Fake Lalamove Payment Link Targets Marketplace Sellers

The buyer did not haggle, inspect the item, or ask the usual delivery questions. He said payment was complete and sent a Lalamove link so the seller could collect the money.

The page looked reassuring, but receiving a payment should never require the seller to hand banking secrets to a website chosen by the buyer.

Realistic reconstruction of a marketplace buyer sending a fake courier payment page that asks the seller for card details to collect funds

Overview

The buyer was interested in the payment process, not the item

A Marketplace seller received a quick offer from someone claiming to have arranged delivery through Lalamove. The supposed buyer then sent an external page where the sale proceeds could be collected.

The seller opened the page but stopped before pressing the collection button or entering bank information. That pause appears to have prevented the most dangerous part of the attempt.

The listing was only an introduction. The fake buyer’s real objective was to move a person expecting payment onto a page controlled by the scam operation.

A real courier name made a false process seem normal

Lalamove is a legitimate delivery platform. Scammers use familiar courier names because shipping is a believable concern when a buyer cannot collect an item in person.

The brand does not authenticate a link sent by a stranger. Lalamove’s own phishing notice warns about fake sites requesting bank credentials and says users should not trust external payment or collection links.

The buyer controlled the story, the supposed payment confirmation, and the page offered as proof. None of those elements came from a channel the seller opened independently.

One click was not the same as giving away the account

Opening the page can reveal an IP address, browser details, approximate location, and the fact that the seller responded. A tracking code may connect that visit to the Marketplace conversation.

That is different from entering a bank login, card number, security code, or one-time passcode. If no file ran and no permission or information was provided, the immediate risk is generally much lower.

Here are the warning signs that exposed the fake collection process:

  • The buyer announced payment before the seller saw money independently.
  • A courier was described as holding the sale proceeds.
  • The seller was pushed onto an external “collect funds” page.
  • The payment did not appear inside the seller’s real account.
  • The link came from the buyer, not an official app opened by the seller.
  • The person receiving money was being asked for banking details.
  • The buyer controlled both the claim and the route used to verify it.
  • The easy sale left normal Marketplace safeguards behind.
Realistic tablet and phone reconstruction of a Marketplace buyer sending a fictional courier Collect Funds phishing link

If You Opened the Page but Entered Nothing

First, close the page and do not return to it for another look. A scam site can change its content, and repeated visits tell the operator that the target is still engaged.

Check the browser’s download history. If an unfamiliar file appeared, do not open it. Delete it and run a security scan. Also check whether the page requested notification, camera, microphone, location, or clipboard permission.

On a phone, look for recently installed apps, configuration profiles, accessibility services, and device-management permissions. These require separate approval, but a rushed user can grant them without realizing what they control.

Update the browser and operating system. A fully patched device reduces the chance that a malicious page can exploit a known software flaw without the usual form or download.

If no data, download, or permission was involved, there is usually no reason to close every bank account. Monitor activity, secure Marketplace, and act quickly if an alert or unfamiliar login appears.

If the browser autofilled any field or you are unsure what was submitted, call the bank. Explain that you visited a suspected courier-payment phishing page and describe exactly what appeared.

How the Fake Lalamove Payment Link Scam Works

Step 1: A fresh listing provides the target

Scammers watch new listings because sellers expect messages from people they do not know. A fake buyer may respond within minutes and offer the full asking price.

The lack of curiosity can feel convenient. In reality, the person does not care about condition, measurements, defects, or accessories because the item is not the objective.

Step 2: Distance makes the courier story believable

The buyer says work, travel, or location prevents an in-person pickup. A courier will supposedly collect the item after payment, removing every inconvenience from the sale.

The brand changes by region. The scam survives because the operator copies whichever delivery company local sellers already recognize.

Step 3: Payment is announced without arriving

A chat message, screenshot, or fake email says the funds have been sent. The seller is told the money is waiting for one final confirmation.

Only the seller’s real bank or payment account can confirm receipt. A screenshot supplied by the buyer is part of the claim, not independent evidence.

