LIVE
TRACECHAIN FORENSICS
FRAUD INTELLIGENCE · CASE FILES · GLOBAL SCOREBOARD
INTEL
PIG BUTCHERING: now the #1 loss category in the US by estimated volume / HUSHPUPPI: the Instagram that became the evidence -- Case 001 open / BEC: one spoofed email, one wire, seven figures -- see the methodology / ROSS ULBRICHT: full pardon January 21 2025 after 11+ years -- Case 013 open / ALL FIGURES LABELED: estimate vs conviction vs market collapse -- see Methodology / UNODC 2023: $5.4B estimated annually from SE Asia pig-butchering compounds [UNVERIFIED] / PIG BUTCHERING: now the #1 loss category in the US by estimated volume / HUSHPUPPI: the Instagram that became the evidence -- Case 001 open / BEC: one spoofed email, one wire, seven figures -- see the methodology / ROSS ULBRICHT: full pardon January 21 2025 after 11+ years -- Case 013 open / ALL FIGURES LABELED: estimate vs conviction vs market collapse -- see Methodology / UNODC 2023: $5.4B estimated annually from SE Asia pig-butchering compounds [UNVERIFIED]
TOP FRAUDSTERS
Every case in the series, ranked from the biggest figure to the smallest. Next to each person: how much, what was taken, and how they did it. Tap a case to open its full report.
ONE PERSON OR A GROUP
BROWSE BY CATEGORY
RANKED — HIGHEST TO LOWEST
MORE
GLOBAL FRAUD SCOREBOARD

THE GLOBAL FRAUD SCOREBOARD

Documented cases from court filings, regulatory actions, and public reporting. Ranked by scale — and we always state what is being measured. Fabricated account value is not the same as customer funds. Market collapse is not the same as direct theft.

DEMO BUILD — figures illustrative pending source verification · [UNVERIFIED] labels applied to unconfirmed figures
RANKED BY DOCUMENTED SCALE
PUBLISHED — FULL CASE FILES
· PONZICASE FILE OPEN
Bernie Madoff
Died in custody Apr 2021 · 12 yrs served of 150-yr sentence
Scale$64.8B
MetricFabricated statement value
Longest-running Ponzi of the modern era. $64.8B is fabricated account value -- actual principal lost was approximately $17B.
SOURCE: Federal prosecution / DOJ
· CRYPTOCASE FILE OPEN
Do Kwon
Terra / LUNA · 15 years · SDNY Dec 2025
Scale~$40B
MetricMarket value destroyed
Collapse of TerraUSD and LUNA algorithmic stablecoin May 2022. Figure is market cap destroyed -- not direct theft.
SOURCE: Federal prosecution / SEC
· CRYPTOCASE FILE OPEN
Caroline Ellison
CEO Alameda Research / star witness · 2 years · served ~14 months · released 2026
Scale$11B forfeiture ordered
MetricForfeiture ordered — cooperation case · 110 yrs possible → ~14 months served
Ran Alameda Research, the fund that received the misappropriated FTX customer money. Pleaded guilty Dec 2022 and testified 3 days against . The same fraud as , two choices, two outcomes: 25 years vs 14 months.
SOURCE: DOJ · SDNY · Wikipedia (release date)
· CRYPTOCASE FILE OPEN
Sam Bankman-Fried
FTX · 25 years
Scale~$8B
MetricCustomer funds misappropriated
FTX founder convicted of misappropriating customer deposits. The flagship case for crypto exchange accountability.
SOURCE: Federal prosecution / SDNY
· PONZICASE FILE OPEN
Allen Stanford
110 years
Scale~$7B
MetricInvestor funds
Certificate-of-deposit Ponzi run from Antigua. Second-largest individual Ponzi after Madoff.
SOURCE: Federal prosecution / DOJ
· CRYPTOCASE FILE OPEN
Alex Mashinsky
Celsius Network · 12 years · SDNY May 2025
Scale~$4.7B
MetricCustomer assets frozen (FTC) — $48M personal gain
Misrepresentations to Celsius depositors about the safety and use of their funds.
SOURCE: Federal prosecution / SDNY
· SOVEREIGNCASE FILE OPEN
Taek Jho Low
· 1MDB · Fugitive — never tried
Scale$4.5B+ [ALLEGED]
MetricDOJ civil forfeiture allegation — NOT adjudicated
[ALLEGED] 1MDB sovereign fund fraud. has never been convicted. Najib Razak (PM) convicted 7 counts separately. Wolf of Wall Street allegedly funded via Red Granite/1MDB. Last seen Shanghai Disneyland Dec 24 2019.
SOURCE: DOJ civil complaints 2016– · Malaysian court record (Najib)
· CRYPTOCASE FILE OPEN
Ruja Ignatova
OneCoin / The · Fugitive -- FBI Top 10
Scale~$4B [alleged]
MetricAlleged scheme total — charged, never tried
OneCoin was a fake cryptocurrency with no blockchain. Ignatova disappeared in 2017 and remains on the FBI Most Wanted list.
SOURCE: FBI Most Wanted / DOJ
· DARKCASE FILE OPEN
James Zhong
Individual X · Silk Road thief · 1 year and 1 day · released 2023
Scale51,680 BTC stolen (~$3.4B Nov 2021 value)
MetricBTC count is the fact — $3.4B is Nov 2021 valuation only
Stole 51,680 BTC from Silk Road in 2012. Held it 9 years. Found in a popcorn tin in a bathroom closet in Georgia. Lightest sentence-to-dollar ratio in the series. The blockchain does not forget.
SOURCE: DOJ / SDNY · US v. Zhong 22 Cr. 606 (PGG)
· MEDTECHCASE FILE OPEN
Elizabeth Holmes
Theranos founder · 11 yrs 3 mo (135 mo) · serving FPC Bryan TX
Scale$452M restitution ordered
MetricRestitution ordered — investor fraud only
Theranos founder convicted of investor fraud. Edison blood-testing device could not perform as claimed. The story was the product. Ninth Circuit: 'a mirage.' Company peak valuation $9B (paper). $9B ≠ money stolen.
SOURCE: DOJ · N.D. California · Ninth Circuit Feb 2025
· CRYPTOCASE FILE OPEN
Malone Lam Yu Xuan
Anne Hathaway / King Greavys · Pleaded guilty Sep 2026 · awaiting sentence · status hearing Dec 8 2026
Scale$245M
MetricValue in RICO plea — stolen from a single victim
Largest known single-victim crypto heist in history. First Bitcoin RICO case. Social engineering attack. 4,100 BTC stolen in one phone call. Age 20 at arrest. 31 luxury cars in 30 days.
SOURCE: DOJ DC · US Attorney DC Sep 2026
· HISTORICCASE FILE OPEN
Jordan Belfort
Wolf of Wall Street · 22 months
Scale~$200M
MetricInvestor funds
Pump-and-dump via Stratton Oakmont. The pop-culture benchmark for the broker-fraud lifestyle narrative.
SOURCE: Federal prosecution / SEC
· CRYPTOCASE FILE OPEN
Changpeng Zhao
· Binance · 4 months · pardoned Oct 23 2025
Scale$50M personal · $4.3B company
Metric$50M = personal fine · $4.3B = Binance company penalty — different things
BSA compliance failure — NOT fraud. First person sentenced to prison for single BSA violation. Built the world's largest crypto exchange without adequate AML controls. $4.3B corporate resolution. 4 months. Pardoned.
SOURCE: DOJ plea agreement Nov 2023 · W.D. Wash. sentencing Apr 2024 · White House pardon Oct 2025
· HISTORICCASE FILE OPEN
Charles Ponzi
Carlo Ponzi · Died 1949 · served ~12 yrs total across 3 convictions
Scale~$20M [1920 $]
MetricInvestor losses 1920 dollars (≈$237M 2024)
The man who named the scheme. Securities Exchange Company, Boston, 1919–1920. $61 worth of postal coupons. Arrived with $2.50. Died with $75. He did not invent it. He made it his name.
SOURCE: In re Ponzi 268 F.997 (D.Mass.1920) · Suffolk County · Boston Post 1920
· BECCASE FILE OPEN
Ramon Abbas
· 135 months (11 yrs 3 mo) · C.D. Cal. Nov 2022
Scale$1.73M restitution ordered
MetricRestitution to two victims — court figure, not total losses
BEC fraud architect whose Instagram lifestyle became federal evidence. Dubai arrest 2020, sentenced 2022.
SOURCE: DOJ / FBI / Dubai Police
· HISTORICCASE FILE OPEN
Frank Abagnale
Served time (historic); now a fraud-prevention consultant
Scale$1,448.60 documented
MetricCheque / impersonation
Claims disputed -- biographer concluded much of the widely reported story was fabricated. Historic cheque fraud and impersonation. Later worked as fraud consultant.
SOURCE: Historic record / disputed
· BECCASE FILE OPEN
Albert Gonzalez
segvec · soupnazi · 20 years (served ~13, released 2023)
Scale170M card numbers
MetricCard & debit numbers stolen — not a dollar figure
Largest card data theft in US history. Cooperating Secret Service informant while running the operation. SQL injection, packet sniffing, Heartland 130M, TJX 45.6M. He taught the agents how it worked. He was the operation.
SOURCE: DOJ · Secret Service · D.N.J. 2009
· DARKCASE FILE OPEN
Ross Ulbricht
· 2 life terms + 40 years · full pardon Jan 21 2025
ScaleNo theft figure
MetricMarketplace — no direct theft figure — infrastructure case
Founder of Silk Road dark web marketplace. Full and unconditional pardon signed by President Trump on January 21, 2025.
SOURCE: US v. Ulbricht, S.D.N.Y. · Executive pardon Jan 21 2025
ON THE RADAR — REPORT PENDING
ROMANCEREPORT PENDING
SE Asia Pig-Butchering Syndicates
KK Park compounds
Report in preparation. Full case file publishes when audit is complete.
BECREPORT PENDING
Olalekan Ponle
Mr Woodberry
Report in preparation. Full case file publishes when audit is complete.
PROFILES — 28 PEOPLE
Ramon Abbas
CONVICTED
· Ray · Hush
Born
October 11, 1982 · Lagos, Nigeria
Education
—
Role
BEC fraud coordinator · money launderer
Court
CD California
Judge
Otis D. Wright II
Charge
Conspiracy to engage in money laundering
Plea
Guilty · April 2021
Sentence
11 years (135 months)
Restitution / Forfeiture
$1,732,841

BEC fraud architect whose Instagram lifestyle became the prosecution's exhibit list. Dubai arrest June 2020, Operation Fox Hunt 2.

Malone Lam Yu Xuan
PLEADED GUILTY — AWAITING SENTENCE
Yu Xuan
Anne Hathaway · King Greavys · $$$
Born
July 19, 2004 · Singapore
Education
Unity Secondary School, Choa Chu Kang (eighth-grade dropout)
Role
Ringleader, $245M crypto RICO conspiracy
Court
US District Court · District of Columbia
Judge
Colleen Kollar-Kotelly
Charge
RICO conspiracy · wire fraud conspiracy
Plea
Guilty · September 2026
Sentence
Pending — not yet scheduled; status hearing December 8, 2026 (max 20 years)
Restitution / Forfeiture
TBD

Largest known single-victim crypto heist in history. First Bitcoin RICO case. Social engineering, one phone call, $230M drained. 31 luxury cars in 30 days.

Kwon Do-hyung
CONVICTED
· @stablekwon · crypto king
Born
c. 1991 · South Korea
Education
Stanford University · Computer Science
Role
Co-founder Terraform Labs · TerraUSD / LUNA
Court
SDNY
Judge
Paul A. Engelmayer
Charge
Wire fraud · conspiracy to defraud
Plea
Guilty · August 2025
Sentence
15 years · December 11, 2025
Restitution / Forfeiture
—

$40B market value destroyed in Terra-LUNA collapse. Two depegs: May 2021 (hidden) and May 2022 (terminal). "You chose to lie. You chose poorly." — Judge Engelmayer

Bernard Lawrence Madoff
DECEASED
Born
April 29, 1938 · Queens, New York
Education
Hofstra University · Political Science
Role
Founder BLMIS · Former NASDAQ chairman
Court
SDNY
Judge
Denny Chin
Charge
Securities fraud · 11 felony counts
Plea
Guilty · March 12, 2009
Sentence
150 years · died in custody April 14, 2021
Forfeiture
$170.8B ordered

Largest Ponzi scheme in history. 48 years. $64.8B in fabricated statements. Warned to the SEC eight years before collapse. Duration was the disguise.

Samuel Benjamin Bankman-Fried
CONVICTED
Samuel Benjamin
Born
March 6, 1992 · Stanford, California
Education
MIT · Physics 2014
Role
Founder & CEO FTX · Founder Alameda Research
Court
SDNY
Judge
Lewis A. Kaplan
Charge
Wire fraud · securities fraud · commodities fraud · money laundering · 7 counts
Plea
Not guilty → convicted all 7 counts November 2, 2023
Sentence
25 years · March 28, 2024
Restitution / Forfeiture
$11B forfeiture

The trust of the smart. Misappropriated $8B in FTX customer funds. MIT, Jane Street, effective altruism, beanbag, cargo shorts — trusted by everyone who was most careful about trust.

Caroline Ellison
CONVICTED
—
Born
November 1994 · Boston, Massachusetts
Education
Stanford University · Mathematics · then Jane Street Capital
Role
CEO Alameda Research · Star prosecution witness
Court
SDNY
Judge
Lewis A. Kaplan
Charge
Wire fraud · securities fraud · commodities fraud · money laundering · 7 counts
Plea
Guilty · December 2022 (before charged)
Sentence
2 years · September 24, 2024
Restitution / Forfeiture
$11B forfeiture

Ran the fund that received the stolen money. Cooperated before she was charged. Testified 3 days against . He leaked her diary to try to stop her. She testified anyway. 14 months served. Released January 2026.

Olalekan Jacob Ponle
CONVICTED
Olalekan Jacob Ponle
Mr Woodberry
Born
—
Education
—
Role
BEC co-conspirator
Court
US Federal
Judge
—
Charge
Wire fraud · BEC conspiracy
Plea
Guilty
Sentence
8 years
Restitution / Forfeiture
—

Arrested alongside in Operation Fox Hunt 2, Dubai, June 2020. Extradited to the US.

Ghaleb Alaumary
CONVICTED
Ghaleb Alaumary
Big Boss
Born
—
Education
—
Role
High-level money launderer · North Korea connection
Court
CD California
Judge
—
Charge
Conspiracy to commit money laundering
Plea
Guilty · November 2020
Sentence
—
Restitution / Forfeiture
—

Connected to North Korean / APT38 operations. Conspired with Abbas to launder funds from the Bank of Valletta (Malta) cyber heist, February 2019.

Abba Kyari
ALLEGED ONLY
Abba Kyari
—
Born
—
Education
—
Role
Former Nigerian Deputy Commissioner of Police
Court
US Federal (indicted)
Judge
—
Charge
Conspiracy to commit wire fraud · money laundering [ALLEGED]
Plea
—
Sentence
—
Restitution / Forfeiture
—

Alleged in US court documents as co-conspirator who received bribes from Abbas and used law enforcement authority to arrest individuals Abbas wanted targeted. Denied all charges. Case unresolved as of this writing. All claims are allegations.

Ross Ulbricht
PARDONED
Born
March 27, 1984 · Austin, Texas
Education
University of Texas · Physics · Penn State MS materials science
Role
Founder Silk Road dark web marketplace
Court
SDNY
Judge
Katherine Forrest
Charge
Drug trafficking · money laundering · computer hacking · conspiracy
Plea
Not guilty → convicted February 2015
Sentence
Two life terms + 40 years (2015) · full and unconditional pardon, January 21, 2025
Restitution / Forfeiture
—

Founded Silk Road in 2011. Arrested October 2013, SF public library. Sentenced to two life terms plus 40 years in 2015. Pardoned by President Trump on January 21, 2025 — a full and unconditional pardon, not a commutation.

Jordan Belfort
CONVICTED
Wolf of Wall Street
Born
July 9, 1962 · Queens, New York
Education
American University (briefly) · University of Maryland School of Dentistry (dropped out)
Role
Founder Stratton Oakmont · stockbroker
Court
EDNY
Judge
—
Charge
Securities fraud · money laundering
Plea
Guilty · 1999
Sentence
22 months
Restitution / Forfeiture
~$110M ordered

Pump-and-dump fraud via Stratton Oakmont. ~$200M in investor losses. Later became motivational speaker and fraud consultant. Subject of Martin Scorsese film (2013).

Frank William Abagnale Jr.
CONVICTED
Frank William Abagnale Jr.
—
Born
April 27, 1948 · Bronxville, New York
Education
Claims disputed
Role
Impostor · cheque fraud (claims extensively disputed)
Court
Various (historic)
Judge
—
Charge
Cheque fraud · impersonation (disputed — biographer concluded much was fabricated)
Plea
—
Sentence
Served time (disputed timeline)
Restitution / Forfeiture
—

Claims disputed. 's widely reported autobiography has been substantially challenged by investigative biographer Alan Logan, who concluded most of the famous story was fabricated. Later worked as fraud consultant.

Alexander Mashinsky
CONVICTED
Born
October 2, 1965 · Ukraine
Education
—
Role
Co-founder & CEO Celsius Network
Court
SDNY
Judge
John G. Koeltl
Charge
Pleaded guilty: commodities fraud · securities fraud (CEL manipulation)
Plea
Guilty · December 2024
Sentence
12 years · May 8, 2025
Restitution / Forfeiture
—

Celsius Network froze withdrawals June 2022, filed bankruptcy July 2022. ~$4.7B in customer funds. Collapse partly driven by Terra-LUNA contagion. Pleaded guilty December 2024.

Ruja Ignatova
FUGITIVE — AT LARGE
The
Born
May 30, 1980 · Ruse, Bulgaria
Education
University of Konstanz · Law · Oxford PhD
Role
Co-founder OneCoin · fugitive
Court
SDNY (indicted)
Judge
—
Charge
Wire fraud · securities fraud · money laundering
Plea
—
Sentence
Fugitive — FBI Top 10 Most Wanted
Restitution / Forfeiture
—

OneCoin was a fake cryptocurrency — no real blockchain. Co-founder disappeared in 2017. Estimated $4B+ raised from investors. On FBI's Most Wanted list. Warrant outstanding.

Elizabeth Anne Holmes
CONVICTED · SERVING
Elizabeth Anne Holmes
Theranos Founder · Edison device
Born
February 3, 1984 · Washington D.C.
Education
Stanford (2002) — dropped out at 19
Role
Founder & CEO Theranos
Court
N.D. California · San Jose
Judge
Edward J. Davila
Charge
Wire fraud · conspiracy to defraud investors
Verdict
Guilty 4 counts (investors) · acquitted patient counts
Sentence
135 months (11 yrs 3 mo)
Restitution
$452M ordered

She built a company on a story. The Edison blood-testing device could not perform as claimed. Board of Kissinger, Shultz, Mattis. Stanford dropout. Black turtleneck. The Jobs comparison. Ninth Circuit affirmed conviction February 2025: "the promise was a mirage."

Ramesh “Sunny” Balwani
CONVICTED — 12 COUNTS
Ramesh “Sunny” Balwani
Theranos President & COO · tried separately
Born
—
Role
President & COO Theranos
Court
N.D. California
Charge
Wire fraud · patient fraud · 12 counts
Verdict
Guilty all 12 counts · July 2022
Sentence
13 years · December 2022

Tried separately from Holmes. His jury convicted him on all 12 counts including the patient-related fraud charges that Holmes was acquitted on. Managed laboratory operations and the customer-facing blood-testing business. Romantic relationship with Holmes during the fraud period.

Karl Sebastian Greenwood
CONVICTED — 20 YEARS
Karl Sebastian Greenwood
OneCoin co-founder · Swedish / UK national
Nationality
Swedish / UK
Role
Co-founder OneCoin
Arrested
Thailand · July 2018
Sentence
20 years · Sep 2023
Fine
$300M
Judge
Edgardo Ramos · SDNY

Co-founded OneCoin with Ignatova. Personally misappropriated $300M+ on five-star resorts, villas, private jet, and a yacht. Arrested in Thailand 2018, 20 years sentenced 2023.

