Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Your ‘boss’ wants gift cards. This favour should wait

A quick message, an urgent request and photos of scratched-off codes: learn how the boss gift-card scam works and how to verify the request safely.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
6 September 2026
READING TIME
7 min read
TOPIC
Human Security
Your ‘boss’ wants gift cards. This favour should wait

“Do you have a minute? I’m in a meeting and can’t talk.” A few messages later comes the request: buy six gift cards for clients, scratch off the codes and send photographs. It must be done quickly and quietly because the cards are meant to be a surprise.

It sounds like a small favour for a manager. It may instead be a simple scam in which authority, urgency and the desire to help replace the company’s purchasing process. There is no malicious file or clever technical trick. The scammer only needs to reach someone who does not want to disappoint their boss.

Why scammers ask for gift cards

A gift-card code behaves much like cash. Once the code has been shared, the scammer can spend the balance or resell it quickly, even while the physical card is still sitting on your desk. A photograph of the revealed number and PIN can therefore be enough to lose the money.

Businesses do buy rewards and presents. The difference is the process around the purchase. A genuine order has a purpose, approval, an accounting record and usually a known supplier. A scammer tries to move the conversation to a personal messaging app, bypass colleagues and finish before anybody asks a second question.

Signals that deserve a pause

No single detail proves fraud, but the pattern becomes familiar when several appear together:

  • the message comes from a new number or an address that merely resembles the company account;
  • the sender cannot take a call even though the request is “extremely urgent”;
  • they demand secrecy or want you to bypass normal approval;
  • they ask you to use your own money and promise reimbursement later;
  • photographs of the codes matter more than the cards or receipt;
  • the sender becomes irritated when you try to verify the request elsewhere.

Pausing here is not disloyal. It protects both the company and the person being impersonated.

One sentence that breaks the script

Do not ask the suspicious account, “Is this really you?” A scammer will simply say yes. Contact the manager through a number you already have, open the official work chat yourself or speak to somebody on their team.

Try this:

Of course. I’ll help as soon as it is confirmed through our purchasing process. I’ll call you on the number I have saved.

You do not need to prove it is a scam, keep the conversation going or outsmart the sender. Stop the purchase and verify the request outside the channel where it arrived.

You already bought the cards

If you have the cards but have not sent the codes, do not scratch or photograph them. Keep the cards and receipts, tell your manager or finance team and check the retailer’s return policy.

If you have already shared the codes:

  1. contact each card issuer immediately, report the scam and ask whether the balance can be frozen or refunded;
  2. keep the card numbers, receipts and full conversation;
  3. if you paid from a bank account or payment card, alert the bank;
  4. report the incident inside the company, then to law enforcement or the appropriate response team under your organisation’s procedure;
  5. if you disclosed a password or signed in through a supplied link, change the password from a trusted device and close unfamiliar sessions.

Speed matters, but shame is not useful. In the first few minutes, the organisation needs accurate information rather than someone to blame.

Make it easier for staff to say “hold on”

A good process should protect people from pressure created by hierarchy. Require a second approval for gift-card purchases and make it clear that managers welcome a verification call. Decide whether staff should ever use personal funds for an urgent company purchase.

Awareness exercises should include text messages and chat apps, not only email. The most useful outcome is not memorising a list of warning signs. It is building a habit: an urgent financial request through an unusual channel must be confirmed independently.

Source and Breachroad’s conclusion

In a 2026 consumer alert, the US Federal Trade Commission describes this exact script: a supposed manager asks an employee to buy gift cards and send the numbers or PINs, while the employee should verify the request through a known channel. The FTC also advises keeping the cards and receipts and contacting the issuer quickly if a code has been shared.

That source supports the scam pattern and immediate recovery steps. Dual approval and a blame-free reporting culture are Breachroad recommendations based on how organisations can make safe behaviour easier under pressure.

For the wider impersonation pattern, read our guide to business email compromise. Teams that want to practise calm verification under pressure can explore Breachroad’s cybersecurity awareness training and phishing simulations.

SHARE / COPY