Every artist who posts work online eventually gets the message. A polite stranger loves your style, has a generous budget, and needs a commission finished quickly. Sometimes it is real. Increasingly it is not. Artists have become a favorite target for online fraud, because a working illustrator combines three things criminals want: an audience, a payment method, and a professional habit of opening files from people they have never met. This guide covers how those scams work and how to shut them down.
The short answer
The threats aimed at artists are mostly social rather than technical. Someone pretends to be a client, a brand, or platform support, and persuades you to open a file, click a link, or refund money that never really arrived. Two habits stop almost all of it: never run a file a stranger sent you, and never act quickly because a message says you must.
Key takeaways
- Treat every unsolicited commission offer as unverified until you have checked the sender independently.
- Never open executable files from clients. Real reference material arrives as images, PDFs or a shared folder, not as a program.
- Turn on two factor authentication everywhere, and use an authenticator app or passkey rather than text messages.
- Back up your artwork properly, because cloud sync is not a backup and a corrupted file syncs instantly.
- If you sell prints or take payments through your own website, you have crossed into running a small business, and the security bar rises accordingly.
Why artists get targeted
It is tempting to assume criminals chase banks and big companies. In practice they chase whoever is easiest to reach and most likely to respond, and the creative community scores badly on both counts for entirely understandable reasons.
Artists are publicly reachable by design. Your portfolio, your email address and your contact form exist precisely so strangers can approach you with work. You are professionally obliged to be friendly and responsive to people you do not know. You routinely open files from clients: references, briefs, mood boards, brand guidelines. And a growing account, whether on Instagram, YouTube, Patreon or a marketplace, is itself valuable, because an established following can be sold, used to scam your followers, or held for ransom.
The tooling has also improved on the attacker’s side. Scam messages that were once riddled with obvious errors are now generated in fluent, flattering English, with variations produced automatically so the same campaign hits thousands of artists without repeating itself. Illustration industry groups documented exactly this pattern through 2026, with waves of AI generated approach emails arriving through artists’ own website contact forms, each version slightly different, all leading to the same place.
The FBI’s Internet Crime Complaint Center recorded more than three billion dollars in losses to business email compromise alone in its 2025 annual report, and separately tracked over 893 million dollars in losses connected to fraud using artificial intelligence, largely convincing written content, synthetic voice and video. Freelancers rarely appear in those headline figures, but the techniques reaching them are the same ones being counted.
The scams built specifically for artists
| Scam | How it opens | What they actually want | The tell |
| Overpayment commission | Enthusiastic client agrees to your rate immediately, then “accidentally” pays too much | You to refund the difference before their fraudulent payment reverses | Any request to return part of a payment, ever |
| Malicious reference file | Client sends a link to references in a password protected archive or an installer | You to run malware that steals saved passwords and session cookies | Archives with passwords, or any file ending in exe, scr, bat or msi |
| Fake brand collaboration | Well written sponsorship offer from a recognizable company, with a contract attached | The attachment or link, which delivers information stealing malware | Free email domains, urgency, and contracts sent before any call |
| Fake job offer | Recruiter approaches on LinkedIn or Discord, conducts a plausible interview process | A “role details” file that is actually a malware dropper | Any hiring process where files must be run rather than read |
| Platform support impersonation | Message claims your account was reported and will be deleted unless you verify | Your login details and two factor code on a lookalike page | Platforms notify inside the app, and never ask for your code |
| Contact form approach | Flattering enquiry through your own website form, referencing your portfolio vaguely | You to visit a prepared site or open an attachment | Praise with no specifics, and no mention of an actual project |
The overpayment scam is the oldest and still the most common. The mechanics are always identical: a payment arrives and appears in your balance, you are asked to refund an excess to a third party, and days later the original payment reverses because the check was fraudulent or the card was stolen. You are left owing the full amount. The rule that defeats it needs no judgment at all. You never refund a client, in any currency, for any reason. If a genuine client genuinely overpays, they can request a refund through the payment platform.