Step 4: The collection page borrows Lalamove’s appearance

The link may include the courier name alongside words such as secure, payout, delivery, or receive. The page copies colors, logos, and support language to look familiar.

Even an HTTPS padlock proves only that the connection to that domain is encrypted. It does not prove the domain belongs to Lalamove or that the operator is honest.

Step 5: “Receiving” money requires sensitive information

The page asks for a card number, online banking login, PIN, identity document, or small verification payment. Some versions claim a refundable courier or insurance charge is required.

The logic is backward. A normal buyer can send money without learning the seller’s bank password or card security code.

Step 6: A real bank code approves the attacker’s action

After receiving card or login details, the operator may attempt a transfer, wallet enrollment, or new-device login. The genuine bank then sends a one-time code.

The fake page labels that code as payout confirmation. Entering it may authorize the criminal’s transaction rather than release any sale proceeds.

Step 7: The buyer vanishes or invents another fee

Once information or money is captured, the account may block the seller. If the seller keeps responding, a fake support agent introduces tax, insurance, cancellation, or account-upgrade charges.

The item remains unsold. The seller is left replacing cards, disputing transfers, and recovering accounts from a transaction that never existed.

Why an Easy Buyer Is So Convincing

Most Marketplace warnings focus on dishonest sellers. Someone listing an item may assume that the person receiving money occupies the safe side of the exchange.

Fake buyers take advantage of that assumption. They agree to the price, volunteer to organize delivery, and appear eager to remove every obstacle.

By the time the link arrives, the seller may have spent time answering messages, marked the listing pending, and packed the item. Walking away begins to feel like losing a completed sale.

The payout page gives the seller a task that appears to finish the deal. Its reassuring button hides the fact that the process has changed from receiving money to disclosing secrets.

Our guide to Facebook Marketplace scam buyers covers the broader pattern of fake buyers using payments, pickup, fees, and verification codes against sellers.

A useful rule cuts through the story: the sale is not paid until funds appear in an account you reached without using anything the buyer sent.

How to Verify a Marketplace Payment

Open the bank or payment app yourself. Do not use a link, QR code, phone number, or support chat supplied by the buyer.

Look for a completed incoming transaction. Confirm the amount, sender, status, and any reversal rules that apply to the payment method.

Keep the item until that verification is complete. A driver waiting outside does not turn a screenshot into money and should not rush the seller into handing over goods.

If Lalamove will handle delivery, arrange or confirm it inside the official app reached independently. Delivery status and payment status are separate facts.

Do not refund an overpayment until the original provider confirms that the money is real and explains the correct return process. A fake or reversible deposit can disappear after the seller sends real funds back.

Keep conversation on Marketplace where possible. Moving to SMS, WhatsApp, or email can remove platform warnings and makes it harder for the service to review the complete exchange.

What a Genuine Remote Sale Looks Like

A real buyer normally asks about the item. Questions about condition, size, included accessories, defects, pickup time, and final price show that the object matters.

Both sides agree on payment before delivery. A brand-new collection system introduced after the price is settled should stop the transaction until it can be checked independently.

The seller chooses the courier or verifies the booking through an official account. A buyer-supplied reference number and buyer-supplied support contact do not confirm each other.

For a high-value item, use an established checkout with seller protection or a safe in-person exchange. Read the protection rules because recognizable payment brands do not cover every type of transfer.

Photograph the item, serial number, packaging, and handover. A signed receipt or platform record helps if a legitimate dispute later arises.

A request for a refundable deposit, business-account upgrade, courier insurance, or release fee is a reason to end the sale. Sellers should not send money to receive the agreed price.

Marketplace account age and ratings are supporting clues, not guarantees. Stolen accounts can carry old photos, genuine conversations, and years of activity.

The same code trick appears in the Visa Click to Pay phishing scam. A code sent by the real bank may approve the attacker’s action while the fake page gives it another name.

If Banking Information Was Submitted

Call the bank through the number on the card or inside the official app. Do not use a number printed on the fake page. Say that the details went to a suspected phishing site.

