Showing posts with label #CryptoScam. Show all posts
Showing posts with label #CryptoScam. Show all posts

Monday, November 10, 2025

Crypto-less Crypto Investment Scams: A California Case

My readers will know by now that I am addicted to PACER - the Public Access to Court Electronic Records.  When I see headlines like this one, I am compelled to dive in and read every publicly released document related to the case.  

USAO Central California

The headline last month was that Shengsheng He, a 39 year old Chinese native living in La Puente California (described as being a resident of Los Angeles and Mexico City) had been sentenced to 51 months in prison and ordered to pay restitution in the amount of $26,867,242. The press release quotes Matthew Geleotti from the Attorney General's office:

 "The defendant was part of a group of co-conspirators that preyed on American investors by promising them high returns on supposed digital asset investments when, in fact, they stole nearly $37 million from U.S. victims using Cambodian scam centers.  Foreign scam centers, purporting to offer investments in digital assets have, unfortunately, proliferated."

When talking about Crypto Investment Scams, they certainly have "proliferated." They are currently the number one form of cybercrime financial losses in America, for the third year in a row, according to the FBI's IC3.gov.  When we refer to these "Pig Butchering" scams as Crypto Investment Scams, it is easy to forget that many "crypto" scams still rely on the tried and true method of wire transfers to shell companies. When we first started exploring Romance Scams and their link to Business Email Compromise, the mostly Nigerian scammers referred to these as "Wire-wire jobs." A wire goes from the victim to a shell company, and a second wire goes from the shell company to the ultimate beneficiary of the crime. While West African Organized Crime continues unabated, Chinese Organized Crime has taken the top spot and is learning that many of the methods of their West African predecessors are still quite useful.
(figures from the ic3.gov 2024 report)

In the Shengsheng He case each of the victims believed that they were wiring money to fund their crypto investments.  Despite believing they have purchased crypto currency with these funds, they cannot be traced on the blockchain because they do not exist on the blockchain!  The first wire transfer went to any of the dozens of shell companies that had been set up across America under the direction of Lu Zhang, an illegal immigrant from China. (Zhang pled guilty to "conspiracy to commit money laundering on 12NOV2024.)  The second wire in the "wire-wire" job would then send those funds to one of two bank accounts at Deltec Bank in the Bahamas in the name "Axis Digital Limited." Deltec Bank's website is titled "Deltec Bank: Ultra-Sophisticated Private Banking" and boasts of their "robust anti-money laundering framework." 


 


Axis Digital Limited served as an off-shore crypto exchange that seems to have been created for the purpose of taking "wire-wire" proceeds from Crypto Investment Scams and converting the funds to USDT before transferring them on to the Chinese Organized Crime gangs operating the scam centers in Sihanoukville, Cambodia.

The case is being prosecuted in the Central District of California in four parts.

Zhang, Wong, Walker, Zhu - Sea Dragon Trading & the Shell Companies

One of the cases focuses primarily on the network of US-based shell companies created to receive the wire transfers from the victims.  The victims believed they were funding their crypto investments, and would see "deposits" into their imaginary crypto investment accounts that corresponded to the amount of their wire transfers.  Court records show that "at least 284 transactions resulted in more than $80 Million in victim losses." The defendants in this case, with their ages as of December 14, 2023, were named in an initial press release entitled: "Four Individuals Charged with Laundering Millions from Cryptocurrency Investment Scmas Known as 'Pig Butchering'" 
  • Lu Zhang - (36, of Alhambra) was sentenced to 24 months + $7,560,014 restitution
  • Joseph Wong - (32, of Rosemead) was sentenced to 51 months + $7,560,014 restitution
  • Justin Walker - (31, of Cypress) was sentenced to 30 months 
  • Hailong Zhu - (40, of Naperville, Illinois) has not been sentenced yet
Sea Dragon Trading, LLC and Sea Dragon Remodel, Inc were two of the companies created by Hailong Zhu, but the list of shell companies below collectively sent $20,083,987 in wires to Deltec Bank in the Bahamas:
• BFC REMODEL, LLC;  - 408 W Glendon Way, San Gabriel, CA 91776
• BFC SUPPLY, LLC; - 408 W Glendon Way, San Gabriel, CA 91776 
• CREATIVE HOMEGOODS, LLC;  - 823 W Huntington Dr. Apt B, Arcadia, CA 91007
• FUYU COMMERCE, LLC;  - 1140 S El Molino St, Alhambra, CA 91801
• GOOD LUCK TRADING, LLC;  - 2220 Falling Leaf Ave, Rosemead, CA 91770
• HONG'S TRADING, LLC; - 1140 S El Molino St, Alhambra, CA 91801 
• KAIS TEA SET SUPPLIES, LLC;  - 508 Bellows Ct, Diamond Bar, CA 91765
• LEADING CONSTRUCTION, LLC;  - (multiple - unsure)
• LJS REMODELING, LLC;  - 1441 Paso Real Ave SPC 254, Rowland Heights, CA 91748
• LJS SUPPLY, LLC;  - 650 W Duarte Rd Suite 100B, Arcadia, CA 91007 
• LQH SUPPLY, LLC;  - 823 W Huntington Dr, Apt B, Arcadia, CA 91007
• MINGXING REMODEL, LLC;  - 4661 District Blvd, Vernon, CA 90058
• MINGXING TRADING, LLC;  - 2220 Falling Leaf Ave, Rosemead, CA 91770 
• QAG TRADING, INC. - 8811 Garvey Ave, 202, Rosemead, CA 91770 
• QAG TRADING, LLC;  - 3254 Evelyn Ave, Rosemead, CA 91770 
• SEA DRAGON REMODEL, INC;  - 4661 District Blvd, Vernon, CA 90058
• SEA DRAGON TRADING, LLC;  - 1140 S El Molino St, Alhambra, CA 91801
• SHANGHAI FOOD & GROCERIES, LLC;   - 250 W Valley Blvd, Ste M, San Gabriel, CA 91776
• SUNRISE SUPPLY, LLC;    - 823 W Huntington Dr. Apt B, Arcadia, CA 91007
• XIEYUNZHU TRADING, INC;  - 1441 71st STreet, Apt 1, Brooklyn, NY 11228 
• YHM SUPPLY, LLC;  - 401 S Canyon Blvd Unit C, Monrovia, CA 91016
• YHM TRADING, LLC;  - 401 S Canyon Blvd Unit C, Monrovia, CA 91016
• YZX LUXURY, LLC;  - 1036 S Garfield Ave, B, Alhambra, CA 91801 
• YZX TRENDING, LLC;    - 1036 S Garfield Ave, B, Alhambra, CA 91801 

