• Watch Out for Scammers!

    We've now added a color code for all accounts. Orange accounts are new members, Blue are full members, and Green are Supporters. If you get a message about a sale from an orange account, make sure you pay attention before sending any money!

SOLD SCAMMER ALERT, sneakypayioad

sneakypayload

Shoot at things semi far away
Supporter
Full Member
Minuteman
Mar 23, 2021
297
183
MO USA
https://www.snipershide.com/shooting/members/sneakypayioad.216681/ or @sneakypayIoad

Because of the type used on this website, an i looks like an l for usernames, this is bad admins.

The members URL and it's limited. Please be careful out there guys, he got someone tonight.

@admins, ya'll need to do some housekeeping on how profiles are made, created, and posting is done. This is security 101. Fonts on the webpage shouldn't be hard to distinguish, or whatever the default font is.

For anyone out there attempting to BST. Try to only deal with members that have some feedback, don't give money to day 1 accounts, and verify who you're talking to. if they aren't willing to talk to you on the phone for an item that costs a bunch of money, whether it's 100 bucks, or 1k, pass on the sale.
 
If you have specific recommendations, please offer them. The lack of visual difference between i and l has as much to do with zoom level (user controlled) as with font choice. For example, if you have a font to recommend, please do so. "Do some housekeeping" is vague and unhelpful. Specifically what "housekeeping" would you recommend they do? Should be easy since this is "security 101." Agree 100% with the last paragraph.
 
I'm the idiot who got scammed btw. $450. I checked the feedback of sneakypayload, but stupidly only did so from the original WTS post, not in DMs where the scammer pretended to be him.
 
If you have specific recommendations, please offer them. The lack of visual difference between i and l has as much to do with zoom level (user controlled) as with font choice. For example, if you have a font to recommend, please do so. "Do some housekeeping" is vague and unhelpful. Specifically what "housekeeping" would you recommend they do? Should be easy since this is "security 101." Agree 100% with the last paragraph.

It's not lack of zoom level. it's the font used. I'm accessing this on my computer, and on multiple machines the "i" in sneakypayioad for the tagged version differs.

And like GBMaryland said, any exchange profile should be open and public.
 
  • Like
Reactions: BoldCorrections
And some simple suggestions:

1. FORCE 2FA. Don't make it an option, make it an actual site requirement to sign up. It's 2023, even the 80 year old users on here have a smartphone. If you cannot figure it out, too bad.
2. Everyone should go through an approval process for buying and selling on here, not just sellers. I'm not saying charge everyone 200 bucks a year, but extended verification of some sorts needs to happen.
3. HEAVILY restrict new accounts. If an account is less than 30 days old, it shouldn't be able to send/receive any DM's.
4. Hide the BST forum for any account under 30 days old.
 
This isn’t the admins fault. It’s pretty text book that upper case i and lower case L are almost impossible to distinguish. If you’re going to blame it on admin then you could just as easily be blamed for picking a username that’s so easy to duplicate, but we wouldn’t want to take any responsibility, would we?

Be smarter about your transactions when buying. If the buyer had checked your profile and/or didn’t post “I’ll take it” then this would have been avoided.
 
Oh my, security 101. I {not lower case L} bet Lowlight will get right on taking all your suggestions if you just PM him whats wrong with his sight. :ROFLMAO::ROFLMAO::ROFLMAO: Word of warning. I have never seen calling out the sight over a scam go well.

There are threads warning about this exact thing happening on this sight. The superintendent of the schools here was scammed for 300K by the same kind of scam. They hacked and monitored communications with a legitimate business. Then when it was time to pay, they stepped in and sent the wrong account info. If you haven't heard of this kind of scam before, you're lucky because its not new. Just new to this sight.
 
  • Like
Reactions: match308
I do not deal with anyone without feedback and/or several months on the site. In one case I was questioning if it was legit, the seller actually shipped the item to me before I paid. It all went well, and afterwards the new guy had positive feedback. If there is a new account that you want to buy from, they should be open to this idea IMO, if not, move on the next guy.

CM
 
Happened to me here. I caught the fraudster by noticing the account they PMd me from having no feedback or followers.
 
  • Like
Reactions: sneakypayload
LowIight would love nothing more than to shut the PX down. I think I’ve heard him say it alone causes 90% of the headaches for him. Also, there’s a special place in hell for scammers.
 
  • Like
Reactions: match308
Oh my, security 101. I {not lower case L} bet Lowlight will get right on taking all your suggestions if you just PM him whats wrong with his sight. :ROFLMAO::ROFLMAO::ROFLMAO: Word of warning. I have never seen calling out the sight over a scam go well.

