惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

WeLiveSecurity

The quest for greater tech independence Why geopolitical turmoil is a gift for scammers, and how to stay safe FrostyNeighbor: Fresh mischief and digital shenanigans Eyes wide open: How to mitigate the security and privacy risks of smart glasses Fake call logs, real payments: How CallPhantom tricks Android users Fixing trivial passwords is as easy as 123456 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack This month in security with Tony Anscombe – April 2026 edition The calm before the ransom: What you see is not all there is GopherWhisper: A burrow full of malware New NGate variant hides in a trojanized NFC payment app Ransomware’s back office: What the ransom note won’t say Why that next data breach alert could be a trap Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition
OfferUp scammers are out in force: Here’s what you should know
2026-02-04 · via WeLiveSecurity

Scams

The mobile marketplace app has a growing number of users, but not all of them are genuine. Watch out for these common scams.

04 Feb 2026  •  , 6 min. read

OfferUp scammers are out in force: Here’s what you should know

OfferUp has been in business for nearly 15 years. Although little known outside the US, the marketplace app competes for consumer hearts and minds with industry giants Craigslist, Facebook Marketplace and eBay. And like them, it has a problem with fraud. If you’re looking to buy or sell on the platform and want to stay clear of the scammers, read on.

Top 10 OfferUp scams

OfferUp claims to process over 30 million transactions each year. That’s inevitably going to attract some users with nefarious motives. Here are the most common scams you may encounter on the platform:

Counterfeit items

Beware of high-value items that turn out to be rip offs. The seller will typically try to persuade you to pay via a third-party service (e.g., Zelle, Venmo) rather than through the app, as doing so means the item won’t be covered by OfferUp’s Purchase Protection.  

Payment scam

As above, scammers (whether buyer or sellers) will often try to trick you into transacting via third-party cash app services. They may:

  • Promise to pay above the asking price for a product you’re selling, in order to persuade you to agree to them using a cash app. They then overpay using a stolen account or fake check, and ask for a refund. If you pay it, you’ll eventually be down the refund, plus your item, and may be asked to repay the original fraudulent sum
  • Ask to pay via gift cards, which turn out to be fake or with zero value
  • Claim to be out-of-town sellers, requesting cash-app payment for items they never end up shipping
offerup scam 1
Source: Reddit

Account takeover

A buyer asks you for a verification code in order to ‘verify’ your listing, for instance through Google Voice. In fact, they’re usually trying to log into your account and need the two-factor authentication code sent by OfferUp. If you hand it over, they get control of your account, enabling them to access your personal information and potentially use your account to scam others.

Empty box

Some sellers add disclaimers in a lengthy item description saying they are only offering the box or a digital photo of the item. So when it arrives, all you’ll receive is an empty box.

Phishing links

Scam buyers and sellers might send you a message saying something like “click here to get paid” or “click to verify your info”. Doing so will take you to a phishing site where you’ll be asked to fill in your logins, payment details and/or other sensitive personal information.

offerup scam 2
Source: Reddit

Email phishing

Some buyers or sellers might ask for your email address or phone number during the transaction process. They’ll use it to spam you with malicious links designed to steal your information or install malware on your device.

Deposit scam

A seller posts a high-value item, offering to deliver it to you as long as you put a deposit down to secure it. It turns out the item doesn’t exist, and you’ve lost the deposit.

offerup scam 3
Source: Reddit

Bouncing checks

A scammer pays for an item you’re selling via check, which bounces several days later, leaving you without the item and no payment.

Investment opportunity

A seller posts a listing about an “investment opportunity” or similar, but requires you to send money first.  

Fake jobs

Scammers may pose as employers that require upfront payment for ‘background checks’ or similar. Alternatively, they may request you fill in your personal and financial details as part of the ‘application process,’ which they can use for identity fraud.

What OfferUp protects

OfferUp offers 2-day Purchase Protection for buyers, meaning that you have 48 hours from delivery to file a claim for items:

  • Significantly not as described
  • Damaged in transit
  • Counterfeit

You can also file for items not received and/or empty box scams.

However, OfferUp will not offer protection for anything purchased off-app, or that violates its rules (e.g., gift cards, alcohol), or that was paid for in cash, in person.

What to look out for

When you’re browsing the app, the following should all be red flags:

  • Deals that are too good to be true, usually from fraudulent sellers who want you to put a deposit down, or scam buyers wanting to persuade you into transacting off app.
  • A buyer profile with no history. This isn’t necessarily a scammer, but it pays to be extra cautious
  • A suggested meetup point that’s not a Community Meetup Spot, as this could indicate they want the transaction not to be observed
  • A buyer/seller asks for a verification code, which they actually want to log into your account
  • Buyers/sellers send you messages containing links to ‘verify’ or similar
  • A seller tries to use urgency to rush you into making an unwise decision, like buying a counterfeit item or putting a deposit down for a non-existent item.
  • Emotional manipulation, such as scammers saying they can't meet in person because they are in the military or out of town on family emergency
  • Phrases like "box only," "digital photo," or "replica" hidden in a lengthy product description
  • Requests to pay off app
  • Stock photos of items rather than ones they’ve taken themselves, indicating they don’t actually own the product
  • Overpayment for an item

Staying safe

To stay safe on the app, the advice is very simple: don’t leave it and don’t click on any dubious links. That means never leaving the app for messaging or payments, never handing over your personal details, and not responding to messages with links in them. If you arrange an in-person sale, make sure it’s at a Community Meetup Spot. And if you want to be ultra careful, only buy from or sell to a user with a “TruYou” badge on their profile, indicating their identity has been verified.

I’ve been scammed, what next?

If the worst-case scenario comes to pass, report the scam to OfferUp immediately, in case you’re covered by the firm’s 2-day Purchase Protection. In Messages, tap the conversation with the scammer and the three dots in the corner, then Report. Submit a Purchase Protection claim in the OfferUp Help Center.

If you’ve paid outside of the app, contact your bank to file a chargeback (if a card payment) or file a report with the cash app you paid with. The latter is unlikely to get your money back, but may help get the scammer banned.

If you’ve shared personal information or a verification code with a scammer, change your app passwords, and do the same for any sites you reuse the same credential on. Monitor your bank accounts for unusual activity. And be wary of any follow-up phishing attempts that pop into your inbox/messages.

Finally, consider reporting the scam to the authorities, eg FTC, FBI or Report Fraud (UK). Before you delete messages or block the user, take screenshots of the original listing, the scammer’s profile, your chat history and any payment receipts.

OfferUp is great way to pick up bargains in your area, or make a little extra money from items you no longer need. But remember, not everyone is acting in good faith.