Tell the representative every field completed and whether a one-time code was entered. The bank may need to replace a card, reset online access, block transfers, or remove a newly enrolled wallet.

Change exposed passwords from a clean device and revoke active sessions. If the password was reused, replace it everywhere else, starting with email.

Save the Marketplace profile, full URL, chat, timestamps, fake receipt, and bank alerts. Do not revisit the page to collect more evidence.

Watch for a second contact claiming to be Lalamove, the bank, or a cyber investigator. A recovery caller who requests another code or fee is continuing the scam.

Report the profile to Facebook and the fake page to Lalamove through official support. When money was taken, also use the appropriate police or cybercrime reporting service in your country.

Company, Address, and Fulfillment Checks

Lalamove was a borrowed brand

Lalamove is real, but nothing in the buyer’s message independently connected the company to the collection page. The courier name supplied familiarity, not proof.

The actual web address mattered more than the logo

Any operator can copy colors, images, and an HTTPS padlock. A word such as “lalamove” inside an unrelated domain or subdomain does not make it official.

The buyer never proved payment

A Marketplace profile, chat message, and screenshot all came from the same unverified person. The seller’s own account showed whether money had actually arrived.

Delivery could not fulfill a nonexistent sale

A courier arriving would prove only that someone booked a driver. The seller should keep the item until the agreed payment is independently verified.

What to Do if You Have Fallen Victim to This Scam

  1. Stop contact with the buyer. Do not open another link or speak with a supposed collection agent.
  2. Preserve and report the profile. Save the conversation, then use Marketplace’s reporting and blocking controls.
  3. Check downloads and permissions. Remove unfamiliar files, apps, extensions, notification access, and device profiles.
  4. Call the bank if you entered information. Explain which details and codes were submitted to the fake courier page.
  5. Replace exposed cards. Ask about attempted wallet enrollment, transfers, recurring charges, and new devices.
  6. Change exposed passwords. Use a clean device, revoke sessions, and replace reused versions on other accounts.
  7. Secure Marketplace and email. Enable multifactor authentication and review recovery details and recent logins.
  8. Document the full URL. Save it from the chat without reopening the site, along with timestamps and screenshots.
  9. Notify Lalamove through official support. The company can identify imitation pages and advise on reporting.
  10. Run a full Malwarebytes scan. This is particularly important if the page downloaded or installed anything.
  11. Use AdGuard after cleanup. It can block many known phishing pages, but it cannot verify a Marketplace buyer.
  12. Report financial loss. Contact the relevant police, cybercrime, and consumer-fraud services in your country.
  13. Ignore recovery scammers. No agent needs another fee or code to release nonexistent sale proceeds.

Frequently Asked Questions

Am I safe if I clicked but entered nothing?

Your risk is generally much lower if no information, file, or permission was involved. Complete the browser and device checks and watch for unusual activity.

Does Lalamove hold Marketplace payments for sellers?

Do not accept that claim from a buyer. Lalamove’s phishing notice warns against external payment and collection links that request sensitive banking details.

Can the page steal my bank login automatically?

Most phishing pages need the user to type credentials or approve an action. Updated software and a security scan remain sensible because malicious downloads and exploits also exist.

Is an HTTPS padlock proof that the page is real?

No. It means the connection to that domain is encrypted. A scam site can obtain HTTPS just as an honest site can.

Why would a buyer arrange a courier before paying?

The waiting courier creates pressure and makes the unusual payment process feel connected to a real delivery. It does not prove that money moved.

Should I close my bank account after one click?

Usually not when no banking data, download, or permission was involved. Call the bank immediately if anything was entered or suspicious activity appears.

The Bottom Line

The fake Lalamove link turned a normal delivery conversation into a counterfeit payout process. The buyer claimed the money existed, then asked the seller to prove bank ownership on a page the buyer controlled.

Verify every payment inside an account you open independently. If the funds are absent, keep the item, report the buyer, and never trade banking secrets for a button that promises to “collect” money.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Dick Van Dyke Cinnamon and Honey Brain Cure Scam Exposed, Fake or Real?

Next

One Stolen Card Funded 200 Food Orders Nationwide