How it works

This one splits the identity in two. The from-address is dressed to look corporate, sometimes a lookalike SoFi domain, sometimes a generic business-sounding one, so the header passes a glance. But the reply-to field is set to a personal mailbox the scammer actually controls. When you hit reply, your message silently goes to that Gmail or Outlook account instead of anywhere near SoFi, and everything after that happens in a channel the brand cannot see. Real senders have no reason to route replies away from their own domain, so a corporate-looking front paired with a personal reply-to is a spoofing pattern, not a quirk of their mail setup. Finance apps are a common skin because the money framing feels normal.

The tell-tale signals

What to do

Before replying, look at the reply-to address, not just the from-line. Most clients show it if you expand the header or start a reply and read the To field. If replies go to a personal inbox while the sender pretends to be a company, stop and do not continue the thread. Verify through sofi.com's own partnerships or affiliate contact, started from the site rather than from anything in the email. If you already replied, do not send any further details, contracts, or payment information, and treat the exchange as compromised.