In short
- ✓No real marketplace or courier ever asks a seller to enter card details to receive money. A link that does is a scam.
- ✓If you typed in card data or a code: block the card and call your bank now, then change your passwords.
- ✓Capture the evidence before you report: the chat (behind login) and the phishing page URL (public, often gone within hours).
- ✓Report to the platform, your bank and the police, then use your bank’s refund and complaint routes.
- ✓Unauthorised payments must be reported to your bank without undue delay and in any case within 13 months.
How the “receive payment” link scam works
The scam targets sellers on second-hand marketplaces all over Europe: Vinted, Facebook Marketplace, OLX, Kleinanzeigen, Leboncoin, eBay and similar sites. It is cheap to run, fully scripted and aimed at people who are not expecting a fraudster to be the buyer.
- A “buyer” contacts you shortly after you publish a listing. They accept your price without haggling and often say they are buying for a relative or cannot meet in person.
- They ask to continue on WhatsApp, Telegram, SMS or email, where the platform’s safety filters cannot see the conversation.
- They claim they have already paid through the platform’s “secure payment”, or that a courier such as DPD, InPost, UPS or DHL has arranged collection.
- You receive a link that looks official: the platform’s logo, your item photo, the agreed price and a button like “Receive funds” or “Confirm sale”.
- The page asks for your card number, expiry date and CVV, sometimes your card balance, and then a code from an SMS or your banking app. That code does not receive money. It authorises a payment or links your card to the fraudster’s mobile wallet.
Variants change every few months: a fake “verification fee”, a fake support chat that “helps” you when the first attempt fails, or a second message saying the payment is blocked until you enter a different card. The core is always the same: you are asked to type card or bank data into a page reached through a link.
The buyer-side variant: fake seller, fake secure checkout
The mirror image targets buyers. An attractive item is listed below market price. The “seller” cannot meet, but offers delivery through the platform’s “secure checkout” or a courier’s “buyer protection” and sends you a link. The checkout page looks real, takes your card payment or bank login, and no item is ever shipped.
- The link leads to a domain that only resembles the platform, often with extra words like pay, secure, delivery or order.
- The seller insists you pay outside the normal in-app flow, even when the platform offers built-in payment.
- On sites without built-in checkout, a “Facebook payment” or “Marketplace delivery” link is itself a warning sign.
- Pressure: another buyer is waiting, the reservation expires in 15 minutes, the courier leaves today.
Red flags to recognise the scam in time
- The buyer wants to move the conversation off the platform straight away.
- The buyer agrees to your price instantly, asks no questions about the item and sometimes offers more.
- You get an email, SMS or chat message saying the buyer has already paid, but nothing appears in your account on the official app.
- The link does not lead to the platform’s real domain, or uses a shortener.
- A page to receive money asks for your full card number, CVV, card balance or online banking login.
- You are asked to approve something in your banking app or copy a code from an SMS in order to receive a payment.
- Grammar errors, generic greetings or a new profile with no reviews.
- Urgency and threats: the payment will be cancelled, your account will be blocked, the courier is waiting.
One rule covers almost every case: receiving money never requires your card’s security data. Your bank or a genuine payment provider already knows where to send it.
How to check whether a website is legit before you type anything in →
Already entered card details? The first hour
Speed matters more than anything else here. Fraudsters usually use the card within minutes. Do these steps in this order, and do not wait until you are sure it was a scam.
- Block the card in your banking app, or call your bank’s card blocking line. If you gave your online banking login, ask the bank to block online access too.
- Call your bank and say clearly that your card data was phished. Ask them to check pending transactions, cancel any mobile wallet token that was added and flag the account.
- Do not approve anything else. Ignore new SMS codes, push notifications or calls from “bank security” you did not start yourself.
- Change the password of your marketplace account and your email, and enable two-factor authentication. Change any other account that uses the same password.
- Note down the time you clicked, what you entered and any transactions you see. You will need this for the bank and the police.
- Keep the phishing link and the chat. Do not delete messages or block the scammer yet: the next section explains why.
Capture the evidence before you report
Reporting is essential, but it has a side effect. Once the platform bans the fake account, the conversation often disappears from your inbox. Phishing pages are taken down by hosting providers within hours or days, and scammers rotate domains constantly. If you report first, you may be left with nothing to show your bank or the police.
1. The conversation (behind login)
The chat on the platform, WhatsApp or email is only visible when you are logged in, so no outside service can capture it for you. You have to capture it from your own device:
- Screenshots of the entire conversation, including the scammer’s profile, username, profile link and the listing it concerns.
- The message containing the link, with the full link visible. Copy the link text into a note as well.
- Your platform data: request a copy of your account data under your GDPR right of access, which usually includes messages.
- For WhatsApp or Telegram, the phone number and an exported chat.
2. The phishing page (public)
The fake payment page is a public URL, so it can be captured independently by a server, without opening it again on your phone. Capture it immediately, even before you report it. Use the exact link you received: many kits generate a unique link per victim that shows your item and your price, which ties the page directly to your case.
Why online evidence disappears and how to preserve it in time →
Why a screenshot is not enough, and how to capture it properly
A screenshot is better than nothing, but it is an editable image. It does not show the page address, where the page came from or when it existed, and anyone can fake one in minutes. For a bank dispute or a police report it helps to have something much harder to challenge.
GetProofAnchor makes a forensic capture of a public URL: you paste the phishing link into the web app and our server records the page, so you never open it on your own device again. The Evidence ZIP contains:
- a full-page screenshot plus the complete HTML source of the page,
- a network log showing which servers and domains the page loaded from,
- SHA-256 hashes of every file and an eIDAS qualified timestamp from an EU-accredited provider,
- a Bitcoin anchor and a PDF report, verifiable independently and offline.
