Visualização normal

Antes de ontemAnalyst
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Carding Tactics & Youth Money Muling BushidoToken
    What HappenedRecent operational successes by UK law enforcement have exposed sophisticated domestic carding networks and the growing threat of youth-targeted money muling syndicates.In June 2026, a major cross-border investigation concluded with the sentencing of a serial fraudster who targeted small businesses, including veterinary clinics and hotels, across 22 different counties in England and Wales.The individual executed over 64 frauds and two thefts, accumulating losses totalling £462,000.
     

UK Cybercrime Journal: Carding Tactics & Youth Money Muling

19 de Agosto de 2026, 05:00

What Happened

  • Recent operational successes by UK law enforcement have exposed sophisticated domestic carding networks and the growing threat of youth-targeted money muling syndicates.
  • In June 2026, a major cross-border investigation concluded with the sentencing of a serial fraudster who targeted small businesses, including veterinary clinics and hotels, across 22 different counties in England and Wales.
  • The individual executed over 64 frauds and two thefts, accumulating losses totalling £462,000. The threat actor utilised stolen payment card details to buy goods and explicitly manipulating transaction values to inflate the amounts charged before requesting rapid refunds directly into bank accounts under his control.
  • Following his arrest, investigators seized an array of high-value items, including designer clothing and mobile devices. Financial telemetry revealed the illicit proceeds were being spent on luxury goods, gambling, hotels, and vehicle hire. Crucially, investigators uncovered an expansive network of money mule accounts specifically set up to layer and obfuscate the stolen funds.
  • Separately, regional policing teams executed a series of targeted strikes aimed directly at these types of laundering networks, resulting in the arrest of three men (aged 18, 22, and 26) on suspicion of conspiracy to defraud and for money laundering, along with the seizure of £14,000 in cash.
  • Law enforcement issued a stark warning following the raids, noting an aggressive operational shift where organised crime groups (OCGs) are actively leveraging social media platforms like Snapchat and Instagram, alongside popular online gaming ecosystems, to systematically recruit young teenagers into mule networks.

Analyst Comment

This twin set of enforcement actions illustrates the complete lifecycle of a modern domestic fraud operation. The acquisition and monetisation of stolen data (also known as Carding), followed by the immediate mobilisation of a decentralised laundering infrastructure (also known as Money Muling). The carding scheme highlighted in the 22-county campaign demonstrates that threat actors are moving away from simple e-commerce checkout abuse and are instead focusing on the operational blind spots of small, brick-and-mortar or service-oriented businesses. 

By manipulating transaction values and exploiting refund protocols, the fraudster successfully weaponised point-of-sale or card-not-present (CNP) systems to manufacture clean cash flows. However, the scale of this carding activity requires a highly liquid laundering pipeline to survive traditional banking fraud detection. This is where the recruitment of money mules becomes a vital asset for OCGs.

The pivot toward social media, such as Snapchat and Instagram as well as online gaming platforms to recruit teenage money mules is a calculated tactic by syndicates. 

Young demographics are highly susceptible to social media advertisements that mask the severe criminal realities of money laundering, framing it instead as a quick, victimless side-hustle. Many young people do not understand that allowing someone to route funds through their personal bank account is a serious criminal offense that can result in first-party fraud markers (such as a CIFAS marker), effectively destroying their financial future before it begins.

Further, a widespread lack of proactive parental supervision, combined with missing or unconfigured digital parental controls on mobile devices and gaming accounts, allows recruiters to directly message minors entirely undetected.

Defensive Takeaways

  • Harden Refund Protocols for Small Businesses: Businesses in vulnerable service sectors must enforce strict multi-factor verification for all card-not-present transactions and mandate that any processed refunds should only return to the exact card used for the initial purchase.
  • Proactive Parental Monitoring & Platform Safety: Parents must actively utilise device level and application-specific parental controls on social media and gaming networks. Conversations regarding digital safety must expand past cyberbullying to include the tactical red flags of financial grooming and "easy cash" offers.
  • Targeted School and Community Education: Educational institutions and financial bodies should collaborate more often on mandatory cyber-hygiene campaigns that explicitly outline the legal penalties of money muling, illustrating how a compromised bank account can permanently restrict access to student loans, mobile contracts, and future employment.