The malicious file version is more dangerous because it targets everything, not just this transaction. Modern information stealing malware is not looking for your artwork. It harvests saved browser passwords, session cookies, two factor backup codes and payment details, then hands over your accounts without ever needing your password. This is why a single opened file can be followed by losing your Instagram, your email and your marketplace account in the same afternoon.
Check a client in sixty seconds
Most fake clients collapse under a small amount of specific attention. Run this before replying with anything substantive.
- Look at the email domain rather than the display name, and treat a free email account claiming to represent a known company as a serious warning.
- Search the company name alongside the word scam, since artists share these campaigns quickly in community forums.
- Ask one specific question a real client can answer instantly, such as where the artwork will be used, in what dimensions, and by what date.
- Propose a short video call, which fake clients almost never accept.
- Check whether their urgency is manufactured, because a genuine deadline comes with a project and a real deadline rarely arrives with a payment offer attached.
- Request the brief as plain text in the email body instead of an attachment, and note how they react to that.
That last one is quietly the most effective test. A real client will paste the brief without complaint. A scammer needs you to open the file, and will keep steering you back to it.
Locking down your accounts
Account takeover is the outcome that hurts most, because it takes your audience along with your access. The defenses are unglamorous and take about an hour in total.
Two factor authentication, done properly
Turn it on everywhere: email first, then social platforms, then payment and marketplace accounts. Prefer an authenticator app or a passkey over text message codes, since phone numbers can be transferred away from you through your mobile provider. Save the backup codes somewhere offline, on paper if necessary, because losing access to your own second factor is the most common way people get locked out of their own work.
Your email account deserves the strongest protection you have available. It is the recovery route to everything else, which means whoever controls it controls your entire online presence regardless of how well the other accounts are secured.
Separate your business identity
Use a dedicated email address for commissions, marketplaces and payment platforms, kept apart from the address you use for personal accounts and casual sign ups. This limits the damage when one is exposed, makes fraudulent messages easier to spot, and keeps your professional correspondence out of a mailbox drowning in newsletters. If you own a domain for your portfolio, use an address on it. It costs little and it makes you noticeably harder to impersonate.
Know the recovery path before you need it
Every major platform has an account recovery process, and every one of them is easier to complete if you prepared in advance. Keep a record of the email address and phone number attached to each account, save your backup codes, and keep proof of identity that matches your account details. If you run a business account, keep a copy of any verification documents already accepted. People who recover hacked accounts quickly are almost always people who had this information ready.
Review sessions and connected apps
Both are ignored until something goes wrong. Every major platform lists active sessions and third party applications with access to your account, and both lists tend to accumulate over years. Check them quarterly, sign out of devices you do not recognize, and remove connected apps you no longer use. A tool you authorized in 2022 for scheduling posts may still hold permission to post as you.
Never run the file
This deserves its own rule because it is the single point where a bad afternoon becomes a serious one.
Genuine client material arrives as images, PDFs, or links to established services like Google Drive, Dropbox or WeTransfer. It does not arrive as a program you must install. If a file ends in exe, scr, bat, cmd, msi or app, do not open it under any circumstances, no matter how the sender explains it.
Password protected archives deserve particular suspicion. The password is not there to protect anything. It exists so that email providers and antivirus tools cannot scan the contents before they reach you. The same applies to the common approach on Discord and similar platforms, where someone asks you to test a game or an app they built and supplies a link and a password. That pattern has been used repeatedly to distribute credential stealing malware, and the friendly framing is the point.
Practical habits that cost nothing:
- Preview files in your browser or in a cloud viewer rather than downloading them.
- Turn on file extension display in your operating system, since “reference.jpg.exe” looks harmless when the extension is hidden.
- Treat any file requiring you to disable antivirus or click through a security warning as confirmed malicious.
- Keep your operating system, browser and creative software updated, because updates close the routes that malware uses after the first click.
- If you must open something questionable, use a device that holds none of your accounts.
