Showing posts with label Call Center Fraud. Show all posts
Showing posts with label Call Center Fraud. Show all posts

Sunday, September 14, 2025

Indian Call Center Scammers partner with Chinese Money Launderers

 


At the end of August 2025, The US Attorney's office in San Diego announced four indictments against members of a Chinese organized crime ring that stole at least $65 million from thousands of older Americans.  The case was notable because the US Attorney credited two YouTube channels with the leads that led to 25 arrests so far in California, New York, Texas, and Michigan. 

When we see 25 Chinese arrests, it might be tempting to think this is all Chinese Organized Crime, but those who actually watch the videos will realize that's not the case.  The referenced videos are from late 2020 and early 2021 and each started with Scammer Payback (Pierogi) responding to a refund scam.

Indian Call Center operators refer to this type of "lead generation" as "email blasting" and we have tens of thousands of example posts from Facebook groups offering the "service" of sending bogus Microsoft Defender emails, claiming that the victim's credit card is being charged and offering a telephone number to dispute the charge. The ads for this service in Tech Support Facebook groups have been constant for years, including ads as recently as this week: 


A typical "Microsoft Defender Refund" from this time period looked like this: 


We've called dozens of these numbers and they all follow a similar script, they convince the caller to allow remote control to their computer to assist them with the "refund." We often feed a Virtual Machine to the scammers and use it to help us understand what remote control tool they are using and where it is hosted.  But Scammer Payback goes quite a bit further! 

When Pierogi received the numbers from a similar call center scam, he called the number.  His video makes clear that the scammers he was communicating with were speaking Hindi to one another. He not only lets the remote control happen, but he helpfully has a bank account open.  The scammers see the millions of dollars available and can't help themselves.  He is a juicy target!
Scammer Payback: https://www.youtube.com/watch?v=hrLZbc-Rfbo

The scammers have Pierogi type in his own refund amount - but they alter it to make it appear that he typed too many digits resulting in a much larger than intended refund.  Then they demand that he withdraw the difference in cash and ship it back to "them."

Being a very compliant victim, Scammer Payback agrees immediately, taking down the address and agreeing to send the package of cash "overnight delivery." At this point, Pierogi engages the Trilogy media team. Trilogy agrees to take their camera crew to the pick up site to find out who is on the other end of the package. 

Trilogy Media: https://www.youtube.com/watch?v=in_Y5q_-F2Y

But in three out of three cases where Pierogi uses Trilogy to deliver a cash package, the package is being sent to a young Chinese person who is at an Air BNB that has been rented for a very short time period. 

We actually have seen this model in other cases ... in 2022, we write about the case of Jianjie Liu on this blog in a post called "Chinese Call Center Runner Pleads Guilty in Georgia."  


Jianjie Liu did cash pickups for a wide variety of scams, including Grandparent scams, Inheritance scams, and Government Grant Scams.  She was actually arrested in a case involving Walmart Gift Cards that led to the discovery of 718 Gift Cards in her vehicle. In one case almost exactly like those above, Liu was sent a $20,000 Cashier's check after someone processing a $555 refund was accidentally refunded $20,555 and had to send the difference back to the scammers.  The check was made payable to a shell company in Georgia controlled by Liu.

Where do these Chinese agents doing the cash, check, and gift card payment come from? Recently it is one of the most popular "Crime As A Service" offerings from the various Chinese Guarantee Syndicates.  Each of the Guarantee Syndicates has a menu of vendors who have made a large deposit in USDT in order to have the right to sell their services there.  This category is usually called some variation of "Collection Services." 

You may have heard of "Huione Pay" which is generally considered the largest of the Chinese Guarantee Syndicates.  FinCEN took action, with an announcement that "Cambodia-based Huione Pay" is a money laundering concern, and proposing new Rule-making calling them a "Primary Money-Laundering Concern" to combat this type of cybercrime.  After this announcement, Huione migrated most of their vendors over to a former competitor, Tudou Danbao (which means "Potato Guarantee.")

The "Buy and Sell" channel for Potato currently has 130,000 subscribers, while one of their primary channels has 209,000 subscribers.  Category 2 on their vendor menu is "Collection Services" which currently has 656 vendors who have paid deposits between 15,000 USDT and 259,000 USDT to have their services recommended and advertised by the new Guarantee Syndicate.  These are the teams that are offering cash pickup services across the United States.