Li & Zhang - the Telegram Connection

In a second case, the defendants were: 
  • Daren Li, 41
  • Yicheng Zhang (39, of China) (sentenced to 18 months and $1,047,226 in restitution)
Zhang & Li controlled four additional shell companies: 
• B&C Commerce, LLC - 180 E Valley Blvd Ste 202, San Gabriel, CA 91776 
• Jimei Trading - 785 King St, San Gabriel, CA 91776 
• SMX Beauty, Inc. - 132 E Emerson Ave, Unit C, Monterey Park, CA 91755 
• SMX Travel, Inc. - 132 E Emerson Ave, Unit C, Monterey Park, CA 91755 

The DOJ described Daren Li as "41, a dual citizen of China and St. Kitts and Nevis, and a resident of China, Cambodia, and the UAE." He was arrested 12APR2024 at the airport in Atlanta.  The DOJ press release "Two Foreign Nationals Arrested for Laundering at Least $73M through Shell Companies Tied to Cryptocurrency Investment Scams" says that Li and Zhang (a resident of Temple City, California) "instructed co-conspirators in the laundering network to open bank accounts in the names of various shell companies. Once the victims sent funds to the shell companies, Li and Zhang monitored the lower-level co-conspirators who transferred the proceeds overseas to bank accounts at Deltec Bank in The Bahamas." The funds were then converted to cryptocurrency and sent to wallets, including at least one controlled by Li. 

Zhang's communications revealed "extensive coordination to facilitate the international money laundering, including chats discussing the commission structure for the network, various shell companies used, victim information, and at least one video from a co-conspirator calling a U.S. financial institution." 

Daren Li is described as being "the leader of the syndicate."  Daren used his Telegram id (@KG71777) to communicate with the Cambodia-based members of the conspiracy.  (Daren's email was: darren1575687@gmail.com).  In court documents, the primary USDT address of the conspiracy is referred to as "the TRteo" address (for the first five characters of the address.)  While TRteo is not an uncommon prefix, there are certainly very few such addresses that have received in excess of $39 Million in deposits, much less the higher number mentioned in the press release of $341 Million! In fact, there is only one. 

Chinese Blockchain intelligence company "BlockSec" blogged about that wallet on their QQ page.  Using their tool, MetaSleuth, they were able to successfully identify the full wallet address, TRteottJGH5caJyy9qFuM8EJJGGCpDaxx6.  The wallet became inactive on 29APR2024, but from its initial transaction on 16APR2021, more than $300 Million USD in more than 16,000 deposits  flowed through that address, including transactions to and from HuionePay. 

BlockSec QQ Post

Because Daren Li is described as being in control of this USDT wallet, it is generally considered that he was the leader of this entire enterprise. In July 2022, a meeting was held in Phnom Penh of the top leadership. Daren Li, JingLiang Su, Shengsheng He, and Jose Somarriba were all present.  Daren Li also controlled a Binance account that received at least $4.5 Million in USDT that originated from "Bahamas Account #2." He was also the source of funds to create that "Bahamas Account #2 at Deltec Bank by transferring $999,383 in USDT. 

Jose Somarriba, Axis Digital, and Itemized Victim Losses 

Jose Somarriba (55, of Los Angeles) (sentenced to 36 months and $26,867,242.44 in restitution) is being held responsible for the losses from 174 victims.  Those victims are listed by their initials and the dollar amounts that each had stolen from them.  The average victim lost $154,409.44!  (The median loss was $61,250.) The victims who had the most money stolen were in the amounts: $5,616,000; $2,340,000; and $1,030,279! Nine victims experienced a theft of $500,000 or more. 

(extract from loss amounts for 174 victims) 

Somarriba was a co-founder of Axis Digital, along with Shengsheng He and Jingliang Su.  He was the one who opened the "Bahamas Account #1" at Deltec Bank which received $36.9 million in wire transfers from American bank accounts. He prepared fraudulent KYC forms to present to the banks as well as being primarily responsible for converting Deltec funds to USDT and transferring the funds to Cambodia via a USDT wallet referred to as "TRteo" in the court documents. 

Jingliang Su - the Dubai Connection

The final of the linked cases is the case of Jingliang Su, (44, of China and Turkey). Su was sentenced to 51 months in federal prison and to pay $26,867,242.44 in restitution.  