Protect the work itself
Losing files is more common than being hacked and just as costly. Every artist eventually meets a corrupted file, a failed drive, or a cloud folder that dutifully synced a bad version over a good one.
Follow the simple version of the standard backup rule: keep at least three copies of anything you cannot afford to lose, on at least two different types of storage, with at least one stored somewhere else entirely. In practice that means your working drive, an external drive kept at home, and a cloud backup service.
Understand the distinction that catches people out. Cloud sync is not backup. Sync services mirror changes, which means deletion and corruption mirror too. Backup services keep previous versions you can return to. Many sync services do offer version history, often for thirty days, so find out what yours provides and how far back it reaches, before you need it.
Keep layered working files rather than only flattened exports, since a flattened image cannot be revised and a client revision six months later is much easier with layers intact. And if a piece matters commercially, keep a dated export outside your main folder structure, so a single mistake in one directory cannot take everything.
Art theft, reposting and scraping
This is the concern raised most often, and it deserves an honest answer rather than a reassuring one.
You cannot prevent an image published on the internet from being copied. Anyone can screenshot anything. What you can do is make theft less rewarding, make ownership easier to prove, and respond effectively when it matters commercially.
- Post at display resolution rather than print resolution, since a 1200 pixel wide image looks excellent on a screen and prints badly on merchandise.
- Watermark work in a way that costs a thief effort, ideally across a meaningful part of the image rather than in a corner that crops away.
- Keep original layered files and dated exports, which together constitute the strongest practical evidence of authorship.
- Search periodically using reverse image search on your most popular pieces, which is how most artists discover unauthorized commercial use.
- Learn the takedown process for the platforms you use, since a properly submitted notice to a host or marketplace is usually faster and more effective than a public complaint.
- Check the settings on every platform you post to, because several now offer controls affecting how your work may be used in automated systems, and defaults are rarely the ones you would choose.
Keep proportion about it. Casual reposting by fans is irritating and generally not worth your time. Someone selling your work on merchandise is a commercial injury with a clear remedy. Spending your energy on the second while ignoring the first is the healthier allocation, and it protects the part of the problem that actually costs you money.
When your art becomes a business
There is a moment when a portfolio becomes a shop. You install a store plugin, take card payments, ship to addresses, collect email subscribers. At that point you hold other people’s personal data, and the security question changes from protecting yourself to protecting them.
Most artist websites run on common content management systems with a stack of plugins for galleries, stores, forms and newsletters. Each plugin is code written by someone else with access to your site, and outdated plugins are the most common way small websites get compromised. Automated tools scan continuously for known vulnerable versions, which means nobody chose you specifically. The practical response is unexciting: keep the platform and every plugin updated, remove anything you no longer use rather than leaving it deactivated, delete unused administrator accounts, use a strong unique password with two factor authentication on the admin login, and take regular backups of the site itself as well as its contents.
One structural decision matters more than all of that. Let an established payment processor handle card details, and never store card numbers yourself. Reputable store platforms do this by default, which means a compromise of your site exposes far less. It also removes an entire category of obligation you do not want.
If your shop grows to the point where a serious number of customer records and orders pass through it, or you build anything custom rather than using off the shelf components, the honest position is that plugin updates alone stop answering the question. At that stage a professional assessment tells you whether your checkout, accounts and admin areas can actually be broken into, which is what commissioning penetration testing services provides: someone experienced attempts it deliberately, in a controlled way, and gives you a written list of what they found and how to fix it. This is not a step for a hobby portfolio. It becomes proportionate when real revenue and real customer data are involved.
Selling from the UK, and what the rules expect
If you sell to customers from the United Kingdom, holding names, addresses and order histories brings you within UK data protection law, whether you trade as a sole trader or a limited company. The obligations at small scale are manageable but real.