Konstantin Ignatov
TIME SERVED — RELEASED
Konstantin Ignatov
’s brother · forklift driver to figurehead
Role
De facto leader after Ruja’s disappearance
Arrested
LAX · March 2019
Plea
Guilty · cooperated
Sentence
Time served (34 months)
Forfeiture
$118,000
Sentenced
March 5, 2024

Recruited by his sister from a forklift driving job in Germany. Ran the operation after she disappeared. Cooperated with prosecutors. “I have only myself to blame.”

Mark Scott
CONVICTED — 10 YEARS
Mark Scott
Former Locke Lord partner · OneCoin money launderer
Role
Lawyer · laundered ~$400M
Firm
Former Locke Lord partner
Convicted
November 2019 · jury trial
Sentence
10 years · Jan 25, 2024

Laundered approximately $400M in OneCoin proceeds through a network of investment funds. The $400M is one piece of the money movement, not the total fraud scale.

Charles Ponzi
DECEASED — 1949
Carlo Ponzi · Securities Exchange Company · Boston 1920
Born
March 3, 1882 · Lugo, Italy
Died
January 18, 1949 · Rio de Janeiro
Arrived US
1903 · $2.50 in pocket
Charge
Mail fraud · larceny
Sentence
~12 years total · 3 convictions
Estate at death
~$75

He named the crime. Not by inventing it — by running it so visibly that the newspapers found the words and the English language absorbed his name permanently. $2.50 in. $75 out. Every case in this series is a version of the structure he made famous.

Robert Allen Stanford
CONVICTED — 110 YEARS
Sir (knighthood stripped) · USP Coleman II
Born
March 24, 1950 · Mexia, Texas
Education
Baylor University · Finance 1974
Court
S.D. Texas (Houston)
Judge
David Hittner
Sentence
110 years · June 14, 2012
Release
March 13, 2103

Legitimacy was the architecture. A real bank, a real knighthood, a real cricket stadium. $7.2B in CD fraud, 20,000 victims across 100 countries. SEC had examined and raised concerns before the collapse. He is still working on his case from Coleman II, scheduled release 2103.

James Davis
COOPERATED — PLEADED GUILTY
James Davis
Stanford CFO · former college roommate · star cooperating witness
Role
CFO Stanford Financial Group
Connection
Stanford’s college roommate at Baylor
Plea
Guilty · 2009 · cooperated
Key role
Testified re: fabricated financials

Stanford’s CFO and former Baylor University roommate. Pleaded guilty 2009 and cooperated with prosecutors, testifying about how the financial statements were fabricated and how investor money was redirected. The prosecution’s most significant inside witness.

Albert Gonzalez
RELEASED 2023
segvec · soupnazi · j4guar17
Born
1981 · Cuba · raised Miami
Role
Card data thief · Secret Service informant
Sentence
20 years · served ~13
Cards stolen
170 million
Released
2023
Court
D. New Jersey + D. Mass + S.D.N.Y.

The only person in this series who was inside the investigation while it was looking for him. He briefed Secret Service agents on how carding worked. He was the largest carder alive. Every briefing was an autobiography with the identifying details edited out.

Taek Jho Low
FUGITIVE — ALLEGED [NOT CONVICTED]
1MDB alleged mastermind · Penang, Malaysia
Born
November 4, 1981 · Penang, Malaysia
Education
Harrow · Wharton / UPenn 2005
Alleged scale
$4.5B+ [DOJ civil allegation]
Status
Fugitive · last seen Dec 24 2019
Conviction
NONE — never tried
Connected
Najib Razak (convicted PM)

Alleged architect of 1MDB sovereign fund fraud. Has never been convicted. Maintains his innocence. Last seen Shanghai Disneyland, December 24, 2019.

Najib Abdul Razak
CONVICTED — 7 COUNTS
Najib Abdul Razak
6th Prime Minister of Malaysia · convicted 2020
Role
PM Malaysia 2009–2018 · 1MDB advisory board
Counts
7: abuse of power · money laundering · breach of trust
Status
Convicted · Malaysian court record [FACT]
Precedent
First Malaysian PM convicted in history

The 1MDB case’s documented conviction. Malaysia had never before convicted a sitting or former prime minister. 7 counts: documented fact, not allegation.

Riza Aziz
CHARGED — MALAYSIA
Riza Aziz
Red Granite Pictures co-founder · stepson of PM Najib
Connection
Stepson of PM Najib Razak
Company
Red Granite Pictures
Film
The Wolf of Wall Street (2013)
Settlement
Red Granite DOJ forfeiture ~$60M (2017)

Co-founded Red Granite Pictures. Produced The Wolf of Wall Street. Red Granite settled a US DOJ forfeiture action for approximately $60M in 2017 without admitting wrongdoing. Charged separately in Malaysia.

Changpeng Zhao
PARDONED — OCT 2025
· Binance founder
Born
Sep 10, 1977 · Jiangsu, China
Education
McGill University · Computer Science
Role
Founder & former CEO, Binance
Charge
BSA violation (AML failure) — NOT fraud
Personal fine
$50M
Company penalty
$4.3B [Binance]
Sentence
4 months · FCI Lompoc
Pardoned
Oct 23, 2025 · Trump

Built the world’s largest crypto exchange without adequate AML controls. First person sentenced to prison for a single BSA violation. $4.3B company resolution. 4 months. Pardoned. The door was real. The controls were not.

James Zhong
RELEASED 2023
Individual X · Silk Road thief
Born
May 24, 1990 · New Jersey
Education
University of Georgia
Stolen
51,680 BTC (Sep 2012)
Value at seizure
~$3.4B (Nov 2021 prices)
Sentence
1 year and 1 day
Found in
Popcorn tin · bathroom closet · Gainesville GA

Stole from the criminals. Held 51,680 BTC for 9 years without spending it. The blockchain found him anyway. He robbed the robbers. The state took the loot.

FRAUD CATEGORIES

FRAUD CATEGORIES

Seven documented fraud categories. Each has a distinct methodology, a distinct victim profile, and a distinct detection signature. Understanding the category is the first step to understanding the case.

DOCUMENTED CATEGORIES
CATEGORY 01
Crypto / Digital Asset Fraud
Exchange collapses, algorithmic stablecoin failures, rug pulls, fake blockchain projects. The largest single-event loss category in recorded financial fraud history. Scale must be measured as market cap destroyed, not direct theft -- these are different figures.
CASES: · · Mashinsky · Ignatova
CATEGORY 02
BEC / Wire Fraud
Business Email Compromise. No malware. No hacking. One spoofed email, one misdirected wire. FBI IC3 #1 loss category by dollar volume since 2019. Single-transaction losses routinely exceed $1M. The attack surface is email trust and human verification failure.
CASES: · Olalekan Ponle
CATEGORY 03
Ponzi / Investment Fraud
Returns paid from new investor capital, not genuine returns. The scheme survives until inflows slow. Fabricated account statements are the instrument. Madoff operated for 17 years before discovery.
CASES: Madoff · Stanford
CATEGORY 04
Romance Scam / Pig Butchering
Long-form social engineering over weeks or months before any financial request. Pig butchering (sha zhu pan) adds a fake investment platform. Industrialized in SE Asia compound operations using trafficked workers. UNODC estimates $5.4B+ annually [UNVERIFIED -- estimate].
CASES: SE Asia syndicate compounds
CATEGORY 05
Dark Web / Marketplace
Tor-based marketplaces for fraud infrastructure: stolen credentials, carding data, synthetic identity kits, money mule recruitment. Silk Road established the model in 2011. Volume continued through successor markets after its takedown in 2013.
CASES: / Silk Road
CATEGORY 06
Card / Bank Fraud
Carding, BIN attacks, account takeover, synthetic identity fraud. High volume, lower per-incident. Compromised card data is the infrastructure input to most other fraud categories. Case files in preparation.
CASES: In preparation
CATEGORY 07
Historic Cases
Pre-digital fraud that established the templates modern schemes still follow. Belfort on pump-and-dump. Abagnale on impersonation. The category that explains why current regulation is structured as it is.
CASES: Belfort · Abagnale
METHODOLOGY

METHODOLOGY

TraceChain Fraud Intelligence publishes documented cases from court filings, regulatory actions, and verified public reporting. We do not publish accusations. We publish convictions, indictments, and sourced estimates -- and we tell you which is which.

EVIDENCE STANDARDS

CONVICTED
Federal or equivalent prosecution resulted in conviction or guilty plea. Sentence confirmed by court record.
INDICTED
Federal charges filed. Not yet adjudicated. Published with status clearly labeled.
ESTIMATED
Aggregate figure from a credible institutional source (UNODC, FBI IC3, regulatory filing). Labeled [UNVERIFIED] or [EST].
MARKET LOSS
Collapse of asset value -- not direct theft. Used for crypto collapses where paper loss and principal loss differ significantly.

WHAT WOULD PROVE US WRONG

Every figure we publish has a falsification condition. If a conviction is overturned, we update the record. If a loss estimate is revised by the source institution, we revise the entry. If you have court records that contradict a published figure, contact us. We review and correct within 48 hours.

WHAT THIS SITE IS NOT

X
Not legal advice, investment advice, or a definitive loss calculation for any individual victim.
X
Not a repository of attack tools or exploit instructions. Methods are explained at category level for defensive awareness only.
X
Not a platform for unverified allegations. Every entry carries a named source.

TRACECHAIN FORENSICS

An AI-powered cryptocurrency and financial fraud investigation platform. The Fraud Intelligence publication is the public research arm -- documenting what the industry has confirmed so defenders understand what they are facing.

Photos from Wikimedia Commons are credited on their cards. A person with no photo yet shows their initials.
MOST WANTED
People in this series who are on the run, ranked from the most taken to the least. Unless a poster says convicted, they have only been charged: what they are accused of is alleged until proven in court.
WANTED
Taek Jho Low (Jho Low)
· alleged 1MDB mastermind
$4.5BMalaysian public money from the 1MDB state fund (alleged; never tried).
WANTED BY
United States and Malaysia · Interpol notice since 2016
CHARGES
Money laundering (US, and others)
REWARD
None announced
DISAPPEARED
Reportedly last seen 24 December 2019
BORN
4 November 1981 · Malaysian
NOTE
Never arrested, never tried. Everything he is accused of is an allegation.
WANTED
Ruja Ignatova
"The " · OneCoin founder
~$4BInvestors' money paid for OneCoin packages (alleged; never tried).
WANTED BY
FBI: Ten Most Wanted list since 30 June 2022 · Interpol Red Notice
CHARGES
Wire fraud · securities fraud · conspiracy to commit wire fraud · conspiracy to commit money laundering (SDNY; indictment unsealed March 2019)
REWARD
Up to $5,000,000 (US State Department, June 2024)
DISAPPEARED
25 October 2017
BORN
30 May 1980 · German (formerly Bulgarian)
NOTE
Reporting alleges she may have been killed in 2018. Unconfirmed: officially she is a fugitive. She has never been tried; the charges are allegations.
Information? Contact the FBI at tips.fbi.gov or your nearest US embassy.
WANTED
Daren Li
"Devon" · "KG" · pig-butchering money launderer
$73.6MMoney Americans lost to fake romance and investment scams run from Cambodia. He moved it; the scammers took it.
WANTED BY
US Secret Service Most Wanted · US State Department
CONVICTED OF
Conspiracy to commit money laundering (C.D. California) — pleaded guilty 12 November 2024
SENTENCE
20 years, in absentia (February 2026)
REWARD
Up to $4,000,000 (US State Department, 24 April 2026)
FLED
December 2025 — cut off his ankle monitor
BORN
8 November 1982 · Chinese and St Kitts and Nevis citizen
NOTE
Unlike the others here, he has been convicted: he pleaded guilty, then fled before sentencing.
Information? Contact the US Secret Service or your nearest US embassy.
FRAUD HOTSPOTS
Where fraud is run from, where it lands, and who is getting caught: 77 countries in 9 regions, taken from three independent indexes (Oxford World Cybercrime Index, Sumsub Fraud Index 2025, GI-TOC Global Organized Crime Index 2025) plus Interpol, Chainalysis, FTC, FBI IC3 and national regulators.
An index rank describes a country's criminal networks or its exposure, never its people. Estimates are labelled. September 2026.
$442B
LOST TO FRAUD WORLDWIDE IN 2025
Interpol Global Financial Fraud Threat Assessment 2026 (victim losses)
$6.75B
CRYPTO STOLEN BY NORTH KOREA, ALL-TIME
Chainalysis, Dec 2025 ($2.02B of it in 2025)
220K+
PEOPLE HELD IN SCAM COMPOUNDS
UN OHCHR 2023: 120,000+ in Myanmar, 100,000+ in Cambodia (estimates)
$48B
E-COMMERCE FRAUD A YEAR
Juniper Research estimate (publisher's figure)
PICK A REGION
WHO LEADS EACH FRAUD TYPE
Ransomware
Russia, Ukraine, Iran
LockBit, BlackCat, REvil — all Russian-speaking
Crypto Theft (State)
North Korea
$6.75B all-time; $2.02B in 2025, 76% of hacks of crypto services (Chainalysis). .
BEC / Romance Scams
Nigeria, Ghana, Côte d'Ivoire
US romance-scam losses $1.14B in 2023 (FTC, from all countries). 'Yahoo Boys'; Black Axe.
Pig Butchering (Industrial)
Myanmar/Cambodia/Laos (Chinese-led)
$43.8–75B a year (estimates). Hundreds of thousands held in compounds (UN).
Card Fraud (Victim)
United States
42% of global losses on 26% of volume. No SCA mandate
Card Fraud (Source)
Russia, Romania, Ukraine
Russian forums dominate. Romanian 'Hackerville'
Gift Card ORC
China → United States
$1B+ drained annually. Project Red Hook
NFC Relay (Ghost Tap)
China (tooling) → Global
300%+ surge H1 2025. Chinese-language FaaS
Banking Trojans
Brazil, Russia
Grandoreiro, Guildma. Pix fraud. Exported globally
Friendly Fraud
United States, UK
36% of all fraud (Mastercard). 83.4% of merchants report an increase.
Synthetic Identity
United States
$23B globally. AI deepfakes. $3.3B of credit extended to synthetic identities.
Call Center Scams
India, Jamaica
Tech support + IRS impersonation + lottery scams
SIM Swap Fraud
Kenya, South Africa, Colombia
M-Pesa + mobile banking targeted. Spreading regionally
Money Laundering Hub
UAE, Switzerland, UK, Singapore
Real estate + banking + crypto used for transit
Government/State Fraud
Angola, Myanmar, Cambodia
Political elites involved in or protecting fraud (GI-TOC; US sanctions).
Identity Fraud (Volume)
Pakistan, Indonesia, Nigeria
#1, #2, #3 on Sumsub fraud vulnerability index
THE INDEXES — WHAT EACH ONE MEASURES
World Cybercrime Index (Oxford, PLOS ONE, Apr 2024). 92 experts rated 100 countries across 5 categories. Measures where cybercriminals operate FROM. Top 10: Russia, Ukraine, China, USA, Nigeria, Romania, North Korea, UK, Brazil, India.
Sumsub Fraud Index 2025. 112 countries ranked by fraud VULNERABILITY — fraud activity, access to resources, government action and economic health. Measures where it is easiest to commit fraud. Least protected: Pakistan, Indonesia, Nigeria, India, Tanzania. Most protected: Luxembourg.
Global Organized Crime Index 2025 (GI-TOC). All organized crime scored 0–10. Financial crime is now the most pervasive criminal market (6.21/10, growing fastest). Top: Myanmar 8.08, Colombia 7.82, Mexico 7.68, Ecuador and Paraguay 7.48. Covers all crime, not just fraud.
Interpol Africa Cyberthreat Assessment 2025. Cybercrime is 30%+ of all reported crime in West and East Africa. Operation Serengeti (2024): 1,006 arrests in 19 countries. Operation Red Card (2024–25): 306 arrests in 7 countries.
Chainalysis (Dec 2025). North Korea stole $2.02B in 2025 (76% of hacks of crypto services). Total crypto theft $3.4B. North Korea all-time: $6.75B.
BioCatch LATAM 2025–2026. Social engineering +155%. Stolen-device fraud +344%. Mexico account takeover +324%. 88% of fraud on mobile.
Interpol Global Financial Fraud Threat Assessment (2026). About $442B lost to fraud worldwide in 2025. AI and deepfakes accelerating.
Figures the desk checked are corrected in data/hotspots.json (editorial_changes). Other figures are the publisher's research and are labelled by source. The indexes measure different things: a high Sumsub rank means a country is easy to defraud, not that its people commit fraud.
🇷🇺🇺🇦🇷🇴🇧🇾🇲🇩🇬🇪
EASTERN EUROPE & CIS
The technical core of cybercrime: ransomware crews, carding forums and malware builders, with laundering routed through the region's banks.
TAP A COUNTRY FOR ITS OWN PAGE
🇨🇳🇰🇵🇯🇵🇰🇷🇹🇼🇵🇭
EAST ASIA & PACIFIC
China is both a leading source and a leading victim; North Korea steals crypto as state policy; Japan, Australia and New Zealand are mostly targets.
TAP A COUNTRY FOR ITS OWN PAGE
🇲🇲🇰🇭🇱🇦🇹🇭🇻🇳🇮🇩
SOUTHEAST ASIA
The scam-compound belt: Myanmar, Cambodia and Laos, where trafficked workers run pig-butchering scams under armed protection.
TAP A COUNTRY FOR ITS OWN PAGE
🇮🇳🇵🇰🇧🇩🇱🇰🇳🇵
SOUTH ASIA
Call-centre and tech-support scams aimed at the US, UK and Australia, and the countries Sumsub rates easiest to defraud.
TAP A COUNTRY FOR ITS OWN PAGE
🇳🇬🇬🇭🇨🇮🇸🇳🇨🇲🇧🇯
WEST AFRICA
Business email compromise, romance scams and advance-fee fraud, and the Interpol operations that target them.
TAP A COUNTRY FOR ITS OWN PAGE
🇿🇦🇰🇪🇹🇿🇺🇬🇪🇹🇷🇼
EAST & SOUTHERN AFRICA
Mobile-money and SIM-swap fraud around M-Pesa, South Africa's card and ransomware problem, and state-level financial scandals.
TAP A COUNTRY FOR ITS OWN PAGE
🇮🇷🇮🇱🇦🇪🇸🇦🇹🇷🇪🇬
MIDDLE EAST & NORTH AFRICA
State-backed hacking from Iran, laundering through Gulf wealth hubs, and a region that is mostly a target.
TAP A COUNTRY FOR ITS OWN PAGE
🇺🇸🇧🇷🇲🇽🇨🇴🇦🇷🇵🇪
AMERICAS
The US is the #1 victim and #4 source; Latin America leads on banking trojans and account takeover; Jamaica on lottery scams.
TAP A COUNTRY FOR ITS OWN PAGE
🇬🇧🇩🇪🇫🇷🇳🇱🇪🇸🇮🇹
WESTERN & NORTHERN EUROPE
Mostly targets and enforcers — Europol, German and Dutch takedowns — plus laundering through London and Swiss banks.
TAP A COUNTRY FOR ITS OWN PAGE
🇧🇬
BULGARIA
Not yet on the Hotspot Map: this page lists the people in our case files tied to Bulgaria.
BORN HERE
1 person in our case files was born in Bulgaria. Tap to open the report.
OPERATED HERE
Physically based or working in Bulgaria — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Sofia, Bulgaria
WHAT THEY DID HERE, AND WHEN
2014Founds OneCoin in Sofia; the 'blockchain' investors were sold never existed.SOURCE: US indictment, SDNY 2019
2014–2017Runs the OneCoin sales machine from Sofia; ~€4B raised worldwide according to prosecutors.SOURCE: DOJ; BBC
25 Oct 2017Boards a Ryanair flight Sofia–Athens and disappears.SOURCE: FBI; BBC
OUR CASES BY CATEGORY
Share of the 1 case tied to Bulgaria (born or operated here)
CRYPTO
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇨🇺
CUBA
Not yet on the Hotspot Map: this page lists the people in our case files tied to Cuba.
BORN HERE
1 person in our case files was born in Cuba. Tap to open the report.
OPERATED HERE
Nobody in our case files is documented as operating from Cuba yet.
OUR CASES BY CATEGORY
Share of the 1 case tied to Cuba (born or operated here)
CARD
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇱🇹
LITHUANIA
Not yet on the Hotspot Map: this page lists the people in our case files tied to Lithuania.
BORN HERE
1 person in our case files was born in Lithuania. Tap to open the report.
OPERATED HERE
Physically based or working in Lithuania — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Vilnius, Lithuania
WHAT THEY DID HERE, AND WHEN
2013–2015Registers a company with the same name as Quanta Computer and sends fake invoices to Facebook and Google; ~$122M paid into his accounts.SOURCE: DOJ SDNY
Mar 2017Arrested by Lithuanian police; extradited to the US in Aug 2017.SOURCE: DOJ
OUR CASES BY CATEGORY
Share of the 1 case tied to Lithuania (born or operated here)
BANK & WIRE
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇲🇪
MONTENEGRO
Not yet on the Hotspot Map: this page lists the people in our case files tied to Montenegro.
BORN HERE
Nobody in our case files was born in Montenegro yet.
OPERATED HERE
Physically based or working in Montenegro — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Montenegro
WHAT THEY DID HERE, AND WHEN
2023Arrested at Podgorica airport travelling on false documents; held until extradition to the US.SOURCE: DOJ; AP
OUR CASES BY CATEGORY
Share of the 1 case tied to Montenegro (born or operated here)
CRYPTO
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇭🇰
HONG KONG
Not yet on the Hotspot Map: this page lists the people in our case files tied to Hong Kong.
BORN HERE
Nobody in our case files was born in Hong Kong yet.
OPERATED HERE
Physically based or working in Hong Kong — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Hong Kong
WHAT THEY DID HERE, AND WHEN
2019–2021Founds FTX and runs both companies from Hong Kong.SOURCE: DOJ SDNY; case brief
Hong Kong
WHAT THEY DID HERE, AND WHEN
2019–2021Runs Alameda alongside FTX from Hong Kong; rises to co-CEO, then CEO.SOURCE: DOJ sentencing letter; Reuters
OUR CASES BY CATEGORY
Share of the 2 cases tied to Hong Kong (born or operated here)
CRYPTO
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇧🇸
BAHAMAS
Not yet on the Hotspot Map: this page lists the people in our case files tied to Bahamas.
BORN HERE
Nobody in our case files was born in Bahamas yet.
OPERATED HERE
Physically based or working in Bahamas — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Nassau, Bahamas
WHAT THEY DID HERE, AND WHEN
2021–2022Moves FTX headquarters to the Bahamas; customer funds flow to Alameda through the exchange's hidden credit line.SOURCE: DOJ SDNY; trial record
Nov–Dec 2022FTX collapses; arrested in Nassau on 12 Dec 2022 and extradited to the US on 21 Dec.SOURCE: DOJ
Nassau, Bahamas
WHAT THEY DID HERE, AND WHEN
2021–Nov 2022As Alameda's CEO, directs the use of FTX customer money to cover Alameda's losses and lenders; keeps the real balance sheet from the public.SOURCE: DOJ sentencing letter, 17 Sept 2024
Nov 2022Tells staff the truth as FTX collapses, then speaks to the government before she is charged.SOURCE: DOJ sentencing letter
OUR CASES BY CATEGORY
Share of the 2 cases tied to Bahamas (born or operated here)
CRYPTO
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇦🇬
ANTIGUA AND BARBUDA
Not yet on the Hotspot Map: this page lists the people in our case files tied to Antigua and Barbuda.
BORN HERE
Nobody in our case files was born in Antigua and Barbuda yet.
OPERATED HERE
Physically based or working in Antigua and Barbuda — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
St. John's, Antigua and Barbuda
WHAT THEY DID HERE, AND WHEN
1990s–2009Stanford International Bank sells ~$7B of certificates of deposit with returns paid from new money; he is knighted by Antigua.SOURCE: SEC complaint, 17 Feb 2009
Aug 2008Lands a helicopter at Lord's with a $20M prize for the Stanford Super Series.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 1 case tied to Antigua and Barbuda (born or operated here)
PONZI
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇲🇻
MALDIVES
Not yet on the Hotspot Map: this page lists the people in our case files tied to Maldives.
BORN HERE
Nobody in our case files was born in Maldives yet.
OPERATED HERE
Physically based or working in Maldives — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Malé, Maldives
WHAT THEY DID HERE, AND WHEN
5 July 2014Detained at Malé airport by US agents and flown to Guam.SOURCE: DOJ
OUR CASES BY CATEGORY
Share of the 1 case tied to Maldives (born or operated here)
CARD
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇱🇨
SAINT LUCIA
Not yet on the Hotspot Map: this page lists the people in our case files tied to Saint Lucia.
BORN HERE
Nobody in our case files was born in Saint Lucia yet.
OPERATED HERE
Physically based or working in Saint Lucia — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Saint Lucia
WHAT THEY DID HERE, AND WHEN
2020–2024Runs Incognito Market from Saint Lucia, according to the DOJ and press; the market moves ~$100M in narcotics.SOURCE: DOJ SDNY
Mar 2024Exit scam: keeps users' deposits and threatens to publish their data.SOURCE: DOJ SDNY
OUR CASES BY CATEGORY
Share of the 1 case tied to Saint Lucia (born or operated here)
DARK WEB
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
🇷🇺
RUSSIA
#1 WCI
CAPITAL Moscow · POPULATION 144.8M (2024, UN)
FRAUD TYPES
Ransomware, carding, dark web, APT hacking, money laundering
KEY FACTS
#1 in all 5 WCI categories. Most technically skilled globally. State tolerance of outbound cybercrime. LockBit, REvil and other major ransomware brands were run by Russian-speaking crews.
BORN HERE
4 people in our case files were born in Russia. Tap to open the report.
OPERATED HERE
Physically based or working in Russia — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Russia
WHAT THEY DID HERE, AND WHEN
variousIndicted members were 'at times stationed' in Russia, the DOJ says.SOURCE: DOJ indictment, Feb 2021
Russia
WHAT THEY DID HERE, AND WHEN
2015–2022Runs Hydra, the Russian-language darknet market supplying drugs across Russia and Belarus by dead drop; >$5.2B in crypto passed through it.SOURCE: Moscow Regional Court, 2 Dec 2024; DOJ
2 Dec 2024Convicted in Moscow and sentenced to life.SOURCE: Moscow Regional Court, per TASS
Syktyvkar and Moscow, Russia
WHAT THEY DID HERE, AND WHEN
2005–2012'Hacker 1': breaks into Heartland, NASDAQ, 7-Eleven and others from Russia; 160M cards across the crew.SOURCE: DOJ D.N.J.
Vladivostok, Russia
WHAT THEY DID HERE, AND WHEN
2009–2013Hacks point-of-sale systems and sells card data on his own forums from Vladivostok; 2.9M cards.SOURCE: W.D. Wash. trial record
OUR CASES BY CATEGORY
Share of the 5 cases tied to Russia (born or operated here)
CARD
40%
CRYPTO
20%
DARK WEB
20%
LAUNDERING
20%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Banking malware and card theftCrypto money laundering exchangesPhone and 'safe account' scamsCrypto Ponzi schemesRansomware-linked fraud
THE PICTURE

