
THE NEWSLETTER | 08.19.26 | V06N28
Co-Founder/Content: Doug Fodeman | Co-Founder/Creative: David Deutsch | Scambaiter: Rob M


Connecting Loving Families with Pets in Need. But Do They?
Have you ever considered adopting an abandoned pet? Or taking care of one for a short period of time? Thinking about an abandoned pet saddens us and it is in our nature to want to help, right? Early last week, Scambaiter Rob noticed a post on NextDoor.com by an account oddly called Dawnsonzpaws. The post said that “every pet deserves a second chance,we try our best to make sure they get the best they could get.” [sic] Some things about this post seemed, well,….off to Rob. He clicked on it to see more and look at the account of the organization that posted it. This account claimed it was a pet adoption service, pet rescue service and even a pet sitter. But the deeper Rob looked, the more red warning flags he found. It didn’t take him long before he was confident that this pet adoption/rescue service was likely a fraud. But what exactly was the fraud? After conducting an investigation of their many posts, using many NextDoor accounts, and their website, we think we understand this fraud. Would you? Let’s take a look at these adorable pets and the passionate appeals from this service to adopt a new family member…
Scambaiter Rob’s gut feelings about the NextDoor account Dawnsonzpaws led us to dive a lot deeper into the information posted. Almost immediately, we discovered that Dawnsonzpaws actually had created at least six different accounts on NextDoor in just a few days. These accounts used three different addresses and two different telephone numbers. All six accounts showed one of two nearly identical email addresses – dawnsonspawss@proton.me or dawnsonspaws@proton.me. And in 5 out of the 6 accounts they showed a link to a Vercel App webpage: paw-haven-pets.vercel[.]app. (NOTE: Vercel is a cloud platform for hosting websites and web applications. It is often abused by scammers and cybercriminals to host a variety of scams or malicious content such as phishing sites, fake brand lookalikes, and more. Sources: Kaseya, Malwarebytes, & Cloudflare.) Please note the odd differences in the name consistently used on these many NextDoor accounts. The accounts are all named Dawnsonzpaws but the name used on their email account is dawnsonspawss or dawnsonspaws. This is a rather strange thing for a business to do, don’t you think? Also, in every NextDoor account, Dawnsonzpaws claimed to be located in New York. So why would they choose to use the free email service proton.me which is based in Switzerland?
As we dug deeper into their many accounts, we also discovered that several of their accounts were no longer online, as if they had been removed by the NextDoor service. Here are 3 examples of removed accounts….
- https://nextdoor.com/pages/dawnsonzpaws-new-york-ny-64r9n4/
- https://nextdoor.com/pages/dawnsonzpaws-new-york-ny/
- https://nextdoor.com/pages/dawnsonzpaws-new-york-ny-iinucx/
The Dawsonzpaws posts showed one address as 48 West 85th Street in New York city. Adding to our suspicions about this service is the fact that a Real Estate firm informed us that the address at 48 West 85th Street, New York, NY is a newly renovated single-family townhouse valued at more than $20 Million! And according to StreetEasy.com and other sources, the other address listed for this service – 157 West 57th Street, New York, NY – is an upscale condominium building with 90 units. There is no listing for a pet adoption agency at either of these locations! Also, several of the Dawnsonzpaws accounts simply listed their address as “New York” with no street location. A search for their business phone numbers, 601-568-4369 and 401-386-9524, associated with these NextDoor accounts turn up nothing reliable or even associated with this pet adoption service. However, a third phone number found associated with one of these NextDoor accounts, 401-374-7377, appears to be used by a woman in South Carolina. We tried calling her on August 12 to inquire about this business but our call went to a voicemail box without any information. (Note: Area code 401 is for Rhode Island and area code 601 is for Southern Mississippi.)