(findings from non-profit Intelligence for Good)

Many other Guarantee Syndicates have dozens to hundreds of similar vendors in their respective Collection Services vendor category.  Here is a typical ad, boasting of the cities where the vendor maintains teams of workers, ready to pick up packages: 



The US Financial Crimes Enforcement Network (FinCEN) has issued two recent reports about Chinese Money Laundering Networks.  One is an advisory regarding the use of Chinese Money Laundering Networks by drug cartels from Mexico.  The other has detailed analysis on several different models used by Chinese Money Laundering networks.


Several "Red Flags" are shared as advice to Financial Institutions to help them recognize CMLO behaviors that should be reported via Suspicious Activity Reports: 









Sunday, August 10, 2025

Operation Chakra V: Call Center Scammers and your PII

Here we have another cautionary tale about off-shoring customer service when faced with the reality of Call Center Scams that commit fraud via Tech Support Scams and Government Impersonation. In this case, FirstIdea, an Indian company is charged with committing fraud against at least 100 victims from Australia and the UK. 

FirstIdea.us, according to their website, provides Debt Collection services for ADP, Aetna, Aramark, BASF, Bic, CareOne, CostCo, Horizon Blue Cross Blue Shielf, JPMorgan Chase, Kessler, Siemens, Sony, and others.

firstidea.us website "Our Clients" page


India's Central Bureau of Investigation (CBI) recently announced Operation Chakra V, which claims Microsoft Digital Crimes Unit, the US's Federal Bureau of Investigations (FBI), Japan's National Police Agency, and the UK's National Crime Agency (NCA) as partners. The Operation has had many focuses and has been ongoing for several months, including a bust of an Amazon-imitating call center today (10AUG2025).

One of the most significant findings was announced last month, as 37 were arrested with the announcement that 850,000 money mule accounts (8.5 Lakh) had been opened at 743 bank branches. That announcement pointed out a total disregard for KYC (India calls it Customer Due Diligence) and widespread failure to file STRs (Suspicious Transaction Reports.)

While there are dozens of articles that could be written about the successes of Operation Chakhra V, I want to focus on a ring-leader arrested in raids in Noida on July 7th. According to CBI's First Information Report (FIR) (similar to a Criminal Complaint in the US) Nishant Walia, Arjun Prakash, and Arjita Chopra were considered Significant Persons in a fraudulent Call Center operation.

Nishant Walia operated FirstIdea Solutions where Arjun Prakash was listed as a director. Nishant and Arjun were co-directors at several companies, including Marvello Infotech, FirstIdea Solutions, and DroidOne InfoSol.



Whistle-blowers who post on "Scammer.info" share more details and point out that Nishant's other company, Click Aurum, is also worth looking into.  In that chat thread, "Rogger" says they are "running outbound calling in UK, AUS and ask for cancellation and collect money from them. 

https://scammer.info/t/https-www-youtube-com-watch-v-xow1vct-whg/57340

While the date on the Scammer.info post shows Nishant Walia was "in the game" as early as May 2020, a UK court document actually puts the timeline even earlier.  In a case against one Baljinder Singh in a document dated 04JUL2019, we find that "Devine Technical Services Ltd" based in the UK was linked to "an Indian company which purported to provide online technical support for computer users." In that earlier case it is explained "The nature of the fraud was that computer users were made to think that their machines had been infected with viruses or had been subject to hacking and were encouraged to pay for the services of the IT support company."  Mr. Singh was charged with money laundering, receiving payments totaling  £300,188 from victims of the scam and forwarding the proceeds (minus his commission) to Nishant Walia in India. 

https://crimeline.co.uk/wp-content/uploads/2019/09/singh2019ewcacrim1428.pdf


Dozens of Indian media outlets shared the story of Nishant's arrest, calling him a "Key Operative" a "Kingpin" or a "Leader" of a "Cyberfraud syndicate." 


https://www.thehindu.com/news/national/cbi-arrests-key-operative-of-cyber-fraud-syndicate-targeting-uk-and-australian-citizens/article69788011.ece

While Nishant has been arrested by the CBI and charged with running a major fraud call center operation, Arjun Prakash claims to have moved to Hawaiian Gardens, California and began operating as the "Business Owner & Chief Executive Officer" of FirstIdea, sharing the firstidea.us website in his LinkedIn profile, but claiming to have worked their consistently for 9 years and 10 months (since October 2015) making it clear that this is the same organization.