Russia is both a major source of cyber-enabled fraud aimed abroad and a heavy target of domestic phone and online scams. Russian-speaking groups have run banking-malware and card-theft operations such as Evil Corp's Dridex campaign, which US authorities say caused more than $100 million in losses (US Treasury/DOJ, 2019), and exchanges such as BTC-e and Garantex that US prosecutors say laundered criminal proceeds (DOJ, 2024–2025). At home, the Bank of Russia reported a record 27.5 billion rubles stolen through unauthorised bank transactions in 2024 and 29.3 billion rubles in 2025 (Bank of Russia, 2025–2026). Russia does not extradite its nationals, so most foreign cases end in indictments, sanctions or arrests abroad, and several convicted cybercriminals were returned to Russia in the 2024 and 2025 US–Russia prisoner exchanges (CBS News, 2025).

TOP FRAUDSTERS FROM HERE
Aleksandr Mira Serda CHARGED (NOT TRIED)REPORT PENDING
$96bn (transactions processed by Garantex, per DOJ) · 2019–2025
Named by US prosecutors as a co-founder of the Garantex crypto exchange, which they say processed at least $96 billion, including proceeds of hacks, ransomware and sanctions evasion.
SOURCE: US Department of Justice, March 2025
Alexander Vinnik PLEADED GUILTYREPORT PENDING
$9bn+ (transactions through BTC-e, per DOJ) · 2011–2017
Operated the BTC-e crypto exchange, which prosecutors said handled more than $9 billion in transactions and served hackers, ransomware gangs and drug rings; released to Russia in a February 2025 prisoner swap.
SOURCE: US Department of Justice, May 2024; CBS News, Feb 2025
Vladimir Okhotnikov CHARGED (NOT TRIED)REPORT PENDING
$340M (alleged investor funds raised) · 2020–2022
One of four Forsage founders indicted in the US over a crypto 'smart contract' Ponzi and pyramid scheme.
SOURCE: US Department of Justice, Feb 2023
Maksim Yakubets FUGITIVEREPORT PENDING
$100M+ (theft losses, per US Treasury) · 2011–2019
Alleged leader of Evil Corp, whose Dridex malware stole online-banking credentials from banks in over 40 countries; subject of a $5M US reward.
SOURCE: US Treasury OFAC / DOJ, Dec 2019
Vladislav Klyushin CONVICTEDREPORT PENDING
$93M (illicit trading profits) · 2018–2020
Ran a hack-to-trade scheme that stole corporate earnings reports before release; sentenced to nine years in the US, released in the August 2024 prisoner swap.
SOURCE: CNBC, Aug 2024
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
27.5bn rubles Stolen via unauthorised bank transactions in 2024 (+74.4% y/y) (Bank of Russia, Feb 2025)
29.3bn rubles Stolen via unauthorised bank transactions in 2025 (+6.4% y/y) (Bank of Russia, 2026)
$96bn Transactions processed by Garantex since 2019, per US prosecutors (US Department of Justice, March 2025)
WHO FIGHTS IT
Bank of Russia operates the FinCERT anti-fraud centre and publishes quarterly statistics on unauthorised transactions.
A 2025 federal anti-fraud law (No. 41-FZ) added measures such as limits on SIM cards and the option for people to block new loans (The Record, 2025).
The US, Germany and Finland seized Garantex domains and servers in March 2025; the US has sanctioned Evil Corp (2019) and indicted Garantex and Forsage figures.
Russia's constitution bars extradition of its citizens; Vinnik, Seleznev and Klyushin were returned to Russia in the 2024–2025 prisoner exchanges.
SOURCES
Bank of Russia, anti-fraud statistics, 2025–2026
The Record (Recorded Future News), 2025
US Department of Justice press releases, 2017–2025
US Treasury OFAC, Dec 2019
CBS News, Feb 2025
CNBC, Aug 2024
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇺🇦
UKRAINE
#2 WCI
CAPITAL Kyiv · POPULATION 37.9M (2024, UN)
FRAUD TYPES
Ransomware, carding, malware dev, hacking-for-hire
KEY FACTS
#2 globally for cybercrime skill. War has not reduced output. Criminal/hacktivist overlap.
BORN HERE
1 person in our case files was born in Ukraine. Tap to open the report.
OPERATED HERE
Physically based or working in Ukraine — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Ukraine
WHAT THEY DID HERE, AND WHEN
2019Spends about a month in Ukraine, which the government says was used to move funds.SOURCE: sentencing filings
OUR CASES BY CATEGORY
Share of the 2 cases tied to Ukraine (born or operated here)
CRYPTO
50%
LAUNDERING
50%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Investment scam call centresBank and police impersonation callsBanking malwareRansomware
THE PICTURE

Ukraine hosts scam call centres that target victims across Europe with fake investment platforms and bank- or police-impersonation calls; the UN Office on Drugs and Crime estimated that up to 1,500 such call centres operated there as recently as 2024, many in and around Dnipro (bne IntelliNews citing UNODC, 2025). In October 2024, Czech, Latvian, Lithuanian and Ukrainian authorities, with Eurojust, hit a network running call centres in Dnipro, Ivano-Frankivsk and Kyiv, with estimated losses above EUR 10 million from more than 400 known victims (Eurojust, 2024). Ukraine's Cyber Police and Europol also arrested suspects in an investment scheme said to take more than EUR 200 million a year (Europol/Cyber Police, 2024). Several Ukrainian nationals have been convicted in the US for ransomware and banking-malware schemes.

TOP FRAUDSTERS FROM HERE
Yaroslav Vasinskyi CONVICTEDREPORT PENDING
$700M+ (ransom demanded, per DOJ); $16M restitution ordered · 2019–2021
REvil/Sodinokibi ransomware affiliate behind about 2,500 attacks, including the 2021 Kaseya attack; sentenced to 13 years 7 months in the US.
SOURCE: US Department of Justice, May 2024
Vyacheslav Penchukov PLEADED GUILTYREPORT PENDING
Tens of millions of dollars (stolen from victims' bank accounts, per DOJ) · 2009–2021
Leader in the Jabber Zeus banking-malware crew and the IcedID malware operation; sentenced to two concurrent nine-year terms in the US.
SOURCE: US Department of Justice, July 2024
Oleksandr Ieremenko FUGITIVEREPORT PENDING
$4.1M (alleged trading profits) · 2016–2019
Charged with hacking the US SEC's EDGAR filing system to steal non-public earnings releases for insider trading.
SOURCE: US Department of Justice / SEC, Jan 2019
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
Up to 1,500 Fraudulent call centres estimated to operate in Ukraine (2024) (UNODC via bne IntelliNews, 2025)
EUR 10M+ Losses to 400+ known victims of one Dnipro/Ivano-Frankivsk/Kyiv call-centre network (Eurojust, Oct 2024)
EUR 200M+ a year Alleged take of an investment-fraud scheme disrupted by Cyber Police and Europol (Europol / Ukraine Cyber Police, 2024)
WHO FIGHTS IT
Cyber Police Department of the National Police leads call-centre raids, often with Europol and Eurojust.
Office of the Prosecutor General ran special operation 'Connect' with EU partners against a transnational call-centre network.
October 2024 Eurojust-supported joint action with Czechia, Latvia and Lithuania against call centres in Dnipro, Ivano-Frankivsk and Kyiv.
US prosecutions of extradited Ukrainians (Vasinskyi, 2024; Penchukov, 2024) for ransomware and banking malware.
SOURCES
bne IntelliNews, 2025
Eurojust press release, Oct 2024
Europol / Bitdefender, 2024
Prosecutor General of Ukraine
US Department of Justice press releases, 2019–2024
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇷🇴
ROMANIA
#6 WCI
CAPITAL Bucharest · POPULATION 19.0M (2024, UN)
FRAUD TYPES
Carding, auction fraud, ATM skimming, malware
KEY FACTS
'Hackerville' (Ramnicu Valcea). Top 10 in every WCI category. Strong technical pipeline.
BORN HERE
Nobody in our case files was born in Romania yet.
OPERATED HERE
Nobody in our case files is documented as operating from Romania yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Online auction and marketplace fraudATM card skimmingBanking malwareInvestment fund collapse (FNI)
THE PICTURE

Romanian criminal groups have been prominent in online auction fraud, card skimming and malware for over two decades, often operating abroad. The Bayrob group used fake eBay listings and malware to steal more than $4 million from US victims; two leaders were sentenced in the US in 2019 (DOJ, 2019). The Riviera Maya gang, allegedly led by Romanian national Florian Tudor, is accused of large-scale ATM skimming in Mexico (OCCRP, 2020). At home, the FNI investment-fund collapse of 2000 left a lasting mark, with businessman Sorin Ovidiu Vântu later jailed over it (Wikipedia summary of court rulings). Enforcement rests with DIICOT, the organised-crime and terrorism prosecutors' office, working closely with the FBI and Europol.

TOP FRAUDSTERS FROM HERE
Florian Tudor CHARGED (NOT TRIED)REPORT PENDING
Up to $1.2bn (OCCRP estimate of gang earnings; alleged) · 2014–2021
Alleged leader of the Riviera Maya gang, accused of running ATM skimming across Mexico's tourist areas; arrested in Mexico in 2021.
SOURCE: OCCRP, 2020–2021
Bogdan Nicolescu CONVICTEDREPORT PENDING
$4M+ (stolen from victims) · 2007–2016
Led the Bayrob group, which posted fake car listings on eBay, infected computers with malware and mined crypto on victims' machines; sentenced to 20 years in the US.
SOURCE: US Department of Justice, Dec 2019
Radu Miclaus CONVICTEDREPORT PENDING
$4M+ (stolen from victims, group total) · 2007–2016
Bayrob group member convicted alongside Nicolescu; sentenced to 18 years in the US.
SOURCE: US Department of Justice, Dec 2019
Sorin Ovidiu Vântu CONVICTEDREPORT PENDING
Not quantified in sources reviewed · 2000
Controlled the FNI investment fund, whose collapse wiped out small savers; sentenced to eight years over the scheme.
SOURCE: Wikipedia summary of Romanian court rulings, 2016
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$4M+ Stolen by the Bayrob group from US victims (US Department of Justice, Dec 2019)
Up to $1.2bn OCCRP estimate of Riviera Maya gang's skimming earnings (alleged) (OCCRP, 2020)
WHO FIGHTS IT
DIICOT (Directorate for Investigating Organized Crime and Terrorism) prosecutes cybercrime and organised fraud.
Long-running cooperation with the FBI led to the extradition and US conviction of Bayrob leaders (2016–2019).
Romania participates in Europol-coordinated actions against skimming and online fraud networks.
SOURCES
US Department of Justice, Dec 2019
OCCRP, Riviera Maya Gang investigation, 2020
Wikipedia, Sorin Ovidiu Vântu (court rulings)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇧🇾
BELARUS
WCI top 20
CAPITAL Minsk · POPULATION 9.1M (2024, UN)
FRAUD TYPES
Ransomware infrastructure, money laundering
KEY FACTS
Safe harbor alongside Russia. Infrastructure for ransomware operations.
BORN HERE
Nobody in our case files was born in Belarus yet.
OPERATED HERE
Nobody in our case files is documented as operating from Belarus yet.
KNOWN FOR
Crypto money launderingRansomware and cybercrime (cases prosecuted abroad)
THE PICTURE

Public, independently verifiable data on fraud in Belarus is limited, and official statistics are not published in a form suitable for a sourced breakdown. The best-documented cases involve Belarusian nationals prosecuted abroad over crypto money laundering, such as Aliaksandr Klimenka, charged by US prosecutors in connection with the BTC-e exchange (DOJ, 2023). Western sanctions and the breakdown in law-enforcement cooperation since 2020 make cross-border fraud cases harder to pursue.

TOP FRAUDSTERS FROM HERE
Aliaksandr Klimenka CHARGED (NOT TRIED)REPORT PENDING
Not quantified separately (BTC-e processed $9bn+, per DOJ) · 2011–2017
Belarusian-Ukrainian national arrested in Latvia and charged by US prosecutors with laundering money through the BTC-e exchange and running an unlicensed money business.
SOURCE: US Department of Justice, 2024
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Ministry of Internal Affairs (Main Directorate for Combating Cybercrime) handles domestic online fraud.
Cross-border cases involving Belarusian nationals are mostly prosecuted in the US and EU after arrests in third countries.
SOURCES
US Department of Justice, 2024
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇲🇩
MOLDOVA
GI-TOC flagged
CAPITAL Chișinău · POPULATION 3.0M (2024, UN)
FRAUD TYPES
Money laundering, banking fraud
KEY FACTS
The 'Russian Laundromat': $20.8B moved through Moldovan banks in 2010–2014 (OCCRP); some estimates go up to $80B.
BORN HERE
Nobody in our case files was born in Moldova yet.
OPERATED HERE
Nobody in our case files is documented as operating from Moldova yet.
KNOWN FOR
Bank fraud (2014 'theft of the billion')Money launderingPhone and online scams
THE PICTURE

Moldova's defining fraud case is the 2014 'theft of the billion', in which about $1 billion vanished from three banks, equal to roughly an eighth of GDP at the time (Euronews, 2026). Ilan Shor was sentenced in absentia to 15 years in 2023 and remains a fugitive (AP, 2023), while former Democratic Party leader Vladimir Plahotniuc was extradited from Greece in September 2025 and sentenced to 19 years in April 2026; he says the case is political and is appealing (Euronews, 2026). Police also report a sharp rise in phone and online fraud, with online fraud damages growing from 73 million to over 211 million lei in one year (General Police Inspectorate, 2025).

