This is the working picture we keep of how scam material is arriving at business contact forms and inboxes, published as it stands rather than rewritten for an audience. It is dated because it will go out of date, and we would rather you could see that than take our word for it being current.
What this is not: a dataset of our own. We do not yet have the traffic to publish first-party measurements, and we will not pretend otherwise. Everything numeric below is attributed to someone else, with the date we read it. Our own observations will appear in the signals section when they clear the thresholds set out in our methodology.
Two tells that stopped working
These matter more than any individual scam pattern, because they invalidate the assumptions underneath a lot of deployed filtering.
Poor writing no longer indicates junk
Reported figures put AI-generated content in the large majority of phishing messages, and Microsoft's own testing found AI-assisted attempts achieving roughly four and a half times the click-through of standard ones. The practical effect for a contact form is that the scam arrives fluent, correctly punctuated and neatly structured, while the genuine customer thumbing a message on a phone produces the mess.
Naming the business no longer indicates a genuine enquiry
Personalisation is now cheap at scale. A generated message can reference a business's suburb, its services, its owner and its recent work, for thousands of businesses at once, because all of it is on the public web. A message that knows who you are is no longer telling you anything it had to earn.
Why the contact form specifically
A form submission is sent by the receiving business's own web server or form service, so it arrives from trusted infrastructure carrying that business's own sending reputation. Ordinary email filtering, which leans heavily on the envelope, never gets a meaningful look at it. We have written about this at length in why your contact form still fills up.
Three abuse shapes follow from that property:
- Auto-reply as a relay. A copy-to-sender option or any auto-confirmation will deliver attacker content from trusted infrastructure to an address the attacker chose. One documented incident produced roughly 149,700 emails from a single such feature.
- Confirmation as impersonation. Lookalike sending domains registered with a chosen display name, driven through form confirmations so a trusted third party carries the identity. Concentrated in legal, finance, healthcare and insurance.
- Volume as reputation damage. Sustained submission can exhaust resources and get the business's own sending infrastructure blacklisted, which is a cost well beyond nuisance.
Automation is no longer crude, and there is a human tier
Bots run headless browsers, execute JavaScript, hold plausible timings and submit well-formed payloads. The hidden-field and timing checks most forms already carry still remove a great deal of traffic, but they now catch the cheap end of it. Their silence is not evidence a message is genuine.
Above that sits a fully human tier: real people sending real pitches and real scams by hand. No visitor challenge can stop them, because they are visitors. Nothing about the connection tells them apart from a customer, which is the difficulty this whole category exists to address.
Fraud patterns in heavy circulation
- Overpayment and advance-fee
- An unusually large or vague order, payment by a reversible instrument, an overpayment, and a request to forward the balance onward.
- Supplier and payment redirection
- A claim that banking details have changed, often referencing a plausible invoice or an existing relationship, sometimes following a real thread convincingly.
- Authority impersonation
- Presenting as a bank, a courier, a government body, a platform, or someone senior at the business itself, with urgency and a request for payment, credentials or an account change.
- Credential harvesting
- The payload is a link to a sign-in page. Some now present a CAPTCHA first, because a challenge makes a page look legitimate and deters automated inspection. There is a certain irony in a scam using a CAPTCHA to appear trustworthy.
- Obfuscated destinations
- QR codes, vector images carrying links, redirect chains, shorteners, and link text describing a destination different from the actual target.
- Channel switching
- The form message exists only to open a channel, moving quickly to a phone number or messaging app where the pressure is applied and nothing is logged.
What none of this changes
A real customer is still a real person contacting a business about something it does. Nothing above makes a message junk on its own, and none of it is a reason to be certain. Where it is not clear, the honest answer is that we do not know, and a message we do not know about reaches the business rather than being held on suspicion.
That is the part worth insisting on. Every item in this brief could be used to justify holding more messages, and this field drifts that way, because holding too much produces the quiet error. A real enquiry that was held costs a business a customer and tells nobody it happened. We would rather be wrong in the other direction, and we are built to be. Genuine enquiries are never silently lost.
Revisions
10 August 2026. Passages describing how our own system reaches a decision were removed. This brief covers what senders are doing, not what we do about it. We publish how our claims are measured, not the signals used to reach a verdict.