According to business registration documents, Arjun left the company, opening a debt collection service in the US using the domain "firstidea.us" which he registered in 2015 using his personal gmail account (arjunprakash11@gmail.com) and later renewed using the company gmail (firstideasolutionsinc@gmail.com).  Clearly, despite resigning his directorship, Arjun was still part of the company.

linkedin.com/in/aazur (now deleted)

We have seen this pattern repeatedly where a company establishes an off-shore relationship for a business process operation that requires the sharing of #PII, and then operators of that same call center are subsequently accused of running fraudulent call centers.

Tuesday, September 08, 2020

RoboCallers Hit with Permanent Injunction by Courts

The Eastern District of New York has ruled in the case "United States v. Nicholas Palumbo, et al" effectively putting TollFreeDeals.com and SIPRetail.com out of business.  These are the "Voice Over IP" companies that have allowed millions of overseas calls per day to be routed to Americans, often for the purposes of facilitating fraud, often by imitating either the Social Security Administration or the IRS.  The case, originally filed 28JAN2020 ( 1:2020cv00473) announced their final "permanent injunction" ruling on 26AUG2020, as conveyed by the Office of the Inspector General of the Social Security Administration.  

In the 62-page criminal complaint against the two companies, the government explains that the major fraud types facilitated by the Palumbos were: 

a. Social Security Administration ("SSA") Imposters

b. Internal Revenue Service ("IRS") Imposters 

c. United States Citizenship and Immigration Services ("USCIS") Imposters 

d. Tech Support Imposters -- often claiming to be Apple or Microsoft 

e. Loan Approval Scams

Through the use of the Palumbos' companies, the callers were able to spoof their caller ID to seem to originate from a U.S. Federal government agency, local police department, or technical support organization. 

From October 1, 2018 to September 30, 2019, the SSA received more than 465,000 complaint related to these types of calls and documented losses of more than $14 million.  The Federal Trade Commission's Consumer Sentinel Database documented 166,000 such calls with losses of $37 million just in calendar 2019.  When all types of government impersonation calls were included, the FTC Consumer Sentinel reported 255,223 complaints causing $128 Million in fraud losses in 2018 and 389,563 complaints resulting in $152 Million in fraud losses in 2019!

The Social Security Calls

According to the government's complaint one such robocall, sent to millions of American telephone numbers in early 2019 used this text: 

"Hello this call is from Department of Social Security Administration the reason you have received this phone call from our department is to inform you that there is a legal enforcement actions filed on your social security number for fraudulent activities so when you get this message kindly call back at the earliest possible on our number before we begin the legal proceedings that is 619-XXX-XXXX. I repeat 619-XXX-XXXX.  Thank you."

The Technology 

How does the technology work?  The foreign call center uses Voice Over IP (VoIP) to connect via broadband Internet to a U.S. based telecommunications company called a "gateway carrier."  The gateway carrier then routes the call to a "common carrier" such as AT&T or Verizon.  Because of the need to bill for these services, both the gateway carrier and the common carrier keep logs of these calls. Part of the service provided by the Gateway Carrier is to perform "least-cost routing" - basically real-time auctioning the call so that the call is routed to the cheapest bidder. 

These logs provide: 
timestamp => destination consumer # => gateway carrier => caller-id presented (often spoofed) => downstream customer (usually the foreign call center) .   

In just 23 days in May and June of 2019, TollFreeDeals transmitted more than SEVEN HUNDRED TWENTY MILLION calls!  (720,000,000 calls!!!!)  425 million of these calls lasted less than one second.  More than 24 million of these calls were placed to residents of the Eastern District of New York.

182 Million of these TollFreeDeals calls were originated from a single India-based VoIP carrier co-conspirator in the United States.  One thousand different source numbers accounted for 90% of these calls.  79% of these 1,000 numbers were listed as fraudulent robocall numbers by a robocall blocking company (YouMail).  Of these 143 million calls, 20% were Social Security imposter calls, 35% were loan approval scams, and 14% were Microsoft refund calls. Other calls imitated the IRS, the U.S. Treasury, and additional tech support scams.

In May 2017, Nicholas Palumbo was notified by AT&T and others that his company was routing fraud government imposter calls.  Palumbo promised to block two particular telephone numbers, but continued to allow the others.  

In February 2019, AT&T notified Palumbo that calls spoofing the USCIS and attempting to extort money had been traced to his company.  Again, Palumbo blamed his India-based VoIP carrier customer, even though this was the same company for which he had already received many warnings.  

