A copy of the Fiverr website tells a freelancer that a buyer has already paid for an order and that the money is waiting. To release it, the page says you must verify a bank card. A support chat opens by itself and repeats the request, and only a bank card is accepted. The card step happens on a second website, which asks for the card number, expiry date and security code. The page is not Fiverr, and anything typed into it does not reach Fiverr. Being paid never requires your card number or security code.
Step 1: You reach a page that looks like Fiverr, with the familiar logo, menus and footer. It shows an order a buyer has supposedly already paid for.
Step 2: A support chat opens by itself. It says the buyer's payment is waiting, and that you need to give card details so the money can be sent to you. It calls this a one-time identification.
Step 3: The page asks how you want to be paid, but a bank card is the only option it will accept. Nearby labels promise the page is encrypted and that no charge will be made.
Step 4: A press and hold button appears, described as a security check before confirming your order.
Step 5: The card step happens on a different website, which asks for the card number, expiry date and security code.
Step 6: While all this happens, someone is working the page live. The page reports back whether you are still on it, and the person at the other end can move you on to the next step.
✓ Do this
✗ Avoid this
Do not reply, pay, or use contact details in an unexpected message. Verify through the official app or website, then report what you saw so the Archive can connect related patterns.
Don’t call numbers or click links in unexpected messages. Go directly to the company’s official site or app and contact support from there.