Leadership1 publisher3 min readPublished
Lisa Riley is still fielding scam calls 17 months after paying a fake Esta site 16 pounds
Lisa Riley lost 16 pounds to a fake US Esta site and has had scam calls and texts every week in the 17 months since. For anyone booking US travel, the fee is the small part of the loss, because details typed into a lookalike site are sold on and reused.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Riley, a British actor, found the site through a Google search and entered her passport, bank and personal details to apply for permission to travel to the US.
- She realised it was a scam when the confirmation, which normally takes just under an hour, never came and an emailed query brought back a link to a page of jumbled text.
- The callers who have targeted her since often claim to be from her bank, with questions about a money transfer.
- Nationwide building society research suggests 15% of people have given personal information to something that later turned out not to be genuine.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- cost The fee is paid once, but the victim goes on screening calls and texts for months, and each impersonation attempt is a new chance to lose far more than the fee.
- exposure Once details are sold on, any scammer who buys them can contact the victim with enough real information to pass as their bank.
- constraint Checking how a page looks offers little protection against identical copies that AI can produce, so the domain name is the check a traveller can rely on.
- decision Putting the .gov address or the app into US travel instructions removes the search step where Riley's application went to a fake site.
Riley describes a huge increase in scam calls and texts since the fraud [5]. "Calls are once a week, easy - sometimes twice a week," she said. "And the texts even more often." [6] Seventeen months is about 74 weeks. If even the lower rate held throughout, she has taken at least 74 calls from one application, before counting texts [1].
Annya Burskys, head of fraud operations at Nationwide, said the follow-up is routine. "Criminals do sadly retarget people after an initial scam," she said. "They take the personal information they have gained and either sell it on to other scammers or use them to make follow-up bank impersonation calls, texts and emails appear more convincing." [8] The Guardian describes fake Esta sites as copies of the official CBP site whose operators pocket a fee and use victims' personal details for later scams [17].
Riley had little chance of spotting the copy. "The webpage was absolutely identical," she said [10]. She said it also sat high in search results [9]. Criminals can use AI to recreate government sites and often put words such as "Esta" in the domain name, according to the Guardian [11]. A CBP spokesperson said some sites may demand quick action from the applicant, a common way to get people to act without thinking [12]. The Guardian's advice is to use only the official Esta site, which has a .gov address, or the mobile app [13].
A skeptic would say one actor's small loss is a consumer story with little bearing on how a company runs its travel. The record is narrow: one victim's account and one Nationwide survey figure [3]. It does not measure how often Esta victims in particular are retargeted, and it includes no business traveller. I think it bears on the travel desk anyway. What a traveller types into a lookalike form is identity and payment data, and on Burskys's account that data is sold on and reused [8].
The costs fall at different times. Fixing the instructions sent to US-bound staff costs an organisation almost nothing this quarter. Leaving travellers to search pushes the cost later and onto the employee, who on Riley's record could face impersonation contact for well over a year [5][6].
For anyone who has already used a lookalike, the CBP spokesperson said: "Applicants should protect their Esta confirmation number and payment details, retain application records, and review financial statements for unauthorised charges." [14] Suspected fraud should be documented and reported promptly to the applicant's financial institution and local reporting channels, the spokesperson said; the Guardian notes that in the UK this means the bank and Report Fraud [15]. Burskys said: "A genuine call or message from your bank will never ask you to move money, never ask you to share codes" [16].
What to watch
- Bank or Nationwide data on how often first-time scam victims are retargeted, and at what loss, would turn one account into a measured rate.
- Action by CBP or search engines against lookalike domains that use "Esta" to rank high would reduce the risk at the search step.
- Reported cases involving business travellers or company cards would put the travel-policy case on direct evidence.