TOP FRAUDSTERS FROM HERE
Vladimir Plahotniuc CONVICTEDREPORT PENDING
$1bn (stolen from Moldovan banks, whole scheme) · 2014
Convicted of creating a criminal organisation, fraud and money laundering over the 2014 disappearance of about $1 billion from three Moldovan banks; appealing.
SOURCE: Euronews, April 2026
Ilan Shor FUGITIVEREPORT PENDING
$1bn (stolen from Moldovan banks, whole scheme) · 2012–2014
Sentenced in absentia to 15 years for fraud and money laundering in the $1 billion bank theft; fled Moldova in 2019 and is sanctioned by the US, UK and EU.
SOURCE: AP / The Hill, April 2023
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$1bn Stolen from three Moldovan banks in 2014, about one-eighth of GDP (Euronews, April 2026)
211M+ lei Online fraud damages, up from 73M lei a year earlier (Moldova General Police Inspectorate via e-Governance Academy, Oct 2025)
1,225 Online financial-banking crimes recorded in 2025 (832 in 2024) (Moldova General Police Inspectorate via e-Governance Academy, Oct 2025)
WHO FIGHTS IT
Anti-Corruption Prosecutor's Office leads bank-fraud cases; Plahotniuc sentenced to 19 years by a Chișinău court (April 2026).
General Police Inspectorate cybercrime unit investigates phone and online fraud and runs a national awareness campaign (2025).
Plahotniuc was arrested in Greece on an Interpol notice (July 2025) and extradited (September 2025).
SOURCES
Euronews, April 2026
AP / The Hill, April 2023
Balkan Insight, Sept 2025
e-Governance Academy, Oct 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇬🇪
GEORGIA
Sumsub flagged
CAPITAL Tbilisi · POPULATION 3.8M (2024, UN)
FRAUD TYPES
Call center scams, identity fraud
KEY FACTS
Growing digital economy and weak enforcement mean rising fraud.
BORN HERE
Nobody in our case files was born in Georgia yet.
OPERATED HERE
Nobody in our case files is documented as operating from Georgia yet.
KNOWN FOR
Investment scam call centresFake crypto and forex trading platformsAlleged official protection of call centres
THE PICTURE

Tbilisi became a base for investment-scam call centres that sell fake crypto and forex trading to victims in Europe and Canada. The 2025 'Scam Empire' investigation, based on 1.9TB of leaked data, found one Tbilisi operation had taken $35.3 million from more than 6,100 people between May 2022 and February 2025, and linked networks in Israel, Eastern Europe and Georgia to at least $275 million from 32,000 people (OCCRP, March 2025). Georgian prosecutors opened a criminal probe days after publication (OCCRP, 2025), and in December 2025 former State Security Service chief Grigol Liluashvili was detained on charges of taking bribes to protect call centres; he has not been tried (OCCRP, Dec 2025).

TOP FRAUDSTERS FROM HERE
Grigol Liluashvili CHARGED (NOT TRIED)REPORT PENDING
$1.365M (alleged bribes received) · 2021–2023
Former head of Georgia's State Security Service, charged with accepting bribes to shield scam call centres targeting foreign victims.
SOURCE: OCCRP, Dec 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$35.3M Taken from 6,100+ victims by one Tbilisi call centre, May 2022–Feb 2025 (OCCRP, March 2025)
$275M+ Taken from 32,000 people by the call-centre networks in the Scam Empire leak (OCCRP, March 2025)
WHO FIGHTS IT
Prosecutor's Office of Georgia opened a criminal investigation into the exposed Tbilisi call centre in March 2025.
Ex-security chief Grigol Liluashvili detained in December 2025 on four corruption charges linked to call-centre protection.
Investigative reporting (OCCRP, SVT, iFact) has driven most public exposure of the sector.
SOURCES
OCCRP, Scam Empire project, March 2025
OCCRP news, March 2025 and Dec 2025
OC Media, 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇰🇿
KAZAKHSTAN
Emerging
CAPITAL Astana · POPULATION 20.6M (2024, UN)
FRAUD TYPES
Crypto mining fraud, investment scams
KEY FACTS
Growing crypto adoption without matching regulation.
BORN HERE
Nobody in our case files was born in Kazakhstan yet.
OPERATED HERE
Nobody in our case files is documented as operating from Kazakhstan yet.
KNOWN FOR
Fake online storesFraudulent investment and pyramid schemesPhone and social-media scamsBank asset stripping (BTA Bank)
THE PICTURE

Kazakhstan faces high volumes of online fraud, especially fake online shops, phone scams and fraudulent investment schemes, including pyramid schemes promoted through messaging apps. A national Anti-Fraud Center run by the National Payment Corporation logged more than 90,000 fraud cases between its July 2024 launch and February 2026 (Astana Times, 2026). The country's largest fraud dispute is the BTA Bank case: the bank won English court claims worth over $6 billion against former chairman Mukhtar Ablyazov, who was also convicted in absentia in Kazakhstan and lives in France (RFE/RL, 2018; English High Court records). The Agency for Financial Monitoring leads investigations into pyramid schemes and money laundering.

TOP FRAUDSTERS FROM HERE
Mukhtar Ablyazov FUGITIVEREPORT PENDING
$6bn+ (value of BTA Bank's English court claims) · 2005–2009
Former BTA Bank chairman found liable by English courts in claims worth over $6 billion; convicted in absentia in Kazakhstan and living in France. He says the cases are political.
SOURCE: English High Court judgments; RFE/RL, 2018
FRAUD BY CATEGORY
share of cases within the five most-reported fraud types (computed from published counts) · July 2024–Feb 2026
Fake online stores
30.9%
Scams (general)
27%
Fraudulent investment schemes
20.8%
Social media fraud
11.7%
Credit fraud
9.6%
SOURCE: National Payment Corporation Anti-Fraud Center, as reported by The Astana Times, 11 Feb 2026
KEY NUMBERS
90,000+ Fraud cases logged by the Anti-Fraud Center, July 2024–Feb 2026 (The Astana Times, Feb 2026)
24,042 Fake online store cases, the most common type (The Astana Times, Feb 2026)
$6bn+ Combined value of BTA Bank's English court claims against Ablyazov (English High Court records)
WHO FIGHTS IT
Agency for Financial Monitoring (AFM), created in 2021, investigates financial pyramids and money laundering.
Anti-Fraud Center at the National Payment Corporation (launched July 2024) links banks and police to trace and block fraudulent transfers.
A 2026–2028 plan targets digital, crypto and marketplace fraud (Astana Times, 2026).
SOURCES
The Astana Times, Feb 2026
RFE/RL, 2018
English High Court (JSC BTA Bank v Ablyazov)
Agency for Financial Monitoring
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇨🇳
CHINA
#3 WCI
CAPITAL Beijing · POPULATION 1.42B (2024, UN)
FRAUD TYPES
ORC networks, pig butchering leadership, NFC relay (Ghost Tap), digital skimming, telecom fraud
KEY FACTS
Chinese-led syndicates run much of the Southeast Asian scam-compound industry (estimates $43.8–75B a year). Gift-card draining targeted by US Project Red Hook. 'Ghost Tap' NFC-relay tools sold on Chinese-language channels.
BORN HERE
3 people in our case files were born in China. Tap to open the report.
OPERATED HERE
Physically based or working in China — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Anhui province and Beijing, China
WHAT THEY DID HERE, AND WHEN
July 2014–Dec 2015Runs Ezubao from Yucheng Group; fake leasing projects raise ¥50B+ from ~900,000 investors.SOURCE: Beijing No.1 Intermediate People's Court, Sept 2017
Jan 2016Arrested; sentenced to life in Sept 2017.SOURCE: Xinhua
Dalian, China
WHAT THEY DID HERE, AND WHEN
2011–2013Park Jin Hyok works at Chosun Expo, a front company in Dalian, according to the DOJ.SOURCE: DOJ complaint, Sept 2018
Shanghai, China
WHAT THEY DID HERE, AND WHEN
24 Dec 2019Reportedly last seen at Shanghai Disneyland; a fugitive since.SOURCE: press reports; Malaysian police
Shanghai, China
WHAT THEY DID HERE, AND WHEN
2017Founds Binance in Shanghai; leaves after China bans crypto exchanges that autumn.SOURCE: case brief
Shenzhen, China
WHAT THEY DID HERE, AND WHEN
2016–2023Lives in Shenzhen and runs Bitzlato, the exchange that the DOJ says moved ~$700M for darknet markets including Hydra.SOURCE: DOJ E.D.N.Y.
China
WHAT THEY DID HERE, AND WHEN
before 2021Chinese national; lived in China before moving to Cambodia and the UAE, according to the DOJ.SOURCE: DOJ
OUR CASES BY CATEGORY
Share of the 6 cases tied to China (born or operated here)
LAUNDERING
50%
CRYPTO
33%
PONZI
17%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Scam compounds in Southeast Asia'Pig-butchering' investment and romance fraudTelecom fraudPonzi schemesCrypto money laundering
THE PICTURE

Chinese-run criminal networks are central to the industrial scam compounds of Southeast Asia, especially in Myanmar, Cambodia and Laos, which run 'pig-butchering' investment and romance fraud against victims in China and worldwide. Beijing has cracked down hard: 2,876 Chinese suspects were repatriated from Myawaddy in early 2025, over 630 buildings at the KK Park compound were demolished, and all related suspects were reported returned by February 2026 (Ministry of Public Security, 2025–2026). In January 2026 a Wenzhou court executed 11 members of the Ming family syndicate from Myanmar's Kokang region after death sentences in September 2025 (CNN, 2026). Chinese investors are also frequent victims of domestic Ponzi schemes, such as the Lantian Gerui scheme whose proceeds turned up as 61,000 bitcoin in the UK (Metropolitan Police, 2025).

TOP FRAUDSTERS FROM HERE
Xu Jiayin (Hui Ka Yan) SANCTIONEDREPORT PENDING
$78bn (inflated revenue); 47M yuan fine · 2019–2020
Evergrande founder, fined by China's securities regulator after its property arm inflated revenue in 2019–2020; banned from the securities market for life.
SOURCE: China Securities Regulatory Commission, March 2024
Chen Zhi CHARGED (NOT TRIED)REPORT PENDING
~$15bn (bitcoin subject to US forfeiture action) · 2015–2025
Chairman of Cambodia's Prince Group, charged by US prosecutors over forced-labour scam compounds; the US sought forfeiture of about 127,271 bitcoin.
SOURCE: US Department of Justice, Oct 2025
Qian Zhimin PLEADED GUILTYREPORT PENDING
£5bn (~$6.6bn) in bitcoin seized (61,000 BTC) · 2014–2017
Ran the Tianjin Lantian Gerui Ponzi scheme that took money from more than 128,000 Chinese investors, then fled to the UK with the proceeds in bitcoin; sentenced to 11 years 8 months.
SOURCE: Metropolitan Police / CNN, Nov 2025
Ming Guoping (Ming Xiaoping) CONVICTEDREPORT PENDING
10bn yuan+ (~$1.4bn; telecom fraud and gambling proceeds) · 2015–2023
Member of the Kokang-based Ming family that ran scam compounds in Myanmar; sentenced to death with 10 others and executed in January 2026.
SOURCE: CNN / SCMP, Jan 2026
Guo Wengui (Miles Guo) CONVICTEDREPORT PENDING
$1bn+ (raised from followers) · 2018–2023
Exiled Chinese businessman convicted in New York of defrauding thousands of online followers through fake investment offers; sentenced to 30 years and ordered to forfeit $889 million. He plans to appeal.
SOURCE: US DOJ; Bloomberg, June 2026
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
2,876 Chinese telecom-fraud suspects repatriated from Myawaddy, Myanmar (Ministry of Public Security, March 2025)
630+ Buildings demolished at Myawaddy's KK Park scam compound (Ministry of Public Security via Global Times, Feb 2026)
62,000 People prosecuted for telecom and online fraud (Supreme People's Procuratorate via Global Times, Feb 2026)
11 Ming family members executed in January 2026 (CNN, Jan 2026)
WHO FIGHTS IT
Anti-Telecom and Online Fraud Law in force since 1 December 2022.
Ministry of Public Security runs joint repatriation operations with Myanmar and Thailand under a ministerial coordination mechanism set up in early 2025.
Courts sentenced leaders of the Kokang 'four families' (Ming, Bai, Wei, Liu); 11 Ming and four Bai family members were executed in early 2026.
The China Securities Regulatory Commission pursues securities fraud, including the 2024 Evergrande penalties.
SOURCES
Ministry of Public Security via Xinhua / Global Times, 2025–2026
CNN, Sept 2025 and Jan 2026
South China Morning Post, Jan 2026
Metropolitan Police / CNN, Nov 2025
Bloomberg / NBC News, June 2026
US Department of Justice, Oct 2025
China Securities Regulatory Commission, March 2024
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇰🇵
NORTH KOREA
#7 WCI
CAPITAL Pyongyang · POPULATION 26.5M (2024, UN)
FRAUD TYPES
State crypto theft, exchange hacking, supply chain attacks, IT worker infiltration
KEY FACTS
$6.75B in crypto stolen all-time; a record $2.02B in 2025, 76% of all hacks of crypto services (Chainalysis). . Cybercrime is estimated to fund a large share of the state's budget.
BORN HERE
Nobody in our case files was born in North Korea yet.
GROUPS ESTABLISHED HERE
1 group in our case files was established in North Korea. Tap to open the report.
OPERATED HERE
Physically based or working in North Korea — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Pyongyang, North Korea
WHAT THEY DID HERE, AND WHEN
2014–presentReconnaissance General Bureau units run the operations; Sony (2014), Bangladesh Bank (2016), Ronin (2022), Bybit (2025).SOURCE: US Treasury designation, 13 Sept 2019; DOJ
OUR CASES BY CATEGORY
Share of the 1 case tied to North Korea (born or operated here)
CRYPTO
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Crypto exchange hacksFake IT worker schemesBank heists via SWIFTCrypto money laundering
THE PICTURE

North Korea runs the world's largest state-directed crypto theft programme, using hacking groups tracked as and TraderTraitor and IT workers placed in foreign companies under false identities. Chainalysis estimates North Korea-linked hackers stole $2.02 billion in 2025, bringing their all-time total to about $6.75 billion (Chainalysis, Dec 2025). The FBI attributed the $1.5 billion Bybit theft of February 2025, the largest crypto heist on record, to North Korea (FBI, 2025), and with Japan's police attributed the $308 million DMM Bitcoin theft of 2024 (FBI/NPA, Dec 2024). Because North Korean operators are out of reach, enforcement relies on US indictments, sanctions, rewards and seizure of laundered funds.

TOP FRAUDSTERS FROM HERE
Jon Chang Hyok FUGITIVEREPORT PENDING
$1.3bn+ (attempted theft and extortion, per DOJ) · 2014–2020
North Korean military intelligence hacker indicted in the US in a scheme to steal and extort more than $1.3 billion from banks and crypto firms.
SOURCE: US Department of Justice, Feb 2021
Kim Il FUGITIVEREPORT PENDING
$1.3bn+ (attempted theft and extortion, per DOJ) · 2014–2020
Co-defendant of Jon Chang Hyok in the same $1.3 billion bank and crypto hacking indictment.
SOURCE: US Department of Justice, Feb 2021
Park Jin Hyok FUGITIVEREPORT PENDING
$81M (stolen from Bangladesh Bank, 2016) · 2014–2018
programmer charged over the 2016 Bangladesh Bank heist, the 2014 Sony hack and WannaCry; also named in the 2021 indictment.
SOURCE: US Department of Justice, Sept 2018
Rim Jong Hyok FUGITIVEREPORT PENDING
Not quantified in charges (ransom payments) · 2021–2023
Charged over Maui ransomware attacks on US hospitals, with ransoms allegedly laundered to fund further hacks; subject of a US reward of up to $10M.
SOURCE: US Department of Justice, July 2024
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$2.02bn Crypto stolen by North Korea-linked hackers in 2025 (+51% y/y) (Chainalysis, Dec 2025)
$6.75bn Estimated all-time crypto stolen by North Korea-linked hackers (Chainalysis, Dec 2025)
$1.5bn Stolen from Bybit in Feb 2025, attributed to North Korea (FBI / Chainalysis, Feb 2025)
$308M Stolen from Japan's DMM Bitcoin in May 2024 by TraderTraitor (FBI, DC3 and Japan NPA, Dec 2024)
WHO FIGHTS IT
US Treasury OFAC sanctioned the and related units in September 2019.
US DOJ indictments in 2018, 2021 and 2024 name North Korean hackers; the 'DPRK RevGen' initiative targets IT worker schemes and laptop farms.
FBI, Japan's National Police Agency and South Korean agencies issue joint attributions for major thefts (e.g. DMM Bitcoin, Dec 2024).
UN sanctions monitoring has tracked crypto theft as a revenue source for weapons programmes.
SOURCES
Chainalysis, Dec 2025
FBI, Feb 2025 and Dec 2024
US Department of Justice, 2018, 2021, 2024
US Treasury OFAC, Sept 2019
The Hacker News / The Record, 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇯🇵
JAPAN
Low source / High target
CAPITAL Tokyo · POPULATION 124.0M (2024, UN)
FRAUD TYPES
Target of ransomware, card fraud victim
KEY FACTS
Frozen food chain ransomware attack 2025. High card fraud victim rate. Strong enforcement.
BORN HERE
Nobody in our case files was born in Japan yet.
OPERATED HERE
Physically based or working in Japan — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Tokyo, Japan
WHAT THEY DID HERE, AND WHEN
2017–2018Binance operates from Japan until the regulator warns it is unlicensed.SOURCE: case brief; FSA warning 2018
OUR CASES BY CATEGORY
Share of the 1 case tied to Japan (born or operated here)
CRYPTO
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Phone 'special fraud' against older peopleFake police impersonationSocial-media investment scamsRomance scamsCrypto exchange hacks
THE PICTURE

Japan's fraud problem is dominated by 'special fraud' (tokushu sagi) phone scams against older people and by social-media investment and romance scams. The National Police Agency reported record combined losses of ¥324.11 billion (about $2.1 billion) in 2025, up from ¥199.1 billion in 2024 (NPA via Japan Times, Feb 2026). Special fraud losses almost doubled to ¥142.3 billion, with fake-police impersonation accounting for about 70% of them (NPA, 2026). Many calls are run from overseas; police cite fluid, anonymous groups ('tokuryu') that recruit through social media, and some cells operate from Southeast Asia. Japan was also the target of North Korea's $308 million DMM Bitcoin hack in 2024 (FBI/NPA, 2024).

