab).

What is a romance scam in cybersecurity?

In cybersecurity terms, a romance scam is a social engineering attack (opens in new tab) that works by exploiting a person's trust. It sits alongside business email compromise, sextortion, and investment scams under the social engineering umbrella. For enterprises it matters because attackers often build the fake persona from a real brand's name or a cloned regulated website. They may also use a real executive's photos and voice, or groom employees into acting as money mules. The attack infrastructure sits outside the company's perimeter, so traditional security operations center tooling rarely sees it (opens in new tab).

What is the difference between a romance scam and pig butchering?

Pig butchering is a long-con investment scam that often uses romance-style social engineering and fraudulent trading platforms, frequently involving fraudulent cryptocurrency trading (opens in new tab). A classic romance scam asks for direct payments such as emergency medical bills, airfare, or customs fees. Pig butchering guides the victim onto a fraudulent trading platform that displays fake gains, permits a small withdrawal to build confidence, then blocks access behind fees and taxes. The term "romance baiting" (opens in new tab) avoids the victim-shaming associated with "pig butchering," which can discourage reporting. Romance-led pig-butchering schemes contain a romance-scam phase, though not every romance scam reaches an investment platform (opens in new tab).

What is an example of a romance scam that uses brand or executive impersonation?

On September 17, 2024, operators of two fake crypto platforms (opens in new tab), NanoBit and CoinW6, faced the first U.S. Securities and Exchange Commission (SEC) enforcement actions alleging relationship investment scams after building trust on LinkedIn, WhatsApp, and Instagram before steering victims to the sites. Fraudsters have also copied a registered professional's name and Central Registration Depository (CRD) number into a fake BrokerCheck report (opens in new tab) impersonating Financial Industry Regulatory Authority (FINRA) records. In each case, the impersonated firm may need to respond to victim reports (opens in new tab) and alert regulators (opens in new tab).

Last updated: September 23, 2026