handcrafted websites & more

Website owner tips

Someone Is Impersonating Me to Defraud My Clients

Over the past several days, I have learned that someone is impersonating me and Raven’s Eye Design in an effort to steal money and website login credentials from my clients.

As of September 11, I know of six clients who have been targeted.

One of them lost $550.

The fraudster is sending emails using my name, my business name and information about websites I have built. The messages claim that I have discovered urgent technical problems requiring additional paid work: security problems, plugin problems, SEO problems, compliance problems, domain issues, template licensing and assorted other bits of technical-sounding nonsense.

None of those messages came from me.

I have created a permanent page with the current fraudulent email addresses I know about, examples of the scam, instructions for verifying messages from Raven’s Eye Design and information about what to do if you receive one:

That page will remain current. This post is the story of what has happened so far and what I have learned from it.

At first, I thought someone had targeted my business

That would almost have been preferable.

Once I started researching the fraud, I discovered that web designers and agencies around the world have been reporting variations of essentially the same scam.

The details vary, but the basic recipe is remarkably consistent.

  1. Find a web designer with a public portfolio.
  2. Find the businesses in that portfolio.
  3. Follow the links to their websites.
  4. Find publicly available contact information.
  5. Create a free Gmail account that incorporates the designer’s name or business name.
  6. Then contact the designer’s clients while pretending to be someone they already know and trust.

99designs now specifically warns designers about impersonation scams in which criminals use portfolios, social profiles and “designed by” credits to determine which designers and clients have worked together.

Other web designers have reported the same thing happening to their clients this year.

And the fake technical problems being reported by those designers sound awfully familiar: WordPress updates, domain renewals, plugins, SEO, compliance, security, accessibility and warnings that something terrible will happen to the website unless the client acts quickly.

Apparently my scammer has read from the same menu.

My portfolio appears to be the target list

I can’t prove exactly how the person targeting my clients assembled the list.

I can, however, make a pretty good inference.

Raven’s Eye Design has been around a long time. I have many clients and former clients who do not appear in my current website portfolio, including plenty of more recent clients with whom I communicate regularly.

So far, I have no evidence that those people are being targeted.

The confirmed targets instead appear among businesses whose websites I publicly feature and link to from my portfolio.

That is also consistent with what other designers have reported.

This does not require a data breach.

My portfolio is public because prospective clients are supposed to look at it. My clients’ websites are public because that is rather famously the point of having a website. Their contact pages are there because they want people to contact them.

A human can follow that trail.

So can a bot.

And, in 2026, so can an AI agent.

I don’t know whether AI is being used in this particular operation, and I’m not going to claim that it is without evidence. But automating this kind of reconnaissance is no longer technically difficult.

That changes the economics of an old-fashioned confidence trick considerably.

Some of the fake work is wonderfully ridiculous

The scammer does not merely write, “Hi, this is Chad, please send me money.”

There is theater involved.

My clients have received lists of supposedly urgent website problems and proposed packages costing hundreds of dollars. The scammer peppers the correspondence with enough web-development terminology to make it sound plausible to someone who quite reasonably hired me because they don’t want to become a web developer themselves.

More recently, the fraudster has begun supplying screenshots as “evidence.”

One sent to a client this morning included information from a perfectly ordinary Google performance rating and presented it as evidence that the website had some sort of problem.

It didn’t.

The screenshot was real.

The conclusion attached to it was nonsense.

That distinction is important.

A scammer can know something real about your website without having access to your website.

Websites are public documents. Browsers download their HTML, CSS, JavaScript, images and other resources all day long. WordPress sites reveal various information about how they’re constructed. Search engines crawl them.

In this case, the scammer also included material scraped from my client’s own public site.

Again, that doesn’t require hacking anything.

Here’s a screenshot of the most recent one, forwarded to me by a client (click to enlarge):

The real thing being stolen is trust

I’ve been designing and developing websites for a long time.

Some of my client relationships go back to the days when building a website involved slicing a Photoshop design into pieces and assembling the result in HTML.

That’s a lot of accumulated trust.

Clients know that I maintain their websites. They know that I sometimes contact them when something needs attention. They know that I understand technical things about their websites that they may not understand themselves.