TOP FRAUDSTERS FROM HERE
Tsuyoshi Kikukawa CONVICTEDREPORT PENDING
$1.7bn (hidden losses) · 1990s–2011
Former Olympus chairman convicted over an accounting fraud that hid about $1.7 billion in investment losses; given a suspended three-year sentence.
SOURCE: The Accountant; Wikipedia, 2013
Mark Karpelès CONVICTEDREPORT PENDING
$33.5M (holdings falsely inflated) · 2013
CEO of the Mt. Gox crypto exchange, which collapsed in 2014; convicted in Tokyo only of falsifying data to inflate holdings and acquitted of embezzlement.
SOURCE: CoinDesk, March 2019
Kazutsugi Nami CONVICTEDREPORT PENDING
Not quantified in sources reviewed · 2001–2007
Ran the L&G pyramid scheme, which paid 'dividends' in its own quasi-currency ('Enten'); sentenced to 18 years.
SOURCE: Wikipedia summary, 2010
FRAUD BY CATEGORY
share of combined reported losses (special fraud plus social-media investment and romance fraud); computed from NPA figures · 2025
Social-media investment and romance fraud
56.3%
Fake police impersonation (special fraud)
30.9%
Other special fraud (phone scams, refund and billing fraud)
12.8%
SOURCE: National Police Agency figures reported by Nippon.com, 16 June 2026
KEY NUMBERS
¥324.11bn Combined special fraud and social-media scam losses in 2025 (record) (National Police Agency via Japan Times, Feb 2026)
¥142.3bn Special fraud losses in 2025, up 98% (National Police Agency via Nippon.com, 2026)
27,832 Special fraud cases in 2025, up 32.3% (National Police Agency via Nippon.com, 2026)
$308M Stolen from DMM Bitcoin in 2024 by North Korean hackers (FBI / Japan NPA, Dec 2024)
WHO FIGHTS IT
National Police Agency publishes annual special-fraud and social-media fraud statistics and began tracking fake-police fraud separately in 2025.
Police target 'tokuryu' (anonymous, fluid) crime groups; Luffy ring leaders deported from the Philippines in 2023 were tried in Tokyo (a senior member received life in Feb 2026 for a fatal robbery).
The Financial Services Agency regulates crypto exchanges following the Mt. Gox and Coincheck hacks.
SOURCES
National Police Agency via Japan Times, Feb 2026
Nippon.com, June 2026
SCMP, Feb 2025
FBI, Dec 2024
CoinDesk, March 2019
The Star, Feb 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇰🇷
SOUTH KOREA
WCI top 15
CAPITAL Seoul · POPULATION 51.7M (2024, UN)
FRAUD TYPES
Voice phishing, romance scams, crypto fraud
KEY FACTS
$1.3B in telecom fraud losses annually. Upbit exchange $36M theft (). Growing crypto scam market.
BORN HERE
2 people in our case files were born in South Korea. Tap to open the report.
OPERATED HERE
Physically based or working in South Korea — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Seoul, South Korea
WHAT THEY DID HERE, AND WHEN
2018–2022Terraform Labs' Korean base; UST and LUNA are built and promoted from here.SOURCE: US v. Kwon, 23 Cr. 151; case brief
May 2022UST breaks its peg for good and LUNA collapses; ~$40B of market value is wiped out.SOURCE: DOJ; BBC
OUR CASES BY CATEGORY
Share of the 2 cases tied to South Korea (born or operated here)
CRYPTO
50%
STOCK
50%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Voice phishingCrypto fraudFund and Ponzi schemesScam-centre recruitment of Koreans abroad
THE PICTURE

Voice phishing is South Korea's most persistent fraud threat, much of it run by call centres in China and Southeast Asia that impersonate prosecutors, banks and lenders. The National Police Agency reported voice-phishing losses of over 1.1 trillion won in the first 11 months of 2025, up more than 56% (Korea Times, Jan 2026), while the Financial Supervisory Service, which counts only formal refund claims, recorded 433.8 billion won in 2025 (Seoul Economic Daily, March 2026). Korea has also produced some of the largest investment frauds in Asia, from the Optimus and Lime fund scandals to the $40 billion collapse of Terraform's TerraUSD and Luna.

TOP FRAUDSTERS FROM HERE
Cho Hee-pal DIED BEFORE TRIALREPORT PENDING
4 trillion won (~$3.5bn; alleged investor losses) · 2004–2008
Ran a medical-equipment leasing pyramid scheme, then fled to China in 2008; police declared him dead in 2012, though doubts remain.
SOURCE: Korea Herald / Korea JoongAng Daily
Lee Jong-pil CONVICTEDREPORT PENDING
1.7 trillion won (funds involved in the Lime scandal) · 2017–2019
Former Lime Asset Management CIO at the centre of a 1.7 trillion won fund scandal; sentenced to 15 years.
SOURCE: The Investor / Korea Herald
Kim Jae-hyun CONVICTEDREPORT PENDING
1.3 trillion won (raised from investors) · 2018–2020
Optimus Asset Management CEO who raised money by claiming to invest in public-sector receivables and ran a Ponzi scheme; 40-year sentence upheld.
SOURCE: Korea Herald, July 2022
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
1.1 trillion won+ Voice-phishing losses, Jan–Nov 2025 (+56% y/y) (National Police Agency via Korea Times, Jan 2026)
433.8bn won Telecom financial fraud losses under formal refund claims, 2025 (Financial Supervisory Service via Seoul Economic Daily, March 2026)
20.2M won Average loss per voice-phishing case, 2024 (Financial Supervisory Service via Seoul Economic Daily, 2026)
WHO FIGHTS IT
National Police Agency and prosecutors run a joint voice-phishing investigation unit; the Telecommunications Financial Fraud Refund Act lets banks freeze and return funds.
Financial Supervisory Service compiles refund-based loss data; lawmakers debated no-fault bank liability for phishing losses in 2026.
Korea pursued fugitives abroad, including the extradition of from Montenegro to the US (2024–2025).
SOURCES
Korea Times, Jan 2026
Seoul Economic Daily, March 2026
US Department of Justice (SDNY), Dec 2025
Korea Herald, 2015 and 2022
The Investor
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇹🇼
TAIWAN
Low source
CAPITAL Taipei · POPULATION 23.4M (2024, Ministry of the Interior)
FRAUD TYPES
Telecom fraud (targeting China)
KEY FACTS
Cross-strait VoIP scam operations. Some operators relocated to SE Asia.
BORN HERE
1 person in our case files was born in Taiwan. Tap to open the report.
OPERATED HERE
Nobody in our case files is documented as operating from Taiwan yet.
OUR CASES BY CATEGORY
Share of the 1 case tied to Taiwan (born or operated here)
DARK WEB
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Investment scams via social media and LINEPhone scamsOnline shopping fraudMoney-mule and laundering networks
THE PICTURE

Taiwan faces heavy losses to investment scams promoted through social-media ads and LINE groups, alongside phone and shopping fraud, while Taiwanese nationals have also been recruited into or run scam operations abroad. The National Police Agency's 165 Anti-Fraud Dashboard recorded NT$12.6 billion in losses in November 2024 alone (Taipei Times, Dec 2024); by November 2025 monthly losses had fallen to NT$5.99 billion, 57% below August 2024 (NPA via TWSE, 2025). Investment fraud accounts for the largest share of losses (TWSE citing NPA, 2025). In July 2024 Taiwan passed the Fraud Crime Hazard Prevention Act, requiring platforms, banks and telecoms to help block scams.

TOP FRAUDSTERS FROM HERE
Wang You-theng DIED BEFORE TRIALREPORT PENDING
NT$60bn (~$1.8bn; alleged embezzlement) · 2006
Chairman of China Rebar Group, who fled Taiwan days before prosecutors investigated alleged embezzlement; declared a wanted fugitive and died in the US in 2016.
SOURCE: Wikipedia summary of Taipei prosecutors' actions
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
NT$12.6bn Fraud losses in November 2024 (one month) (National Police Agency 165 Dashboard via Taipei Times, Dec 2024)
NT$5.99bn Fraud losses in November 2025, down 57% from August 2024 (National Police Agency via TWSE, 2025)
1,698 People arrested in fraud cases in November 2024 (National Police Agency via Taipei Times, Dec 2024)
WHO FIGHTS IT
Fraud Crime Hazard Prevention Act (2024) places anti-fraud duties on banks, telecoms and online platforms.
National Police Agency's Criminal Investigation Bureau runs the 165 anti-fraud hotline (since 2004) and the 165 Dashboard (since August 2024).
Joint Taiwan–US investigations have dismantled scam call centres and crypto laundering operations (CIB press releases).
SOURCES
Taipei Times, Dec 2024
Taiwan Stock Exchange (TWSE) Market Insights, 2025
Criminal Investigation Bureau news releases
Wikipedia, Wang You-theng
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇵🇭
PHILIPPINES
GI-TOC flagged
CAPITAL Manila · POPULATION 115.8M (2024, UN)
FRAUD TYPES
Scam compounds, POGOs, online gambling fraud
KEY FACTS
Former Bamban mayor Alice Guo sentenced to life on 20 Nov 2025 for qualified human trafficking tied to a scam hub (claims she was a Chinese spy were never proven). POGOs (Philippine Offshore Gaming Operators) banned by the president in 2024.
BORN HERE
Nobody in our case files was born in Philippines yet.
OPERATED HERE
Nobody in our case files is documented as operating from Philippines yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
POGO-linked scam hubsHuman trafficking into scam workOnline shopping fraudE-wallet and SMS scamsPublic-fund fraud
THE PICTURE

The Philippines has been both a base for scam hubs and a target of online fraud. Offshore gaming operators (POGOs) became linked to scam compounds and human trafficking, leading President Marcos to ban all POGOs in July 2024; PAGCOR said all 42 licences had been cancelled and 304 sites closed by 31 December 2024 (PAGCOR / PNA, 2025). Former Bamban mayor Alice Guo, linked to a raided scam hub, was convicted of qualified trafficking and sentenced to life in November 2025 (GMA News, 2025). Domestically, the Cybercrime Investigation and Coordinating Center received 10,004 online scam complaints in 2024, triple the previous year, with losses of nearly ₱198 million (CICC, 2025).

TOP FRAUDSTERS FROM HERE
Janet Lim-Napoles CONVICTEDREPORT PENDING
₱10bn (~$200M; public funds diverted) · 2000s–2013
Ran the 'pork barrel' scheme that diverted lawmakers' development funds through fake NGOs; convicted of plunder and multiple graft and malversation counts.
SOURCE: Sandiganbayan rulings, 2018–2024
Alice Guo (Guo Hua Ping) CONVICTEDREPORT PENDING
Not quantified in the trafficking verdict · 2023–2024
Former Bamban mayor convicted of qualified trafficking linked to a POGO hub that ran scams; also faces money-laundering charges.
SOURCE: GMA News, Nov 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
10,004 Online scam complaints to CICC in 2024 (3x 2023) (CICC via Philippine News Agency, Jan 2025)
₱198M Reported cybercrime victim losses in 2024 (CICC via Manila Bulletin, Jan 2025)
35% Share of 2024 CICC complaints that were consumer fraud (CICC via Inquirer, 2025)
304 POGO operating sites closed by end-2024 (PAGCOR / Philippine News Agency, 2025)
WHO FIGHTS IT
Executive Order 74 (Nov 2024) formalised the POGO ban announced in July 2024.
Anti-Financial Account Scamming Act (2024) criminalises money muling and account takeovers; SIM Registration Act (2022) targets text scams.
CICC, the PNP Anti-Cybercrime Group, NBI and PAOCC lead enforcement; raids on POGO hubs in Bamban and Porac (2024) rescued hundreds of workers.
SOURCES
Philippine News Agency, Jan 2025
Manila Bulletin, Jan 2025
Inquirer, 2025
PAGCOR, 2025
GMA News, Nov 2025
Wikipedia, Janet Lim-Napoles (Sandiganbayan rulings)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇦🇺
AUSTRALIA
Low source / High target
CAPITAL Canberra · POPULATION 27.2M (2024, ABS)
FRAUD TYPES
Card fraud victim, romance scam victim, investment fraud
KEY FACTS
A$2.03B in scam losses reported in 2024, down 26% on 2023 (NASC). High per-capita fraud victimisation.
BORN HERE
Nobody in our case files was born in Australia yet.
OPERATED HERE
Nobody in our case files is documented as operating from Australia yet.
KNOWN FOR
Investment scamsPayment redirection (business email compromise)Romance scamsPhishing and remote-access scamsTax fraud
THE PICTURE

Australia publishes some of the world's most complete scam data through the National Anti-Scam Centre (NASC), which combines reports to Scamwatch, ReportCyber, banks (via AFCX), IDCARE and ASIC. Australians reported losing A$2.18 billion to scams in 2025, up 7.8% on 2024, across 481,523 reports (NASC, March 2026). Investment scams remain the costliest category at A$837.7 million, followed by payment redirection and romance scams (NASC, 2026). Much of the activity comes from offshore groups, including Southeast Asian scam compounds; the AFP has worked with foreign police to warn Australian targets. Major domestic fraud cases include the HIH Insurance collapse and the Plutus Payroll tax fraud.

TOP FRAUDSTERS FROM HERE
Ray Williams PLEADED GUILTYREPORT PENDING
A$5.3bn (estimated HIH losses) · 1998–2001
HIH Insurance co-founder who pleaded guilty to misleading shareholders before Australia's largest corporate collapse; jailed for 4 years 6 months.
SOURCE: Wikipedia summary of NSW court records, 2005
Rodney Adler PLEADED GUILTYREPORT PENDING
A$5.3bn (estimated HIH losses, whole collapse) · 2000–2001
HIH director who pleaded guilty to four charges including spreading false information; jailed for 4.5 years.
SOURCE: Wikipedia summary of NSW court records, 2005
Adam Cranston CONVICTEDREPORT PENDING
A$105M (estimated tax defrauded) · 2014–2017
Found guilty of conspiring to defraud the Commonwealth through the Plutus Payroll scheme, which withheld tax from payroll companies.
SOURCE: NSW Supreme Court verdict, March 2023 (Wikipedia summary)
Melissa Caddick DIED BEFORE TRIALREPORT PENDING
A$30M (misappropriated from investors) · 2012–2020
Sydney financial adviser who misappropriated investors' money; disappeared the day after an ASIC raid in 2020 and was later declared dead.
SOURCE: NSW Coroner, 2023; ASIC
FRAUD BY CATEGORY
share of combined reported scam losses (computed from NASC Table 3 amounts; total A$2,184.0m) · 2025
All other scams
39.9%
Investment scams
38.4%
Payment redirection
7.6%
Romance scams
6.4%
Phishing
4.5%
Remote access scams
3.2%
SOURCE: National Anti-Scam Centre, Targeting Scams report 2025, March 2026
KEY NUMBERS
A$2.18bn Combined reported scam losses in 2025 (+7.8%) (NASC Targeting Scams report, March 2026)
481,523 Scam reports across all agencies in 2025 (NASC Targeting Scams report, March 2026)
A$837.7M Investment scam losses in 2025, the largest category (NASC Targeting Scams report, March 2026)
A$3.1bn Peak combined losses, recorded in 2022 (NASC Targeting Scams report, March 2026)
WHO FIGHTS IT
National Anti-Scam Centre (ACCC, launched July 2023) coordinates fusion cells on investment, job and romance scams.
Scams Prevention Framework Act 2025 imposes anti-scam obligations on banks, telcos and digital platforms.
ASIC takes down an average of about 230 investment-scam and phishing websites a week (NASC, 2026).
AFP, state police and the ATO pursue fraud prosecutions; ASIC brings civil and criminal cases against financial misconduct.
SOURCES
National Anti-Scam Centre, Targeting Scams report 2025, March 2026
National Anti-Scam Centre, Targeting Scams report 2024, March 2025
Wikipedia summaries: HIH Insurance, Plutus Payroll, Melissa Caddick
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇳🇿
NEW ZEALAND
Low source / High target
CAPITAL Wellington · POPULATION 5.3M (2024, Stats NZ)
FRAUD TYPES
Investment scam victim, romance scam victim
KEY FACTS
Small market, high digital adoption, growing fraud losses.
BORN HERE
Nobody in our case files was born in New Zealand yet.
OPERATED HERE
Nobody in our case files is documented as operating from New Zealand yet.
KNOWN FOR
Investment scamsRomance scamsBank impersonation and phishingFinance-company and Ponzi collapses
THE PICTURE

New Zealanders are mainly targeted by offshore scammers through investment, romance and bank-impersonation scams. Scams and fraud became the most commonly reported incident category to the National Cyber Security Centre in late 2024, and reported direct financial losses to NCSC reached NZ$25.7 million for 2024 (NCSC, 2025). The country's largest home-grown frauds came from the finance-company and investment collapses after 2007, including Bridgecorp and Ross Asset Management, whose leaders were jailed. The Serious Fraud Office, Financial Markets Authority, Police and NCSC share enforcement.

TOP FRAUDSTERS FROM HERE
Rod Petricevic CONVICTEDREPORT PENDING
NZ$467M (owed to about 14,500 investors) · 2006–2007
Bridgecorp managing director found guilty of making untrue statements in investment prospectuses; jailed for six and a half years.
SOURCE: Wikipedia summary of High Court ruling, April 2012
David Ross PLEADED GUILTYREPORT PENDING
NZ$450M (fictitious portfolio values reported to investors) · 1990s–2012
Ran Ross Asset Management as a Ponzi scheme, reporting fictitious investment holdings to clients; sentenced to 10 years 10 months.
SOURCE: Serious Fraud Office / FMA, Nov 2013
Joanne Harrison PLEADED GUILTYREPORT PENDING
NZ$726,000 (stolen from the ministry) · 2012–2016
Ministry of Transport manager who made false invoices to divert public money to herself; sentenced to 3 years 7 months.
SOURCE: Serious Fraud Office, Feb 2017
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
NZ$25.7M Direct financial loss reported to NCSC in 2024 (National Cyber Security Centre, Q4 2024 Cyber Security Insights)
NZ$6.8M Direct financial loss reported to NCSC in Q4 2024 (+24% q/q) (National Cyber Security Centre, 2025)
506 Scams and fraud incidents reported to NCSC in Q4 2024, the top category (National Cyber Security Centre, 2025)
WHO FIGHTS IT
Serious Fraud Office prosecutes large and complex fraud; the Financial Markets Authority handles investment misconduct.
National Cyber Security Centre (merged with CERT NZ in 2024) collects scam and cyber incident reports.
NZ Police and banks run anti-scam measures, including bank-led scam-prevention initiatives.
SOURCES
National Cyber Security Centre, Cyber Security Insights Q3–Q4 2024
interest.co.nz, 2025
Wikipedia, Bridgecorp
Serious Fraud Office
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇲🇲
MYANMAR
#1 GI-TOC (8.08)
CAPITAL Naypyidaw · POPULATION 54.1M (2023, UN WPP 2024)
FRAUD TYPES
Pig butchering compounds, forced labor, crypto scams
KEY FACTS
120,000+ forced scam workers. Armed militia-protected compounds. $43.8B combined annual revenue w/ Cambodia + Laos.
BORN HERE
Nobody in our case files was born in Myanmar yet.
OPERATED HERE
Nobody in our case files is documented as operating from Myanmar yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Scam compoundsPig-butchering crypto investment fraudHuman trafficking into forced scam labourMilitia-protected crime zonesOnline gambling fraud
THE PICTURE

Myanmar's lawless border zones, especially Myawaddy (Shwe Kokko, KK Park) in Karen State and the Kokang region of northern Shan State, host industrial scam compounds run largely by Chinese-led syndicates under the protection of local militias; the UN human rights office estimated in August 2023 that at least 120,000 people were being held there and forced to run online scams (OHCHR, 2023). The militias include the Karen National Army of Saw Chit Thu, which the US Treasury sanctioned in May 2025 for facilitating cyber scams (US Treasury, 2025). China has led enforcement: 16 members of the Kokang Ming family were sentenced to death in September 2025 and 11 were executed in January 2026, and Bai-family leaders were sentenced to death in November 2025 (CNN, 2025-2026). The junta raided KK Park in October 2025 and said it had demolished scam buildings, but reporting showed new construction nearby, suggesting the networks moved rather than shut down (AP, Dec 2025; Center for Information Resilience, 2025).

