
THE NEWSLETTER | 05.27.26 | V06N16
Co-Founder/Content: Doug Fodeman | Co-Founder/Creative: David Deutsch | Scambaiter: Rob M


Free Spins! Start with $1K on Us! Or So You Think….
If your email inbox and spam folder is anything like ours, we’re guessing that you’ve likely seen many emails that randomly drop into one or the other claiming to be from online casinos offering enticing rewards for you to join their site. These emails typically offer things like “free spins,” and thousands of dollars in “free” money once you set up your account and make some initial deposits first. We wondered….Are any of them legitimate? Are there any risks besides the obvious that come from gambling losses? And if so, what are the risks? Given the many hundreds of online casinos all over the Internet, we decided to just dip our toes into a few rather than plunge deep into these waters for fear of drowning. And yet, what our brief investigation uncovered was deeply disturbing! Once again, we ask you to put on your safety suit, button up, and expect troubled waters ahead because luck is not on your side!
On Saturday, May 23, we Googled “best online casinos” and the second of two Google sponsored links came up as freespin.com. That sounded inviting as the description began with “Join now, start playing best online games in the USA.“ A WHOIS tool tells us that Freespin.com was registered waaaaaaay back in April, 2001 which brings it a lot of credibility, right? However, when we searched for “Freespin.com reviews” we found a rather poor 2.6 star rating on Trustpilot.com. In fact, 54% of the 75 reviews were just 1-star. (Also, it felt odd to us that a 25-year old website casino has only 75 reviews on Trustpilot.) Some people who left reviews called the site a scam and fraud. Others complained that it took far to long to receive their winnings after jumping through lots of annoying verification hoops. For example, on April 21 one reviewer said “You give them all of the required documents and they ask for more just to extend the process probably in hopes you will gamble away your winnings. This took 10+ days, then the email I just received said I can expect payment in 5-10 business days.” Remember, we found Freespin at the top of Google because it is a sponsored return, i.e. paid advertisement. This Sponsor has been around for 25 years, claims to be based in the US, and yet has an awful rating!
What of other online casinos whose promotional emails land in your inbox or spam folder? Since Canada in one our closet neighbors, we decided to take a look at an online casino called Fair Spin Casino Canada (fairspin). On May 16, we took a screenshot of their website we found at fairspin-login[.]cc. They say “get up to $10,000 CAD plus 200 free spins across your first four deposits at Fair Spin Casino.” We find that to be terribly sketchy! They say they’ll give us up to $10,000 CAD if we make four deposits into our account? SERIOUSLY? If they’re willing to give us that much money to begin with, why would we need to deposit anything at all? However, the bigger issue is their credibility. Their website says they were established in 2018. But their domain fairspin-login[.]cc was just registered about 3 weeks before we found their website – April 27. And it is already listed as malicious on VirusTotal.com!
But wait, maybe we somehow located the wrong Fairspin Casino of Canada! When we Googled “Fairspin Casino of Canada” we saw a bunch of returns totaling more than 15 different websites that either had the name “Fairspin” in the domain or in the first line of the description. We seriously doubt that all 15+ are the same Fairspin casino. Many are likely malicious mimics. We moved on and decided to check out another online casino we had found, called spinflex[.]pro. Spinflex[.]pro claimed to have been founded in 2017 and to have “licensed slots.” But licensed by whom? We have no idea because they didn’t say. And again, when we checked a WHOIS tool, we discovered that it was registered just a few weeks earlier using a Registrar that has a phone number in Estonia! Also once again, VirusTotal showed us that four security services had identified this online casino as malicious!
