WSJ Prime7.00%▲ 25 bpsSOFR3.87%▲ 23 bpsFed Funds Target4.00%▲ 25 bps10-Yr Treasury5.22%▲ 42 bpsDiesel, retail$6.199▲ 60¢Bank C&I Lending$2,959B▲ 0.82%WSJ Prime7.00%▲ 25 bpsSOFR3.87%▲ 23 bpsFed Funds Target4.00%▲ 25 bps10-Yr Treasury5.22%▲ 42 bpsDiesel, retail$6.199▲ 60¢Bank C&I Lending$2,959B▲ 0.82%

Front Page › Brokers & Harassment › Industry Scams

Scam Report

The email said her website's search bar was a wiretap. Pay $7,500.

Letters claim your website's pixel or search bar is an illegal wiretap and demand fast payment. The Texas AG's red flags and what to do before you pay.

Metal wiretap clips clamp onto a glowing computer screen beside a sealed envelope on a dimly lit office desk.
Scam Report · Brokers & Harassment

"Your website unlawfully intercepted my communications. A draft complaint is attached. Resolve this within 14 days for $7,500, or I file."

Tasha read it twice at 11 p.m., standing behind the counter of her bakery after close. She sells cakes. Her website has a menu, an order form, a little search box and the Meta pixel her nephew installed so her Instagram ads would work.

The email had screenshots. Her homepage. Her search bar. A line of code with her pixel ID circled in red. Then twelve pages of something that looked exactly like a lawsuit, with her LLC's name typed in the caption.

It cited a California law. Tasha has never been to California.

The letter threatened a large per-violation amount. The math underneath it said every visit could count. By midnight she had her card out and a payment link open.

Tasha is a composite. The letters aren't. On September 17, Texas Attorney General Ken Paxton warned of a "recent surge" of what his office called scam demand letters hitting businesses and nonprofits. They claim that ordinary website tools, like cookies, pixels, analytics and search bars, count as illegal "wiretapping" under the California Invasion of Privacy Act, a 1967 eavesdropping law. The AG says the letters may come with screenshots of your own site and a draft complaint, and they push for immediate payment to avoid a lawsuit.

Here's the twist. Some of these letters are real legal claims, and some are pure pressure. From the outside they look the same. That's the whole trick: there's no way to know which one you got, so you're tempted to pay just to make it stop.

The AG's alert says letters like these "may exaggerate or misrepresent" a violation. One serial sender has been declared a vexatious litigant by a federal court in California. A July order bars him from filing new website-privacy cases in that court without a judge's permission first. A law firm that has handled more than a dozen of these says thousands of businesses have received them since fall 2025, many with no real connection to California.

And the law itself is unsettled. California courts are split on whether this old wiretap law even covers a pixel, and two appeals are pending.

Red flags

  • "Pay in 14 days or we file." The deadline comes from the sender, not a court. A demand letter isn't a court order, and you don't have to pay on the spot.
  • Screenshots of your own site plus a "draft complaint." The Texas AG names both as features of these letters. Your site is public, so anyone can screenshot it in a minute.
  • A tiny business, a huge number. The letter threatens a large per-violation amount and suggests every visit counts. That math is the pressure.
  • A state you don't do business in. A neighborhood bakery that has never shipped a cake out of state getting a California wiretap claim is exactly the pattern.
  • A payment link or a "quick settlement" before anyone has looked at your site. Real disputes get reviewed. Shakedowns get paid.

What to do

  1. Don't pay, and don't reply yourself. The Texas AG says not to respond to the sender or pay without first getting qualified legal advice, if you can.
  2. Don't ignore it either. Save the email, every attachment and the date it arrived.
  3. Freeze a snapshot of your site before you change anything. Screenshot the homepage, any form, your cookie banner and your privacy policy, with the date showing. Then check which pixels, chat widgets and analytics tags load before a visitor clicks "accept."
  4. Get privacy help. Look for a privacy or website-tracking attorney (your state bar can help you find one), and ask your insurer whether a cyber or liability policy covers it.
  5. Fix it going forward. With that help, set nonessential trackers to load only after a visitor agrees.
  6. Report it. If you think a letter is fraudulent or abusive, report it to your state attorney general (find yours at naag.org) and at ReportFraud.FTC.gov. In Texas, the AG's Consumer Protection Division takes reports at 1-800-621-0508.

Tasha closed the payment tab. The pixel's still on her site. Now it waits for a yes.

Sources:

More from Scam Report

The series →

She tapped "approve." Her 214 Google reviews got a new owner.

Industry Scams · Oct 9

The skid steer was $28,500. The dealer was real. The phone number wasn't.

Industry Scams · Oct 8

Your $18,412 tariff refund is ready. Just scan the QR code.

Industry Scams · Oct 7

More in Brokers & Harassment

All →

Stop the Calls, Part 8: the voicemail that never rang

Your Rights & the Law · Oct 10

Your green-card co-founder owns 5%. SBA says no loan.

From the Notebook · Oct 10

Stop the Calls, Part 7: one word ends the text thread

Your Rights & the Law · Oct 9

Getting the calls? Shut it down.

MCAFax was built to do the thing you can't do from inside the room: make the phone stop. Check any broker against our member-built database, send cease & desist letters from your own Gmail, and build the paper trail. Some laws, like the TCPA, put statutory damages on illegal calls — whether they apply to your calls depends on your situation, and business lines get less protection than home ones. It's free, and we're not a law firm.

Join the network