Scam Trends, October 2026: Fake Officials, Fake Recalls, and the Enrollment Window

ScamDrill October 2026 scam report cover: the deadlines are real, the callers are not. More than $1.6 billion lost to fake officials and police from January 2025 to July 2026, 4.3 billion robocalls in July 2026, and Medicare open enrollment beginning October 15
Bottom line up front

October stacks real deadlines on top of each other. Amazon’s Prime Big Deal Days run October 6 and 7, Medicare open enrollment starts October 15, and holiday shopping season starts with them. Scammers borrow every one. The loudest warning this month came from the FBI, which counted more than $1.6 billion lost to people posing as police and government officials between January 2025 and July 2026. The defense rarely changes: end the call or close the message, then go to the source yourself.

September’s report was about lists, and the crews that call back people who already paid once. October is about borrowed authority. A badge, a .gov look-alike, a recall notice, a son’s voice: none belong to the scammer, and all of them do the persuading. For scale: Americans reported $15.9 billion in fraud losses to the FTC in 2025 across 3 million reports, and imposter scams were the most reported category again, with more than a million reports and over $3.5 billion lost.

October’s calendar, as a scammer reads it Real dates on the left. What shows up around them on the right. OCT 6–7 Prime Big Deal Days Scam texts spike in the days right after Amazon OCT 15 Medicare enrollment opens Sponsored search ads posing as Medicare.gov FTC ALL MONTH Shopping and recall season Fake recall texts; Amazon most impersonated AARP ALL MONTH Officials who are not Warrants, jury duty, “boost your benefits” FBI, SSA OIG One fix covers all four: go to the source yourself, not the link. Sources: Amazon, FTC, AARP, FBI IC3, SSA OIG (2026) ScamDrill
Every date here is real. The texts, ads and calls that cluster around them are not.

The badge on the phone

On September 17 the FBI’s Internet Crime Complaint Center reissued a warning it first published in 2022, and the update came with numbers. Between January 2025 and July 2026, IC3 received nearly 61,000 complaints about scammers impersonating US or foreign law enforcement and government officials, with losses topping $1.6 billion. Most of those complaints follow one script: you are connected to a crime, and paying is how you clear your name or help catch the “real” criminals.

The FBI broke out several smaller scripts. Missed jury duty or a skipped court date produced 6,833 complaints and nearly $36 million in losses. An expiring passport or driver’s license that needs a paid “renewal” produced 496 complaints. Medical practitioners told their license is expiring, or was used in a crime, filed 3,322 complaints and lost more than $37 million. The costliest version targets international students and immigrant communities: callers posing as foreign police or diplomats threaten extradition or a cancelled passport, sometimes in fake uniforms in front of mock government offices. That version cost 1,809 complainants more than $140 million.

What fake officials took, by script Complaints to the FBI’s IC3, January 2025 to July 2026 $1.6B+ lost across nearly 61,000 complaints about callers posing as police or government officials Posing as foreign police or diplomats 1,809 complaints $140M+ Threatening a medical license 3,322 complaints $37M+ Missed jury duty or court date 6,833 complaints ~$36M Expiring passport or license 496 complaints $348K Most complaints were “you are linked to a crime” calls. The FBI did not give a separate loss figure for that script, so it is not shown. Source: FBI IC3 PSA I-091726-PSA, Sept 17, 2026 ScamDrill
The FBI also notes scammers now appear as officials on AI-assisted video calls, so seeing a uniform on screen proves nothing.

The tradecraft barely varies: spoofed caller ID showing a real agency number, an urgent tone, a demand that you stay on the line, and payment by prepaid card, courier, wire, crypto, or cash fed into a crypto kiosk. One fact ends the call: law enforcement and government agencies do not phone or text people to demand payment of any kind. Hang up, find the agency’s number yourself, and call it. Our jury duty scam guide walks through the warrant version line by line, and this piece on fake IC3 agents covers the ones who claim to be the FBI itself.

“Don’t tell your bank”

The FBI says these callers routinely tell victims not to talk to family, friends, their bank or the police. No real investigation needs your silence. When a caller asks for secrecy, treat that request as the confirmation that it is a scam.

Social Security has its own variant this fall. On September 21 the agency’s inspector general warned about offers to “boost,” “unlock,” or “maximize” benefits for a fee. The agency does not raise anyone’s benefits in exchange for money. The annual cost-of-living announcement normally lands in October, and the pitch will borrow it. The real number is 1-800-772-1213.

