Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that a romance scam…
Cyber Security

What are the signs that a romance scam is underway?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Cyber Security

Common warning signs include unsolicited messages, rushed intimacy, requests to move to private channels, too-good-to-be-true offers, and links or downloads that were not expected. A scammer may also use false identities, urgent language, or attempts to get money and sensitive information quickly. Any mismatch between the story, the sender, and the request should raise suspicion.

Common signals that the approach has shifted from conversation to scam

The warning signs usually cluster rather than appear in isolation. A romance scam often starts with unusually fast emotional pressure, then moves toward secrecy, channel switching, or a request to keep the relationship away from normal scrutiny. The key pattern is not one odd message, but a sequence that steadily narrows your ability to verify who you are dealing with.

Look for contact that arrives out of the blue and becomes intensely personal very quickly. If the other person avoids video calls, gives inconsistent biographical details, or repeatedly resets the story when asked simple verification questions, that is a strong signal the relationship is being shaped to prevent validation rather than build trust.

  • Unsolicited outreach followed by rapid intimacy.
  • Pressure to leave the original platform for private messaging or email.
  • Stories that feel polished, emotionally urgent, or difficult to verify.
  • Requests to avoid discussing the relationship with friends, family, or colleagues.

Once a scammer has established rapport, the next phase is often a request: money, gift cards, investment help, travel costs, emergency support, or personal data. That request may be framed as temporary, confidential, or time-sensitive, which is designed to reduce the chance that you stop and check the story. Unexpected links, downloads, or forms can serve the same purpose by creating a technical path into your devices or accounts.

Any demand that combines urgency with secrecy deserves extra scrutiny. A legitimate relationship does not require you to bypass normal checks, ignore identity proof, or send sensitive information before the relationship has been independently verified. If the request is disconnected from the relationship timeline or becomes more intense when you hesitate, the interaction has likely crossed into manipulation.

For identity and secret-protection context, NHI Mgmt Group’s Ultimate Guide to NHIs is useful background on how exposed credentials, tokens, and access paths become security risks when trust is misplaced.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC — Organizational ContextRomance scams exploit social context, trust, and communication channels.
PR.AA — Identity Management, Authentication, and Access ControlVerifying a person's identity before trusting requests is central to scam resistance.
RS.CO — CommunicationsScams often push victims into private channels and secrecy to avoid scrutiny.
Recommendation — Assess social-engineering exposure and define escalation paths for suspicious contact. Verify identity before sharing information or taking action on unusual requests. Use trusted communication channels and report suspicious contact quickly.
CIS Controls v814 — Security Awareness and Skills TrainingRecognising romance-scam patterns is a core awareness and social-engineering control.
9 — Email and Web Browser ProtectionsUnexpected links and downloads are common delivery paths in scam campaigns.
Recommendation — Train users to spot urgency, secrecy, and request patterns typical of scams. Block or inspect unexpected links and downloads before opening them.
NIST SP 800-63IAL — Identity Assurance LevelThe scam hinges on weak identity proof and unverified claims about who the sender is.
Recommendation — Require stronger identity proof before trusting high-stakes requests.

Practitioner Guidance

What to verify: Treat consistency as the first control. Verify whether the person’s identity, story, and request still align after a simple challenge, such as asking for a live video call, a normal conversation at a normal pace, or an explanation that does not rely on urgency.

Decision rule: If the relationship advances faster than the evidence supporting it, slow the interaction down immediately. If the other party resists verification, pressures secrecy, or pivots to money or sensitive data, assume the interaction is high risk until proven otherwise.

What to measure: Pay attention to the combination of speed, secrecy, and exception handling. The more often you are asked to ignore ordinary verification steps, the less likely the relationship is genuine.

Practitioner takeaway: The most reliable warning sign is not charm or flattery, but a pattern of requests that progressively remove your ability to verify the person, the story, and the motive.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org