We didn’t like those odds of 4-to-1 saying that Spinflex[.]pro was nasty so, again, we moved on. We were hoping to find a really good online casino through which we might make a big bet, and turned our attention to a site called Mega.bet. According to the WHOIS record, Mega.bet was founded just over seven years ago, giving it some nice credibility. But when we visited Trustpilot to ask for reviews about this online casino, we were very disappointed to see it rated as 3.2 out of 5 stars, giving it a “mehhhh” rating. And, similar to the reviews of Freespin, many reviewers complained about delays in receiving their payouts. The AI-generated summary of more than 110 of these reviews said “Customers frequently report issues with payments and refunds, with many experiencing delays or difficulties in receiving their money.” (42% of reviews were 1-star, as of 5/23/26).
However, we were also rather confused again by what we found online. We found another website called Megabet and using the domain megabet[.]cfd. This Megabet claimed to be the “#1 online casino & slot games platform in the Philippines.” That’s impressive, but also pretty hard to believe when you consider that their domain, megabet[.]cfd, was registered on April 8, just 5 weeks before we found it! The bottom of their website has a lovely offer of a “150% Welcome Bonus” if you download and install their Megabet app” on your device. Hmmmm…. Would you trust downloading and installing an App for a 5-week old Casino from the Philippines? We would not! Though VirusTotal shows no concerns about this website, Scam-Detector rates it as unsafe and risky, 16.4/100.
Wherever we looked for online casinos, we had no problem finding ones that turned out to be malicious and/or highly sketchy! Here are a few more examples, starting with Sera[.]casino. What makes this casino very bizarre is that we discovered it appears to have been registered just three weeks earlier through a drug company in Hungary called Virtua Drug, based on the Registrar’s email address! And after just three weeks, this online casino is listed on VirusTotal as malicious and the site has already been taken down!
And then there was a casino called Arixswin, using arixswin[.]com. It claimed to offer “blockchain-powered casino games and VIP rewards.” This supposed casino was registered in late November, 2025 by someone in Hong Kong. But VirusTotal had a whopping thirteen security services that identified this casino as a malicious fraud!
We thought, “how could this type of fraud be any worse than that in the online gambling world?” Well, apparently, it can! We then discovered an online casino that was called siodax[.]com. It turns out that this particular online casino was associated with pig butchering scammers in Asia (according to Google’s AI response.) Not only was it a fraud, but two security services found malware on this site waiting to infect visitor’s devices! In total, NINETEEN security services found this so-called casino to be HIGHLY MALICIOUS! And that was in just a 4-month period of time, since it’s creation in mid-January of this year! Fortunately for all, it is no longer up and running.
Our cursory review of online casinos was, to be frank, shallow and short-lived. However, even “credible” online casinos around for a quarter century in the online world left us deeply disappointed. Adding insult to injury, anytime we searched for an established online casino, we found lots of mimics, many of which felt deceptive or turned out to be malicious and fraudulent. For example, we learned of an online casino called “SpinBoss” through the lovely email you see below. However, we also figured out that this email was just a malicious mimic sent from a crap domain! The real SpinBoss casino seems to be associated with a Signature Arts Digital website that was registered on April 1, about 7 weeks before we found it. But Trustpilot tells us that this real SpinBoss casino also has a poor 2.7 star rating! Shocking, right?
Equally interesting about this betting mess is the fact that at the bottom of Google’s first page of returns when we searched for freespin.com, was the following disclaimer… “In response to multiple complaints we received under the US Digital Millennium Copyright Act, we have removed 3 results from this page. If you wish, you may read the DMCA complaints that caused the removals at LumenDatabase.org: Complaint, Complaint, Complaint.” Hmmmmm….We think Google and others need to do a much better job at identifying and removing the MANY malicious and fraudulent online casinos! We started this exploration thinking about making a big bet. We ended this exploration doing a 180, and now all our bets are off. If you are ever seriously thinking about gambling online, we strongly urge you to investigate the website you are considering using, before you open an account and hand over your money to them!


Is This Social Media Post AI-Generated, Romance Scam Addiction, & More!