Oddly, as we were working on the draft of this story last Wednesday and Thursday, Scambaiter Rob suddenly discovered 2 brand new posts made by 2 new NextDoor accounts for Dawnsonzpaws. One account also showed a new phone number as 401-528-6952 and a new email address pawswhiskersh@gmail.com. However, the account still showed the address for this pet adoption service as 157 West 57th Street, New York, NY. The post included a photo of a likely Maltese dog, followed by…. “don’t understand why the cozy, quiet home I loved for two years vanished, or why the loudest, scariest noises now fill every second of my days. Five months ago, my family held me tight, cried, and left me here because they couldn’t afford to keep me anymore—and ever since, I’ve been sitting in the corner of this kennel, trembling at every echo and waiting for a gentle hand to reach through the bars, whisper that I’m safe, and take me back to a lap of my own.” This paragraph sounded artificial to us, and almost poetic, as if it was created by an AI tool. We used four different AI text detection tools and two said this text was 100% AI-generated (GPTzero & Grammarly), and the other two said 0% AI-generated. (Quillbot & Scribbr). One of these two other new accounts also included a photo of a nearly bald man wearing a gray sweatshirt, and holding a small puppy. But a Google reverse image search showed us that this photo was stolen from a Polish Air Pet Service business which was started in 2015. The original photo was posted on May 4 of this year on this Facebook account. (Thankfully, both newly created Dawnsonzpaws accounts were taken down in 1-2 days.)
(CAUTION: Last week, none of our usual security services found anything malicious about their business website located at paws-haven-pets.vercel[.]app. However, we urge caution if you are considering visiting their site. Please first use VirusTotal.com to recheck the site before you visit.)
The meta tags used in the coding of their pet adoption website says things like “Pawshaven App” for a title, “Pet Adoption Project” for a description, as well as “Pawshaven connects loving families with pets in need across USA and Canada. Browse dogs, cats and more available for adoption.” And the page title simply says “Find your forever friend | Pet adoption.” But we believe this is all a ruse. Before you think that we are being overly suspicious in our concerns about this service, check out our deeper investigation of their website at paws-haven-pets.vercel[.]app…
Their mission seems extremely noble and it must touch the hearts of many if you consider that they have more than 1000 volunteers and their services are expanding fast! But are their numbers believable? Over the course of 4 days last week, we checked their website for pets to adopt and consistently saw the same 7 dogs and 2 cats posted on their site. That’s it. There were no other animals. And yet, their stats say more than 500 pets have been rescued, but only 350+ adoptions. Shouldn’t there be a lot more photos of adoptable pets? It also seems odd that several of their NextDoor accounts show the “trademark” symbol ™ next to their name: Dawnsonzpaws. And yet, their official website uses the name PawsHaven. We couldn’t find the name Dawnsonzpaws anywhere on their website. Also note: on Friday morning by 7 AM EST, their website appeared to be down!
We decided to dig in a little deeper into several of the 7 dogs and 2 cats shown on their Vercel website last week. Their list included a photo of an adorable 1-year old male dog, Beagle mix, named Biscuit. (Note: This Vercel website stores their photos on an alternate service called supabase.co. Though their website has been offline since last Friday morning, their pet’s photos were still available! This suggests that they may repost their website at another, different webpage. Here is the photo of Biscuit on the supabase site.) Under “About Biscuit” their website stated “## Biscuit’s Story Biscuit is one year old and full of love, personality, and playful energy. He’s the kind of dog who believes everyone he meets is a potential best friend. Whether it’s playtime, a walk, or simply relaxing beside his favorite people, Biscuit is happiest when he’s part of the action. ## Health Biscuit is a healthy young dog and ready to find his forever home. ## Medical History His vaccinations and deworming are up to date. Biscuit is neutered and ready for adoption. ## What They Need From You Biscuit is looking for a loving family who will give him plenty of exercise, playtime, training, and affection. He would thrive with patient people who are ready to help him continue learning and growing into the wonderful companion he is meant to be. Could Biscuit be your new best friend?” (NOTE: Our AI-detection tools consistently thought that this description of Biscuit was mostly or all AI-generated.) Most importantly, when we conducted a reverse image search of the photo of Biscuit on the PawsHaven Vercel website, Google returned more than 60 different links from around the world showing this exact same photo! One of these links pointed to a website called DailyPaws.com. This Daily Paws domain was registered way back in 2005 and is legitimate. The photo of “Biscuit” can be found near the bottom of the Daily Paws webpage. And the DailyPaws website even gave credit for this photo as coming from an instagram account called “bearthecrook.”
WARNING: If you ever do a reverse image search yourself, please be extremely careful what links you click on! Google also showed us that the photo of Biscuit was also found on two very malicious websites that we evaluated. One was called salesteqar[.]click (VirusTotal results) and the other was called blueoakspropertymanagement[.]com, but this second site redirected to salesteqar! (VirusTotal results of the 2nd site).
The fact that the photo of Biscuit was found on so many other websites, including a legitimate business that cited a source, had us wonder about the other 8 pet photos. We conducted reverse image searches of each of these photos and discovered serious red flags that they had been stolen from other websites or accounts. Here’s a sample of our evidence. (Note: though their PawsHaven website is now offline, the pet photos are still up as of 8/16).
- Jessy (female Maine Coon cat) – Exact photo found over 35 times across multiple social media accounts. For example, this March 22 Facebook post that was written in Russian and appeared on an account called “alla Maine coon Fluffytails.” Several other social media accounts also have ties to the Russian language such as this post of the photo on Instagram. We also found this exact photo on a Facebook account that represents a pet adoption and rescue service in Denver, Colorado. The email address for this adoption service is different than the email accounts used for the PawsHaven service.
- Atlas (male German Shepherd dog) – Exact photo found more than 200 times on websites across the Internet! The PawHavens website claims that Atlas is 4 years old. This is especially interesting since this exact photo was published many times before this supposed 4-year old dog was born! For example, this January, 2022 on this UK website article about German Shepherd dogs or this 2021 Facebook post.
- Julia (female Basset Hound) – Exact photo found 6 times; on 3 Facebook posts and 3 other websites. On June 24, 2024, a woman named Amy dropped this Facebook post to a group, saying that she had recently acquired this adorable male Basset Hound (not female). Her post included 2 photos, one of which was the exact photo of Julia on the PawsHaven website. Last week we reached out to Amy via Facebook DM to ask whether or not she still owns this dog. She said yes! And that she has not put her dog up for adoption! Also, we found that 3 of these exact photos were found by Google on websites in other countries. One was a site in Portugal called gazo[.]pt. This site was found to be a phishing scam site by VirusTotal.com. Another website is located in Germany, called sternimnorden[.]de. According to Google Gemini on August 13, this German website has been compromised or hijacked and displaying random texts and products. The third website Google reported as having this exact photo was a travel-related website in Croatia called tzzminj[.]hr (“.hr” = Croatia) However, we also saw evidence in Google’s returns that this Croatian tourist website contained strange unrelated content about brain health, health-related products and insurance. These odd discoveries also lead us to suspect that this Croatian website may also have been compromised and misused.
- Sage (male Husky mix dog) – Exact photo was found on more than 120 websites around the Internet, including many commercial sites, sites in other countries and social media sites. For example, this photo was also found in a January, 2023 article on Buzzfeed.com. The Buzzfeed article credited this photo to a photographer named Nataliia Kvitovska; Nataliia’s photo of this Husky is also shown here on Unsplash and indicates that she took this photo in November, 2020. The date of this photo is about 9 months older than the 5-year old age listed on the PawsHaven website! (Our brief investigation of this photographer shows that she is likely from Ukraine, though now living in Canada.)
In the black footer of each web page on the paw-haven-pets.vercel[.]app site is a Contact area. There is no specific street address listed for this business. They show yet another email address as pethaven189@gmail.com and display their phone number as 401-386-9524. Clearly, we believe that we have demonstrated enough suspicious facts about this pet adoption service to convince you that it is a fraud. But what exactly is their fraud game? How are they stealing money or information from people? Here’s a possible clue. Each of their web pages has a “Donate” button and a “Adopt Now” button in the upper right corner. Clicking the donate button, for example, opens a window inviting you to select a dollar amount to donate. But this popup also says “Every gift helps” and “Your generosity directly impacts the lives of pets in need. 100% of your gift goes toward: safe shelter, nutritious food, and medical care.” This claims strikes us as odd because this pet service never claimed to be a 501(c)3 nonprofit. Also, how can 100% of every donation be used for shelter, food and care? There are many other expenses, including staffing, that are outside of these costs. In fact, no charity can say that 100% of every dollar goes to helping pets in this way. When we asked Google’s Gemini what percent of donations are typically used to support pets in an animal shelter, it responded with “typically, 70% to 85% of donations and overall revenue in reputable, well-run animal shelters go directly to program services and animal care, while the remaining 15% to 30% covers administrative and fundraising overhead” followed by several sources to support this answer. Perhaps this fraud operates by tricking the public into making donations that are simply pocketed by the scammers behind this site.