Preferring the name "James," Su resided in Dubai.  He was a director of Axis Digital and was a signatory to "Bahamas Account #1" at Deltec Bank. He is described as being "a citizen of China and St. Kitts and Nevis" and a resident of Cambodia, the UAE, and the People's Republic of China.

Friday, October 03, 2025

Scam Compound Operators: Members of The Four Great Families sentenced to death in China

(photo from BBC article "China sentences 11 members of mafia family to death")

On Monday this week, Chinese authorities sentenced to death 16 members of "The Four Families" for the multitude of crimes they committed while operating scam compounds in Northern Myanmar near the Chinese border. This was the culmination of an investigation that has been on-going since July 2023 and that we have been tracking primarily through Chinese Telegram channels that discuss the scam compounds.  Thirty-nine criminals were sentenced in the hearing. Eleven will be immediately executed, while five others have a two year reprieve, during which their sentences might be commuted to life in prison. Eleven more received life sentences, while the rest received sentences of between five and twenty-four years.  But who are The Four Families?  Read on . . .

The Incident at Crouching Tiger Villa - October 20, 2023

In Myanmar this is referred to as the "1020 Incident."  Crouching Tiger Villa, which is also called "Wohu Mountain Villa" was a telecom scam compound that covered 200 acres, and encompassed hotels, shopping malls, and buildings full of high tech equipment.  Ming Xuechang, who was the richest man in the Kokang Autonomous Region had a private army of 2,000 men to help patrol and protect the area. On October 20th a large group of prisoners, forced to work as cyber scammers, rioted and attempted to escape.  In the ensuing chaos, Ming's troops began to fire into the crowd, killing at least 60 (some say 70.) Rumors indicate that some of those killed were undercover Chinese police officers, but some say this is based on the plot of a Chinese movie with a similar theme.  

As a result, on November 12, 2023, the Criminal Investigation Bureau of the Ministry of Public Security issued a reward notice, offering a cash incentive for four leaders of the Myanmar Kokang group headed by Ming.  Within just a few days, all four had been arrested! 

Ming Guoping, Ming Julan, and Ming Zhenzhen were turned over to the Chinese police


Myanmar hands over 10 crime bosses to the Chinese - January 30, 2024

The Record: Crime bosses behind Myanmar cyber 'fraud dens' handed over to Chinese government

(image from: X.com/johnwSEAP )

On December 10, 2023, China issued arrest warrants for Bai Suocheng and ten other key leaders of the Kokang Autonomous Region's telecom and internet fraud rings.  Working with Myanmar's Ministry of Foreign Affairs, six of the ten were arrested and on January 30, 2024, sent to China to answer for their crimes. 

These are the ten in the China Warrant according to the Irawaddy


Two leaders of the Bai Family were among those sent back to China. The Bai family operated many casinos around Laukkaing, especially "the Silver Palace." They had many construction and logistics firm that served their own needs and those of the other families. Bai's most famous brand was the "Yum! Brands" which operated several other casinos that served as scam compounds as well. 

Bai Suocheng -白所成
Bai Yingcang - 白应苍

The Wei family was led by Wei Chaoren ( 魏朝仁 ), operating chiefly from Kongyang Township.  They were significant players in telecom infrastructure and provided SIM Pools for the use of the families.  The Henry Group was the chief company of Wei Chaoren, as well as The Xiaozhu.

Arrested: 
Wei Huairen - 魏怀仁 

Remaining at large from the Wei family were: 
Wei Rong
Wei Qingsong 

The Liu family also operated from Kongyang and other nearby border towns. The Liu family came to wealth in the mining industry and control most of the mining in Kokang.  They were significant players in money laundering. Liu's primary casinos were operated under the name "Fully Light Group." Liu Guoxi has also been linked to organ trafficking. Liu Zhengxiang was the founder of the Fulilai Group back in 1992 which operates a number of casinos in the area. His predecessor, Liu Abao, was known to be a significant drug trafficker.

Arrested: 
Liu Zhengxiang - 刘正祥
Liu Zhengmao - 刘正茂

Remaining at large from the Liu family was: 
Liu Zhengmao 

Ministry of Public Security - May 27, 2024

Ministry of Public Security spokesman Li Guozhong gave a major update on the strategy "Four Specializations and Two Joint Efforts" and their results.  He said that over the past five years, they had worked 1.945 million telecom network fraud cases and that for eight months in a row, they had significant declines in fraud as a result of their efforts.  The operation, which began in July 2023, had specifically targeted the "Four Major Families" ( “四大家族” ) in Kokang and had brought to justice members of the Bai, Wei, Liu, and Ming families. 

In this press conference, Li mentions that Ming Zhenzhen ( 明珍珍  ) had also been taken into custody. 

Myanmar's Cooperation with China's Ministry of Public Security 



September 28, 2024 - The Ministry of Public Security announced that they had made key arrests in Yangon and Mandalay, and that 20 "telecom network fraud crime group leaders and key members" had been arrested and were being handed over the China.  These included Chen Mouwei ( 陈某卫 ) and Yang Mou ( 杨某 ). The press release at that time said that Chen and Yang had "relied on the Four Great Families" of Myanmar's Kokang region, as well as criminal groups "such as Xu Laofa ( 徐老发 )" in order to "control armed forces, set up telecom fraud dens, and carry out telecom network fraud crimes targeting Chinese citizens.  They were also said to be suspected of intentional homicide, intentional injury and other serious violent crimes. 

The Crouching Tiger Villa arrests - December 30, 2024

"Tracking down and investigating the truth! The story of the investigation into the Mingjia criminal group in northern Myanmar.  Chinese people are being "traded" in northern Myanmar.

On December 30, 2024, China's Supreme People's Procuratorate published the first round of charges under the headline "Exposing the Northern Myanmar Mingjia Criminal Group's Fraud, Murder, and Drug-related Activities" ( 揭露缅北明家犯罪集团诈骗杀人涉毒解密数宗罪 ).  At that time, the Wenzhou Municipal court in Zhejiang Province charged 39 defendants, calling the Mingjia criminal group "one of the four major families in northern Myanmar.

They interviewed many victims, who told stories of the promises made to them by the "snakeheads" (a Chinese term for a human trafficker) and the reality they faced when they arrived.  One victim, Li Mouqian, from Guangdong, was sold to the Ming family and told he could buy his freedom for 300,000 Yuan. At Crouching Tiger Villa, he was expected to make 100 phone calls per day and to land three new victims of cyber scams each day.  If he failed to do so, he was beaten.  When he tried to escape with a colleague, he was beaten with steal pipes and his accomplice in the escape was beaten to death. 

The Ming family at that time was led by Ming Zhenzhen (明珍珍 ), the granddaughter of their founder Ming Xuechang (明学昌). Xuechang had been a part of Myanmar's Shan State legislature, representing the Kokang Self-Administered Zone as a member of the Union Solidarity and Development Party.  He was also in charge of the local police.  He controlled a personal army of at least 2,000 men. During a previous cross-border police action against Ming Xuechang, he shot himself rather than being captured, and died in the hospital leaving his granddaughter in charge. 

Between July 2023 and December 2024, the Chinese Ministry of Public Security managed to repatriate 53,000 telecom and internet fraud suspects from northern Myanmar. 


Saturday, September 13, 2025

Attorney Generals go after Bitcoin ATMs for supporting Fraud

On 08SEP2025, the District of Columbia's Attorney General filed a lawsuit against Athena, a "Bitcoin ATM machine" provider with 4100+ BTMs installed. Athena charges as much as a 26% fee when someone deposits cash to buy cryptocurrency. More importantly, the lawsuit claims that 93% of all deposits into Athena “BTMs” in the DC area were made by scam victims.

The main argument made by this lawsuit is that Athena knows that it is facilitating fraud, it is making substantial profit from that fraud (up to 26% per transaction), and that it refuses to refund money to the victims, despite 1/4th of the money still being in Athena's coffers after a transaction!  

https://oag.dc.gov/sites/default/files/2025-09/Athena%20Complaint.pdf


The DC AG goes further, with a very significant accusation:

"Athena also has allowed elderly consumers to deposit very large amounts of cash over short time periods into wallets that Athena knew had already been used by other scam victims. Athena’s ineffective oversight procedures have created an unchecked pipeline for illicit international fraud transactions." 


 The DC AG's lawsuit claims that the average age of the victims who were enticed to depositing fraud funds into an Athena BTM in their district was 71 and that half of them deposited at least $8000!

Despite included statistics showing only 1.2% of elders invest in Bitcoin, the vast majority of BTM deposits are made by those over the age of 60. The FBI’s IC3.gov in 2023 reported $124 Million in Bitcoin ATM scams against those over 60, compared to $33 Million for all other ages combined.

In response to the common claim that Bitcoin ATMs are intended to help the "unbanked", there is nothing to support that claim. Compare that statistic to an FDIC Survey of "unbanked" Americans, which showed that only 1.2% of "unbanked" citizens use crypto for any reason other than "Investment." I loved this survey question by the FDIC in their 2023 survey.

https://www.fdic.gov/household-survey/2023-fdic-national-survey-unbanked-and-underbanked-households-report


The FDIC Survey also broke down crypto usage by household income.

While the DC AG's lawsuit is significant, it was not the first. Iowa's Attorney General filed two similar lawsuits, one against Coinflip and the other against Bitcoin Depot. (Click to see a list of the Factual Allegations for each.) Iowa's lawsuits show that Coinflip BTMs in Iowa were used to assist in the theft of $13 Million from scam victims between Jan 2021 and June 2024, while Bitcoin Depot BTMs in Iowa were used to assist in the theft of $7.2 Million between October 2021 and July 2023. That's $20 Million in scams in a state with only 3.2 million residents.

My favorite quote from Iowa:

“At best, Bitcoin Depot is a willfully blind participant in the victimization of hundreds of Iowans. At worst it is a silent partner to many scammers’ preying on Iowans, taking a cut of each scam with its excessive and deceptive BTM fees that are further paired with a lack of refunds.”

This analyst would believe that statement could be applied to every “Bitcoin ATM” in every state.

Coinflip Lawsuit
Bitcoin Depot Lawsuit

While the process of using a BTM involves the display of several warnings and disclaimers, the lawsuits point out that the elderly victims of these scams are almost always on the phone with a scammer while they conduct the transaction, who is warning them to ignore all of these disclaimers. But the disclaimer itself is given as evidence that the BTM providers are fully aware that their company is being used to facilitate significant volumes of fraud against the elderly, and that this fraud is providing significant revenue to said companies. These images are from the DC AG v. Athena complaint:

Bitcoin Depot has over 8,000 BTMs, but boasts more than 16,000 locations where you can buy cryptocurrency (including their "BDCheckout" where you can purchase crypto at a cash register.) Here's a location breakdown by state, including 414 Iowa locations (and 399 in my home state, Alabama!):

http://branches.bitcoindepot.com/

Coinflip has over 5500+ BTM locations and claims to have processed at least $4 Billion in transactions. But what percentage of those transactions are fraudulent?

https://coinflip.tech/about

Monday, June 24, 2024

Millions and Millions of Fraud Domains: China attacks Illegal Gambling and Telecom Fraud

Last week I was reviewing a publication by the United Nation Office on Drugs and Crime published in January 2024, titled "Casinos, Money Laundering, Underground Banking, and Transnational Organized Crime in East and Southeast Asia: A Hidden and Accelerating Threat."