TOP FRAUDSTERS FROM HERE
Ming Guoping CONVICTEDREPORT PENDING
Not published in a single figure (CNN describes a 'billion-dollar' criminal empire; court cited 14 deaths of Chinese nationals) · 2015–2023
Kokang militia leader and senior member of the Ming family syndicate that ran scam compounds in Laukkaing; executed in China with 10 other family members.
SOURCE: CNN, 29 Jan 2026
Bai Suocheng CONVICTEDREPORT PENDING
Not published in a single figure · 2025
Former chairman of the Kokang Self-Administered Zone whose family ran scam and gambling operations; sentenced to death by a Shenzhen court.
SOURCE: The Record / Irrawaddy, Nov 2025
She Zhijiang CHARGED (NOT TRIED)REPORT PENDING
2.7bn yuan (~$380M; illicit funds alleged by Chinese authorities) · 2014–2022
Developer of the Shwe Kokko zone in Myawaddy, accused by China of running more than 200 online gambling platforms linked to trafficking and scams.
SOURCE: ABC News (Australia), 12 Nov 2025
Wei Huairen CHARGED (NOT TRIED)REPORT PENDING
Not published · 2025
Co-leader with his brother Wei Chaoren of the Wei family, one of the Kokang 'four families' prosecuted in China over scam compounds.
SOURCE: Shan Herald Agency for News / CNN, Oct 2025–Jan 2026
Saw Chit Thu SANCTIONEDREPORT PENDING
n/a (sanctions designation) · 2023–2025
Leader of the Karen National Army (ex-Border Guard Force), accused of providing security and land to scam compounds in Shwe Kokko.
SOURCE: US Treasury OFAC, 5 May 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
120,000+ People estimated to be held and forced into online scam work in Myanmar (UN OHCHR, Aug 2023)
2,500+ Starlink terminals near suspected Myanmar scam centres cut off by SpaceX (SpaceX via press reports, Oct 2025)
16 Ming family syndicate members sentenced to death by a Wenzhou court (11 executed Jan 2026) (CNN, Sep 2025 and Jan 2026)
$3.5bn US losses in 2023 to cyber scams from Myanmar and elsewhere in Southeast Asia (US Treasury, May 2025)
WHO FIGHTS IT
China's Ministry of Public Security and courts have prosecuted Kokang crime families: Wenzhou court sentenced 16 Ming family members to death (Sep 2025), 11 executed (29 Jan 2026); Shenzhen court sentenced Bai Suocheng and four others to death (Nov 2025).
Thailand cut electricity to five Myanmar border areas hosting scam hubs, including Myawaddy and Tachileik (5 Feb 2025).
Myanmar junta raided KK Park (Oct 2025) and claimed demolition of scam buildings; analysts reported relocation rather than dismantling.
US Treasury sanctioned the Karen National Army and Saw Chit Thu as a transnational criminal organisation (May 2025); the UK sanctioned him in Dec 2023.
SOURCES
UN OHCHR report on online scam trafficking, Aug 2023
US Treasury press release, 5 May 2025
CNN, 30 Sep 2025, 4 Jan 2026 and 29 Jan 2026
The Record (Recorded Future News), Nov 2025
ABC News (Australia), 12 Nov 2025
Japan Times / AP, Nov-Dec 2025
RFA and The Diplomat, Feb 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇰🇭
CAMBODIA
GI-TOC flagged
CAPITAL Phnom Penh · POPULATION 17.4M (2023, UN WPP 2024)
FRAUD TYPES
Pig butchering compounds, forced labor, online gambling
KEY FACTS
100,000+ people held in scam compounds (UN, 2023). Senator Kok An sanctioned by the US Treasury on 23 Apr 2026. Sihanoukville is the compound epicentre.
BORN HERE
Nobody in our case files was born in Cambodia yet.
OPERATED HERE
Physically based or working in Cambodia — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Cambodia
WHAT THEY DID HERE, AND WHEN
2021–2024Lives in Cambodia and launders proceeds of the 'pig-butchering' scam centres there through shell companies and US bank accounts; ~$73M.SOURCE: DOJ C.D. Cal. plea
OUR CASES BY CATEGORY
Share of the 1 case tied to Cambodia (born or operated here)
LAUNDERING
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Pig-butchering crypto investment scamsScam compounds and forced labourCasino-linked money launderingRomance scamsCrypto laundering marketplaces
THE PICTURE

Cambodia became one of the world's largest bases for industrial-scale 'pig-butchering' investment and romance scams, run from casinos and compounds in Sihanoukville, Poipet, Bavet and O'Smach and staffed partly by trafficked workers; the UN estimated in 2023 that at least 100,000 people were held in Cambodian scam operations (OHCHR, 2023). In October 2025 US prosecutors indicted Prince Group founder Chen Zhi on wire-fraud and money-laundering conspiracy charges and sought forfeiture of 127,271 bitcoin (~$15bn), while Treasury sanctioned 146 related targets; Cambodia arrested Chen and sent him to China in January 2026 (US DOJ, 2025; CNN, 2026). The US Treasury has also sanctioned tycoon Ly Yong Phat (2024) and Senator Kok An (April 2026), saying Americans lost at least $10bn in 2024 to Southeast Asia-based scam operations (US Treasury, 2026). Cambodia launched a crackdown in July 2025, reporting nearly 30,000 suspects detained by August 2026, and passed its first dedicated anti-scam-centre law in April 2026, though job adverts suggest the industry persists (AP, 2026; Al Jazeera, 2026; ABC Australia, Sep 2026).

TOP FRAUDSTERS FROM HERE
Chen Zhi CHARGED (NOT TRIED)REPORT PENDING
$15bn (127,271 bitcoin sought in US civil forfeiture) · 2015–2025
Founder of Cambodia's Prince Group, accused by US prosecutors of directing forced-labour scam compounds and laundering the proceeds; he denies wrongdoing.
SOURCE: US DOJ / Wikipedia summary; CNN, 7 Jan 2026
Kok An SANCTIONEDREPORT PENDING
n/a (sanctions designation) · 2026
Cambodian senator sanctioned by the US for scam centres operating from his casinos and properties in Poipet, Sihanoukville and Bavet.
SOURCE: US Treasury, 23 Apr 2026
Ly Yong Phat SANCTIONEDREPORT PENDING
n/a (sanctions designation) · 2024
Tycoon whose O'Smach Resort was sanctioned by the US over trafficked workers forced to run online scams.
SOURCE: US Treasury, Sep 2024
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$15bn Bitcoin (127,271 BTC) the US sought to forfeit from the Prince Group case, the largest forfeiture action in US history (US DOJ via TRM Labs / ICIJ, Oct 2025)
~30,000 Suspects of 39 nationalities detained in Cambodia's scam crackdown, Jul 2025 to Aug 2026 (Cambodian authorities via AP, Sep 2026)
$300M+ Bank funds frozen; 446 cases (3,927 suspects) sent to court (Agence Kampuchea Presse (AKP), 2026)
$10bn US losses in 2024 to Southeast Asia-based scam operations (US Treasury, 23 Apr 2026)
WHO FIGHTS IT
US: EDNY indictment of Chen Zhi and record bitcoin forfeiture action; Treasury sanctions on 146 Prince Group targets (Oct 2025); sanctions on Ly Yong Phat (Sep 2024) and Kok An network (Apr 2026). UK froze ~$134M in Prince Group-linked London property (Oct 2025).
Cambodia arrested Chen Zhi, revoked his citizenship and sent him to China (6 Jan 2026).
Nationwide raids from July 2025, including 1,000+ arrests in one July 2025 sweep (Al Jazeera, 16 Jul 2025).
Parliament approved a law on cyber-scam centres with up to 20 years' prison and $500,000 fines for ringleaders (Apr 2026).
SOURCES
US Treasury press releases, Sep 2024, Oct 2025 and 23 Apr 2026
CNN, 7 Jan 2026
ICIJ and TRM Labs on Prince Group forfeiture, 2025
Al Jazeera, 16 Jul 2025 and 3 Apr 2026
AP via ABC News, 2026; ABC Australia, 25 Sep 2026
AKP (Cambodian state news), 2026
UN OHCHR, Aug 2023
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇱🇦
LAOS
GI-TOC flagged
CAPITAL Vientiane · POPULATION 7.7M (2023, UN WPP 2024)
FRAUD TYPES
Compounds, forced labor, gambling, money laundering
KEY FACTS
Golden Triangle SEZ controlled by sanctioned Zhao Wei. Expanding operations. 74% of compounds in Mekong region.
BORN HERE
Nobody in our case files was born in Laos yet.
OPERATED HERE
Nobody in our case files is documented as operating from Laos yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Scam centres in the Golden Triangle SEZCrypto investment and romance scamsHuman trafficking into scam workCasino-linked money laundering
THE PICTURE

Laos' main fraud exposure is the Golden Triangle Special Economic Zone (GTSEZ) in Bokeo province, a casino enclave on a 99-year lease to Chinese businessman Zhao Wei, which hosts online scam centres staffed partly by trafficked workers (Crisis Group; Bloomberg, 2024). The US sanctioned Zhao Wei's network as a transnational criminal organisation in 2018 and the UK sanctioned him in 2023 over trafficking people into scam work (US Treasury, 2018; UK government, 2023). After a government ultimatum, Lao and Chinese police raided the zone in August 2024 and detained 771 people, but the Kings Romans casino kept operating and Zhao received a Lao state medal in December 2024 (RFA, 2024; The Diplomat, Dec 2024).

TOP FRAUDSTERS FROM HERE
Zhao Wei SANCTIONEDREPORT PENDING
n/a (sanctions designation) · 2018–2023
Chairman of Kings Romans and the Golden Triangle SEZ, sanctioned by the US and UK over drug trafficking, money laundering and trafficking people into scam work; he has not been charged in Laos.
SOURCE: US Treasury (Jan 2018); UK sanctions list (Dec 2023)
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
771 People detained in Lao raids on GTSEZ scam centres, August 2024 (Lao Ministry of Public Security via RFA, Aug 2024)
99 years Length of the GTSEZ land lease granted to Zhao Wei's company in 2007 (Wikipedia / Crisis Group)
WHO FIGHTS IT
Lao government ordered all GTSEZ scam centres shut by 25 Aug 2024; joint Lao-Chinese raids on 9 and 12 Aug 2024.
US OFAC designated the Zhao Wei Transnational Criminal Organisation (2018); UK sanctioned Zhao Wei and Su Guiqin (2023).
Laos was placed on the FATF grey list (increased monitoring) in February 2025.
SOURCES
Radio Free Asia, Aug 2024 and Dec 2024
The Diplomat, Aug 2024 and Dec 2024
International Crisis Group, GTSEZ report
Bloomberg, 2024
Wikipedia, 'Zhao Wei (businessman)', accessed Sep 2026
FATF plenary outcomes, Feb 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇹🇭
THAILAND
Transit hub
CAPITAL Bangkok · POPULATION 71.7M (2023, UN WPP 2024)
FRAUD TYPES
Transit for trafficking to compounds, money muling, call center scams
KEY FACTS
Cut power, fuel and internet to Myanmar border scam areas on 5 Feb 2025. The abduction of Chinese actor Wang Xing (rescued 7 Jan 2025) triggered the crackdown.
BORN HERE
Nobody in our case files was born in Thailand yet.
OPERATED HERE
Nobody in our case files is documented as operating from Thailand yet.
KNOWN FOR
Call-centre impersonation scamsInvestment and Ponzi schemesMule accounts for cross-border scam networksTransit hub for trafficking to scam compoundsCorporate accounting fraud
THE PICTURE

Thailand is both a major target of call-centre and investment scams, many run from compounds just across its borders in Myanmar and Cambodia, and a transit hub for trafficked scam workers (Kyoto Review, Mar 2026). Domestically, large investment frauds include the Forex-3D Ponzi scheme (about 2.5bn baht from ~9,800 investors) and the Stark Corporation accounting fraud (14.8bn baht, 4,704 victims) (Thai PBS, Dec 2024; Khaosod, Jun 2024). Thailand cut power to five Myanmar border scam zones in February 2025 and enacted an emergency decree in April 2025 making banks and telecom firms share liability for scam losses (CNN, Feb 2025; AGB, Apr 2025). The government said in June 2026 that a nine-month crackdown had arrested more than 29,000 suspects and seized or frozen over 24bn baht (Nation Thailand, Jun 2026).

TOP FRAUDSTERS FROM HERE
Chanin Yensudchai CHARGED (NOT TRIED)REPORT PENDING
14.8bn baht (~$402M; damages to 4,704 victims) · 2022–2023
Former Stark Corporation chairman accused of falsifying accounts and siphoning shareholders' money; extradited from the UAE in 2024.
SOURCE: Khaosod English, 23 Jun 2024
Teepatsakorn Kimwangtako CONVICTEDREPORT PENDING
2.5bn baht (investor losses, ~9,800 victims) · 2015–2020
One of three Forex-3D defendants convicted for a fake forex-trading Ponzi scheme promising 60-80% returns; each got 20 years served.
SOURCE: Thai PBS World, 26 Dec 2024
Warathaphon Waratyaworrakul CHARGED (NOT TRIED)REPORT PENDING
841M baht (losses claimed in 2,000+ complaints) · 2024
CEO of The iCon Group, a direct-sales company accused of defrauding thousands of investors; a separate money-laundering charge was dismissed.
SOURCE: Bangkok Post, Oct 2024
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
29,000+ Suspects linked to scam networks arrested in a nine-month crackdown (PM Anutin Charnvirakul via Nation Thailand, 22 Jun 2026)
฿24bn+ Money and assets seized or frozen in the same crackdown (Nation Thailand, 22 Jun 2026)
122,840 Fraudulent websites shut down (Nation Thailand, 22 Jun 2026)
WHO FIGHTS IT
Emergency Decree on Measures for the Prevention and Suppression of Technology Crimes (amended) took effect 13 Apr 2025, adding shared liability for banks, telecoms and platforms.
Thailand cut power, fuel and internet supplies to Myanmar border scam hubs (Feb 2025).
Department of Special Investigation (DSI) and the Cyber Crime Investigation Bureau lead major fraud cases (e.g. Stark, Special Case 57/2566).
Forex-3D verdict: Bangkok Criminal Court convicted three and acquitted three celebrities (26 Dec 2024).
SOURCES
Thai PBS World and Nation Thailand, 26 Dec 2024
Khaosod English, 23 Jun 2024
Bangkok Post, Oct 2024
CNN, 5 Feb 2025
AGB / Pattaya News, Apr 2025
Nation Thailand, 22 Jun 2026
Kyoto Review of Southeast Asia, Mar 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇻🇳
VIETNAM
#16 Sumsub
CAPITAL Hanoi · POPULATION 100.4M (2023, UN WPP 2024)
FRAUD TYPES
Call center scams, pig butchering participation, card fraud
KEY FACTS
Growing source of cybercrime. Vietnamese workers found in Myanmar compounds. Online fraud rising with digital adoption.
BORN HERE
Nobody in our case files was born in Vietnam yet.
OPERATED HERE
Nobody in our case files is documented as operating from Vietnam yet.
KNOWN FOR
Bank and corporate embezzlementBond and stock-market fraudFake forex and crypto trading platformsImpersonation phone scams
THE PICTURE

Vietnam's biggest frauds have been corporate and banking scandals: property tycoon Truong My Lan was convicted in 2024 over the looting of Saigon Commercial Bank, and bond and stock-market frauds brought down the chairmen of Tan Hoang Minh and FLC (AP, 2024; VnExpress, 2024). Online fraud has grown fast, with estimated losses of VND18.9 trillion (~$744M) in 2024 (Viet Nam News, 2025), and police in 2025 broke up the 'Mr Pips' fake forex-trading network, which recruited staff in Cambodia (VietNamNet; Tuoi Tre, 2025). Vietnamese nationals also appear among workers trafficked to Cambodian and Myanmar scam compounds. Enforcement is led by the Ministry of Public Security; Vietnam abolished the death penalty for embezzlement in 2025, commuting Lan's sentence to life (CNN, Jun 2025).

TOP FRAUDSTERS FROM HERE
Truong My Lan CONVICTEDREPORT PENDING
$27bn (total damages cited by court; about $12.5bn embezzled) · 2012–2022
Van Thinh Phat chairwoman convicted of secretly controlling Saigon Commercial Bank and embezzling from it through sham loans; death sentence commuted to life in 2025.
SOURCE: AP / CNN, Apr 2024 and Jun 2025
Do Anh Dung CONVICTEDREPORT PENDING
$349M (appropriated from bond investors) · 2021–2022
Tan Hoang Minh chairman convicted of fraud over bond issues that took money from 6,630 investors; jailed for 8 years.
SOURCE: VnExpress International, 2024
Trinh Van Quyet CONVICTEDREPORT PENDING
$146M (fraud found by court) · 2017–2022
FLC Group founder convicted of fraud and stock manipulation; 21-year sentence cut to 7 years on appeal after he repaid victims.
SOURCE: VOA, Aug 2024; VietnamPlus, 2025
Pho Duc Nam CHARGED (NOT TRIED)REPORT PENDING
VND1.57 trillion (~$60M; defrauded, per police) · 2020–2025
TikToker 'Mr Pips', accused of running a fake forex-trading platform via sham offices and staff in Cambodia.
SOURCE: VietNamNet / VietnamPlus, 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$744.5M Estimated losses to online fraud in Vietnam in 2024 (VND18.9 trillion) (Viet Nam News, 2025)
~$210M Assets seized in the Mr Pips fake forex case (VietNamNet, 2025)
WHO FIGHTS IT
Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention) leads fraud and cybercrime investigations.
National Assembly removed the death penalty for embezzlement and seven other crimes from 1 Jul 2025.
Vietnam has been on the FATF grey list since June 2023.
SOURCES
AP / CBS / CNN coverage of Van Thinh Phat case, 2024-2025
VnExpress International, 2024
VOA, Aug 2024; VietnamPlus, 2025
Viet Nam News, 'Online frauds caused $744 million in damages in 2024', 2025
VietNamNet and VietnamPlus on Mr Pips case, 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇮🇩
INDONESIA
#2 Sumsub
CAPITAL Jakarta · POPULATION 281.2M (2023, UN WPP 2024)
FRAUD TYPES
Identity fraud, SIM swap, mobile banking fraud, investment scams
KEY FACTS
#2 fraud vulnerability globally (Sumsub). Massive mobile-first population. SIM swap fraud epidemic.
BORN HERE
Nobody in our case files was born in Indonesia yet.
OPERATED HERE
Physically based or working in Indonesia — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Jakarta, Indonesia
WHAT THEY DID HERE, AND WHEN
1990–1992Sent by Barings to sort out its Jakarta back office before the Singapore posting.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 1 case tied to Indonesia (born or operated here)
STOCK
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Illegal online lending (pinjol)Binary-option and fake investment appsOnline shopping fraudCooperative and insurance fraudImpersonation phone scams
THE PICTURE

Indonesia's largest fraud cases involve state insurers and cooperatives: the Jiwasraya case, in which businessmen Benny Tjokrosaputro and Heru Hidayat got life sentences for manipulating investments that cost the state Rp16.81 trillion, and the KSP Indosurya cooperative collapse (Jakarta Globe, 2020-2021; Kompas, 2023). Retail investors have also been hit by illegal binary-option platforms promoted by influencers such as Indra Kenz (Binomo) and Doni Salmanan (Quotex), both jailed (Media Indonesia; detik, 2022-2023). Scam reports have surged: the OJK-led Indonesia Anti-Scam Centre received 432,637 complaints with Rp9.1 trillion in reported losses between November 2024 and January 2026, led by online shopping fraud and impersonation calls (Infobanknews, 2026). The Satgas PASTI task force has shut thousands of illegal online lenders and investment offers.