There are threads warning about this exact thing happening on this sight. The superintendent of the schools here was scammed for 300K by the same kind of scam. They hacked and monitored communications with a legitimate business. Then when it was time to pay, they stepped in and sent the wrong account info. If you haven't heard of this kind of scam before, you're lucky because its not new. Just new to this sight.
It's not a matter of calling out the "sight". It's a matter of making it better for everyone that pays what, 200 dollars a year to be able to B/S/T on here?

Frank and crew do an excellent job with the "sight", but scammers utilizing this site scamming people out of 100/200/450 and god knows how much more isn't a good thing, it'll reduce potential income for the site. Id rather this place stay around, considering I'm a left handed shooter and 3/4's of the actions and gear I found on here, when it was unavailable anywhere else or had a long lead time.
 
  • Like
Reactions: match308
As one option, Reddit uses this font, which avoids the issue: https://fonts.google.com/specimen/IBM+Plex+Sans?preview.text=sneakypayload

I think it's really easy to think this wouldn't happen to you, and just exclusively blame this on the folks who get scammed for being stupid. But as a frame of reference, I'm the one who was scammed in this instance. I'm a software engineer who was well aware of this sort of scam in general, and I've never been scammed my entire life until now despite countless attempts by folks. I just simply didn't consider this specific type of scam in the timing of how it unfolded.

In fact, I even looked fairly deeply into @sneakypayload's feedback and post history to confirm he was legit. The trouble was that indeed I posted a dibs comment and went to DM him, but at nearly the same moment I got another DM from the scammer, so my mind wasn't thinking "this is a scammer who must have a bot watching threads for matching comments" instead thinking that we simply raced to DM each other since the real @sneakypayload had just replied to the WTS post too. Add in the fact that the scammer wasn't pushy for payment, and made a comment about PayPal being anti-gun which I wouldn't normally expect a scammer to be aware of. Collectively it just didn't activate my suspicious sense like it should have and I was excited when he replied that the item was still (for real) available after several months.

I take responsibility for being scammed, so I'm not blaming them at all or asking anyone to help me. It's not the admins fault, but that doesn't mean there aren't more things that can be done to prevent it and save other people with minimal effort like font choice. It certainly wouldn't prevent it from working sometimes, but even one time is worth it.

If feasible, making accounts which are new more obvious would also go a long way as well for this type of phishing scam. It's not about people doing due diligence, which they should do and I did, it's about scammers tricking people (like me) into thinking they're talking with someone they're not.
 
If feasible, making accounts which are new more obvious would also go a long way as well for this type of phishing scam.

Like putting "Minuteman" under their screen names? :rolleyes:

As mentioned, Frank has talked about doing away with the PX because it is most of our issues. You all need to be smart when sending money and look that PMs are coming from the person selling and not a guy with 0 posts and a period at the end of their name.

If you see an issue REPORT IT! Do not post about it or comment on someone else's post. Report the individual so we can get rid of them.
 
As one option, Reddit uses this font, which avoids the issue: https://fonts.google.com/specimen/IBM+Plex+Sans?preview.text=sneakypayload

I think it's really easy to think this wouldn't happen to you, and just exclusively blame this on the folks who get scammed for being stupid. But as a frame of reference, I'm the one who was scammed in this instance. I'm a software engineer who was well aware of this sort of scam in general, and I've never been scammed my entire life until now despite countless attempts by folks. I just simply didn't consider this specific type of scam in the timing of how it unfolded.

In fact, I even looked fairly deeply into @sneakypayload's feedback and post history to confirm he was legit. The trouble was that indeed I posted a dibs comment and went to DM him, but at nearly the same moment I got another DM from the scammer, so my mind wasn't thinking "this is a scammer who must have a bot watching threads for matching comments" instead thinking that we simply raced to DM each other since the real @sneakypayload had just replied to the WTS post too. Add in the fact that the scammer wasn't pushy for payment, and made a comment about PayPal being anti-gun which I wouldn't normally expect a scammer to be aware of. Collectively it just didn't activate my suspicious sense like it should have and I was excited when he replied that the item was still (for real) available after several months.

I take responsibility for being scammed, so I'm not blaming them at all or asking anyone to help me. It's not the admins fault, but that doesn't mean there aren't more things that can be done to prevent it and save other people with minimal effort like font choice. It certainly wouldn't prevent it from working sometimes, but even one time is worth it.