Medicare opens October 15, and the top result may be an ad

Open enrollment for 2027 Medicare coverage runs October 15 through December 7. Last month’s warning was about early cold calls. This month the risk moves to the search bar. On September 28 the FTC pointed out that scammers and dishonest businesses pay to sit at the top of search results, use web addresses that look like government ones, and copy official logos. Call the number in one of those ads and you may buy a “plan” that is not health insurance, or hand over enough for medical identity theft.

The defense is boring and it works. Type Medicare.gov yourself, or call 800-633-4227. For Marketplace plans, type HealthCare.gov or call 800-318-2596. Scroll past anything labeled Ad or Sponsored, and check that the address ends in .gov. For free help comparing plans, the State Health Insurance Assistance Program and the Senior Medicare Patrol both exist for exactly this. Patient portals get imitated too, as our breakdown of the MyChart “Medicare kit” email shows.

Ten minutes this weekend

Save Medicare.gov as a bookmark on a parent’s phone and 800-633-4227 as a contact named “Medicare (real).” No advertiser can outbid a saved link. More on the wider conversation in our guide to protecting elderly parents.

Prime days, recall notices, and the text that comes after

Amazon’s Prime Big Deal Days run October 6 and 7. Amazon’s own trust team says scam texts tend to spike in the days immediately after a Prime event, when a “problem with your order” text sounds plausible to almost everyone. The variant AARP is hearing most about right now is the fake recall. The Fraud Watch Network helpline reported a spike in texts and emails claiming something you bought has been recalled for safety reasons. Amazon is the most impersonated retailer, with Walmart, Costco and Best Buy appearing too. The link promises a refund or a repair, and the page behind it wants your login or card details. AARP notes recall scams tend to peak during shopping seasons, which is the season we just entered.

Check real recalls without touching the message: look the product up at cpsc.gov/recalls, or sign in to the retailer through its app or a typed address and look at your orders. FTC data show social media was the costliest way scams reached people in 2025, at $2.1 billion, and shopping scams were the most reported type there. More than 40 percent of people who lost money to a scam on social media said it started with an ad for something they ordered. If a text has you unsure, paste it into our SMS scam checker before you tap anything.

Voices and faces you know

AARP published a story on September 28 that is worth forwarding to anyone with grown kids. A New Hampshire man got a call from someone claiming to be an attorney: his son had been arrested in Boston. Then the son came on the line. To keep him out of jail through the weekend, the family needed $15,000, supposedly 10 percent of the bail, and a courier would collect it in an envelope. He paid. That call was in 2023. He now volunteers to warn others, and AARP’s point is blunt: as voice cloning improves, these calls only get more convincing.

The counter costs nothing. Agree on a family safe word that never appears in a text or a post, and ask for it whenever a call involves money and panic at the same time. Our safe word guide covers picking one, and this piece on voice cloning explains how little audio a scammer needs. For parents of teens, the FTC also published a guide on talking with kids about deepfakes and the Take It Down Act. Platforms must now remove a reported intimate image, and known identical copies, within 48 hours, and if one does not, you can report it at TakeItDown.ftc.gov. Our sextortion playbook covers the first hour if it happens to your child.

Also moving this month

For businesses: close the easy doors this month

October is Cybersecurity Awareness Month. CISA is running it under the banner “Securing the Next 250,” and the National Cybersecurity Alliance picked a theme that reads like advice: “Don’t Make It Easy for Them.” Its four habits are a password manager, multifactor authentication, recognizing and reporting scams, and updating software. They are the right four, and they still leave a gap.

On September 1 the FBI warned about OAuth consent phishing. Instead of stealing a password, the attacker gets an employee to click Accept on a malicious app that asks for access to mail or files. That access skips the password and MFA entirely, and it survives a password reset until someone revokes the app. Ask whoever runs your Microsoft 365 or Google Workspace two questions this week: can employees approve third-party apps on their own, and when did anyone last review which apps already have access? Our guide to device code phishing covers a close cousin that also walks past MFA.

Don’t make it easy: four habits and a gap The Cybersecurity Awareness Month basics, and what they do not cover Use a password manager Unique passwords, no reuse Turn on MFA Every account that offers it Recognize and report scams Teach the team to flag, not delete Update your software Phones and browsers included The gap: consent phishing An employee clicks “Accept” on a malicious app. It gets access that skips the password and MFA, and a password reset does not remove it. Only revoking the app does. Audit app consents now. Sources: National Cybersecurity Alliance; FBI IC3, Sept 1, 2026 ScamDrill
Password resets fix stolen passwords. They do nothing about an app someone already approved.