TOP FRAUDSTERS FROM HERE
Benny Tjokrosaputro CONVICTEDREPORT PENDING
Rp16.81 trillion (~$1.1bn; state losses in Jiwasraya case) · 2008–2018
Stock manipulator who steered state insurer Jiwasraya into inflated shares and mutual funds; sentenced to life, upheld by the Supreme Court.
SOURCE: Jakarta Globe, Oct 2020 and 2021
Heru Hidayat CONVICTEDREPORT PENDING
Rp16.81 trillion (state losses, joint case) · 2008–2018
Trada Alam Minera commissioner and Benny Tjokrosaputro's partner in the Jiwasraya fraud; sentenced to life.
SOURCE: Jakarta Post, 27 Oct 2020
Henry Surya CONVICTEDREPORT PENDING
Rp16 trillion (customer losses cited by prosecutors) · 2012–2020
Head of the KSP Indosurya savings cooperative; acquitted at trial but sentenced to 18 years by the Supreme Court for fraud and embezzlement of members' funds.
SOURCE: Kompas / Tempo, 17 May 2023
Indra Kenz CONVICTEDREPORT PENDING
Rp5bn (fine) · 2020–2022
Influencer who promoted the Binomo binary-option platform to followers; 10-year sentence upheld by the Supreme Court.
SOURCE: Supreme Court decision 2029 K/Pid.Sus/2023
Doni Salmanan CONVICTEDREPORT PENDING
Not published in a single figure (assets seized by the state) · 2020–2022
Influencer who promoted the Quotex binary-option platform; sentence raised to 8 years on appeal, paroled April 2026.
SOURCE: detik, Dec 2022; Hukumindo, Apr 2026
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
432,637 Scam complaints to the Indonesia Anti-Scam Centre, 22 Nov 2024 to 14 Jan 2026 (OJK IASC via Infobanknews, Jan 2026)
Rp9.1 trillion Reported losses in those complaints (~$550M) (OJK IASC via Infobanknews, Jan 2026)
2,263 Illegal online-lending entities stopped by Satgas PASTI (OJK via Infobanknews, 2026)
WHO FIGHTS IT
Financial Services Authority (OJK) launched the Indonesia Anti-Scam Centre (IASC) on 22 Nov 2024 to freeze scam proceeds across banks.
Satgas PASTI (task force on illegal financial activities) shuts illegal lenders and investment offers; Komdigi blocks accounts and sites.
Attorney General's Office prosecuted Jiwasraya and Asabri state-insurer fraud cases; Supreme Court upheld life sentences.
SOURCES
Jakarta Globe and Jakarta Post, Oct 2020-2021
Kompas / Tempo, 17 May 2023
detik and Media Indonesia, Dec 2022
Hukumindo, Apr 2026
Infobanknews, Jan 2026; investortrust.id IASC updates, 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇲🇾
MALAYSIA
#27 Sumsub
CAPITAL Kuala Lumpur · POPULATION 35.1M (2023, UN WPP 2024)
FRAUD TYPES
Call center scams, investment fraud, money muling
KEY FACTS
Transit point for scam compound trafficking. Macau scam syndicates active. Growing crypto fraud.
BORN HERE
1 person in our case files was born in Malaysia. Tap to open the report.
OPERATED HERE
Physically based or working in Malaysia — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Kuala Lumpur, Malaysia
WHAT THEY DID HERE, AND WHEN
2009Helps set up 1MDB, the state fund prosecutors say he later drained.SOURCE: DOJ forfeiture complaints
2009–2015Allegedly diverts over $4.5B from 1MDB through offshore companies.SOURCE: DOJ (alleged; never tried)
Kuala Lumpur, Malaysia
WHAT THEY DID HERE, AND WHEN
2014–c.2017Lives in Kuala Lumpur while the persona takes off: designer goods, cars, the follower count climbing towards two million.SOURCE: BBC; Bloomberg
OUR CASES BY CATEGORY
Share of the 2 cases tied to Malaysia (born or operated here)
LAUNDERING
50%
BANK & WIRE
50%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Sovereign fund embezzlement (1MDB)Non-existent investment scamsPhone impersonation (Macau) scamsMule accountsE-commerce fraud
THE PICTURE

Malaysia is linked to one of the largest financial scandals on record, 1MDB, in which US prosecutors say at least $4.5bn was stolen from the state fund; former prime minister Najib Razak was convicted in the main 1MDB trial in December 2025, while financier remains a fugitive (DOJ; CNN, Dec 2025). Online scam losses rose sharply to RM2.97bn in 2025 from RM1.57bn in 2024, with 66,204 cases, led by fake investment schemes (RM1.47bn) and phone impersonation scams (Royal Malaysia Police, Jun 2026). Malaysia is also a source and transit country for workers trafficked to regional scam compounds and a base for mule accounts. Enforcement is led by the police Commercial Crime Investigation Department, the National Scam Response Centre and the anti-corruption commission (MACC).

TOP FRAUDSTERS FROM HERE
Najib Razak CONVICTEDREPORT PENDING
RM13.5bn (~$3.3bn; fines and penalty ordered) · 2009–2015
Former prime minister convicted of abuse of power and money laundering over more than $700M from 1MDB entering his accounts; he is appealing.
SOURCE: CNN / Al Jazeera, 26 Dec 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
RM2.97bn Online scam losses in 2025, up from RM1.57bn in 2024 (Royal Malaysia Police (IGP), 15 Jun 2026)
66,204 Online fraud cases in 2025, up 87% from 35,368 in 2024 (Royal Malaysia Police (IGP), 15 Jun 2026)
RM1.47bn Losses to non-existent investment scams in 2025 (Royal Malaysia Police (IGP), 15 Jun 2026)
28,388 Phone (telecommunications) scam cases in 2025 (Royal Malaysia Police (IGP), 15 Jun 2026)
WHO FIGHTS IT
Royal Malaysia Police Commercial Crime Investigation Department (CCID) and the National Scam Response Centre (997 hotline, since 2022).
1MDB prosecutions: Najib convicted in the SRC case (2020) and the main 1MDB trial (26 Dec 2025, 15 years plus RM11.38bn fine); appeal filed.
Malaysian Anti-Corruption Commission (MACC) and Bank Negara Malaysia pursue laundering and mule-account networks.
SOURCES
CNN, PBS and Al Jazeera, 26 Dec 2025
Malay Mail, 30 Dec 2025
Bloomberg / Japan Times, 12-13 May 2026
The Sun / The Edge / Malay Mail, Jun 2026 (IGP and Home Ministry figures)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇸🇬
SINGAPORE
Low source / Enforcement hub
CAPITAL Singapore · POPULATION 5.8M (2023, UN WPP 2024)
FRAUD TYPES
Financial hub — target for money laundering and investment fraud
KEY FACTS
Strong enforcement. Su Zhu (Three Arrows Capital) arrested at Changi Airport in Sept 2023. Banking system used for fraud transit.
BORN HERE
1 person in our case files was born in Singapore. Tap to open the report.
OPERATED HERE
Physically based or working in Singapore — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Singapore
WHAT THEY DID HERE, AND WHEN
2018Co-founds Terraform Labs, incorporated in Singapore.SOURCE: case brief
May 2021After the first depeg, tells investors the algorithm restored the peg; court documents say a trading firm was secretly buying the coin.SOURCE: court documents cited by BBC
Singapore
WHAT THEY DID HERE, AND WHEN
2012–2015Accounts at BSI and Falcon in Singapore allegedly move 1MDB money; the banks are later shut by the regulator.SOURCE: MAS; DOJ (alleged)
Singapore
WHAT THEY DID HERE, AND WHEN
1992–1995Runs Barings Futures Singapore; hides losses in account 88888 until they reach £827M.SOURCE: Bank of England report; Singapore court
Feb 1995Leaves Singapore with a note reading 'I'm sorry'; Barings collapses three days later.SOURCE: case brief
Dec 1995–1999Returned from Frankfurt; sentenced in Singapore to 6½ years, released in 1999.SOURCE: Singapore court
OUR CASES BY CATEGORY
Share of the 4 cases tied to Singapore (born or operated here)
CRYPTO
50%
LAUNDERING
25%
STOCK
25%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Investment scamsGovernment-official impersonation scamsMoney laundering through the financial hubTrade-finance fraudJob and e-commerce scams
THE PICTURE

Singapore is a high-value target for scams and a regional financial hub that criminal networks use to launder money. Police recorded 37,308 scam cases and S$913.1M in losses in 2025, both down on 2024, but government-official impersonation scams more than doubled to 3,363 cases and S$242.9M (SPF, Feb 2026). In 2023 police seized about S$3bn in assets from a Fujian-linked network of ten foreign nationals, all later convicted of money laundering, and oil trader Hin Leong's founder Lim Oon Kuin was jailed in 2024 for cheating HSBC (Wikipedia; Malay Mail, 2024-2026). Enforcement relies on the police Anti-Scam Command, the 2025 Protection from Scams Act and close bank-police data sharing.

TOP FRAUDSTERS FROM HERE
Su Haijin PLEADED GUILTYREPORT PENDING
S$3bn (assets seized across the ten-person case) · 2023–2024
One of ten foreign nationals convicted in Singapore's S$3bn money-laundering case; jailed 14 months and forfeited about 90% of S$170M in seized assets.
SOURCE: Singapore Police Force / Gutzy Asia, 4-5 Apr 2024
Lim Oon Kuin CONVICTEDREPORT PENDING
$111.7M (loans obtained from HSBC by deception) · 2020
Founder of Hin Leong Trading convicted of cheating HSBC with fake oil deals and abetting forgery; sentence cut to 13.5 years on appeal.
SOURCE: France 24, 18 Nov 2024; Malay Mail, 4 Mar 2026
Ng Yu Zhi CHARGED (NOT TRIED)REPORT PENDING
S$1.5bn (~$1.1bn; investor funds raised, per prosecutors) · 2016–2021
Envy Group founder on trial for an alleged nickel-trading scheme prosecutors call 'pure fiction'; he denies 42 charges. A civil court ordered Envy directors to pay over S$249M.
SOURCE: Bloomberg, Nov 2024; Singapore High Court [2025] SGHC 143
FRAUD BY CATEGORY
share of reported scam losses (amount lost) · 2025
Investment scams
36.8%
Government official impersonation scams
26.6%
Others
14.8%
Job scams
13.5%
Phishing scams
4.4%
Business email compromise scams
3.9%
SOURCE: Singapore Police Force, Annual Scam and Cybercrime Brief 2025, Feb 2026
KEY NUMBERS
S$913.1M Scam losses in 2025, down 17.9% from S$1,112.4M in 2024 (Singapore Police Force, Feb 2026)
37,308 Scam cases in 2025, down 27.6% (Singapore Police Force, Feb 2026)
81.8% Share of scams where victims made the transfers themselves (Singapore Police Force, Feb 2026)
S$140.5M Scam losses recovered by the Anti-Scam Command in 2025 (Singapore Police Force, Feb 2026)
WHO FIGHTS IT
Anti-Scam Command (ASCom) of the Singapore Police Force, working with banks to freeze funds; S$348M in potential losses averted in 2025.
Protection from Scams Act (in force 2025) lets police issue restriction orders on bank accounts of people being scammed; Online Criminal Harms Act (2023).
2023 anti-money-laundering raids seized ~S$3bn; all ten accused convicted in 2024.
SOURCES
Singapore Police Force, Annual Scam and Cybercrime Brief 2025, Feb 2026
Singapore Police Force news release, 4 Apr 2024
Wikipedia, '2023 Singapore money laundering case'
France 24, 18 Nov 2024; Malay Mail, 4 Mar 2026
Bloomberg, 26-27 Nov 2024
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇮🇳
INDIA
#10 WCI / #4 Sumsub
CAPITAL New Delhi · POPULATION 1,438M (2023, UN WPP 2024)
FRAUD TYPES
Call center scams, tech support fraud, UPI fraud, digital financial fraud
KEY FACTS
Cybersecurity incidents: 10.29 lakh (2022) → 22.68 lakh (2024). Call-centre industry targeting the US, UK and Australia.
BORN HERE
Nobody in our case files was born in India yet.
OPERATED HERE
Nobody in our case files is documented as operating from India yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Investment and trading-app scams'Digital arrest' impersonation scamsTech-support call-centre scams targeting foreignersBank loan fraudSextortion
THE PICTURE

India faces fast-growing cyber fraud at home: the Home Ministry says Indians reported losses of Rs22,495 crore (~$2.6bn) to cyber fraud in 2025 from 2.8 million complaints, three-quarters of it to investment scams, with 'digital arrest' impersonation scams also rising (MHA via ThePrint, Feb 2026). Illegal call centres in India also run tech-support and government-impersonation scams against people in the US and elsewhere; the CBI's Operation Chakra has worked with the FBI against these networks, including a Noida ring accused of defrauding more than 600 Americans (Dec 2025). Large bank frauds remain a separate problem: Nirav Modi and Mehul Choksi are accused over the roughly Rs13,000-14,000 crore Punjab National Bank fraud and are fighting extradition from the UK and Belgium (AIR, 2025-2026). Enforcement runs through the Indian Cyber Crime Coordination Centre (I4C), the 1930 helpline, state cyber police, the CBI and the Enforcement Directorate.

TOP FRAUDSTERS FROM HERE
Nirav Modi CHARGED (NOT TRIED)REPORT PENDING
Rs14,000 crore (~$2bn; alleged bank fraud) · 2011–2018
Diamond merchant accused of the Punjab National Bank fraud using fake letters of undertaking; lost his final European Court of Human Rights challenge to extradition from the UK in July 2026.
SOURCE: The Week, 6 Jul 2026
Mehul Choksi CHARGED (NOT TRIED)REPORT PENDING
Rs13,000 crore (alleged PNB fraud, joint case) · 2011–2018
Jeweller and Nirav Modi's uncle, co-accused in the PNB fraud; arrested in Belgium in 2025 and cleared for extradition by Belgian courts.
SOURCE: All India Radio, 18 Oct and 10 Dec 2025
Vijay Mallya FUGITIVEREPORT PENDING
Rs9,000 crore (loans owed to 17 banks) · 2004–2016
Former Kingfisher Airlines owner accused of fraud and money laundering over bank loans; declared a fugitive economic offender in 2019 and living in the UK.
SOURCE: Business Standard, 2025
B. Ramalinga Raju CONVICTEDREPORT PENDING
Rs7,000 crore+ (~$1bn; accounting fraud he admitted) · 2001–2008
Satyam Computer Services founder who confessed in 2009 to inflating profits and cash for years; convicted with nine others in 2015.
SOURCE: Hyderabad special court verdict via Reuters/BBC, Apr 2015
FRAUD BY CATEGORY
share of reported cyber fraud losses (amount lost) · 2025
Investment fraud
76%
Other frauds
11%
Digital arrest scams
9%
Sextortion
4%
SOURCE: Ministry of Home Affairs / I4C data, reported by ThePrint, 21 Feb 2026
KEY NUMBERS
Rs22,495 crore Losses reported to cyber fraud in 2025 (Rs22,845 crore in 2024) (MHA / I4C via ThePrint, Feb 2026)
2.8M Cyber fraud complaints in 2025, up from 2.27M in 2024 (MHA / I4C via ThePrint, Feb 2026)
Rs36,014 crore Value of bank frauds reported in FY2024-25 (23,953 cases) (RBI Annual Report 2024-25, May 2025)
WHO FIGHTS IT
Indian Cyber Crime Coordination Centre (I4C, MHA), the National Cybercrime Reporting Portal and 1930 helpline, with the Citizen Financial Cyber Fraud Reporting and Management System to block funds.
CBI Operation Chakra with the FBI and other partners against call-centre fraud, e.g. Noida network busted Dec 2025.
Fugitive Economic Offenders Act 2018 (used against Mallya and Nirav Modi); Enforcement Directorate money-laundering cases under PMLA.
SOURCES
ThePrint, 21 Feb 2026 (MHA data)
RBI Annual Report 2024-25 (via Millennium Post / Business Standard)
APAC News Network / The420.in, Dec 2025 (Operation Chakra)
All India Radio, Oct-Dec 2025
The Week, 6 Jul 2026
Business Standard, 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇵🇰
PAKISTAN
#1 Sumsub
CAPITAL Islamabad · POPULATION 247.5M (2023, UN WPP 2024)
FRAUD TYPES
Identity fraud, financial fraud, telecom fraud, digital payment fraud
KEY FACTS
#1 fraud vulnerability globally (Sumsub 2025). Rapidly digitizing economy. FMU updated STR framework 2024.
BORN HERE
Nobody in our case files was born in Pakistan yet.
OPERATED HERE
Nobody in our case files is documented as operating from Pakistan yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Phishing kits and spam toolsIllegal call centresFake degree millsOnline financial fraud
THE PICTURE

Pakistan-based groups have supplied tools and labour to global online fraud: in May 2025 police arrested 21 people in Lahore and Multan linked to 'HeartSender', a phishing-kit and spam service tied to more than $50M in US losses, after the FBI and Dutch police seized its infrastructure (KrebsOnSecurity; Dawn, May 2025). Illegal call centres, some run with Chinese and other foreign nationals, have been raided repeatedly in Islamabad and Rawalpindi, including a 2026 raid in which 212 people were detained (Express Tribune, 2026). Enforcement is hampered by capacity: the FIA received over 73,000 cybercrime complaints in 2024 but registered only 1,604 cases (Business Recorder, citing FIA). Cyber-fraud policing moved in 2025 from the FIA to the new National Cyber Crime Investigation Agency, which itself faced a bribery scandal over protecting illegal call centres.

TOP FRAUDSTERS FROM HERE
Rameez Shahzad (alias Saim Raza) CHARGED (NOT TRIED)REPORT PENDING
$50M+ (US losses linked to the group's tools) · 2015–2025
Alleged mastermind of the HeartSender/Fudtools phishing-kit service sold to fraudsters worldwide; arrested in Lahore in May 2025.
SOURCE: KrebsOnSecurity / Dawn, May 2025
Agha Hasan Abedi CONVICTEDREPORT PENDING
Not reliably quantified (bank had ~1.3M depositors in 70+ countries) · 1972–1991
Founder of BCCI, the bank shut by regulators worldwide in 1991 over fraud and money laundering; convicted of fraud in absentia in the UAE, he died in Karachi in 1995 while Pakistan refused extradition.
SOURCE: Deseret News / AP, 6 Aug 1995
Shoaib Ahmed Shaikh ACQUITTEDREPORT PENDING
$140M (alleged fake-degree scheme) · 2009–2015
CEO of Axact, accused of selling fake degrees from hundreds of fictitious online universities; a 2018 conviction was overturned and he was acquitted in 2023.
SOURCE: University World News, May 2024; Gulf News, 2018
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
73,000+ Cybercrime complaints filed with the FIA in 2024; 1,604 cases registered (FIA 2024 annual report via Business Recorder)
13,000+ Online financial fraud complaints in 2024, with 1,212 arrests and 17 verdicts (FIA 2024 annual report via Business Recorder)
21 Arrests in the HeartSender raids in Lahore and Multan, May 2025 (Dawn, May 2025)
WHO FIGHTS IT
National Cyber Crime Investigation Agency (NCCIA) replaced the FIA Cybercrime Wing in 2025 under the amended Prevention of Electronic Crimes Act (PECA, amended Jan 2025).
Joint operation with the FBI and Dutch police against HeartSender (infrastructure seized Jan 2025; arrests May 2025).
Repeated raids on illegal call centres in Islamabad (e.g. 212 detained in E-11/G-10; 100 detained Sep 2026).
SOURCES
KrebsOnSecurity, May 2025
Dawn, May 2025
Express Tribune, 2026; The Nation, 22 Sep 2026
Business Recorder (citing FIA 2024 annual report)
University World News, May 2024
Deseret News / AP, 6 Aug 1995
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇧🇩
BANGLADESH
#7 Sumsub
CAPITAL Dhaka · POPULATION 171.5M (2023, UN WPP 2024)
FRAUD TYPES
Mobile banking fraud, identity fraud, garment industry BEC
KEY FACTS
Growing digital economy. Mobile financial services (bKash/Nagad) fraud rising. Part of global BEC target list.
BORN HERE
Nobody in our case files was born in Bangladesh yet.
OPERATED HERE
Nobody in our case files is documented as operating from Bangladesh yet.
KNOWN FOR
Bank and NBFI loan embezzlementMulti-level marketing schemesMoney laundering abroadSWIFT cyber-heist victim (2016)
THE PICTURE

Bangladesh's major frauds have centred on banks and financial firms: former NBFI executive P K Halder is accused of siphoning roughly Tk10,000-11,000 crore from non-bank lenders and was sentenced in absentia in 2023, and the multi-level-marketing Destiny Group's leaders were convicted in money-laundering cases (Daily Star, 2022-2025). In 2016 hackers attributed by the US to North Korea's stole $101M from Bangladesh Bank's New York Fed account through fraudulent SWIFT orders; only part has been recovered (US DOJ, 2018; Wikipedia). The Anti-Corruption Commission (ACC), Bangladesh Financial Intelligence Unit and CID lead investigations, and many cases involve suspects abroad.