If feasible, making accounts which are new more obvious would also go a long way as well for this type of phishing scam. It's not about people doing due diligence, which they should do and I did, it's about scammers tricking people (like me) into thinking they're talking with someone they're not.
Perhaps that helps with lowercase L but it does nothing for zero and capital O. So now you’re playing whack a mole trying to solve one specific problem while the scammers have moved on to the next method. So no, if it stopped one person, it isn’t worth it when you’re talking actual ROI. Just my opinion of course.

My recommendation: when you’re having a DM conversation with someone, click on their name from the DM. Do your research from that starting point. NOT from the username in the thread.
 
Last edited:
Like putting "Minuteman" under their screen names? :rolleyes:

As mentioned, Frank has talked about doing away with the PX because it is most of our issues. You all need to be smart when sending money and look that PMs are coming from the person selling and not a guy with 0 posts and a period at the end of their name.

If you see an issue REPORT IT! Do not post about it or comment on someone else's post. Report the individual so we can get rid of them.
Ah. As a new user, I had no idea that Minuteman meant they were new. Sorry for my ignorance. I was trying to help the community learn from my mistake. Just know these attitudes push away users like myself who would otherwise stick around.
 
Ah. As a new user, I had no idea that Minuteman meant they were new. Sorry for my ignorance. I was trying to help the community learn from my mistake. Just know these attitudes push away users like myself who would otherwise stick around.

Not trying to push anyone away but in a community who thinks of themselves as adults a lot of people here act like children and want to be coddled. Stay if you like or go if you are not happy here but the site has been here for 23 years and you have been here less than 24 hours. Maybe look around and learn about the site before telling us how we need to change.
 
STOP REPLYING TO WTS ADDS IN THE ADD AND THE SCAMMER WILL NEVER HAVE A WAY IN.

See something you want? Send a DM. No “dibs”, no “I’ll take it”, no “seconds”, no “dm inbound”.

And sellers need to stop encouraging responses in their adds. When I sell stuff now, you can expect the add to say something to the effect of “no messages in the thread, DMs only”.
 
You can say/write what ever you want. Half the people wont read it and half the people wont listen or understand. You can PM people two line. PP F&F is ok, but no messages. That means don't put what item you bought in the messages. And they will name the item in the message. Scammers will never go away because people do stupid shit.
 
An extremely easy way to avoid this as a buyer is to initiate the PM. That forces you to click on the original poster's screename to PM them.

Then you don't have to worry about the scammer's PMing you with fake names. As you've already PM'd the right person.



Obviously there are other ways to scam, but this 100% fixes this specific scam.
 
I'm the idiot who got scammed btw. $450. I checked the feedback of sneakypayload, but stupidly only did so from the original WTS post, not in DMs where the scammer pretended to be him.
I'm sorry your first transaction here did not go well. Not the idiot, just a combination of bad luck and a missed step.

Problems like these are more a function of forum software being used to facilitate transactions (not the design goal, open to these kinds of exploits) than e.g. fonts or lack of MFA. What you experienced is one reason only the seller sees the full account names of bidders in an auction e.g. on Ebay.
 
Ah. As a new user, I had no idea that Minuteman meant they were new. Sorry for my ignorance. I was trying to help the community learn from my mistake. Just know these attitudes push away users like myself who would otherwise stick around.
Minuteman means the user is unpaid and can't post new threads in PX, which makes it obvious not the OP.

One thing you'll learn from here is that the overall phenomenon is less forgiving than most other online communities but hey, welcome to the shooters world! We fit right into the stereotypes.
 
  • Like
Reactions: match308
Minuteman means the user is unpaid and can't post new threads in PX, which makes it obvious not the OP.

One thing you'll learn from here is that the overall phenomenon is less forgiving than most other online communities but hey, welcome to the shooters world! We fit right into the stereotypes.

No. Minuteman is a newer member. You can add Supporter on top of it by paying to use the PX.
 
25 bucks from a hacked pp account to get access is nothing. Probably needs to be more like a thousand per month. Then the scammers would stay out.

Or maybe people put on thier big boy pants and do their own due diligence and act like adults. If you got scammed and there weren't many blatant signs, you are in the minority. Bunch of whiney dip shits already got selling in the PX put behind a 200 dollar per year pay wall. And it didn't do shit for you. I feel like there must be a literal place named retardville sometimes. Fuck me no wonder Gorden Ramsey screams at people. 🤣🤣🤣
 
I think paying a fee to use the PX, like $25 a year or something would probably kill off alot of issues.
There is a fee to sell on the PX as you know as you are a Supporter. Making people pay to use it won't cure anything but hurt the people paying to sell.

People just need to check who is sending them a PM. If it's someone who is not a supporter and has 0 posts on the site then maybe it's not the person selling the item.