Two more items for October. Clinics and dental offices should brief the front desk on the medical license script above, since those callers often reach staff first. And the invoice problem persists: business email compromise cost $3.05 billion of the $20.9 billion reported to IC3 in 2025. Confirm any change to payment details by calling a number you already had, never one in the email. Our vendor email compromise guide and help desk vishing playbook have the procedures.

The pattern underneath

Every scam in this report borrows something real: an agency’s name, an enrollment deadline, a retailer’s logo, a relative’s voice. So judging by appearance keeps getting harder. A better question is who started the conversation. If they reached you first and the next step involves money, a login, or secrecy, the safe move is to leave their channel and open your own.

Practice beats panic.

ScamDrill sends safe, realistic fake texts, voicemails, and emails to your family or your team on a rotating schedule, tuned to the scams trending right now. When someone clicks, they get a teachable moment instead of a real loss.

Start a free drill →

Three questions to ask out loud this week. What would you do if a caller said there was a warrant out for you? Where would a parent click to compare Medicare plans? Who in your business can approve a new app’s access to company email? Any “I’m not sure” is the drill to run.

Sources: FBI IC3 PSAs on government impersonation (Sept 17, 2026) and OAuth consent phishing (Sept 1, 2026); FBI IC3 2025 Internet Crime Report; FTC 2025 Consumer Sentinel data (March 25, 2026) and social media Data Spotlight (April 27, 2026); FTC consumer alerts on parking QR codes (Sept 3), farm equipment impersonators (Sept 15), open enrollment health insurance scams (Sept 28) and deepfakes and the Take It Down Act; SSA OIG scam alert (Sept 21, 2026); AARP on recall scams (Sept 24), voice cloning (Sept 28), robocalls, and its 2026 fraud survey; Amazon scam trends and Prime Big Deal Days (2026); National Cybersecurity Alliance and CISA; CMS enrollment dates.

Frequently asked questions

Do the police, FBI, or a court ever call to demand payment?

No. The FBI says law enforcement and government agencies never contact the public by phone or text to demand any form of payment or to ask for personal information, and never ask for payment by prepaid card, cryptocurrency, or courier. Between January 2025 and July 2026 the FBI’s Internet Crime Complaint Center received nearly 61,000 complaints about officials being impersonated, with more than $1.6 billion lost. Common scripts include a missed jury duty date, a warrant for your arrest, an expiring passport or license, or a claim that you are linked to a crime. Hang up, look up the agency’s number yourself, and call it. If you already paid, contact your bank right away and file a report at ic3.gov.

How do I find the real Medicare site during open enrollment?

Open enrollment for 2027 Medicare coverage runs October 15 through December 7, 2026. Type Medicare.gov into your browser yourself or call 800-633-4227. For Marketplace plans use HealthCare.gov or 800-318-2596. The FTC warned on September 28, 2026 that scammers and dishonest businesses pay to appear at the top of search results with look-alike addresses and official-looking logos, so scroll past anything marked Ad or Sponsored and confirm the address ends in .gov. Free, unbiased help is available from your State Health Insurance Assistance Program (SHIP) and the Senior Medicare Patrol.

I got a text saying something I bought was recalled. What should I do?

Do not click the link. AARP’s Fraud Watch Network reported a spike in fake recall texts and emails in September 2026, most often impersonating Amazon, with Walmart, Costco and Best Buy also used. The link typically offers a refund or repair and leads to a page that asks for your login or card details. Check real recalls at cpsc.gov/recalls, or sign in to the retailer through its app or a web address you type yourself and look at your orders. Report scam texts to your carrier by forwarding them to 7726, and report the scam to the FTC at ReportFraud.ftc.gov.

What is OAuth consent phishing, and why doesn’t MFA stop it?

In OAuth consent phishing, an attacker tricks an employee into approving a malicious app that requests access to email, files, or other company data. Because the app is granted access directly, it does not need the employee’s password, so multifactor authentication never comes into play. The FBI warned about this on September 1, 2026, noting that the access persists until the app is removed, so resetting the password does not fix it. Limit employees’ ability to approve third-party apps on their own, review which apps already have access to Microsoft 365 or Google Workspace, and revoke anything you do not recognize.