Lately, I’ve been encountering scammers who promise "free lessons," "career advancement," "business partnerships," and more. These ads frequently pop up on Instagram, and I often see many students commenting with a simple "+" or "I’m interested" under these posts. Given that courses in many fields typically cost upwards of 200 AZN, these offers are very tempting. Once people believe these offers and make contact, they fall into a trap we call "Social Engineering."
What is Social Engineering?
Social Engineering might sound like a sophisticated technical term, but it is actually a common attack method used by scammers.
This technique is based on manipulating the victim through psychological methods rather than technical ones (hacking).
A widely spread form of social engineering today is the Phishing attack.
What is a Phishing attack?
Phishing attacks involve sending the victim a specially prepared URL (link) and engaging in communication to trick them into clicking it.
Scammers usually start by creating artificial panic. For example, they might claim your account has been hacked and that you must click a link to recover it. The moment you click, you are redirected to a fake site built by the scammer. These sites are often highly accurate copies of real websites.
As soon as you mistake it for the original site and enter your personal credentials, that information falls directly into the scammer’s hands.
What are "Red Flags"?
In social engineering, scammers often exhibit certain suspicious behaviors while trying to convince their victims. The best way to protect yourself is to analyze and evaluate these suspicious signs.
A Red Flag is a warning sign that something is dangerous, unreliable, or fraudulent. If the information in a message is inconsistent, if they avoid providing specific details, if they demand payment for no reason, or if they create an artificial sense of urgency ("limited spots," "if you don't buy today, it won't be available tomorrow, etc."), these are all Red Flags.
Not every Red Flag guarantees the person is a 100% scammer, but it definitely requires you to be cautious. Some Red Flags can be false alarms. For example, avoiding specific information isn't always a sign of a scam; it could be company policy.
In summary, Red Flags don't guarantee you are being scammed, but they are a signal to be extra vigilant.
My Experience: The Social Engineering Trap
While browsing a well-known classifieds site, I saw a listing for a "free training" course. It claimed to teach 4 different financial fields in just 8 lessons, and it was advertised as completely free.
I contacted the course via WhatsApp to register. They provided the syllabus, the schedule (how many days and hours per week), and the start date. Finally, they claimed that the "free training" required a certificate and that I had to pay for it. They sent a very hollow and nonsensical response about why this was mandatory, claiming "it is a project and the company name must be noted."
Another Red Flag was the methodology of the syllabus. The syllabus was clearly generated entirely by AI, and the topics they claimed to cover were too broad and disconnected to be taught in just 8 lessons.

The syllabus is thrown together, and they avoid answering direct questions.
In reality, one could conclude this was a social engineering attempt based on the first two Red Flags alone. I continued the conversation to see what the next steps would be.
I pretended to agree, expressed interest in taking the course, and asked for the payment method. As I expected, instead of a formal payment system, they sent a card number to perform an informal card-to-card transfer.

They are demanding a card-to-card payment and that I send a receipt.
Of course, I didn't pay; I was just measuring their reaction. After that last message, the tone of the conversation changed.
In a normal scenario, free courses should provide certificates without requiring payment. Demanding payment falls under the category of consumer deception, especially since the course was advertised as "free."
Even if you paid for these types of trainings, you wouldn't receive quality education. These are just money traps or low-quality mini-courses created by AI in a short time.
Back to the chat: I asked why the syllabus was prepared poorly by AI and why the certificate was paid. The answers I got were just attempts to distract from the subject.
One of the biggest Red Flags was this: They claimed to have been holding classes since 2025 and that 8 groups had finished so far. I asked them to send photos of these classes, and they redirected me to their social media page. Interestingly, all the posts on their social media were AI-generated, and there wasn't a single photo of actual classes.
When I asked how they could fit so many topics into the two lessons in the AI-generated syllabus, the response was:
"We don't guarantee that..."
Then, the other party gave up and ended the conversation: "Anyway, if you don't want to join, that's fine, we don't have to prove anything to anyone 🙏 good luck."
Note: Despite reporting this as fraud to the well-known classifieds site that hosted the ad, the listing was not removed.
How Can You Protect Yourself?
While it is impossible to be fully protected from such attacks, you can reduce the risk:
- Don't fall for FOMO (Fear of Missing Out): If the other party tries to rush you into making a decision with phrases like "Spots are limited" or "Today is the last day," don't let them pressure you.
- Ask for Proof: If they claim something, ask them to substantiate it. If they dodge the question, it's a Red Flag.
- Be careful when paying: Legitimate companies never demand card-to-card transfers. Such transactions should always involve an invoice or a legal entity.
- Check official sources: Verify the party's information. Check their official website, tax ID (VÖEN), and whether the company name exists and matches their claims.
Conclusion
As you can see, social engineering attacks can be easily detected with Red Flags. In this specific conversation, we encountered several Red Flags from the start. Once you spot these, you should stop all communication with the party.
These types of attacks mostly target students, those with no work experience, people urgently looking for a job, and young people. If you are in one of these groups, the likelihood of them exploiting your inexperience is higher.
I wrote this article to inform you about this topic and to encourage you to be more cautious.
Footer
If you liked this article, don't forget to share, like, and share your thoughts to help educate more people.
Also, if this article is well-received, I will share an article about a much more dangerous model of the social engineering attacks I've encountered.
Thanks for your time!


Top comments (0)