The scammer doesn’t need to build that relationship.

He just needs to impersonate the person who did.

That is what makes this fraud more effective than the usual badly spelled email informing you that your long-lost uncle has left $14 million in a Nigerian bank.

The recipient already knows Chad.

The recipient already knows Raven’s Eye Design.

The recipient may have paid me for website work for 10 or 15 years.

So when “Chad” suddenly says there is a website problem that will cost $550 to fix, the scammer begins with a reservoir of credibility he did nothing to earn.

One of my clients paid him $550.

Another was preparing to pay before something prompted him to contact me instead.

Another received a long list of supposed maintenance problems and contacted me because he thought that work ought to be covered by the website care plan he already pays me for.

From his perspective, that was a perfectly reasonable question.

The problem was that I had never proposed the work.

Even warning people is harder than it sounds

As soon as I understood what was happening, I sent a warning to the clients I believed might be at risk.

Then something instructive happened.

Two days later, a longtime client contacted me because he had replied to a September 9 email from “me” and hadn’t heard back.

The September 9 email was from the scammer.

I told him that every legitimate business email I send ends in @ravenseyedesign.com, and that the scammer was using Gmail.

A few minutes later he wrote back:

“I see the name discrepancy now. I should have known because you always use info@.”

Except I don’t use info@.

I currently use hello@ravenseyedesign.com. I also still receive mail at chad@ravenseyedesign.com because I used that address for years.

What mattered was the part after the @.

He had absorbed my warning and almost immediately transformed it into a different rule.

I don’t tell that story to make fun of him. He’s a smart, successful professional I’ve worked with for many years.

It taught me something useful about security communication.

People who don’t spend their days thinking about domains, DNS, email headers and web servers should not have to perform forensic analysis on every email they receive.

The better rule is behavioral:

Start a fresh email.

Call me.

Use the contact form on my website.

Thirty seconds can settle the question.

What I’m doing now

I’ve reported the fraud to Google and the FBI and am working on a report with the Tucson Police Department.

I’m preserving the correspondence my clients send me, including original messages and email headers when available.

I’m documenting the Gmail accounts, payment mechanisms, screenshots and changing claims.

And I’ve just done something else that seems obvious now that I understand the apparent attack method.

I’ve scraped my own portfolio.

I’ve done my best to follow every live client link the same way a scammer could, visit those websites, find the publicly available contact information and assemble the broadest reasonable list of businesses that could be targeted.

Then I warned them all.

That includes the people I’d already warned.

I’ve now heard from two targets who apparently didn’t absorb the first warning, so I’m no longer particularly worried about being repetitive.

For other web designers: this isn’t just my problem

If you’re a designer or developer with a public portfolio, I wouldn’t suggest panicking and taking it offline.

I’m certainly not doing that.

But it’s worth looking at your portfolio through a different pair of eyes.

It isn’t only a showcase of your work.

It may also be a public map of the people who trust you.

The same applies to case studies, “site by” footer credits, social-media posts and other public connections between your business and your clients.

There is no practical way to make a public portfolio simultaneously public to legitimate prospects and secret from criminals.

The better defense is to establish rules your clients can understand.

Tell them what email domain you use.

Tell them how you normally invoice.

Tell them that unexpected requests for money or credentials should be verified independently.

And make sure the people receiving that warning include not just your primary contact, but anyone who pays invoices or has access to the website.

I wish I had done more of that before somebody decided to become “Chad Bush” for a week.

I will now.

If you’re a Raven’s Eye Design client

I’ve created a permanent fraud-warning page containing current information about the scam, known fraudulent email addresses, examples, verification instructions and what to do if you’ve received one of these messages.

Unlike this blog post, I’ll keep that page updated as the situation changes.

And the simplest rule remains this:

If “Chad” suddenly wants money, credentials or urgent website work and you’re not sure it’s really me, don’t investigate.

Just call Chad.

About the Author

Chad Bush

I'm a people-friendly designer, musician and artist who writes code, does yoga and rides bicycles.

View author website

Post navigation

Want to work together?

Yes Let’s talk
Scroll to top