An SMS, email, or WhatsApp message says your Uber account is on hold, a trip was flagged for fraud, or “Uber Support” needs you to verify a payment before your driver rating resets. The agent asks for your password, the SMS MFA code Uber just sent, or payment in Apple, Google Play, or Steam gift cards to “release the hold.” A related script hijacks the account first, then the thief’s fake help desk sells you a recovery.
Same password-and-gift-card playbook as Phishing and account takeover, Fake Spotify support scams, and Gift cards and prepaid debit risks. Broader consumer fraud patterns: Credit and debt scams.
Two Uber scripts to expect
| Script | Hook | Goal |
|---|---|---|
| Account-hold / trip fraud alert | “Unusual charge—call Uber Security in 30 minutes or lose access” | Steal login + MFA; drain linked Visa/Mastercard or sell the rider account |
| Post-takeover “recovery desk” | WhatsApp / Telegram “Uber Trust & Safety” after you cannot log in | Cash-out with gift cards, Zelle, or crypto “unlock fees” |
| Driver/rider refund bait | “We overcharged you $89—confirm routing to reverse it” | Remote-access malware or bank details (Apple Support iMessage cousins) |
Uber’s real help flows live in the official Uber app (Account → Help) or Uber’s published support pages—not a random callback number in a text, and not a stranger who needs gift-card PINs.
Red flags
- Support that messages you first on WhatsApp, Telegram, SMS, or email with a phone number to call.
- Anyone asking for your password, MFA code, session cookie, or backup codes.
- Payment demands in gift cards, Zelle, Cash App, crypto, or prepaid debit to “clear a hold.”
- URLs that are not Uber’s official domain (extra hyphens, look-alike TLDs, “uber-secure-help” clones).
- Urgency: “account deleted tonight,” “police report filed,” or “fraud department waiting on the line.”
- Remote-access apps (AnyDesk, TeamViewer) “so we can unlock trips.”
Worked example: the “account hold” SMS
Sam gets a text: “Uber: Account on hold after $74.50 fraud trip. Call 1-888-XXX-XXXX now.” The voice says Uber Trust & Safety and asks Sam to read the six-digit code that just arrived from Uber, then to buy $300 in Apple gift cards at a Walmart self-checkout and read the numbers “to reverse the charge.” Sam buys the cards. The line goes dead. Uber’s real app still shows the usual payment method; the Apple cards are drained.
Sam’s next steps: stop buying cards; from a trusted phone open the official Uber app Help / password reset; change the email password if reused; enable app-based MFA where available; tell the card issuer about the gift-card spend (recovery is often limited); report to FTC ReportFraud and Uber through in-app Help; ignore any “supervisor” callback that asks for more cards. Same irreversible-payment pattern as Zelle and P2P scams.
What real Uber help looks like
- Open the Uber app or type Uber’s official site yourself—do not tap SMS links.
- Use in-app Help / trip issues; Uber does not need gift-card PINs to fix billing or unlock an account.
- Check card charges through your bank or card issuer (Chase, Capital One, Bank of America, etc.) if a trip looks wrong—not a stranger on Telegram.
- Revoke sessions and change passwords after any suspected phish; remove unknown payment methods in the app.
Named brands that appear in these scripts include Uber, Uber Eats, Apple App Store, Google Play, Steam, Walmart, Target, Best Buy (gift-card aisles), WhatsApp, Telegram, and common remote-access tools. None of those gift-card aisles are a legitimate Uber fee channel.
If you already shared codes or paid
- Reset Uber password and review payment methods immediately; change reused passwords elsewhere.
- Call your bank or card issuer about unauthorized Uber trips and gift-card purchases.
- Preserve texts, call logs, and gift-card receipts for reports.
- File ReportFraud.ftc.gov; report the takeover through Uber’s official Help.
- Do not pay a second “escalation” or “cybercrime unit” fee.
Checklist
- Treat unsolicited Uber “hold” calls and texts as hostile until proven otherwise.
- Never give MFA codes or passwords to someone who contacted you.
- Never pay support with gift cards, crypto, or Friends & Family P2P.
- Recover only through the official app or typed URL.
- Revoke sessions and audit payment methods after any scare.
- Teach household members who share rides or Uber Eats the same rules.
Educational only. Not legal, banking, or fraud-recovery advice. Scam tactics change; verify support only through official Uber channels.