For the chat behind login, the browser widget on subscription plans captures what you see in your own logged-in browser, for example the marketplace inbox on the desktop website. If you only need the phishing page, the one-time Starter pack costs 9 € for 3 forensic proofs, with no subscription. No court is obliged to accept any particular evidence, but a sealed capture is much harder to dispute than a screenshot.
How the browser widget captures chats behind login →
Where to report it
The platform
Report the profile and the conversation using the in-app report button, and forward phishing emails to the platform’s abuse or support address listed in its help centre. Mention the phishing URL. This protects other sellers and creates a record on the platform’s side that your bank or the police may later request.
Your bank
Tell your bank in writing, not only by phone, that your card data was obtained through a phishing page and that you did not authorise the payments. Attach your notes, screenshots and the evidence files, and ask for a written reference number.
Police and national channels
File a police report for fraud. In most EU countries this can be done at any police station and often online. Bring the phishing URL, the scammer’s profile and phone number, the transactions and your evidence. Many countries also have a national reporting point for phishing and cybercrime, and banks often ask for the police reference before they decide on a refund.
How to report a scam website and get it taken down →
Getting your money back
Under EU payment rules, you have to report an unauthorised card payment to your bank without undue delay and at the latest 13 months after the debit. The bank must then refund an unauthorised payment unless it can show fraud or gross negligence on your side. With phishing, banks sometimes argue that you approved the payment yourself with a code. Whether that holds depends on the details, and first-time marketplace users are not automatically negligent.
- Seller side: ask for a refund of the unauthorised payments and dispute any transaction you did not recognise.
- Buyer side, paid by card: ask your bank about a chargeback because the goods were never delivered.
- Buyer side, bank transfer: ask the bank to try a recall immediately. The sooner, the better the chances.
- If the bank refuses, use its complaint procedure and then the free banking ombudsman or dispute resolution body in your country.
In every case the same thing decides the outcome: what you can prove about how the scam happened. A clear timeline plus sealed evidence of the phishing page and the chat makes your position much stronger.
Step by step: how to get money back after an online scam →
Platform notes: Vinted, Facebook Marketplace, Kleinanzeigen, Leboncoin, OLX
- Vinted: buyers pay inside the app and the money reaches your Vinted balance after the order is completed. Vinted states that sellers never need to enter card details to get paid.
- Facebook Marketplace: in most European countries there is no built-in checkout, so any link to a “Facebook payment” or “Marketplace delivery” page is a strong warning sign.
- Kleinanzeigen: the official payment feature works only inside the Kleinanzeigen app or website. Fake emails and pages copying it are one of the most common scams in Germany.
- Leboncoin: secure payment and delivery are handled inside your leboncoin account. Messages sending you to an external page to receive money are fake.
- OLX and courier-themed scams: fake pages imitating the platform’s delivery service or couriers like DPD, InPost or UPS ask sellers to “receive” payment with a card.
What to capture on Vinted, and how →
What to capture on Facebook Marketplace →
Evidence guides for all major platforms →
How to protect yourself next time
- Keep every conversation and every payment on the platform. Decline requests to move to WhatsApp or email.
- Check payments only in the official app or by typing the website address yourself, never through a link.
- Treat any request for card details, CVV, balance or banking codes in order to receive money as proof of a scam.
- Set up card spending alerts and lower online limits in your banking app.
- If something feels off, stop and capture the chat and the link before you do anything else.
Capture it before it disappears
Turn the page into evidence in 2 minutes
Paste the URL and get a sealed Evidence ZIP with an eIDAS qualified timestamp — much harder to challenge than a screenshot. No subscription needed.
Verify an existing proof → · Guides for Airbnb, Vinted, Amazon & more →
Related guides
-
Get money back after an online scamBank refunds, chargebacks, recalls and complaint routes explained.
-
Evidence from VintedWhat to capture on Vinted before a dispute or report.
-
Evidence from Facebook MarketplaceHow to preserve listings, profiles and chats from Marketplace.
-
Fake delivery SMS scamThe courier-themed text messages that lead to similar phishing pages.
Frequently asked questions
Can a marketplace really require me to enter my card to receive money?
No. Vinted, Kleinanzeigen, Leboncoin and similar platforms pay sellers through their own payment system to your account balance or bank account. A page asking for your card number, CVV or a banking code to receive money is a phishing page.
I only clicked the link but did not enter anything. Am I at risk?
Usually the danger starts when you type in data. Close the page, do not enter anything, and run a security scan if you downloaded a file. Still capture the link and the chat and report the profile, so the scammer cannot target others.
I entered my card number and a code from my bank. What now?
Block the card immediately and call your bank. Tell them the code was obtained by phishing and ask them to check for new mobile wallet tokens and pending payments. Then change your passwords and capture the evidence before reporting.
Should I report the scammer to the platform straight away?
Yes, but only after you have captured the chat and the phishing page. Once the account is banned, the conversation may disappear from your inbox, and phishing pages are often offline within hours.
Will my bank refund me?
Banks must refund unauthorised payments unless they prove fraud or gross negligence. With phishing codes the answer depends on the circumstances. Report quickly, in writing, with evidence, and use the banking ombudsman if the bank refuses.
Can I capture the phishing page without opening it again?
Yes. A server-side forensic capture visits the public URL from our server and records the page, source code and network traffic, sealed with a qualified timestamp. You only paste the link, nothing runs on your device.
This article is general information, not legal or financial advice. Refund rules and reporting procedures vary by country and bank, so contact your bank and the police as soon as possible.