What Is a Romance Scam?
A romance scam is a confidence scheme in which a criminal builds a fabricated personal relationship with a target, usually through a fake online identity, then uses the trust that relationship creates to extract money, financial information, valuables, or help moving stolen funds.
The scheme falls under the FBI's confidence fraud (opens in new tab) classification, which covers romantic, friendly, and familial ties alike. It sits in the same social engineering (opens in new tab) category as business email compromise, sextortion, and investment scams.
How a romance scam works
Weeks or months of grooming (opens in new tab) precede the first request for money, though cases rarely run in a fixed order (opens in new tab). Contact opens on dating or networking sites (opens in new tab) or by text (opens in new tab), and the scammer uses that initial outreach to build an ongoing conversation before money is requested (opens in new tab).
Early on, the scammer moves the conversation to WhatsApp messaging, Telegram, or WeChat, off the dating platform (opens in new tab) and beyond its moderation. Grooming runs on daily messages, love declarations (opens in new tab), marriage talk, visits that collapse through a manufactured emergency, and pressure to keep the relationship from friends and family (opens in new tab).
The first request arrives one of two ways: a foot-in-door approach (opens in new tab) uses gifts or small sums to test compliance before amounts climb, or manufactured crisis pretexts (opens in new tab), such as a medical emergency, legal fees, or customs charges, jump straight to a large ask. Scammers then compound payments through sunk-cost exploitation, a defining characteristic (opens in new tab) of the crime.
In the crypto variant, the contact walks the target through buying coins on a legitimate exchange and moving them to a fake trading site; when the victim tries to withdraw, a fake "customer service" team demands fees or taxes, and once the money stops, communication stops (opens in new tab).
Why romance scams are hard to stop
Attackers build romance personas from real brands and real people. Clone firms copy the name, address, and Firm Reference Number of authorised companies (opens in new tab), and seized domains such as tickmilleas.com belonged to a compound that impersonated a legitimate firm (opens in new tab). The impersonated company can then face victim complaints (opens in new tab) and regulatory notifications (opens in new tab) it never caused.
AI weakens familiar red flags. Attackers now run fake profiles on scripts AI chat generators produce (opens in new tab), which removes the poor-grammar tell (opens in new tab), while synthetic profile photos make image-based verification less reliable. Southeast Asian scam centers run "AI rooms" where real-time face-swap (opens in new tab) video calls answer any request to appear on camera.
An industrial operation sits behind each persona: the Chinese Sha Zhu Pan model relies on specialized teams (opens in new tab), with separate crews for talking to victims, sourcing targets, building fake apps and sites, and laundering the proceeds.
When crackdowns disrupt compounds, operations reappear in other purpose-built parks (opens in new tab), and victims underreport out of shame, the main reason reporting stays low (opens in new tab).
Types of romance scams
Several variants recur across law enforcement, regulator, and research reporting, and they can overlap within campaigns (opens in new tab):
- Pig butchering/romance baiting. A romance scam that pivots to a fraudulent cryptocurrency investment platform: text or dating-app contact (opens in new tab) moves to WhatsApp or WeChat, then to a fake trading site showing artificial gains. The term "romance baiting" (opens in new tab) avoids the victim-shaming of the older term, which can deter reporting.
- Military and professional impersonation. Scammers pair the real rank and name of serving personnel with photos found online (opens in new tab) to build a false identity. A deployed soldier or an oil-rig worker can use distance to avoid meeting and plausibly ask for flight money home.
- Romance-to-sextortion pivot. After intimate images change hands, the scammer threatens to publish them (opens in new tab) unless the victim pays; criminal networks now build sextortion systematically into (opens in new tab) romance and investment fraud operations.
- Money mule recruitment. The relationship becomes a laundering channel: a persona posing as an entrepreneur or bachelor (opens in new tab) turns the victim into a mule, whether unwitting, witting, or complicit (opens in new tab).
- Recovery scams. A second wave poses as a law firm, government agency, or blockchain analytics firm and offers to retrieve the lost funds for an upfront fee, another scheme (opens in new tab) layered on the first.
- AI-assisted and deepfake variants. Attackers layer this onto every type above: voice cloning mimics a known person, LLMs support scam conversations (opens in new tab), and real-time face swaps carry it onto live video.
How to defend against romance scams
Platforms can intervene early (opens in new tab), but romance-scam infrastructure otherwise sits outside a company's own systems, so defense has to combine platform controls, clear internal ownership, and law-enforcement reporting.