(URL to the UNODC report: UNODC: Casinos, Money Laundering, Underground Banking ... full report)

(URL to the USIP report: https://www.usip.org/node/160386 )


The reason I was looking into the report is that this 106 page report is about how Chinese organized crime has planted themselves in Casino complexes across Cambodia, Indonesia, Lao PDR, the Philippine, Thailand, and Viet Nam. The same modus operandi that we associate with the crypto investment scams that use the horrible name "pig butchering" to describe the financial grooming that leads to the complete financial devastation of so many Americans. In fact, I discovered the UN report, only by seeing it quoted in he report by the United States Institute of Peace, "Transnational Crime in Southeast Asia: A Growing Threat to Global Peace and Security" where it was mentioned in a footnote.


Examining Chinese Ministry of Public Security reports

The UNODC report shares statistics from a Ministry of Public Security of China note, without providing a URL, that "between January to November 2023, authorities in the country successfully resolved 391,000 cases related to telecommunications and network fraud, totaling the arrest of 79,000 suspects, including 263 'backbone members or paymasters' of cyberfraud groups" (in the countries mentioned above.) This included:

  • interception of 2.75 BILLION fraud calls
  • interception of 2.28 BILLION fraud messages
  • the removal of 8.36 million fraud-related domain names
  • and 328.8 billion yuan (US $46 billion) in funds related to fraud cases.
Since I am working on a project that we call "Twenty Targets for Takedown" that is attempting to shut own illicit websites by terminating their domain registrations and hosting arrangements, the number "8.36 million fraud-related domains" made me shudder. I am fortunate to count among my network some of the leading experts in domain-name related fraud and abuse, the number seemed overwhelmingly high, and I asked my colleagues from CAUCE, the Coalition Against Unsolicited Commercial Email, for assistance in looking into it. One quick opinion was that this could include a definition of domain name that would be more akin to a hostname, similar to what we have on Blogspot. "garwarner.blogspot.com" is a hostname on the domain "blogspot.com" ... but some would call it a "fully qualified domain name" and consider it a separate FQDN than other xyz.blogspot.com or abc.blogspot.com "domains." John Levine helped me solve the "did they really mean millions, or is this possibly a bad translation" by helping me find the Ministry of Public Security site where the article was coming from and share several updated versions of these statistics.


18 Million Websites! 

The latest article we can find, dated 31MAY2024, quotes Li Guozhong ( 李国中 ) the Spokesman for China's Ministry of Pubic Security describing their successes over the past five years.  In 2021, they established a National Anti-Fraud Center which sent out 660 million notices and were able to help stop fraud against 18.44 million people. This most recent article, which is focused on fraud and doesn't mention gambling at all, says that they have "handled 18 million domain names and websites."  That's a machine translation of ( 处置涉案域名网址1800万个 ).  I can confirm the 18 million ... written as 1800 ten thousands - 1800万个.  Handled is perhaps better rendered "disposed of" 处置  (Chǔzhì).  Still unsure how to interpret 域名 ( Yùmíng - Domain name) 网址 (Wǎngzhǐ - website), but I think for now, I'm going to assume it means "URLs" or "FQDNs" as opposed to only registered domains 

The Anti-Fraud Center has intercepted 6.99 billion fraud calls and 6.84 billion text messages and intercepted 1.1 trillion yuan of funds. At current exchange rates, that would be around $151 Billion US Dollars!   

Just since July 2023, 49,000 cyber fraud suspects have been transferred to China from northern Myanmar. 82,000 criminal suspect have been arrested, including 426 key "financial backers" behind the fraud groups.  

Several maps help to demonstrate what's going on in Southeast Asia: 
(Source: Figure 1 from the afore-mentioned USIP report) 

Source: afore-mentioned UNODC report -- note the Myanmar/China border, which is where most of the Chinese rescues and raids have been conducted.

How Much Fraud? $64 Billion to $157 Billion per year!


The US Institute of Peace report estimates that there are as many as 500,000 scammers deployed in the region, earning potentially $64 Billion per year in fraud. The methodology they used for this calculation came from the UNODC report above. On p. 55 of that report, the UN said that they estimated each scammer was earning between $300 and 400 per day, and that they believed there were 80,000 to 100,000 scammers working six days per week in one unnamed Mekong country.  Using that estimate, they gave a "range" of $7.5 Billion to $12.5 billion in scam revenue for that country.  These numbers were calculated consistently with a Chinese MPS report about an initiative they called "Operation Chain Break" which estimated that scam compounds, including gambling and cyber scams, were generating $157 Billion per year. 

China's Ministry of Public Security is actively conducting military style raids to help recover these fraud suspects from northern Myanmar, where China shares a long border with the country, which remains deeply embroiled in a state of civil war. MPS is also working collectively with other Southeast Asian countries and says it has "destroyed 37 overseas fraud dens." 

