Overview
I recently found out that The Neighbourhood were coming to Melbourne this year for a two-night concert event. Unfortunately, by the time I discovered the event, tickets had already completely sold out.
Rather than accepting that I had missed out, I decided to look for resale tickets through Facebook ticket-buying groups. I posted in two separate Facebook groups:
- Tixel Australia Buy and Sell Concert & Sports Verified Tickets
- Ticketmaster & Tickettek Australia Tickets Buy/Sell/Swap
Within less than 24 hours, I received more than 20 comments and multiple direct messages from individuals claiming to have tickets available for sale.
Almost immediately, several behavioural patterns began to emerge across the responding accounts. In many cases, the Facebook profiles appeared recently created or recently repurposed. Where profile visibility allowed for inspection, profile photos had often only been uploaded within the last few hours or days, with little to no legitimate social interaction visible across the account, including likes, comments, tagged content, or friend engagement.
Another repeated pattern involved identical ticket-sale comments being reused across multiple posts on unrelated events from the same account.
One recurring example observed from a suspected scam account across multiple posts was:
“We’ve got 4x tickets!! if anyone is interested in getting them, Open to offers thanks. Would split in pairs or sell separately 🎫”
Through Facebook’s “Recent Activity” feature, the same account was observed posting this identical comment across multiple unrelated ticket-buying posts, including my own. The repeated reuse of identical wording strongly suggested templated scam behaviour.
Interestingly, other Facebook group members had also begun noticing this pattern.
(example of a user responding with frustration to a suspected scammer)
Although several scam indicators were already present, I became interested in understanding how these individuals would attempt to bypass trusted resale platforms such as Tixel and how they would attempt to socially engineer buyers into moving outside secure payment ecosystems.
To better understand the scam workflow, I began engaging directly with multiple suspected scam accounts while posing as a legitimate interested buyer.
Attempted Tixel Bypass & Social Engineering Tactics
After engaging directly with multiple suspected scam accounts, a consistent behavioural pattern quickly began to emerge across nearly all conversations. Although each account used slightly different wording and communication styles, the underlying objective remained largely the same: attempting to move transactions outside Tixel’s protected payment ecosystem.
In many cases, the accounts initially appeared willing to use Tixel when first contacted. However, once discussions progressed, the conversations would often shift toward explanations as to why full payment supposedly could not be completed through the platform.
Common justifications observed included:
- claims that Tixel delayed seller payouts until after the event,
- claims that Tixel restricted ticket pricing,
- claims that tickets could only be partially listed,
- or requests for buyers to pay an additional “difference” through direct bank transfer.
Several accounts also attempted to make these requests appear more legitimate by referencing genuine Tixel platform mechanics, including payout delays, resale caps, or listing limitations. This created a more believable explanation for why buyers were allegedly required to complete part of the transaction outside the platform.
(Example of a suspected scam account discouraging Tixel use by claiming platform payout delays and preferring direct transfer methods)
(Example of a suspected scam account attempting to split payment between Tixel and direct bank transfer while referencing supposed Tixel pricing restrictions)
(Example of a suspected scam account attempting to split payment between Tixel and direct bank transfer while referencing supposed Tixel pricing restrictions)
Another notable pattern was the repeated use of urgency and convenience-based persuasion. Some accounts claimed bank transfer would allow tickets to be transferred “immediately” or offered small “discounts” if payment was completed directly rather than through Tixel. These tactics appeared designed to encourage buyers to prioritise speed, savings, or convenience over platform security protections.
(Example of a suspected scam account requesting bank transfer payment despite initially agreeing to use Tixel, while attempting to create urgency and offer a discount)
Importantly, once I insisted on completing the entire transaction exclusively through Tixel, communication frequently stopped entirely. Multiple accounts either ceased responding, avoided answering follow-up questions, or abandoned the conversation altogether after secure platform-only payment was requested.
The repeated behavioural similarities observed across multiple unrelated accounts indicated recurring scam patterns and social engineering techniques designed to move buyers outside secure resale platforms.
Identity-Based Trust Manipulation
One of the more sophisticated examples observed during this investigation involved a Facebook account operating under the name “Edward”. Similar to previously observed accounts, the conversation initially began with willingness to use Tixel before quickly shifting toward requests for partial payment outside the platform through direct bank transfer.