Relevant Sources

  1. https://www.rocu.police.uk/news/2026/june/serial-fraudsters-jailed-after-targeting-businesses-across-england-and-wales/
  2. https://www.rocu.police.uk/news/2026/june/suspected-money-mules-arrested

  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Evolution of Courier Fraud Campaigns BushidoToken
    What HappenedNew data published by the City of London Police in June 2026 reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties.Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to messaging platforms like WhatsApp to contact their victims and remotely paying for third-party courier servic
     

UK Cybercrime Journal: Evolution of Courier Fraud Campaigns

12 de Agosto de 2026, 05:00

What Happened

  • New data published by the City of London Police in June 2026 reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties.
  • Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to messaging platforms like WhatsApp to contact their victims and remotely paying for third-party courier services to facilitate physical collections.
  • UK law enforcement also highlighted a dangerous shift in 2025 toward high-value physical goods. Victims are being systematically manipulated into visiting multiple jewellers over an extended period to purchase gold and expensive jewellery, which they then hand directly to fraud couriers.

Recent operational crackdowns by UK Regional Organised Crime Units (ROCUs) showcase the nationwide scale of these networks:

  • North West ROCU Operations (July 2026): Police executed coordinated search warrants in Huddersfield and Manchester, arresting two men (aged 21 and 25) on suspicion of Conspiracy to Defraud and Money Laundering. In this specific series, the suspects impersonated bank fraud departments, convinced a victim her card was compromised, sent a courier to collect it, and immediately exploit the physical card to make numerous fraudulent transactions.
  • North East ROCU (NEROCU) Sentencing (June 2026): A complex, cross-country courier fraud operation spanning March to May 2022 concluded with a prison sentence for a primary operative. The network targeted 14 separate victims, convincing them to hand over physical bank cards and PIN numbers under the guise of an internal "investigation" by their bank's fraud department. The group scammed a total of £56,000, which was then rapidly laundered through the high street purchase of smartphones, designer clothing, and luxury jewellery.

Analyst Comment

Courier fraud is effectively a hybrid cyber-physical social engineering campaign. While the final phase relies on a physical courier arriving at a victim’s doorstep, the initial approach relies heavily on psychological manipulation and email, message, or phone call-based deception.

This type of fraud is notable as it follows a structured cybercriminal playbook that bypasses detection systems and takes advantage of the vulnerable in society. The victim is instructed to bypass normal banking security controls by withdrawing cash, disclosing sensitive credentials (like PINs), or purchasing high-value physical commodities like gold or luxury jewellery. This makes it difficult to proactively detect and prevent.

The other concerning factor is the couriers themselves. According to reports, they can be an unwitting third-party courier service that is paid to go to the victim's home to collect the assets. Online services enable cybercriminals to organise these pickups remotely, lowering their risk of being caught.

The £21 million sizeable loss metric from 2025 shows how profitable this low-tech, high manipulation vector remains. The recent shift to targeting gold and luxury jewellery is a deliberate evasion tactic against traditional anti-money laundering (AML) and banking fraud detection algorithms. While banks have grown adept at flagging unusual rapid bank transfers, they cannot easily stop an account holder from physically withdrawing funds or using a card over several days at different brick-and-mortar luxury retailers. This tactic serves as a highly liquid physical laundering pipeline for these syndicates that remains a challenge to prevent.

