← All terms

Gift Card Scam

A gift card scam is a fraud in which attackers impersonate executives or vendors to pressure employees into buying gift cards and sending the redemption codes.

A gift card scam is a fraud in which an attacker — typically impersonating a senior executive, manager, or trusted vendor — pressures an employee into purchasing gift cards and sending back the redemption codes. It is one of the most common low-value variants of CEO fraud, and it thrives because gift card codes are effectively cash: instantly transferable, easily laundered through resale markets, and almost impossible to recover once shared.

How it works

The attack usually opens with a short, urgent message that looks like it comes from the boss: "Are you at your desk? I need a favor." It arrives by spoofed or lookalike email, or increasingly by text message (smishing) to the employee's personal phone, where corporate email filters cannot see it. Once the employee responds, the story lands: the executive is stuck in a meeting and needs gift cards for a client, a partner, or an employee-appreciation surprise — today, quietly, as a favor.

The script is engineered to suppress verification. Urgency ("before the meeting ends"), authority (the CEO's name), secrecy ("it's a surprise, don't mention it"), and flattery ("I knew I could count on you") each close off a path the employee might use to check. The victim buys the cards with personal or company funds, photographs the scratched-off codes, and sends them. The attacker drains the value within minutes, often reselling the codes on secondary markets.

Losses per incident are small compared to wire-fraud BEC — our business email compromise defense guide covers the full playbook — but the volume is enormous — the low amounts fly under approval thresholds and often go unreported out of embarrassment.

How to defend against it

  • Make the policy explicit: the company never asks employees to buy gift cards, for any reason, from any level of management. An absolute rule leaves nothing to judge under pressure.
  • Verify out-of-band. Any unusual request from an executive gets confirmed by calling or messaging them on a known channel — never by replying to the request itself.
  • Simulate the lure. Gift card pretexts belong in your phishing simulation scenarios, including SMS variants, so the "urgent favor" pattern is recognized on sight.
  • Normalize reporting. Employees who paid personally often stay silent; make clear that reporting is welcomed and blame-free, because each report exposes an active campaign.

Related terms

CEO FraudCEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.SmishingSmishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo