Recovery fraud turns former victims into primary targets. We explain how it works, how to recognize it, and why it is more dangerous than the original fraud.
Recovery fraud

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

 

Imagine that a few months ago you fell into a banking phishing trap. You lost money, filed a report, and have spent weeks trying to recover both financially and emotionally. Then, an email arrives.

 

The sender introduces themselves as the Fund Recovery Unit of the Bank of Spain. They have located the money. They have a file with your name on it. They just need you to pay a small administrative fee to release the funds.

 

It is not the Bank of Spain. It is the same type of scammer, or one who bought your name on a list. And this time, they know exactly where it hurts.

 

What is Recovery Fraud?

Recovery fraud—or recovery scam—is a type of fraud that targets previous victims of other scams. The attacker poses as an official body, a firm specialized in fund recovery, or a bank's anti-fraud department, promising to return the lost money in exchange for an upfront payment.

 

It is, in essence, an advance fee fraud with an added layer of cruelty: it exploits the desperation of someone who has already suffered a deception.

 

In the United States, the FBI recorded over 7,000 cases in 2024, with losses exceeding 102 million dollars. In Spain, the primary vector is email, impersonating organizations such as the Bank of Spain, the CNMV (National Securities Market Commission), the National Police, or invented "anti-fraud units" that sound official.

 

How Do They Know You Were a Fraud Victim?

Scammers access victim data through two main routes:

 

 

Anatomy of a Recovery Fraud Email

Below we analyze a real example of this type of email, built using patterns documented in recent months. Each element has a specific function in the engineering of deception.

 

1. The Sender and the Trap Domain

The From: field of the email says:

 

From: "Fund Recovery Unit - Bank of Spain"
       <recuperacion@bde-fondos-clientes.com>

 

The display name is convincing. But the actual domain is bde-fondos-clientes.com, which has no relationship with the Bank of Spain. The official domain is bde.es.

 

Golden rule: the display name in the "From" field is written by the scammer. The only verifiable part is the address between <brackets>. If the domain is not the official one of the organization, the email does not come from that organization.

 

2. Authentication Fails — and the Email Still Arrives

The technical headers of the email reveal what the eye cannot see:

 

spf=fail (domain of recuperacion@bde-fondos-clientes.com
         does not designate 185.220.101.47 as permitted sender)
dkim=none
dmarc=fail

 

SPF fails, there is no DKIM signature, and DMARC returns an error. The server sending the email (IP 185.220.101.47) is not authorized by the domain of the alleged sender. In any forensic analysis tool, this immediately adds risk points.

 

However, the email reaches the inbox because the domain bde-fondos-clientes.com is not on any blacklist at the time of sending. Attackers register fresh domains precisely for this reason.

 

3. The Five Fraud Signals in the Content

Signal Where it appears in the email
Recovery fraud (+50 pts) "we have located and held in judicial custody funds... that correspond to your victim profile" — compound condition: recovery agency + promise of return.
Impersonation of an official body (+60 pts) Mentions Bank of Spain and National Police, but no link points to bde.es or policia.es.
Unsolicited credit fraud (+40 pts) Notification of a specific amount (€1,847.00) via external email. Banks never notify credits via email.
Premium rate telephone number (+25 pts) 807 441 223 — prefix 807, high cost (~€1.18/min). Fraudulent billing infrastructure.
Artificial urgency (+10 pts) "valid until April 23, 2026" with threat of fund reallocation. Prevents consulting with someone trusted.

 

4. The Payment Mechanism: Why They Ask for €89 and Not €1,000

The 89-euro fee is an amount calculated with psychological precision. It is small enough for the victim to consider it reasonable compared to the €1,847 they expect to recover (a 1:20 ratio). It is large enough to be profitable when multiplied by hundreds of victims.

 

The collection method—Bizum to a personal mobile number—is another unmistakable indicator. No official body collects fees via Bizum. Payments go to personal accounts that are impossible to track and recover once made.

 

If at any point you pay the "release fee," the scammer will ask for another fee. And another. There will always be a new tax, a new bureaucratic unforeseen event, a new reason for a new payment. The promised money does not exist.

 

5. The 807 Number: Double Billing

The contact number 807 441 223 has special pricing: approximately €1.18/min. Scammers benefit twice: they collect the advance fee and earn money for every minute the victim stays on the line trying to "resolve the file."

 

The Bank of Spain serves citizens at 900 545 454, a toll-free number. Any public body that gives you an 807, 806, 803, or 902 to "manage your case" is a fraud.

 

How to Identify and Avoid Recovery Fraud

These are the signs that, alone or combined, indicate that a "fund recovery" email is fraudulent:

 

 

If You Have Already Been a Victim of the Original Fraud

Before responding to any email promising to recover your money, consult your bank directly—using the number on the back of your card, not the one in the email—and file a report with the National Police (www.policia.es) or the Civil Guard (www.guardiacivil.es) if you haven't already done so.

 

April 2026 Update — ESET Report

ESET published a detailed analysis of this threat in April 2026, warning that fraud victims are priority targets because their information circulates on sucker lists: lists of victims that criminals buy and sell among themselves as if they were marketing leads, with data on the amount lost, country, age, and type of fraud suffered.

The report confirms that if you try to negotiate for them to deduct their commission from the recovered money, the scammer always has an excuse. That is because there is no recovered money—the excuse is part of the script.

Source: ESET WeLiveSecurity — Recovery scammers hit you when you're down (April 2026)

Dominios falsos de BTS ARIRANG: cómo detectar entradas falsas a conciertos