Defensive Takeaways

  • Implement Bank Transfer and Purchase Outlier Alerts: Financial institutions can focus on further behavioural monitoring for elderly demographics, looking specifically for sudden, consecutive high-value transactions at physical luxury retail or jewellery establishments and flag patterns on unusual activity for review.
  • Public Awareness on Cross-Media Scams: Security awareness campaigns must make it clear that legitimate institutions, specifically the Police and Banking Fraud teams, will never send a courier to a residential address to collect cash, PIN numbers, bank cards, or purchased items.
  • Vetting of Courier Logistics: Commercial courier services are increasingly being abused as infrastructure by these threat groups. Logistics firms must implement logging and analysis systems to detect unusual residential pickups booked via suspicious accounts and forged identities.

Relevant Sources

  1. https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/over-70s-targeted-as-courier-fraud-exceeds-21-million-in-2025-with-london-and-home-counties-hit-hardest/
  2. https://www.rocu.police.uk/news/2026/july/two-suspected-fraudsters-arrested-after-cross-border-strikes/
  3. https://www.rocu.police.uk/news/2026/june/a-courier-fraud-conman-has-been-jailed/

  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: H1 2026 Social Media Fraud Trends BushidoToken
    What HappenedHMRC Issues Warning to TikTok UsersOn 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.The wa
     

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

29 de Julho de 2026, 05:00

What Happened

HMRC Issues Warning to TikTok Users

  • On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.
  • The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.
  • Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.
  • The warning comes after two Romanian men, aged 22 and 25, were apprehended by HMRC officers in east London on 23 April 2026 in connection with the alleged fraud.

Lloyds Bank found Two Thirds of Fraud Cases Started on Meta 

  • On 6 June 2026, Liz Ziegler, the Lloyds fraud prevention director disclosed that 68% of fraud reports from their customers started on a Meta platform, including Facebook, Instagram, and WhatsApp.
  • The average claim value submitted to Lloyds Bank is now above £500, an increase of about £100 from last year. Plus, victims were sending up to £66 million a year to fraudsters after falling victim to a scam advert via Meta, up from £27 million in 2023.
  • The most common scams involve fake tickets for concerts, festivals and sporting events. Meta’s Facebook Marketplace is also plagued by fake adverts for cars, bikes, campervans and mobility vehicles.
  • Other categories of fraud on Meta platforms, collected by Lloyds between March 2025 and 2026, include: wedding photobooths, tattoo deposits, vapes, wigs, Moncler jackets, football shirts, Dyson products and Amazon Alexas. Fraudulent transactions for deposits for flats, mobile phones, household furniture and gym equipment have also been observed.

UK Finance Recorded £221.5m Lost to Investment Scams

  • In June 2026, UK Finance's Annual Fraud Report recorded the highest loss total ever recorded and the highest total number of cases ever reported at 14,893, which was 26% higher than 2025.
  • Up to £221.5m was lost to scams in which victims were persuaded to transfer funds to a fake investment or fictitious fund. This figure also marked a 40% rise more than 2025.
  • The primary observed tactics involved in investment scams include traditional cold calling to pressurise victims into acting quickly to claim an opportunity before it expires, as well as adverts on social media offering unrealistic rates of returns on investments, and hand-delivered letters.
  • The types of investments fraudsters used as bait in 2026 involved gold, property, carbon credits, cryptocurrencies, land banks, and wine.

Fraudsters arrested in Nigeria following NCA intelligence sharing

  • In February 2026, the National Crime Agency (NCA) announced that seven men were arrested in Nigeria after intelligence identified an online investment scam compound targeting UK victims. These arrests were the result of co-operation between the National Crime Agency, Meta and the Nigerian Police.
  • Using hundreds of fake Facebook accounts accounts to impersonate cryptocurrency traders, the Nigeria-based scammers targeted people who used legitimate investment platforms.
  • The scam compound was also allegedly recruiting and training young people in targeting victims for future investment frauds and phishing attacks. A total of 26 phones, 42 sim cards and a laptop were seized on 13 January.