There is also another possibility. Clicking to “Adopt now” leads you to a webpage that collects a lot of information about you, including your name, address, email, phone number. But this adoption application also requires an adoption fee. Whether it is by stealing donated money, or collecting adoption fees followed by turning down adoption applications, or simply collecting and misusing the personal information of those who fill out and submit the forms, we’re convinced that this website is 100% a fraud. We should also note that we thought it interesting that there were a few small breadcrumb clues that turned up in our investigation suggesting that the scammers behind this site may be from Russia or nearby countries. Obviously, we don’t know for certain and this is just conjecture.
Also oddly, during our investigation of PawsHaven, using paw-haven-pets.vercel[.]app, we found several other scam pet rescue websites, including some that have been reported as donation fraud on social media, such as one similarly called Paw Haven Rescue. (Also identified on this Facebook post as a fraud pet service looking for donations.) Other warning signs included this post from a legitimate Happy Paws Haven Instagram account. They reported to the public that scammers were misusing their name and logo. Finally, remember that we thought it was odd that the PawsHaven website was posted by misusing a Vercel App service. Other scam pet-related websites have been identified using the Vercel DOT app service. For example, PCRisk posted an article about these types of scam sites. Once again, before you enter your personal information, make a purchase or donate money to any cause, please verify, VERIFY, VERIFY that what you see is legitimate!
FOOTNOTE: Scambaiter Rob discovered, and reported 13 more posts on NextDoor of fake pet charities just a few days ago on Saturday, August 15. Thankfully, he said, each post was taken down after he reported it! Many of these posts included links to a new website that is IDENTICAL in every way to the PawsHaven website we described above. The new website can be found at safe-haven-pets.vercel.app We strongly suspect this fraud will continue, even if safe-haven-pets is taken down.


BREAKING! Deadly Crash Reported via FB Post, Vanity Scams & More!
Last week as I opened Facebook I saw a post appear on the account of a longtime friend. The post showed a screenshot of a horrible car crash, and using the ABC News logo. It simply read “I can’t believe you’re gone. I’m going to miss you R.I.P.” The post included a link supposedly pointing to the full article. No names were mentioned about who, exactly, had died in this horrible crash. This post was exactly the type of clickbait we saw and reported in a November, 2023 newsletter. We immediately recognized this as malicious and reached out to the friend’s account on which the post appeared. She informed us that her husband’s Facebook account had been hacked the day before and the hacker locked out her husband and dropped this post. The link to read the article and perhaps find out who died was a social engineering trick. It pointed to malicious coding on a website called r2[.]dev. R2[.]dev is a Cloudflare service that is often misused by cybercriminals, as reported by many sources, such as in this Malwarebytes article. If you see anything like this on social media, DO NOT CLICK the link! Call your friend to report it. Tell them to notify all their friends and family that this fraud was posted on their account and NOT to click it! If they did click, urge them to use at least two different anti-spyware tools to carefully review their device for threats. Also, urge them to immediately change the password to their social media account AND to any other account that uses this same password!