On May 19, a woman in New York named “Justin N.” posted the following on NextDoor.com… “I am nearly 40 years old. The books on my shelves have changed wave after wave the grand narratives I was obsessed with in my youth have now turned into late night self reflections. Since my divorce I’ve protected myself incredibly well with absolute discipline and confidence Yet I often feel a vast sense of solitude the moment I close a book. No matter how brilliant the ideas on the page are it’s a one way street. I miss those moments when two sharp minds spark in real time. You don’t have to agree with my views you can even challenge me as long as your inner core is intriguing enough If you aren’t looking for fast food socializing but crave a deep spiritual resonance instead send me a message. Tell me what you’ve been reading lately.” We thought that the name “Justin” for a woman is very unconventional, don’t you agree? Also, Justin’s post actually sounds like it was AI-generated. It turns out that Justin just joined NextDoor on the day of her post and it was her only post!
Speaking of messages publicly posted on NextDoor…. A woman contacted me to say that she had suspicions about a newly posted message on NextDoor from a man named Larry Miccicke. Once again, Larry’s post seemed too open, too honest. It almost felt like a lure. That’s what caused this woman to actually run a reverse image search of his profile photo of Larry wearing a suit with a pink tie. It turns out she found that same photo of the man, but with an entirely different background, in an Instagram account! The Instagram account was of a man named Christian and the Instagram account had many other photos of the man as well. Not just the suit with pink tie! Based on what she discovered, we think “Larry” is a fraud and trying to engage in a romance fraud with women!
And, speaking of romance scams, last week we read a heartbreaking post by someone to Reddit about their mother being scammed and not being able to stop it. The scammers kept returning and the mother kept falling for it, over and over. It became so severe that the mother had given away all her money to the scammers and then took out loans to give more. Her adult child who posted asked the Reddit community for advice and help on how to break the mother’s seeming addiction to this scammer. Most agreed that the mother was likely addicted to the attention she got and that this was probably a romance scam. One person giving advice recommended that the adult child listen to this episode of a podcast called Scammer Stories, on Spotify. The episode is called “‘What happens when nothing works while trying to save a parent from a romance scam.” It was published on May 9, 2026 and can be found here: https://open.spotify.com/show/1TV3rDyr4G1oHH1RoyIJ33 Here is the description of the episode from their website: “The number one question I get in my email inbox is from adult children desperately trying to save a parent who is trapped in a romance scam. They’ve tried everything… begging, interventions, cutting off money, even taking control through power of attorney. And still, nothing seems to work.
Over the years, I’ve heard countless theories. Do you hit them with tough love? Do you back off? Is there actually a right way to help someone who is emotionally attached to a scammer? The woman in this episode has a very different perspective… because she tried one approach and when it failed she tried the exact opposite.
Jennifer Wallis is a financial advisor who now speaks publicly about romance scams after watching her own mother become a victim. In this episode, she shares the mistakes she made, the lessons she learned, and why changing the way she communicated may have helped save her relationship with her mother.”