Analyst Comment 

H1 2026 reinforces the transition from email-centric fraud campaigns to social-media-powered fraud operations, with platforms increasingly serving as the primary source of victims for organised cybercriminal groups. Fraudsters are also adapting scams to the culture and user behaviour of individual platforms, such as generate short promotional videos on TikTok or listing fake items for sale on Facebook Marketplace. Rather than deploying identical scams everywhere, criminals tailor campaigns to the platform's intended purpose. Recommendation algorithms and advertising ecosystems provide fraudsters with scalable victim acquisition channels that were previously unavailable through traditional phishing campaigns.

Advances in artificial intelligence (AI) and large language models (LLMs) has also meant it is much easier for cybercriminals to carry out scams on a much larger scale than they were previously able to. Autonomous systems can enable them to send out messages at scale and contact users by telephone at scale. Plus the scam attempts are also more convincing as they can mimic voices and appearance of celebrities or even a target’s friends and family.

The scale of fraudulent activities across social media is so large, it requires vast resources and expertise to monitor, detect, and prevent. At the same time, the response from HMRC, banks, social media companies, the NCA, and international law enforcement suggests increasing recognition that combating social media fraud requires coordinated action.

The volume of fake accounts on social media used for scams does also validate the calls for increased verification and security checks on such platforms. The UK Government's proposal to introduce a national digital ID system, however, was met with fierce opposition. Up to 2.9 million people signed a UK parliament petition to show their disagreement with such a system.

Defensive Takeaways 

  • Reduce Public Exposure: Fraudsters increasingly use information shared on social media to personalise scams and identify potential victims. Consider making profiles private or limiting visibility to trusted contacts and if you no longer actively use a social media platform, consider deleting the account entirely.
  • Be on Guard for Scams: Sponsored advertisements should not automatically be considered legitimate. Refuse any financial rewards in exchange for your login credentials. Be cautious of investment opportunities promoted solely through social media. Assume Facebook Marketplace listings can be fraudulent.
  • Report Suspicious Activity: Reporting scams helps remove fraudulent content and supports law enforcement investigations. Useful UK reporting channels include Report Fraud and the UK NCSC's Suspicious Email Reporting Service report@phishing.gov.uk.
  • Seek Support after a Scam: Victims should not assume financial losses are unrecoverable. It can be possible to get funds returned if they contact their bank immediately, preserve screenshots and transactions records, and report the incident to Report Fraud. Further, if a victim is dissatisfied with how their bank handled their case, they can complain to the Financial Ombudsman Service.

Relevant Sources 

  1. https://www.independent.co.uk/news/uk/crime/tiktok-hmrc-tax-fraud-scam-b2989914.html
  2. https://www.thetimes.com/article/840020a8-1210-47c9-9262-e3139116b652?shareToken=771d08288cd2ac9d0ba13194f43d75a0
  3. https://www.theguardian.com/money/2026/jun/15/investment-fraud-uk-more-than-220m-lost-last-year-scams-ai
  4. https://www.ukfinance.org.uk/system/files/2026-06/UK%20Finance%20Fraud%20Report%202026.pdf
  5. https://www.nationalcrimeagency.gov.uk/news/fraudsters-arrested-in-nigeria-following-nca-intelligence-sharing 

  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Argos Account Takeover Fraud BushidoToken
    What HappenedOn 3 June 2026, the City of London Police issued a warning stating Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands.Report Fraud, which is run by the City of London Police, warned that cybercriminals are using leaked credentials from historical data breaches to hijack Argos user accounts.Once on the account, the fraudsters order and then collect the goods in-person at a physical store. In some ins
     

UK Cybercrime Journal: Argos Account Takeover Fraud

1 de Julho de 2026, 05:00


What Happened

  • On 3 June 2026, the City of London Police issued a warning stating Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands.
  • Report Fraud, which is run by the City of London Police, warned that cybercriminals are using leaked credentials from historical data breaches to hijack Argos user accounts.
  • Once on the account, the fraudsters order and then collect the goods in-person at a physical store. In some instances, the goods are paid for using payment details not connected to the victim of the compromised account.
  • Notably, the goods from fraudulent orders are often claimed via Click & Collect option that Argos allows, enabling the threat actors to retrieve goods in store.
  • In May, Report Fraud received 652 reports which mention Argos, a 323% increase compared to April, when 154 reports mentioning the retailer were made. Since the start of 2026, there have been 1,175 reports mentioning the retailer, with May seeing the highest number to date.
  • This alert is also not the first raised about Argos. On 18 November 2025, the East Midlands Cyber Resilience Center issued a warning about Argos and Currys accounts getting compromised and unauthorised purchases being made. In some instances, particularly with Currys, the Buy Now Pay Later (BNPL) option was used, leaving the account holder with finance plans in their names.

Analyst Comment

For both everyday UK consumers and UK retail risk teams, these alerts provide several layered insights. Retailers have spent years optimising Click & Collect to be as frictionless as possible to compete with online shopping giants like Amazon. However, this alert shows how Click & Collect can be a security liability. As Argos allows quick collections, criminals can buy an item online and pick it up at a local store before the real account owner notices an order confirmation email.


The police alerts also note that the items may even be paid for using payment details not connected to the victim. Criminals are mixing stolen accounts with stolen credit cards. This is likely due to an established Argos account with a multi-year history buying expensive items would look pretty normal to a fraud detection engines.


The combination of an Account Takeover (ATO) and Buy Now Pay Later (BNPL) fraud creates a difficult scenario for retailers, credit providers, and consumers. The regulatory and reputational fallout for a retailer under the rules of the UK Financial Conduct Authority (FCA) could be severe. If a retailer's poor account security allows fraudsters to easily spin up a finance plan in a victim's name, the FCA will view this as a systemic failure to protect consumers, resulting in massive fines.


These attacks are possible due to the practice of Argos users who are reusing the same previously leaked password across multiple accounts, plus users not having multi-factor authentication (MFA) turned on in their account settings. 


Campaigns like this can trigger a reputational hit to retailers as victims often do not suffer silently. They take to social media to share stories and the public narrative can shift to being about a retailer who is complicit in disrupting innocent people's financial lives.


Defensive Takeaways

  • User Account Hygiene Best Practices: Standard practices such as rotating passwords, using complex password, using a different password per service, using a password manager, using passkeys, and turning on MFA would all help mitigate this type of threat for users.
  • Credit Monitoring: If a user suspects their account has been compromised, they should consider using a credit monitoring service to help prevent unauthorised loans taken out in their name.
  • Cancel and Replace Payment Cards: If a user suspects their payment card data has been stolen, then they should contact their financial institution and have it cancelled and replaced.
  • Implement Click-and-Collect Controls: Retailers with click-and-click options should introduce controls such as requiring ID of the account owner or a single-use QR code or PIN via SMS/Email at the point of collection for high-value items to prevent this type of fraud.
  • Detecting Credential Stuff Attacks: If the cybercriminals were using credential stuffing attacks, then retailers should be able to detect unauthorised password guessing attempts against their online portals. It is recommended to use IP context analysis and perform source IP correlation. If one IP address tagged as a proxy or VPN is observed attempting to login to dozens of accounts simultaneously, then there’s an issue.
  • Leverage Stripe’s FT3 framework: If your organisation or team is tasked with combating fraud, then categorising these scammers TTPs is crucial. That’s why Stripe has developed the Fraud Tools, Tactics, and Techniques (FT3) framework. It’s designed to help security teams understand the landscape, spot gaps, develop detections, improve incident response, and foster collaboration.


Relevant Sources

  1. https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/report-fraud-alert-warning-for-argos-shoppers-after-323-per-cent-spike-in-fraud-reports-mentioning-the-retailer/report-fraud-alert-warning-for-online-shoppers-after-spike-in-criminals-gaining-unauthorised-access-to-retailer-accounts/
  2. https://www.emcrc.co.uk/post/currys-and-argos-account-warning-issued-by-police


Social Media Intelligence (SOCMINT)