A telecommunications industry trade association, USTelecom, provided an additional 144 notifications of fraudulent call origination to the Palumbos' companies from May 2019 to January 2020, including 83 SSA Imposter fraud call cases, 24 Tech Support imposter fraud cases, 10 IRS imposter fraud cases, and 1 USCIS impersonation fraud calls.  USTelecom's notices estimated that TollFreeDeals was placing "more than 1 million fraudulent calls per day."  Palumbo logged in to the USTelecom portal and repeatedly indicated the calls had been placed by the same India-based customers of TollFreeDeals.

USTelecom also formally notified SIP Retail of similar traffic, including 35 traceback investigations from August 2019 to January 2020, including 19 SSA Impersonation cases, 3 Tech Support impersonation cases, and 1 USCIS Impersonation case.

Elder Fraud Task Force Reports

To put a human face on the crimes, a Postal Inspector working for the Elder Fraud Task Force in the Consumer Protection Branch of the Department of Justice investigated many example calls facilitated via the Palumbos' companies.

Palumbo received at least nineteen large cash deposits into Wells Fargo Bank accounts that he controlled from May 28, 2019 to September 11, 2019, totalling $130,250.  The deposits were made in Minnesota, South Carolina, Florida, Alabama, and New Jersey.  After each cash deposit, Palumbo would move the funds to his Ecommerce National LLC accounts at JP Morgan Chase. These activities are characterized by the Postal Inspector as "Interstate Funnel Account" transactions, a form of laundering money.

Some of the victims interviewed by the Postal Inspector included: 

J.K - an 84 year old veteran of the US Marine Corps from Belle Harbor, NY.  He received a call claiming to be from the U.S. Marshals Service with a wrarant for his arrest.  He then was told by a "SSA Employee" that someone had used his SSN to rent a car in Texas and that the car was used in drug trafficking and money laundering.  The "SSA Employee" then forced J.K to wire all of the money in his bank accounts to him - $9,800. 

C.E. - a 36 year old man who was a brand-new U.S. citizen.  He was told be "George" from SSA that he was being investigated for money laundering.  He was told to drive to a Best Buy in Queens, NY and buy $700 worth of Hotels.com gift cards. 

L.U. - a man in his 40s from Roosevelt, NY lost $2,200 in an SSA Imposter scam 

More on Call Routing


Another Affidavit related to this case was the Declaration of a Special Agent of the Social Security Administration's Office of the Inspector General, who provided the diagram above to explain the complication of Least-Call Routing Tracebacks. 

From 2016 to 2020, TollFreeDeals.com was offering VoIP termination services specializing in servicing foreign call center call originators.  Their website specifically stated: 

"TollFreeDeals.com is your premier connection for call center and dialer termination.  We are always looking for the best call center routes in the telecom industry.  We specialize in short call duration traffic or call center traffic.  We understand there is a need for it and we want to help you find all the channels you need!" 

They were proud of the number of call minutes they had "terminated" (which means, facilitated the call from VoIP to a Common Carrier call completion.)  As of January 23, 2020, they boasted that they had helped to completed 10,491,500,323 minutes of calls!  That's TEN BILLION MINUTES of mostly fraud calls! 

archive.org's WayBack machine - Jan 10, 2020


One of the calls documented by the SSA OIG Special Agent stated: 

"We have been forced to suspend your social security number with immediate effect.  Due to this, all your social benefits will be cancelled until further clearance. In case you feel this is due to an error you may connect with legal [unintelligible] Social Security Administration. In order to connect with a Social Security Administration office, press One now.  In case we do not hear from you, your social will be blocked permanently. To connect with an officer now, press One and you will automatically be connected with the concern departments. We did not receive any input. Dear citizen, in order to speak with Social Security personnel regarding your social security, press One and this automated system will connect you with the officials." 

This affiant establishes that those 1,000 top phone numbers identified by YouMail and confirmed as fraud based on complaints in the FTC Consumer Sentinel database came from 29 unique TollFreeDeals customers.

Many Additional Details 

There were many rounds of filings by the Palumbos' lawyers, all soundly rebutted by the Department of Justice and their investigators, often with the help of industry experts.  One in particular addresses the behavior of "Yodel" ... in a single day, January 20, 2020, Yodel sent more than 6.5 million robocalls through the Palumbos' services.  5.2 million of these calls use "Neighbor Spoofing" which is the practice of assigning a caller id to the call which seems to originate from someone in the same area code and with the same prefix.