Skip to content

From the logs · July 2026

The best lead in our pipeline was a scam.

Last week a birthday inquiry landed in our own venue's inbox: good budget, easy headcount, pay-in-full by card. For two days it sat in our pipeline as a hot lead — that's how good this script is. Then it got flagged, quarantined, and zero dollars moved. Below is the entire thing, verbatim from our CRM, annotated. Venues get this exact script every week. Read it once and you'll never fall for it.

48 hrs

from contact form to full script

5

places one “lead” traced to at once

0

questions a real client asks

29

invisible characters hidden in the text

Exhibit A — the contact formJuly 16 · 11:10 AM · our website

CelebratingBirthday Party

Event dateAug 4, 2026 — a Tuesday

GuestsUnder 50

Will alcohol be served?No ← remember this

Time5:pm - 10pm

“Who referred you?”a completely different full name [4]

Device timezone (auto-captured)Africa/Lagos [4]

IP owner (auto-captured)a server-hosting company [4]

Phone area code925 — East Bay, California [4]

Hello,

U+200EMy name is name redacted, I am having my birthday party in August, and I want it to be held at your venue. Before I proceed with my request, please answer the following questions below.

U+200E1. Do you accept a credit card for payment? [1]

U+200E2. Can you work with my official band performing for the event? [2]

U+200EU+200EI await your urgent response. [3]

U+200EU+200EEmail me: email redacted

U+200EBest Regards

U+200Ename redactedU+200E

The tell you can't see

Every amber chip above is a character that exists in the real message but renders as nothing in a normal inbox: U+200E, the left-to-right mark. There are 29of them across the two messages. Hand-typed inquiries never contain these. Text pasted out of a template that has been copied between documents and mail clients for years does. The message you can read says "birthday party." The characters you can't read say "mass-produced script."

We did everything right. That's exactly what the script counts on.

Our front desk answered the way it answers everyone — fast. The same speed that wins real bookings is what this scam farms for: a responsive venue is a venue that will respond to the next ask, too.

Jul 16 · 11:10 AMForm arrives.
Jul 16 · 11:12 AMOur reply email goes out. Two minutes.
Jul 16 · 11:13 AMOur text goes out: “What kind of event are you planning?”
Jul 16 · 2:21 PMWe call. No answer. (Remember that for later.)
Jul 18 · 11:12 AMFollow-up text and email — standard nurture.
Jul 18The reply arrives: Exhibit B.
Jul 20 · morningFlagged. Quarantined. Zero replies sent to it. Date freed. $0 moved.
Exhibit B — the replyJuly 18 · email

Hello,

U+200EThanks for your Email, the date is 4th August but I'm flexible with the date[5]. I work as an Electrical Engineer with Adriatic yacht Charter presently at Sea, according to company policy this is the best way I can communicate [6] and can make calls once in a while but will be back in a couple of days before my party.

U+200EU+200EI want a private function for my 60th birthday party and I am expecting a total of 30 guests and I have a good budget for this celebration, hence I need you to provide the foods, wines and beverages [7]..

U+200EU+200EAlso, I want the party to be from 5PM - 10PM at your venue, I want you to make a booking with a Diamond Rio Band Entertainment.The Band will be entertaining my guests and they are my Family's favorite. I would like to hand over every other arrangement to you [9]. Do get in touch with the band  Email: bandhandle redacted@gmail.com [8]

U+200EU+200EKindly let me know all that is needed to make the day memorable for me and my family. Kindly go ahead and put up a great show for me and let me know the total cost and I shall advise you with my credit card details for payment accordingly [10].

U+200EU+200ERegards,

U+200Ename redacted.

Below the signature, his mail client quoted our follow-up — sent at 11:12 AM Seattle time, stamped "7:12 PM"in his inbox. That's UTC+1: Lagos. The Adriatic, where he's supposedly at sea, runs UTC+2 in July. [4]

Ten tells, one script.

No single line proves anything — real clients ask about credit cards too, and some really do have their own band. It's the stack. This message fires every tell at once.

01

The first question is about payment.

Before the venue, before the date, before anything: “Do you accept a credit card for payment?” Real clients ask about your space. This script needs to know, up front, whether your card terminal can be used as an exit.

02

The band arrives in message one.

An “official band” is introduced before a single question about the venue itself. The third party is not a detail — it is the entire point of the scam. Everything after this exists to move money to that band.

03

Manufactured urgency, zero urgency behavior.

“I await your urgent response” — from a lead who then took two days to answer and never once picked up the phone. Pressure in the text, patience in the behavior. Real urgency doesn't work like that.

04

One lead, five places.

The party is in Seattle. The phone number is East Bay, California. The device that filled the form runs on Africa/Lagos time. The IP belongs to a server-hosting company, not a home internet provider. The story says the Adriatic Sea. And his own mail client testified: our follow-up went out at 11:12 AM Seattle time, and his reply quotes it as “7:12 PM” — an inbox living at UTC+1. Lagos is UTC+1. The Adriatic in July is UTC+2.

