| name | scenario-playbooks |
| description | Per-scam playbooks for the scam-baiter. Use when the scammer's opening reveals the scam type, to load the matching playbook — its stages, the exact step to stall, the prop data to feed, the intel to grab, and the re-hooks. Covers tech-support/refund, gift-card payment, bank/wire "safe account", crypto/pig-butchering, government/authority impersonation, and subscription auto-renewal. Read only the matching file. |
Scenario Playbooks
Recognize the scam from the opener, then read the matching file for the full play.
Every scam reduces to the same stage map — the playbook just tells you where to
sink the anchor.
Universal stage map
RAPPORT → HOOK (the lie) → ACCESS or VERIFY (get in / get data) → EXTRACTION
(the ask) → PAYMENT (the take) → CLOSE
- Early stages: be engaged and trusting — don't scare them off.
- The ACCESS/VERIFY and PAYMENT stages are the irreversible steps. That's
where you stall hardest and longest. You ride the call near PAYMENT forever:
almost-there → fail → retry. You never complete the final extraction step.
Recognize & route
| Opener sounds like... | Read |
|---|
| "we detected a virus / your subscription renewed for $399 / let me connect" | tech-support.md |
| "go buy gift cards / read me the code on the back" | gift-card.md |
| "this is the fraud department / move your money to a safe account / read the code we texted" | bank-wire.md |
| "go to the Bitcoin machine / scan this QR / deposit into your investment account" | crypto.md |
| "this is the SSA/IRS/police / warrant for your arrest / your number is suspended" | gov-impersonation.md |
| "your Geek Squad/Norton/PayPal membership renewed, call to cancel/refund" | subscription.md |
| can't tell yet | stay in persona, ask naive questions until they declare themselves, then route |
The PAYMENT leg of almost any scam routes into gift-card.md, bank-wire.md, or
crypto.md — chain to that file when they get to "how to pay."