The account claimed the tickets could only be partially sold through Tixel, requesting that part of the payment be completed directly through bank transfer instead.
(Suspected scam account attempting to split payment between Tixel and direct bank transfer)
After concerns were raised regarding the safety of the off-platform payment request, the account escalated its trust-building tactics by offering identity “verification” material.
The account proceeded to send multiple forms of identification-based reassurance, including:
- photographs of a Victorian driver licence,
- images of an individual physically holding the licence,
- and short video recordings showing the licence being presented to camera while verbally reassuring that the transaction was legitimate.
(Identity-verification material sent by the suspected scam account)
This behaviour represented a notable escalation compared to the previously observed accounts. Rather than relying solely on urgency or excuses relating to Tixel limitations, the account attempted to establish credibility through increasingly personal forms of “proof”.
Several observations made this example particularly interesting.
The Facebook account name matched the formatting exactly shown on the licence, including the middle initial (“Edward N”), appearing intentionally structured to reinforce authenticity. The profile imagery used by the account also appeared visually consistent with the individual shown within the supplied licence photos and videos.
Further open-source searches revealed multiple Facebook accounts using the same name and profile image. Additional searches combining the name with the suburb listed on the licence surfaced historical surfing or junior lifesaving competition references appearing to match the same individual and approximate age shown within the identification material.
Importantly, these findings do not confirm the identity of the person operating the Facebook account. Several possibilities remain plausible, including:
- the individual shown in the videos and identification material may be a legitimate real person whose images or verification material were potentially compromised and reused by scammers without consent,
- the individual shown may have been knowingly participating in the scam activity while using genuine identification material to increase perceived legitimacy,
- or the identification material itself may have been manipulated, falsified, or partially fabricated.
Notably, after the account realised the scam attempt had been identified and off-platform payment would not proceed, all previously shared identification images and video messages were deleted from the conversation by the account.
(Previously shared verification material being removed after scam attempt had been identified)
This example demonstrated how identity-based reassurance itself can become part of a social engineering workflow. Rather than avoiding suspicion entirely, the apparent objective was to overwhelm buyer hesitation through increasingly personal and convincing forms of “proof”, including government identification and video-based reassurance.
Key Takeaways & Buyer Safety Considerations
This investigation highlighted how modern ticket scams increasingly rely less on obviously fake profiles and more on layered social engineering techniques designed to bypass platform protections while maintaining perceived legitimacy.
Across multiple interactions, several recurring behavioural patterns emerged, including:
- attempts to move transactions outside trusted resale platforms,
- requests for partial bank transfer payments,
- urgency and discount-based persuasion,
- references to genuine platform mechanics to appear credible,
- and, in more advanced cases, the use of identification documents and personalised video reassurance.
Importantly, many of the accounts initially appeared willing to use Tixel before gradually attempting to redirect parts of the transaction outside the platform’s protected payment ecosystem. In nearly every observed example, communication either stopped or behaviour changed once full platform-only payment was insisted upon.
These observations align with broader industry reporting surrounding social media ticket scams. According to reporting by Digital Music News referencing a Lloyds Banking Group study, approximately 90% of reported ticket scams involved social media platforms, with scammers frequently targeting high-demand sold-out events and encouraging victims to complete payment through direct bank transfer methods rather than protected payment systems.
The behaviour observed throughout this investigation also directly conflicted with Tixel’s own platform safety guidance, which explicitly warns users against moving payments or conversations outside the platform.
“Stick to the platform. Don’t ask people to pay or message outside Tixel. We can’t help you if you’ve taken things offline.”
This investigation reinforced an important reality of modern online fraud: social engineering often succeeds not through technical sophistication alone, but by gradually manipulating trust, urgency, familiarity, and perceived legitimacy.
Even when scam indicators are visible, tactics such as personalised reassurance, discounts, identity material, and platform-specific explanations may still pressure users into bypassing secure transaction protections.
For consumers purchasing tickets through resale channels, remaining entirely within trusted payment ecosystems and avoiding direct transfer arrangements remains one of the most effective protections against this type of fraud.