You need a lawful basis for processing customer data, a privacy notice on your site describing what you collect and why, and separate consent for marketing emails rather than adding buyers to a newsletter automatically. Most organizations processing personal data must also register with the Information Commissioner’s Office and pay an annual data protection fee, which sits at a modest level for the smallest tier, and some limited exemptions apply. If personal data is lost or exposed in a way likely to risk harm to those individuals, you must report it to the ICO within seventy two hours of becoming aware. Keeping only what you need, and deleting old order data on a schedule, reduces both the work and the exposure.
For an artist running a substantial UK store, or anyone building custom functionality where security genuinely needs verifying, working with a provider familiar with UK requirements makes the process considerably simpler, and comparing established options such as the Top Penetration Testing Companies in UK is a sensible way to understand what a proper assessment involves and what it should cost before contacting anyone. For most artists this remains a future consideration rather than a current one, and the earlier sections of this article matter far more day to day.
Getting paid without getting caught out
- Take a deposit before starting work, typically between thirty and fifty percent, which filters out most time wasters and every overpayment scammer.
- Use established payment platforms with dispute processes rather than direct bank transfers from clients you have not worked with before.
- Never accept a check or a payment you are asked to partially return, since this is the overpayment scam in every one of its forms.
- Send invoices from your business email address and confirm any change of bank details by phone, because invoice interception is a real and expensive fraud.
- Watch for payment reversals after delivery on card payments from new clients, and keep records of the brief, the approvals and the delivery.
- Write down your terms, even briefly, covering revisions, usage rights, timelines and what happens if the client disappears.
Clear terms are a security control as much as a business one. Most disputes with genuine clients come from unstated assumptions, and most fraudulent clients avoid anything written down.
An afternoon of setup that covers most of it
| Task | Time |
| Enable two factor authentication on email, social, payment and marketplace accounts | 30 minutes |
| Save backup codes offline and record recovery details for each account | 15 minutes |
| Create a dedicated business email address | 15 minutes |
| Review active sessions and connected apps, removing anything unrecognized | 20 minutes |
| Set up an external drive backup and a cloud backup for your artwork | 45 minutes |
| Turn on file extension display and update your operating system and creative software | 20 minutes |
| Write a short standard reply for commission enquiries, including your deposit terms | 20 minutes |
That last item is worth more than it looks. Having a standard reply means you respond to unexpected offers with a process rather than with excitement, and process is what scams cannot survive.
Frequently asked questions
Someone offered me a large commission out of nowhere. Is it a scam? Not necessarily, but verify before investing time. Check the email domain, ask a specific question about usage and dimensions, request the brief as text rather than an attachment, and propose a short call. Real clients handle all four without difficulty.
I clicked a link or opened a file I should not have. What now? Disconnect from the internet, run a full scan with reputable security software, then change passwords for your email and important accounts from a different device that was not affected. Sign out of all sessions everywhere and check for changes to recovery email addresses, since attackers commonly change those first.
How do I stop people stealing my art? You cannot prevent copying entirely. Post at screen resolution, watermark meaningfully, keep original layered files as proof of authorship, and use takedown processes when someone profits from your work. Focus your energy on commercial theft rather than casual reposting.
Is a watermark worth the damage to the image? It depends on the piece and the platform. Portfolio work aimed at attracting clients often looks better clean, while pieces likely to be lifted for merchandise benefit from protection. Many artists post clean images at low resolution and reserve visible watermarks for their most copied work.
Do I need a business account for commissions? Not always, but separating business and personal finances makes bookkeeping simpler, gives you clearer records if a payment is disputed, and reduces what is exposed if a payment account is compromised. Check the terms of your payment platform, since some restrict business use on personal accounts.
My account was hacked. Can I get it back? Often yes, though it is slower than it should be. Use the official recovery process rather than any service offering to restore accounts for a fee, since those are usually scams themselves. Recovery is much faster if your recovery email, phone number and identity documents already match your account details.
Do I really need to worry about any of this as a hobbyist? The account and file sections apply to everyone, since a hobbyist with a nice following is still a target and lost work hurts regardless of whether it was paid. The website, payment and data protection sections only become relevant once you sell.