Back to glossary

Advance-fee fraud (419 scam)

7 min read

Advance-fee fraud, also known as the 419 scam or the Nigerian letter, promises a large sum of money and then asks for a series of small payments to unlock it. It is pure social engineering with no technical component at all, which is why no antivirus will ever see it.

July 30, 2026
Compartir:

What it is

The scam promises the victim a very large sum of money they can only reach with the victim’s help, then asks for small payments covering fees, taxes or commissions that supposedly release the transfer. The promised money does not exist; the payments do.

The name comes from the era when these requests arrived by post and by fax from Nigeria, and the 419 label comes from the article of the Nigerian penal code that covers this kind of deception. Today the technique is run from anywhere, and the name describes the historical origin of the fraud rather than whoever runs it now. The neutral description, and the one that says exactly how it works, is advance-fee fraud.

There is nothing technical about it. No exploit, no malware, no software flaw to patch. It is social engineering, and all of its machinery sits in the text of the message.

It survives because it is cheap. Sending a million messages costs almost nothing, and the operator only needs a very small number of people to reply for the operation to pay for itself.

How it works, step by step

The approach. An unsolicited message arrives with a story explaining why they are writing to you specifically: an unclaimed inheritance, a prize, frozen funds, a contract that has to be signed from outside the country.

The filter. The story is usually implausible on purpose, complete with the spelling and the inconsistencies you would expect. That is not carelessness: whoever replies to something that crude is exactly the profile that will keep replying later, and the operator saves time by discarding everyone else.

The relationship. Once there is a reply, the tone changes. Official-looking documents appear, with stamps, case references and sometimes a third person playing a lawyer or an official. The victim stops dealing with an email and starts dealing with a story that now has characters in it.

The first payment. It is always small relative to what has been promised: a fee, a tax, an administrative cost. It is the step that turns a conversation into a fraud.

The escalation. After the first comes another, and another. Each is justified by a new obstacle, and each rests on the last: the more the victim has paid, the harder it becomes to accept that the money is gone. That mechanism, rather than the initial credulity, is what keeps the fraud running.

The ending. It ends when the victim runs out of money or stops. And there is sometimes a second act: somebody gets in touch offering to recover what was lost, in exchange for an advance. It is the same scam applied to the same person.

Advance-fee fraud and CEO fraud

Both are email fraud and both depend on somebody authorising a payment, but they are defended very differently and it is worth not lumping them together.

Advance-fee fraud CEO fraud and business email compromise
Who it targets Anyone, at scale One named person who can move money
What the operator knows about you Nothing Your org chart, your suppliers and your calendar
Plausibility Deliberately low, to filter Deliberately high, to avoid suspicion
Where the money comes from The victim’s own pocket The company’s account
What stops it Recognising the pattern A payment verification procedure
Who the victim is A person The organisation

For an organisation the real risk is usually not the first one. An employee who falls for a 419 letter loses their own money; an employee who falls for business email compromise transfers the company’s.

They do share the one defence that genuinely works against email fraud: no transfer should ever depend on a single message and a single person.

How it has evolved

The channel has changed several times. From letter to fax, from fax to email, and from email to text messages, social networks and messaging apps. The structure of the deception has never changed.

The pretext has been updated too. Where there used to be an inheritance, there is now a cryptocurrency investment, a very well paid remote job, or a romantic relationship cultivated for months before the first request for money appears.

And the messages have started to be better written. Text generation tools have removed the language barrier, which used to be one of the signals that helped people recognise them. That does not change the defence, but it does take away a clue.

What is genuinely new is the move into the corporate world. The same groups found that the same script, aimed at a company and sent from the right address, moves far more money per attempt, and that is where the CEO fraud and fake invoice family comes from.

Common mistakes

Assuming only naive people fall for it. The initial filter is crude, but the rest of the operation is not: there are documents, characters and months of conversation. And with every payment made, walking away costs more.

Replying to string the scammer along. Replying confirms the address exists and that whoever uses it answers, and that is worth selling. The correct response to a message like this is no response.

Treating it as a domestic problem. Somebody receiving these in their work mailbox is receiving everything else in the same inbox. If they do not know where to report them, they will not report the one that was serious either.

Measuring training by attendance. Staff having seen a presentation tells you nothing. What can be measured is how many people report a suspicious message and how quickly, and that number comes out of a phishing simulation.

Punishing whoever falls for it. That is the most effective way of ensuring the next person says nothing, and the expensive part of a fraud is not the first transfer: it is the hour lost before anybody speaks up.

How an organisation protects itself

Authenticate email. SPF, DKIM and DMARC configured properly stop anybody writing from your domain, which is the foundation the expensive versions of this family are built on.

Put in a payment procedure that does not depend on a message. Any new or changed supplier bank account is verified through a different channel and against a contact you already had, never against the phone number in the email itself.

Give people a report button and answer the people who use it. A reporting channel that returns silence stops being used within weeks, and then the report that mattered does not arrive either.

And train with cases rather than definitions. Training that walks through the whole script, including the second act, leaves people recognising the structure instead of a list of suspicious words.

What to do when somebody has fallen for it

The money comes first. If a transfer has gone out, telling the bank as soon as possible is the only thing that can stop it, and that window is measured in hours.

The report comes second. Reporting to law enforcement is what opens any later avenue, and it requires keeping the original messages with their full headers rather than screenshots.

Third, ask whether it was only fraud. If an attachment was opened, a link was clicked or credentials were typed during the conversation, it stops being just a scam and becomes an incident response case, with a review of accesses and of mailbox forwarding rules.

And fourth, say so internally. The same groups try again with other people in the same organisation, and an internal warning is the measure that stops the most attacks for the least effort.

FAQ

Why is it called the Nigerian letter or 419? Because the requests originally arrived by post from Nigeria, and 419 is the article of the Nigerian penal code covering this kind of deception. The name describes the historical origin, not whoever runs it today.

Is it the same as phishing? No. Phishing wants you to hand over credentials or open something; advance-fee fraud wants you to make a transfer. They share the channel and the social engineering, and differ in what they ask for.

Is there any point replying, or reporting the message to the mail provider? Replying, no, and it helps the operator. Marking it as fraud in your mail client, yes, because it feeds the filters that block it for everybody else.

Will antivirus catch it? No. There is no file and no link to analyse: there is a piece of text. What stops it is reputation and pattern filtering on the mail gateway, and above all a person recognising the script.

Want to see how we work at Asperis Security?

Schedule a 30-minute call with one of our experts. We’ll review your stack, agree on scope, and tell you what’s worth pentesting first.