  1. https://www.reddit.com/r/LegalAdviceUK/s/NbOWRfzvgm
  2. https://www.reddit.com/r/Argos/s/6uOo52UpHf
  3. https://www.reddit.com/r/Argos/s/eZTgBhhNzp
  4. https://x.com/donnaeenichols1/status/2060321697996161165
  5. https://x.com/lottyburns/status/1983581827127259558


Relevant CTI Resources

  1. https://www.cloudflare.com/learning/bots/what-is-credential-stuffing/

  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: £102 million Lost to Scams in 2025 BushidoToken
     What HappenedOn 5 May 2026, new data revealed that British romance scam victims were defrauded of a staggering £102 million last year, representing a 29% surge in reported cases.The figures come from information gathered by Report Fraud (f.k.a ActionFraud), which is a City of London Police-run service that logged 10,784 romance scam reports in 2025.According to the data, cybercriminals are reportedly pocketing roughly £280,000 everyday by exploiting online relationships, with individual losses
     

UK Cybercrime Journal: £102 million Lost to Scams in 2025

27 de Maio de 2026, 04:00

 


What Happened

  • On 5 May 2026, new data revealed that British romance scam victims were defrauded of a staggering £102 million last year, representing a 29% surge in reported cases.
  • The figures come from information gathered by Report Fraud (f.k.a ActionFraud), which is a City of London Police-run service that logged 10,784 romance scam reports in 2025.
  • According to the data, cybercriminals are reportedly pocketing roughly £280,000 everyday by exploiting online relationships, with individual losses averaging £9,500 and in extreme cases, reaching up to £1 million per victim. 
  • This wave of scam victims is part of the growing trend where scammers blend emotional manipulation with fake cryptocurrency investment schemes, heavily weaponising AI-generated profiles, and focusing on lonely victims aged 55 to 74.

Analyst Comment 

When analysing fraud statistics, it is important to remember that underreporting is very common, with many victims staying silent out of shame. Therefore, this is likely only a fraction of the real figures and the problem is likely much worse than we know. The data we do have, however, still reveals there is essentially an army of digital scammers routinely bleeding UK citizens dry, using not much more than a Midjourney AI subscription, a ChatGPT script, face-swapping services, and an entirely fictitious character with an emotional backstory.


Losing £102 million in a single year to fake internet characters is a truly wild national milestone. The fact that reports surged by nearly a third (29%) proves that in our society, emotional vulnerability is being monetised at industrial scale. We aren’t just looking at a clumsy email from a Nigerian prince anymore. This is industrial-grade social engineering. Scammers are playing the long game, spending months "love-bombing" victims before dropping the inevitable bombshell that they need a quick bank transfer to cover a “medical emergency” or an unmissable cryptocurrency investment opportunity.


In March 2026, the UK Government took some action against this threat and sanctioned Xinbi, a Chinese-language cryptocurrency marketplace accused of enabling large-scale online fraud and human exploitation. Xinbi reportedly processed more than $19.9 billion in transactions between 2021 and 2025, highlighting how much money the scam industry is generating globally.


Until we treat the underground scam economy with the same significance we treat ransomware or nation state attacks, the UK will continue to be one of the world's most lucrative money spinners for heartless cybercriminals.


Defensive Takeaways

  • Enforce the "Face-to-Face" Financial Boundary: If you are advising family members (especially those in vulnerable demographics), establish an unshakeable, non-negotiable rule: if you have not looked a person in their physical eyeballs, you do not send them money, gift cards, or cryptocurrency.
  • Teach Others Digital Sanity Checks: Teach your friends and family the art of basic digital literacy. Run profile images through reverse-image search tools (Google Lens or TinEye) and consciously flag the platform migration trap. Scammers desperately want to move targets off monitored apps like Tinder or Bumble and onto unmoderated WhatsApp or Telegram channels as fast as possible to avoid automated dating app ban filters.
  • Learn From the Mistakes of Others: To find examples of victims falling for these scams, the UK Financial Ombudsman Service’s database of decisions can act as a useful resource. The decision details can help you understand how these scams work, how much money individuals can lose, and the rate at which UK banks offer refunds or compensation. More examples can be found in my talk on this topic here.
  • Leverage Stripe’s FT3 Framework: If your organisation or team is tasked with combating fraud, then categorising these scammers TTPs is crucial. That’s why Stripe has developed the Fraud Tools, Tactics, and Techniques (FT3) framework. It’s designed to help security teams understand the landscape, spot gaps, develop detections, improve incident response, and foster collaboration.


Relevant Sources

  1. https://www.cityoflondon.police.uk/news/city-of-london/news/2026/may/romance-fraud-costs-uk-victims-102-million-in-a-year-as-reports-surge-by-nearly-a-third
  2. https://www.theregister.com/security/2026/05/05/romance-fraudsters-fleeced-uk-victims-of-102m-in-2025/5227963
  3. https://therecord.media/xinbi-crypto-marketplace-sanctioned
  4. https://www.financial-ombudsman.org.uk/decisions-case-studies/ombudsman-decisions/search?Keyword=cryptocurrency+investment&Sort=date

Relevant CTI Resources

  1. https://search-uk-sanctions-list.service.gov.uk/designations/GHR0190/Entity
  2. https://www.chainalysis.com/blog/xinbi-designation-chinese-language-crypto-scam-infrastructure/
  3. https://www.trmlabs.com/resources/intel-library/xinbi-guarantee
  4. https://www.justice.gov/usao-edny/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged
  5. https://www.rusi.org/explore-our-research/publications/commentary/multi-billion-dollar-guarantee-marketplaces-exploit-stablecoins-scams
  6. https://github.com/stripe/ft3

  • ✇Krebs on Security
  • SMS Phishers Pivot to Points, Taxes, Fake Retailers BrianKrebs
    China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points. Over the past week, t
     

SMS Phishers Pivot to Points, Taxes, Fake Retailers

4 de Dezembro de 2025, 20:02

China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points.

Over the past week, thousands of domain names were registered for scam websites that purport to offer T-Mobile customers the opportunity to claim a large number of rewards points. The phishing domains are being promoted by scam messages sent via Apple’s iMessage service or the functionally equivalent RCS messaging service built into Google phones.

An instant message spoofing T-Mobile says the recipient is eligible to claim thousands of rewards points.

The website scanning service urlscan.io shows thousands of these phishing domains have been deployed in just the past few days alone. The phishing websites will only load if the recipient visits with a mobile device, and they ask for the visitor’s name, address, phone number and payment card data to claim the points.

A phishing website registered this week that spoofs T-Mobile.

If card data is submitted, the site will then prompt the user to share a one-time code sent via SMS by their financial institution. In reality, the bank is sending the code because the fraudsters have just attempted to enroll the victim’s phished card details in a mobile wallet from Apple or Google. If the victim also provides that one-time code, the phishers can then link the victim’s card to a mobile device that they physically control.

Pivoting off these T-Mobile phishing domains in urlscan.io reveals a similar scam targeting AT&T customers:

An SMS phishing or “smishing” website targeting AT&T users.

Ford Merrill works in security research at SecAlliance, a CSIS Security Group company. Merrill said multiple China-based cybercriminal groups that sell phishing-as-a-service platforms have been using the mobile points lure for some time, but the scam has only recently been pointed at consumers in the United States.

“These points redemption schemes have not been very popular in the U.S., but have been in other geographies like EU and Asia for a while now,” Merrill said.

A review of other domains flagged by urlscan.io as tied to this Chinese SMS phishing syndicate shows they are also spoofing U.S. state tax authorities, telling recipients they have an unclaimed tax refund. Again, the goal is to phish the user’s payment card information and one-time code.

A text message that spoofs the District of Columbia’s Office of Tax and Revenue.

CAVEAT EMPTOR

Many SMS phishing or “smishing” domains are quickly flagged by browser makers as malicious. But Merrill said one burgeoning area of growth for these phishing kits — fake e-commerce shops — can be far harder to spot because they do not call attention to themselves by spamming the entire world.

Merrill said the same Chinese phishing kits used to blast out package redelivery message scams are equipped with modules that make it simple to quickly deploy a fleet of fake but convincing e-commerce storefronts. Those phony stores are typically advertised on Google and Facebook, and consumers usually end up at them by searching online for deals on specific products.

A machine-translated screenshot of an ad from a China-based phishing group promoting their fake e-commerce shop templates.

With these fake e-commerce stores, the customer is supplying their payment card and personal information as part of the normal check-out process, which is then punctuated by a request for a one-time code sent by your financial institution. The fake shopping site claims the code is required by the user’s bank to verify the transaction, but it is sent to the user because the scammers immediately attempt to enroll the supplied card data in a mobile wallet.

According to Merrill, it is only during the check-out process that these fake shops will fetch the malicious code that gives them away as fraudulent, which tends to make it difficult to locate these stores simply by mass-scanning the web. Also, most customers who pay for products through these sites don’t realize they’ve been snookered until weeks later when the purchased item fails to arrive.

“The fake e-commerce sites are tough because a lot of them can fly under the radar,” Merrill said. “They can go months without being shut down, they’re hard to discover, and they generally don’t get flagged by safe browsing tools.”

Happily, reporting these SMS phishing lures and websites is one of the fastest ways to get them properly identified and shut down. Raymond Dijkxhoorn is the CEO and a founding member of SURBL, a widely-used blocklist that flags domains and IP addresses known to be used in unsolicited messages, phishing and malware distribution. SURBL has created a website called smishreport.com that asks users to forward a screenshot of any smishing message(s) received.

“If [a domain is] unlisted, we can find and add the new pattern and kill the rest” of the matching domains, Dijkxhoorn said. “Just make a screenshot and upload. The tool does the rest.”

The SMS phishing reporting site smishreport.com.

Merrill said the last few weeks of the calendar year typically see a big uptick in smishing — particularly package redelivery schemes that spoof the U.S. Postal Service or commercial shipping companies.

“Every holiday season there is an explosion in smishing activity,” he said. “Everyone is in a bigger hurry, frantically shopping online, paying less attention than they should, and they’re just in a better mindset to get phished.”

SHOP ONLINE LIKE A SECURITY PRO

As we can see, adopting a shopping strategy of simply buying from the online merchant with the lowest advertised prices can be a bit like playing Russian Roulette with your wallet. Even people who shop mainly at big-name online stores can get scammed if they’re not wary of too-good-to-be-true offers (think third-party sellers on these platforms).

If you don’t know much about the online merchant that has the item you wish to buy, take a few minutes to investigate its reputation. If you’re buying from an online store that is brand new, the risk that you will get scammed increases significantly. How do you know the lifespan of a site selling that must-have gadget at the lowest price? One easy way to get a quick idea is to run a basic WHOIS search on the site’s domain name. The more recent the site’s “created” date, the more likely it is a phantom store.

If you receive a message warning about a problem with an order or shipment, visit the e-commerce or shipping site directly, and avoid clicking on links or attachments — particularly missives that warn of some dire consequences unless you act quickly. Phishers and malware purveyors typically seize upon some kind of emergency to create a false alarm that often causes recipients to temporarily let their guard down.

But it’s not just outright scammers who can trip up your holiday shopping: Often times, items that are advertised at steeper discounts than other online stores make up for it by charging way more than normal for shipping and handling.

So be careful what you agree to: Check to make sure you know how long the item will take to be shipped, and that you understand the store’s return policies. Also, keep an eye out for hidden surcharges, and be wary of blithely clicking “ok” during the checkout process.

Most importantly, keep a close eye on your monthly statements. If I were a fraudster, I’d most definitely wait until the holidays to cram through a bunch of unauthorized charges on stolen cards, so that the bogus purchases would get buried amid a flurry of other legitimate transactions. That’s why it’s key to closely review your credit card bill and to quickly dispute any charges you didn’t authorize.

❌
❌