- Verify identity at the platform. Match Group's Face Check (opens in new tab) compares a short recorded selfie against profile images to confirm liveness, with in-app prompts (opens in new tab) firing when a conversation turns to money.
- Add friction at the fiat boundary. Confirmation of Payee checks the account name against the name the payer supplied, the kind of positive friction (opens in new tab) regulators want at the point of payment, and related suspicious activity reports use the designated term FIN-2023-PIGBUTCHERING (opens in new tab) so patterns aggregate across institutions.
- Assign a single owner and monitor externally. Brand impersonation often lands with incident response or legal under unclear ownership (opens in new tab), or with marketing instead, and scam sites rarely touch owned infrastructure, so SOC alerting rarely sees them. Run continuous monitoring for lookalike domains and executive-adjacent handles, and document platform reporting paths in advance.
- Report and share intelligence. Report incidents to the FBI's IC3 (opens in new tab) at ic3.gov and the FTC at the FTC reporting portal (opens in new tab), and join cross-industry sharing such as Tech Against Scams (opens in new tab), the coalition Coinbase, Match Group, Meta, Kraken, Ripple, and Gemini announced in May 2024.
Because this infrastructure and these personas rotate after every takedown or report, these controls only hold when they run continuously, not case by case.
How Doppel helps
Doppel is the Frontier AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM) to detect romance scams that borrow your brand or executives and dismantle the attacker infrastructure they run on. Brand Protection detects the lookalike domains, fake profiles, and scam ads behind a persona.
The Doppel Threat Graph links a wrong-number SMS sender to a WhatsApp handle, then connects those identifiers to a cloned investment site in one campaign view.
The same agentic AI correlates and prioritizes threats, then executes multi-channel takedowns across registrars, hosts, social platforms, and ad networks. Doppel's Executive Protection removes executive personal data from broker sites and dismantles deepfake content and impersonation accounts tied to leadership. Coordinated enforcement across every channel makes the campaign too costly to keep rebuilding.
Request a demo to get started.
Frequently asked questions about romance scams
What is a romance scam?
A romance scam is a confidence scheme in which a criminal invents a romantic or friendly relationship with a target, or claims a familial tie, usually through a fake online profile, and uses that trust to obtain money, financial details, valuables, or help laundering funds, conduct that falls under the FBI's confidence fraud (opens in new tab) classification. They typically begin on dating apps or social media, sometimes on messaging platforms, and commonly move to encrypted chat (opens in new tab) before the scammer requests any money. Scammers ask some victims for direct payments, steer others into a fake investment platform (opens in new tab), and use others to move stolen funds (opens in new tab).
What is a romance scam in cybersecurity?
In cybersecurity terms, a romance scam is a social engineering attack (opens in new tab) that works by exploiting a person's trust. It sits alongside business email compromise, sextortion, and investment scams under the social engineering umbrella. For enterprises it matters because attackers often build the fake persona from a real brand's name or a cloned regulated website. They may also use a real executive's photos and voice, or groom employees into acting as money mules. The attack infrastructure sits outside the company's perimeter, so traditional security operations center tooling rarely sees it (opens in new tab).
What is the difference between a romance scam and pig butchering?
Pig butchering is a long-con investment scam that often uses romance-style social engineering and fraudulent trading platforms, frequently involving fraudulent cryptocurrency trading (opens in new tab). A classic romance scam asks for direct payments such as emergency medical bills, airfare, or customs fees. Pig butchering guides the victim onto a fraudulent trading platform that displays fake gains, permits a small withdrawal to build confidence, then blocks access behind fees and taxes. The term "romance baiting" (opens in new tab) avoids the victim-shaming associated with "pig butchering," which can discourage reporting. Romance-led pig-butchering schemes contain a romance-scam phase, though not every romance scam reaches an investment platform (opens in new tab).
What is an example of a romance scam that uses brand or executive impersonation?
On September 17, 2024, operators of two fake crypto platforms (opens in new tab), NanoBit and CoinW6, faced the first U.S. Securities and Exchange Commission (SEC) enforcement actions alleging relationship investment scams after building trust on LinkedIn, WhatsApp, and Instagram before steering victims to the sites. Fraudsters have also copied a registered professional's name and Central Registration Depository (CRD) number into a fake BrokerCheck report (opens in new tab) impersonating Financial Industry Regulatory Authority (FINRA) records. In each case, the impersonated firm may need to respond to victim reports (opens in new tab) and alert regulators (opens in new tab).