We have said many times that Scambaiter Rob gets the best emails! It hasn’t stopped. Check out these two lovely and exciting emails that he’s received in the last few weeks! That man is soooooo lucky! Now he’s addressed as “Sir Uncomparable” by a woman named Mariam who sent it from a server in Japan…
But wait, that’s not all! You’re not gonna believe this but Rob was contacted by Scott Bessent, Secretary of the US Treasury! Mr. Bessent informed Rob that he has a fund of $10.5 MILLION DOLLARS waiting for him!!!! We wondered if this was part of the $1.776 BILLION Dollar fund from President Trump to any and all Americans who were harmed by the last Administration. Mr. Bessent didn’t say that specifically and Rob had never applied. But that doesn’t matter! Rob is very excited and even promised to share some of it with David and I! Although we did find a few oddities in his email and attached photo of his ID card…
In recent years we’ve all experienced the growing use of AI. This has included some awful ideas of how it is used. Well, we just learned of another idea that, in our opinion, is INCREDIBLY RISKY! OpenAI is now making it possible for their Pro version to connect to people’s banks and financial accounts to have access for analysis and tax planning. Would you want to give ChatGPT access to your financial accounts?! Check out…
Perhaps we should add a whole new column to our weekly newsletter that is devoted to the malicious misuse of Facebook and other Meta services! There is NO END to the amount of fraud and malicious use we find in Meta’s communities! Take, for example, the popular Facebook group called Backroad Melodies. Backroad Melodies is another fake fan group managed by cybercriminals in Vietnam! Remarkably, they have over 26,000 followers. Recently they posted lies about something Willie Nelson said. But Google confirms that Willie Nelson never said what they claimed. Their malicious post pointed readers to a website canned softframe[.]info to read the “full article.” But softframe[.]info was registered just 9 days earlier and has already been found to be malicious by a security service on VirusTotal.com! (By the way, a California County is now suing Meta for the widespread fraud in their 2024 advertising effort that victimized people in their County. Meta earned many Billions of dollars from those fraudulent ads. We hope this is just the beginning of lawsuits against Meta! Check out: https://www.almanacnews.com/technology/2026/05/11/santa-clara-county-files-lawsuit-against-meta-alleging-widespread-scam-ads/)
And speaking of the much adored company, Meta (said dripping with sarcasm), they have just recently removed privacy features from Instagram! According to this article on the Malwarebytes Blog “Instagram DMs should now be assumed readable by Meta and potentially accessible to law enforcement, advertisers, or attackers who gain access to Meta’s systems.” By contrast, they actually improved privacy on WhatsApp. You can read more information about this paradox here: https://www.malwarebytes.com/blog/news/2026/05/metas-confusing-new-approach-to-chat-privacy
As for AI, apparently it is being used more frequently to generate more convincing voices of family members by scammers to target other family members. This is so sad and means that it is increasingly important that families use a private “safe word” to tell each other that it is really them, for example, in a phone call! Practice it in your family! Make sure that everyone knows it! Or use a question/answer that ONLY your family would know! Read… https://www.cnbc.com/2026/05/09/ai-powered-scam-calls-getting-more-convincing.html
It is truly remarkable how much information scammers are now able to find out about people as a result of poor privacy laws, hacked or leaked data, and other means. Check out this terrible story of a woman who lost many thousands of dollars after she received a call that appeared as her bank, Chase Bank. But the caller knew her full bank account number and the exact amount of money in her account! Read… https://finance.yahoo.com/markets/crypto/articles/illinois-woman-hands-40-000-201500898.html
A woman with an Indian accent called Rob. She said her name was “Sara” and calling from “Consumer Services” about his Experian account. Of course Rob turned the call over to his new AI Bot. Sara was calling Rob to get him a “lower rate” so he could “pay off his balances.”
Sara from Experian Credit Card Services
Many times, we have written about fraud that involves the use of cryptocurrency ATM machines, such as Bitcoin ATMs found in some convenience stores and elsewhere. (Also called ‘CVC Kiosks’) (For example, read our January 29, 2025 top story about a victim who lost about $7K to a jury duty violation scam.) Based on our research, only the following three states ban the use these cryptocurrency ATMs because of their overwhelming use by fraudsters: Tennessee, Indiana and Minnesota. (Some cities in other states have bans or partial bans.) We bring this up again because we learned that an Oregon couple who lost about $76K to fraud involving the use of Bitcoin ATMs have filed a lawsuit against Bitcoin. We hope that other victims join this class-action lawsuit and that it leads to many more states banning the use of these tools of fraud!