China Launches Month of National Anti-Fraud Action

Today (24JUN2024) China launched a new month-long "National Anti-Fraud Action" with a nation-wide campaign that declares "Beware of new fraud methods and don't be a tool for telecom fraud."  The campaign uses what China calls a "Five-In" approach, meaning that Chinese citizens will see and spread anti-fraud messages in Communities, Rural Areas, Families, Schools, and Businesses.  Students will be provided materials to share with their families, Employees will be encouraged to share anti-fraud messages and materials with their families and communities, and Chinese Communist Party offices in rural areas and civic organizations will make sure the message is spread in those areas as well. The materials being prepared will be written separately to address the awareness needs of merchants, accounting personnel, minors, and the elderly, describing each fraud typology and helping to describe methods to safeguard from these typologies. A major objective will also be to help understand how to avoid becoming a "tool" or an "accomplice" of these fraud rings, who prey on the financially vulnerable to help them launder the proceeds of their crime.  The Ministry of Public Security will jointly publish the "Overseas Telecom Network Fraud Prevention Handbook with the Ministry of Foreign Affairs and the Ministry of Education to help improve prevention awareness especially for overseas students and diaspora Chinese communities. Major news media and new media platforms will continuously feature anti-fraud reports to strengthen and educate the public on fraud prevention and "continue to set off a new wave of anti-fraud among the whole people the whole society." 

Gee, doesn't that sound like REACT's Erin West and Operation Shamrock -- but with the full cooperation of the Government and Society? 

The announcement of the month of National Anti-Fraud Action concludes with some more recent statistics about the work of the National Anti-Fraud Center.  Just since 2023, today's report says that they have: 
  • pushed out 420 million warning and dissuasion instructions
  • met with 14.77 million people face-to-face to give warnings 
  • made 310 million phone calls to warn vitims 
  • sent 230 million dissuasion text messages
  • intercepted 3.7 billion fraud calls 
  • intercepted 2.96 billion fraud-related text messages
  • blocked 11.619 million fraud-related domain names -- BLOCKED - this may mean "prevented access via Chinese Internet -- which may mean the sites are still available to victimize foreigners
  • intercepted 452.9 billion yuan of funds ($62 Billion USD) 
What does this mean to those of us in the United States?  If China is doing an all-hands "Five-In" awareness campaign and deploying police for face-to-face dissuasion, the fraudsters may very realistically need to INCREASE their targeting of overseas victims to make up for the projected revenue hit this new effort may create. 

To quote Director Easterly at CISA: SHIELDS UP! 

Saturday, December 02, 2023

China continues Pig-Butchering Crack-down

One of my techniques for keeping current on Cybercrime trends is having an "interesting" collection of international news ticklers. This story came to me via X:CyberScamMonitor via a QQ account called "onCambodia." @CyberScamMonitor is a Twitter/X account and Substack account dedicated to tracking online scam and gambling operations in Southeast Asia and documenting human trafficking and human rights abuses. Great work and a strong recommendation to follow if you wish to learn more about the links between #CryptoScams and #PigButchering.

I apologize to the original journalist as I have been unable so far to find the original to give them full credit. For reference, the Chinese article I refer to provides the source as 来源:鲁中晨报 (Source: Luzhong Morning News). The headline is: "Chinese woman was arrested after returning to China! Uncovering the financial backers of a fraud syndicate in Sihanoukville." If anyone has a link to the Luzhong Morning News version, please comment and I will update! This post is mostly just a retelling of their story in English!

The story told, in my opinion, should have the headline "Diligent Police Task Force won't stop tracking Fraudsters!" This story features the Yiyuan County Police who started with a telecom fraud case in their jurisdiction and followed it until they had wrapped up the entire organization and seized 200 million yuan from the criminals, 1/4th of it in cash, but also in real estate, luxury cars, watches, and liquour. That's over $28 Million USD! The case started with a local business who found that one of their employees had sent out 38 million yuan in just a few days. The employee was being extorted after installing a porn-dating app on his phone -- when the criminals learned where he worked they demanded that he send money from his company as well. 

 The case was taken up by the "3.01" Task Force. Yiyuan County is administered as part of Zibo City in Shandong Province of China. Police officers from county, city, and provincial level work together on the 3.01 Task Force.  (Shandong is in the east of China, across the Yellow Sea from South Korea.) The deputy magistrate of Yiyuan, Zhang Xiuguang (张秀光), takes an approach to cybercrime that reminds me of the work of the Garda National Economic Crimes Bureau in Ireland!  Zhang says "Since we established the task force, we have firmly believed that we must recover the losses and hit the core.  From catching the first culprit, we will not withdraw our troops until the case is solved!"

(map of Zibo City from medical article by Lili Liu and Ling Wang)

The case dragged on at a very slow pace, Yiyuan deputy director of public safety Ma Wencheng (马文成) described it as involving the tracing of funds from thousands of accounts and peeling back each account like peeling layers from bamboo shoots. Even with a 100 person task force, very little progress was being made, but that changed with a key arrest on 31AUG2022. The key piece of evidence as a suspicious mobile phone number. Among all of the hundreds of thousands of scraps of evidence, there was a telephone number belonging to a woman in Cambodia. Recognizing that Cambodia is the home of many telecom fraud rings, the head analyst for the task force, Lu Lu, focused on the owner of that number. The decision was made to wait for her to return to China. The police have assigned this key figure the alias Xie Xiaofang. When they learned that Xie was returning to China, the task force rushed to Zhengzhou in Henan Province and arrested her as she was leaving quarantine.