At TDS we frequently get emails like the ones below. From our perspective, this is a type of vanity scam. Vanity scams are meant to prey on a person’s ego, pride or desire to be recognized. The emails below are just a few of the many that I have received in the last few months urging me to attend an Education Summit 2027 or a 2027 Education Conference in which “my story” will be featured to participants or because my name has been nominated for recognition. But these many emails have so many red flags about them! For example, they all talk about an Education Summit/Conference and say things like “we’re being selective,” “we’re putting together…” and “we are highlighting forward-thinking educator….” But who exactly are “WE?” They don’t say. And below, Pamela sent her email from a free Gmail account called “piper26590smith” and Lisa sent her email from a free Gmail account called tatumloopchanning. How’s that for sketchy! The many other emails I’ve received and asking me to participate have come from other free Gmail accounts as well. So what’s the fraud? I will have to pay a lot of money to attend this conference! But WOW, the accolades and awards I’ll receive! Who is running this conference, you wonder? We haven’t a clue! Certainly no one with any real credibility based on these bogus emails. (Check out Kevin Fitzgerald’s excellent article on Medium.com about being targeted by a vanity scam in 2019.)
Microsoft is saying that Russian hackers are targeting people via hotels, conferences and other hospitality WIFI networks worldwide! Yikes! Read more about this threat…. https://www.malwarebytes.com/blog/news/2026/08/travelers-targeted-when-logging-into-hotel-wi-fi-networks
As we’ve written about many times, a woman was hired for a remote job after a short text-based interview. She then received a $4000 check to purchase equipment for her new job. Can you say “advance check” scam?
A young man tried to see if his Mom would fall for his voice cloned by AI. Guess what happened?….
https://cybernews.com/ai-news/voice-clone-scam-ai-mother/
According to the Consumer Federation of America, Americans lost about $148 BILLION dollars in 2025 to fraud! Shocking! But perhaps unsurprisingly, the article also mentions that Meta’s products are described as a “cornerstone of the fraud economy.” And, according to this article, Meta doesn’t take down an advertiser flagged as fraud unless it is reported 32 times! SOMEONE NEEDS TO HOLD META ACCOUNTABLE, PLEASE!
This article is from PCworld on a variety of scams and how to better protect yourself…
Would you guess that there are hundreds, if not thousands, of fake AI-generated videos selling useless health supplements and other drugs online?
Sadly, scammers impersonated a Sheriff’s Deputy and tricked a victim into giving them $23,000! https://www.yahoo.com/news/us/articles/victim-loses-23k-scam-where-143235973.html
Unfortunately, the FBI says that cybercriminals are hacking into victims’ online accounts to steal their intimate pictures. Why ANYONE would keep intimate photos online is an enigma to us!
https://www.yahoo.com/news/us/articles/fbi-says-cybercriminals-hacking-victims-193823655.html
For Victims of Fraud:
Scam Alert is an international victim reporting and intelligence platform. It gently guides scam victims through a detailed process to record essential evidence such as crypto wallet addresses, transaction hashes, and scam websites. Reports are enhanced with blockchain analytics to uncover typologies, link cases, and map criminal networks. Victims receive a report for submission to their local authorities, while Scam Alert works directly with LEAs, WASPs, and exchanges to ensure intelligence is delivered in a digestible format. With victim consent, Scam Alert even provides follow-up updates if there is further related activity and information that could benefit the victim, such as asset seizure by authorities. This service is free-to-use for scam victims: https://scam-alert.io/


Phishing Fraud Targets a Small Business Owner & Malicious Mimics
Last week we were contacted again by a small business owner about a nasty phishing email he received. Phishermen tried very hard to target his business. They sent him an email that looked like it came from his own business security team, informing him that “someone may have accessed your account.” The email repeated his business domain four times and tried to use his business logo, though it wasn’t displaying properly. The man first noticed that the email was sent from a domain called gioscafe[.]com, a family-owned Italian restaurant that is being misused. The link to “Review & Secure Your Account” pointed to a misused Amazon AWS service. When we visited that destination, we also found a very clever presentation of the man’s business information, email and name. But he confirmed that this is not what his login window normally looks like. This login link was also found to be a phishing fraud by VirusTotal.com.