In case you didn’t know it, data breaches in the last couple of years have exposed personal information, including dates of birth and social security numbers, on millions of Americans. Now scammers are using that information to contact companies that hold and control ur 401K Retirement accounts. This recent article details how scammers were successful at convincing someone at a 401K service to update the banking information on an account. The real woman lost her entire retirement savings when it was moved out of her account! Check out… https://finance.yahoo.com/markets/options/articles/401-k-identity-theft-target-110542765.html
Sometimes the companies that provide our tech products actually serve as the means for scammers to target us. This happened recently to many apps on Google Play store, until Google finally shut it down. Check out…
https://sg.news.yahoo.com/warning-google-play-call-history-134614449.html
According to this article, many Americans nationwide are receiving deliveries of packages that contain nothing at all! It is a form of a “brushing scam.” There are important tips of what you should, and should not do, if this is happening to you. Check out…. https://www.aol.com/finance/americans-nationwide-receiving-mysterious-white-194500534.html


Odd Characters Mean Fraud & the Customer Name is Customer!
Check out the unusual characters found in the subject line of this first phishing fraud. Scammers use these type of special and accented characters in the hope that it will make it harder for antispam servers to identify them. But it also makes it easier for us to identify them! Not to mention that this email didn’t come from a REAL Microsoft team. Someone simply created the email address called “msonlineservicesteam.” Now lunge for the delete key!
We LOVE IT when scammers make their fraud so incredibly obvious! Like when the name of the customer in their fraud is “Customer!” That and the fact that this email was sent from a free Gmail account! Remember to report your smelly phish to us and Google! https://safebrowsing.google.com/safebrowsing/report_phish/


CVS $100 Offer & Discounted Cruises!
This $100 gift card offer from CVS is not real! It came from a misused email account from Bramble Oak Studio. And the link to validate and ship your gift card points to a malicious website, survionyx[.]su, that was registered a little more than a month earlier! Also don’t believe the pressure tactics used at the bottom of this clickbait. They are meant to get you to click without thinking carefully about this offer. Now deeeeeleeeeete!
This next great offer wants you to believe it came from Avoya Travel. But it was sent from an email at the crazy domain called intermediateinterfaceimplicit[.]tattoo! And the links in this malicious clickbait point to another crazy domain, coreoceangreenstorm[.]de, located on a server in Germany! (“de” = Deutschland = Germany) You are NOT going to get 75% off of any cruise!


Greetings Gamer & Email Delivery Failure Notification
Check out this random email that came to one of our readers about a new gaming website. Sounds exciting when you read through it all, especially the offer of a welcome bonus and credits. However, the attached file is extremely dangerous! It is an HTML file. Files like this contain coding that take control of your web browser to do whatever the sender wants it to do…. Like visit a scammer’s website to download malware! NEVER, EVER click on attached files that end with DOT-html, htm, php, bin, js or svg!
We had no idea until we got this email from the domain official-zh-hth[.]com that our email service was based in the Netherlands! That’s where this domain was registered about 9 months ago. When we moused over the link, it appears to lead to Google. HOWEVER, within that link is a redirect that will send our click to a VERY MALICIOUS website called contabostorage[.]com! Can you spot the redirect to contabostorage?


This is one of three home improvement scams that Scambaiter Rob received last week by text. They all follow the same pattern. A person who knows his first name, asks if he needs any home improvement work done. He’s had a roofing company, a siding company, and now this landscape service contact him this way. And they all stopped texting him when he asked for their state contractor’s license number, which is required in his state.
Rob isn’t the only one to get these bogus texts from people claiming to be local contractors. Check out this text that I got from “Amy” who claims to represent a company called Massachusetts Epoxy. When I asked her for her business address and website, she stopped texting me!
One of our readers received this very malicious text supposedly from someone named Diana using 916-508-3639. The recipient has no idea what Diana is talking about. However, we discovered that the crap domain urginau[.]asia is highly malicious, according to the Zulu URL Risk Analyzer. It was also registered by someone in the Philippines just 5 days earlier and will redirect your click to another crap domain called page-is-offline[.]com. Zulu ALSO shows this website as malicious! Swipe left and hit delete!
Until next week, surf safely!
Copyright © 2026 The Daily Scam. All rights reserved. You are receiving this email because you have subscribed to thedailyscam.com
Marblehead, MA 01945





















