I have not heard of this scam before, but I also cannot think of a way to mitigate it without telling Google and/or cell carriers your IMEI and your personal information.
I would look into buying refurbished from a tech retailer with cash, as opposed to from a random stranger in Craigslist. That way, you can keep the receipt just in case.
Or you could buy a new 8th gen instead of 9th gen. 8th gen is the first one to have the... What was it, the memory tagging or the hardware attestation? Can't remember. Anyway, 8th gen is the one that got the last major hardware security features, from what I remember. You wouldn't be missing out on much, and it would still be a lot cheaper than 9th gen, and it's still new, or refurbished by someone who ostensibly knows what they're doing.