As she was questioned, Xie Xiaofang revealed that her #PigButchering group was based in the Chinatown setion of Sihanoukville, Cambodia. Her job within the organization was laundering the money, but she claimed despite her key role, she only knew middle managers in the gang, and then only by alias. The 3.01 Task Force team began tracking each person traveling to China from Sihanoukville and asking Xie Xiaofang to identify them. Within a few weeks, they had mapped out the leadership of the organization. On 17SEP2022, the team traveled to Jiangxi, Yunnan, Fujian, and other places, arresting two more key members and seven others, followed in quick succession by dozens more, eventually totaling 135 arrests. At this point, the Shandong Provincial Public Security Department thought it was time to reward their team.  The photo below shows the public ceremony where all of the local dignitaries publicly praised the work of the 3.01 Task Force, who had at this point seized 8.5 million yuan (about $1.1 million) and had key leaders of the gang in custody. 

(source: https://zibo.sdchina.com/show/4733923.html ) 


But the team was not done yet. As they interrogated those who had been arrested so far, they realized that there was still a bigger boss. The police assigned him the alias Tang Xiaowei, but they were cautioned by their current detainees that this guy has a "very strong sense of anti-reconnaissance." He only uses cash. He doesn't use mobile phones. He doesn't use credit cards.  He doesn't have a fixed address. But he was known to have a favorite place in Xiamen.  The head analyst, Lu Lu, however, believed that Tang would know about the arrests and would be looking for a way to get out of the country safely, and in the mountains of evidence, Lu Lu believed there was a clue to his exit point. Someone under their surveillance had arranged for a large party in "an Internet celebrity hotel" in Guilin, Guangxi. Lu Lu was confident this would be for Tang. 




Speeding down the highway for nearly 1200 miles with members of the 3.01 task force, Lu Lu's vehicle fell into a pit related to some road construction, but they acquired another vehicle and continued on through the night. They arrived just in time to arrest Tang and his closest associates!  It turned out that Tang and his gang were leaving for the coast that morning where a boat was waiting to smuggle them out of the country and back to Cambodia!  They had the actual top kingpin in their hands and now they could finally pull apart the entire organization.  

Based on the information they acquired, additional arrest teams were sent to Beijing, Shanghai, Tianjin, Guangxi, Hebei, Henan, Guizhou and other cities where 18 teams assigned to different roles for the organization were arrested.  Three technical teams, 1 "payment on behalf" gang, and 14 "point running" gangs totaling 197 additional criminal suspects.  Boxes and suitcases loaded with cash were seized.



While the case that started with the Yiyuan County Police investigating one employee who seemed to be embezzling funds, it led to 38 million yuan ($5.3 million USD) being returned to citizens in Yiyuan and Zibo City and has spawned countless additional investigations as the national and international connections are still being traced. 

This is what COULD happen if we follow the model of the brave Yiyuan Police (the same model which the Garda National Economic Crime Bureaus follows!)  DON'T STOP.  DON'T take your local arrests and be happy with them.  FOLLOW EVERY LEAD.  

We'll close with this quote from Zhang Xiuguan ... 

"No matter how far you run, the Yiyuan police are not afraid of hardships and dangers.  They will catch you no matter how far you go!" 


Tuesday, May 02, 2023

Mirror Trading International's Cornelius Johannes Steynberg and his $3.4 Billion USD Default Judgement

Some of you may have heard that students in UAB's Investigating Online Crimes class have been researching Crypto Investment Scam websites.  You can find a list of some of the sites we've identified so far on URLScan.io using our tag "CryptoScam" (as of this writing we have 3600+ sites on the list -- hosting companies and registrars, please take action!) 

Mirror Trading International and a $3.4 Billion Fine

You may have never heard of the U.S. Government agency, the Commodity Futures Trading Commission, but that doesn't mean they don't have power.  Last week the CFTC announced an order of default judgment against Cornelius Johannes Steynberg of Stellenbosch, Western Cape, South Africa. The order states that Steynberg must pay $1,733,838,372 USD in restitution and an additional $1,733,838,372 as a civil monetary penalty for defrauding 23,000 Americans of 29,421 Bitcoin.  (That's $3.4 Billion USD, or R63.6 Billion South African Rand.)

I'm proud to say that this action was brought in part by the Alabama Securities Commission, who joined Texas, North Carolina, and Mississippi in taking action.  I've met their director (who just retired this week! Thank you Joe Borg for 30 years of service!) and some of their investigators and they fight hard to protect the citizens of Alabama from fraud. 

Mirror Trading International claimed that their members could earn 10% per month in interest on their investments.  A typical ad of theirs boasted of this advantage over traditional bank accounts and other investment vehicles: 




Ponzi Scam or Affiliate Program: Tomato / Tomato

Like many other Crypto Investment Scams, MTI was an affiliate program.  MTI encouraged members to create an account, after which they would be granted an affiliate code. By sharing a link to the main MTI website using their affiliate code, anyone who clicked the link and made an investment would begin generating "passive weekly income" to the member. 

Dozens of webpages, Telegram channels, and Facebook pages were filled with ads claiming how easy it was to earn money.  Here's one that was shared on a Facebook page operated by affiliate "Themba2000." 


This affiliate regularly posted updates supposedly showing how much money they were earning, as well as testimonials where the people they had recruited supposedly thanked them for their newfound financial freedom:



Like many other Crypto Investment Scams, the affiliates were encouraged to share videos claiming that Artificial Intelligence-based training was part of the secret of their success: 


South Africa's Court Order Outlines a Problem: Greed

While the terms of the South African court order against MTI may seem like victim-shaming, Greed is truly one of the factors involved in many of these Crypto Investment Scams.




