“Okay, so I understand how ridiculous this is going to sound or that I even fell for the scam in the first place,” the original poster wrote. “For context it was my first time selling and I was still navigating the site and how it all works. Essentially I posted my listing and bam, within a minute it was sold, I was thinking wow, I love Vinted!”
The euphoria of a fast first sale is the hook. The scammer had created an account with “vinted” in the username, so when the message arrived notifying the seller that her item had sold and that she needed to verify her account, it looked like a platform notification rather than a buyer message. She had not yet added bank details or verified her email, so the request to “verify your account” seemed plausible.
“It looked legit and branding was the same,” she wrote. “From there it told me I needed to link my internet banking and to select my bank. I thought what a strange way to verify my account, I entered my details. The second I entered them I realised what I had done.”
She contacted her bank immediately. The scammers had already tried to access her accounts and had made a phone call on her behalf attempting to change her personal information. Her accounts were locked. The damage was contained. The lesson was expensive.
The Targeting Precision That Should Alarm Platform Operators
The detail that generated the most concern in the thread was not that the scam worked, but how fast it did.
“Also targeting profiles that put up their first listing,” the original poster noted in a reply.
A commenter confirmed: “This also happened to me when I first started selling a couple of years ago, luckily I clocked what was happening before I inputted any details but that was also my first listing. I thought I was just unlucky but after reading this thread can see I was wrong and they somehow knew I was new!”
Another commenter asked the question directly: “How did the scammer know that you were new there? Can they see that and then they target new people on there on purpose? That’s scary.”
One response suggested a simple explanation new listings have free postage enabled by default, making them identifiable. Another went further: “This is a very important question that Vinted actually needs to account for, because this scheme seems to happen to a lot of people and it doesn’t make sense how they could so quickly link x email address to y Vinted account when users don’t show their email addresses AND know immediately when they’ve posted an item. It makes me suspect internal leaks.”

How the Scam Actually Works
The scammer creates an account with “vinted” embedded in the username. A message from an account called “vinted_support” or “vinted_verify” looks, at a glance, like a platform notification rather than a buyer message. This is the same “Living Off Trusted Sites” technique EcomWatch covered in the Shopify fake invoice scam piece this month, the attack uses the platform’s own communication infrastructure to deliver a message that appears to come from the platform.
The message is timed to coincide with a genuine platform event: the first sale. “The only reason I fell for it was because I actually hadn’t uploaded those BSB and account details so it seemed to have checked out,” the original poster explained. The scam is calibrated to the exact state of a new seller’s account.
The link goes to a fake Vinted site with identical branding. The site asks for internet banking credentials. By the time the seller realises what has happened, the credentials are compromised.
The Expert Who Almost Fell For Something Similar
One of the most valuable comments in the thread came from someone with professional experience in fintech:
“Don’t be embarrassed. The scams these days are very well put together. I used to work for a fintech and thought I was so well aware of all the red flags… well, not once but twice I almost fell victim to pretty obvious scams, ignoring multiple red flags, once even after noticing something was odd, all the way until it got to banking details. It works a treat when a scam lands in someone’s phone or inbox at a time they’re not thinking clearly, maybe from being stressed, very busy, very tired or really excited about something, like a quick sale.”
The last phrase is the one that matters for platform design: “really excited about something, like a quick sale.” The emotional state of a new seller who has just made their first sale is precisely the state in which cognitive vigilance is lowest. The scammer is not exploiting stupidity. They are exploiting a predictable human response to a positive emotional event at a moment of platform unfamiliarity.
What Platform Operators Should Take From This
Username policies are a first line of defence. Allowing accounts to include platform brand names in their usernames creates the visual confusion this scam depends on. Most major platforms prohibit brand-name impersonation in usernames but enforcement is reactive rather than proactive. Automated username screening at account creation that flags platform brand strings would close this gap before the account is ever created.
New seller onboarding is the highest-risk window. A seller who has just listed their first item and received their first sale is simultaneously unfamiliar with platform communication patterns and emotionally primed to comply with requests that feel like normal platform process. Explicit onboarding communication about what the platform will and will not ask for, particularly that it will never ask for banking credentials through a chat message or external link, would reduce the attack surface at exactly the moment of highest vulnerability.
Platform communication should be distinguishable from buyer messages. If platform notifications and buyer messages both appear in the same inbox with similar formatting, the visual distinction between “message from Vinted” and “message from an account called vinted_username” becomes difficult to detect. Separating official platform communications into a dedicated verified channel closes this gap.
“Wild How These Scams Are Getting So Slick That Even Careful People Are Getting Caught”
The thread generated 168 upvotes and 38 comments, many from users sharing their own near-misses. “Wild how these scams are getting so slick that even careful people are getting caught now,” one commenter wrote.
“Scammers are getting smart these days, and they know how to operate,” wrote another. “Don’t beat yourself up. Just learn from it.”
The original poster ended her post the way most fraud victims do: “I am so embarrassed and feel really stupid but wanted to post this in hope it can warn people of just another one of the many Vinted scams out there.”
She should not feel stupid. She was targeted with a precisely timed, contextually accurate, emotionally leveraged attack at the moment of maximum vulnerability. The embarrassment belongs to the platform that has allowed this pattern to persist and to the broader ecommerce industry that treats fraud education as the victim’s responsibility rather than the platform’s design problem.
Our Take
The Scam Is Not Clever. The Timing Is.
The Vinted new seller phishing scam is textbook social engineering at scale.
The technical sophistication is minimal, a fake website with copied branding. The human engineering is precise, target the new seller, time the attack to the first sale, calibrate the request to the gaps in their account setup, and exploit the emotional high of a quick first win. Some ecommerce operators are new, they are excited, and they are being targeted by someone who understands exactly what a new seller’s first five minutes on a platform looks like.
Designing against that, with username screening, verified sender channels, and explicit new-seller onboarding about what the platform will never ask for, is a design specification, not a nice-to-have.













