In 2026, the FTC issued a consumer alert about a scam aimed squarely at childcare providers: fake "parents" who urgently need care, send a check in advance, then ask for part of the money back. It's one sign of a bigger shift. Scammers have realized that childcare centers handle steady tuition payments, run on trust, and rarely have a finance department double-checking every transaction. The good news: every scam in this playbook falls apart against a few simple policies and basic security settings.
This guide walks through the three scams hitting childcare providers hardest right now — how each one works, the red flags, and the exact defenses that stop them. Written for busy directors, not IT people.
Scam #1: The fake parent with the "overpaid" check
This is the one the FTC warned providers about this year. Someone contacts you by email, text, social media, or a caregiving platform. They're moving to the area — often from overseas — and need care for their children right away. They offer to pay in advance and send a check.
The check arrives for more than you agreed. The "parent" apologizes for the mix-up and asks you to send the difference back by wire transfer or a payment app like Zelle or Venmo. Here's the trap: banks make deposited funds available before a check fully clears. You see the money in your account, refund the "overpayment," and days later the fake check bounces — and the bank claws back the full amount from you. The refund you sent is gone for good.
- Red flags: urgency, a family you've never met, reluctance to visit or complete your normal enrollment process, and any check for more than you charge.
- The rule that beats it: never accept a check for more than the agreed amount, and never send money back to someone who "overpaid" you. Only a scammer asks you to refund a check via wire, payment app, or gift cards.
- Structural fix: require every new family to complete your standard enrollment and tour process before any payment changes hands. Scammers vanish the moment real-world verification enters the picture.
Scam #2: Tuition and invoice fraud (business email compromise)
Business email compromise — BEC for short — is the most expensive scam in America. The FBI's latest figures put reported U.S. losses in the billions per year, with the average incident costing a business six figures. And it doesn't require any fancy hacking — just a stolen email password and patience.
Here's how it plays out at a childcare center. An attacker phishes a staff member's email password, logs in quietly, and sets up a hidden forwarding rule that copies any message mentioning "invoice," "tuition," or "payment." They watch for weeks. Then, at the right moment, they email parents from your real account (or a lookalike address one letter off) with "updated payment instructions" — a new bank account, a new payment link. Parents pay the scammer, believing they're paying you. The same trick works in reverse on your own bills: a "vendor" emails that their banking details changed, and your next payment to the food supplier or the playground contractor goes straight to a criminal.
- Red flags: any email that changes payment details, urgent payment requests, slightly-off email addresses, and unexplained "you have a new secure message" links.
- The rule that beats it: payment details never change based on an email alone. Every change gets verified by a phone call to a number you already have on file — not one from the email.
- Tell parents, too: put one line in your enrollment packet: "We will never change our payment account by email. If you receive new payment instructions, call us before paying." That single sentence has saved businesses hundreds of thousands of dollars.
Scam #3: Phishing for your childcare software logins
Your childcare management platform — Brightwheel, Procare, or similar — holds family contact details, billing information, and children's records. That makes staff logins a target. Phishing emails impersonate the platform ("your account will be suspended," "a parent sent you a message"), link to a convincing fake login page, and harvest the password. From there, attackers can see exactly who owes what and impersonate your center with perfect accuracy — which feeds directly into Scam #2. AI has made these fakes dramatically more convincing; we covered that shift in our guide to AI phishing and deepfake fraud.
- Red flags: login links in emails, pressure and deadlines, and pages whose web address doesn't exactly match the real platform.
- The rule that beats it: staff never log in from an email link. Bookmark the real login page and always start there. And turn on multi-factor authentication (MFA) — with MFA, a stolen password alone gets the attacker nowhere.
Why childcare centers make attractive targets
It's worth understanding the "why," because it explains the fix. Childcare centers combine recurring payments (tuition arrives like clockwork), a culture of responsiveness (you answer every parent inquiry quickly — scammers exploit exactly that reflex), small teams with no dedicated finance or IT staff, and a steady stream of legitimate strangers. At most businesses, an urgent message from an unknown person is suspicious. At a childcare center, it's Tuesday. That's why process beats instinct here: your enrollment workflow, your payment-verification rule, and your login hygiene do the skepticism for you, so your staff can stay warm and welcoming with real families.
This is also where good systems quietly help. A structured digital front desk like SenLobby.ai ensures every visitor and prospective family goes through the same verified check-in and enrollment flow — no side channels, no exceptions a scammer can slip through.
If it already happened: your first 24 hours
Speed matters more than anything else. Call your bank immediately — wire transfers and payment-app transactions can sometimes be recalled or frozen if you act within hours. Report the fraud to the FTC at ReportFraud.ftc.gov, and for email-based fraud, file with the FBI's Internet Crime Complaint Center (IC3) — the FBI's Recovery Asset Team has frozen millions in fraudulent transfers when notified quickly. Then assume the attacker still has access: change passwords, enable MFA, and check compromised email accounts for hidden forwarding rules. If parents were contacted with fake payment instructions, tell them promptly and plainly — an honest heads-up protects both their money and your reputation. For the full playbook, see our guide on what to do when your small business gets hacked.
And if you'd rather not carry this alone: this is exactly the kind of thing a good IT partner handles — email security that catches spoofed addresses, MFA rolled out across every account, staff phishing training, and monitoring that spots a hidden forwarding rule before it costs anyone money. That's part of what EDCON's managed IT services cover for childcare centers across Los Angeles, Oxnard, Ventura, and Azusa.
Common questions from childcare directors
What is the fake-parent check scam targeting childcare providers?
A scammer poses as a parent — often relocating from out of state or overseas — and urgently requests childcare. They send a check for more than the agreed amount, claim they "accidentally overpaid," and ask you to refund the difference by wire transfer or payment app. The check later bounces, and the bank holds you responsible for the full amount. Never accept a check for more than you charge, and never refund an "overpayment" from a check.
How do scammers steal tuition payments from daycare centers?
Usually through business email compromise: an attacker gets into (or convincingly spoofs) a center's email, watches billing conversations, then sends parents realistic "updated payment instructions" pointing to the scammer's account. The defense is layered — MFA on email, a policy that payment details never change via email alone, and telling parents you'll always confirm changes by phone.
What should I do if my center was scammed?
Call your bank immediately — transfers can sometimes be recalled if caught within hours. Report to the FTC at ReportFraud.ftc.gov and, for email fraud, to the FBI's IC3. Then change passwords, enable MFA, and check email accounts for hidden forwarding rules the attacker may have left behind.
Why are childcare centers targeted by scammers?
Centers combine recurring tuition payments, busy staff who answer every inquiry quickly, small teams without dedicated IT or finance departments, and a constant stream of legitimate strangers. An urgent message from an unknown "new parent" doesn't raise suspicion the way it would at another business — which is exactly what scammers count on.
Want a second set of eyes on your defenses?
EDCON helps childcare centers and small businesses lock down email, roll out MFA, train staff to spot scams, and set up payment-verification policies that actually get followed. Book a free 30-minute consultation — we'll review your setup, flag the gaps scammers look for, and give you a clear, no-pressure plan.
Book a Free Consultation