Skip to main content

Case Study: Romance Scams

Ting-Fang Yen ; Markus Jakobsson (2016) — Understanding Social Engineering Based Scams

What do these research terms mean?
Preprint
A manuscript shared before formal peer review and publication. Check whether a later published version is available.
Dataset
A collection of data or examples for others to inspect or reuse. It can appear in Library search and topic mapping, but RSRC does not use dataset records as evidence in Research Insights.
Dissertation or thesis
Research submitted for an academic degree. This describes its format, not its reliability.
Journal article
An article published in a journal. This label alone does not establish peer review, study quality, or how well the findings apply elsewhere.
Qualitative research
Examines experiences, meanings, or processes, often through interviews or observations. It can explain how something happens without estimating how common it is.
Quantitative research
Uses numerical measurements to describe patterns or test relationships. A relationship between two measurements does not by itself show that one causes the other.
Systematic review
Uses a planned, documented method to find and assess research addressing a question. Its conclusions still depend on the included studies and what the search covered.
Meta-analysis
Statistically combines results from multiple studies. Combining studies does not remove weaknesses in their design or make unlike populations interchangeable.
Not classified
This record has no recognized label in this filter. It does not mean the publication used no method, or that no research exists.

Definitions draw on DataCite resource types; Cochrane review methods; NLM: association and causation. RSRC’s dataset and classification rules are explained in our methodology.

Citation tools


              
              

Transparency

Evidence and review status

This page contains AI-generated content. No human content review or subject-matter-expert review is recorded.

Source basis
Downloaded PDF
Source updates
No notice found at last check
AI-generated page content
Yes
Automated checks
Passed
Administrative approval
Yes
Human content review
Not recorded
Subject-matter-expert review
Not recorded
How this was prepared
Source basis

RSRC downloaded and privately stored a copy of the paper for internal analysis. The PDF is not offered to viewers from this page.

  • PDF added to RSRC:
Source updates

No incoming update notice was found in the dated Crossref response. Coverage is incomplete, particularly for corrections and expressions of concern; this is not a guarantee that the source is valid or unchanged.

  • Last source-status attempt:
AI-generated page content

AI-generated research notes displayed on this page: Synopsis, Identified gaps, Methods, Limitations, Future work. The paper itself is not described as AI-generated.

  • Document analysis recorded:
  • Synopsis generation recorded:
  • Page record updated:
Automated checks

The current, source-bound synopsis passed the recorded versioned publication checks.

  • Checks completed:
View passed checks (3)
  • Length, completeness, repetition, refusal, boilerplate, and active-markup screening
  • Numerical claims checked against the available source text
  • English-source lexical grounding check
Administrative approval

The record is approved for public display, but a complete historical administrator action is not recorded.

Human content review

No human review is recorded for the AI-generated content displayed on this page.

Subject-matter-expert review

RSRC has not recorded review of this content by a subject-matter or methods expert.

Review-state definitions
Found a possible error? Request a correction.

Synopsis

This publication presents a multi-chapter examination of social engineering and related scams, with Case Study: Romance Scams as one of several focal points. It frames the study as part of a broader effort to measure, understand, and counter online fraud, describing tangible data-gathering and analysis approaches used across several scam types. The work situates romance scams within a larger taxonomy that includes sales, rental, business email compromise, and other categories, and it emphasizes the need for empirical measurement, pattern discovery, and intervention points rather than generic warnings. Across the volume, the authors describe a common methodological backbone: automated data collection, pattern clustering, and analysis of attacker infrastructure and monetization. Notably, the sales and rental case studies rely on large-scale crawling of classified-ad platforms, automated honeypot interactions, and conversational engines to elicit and study scam responses. Findings from these chapters highlight that a small number of scam groups account for a large share of activity, that scams often rely on cross-site cloning and fake payment schemes, and that a sizable portion of scammers originate or route through certain geographic clusters. The work also documents gaps in existing defenses and points to concrete levers for disruption, such as targeting prolific scam groups, improving payment-based monitoring, and enhancing brand- and storyline–based detection techniques. Limitations in the presented material include reliance on specific platforms (notably Craigslist-like ecosystems) for measurement and the potential non-generalizability of certain findings to all romance scams or other online fraud domains. The volume argues for continued, methodical measurement and targeted intervention as essential components of fraud prevention, grounded in observed attacker behavior rather than generic advisories. The Romance Scams case study contributes to this empirically anchored, domain-spanning narrative.

Identified Gaps

Traditional filters have difficulty identifying low-volume, targeted romance scams, especially affiliate first-round messages that change frequently and use Craigslist pseudonyms. The authors identify a need for scalable detection of reused romance scripts, better attribution, and timely intelligence collection. The study also leaves victim experiences, victim losses, and effectiveness of proposed countermeasures unmeasured.

Methods

A 3-month (April–July 2015) case study used magnetic honeypot personal advertisements posted on Craigslist’s men-seeking-women forums. Ads were placed in the 100 slowest U.S. Craigslist cities using 20 accounts. Researchers manually labeled 541 responses into scam categories. During the final 2 months, a simulated spam-filter auto-response measured link clicks and replies and collected IP-address and user-agent information from clickers.

Limitations

The evidence comes from responses to deliberately implausible honeypot ads in only the 100 slowest U.S. Craigslist cities, rather than observed victim–scammer interactions. Only 541 responses were collected over 3 months, and just 8 were real responses. Location inferences based on SMTP timestamp/timezone or IP address may not reflect scammers’ true locations; the authors note mail-server timestamps do not necessarily reflect sender timezone and one apparent Canadian source may have used hosting to obscure location.

Future Work

Develop low-volume targeted-scam detection using headers, content, and recipient reactions; detect reused romance-scam text segments and automatically expand reuse signatures; improve attack attribution; test user-interface countermeasures; integrate scam filters with honeypots and automated conversations; and strengthen collaboration among service providers, technology organizations, academia, and government.

See how this publication connects to RSRC's living evidence syntheses through current citations and research-topic mapping.