"People all over the world, and South Africans are no exception, are bewitched and fascinated by any idea or scheme promising, in most cases, instant wealth, new homes, new cars, holidays abroad and all material possessions that can be acquired with an abundance of money. A further attraction of these schemes is the perception that the money will keep rolling in with little or no effort by the participants, the hardest part being to count one's money." 

The conclusion of that case summarized their findings as follows: 

[137] MTI's business clearly amounted to an unlawful ponzi-scheme, i.e. a fraudulent investing scam promising high rates of return to investors and generating returns for earlier investors with investments taken from later investors. 

[138] It would appear that there is no pool of member bitcoin, Trade 300 does not exist, the artificial intelligence bot never existed or traded and the remarkable trading results presented to investors were prima facie false. 

(ordered by A De Wet, Acting Judge of the High Court) 

What?  The AI Magic Bitcoin Genie isn't real?  I'm shocked!

Scammers or Victims:  Why Not Both? 

Unfortunately, many of the people who became involved in the scam are innocent victims while others made fake Facebook accounts in order to scam others into signing up.  As long as they signed up others, they had a good chance of making money, until the whole scheme collapsed.  It took about five minutes to find fifty affiliates with a simple Facebook search:


So will everyone get their money back?  Highly unlikely. 

Steynberg Arrested in Brazil

Mr. Steynberg was arrested in 2022 by the Brazilian Military Police of the state of Goias: 

Assurances from MTI CEO Steynberg: I am not a Ponzi Scheme!

When Mirror Trading was first accused of being a Ponzi Scheme by the Texas Securities Commission, their CEO replied to queries using a form letter like this one, shared by Global Crypto in a story called "MTI Announces It Is Working With the FSCA": 

Dear Kratika,

I unfortunately only received your email this morning, Tuesday 14 July 2020.

As I have declared to the Texas Commissioner in writing, I wish to state and declare from the outset that Mirror Trading International (Pty) Ltd (hereinafter referred to as “MTI”), a privately held company registered in the Republic of South Africa, is not a Ponzi scheme (new money feeding old) or a scam, with which a holder of funds suddenly disappears.

It is also most unfortunate that because MTI is operating in the online passive income building industry, which has a notorious and demonstrated reputation for scams and Ponzi schemes, and, due to the nature and Modus-Operandi of the robust MTI referral-based business model, that MTI is automatically by default behaviour of the media and some regulators, and maybe the behaviours of some members, is being perceived by associative conclusion that MTI is but another of these.

This unfortunate and misinformed perception is far from the reality of what MTI is as a newly formed (15 month old) highly innovative referral-business and brand that the founders would like to see growing over many years into a global, iconic and heritage brand in the market trading sector.

For instance, the Texas Commissions states that …The actual value of the commissions depends on their success in recruiting new investors and multilevel marketers. … While this may apply to Ponzi schemes, this is not correct for MTI.

Daily trading returns using top regulated trading brokers determine the quantum of rewards, which can vary and if there is a negative trading day, there are no rewards. The point is that with MTI, that the funding of MTI referral payments is derived from daily trading profits and not from the funds of new members.

Another important point which differentiates MTI from Ponzi’s and scams is that members have full control over their funds (Bitcoin) at all times. Members are able to add or withdraw their funds (Bitcoin) at any time, with no complications and no fees. If you do research, you will find not a single member of the 75,000+ MTI members worldwide has ever complained or not been able to withdraw their BTC whenever they have opted to.  

It is the aim of MTI and its innovative, unique referral-based business model and MTI’s operating Modus Operandi of trading on world markets to generate real growth and returns on a daily basis, to work with and co-operate with regulators in every regard, in the process of taking MTI along a path that will see MTI fully and properly regulated.
There are three reasons for this.

1. My Founding Vision for MTI: Build a preferred iconic and heritage global brand in the financial services sector that delivers sustainable growth and value creation for all stakeholders, including for the little man in the street:
2. Professional and Compliant:  Ensure that MTI is a professionally managed business and brand that is regulatory compliant and which delivers sustainable growth and value creation for all stakeholders. My team and I are committed to this.
3. Change the reputation of the on-line passive income generating industry: We and myself personally, are extremely tired of this industry having a negative and darkly clouded reputation. And yes, some 99.9% of online passive income building services are scams and  / or Ponzi’s. I am personally very driven to be part of changing this perception once and for all, by showing and demonstrating to regulators, to the media and to consumers that such a business model can on a Bona Fida basis, exist, successfully operate and grow on an organic and sustainable basis, which is what MTI is doing.

To this end, MTI will in the coming period be placing great emphasis on engaging with and working with any regulator with a clear purpose at all times;  be fully compliant as a professionally managed company and brand that delivers sustainable growth and value creation to its stakeholders, and which intends to be around for many years to come.

MTI is already in discussion with the South Africa Financial Services Conduct Authority (FSCA) and will be meeting with the FSCA in a week’s time. MTI is also fully committed to co-operating with the Texas State Securities board and is in correspondence with them on this matter.

We trust that the above gives you some insight into MTI.

Should you wish to correspond further, please use my private email address: [REDACTED]
Your sincerely,

Johann Steynberg
Chief Executive Officer
Mirror Trading International (Pty) Ltd
South Africa