This verified sponsor shows phishing statistics from around the world


Reimbursement Payment & Liberty Crest Financial Bank
In early August, Scambaiter Rob had an interesting exchange of emails with someone named Arnold W. Donald. Arnold Donald claimed that Rob was to be compensated by a settlement program initiated through the United Nations Capital Development Fund. If you try to read the full email below, sent from a free Gmail account to Rob, you’ll likely conclude that this is complete nonsense and barely understandable! Oddly, Arnold Donald provides Rob with information about a Bank of America account, but then proceeds to tell him that he needs to contact Mr. Walton H. Henry, at an affiliated bank called the Liberty Crest Finance Institution. This is where this fraud became really interesting! Visiting this bank’s domain at libertycrestfin[.]com, we found a fairly robust banking website!
However, the libertycrestfin[.]com website was full of anomalies and suspicious red flags, including….
- The bank claimed to have been founded in 1998 and has been around for more than 25 years. And yet, their domain, libertycrestfin[.]com, had been registered less than 3 months earlier!
- The Liberty Crest Finance Bank claimed to have over 50 branches. However, they only showed one address anywhere on their website and it was completely fictitious! Their address was 123 Finance Ave, New York, NY 10001.
- On the Liberty Crest Finance “About Us” webpage, they showed photos and names of the Bank’s Leadership Team. Using a Google reverse image search, we easily discovered that the photos of these bank employees were taken from photo-selling services online, such as Alamy. For example, Mr. Kenji Nakamura, the supposed CEO, had a photo that was coded on their website as “asian-male-in-suit-scaled.jpg.” This photo was taken from this webpage at Alamy photos of a “serious Vietnamese businessman.” Another photo showed their Chief Financial Officer, named Marcus Johnson. But the photo of Marcus Johnson was taken from this model photo at Magnific.com!
Once again, it is far too easy to lie online! It is critically important to verify that what you see is true or false!


Package Delivery Notice & Your Order is on the Move!
Apparently, cybercriminals are using package delivery notices to trick people into clicking very malicious links! For example, in early August, one of our readers received an official package delivery notice, via email. However, he noticed that this email was sent from a server in Brazil (“.br”). He certainly wasn’t expecting anything from Brazil! He also noticed that mousing over (but NOT clicking) the link to “VIEW DOCUMENT” showed that it pointed to a website he did not recognize called alphaolab[.]com. WARNING: DO NOT VISIT THIS WEBSITE! Sucuri.net found malware lying in wait on this website! A Whois lookup showed that alphaolab[.]com was registered in France in 2024. LUNGE for the delete key!
In another example from early August, Scambaiter Rob received the email below about an order he supposedly placed somewhere. The email said that his order had shipped and was on its way. But what order? The email didn’t say what had been ordered. And, rather oddly, this email was sent from a website called Cuba-condos[.]com. Also, if you want to see the order number, or estimated delivery date, you were asked to click a link. The link to track your order appeared to point to Google’s Ad Service. HOWEVER, looking more closely at that link shows that it contains a redirect! Your click will be redirected to a website called deliverytra[.]top. Domains that end with DOT-top are crap domains purchased almost exclusively by cybercriminals! This domain was registered less than 3 weeks earlier and already found as malicious by two security services on VirusTotal.com! It is VERY IMPORTANT to look closely at links and learn to recognize when they contain redirects! You know what to do now with this email!


One of our readers reported this nasty text below. It claimed to be a recall notice for an item purchased in June. But it was sent from a phone number, 509-208-2715, that doesn’t belong to Amazon! Also, the link in the text didn’t point to Amazon. It pointed to the domain lihi2[.]me. This domain is owned by a company in Taiwan and used for link-shortening services. A whopping NINE security services on VirusTotal found that link to be malicious!
Deeeeleeeete!
Oh No! Your iPhone is at risk! So says this scam text that was sent from a phone number in Morocco to an American in the US. It’s sooooo important to look at the sender’s information in the texts you receive. This text wants you to call the scammers back at 817-521-4552 so they can try to manipulate you into moving your money into their hands. Don’t believe this nonsense when they tell you your phone will be blocked permanently! That is utter nonsense.
Until next week, surf safely!
Copyright © 2026 The Daily Scam. All rights reserved. You are receiving this email because you have subscribed to thedailyscam.com
Marblehead, MA 01945
