05

A 60th birthday with a flexible date.

“The date is 4th August but I’m flexible with the date.” Nobody is flexible about their own 60th birthday. The date is flexible because there is no party — any date your calendar accepts is fine.

06

Unreachable by design.

At sea, company policy, “can make calls once in a while.” We called on day one; no answer. Every synchronous channel — a call, a tour, a video chat — would kill the script, so the story removes them all in one sentence.

07

He's ordering things we don't sell.

We're a BYOB venue; we don't cater. He asked us to “provide the foods, wines and beverages.” His own form answer said alcohol would NOT be served. He never read our website, and he contradicts his own intake form — because the same message goes to every venue on the list.

08

The band books through Gmail.

The named act is a real, award-winning country band. Real touring acts book through agencies with contracts — not a free Gmail address. This is the money exit: whatever you “book” through that inbox is a wire to the scammer.

09

“Hand over every other arrangement to you.”

Maximum money routed through your hands, minimum questions. Combined with “I have a good budget,” it invites you to inflate the quote — the bigger the charge, the bigger the forwarded slice they keep.

10

Pay in full, sight unseen, card not present.

“Let me know the total cost and I shall advise you with my credit card details.” No tour, no questions, no negotiation — a full prepayment by card, dictated remotely. Stolen card numbers approve exactly like real ones. The payment isn't the happy ending; it's the trap springing.

The math of how it steals.

The scam is not "he doesn't pay." He pays — first, in full, without haggling. Here's his exact ask — he wanted the full space — priced at our venue's published Tuesday rates:

Full space, 5 hours × $450$2,250

Cleaning fee$400

Bartender, 5 hours × $65$325

Alcohol service, 30 guests ($200 minimum)$200

Security, 5 hours × $75$375

Our side of the quote$3,550

+ the "band deposit" we'd forward to a Gmail address$X

01 · The card “works.”

A quote goes out for $3,550 + X. The card approves on the first try — stolen numbers approve exactly like real ones. The scammer is agreeable, grateful, and in a hurry.

02 · The money leaves.

We “book the band”: X goes out of our account to the Gmail-address vendor as a real transfer. This is the only moment of the entire scam that matters.

03 · The real cardholder wakes up.

Two to six weeks later, whoever actually owns that card disputes the charge. The bank claws back the full $3,550 + X — the processor sides with the cardholder, because the card was stolen.

04 · The tally.

We're out the X we forwarded in cash, a dispute fee on top (processors charge $15 or more per chargeback), the processing fees, and a date we held for a party that never existed. If the “band” had invoiced $3,000 — pick any number, the scam scales to whatever you agree to forward — that's a $6,550 charge, a $3,000 cash loss, and fees. Multi-thousand-dollar exposure from one friendly email thread.

Steal this policy — it makes the scam impossible

You don't need to detect this scam to be immune to it. Three house rules, and there is no version of this script that works on you:

  1. 1.Clients book and pay their own vendors, directly. Always. You never contact a vendor a lead hands you.
  2. 2.Payment comes only from the cardholder, only through your standard checkout link. Never card numbers in chat or email, never "on behalf of" someone unreachable.
  3. 3.Money that comes in never goes out to anyone but the person who paid it — refunds return to the original payment method, and nothing is ever forwarded.

And when a lead asks anyway, decline without accusing — tipping a scammer off just improves their next script:

"Thanks for the details! Quick note on how we work: clients book and pay their vendors directly, and we take payment only from the cardholder through our standard booking link. Happy to keep planning the venue side whenever you're ready."

What this incident is turning into.

Every message to a KAIBAvenue is already read by an AI before anyone replies. We're teaching it this script and every script like it — identity checks, content fingerprints, behavior. We won't publish the exact signals; a scammer reading this page gets nothing to rehearse against. The rules above, though, are already how the agent operates: it will not contact a vendor a lead supplies, will not forward money, and will not take a card outside checkout — no matter how good the story is, no matter what it's told. Detection can miss. The rules can't.

The part we're most excited about: venues on KAIBAare a network. When one venue confirms a scam, its fingerprints quarantine the same scammer at every other venue — the same day. This one already did its tour of duty: it's test case #1. Like everything we ship, it runs at our own venue first.

What's real here

Both exhibits are verbatim from our venue's CRM — typos, double periods, and all 29hidden characters included, each rendered as a chip in the position it actually occupies. We redacted the sender's names, email addresses, and phone number: the names rotate, the script doesn't, and the script is what you'll actually see again. Timezone, IP ownership, and timestamps come from the form's standard capture data. Rates are our venue's published 2026 rate card. No money was lost, and no reply was ever sent to Exhibit B.

Scammers work the night shift too.
Someone on your side should.

No card · No call · About 15 minutes