TOP FRAUDSTERS FROM HERE
Prashanta Kumar (P K) Halder CONVICTEDREPORT PENDING
Tk10,000-11,000 crore (~$850M+; alleged siphoning) · 2014–2020
Former NBFI executive accused of siphoning funds from non-bank lenders; arrested in India in 2022 and sentenced in absentia in Dhaka to 10 years for illegal wealth and 12 years for money laundering.
SOURCE: The Daily Star, 8 Oct 2023
Mohammad Rafiqul Amin CONVICTEDREPORT PENDING
Tk4,200 crore (money-laundering cases) · 2006–2012
Managing director of Destiny Group, whose MLM schemes collected money from members; convicted with dozens of others in money-laundering cases.
SOURCE: The Daily Star, 2020-2022
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$101M Stolen from Bangladesh Bank's New York Fed account in February 2016 (of $951M attempted) (Wikipedia summary of court and press records)
Tk1,044 crore Fine imposed on P K Halder in the 2023 verdict (The Daily Star, Oct 2023)
WHO FIGHTS IT
Anti-Corruption Commission (ACC) files embezzlement and money-laundering cases; CID handles cyber and financial crime.
US charged North Korean programmer Park Jin Hyok over the 2016 Bangladesh Bank heist (2018); Bangladesh Bank is suing RCBC in New York.
Money Laundering Prevention Act 2012 and Bangladesh Financial Intelligence Unit (BFIU).
SOURCES
The Daily Star (Dhaka), 2020-2025
Wikipedia, 'Bangladesh Bank robbery' and 'Destiny Group'
US DOJ complaint against Park Jin Hyok, Sep 2018
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇱🇰
SRI LANKA
#10 Sumsub
CAPITAL Sri Jayawardenepura Kotte (executive: Colombo) · POPULATION 23.0M (2023, UN WPP 2024)
FRAUD TYPES
Identity fraud, investment scams, mobile fraud
KEY FACTS
Rising fraud vulnerability. Economic crisis 2022 drove increase in online scam activity.
BORN HERE
1 person in our case files was born in Sri Lanka. Tap to open the report.
OPERATED HERE
Nobody in our case files is documented as operating from Sri Lanka yet.
OUR CASES BY CATEGORY
Share of the 1 case tied to Sri Lanka (born or operated here)
STOCK
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Central Bank bond scandalPyramid schemesOnline investment scams
THE PICTURE

Sri Lanka's best-known fraud case is the 2015 Central Bank treasury bond scandal, in which a presidential commission found then-governor Arjuna Mahendran responsible for a loss of LKR11.1bn to public institutions through a bond auction that benefited Perpetual Treasuries, owned by his son-in-law; Mahendran stayed in Singapore and later rulings dismissed charges against him (Presidential Commission, 2017; Wikipedia). Sri Lankan bank accounts were also used as an exit route in the 2016 Bangladesh Bank heist, though the $20M sent to Sri Lanka was recovered. Public data breaking down scam losses by type is limited. The Central Bank bans pyramid schemes under the Banking Act and the CID investigates financial fraud.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
LKR11.1bn Loss to public institutions attributed to the 2015 bond auction by the Presidential Commission (Presidential Commission of Inquiry, Dec 2017)
$20M Funds from the 2016 Bangladesh Bank heist sent to Sri Lanka, all recovered (Wikipedia summary of court and press records)
WHO FIGHTS IT
Criminal Investigation Department (CID) and the Commission to Investigate Allegations of Bribery or Corruption (CIABOC).
Central Bank of Sri Lanka prohibits pyramid schemes under Section 83C of the Banking Act.
Online Safety Act (2024) and Financial Intelligence Unit under the Financial Transactions Reporting Act.
SOURCES
Wikipedia, 'Central Bank of Sri Lanka bond scandal' and 'Arjuna Mahendran', accessed Sep 2026
Presidential Commission of Inquiry report, Dec 2017
Wikipedia, 'Bangladesh Bank robbery'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇳🇵
NEPAL
Emerging
CAPITAL Kathmandu · POPULATION 30.0M (2023, UN WPP 2024)
FRAUD TYPES
Mobile money fraud, lottery scams, identity fraud
KEY FACTS
Digital payments growing. Fraud controls lagging behind adoption. Cross-border fraud with India.
BORN HERE
Nobody in our case files was born in Nepal yet.
OPERATED HERE
Nobody in our case files is documented as operating from Nepal yet.
KNOWN FOR
Cooperative savings fraudMoney launderingOnline financial scams
THE PICTURE

Nepal's most prominent fraud problem is the embezzlement of savings in savings-and-credit cooperatives, which has drawn in senior politicians: Rastriya Swatantra Party chair Rabi Lamichhane was arrested in 2024-2025 over more than Rs109M allegedly moved from a Butwal cooperative to a media company he ran, and the case remains before the courts (Wikipedia, 2026). Weak oversight of cooperatives and money-laundering controls led the FATF to place Nepal under increased monitoring in February 2025. Investigations are led by the Nepal Police Central Investigation Bureau and Cyber Bureau and the Department of Money Laundering Investigation.

TOP FRAUDSTERS FROM HERE
Rabi Lamichhane CHARGED (NOT TRIED)REPORT PENDING
Rs109M+ (~$0.8M; alleged transfers from Supreme Savings and Credit Cooperative) · 2017–2021
Rastriya Swatantra Party chair accused of fraud and embezzlement of cooperative savers' money via Gorkha Media Network; released on bail in December 2025 and denies wrongdoing.
SOURCE: Wikipedia, 'Rabi Lamichhane', accessed Sep 2026
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
Feb 2025 Nepal added to the FATF list of jurisdictions under increased monitoring (FATF, Feb 2025)
WHO FIGHTS IT
Nepal Police Central Investigation Bureau (CIB) and Cyber Bureau; Department of Money Laundering Investigation.
Electronic Transactions Act 2008 and Asset (Money) Laundering Prevention Act govern cyber fraud and laundering cases.
Nepal placed on the FATF grey list (Feb 2025).
SOURCES
Wikipedia, 'Rabi Lamichhane', accessed Sep 2026
FATF plenary outcomes, Feb 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇳🇬
NIGERIA
#5 WCI · GI-TOC 7.32
CAPITAL Abuja · POPULATION 227.9M (2023, UN)
FRAUD TYPES
BEC, romance scams ('Yahoo Boys'), advance fee fraud, pig butchering
KEY FACTS
Cybercrime is 30%+ of reported crime in West and East Africa (Interpol 2025). 792 people arrested in one Lagos raid on a crypto and romance scam centre on 10 Dec 2024, including 148 Chinese nationals (EFCC). 'Yahoo Boys' is local slang for online scammers. Members of the Black Axe confraternity have been convicted in romance and BEC cases abroad.
BORN HERE
2 people in our case files were born in Nigeria. Tap to open the report.
OPERATED HERE
Physically based or working in Nigeria — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Lagos, Nigeria
WHAT THEY DID HERE, AND WHEN
1995–1998Poses as the central bank governor to sell Nelson Sakaguchi a non-existent airport; $242M paid to Nigerian accounts.SOURCE: EFCC; Lagos High Court
2003–2005Arrested by the EFCC in June 2003; pleads guilty in Lagos in Nov 2005.SOURCE: EFCC
Lagos, Nigeria
WHAT THEY DID HERE, AND WHEN
1990sSells sneakers and clothes from his car boot in Bariga, Lagos; later opens boutiques.SOURCE: his letter to the court; BBC
2011Starts building the Instagram persona from Lagos.SOURCE: BBC; Business Insider
2014Leaves Nigeria for Kuala Lumpur.SOURCE: BBC
OUR CASES BY CATEGORY
Share of the 2 cases tied to Nigeria (born or operated here)
BANK & WIRE
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Business email compromiseRomance scamsAdvance-fee ('419') fraudCrypto-investment scam hubsSocial-engineering bank fraud
THE PICTURE

Nigeria-based networks are repeatedly named in US prosecutions for business email compromise (BEC) and associated money laundering, including the cases of Ramon '' Abbas (US DOJ, 2022) and Obinwanne Okeke (US DOJ, 2021). The country is also a target: banks and payment firms reported N52.26bn in fraud losses in 2024, falling to N25.85bn in 2025, with social engineering the leading technique (NIBSS, 2026). Foreign-run operations use Nigeria as a base too: in December 2024 the EFCC arrested 792 suspects, including 148 Chinese and 40 Filipino nationals, at a Lagos building allegedly running crypto-investment and romance scams aimed at victims abroad (EFCC, Dec 2024). The EFCC reported a record 4,111 convictions in 2024 (EFCC via Naija News, Mar 2025), and Nigeria took part in INTERPOL's Operation Red Card, where it made 130 arrests, 113 of them foreign nationals (INTERPOL, Mar 2025).

TOP FRAUDSTERS FROM HERE
Obinwanne Okeke PLEADED GUILTYREPORT PENDING
~$11M (known victim losses) · 2015–2019
Founder of Invictus Group who took part in a phishing and email-compromise scheme against Caterpillar dealer Unatrac and other victims.
SOURCE: US DOJ (E.D. Va.), 16 Feb 2021
Olalekan Jacob Ponle CONVICTEDREPORT PENDING
$8.03M (actual losses; $51.3M intended) · 2019
Ran BEC schemes from the UAE, having US companies wire money to money mules who converted it to Bitcoin; sentenced to 8 years 4 months.
SOURCE: US DOJ (N.D. Ill.), 11 Jul 2023
FRAUD BY CATEGORY
share of fraud cases reported by financial institutions, by payment channel (computed from published counts; total 95,620) · 2023
Mobile
49.7%
Web
22.9%
POS
18.4%
Internet banking
5.6%
E-commerce
2.6%
ATM
0.8%
Other/unassigned
0.1%
SOURCE: NIBSS, Annual Fraud Landscape 2023, Apr 2024
KEY NUMBERS
N52.26bn Fraud losses reported by Nigerian financial institutions in 2024 (N25.85bn in 2025) (NIBSS, 2 Jun 2026)
4,111 EFCC convictions in 2024, a record for the agency (EFCC via Naija News, 31 Mar 2025)
792 Suspects arrested in one EFCC raid on an alleged crypto and romance scam hub in Lagos (10 Dec 2024) (EFCC / Vanguard, Dec 2024)
63.4% Share of 2025 digital-payment fraud cases located in Lagos State (NIBSS, 2 Jun 2026)
WHO FIGHTS IT
Economic and Financial Crimes Commission (EFCC): 12,928 cases investigated, 5,083 filed in court and 4,111 convictions in 2024 (EFCC, Mar 2025).
Cybercrimes (Prohibition, Prevention, etc.) Act 2015. Nigeria is a party to the Budapest Convention on Cybercrime.
In INTERPOL's Operation Red Card (Nov 2024–Feb 2025), Nigeria made 130 arrests (113 foreign nationals) and seized 685 devices and 16 houses (INTERPOL, Mar 2025). It also took part in Red Card 2.0 (Dec 2025–Jan 2026).
The CBN and NIBSS run an industry fraud-reporting portal and have published 13,417 fraud suspects on a new portal (Legit.ng, 2026).
SOURCES
NIBSS, Annual Fraud Landscape 2023 (Apr 2024)
NIBSS press release on 2025 fraud, 2 Jun 2026
EFCC statement / Vanguard, Dec 2024
Naija News, 'EFCC 2024 in numbers', 31 Mar 2025
US DOJ E.D. Va., 16 Feb 2021 (Okeke)
US DOJ N.D. Ill., Jul 2023 (Ponle)
Channels TV, 8 Nov 2022 (Abbas)
ThisDay, 19 Nov 2005; ICC-CCS, 2008 (Nwude)
INTERPOL, 'More than 300 arrests as African countries clamp down on cyber threats' (Operation Red Card), 24 Mar 2025
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇬🇭
GHANA
WCI top 15
CAPITAL Accra · POPULATION 33.8M (2023, UN)
FRAUD TYPES
Romance scams ('Sakawa Boys'), auction fraud, gold/commodity scams
KEY FACTS
'Sakawa' is local slang for online fraud. The second-largest source in West Africa after Nigeria. Growing BEC operations.
BORN HERE
Nobody in our case files was born in Ghana yet.
OPERATED HERE
Nobody in our case files is documented as operating from Ghana yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Romance scamsBusiness email compromiseMobile-money and e-money fraudForgery and identity-theft bank fraudUnlicensed investment schemes
THE PICTURE

US prosecutors have charged Ghana-based defendants over romance scams and BEC. Three Ghanaian nationals were extradited to New York over an alleged criminal organisation that stole more than $100M (US DOJ SDNY), and in July 2026 the influencer Frederick Kumi ('Abu Trica') was extradited over an alleged $8M romance-fraud scheme against older Americans (US DOJ N.D. Ohio, 2026). At home, reported fraud cases at banks, specialised deposit-taking institutions (SDIs) and payment firms rose to 16,733 in 2024, with about GH¢99M at risk (Bank of Ghana, Apr 2025), and to 24,778 in 2025 (Bank of Ghana, 2026). The Cyber Security Authority says online fraud made up about 47% of the 3,876 cyber incidents its CERT-GH logged in January–July 2026 (CSA via MyJoyOnline, Sep 2026). The largest domestic investment case, the collapse of gold-trading firm Menzgold, is still on trial (GhanaWeb, 2025).

TOP FRAUDSTERS FROM HERE
Nana Appiah Mensah ('NAM1') CHARGED (NOT TRIED)REPORT PENDING
GH¢340.8M (customer funds, as charged) · 2016–2018
CEO of Menzgold, charged on 39 counts including defrauding by false pretence, unlicensed deposit-taking and money laundering after the SEC shut the firm in 2018.
SOURCE: GhanaWeb / MyJoyOnline, 2025 (trial ongoing)
Isaac Oduro Boateng CHARGED (NOT TRIED)REPORT PENDING
>$100M (alleged thefts by the organisation) · n/a (extradited from Ghana)
One of four Ghanaian nationals charged over a West Africa-based network alleged to run romance scams and BEC; extradited from Ghana.
SOURCE: US DOJ SDNY press release, 'Ghanaian nationals extradited for roles in criminal organization that stole more than $100 million'
Frederick Kumi ('Abu Trica') CHARGED (NOT TRIED)REPORT PENDING
>$8M (alleged proceeds) · 2026
Social-media influencer accused of using AI-built fake personas to run romance scams on elderly US victims.
SOURCE: US DOJ N.D. Ohio; Africanews, 10 Jul 2026
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
16,733 Fraud cases reported by banks, SDIs and payment service providers in 2024 (value at risk ~GH¢99M) (Bank of Ghana, 2024 Fraud Report, 23 Apr 2025)
67% Share of 2024 bank and SDI value at risk from forgery and document manipulation (inflated by one GH¢53M case) (Bank of Ghana, 2024 Fraud Report, 23 Apr 2025)
24,778 Fraud cases reported in 2025, up 48% on 2024 (Bank of Ghana 2025 Fraud Report, via CSA/press, 2026)
~47% Share of CERT-GH cyber incidents that were online fraud, Jan–Jul 2026 (1,818 of 3,876) (Cyber Security Authority via MyJoyOnline, Sep 2026)
WHO FIGHTS IT
The Cyber Security Authority and CERT-GH operate under the Cybersecurity Act 2020 (Act 1038). Ghana is a party to the Budapest Convention on Cybercrime.
The Bank of Ghana publishes annual fraud reports and directs banks, SDIs and payment service providers to report all fraud.
Extraditions to the US in romance and BEC cases, including Frederick Kumi in July 2026 (US DOJ SDNY; N.D. Ohio). Ghana also took part in INTERPOL Operation Red Card 2.0 (Dec 2025–Jan 2026).
SOURCES
Bank of Ghana, Banks, SDIs and PSPs 2024 Fraud Report (Notice BG/GOV/SEC/2025/09), 23 Apr 2025
MyJoyOnline, 'Online fraud accounts for 47% of Ghana's cyber incidents – CSA', Sep 2026
US DOJ SDNY, extradition of Ghanaian nationals (press release)
US DOJ N.D. Ohio / Africanews, 10 Jul 2026
GhanaWeb, Menzgold case reports, 2025
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇨🇮
CÔTE D'IVOIRE
Interpol flagged
CAPITAL Yamoussoukro (official); Abidjan (economic) · POPULATION 31.2M (2023, UN)
FRAUD TYPES
Romance scams, advance fee fraud, lottery scams
KEY FACTS
Part of West Africa BEC belt. French-language targeting. Growing sophistication.
BORN HERE
Nobody in our case files was born in Côte d'Ivoire yet.
OPERATED HERE
Nobody in our case files is documented as operating from Côte d'Ivoire yet.
KNOWN FOR
Online scams ('broutage')Identity-data misuseInheritance and romance scamsMobile-loan fraudPhishing
THE PICTURE

Côte d'Ivoire's police cybercrime platform (PLCC) handled 12,100 cases in 2024, up from 8,132 in 2023, with reported losses of about 6.96bn FCFA (PLCC/ANSSI via KOACI, May 2025). Internet fraud, known locally as 'broutage', caused the largest share of those losses (PLCC, 2025). Abidjan-based suspects have also targeted victims abroad. INTERPOL's Serengeti 2.0 operation broke up an inheritance scam that started in Germany and caused about $1.6M in losses (INTERPOL, Aug 2025), and a US indictment accuses an Ivorian national of phishing travel agencies out of about $14M (US DOJ E.D. Tex., Apr 2026). In Operation Red Card 2.0, Ivorian police arrested 58 people and seized 240 phones and more than 300 SIM cards in a crackdown on mobile-loan fraud (INTERPOL, Feb 2026).

TOP FRAUDSTERS FROM HERE
Christian Marviv Ble CHARGED (NOT TRIED)REPORT PENDING
~$14M (alleged losses) · 2026
Accused of phishing about 430 travel agencies for airline-reservation logins, then booking tickets charged to their accounts.
SOURCE: US DOJ (E.D. Tex.), Apr 2026
FRAUD BY CATEGORY
share of financial losses in cybercrime cases reported to the PLCC (computed from published amounts; 'Other' is the remainder of the 6,960,903,038 FCFA total) · 2024
Internet fraud ('broutage')
33.9%
Fraudulent use of identification data
27.4%
Other
16.4%
Attacks on human dignity
12.4%
Electronic transaction fraud
7.1%
Bank fraud
2.7%
SOURCE: PLCC/ANSSI 2024 figures, reported by KOACI, 27 May 2025
KEY NUMBERS
12,100 Cybercrime cases handled by the PLCC in 2024 (8,132 in 2023) (PLCC/ANSSI via KOACI, 27 May 2025)
6.96bn FCFA Reported losses in PLCC cases in 2024 (9.21bn FCFA in 2023) (PLCC/ANSSI via KOACI, 27 May 2025)
2,326 Internet-fraud cases in 2024, second only to attacks on human dignity (2,822) (PLCC/ANSSI via KOACI, 27 May 2025)
58 Arrests in the mobile-loan fraud crackdown during INTERPOL Operation Red Card 2.0 (INTERPOL, 18 Feb 2026)
WHO FIGHTS IT
Plateforme de Lutte Contre la Cybercriminalité (PLCC), run by the national police and ANSSI, reported a 68% case-resolution rate in 2024.
Côte d'Ivoire is a party to the Budapest Convention on Cybercrime.
It took part in INTERPOL operations Red Card (2025), Serengeti 2.0 (Jun–Aug 2025) and Red Card 2.0 (Dec 2025–Jan 2026).
SOURCES
KOACI, 'la PLCC a enregistré 12100 affaires en 2024', 27 May 2025
Connectionivoirienne, PLCC director interview, 8 Jun 2025
INTERPOL, 'African authorities dismantle massive cybercrime and fraud networks' (Operation Serengeti 2.0), 22 Aug 2025
INTERPOL, 'More than 300 arrests as African countries clamp down on cyber threats' (Operation Red Card), 24 Mar 2025
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
US DOJ E.D. Tex., Ivorian national extradited from France, Apr 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇸🇳
SENEGAL
#19 Sumsub
CAPITAL Dakar · POPULATION 18.1M (2023, UN)
FRAUD TYPES
Mobile money fraud, identity fraud, telecom scams
KEY FACTS
Part of Francophone West Africa fraud ecosystem. Mobile money adoption = new attack surface.
BORN HERE
Nobody in our case files was born in Senegal yet.
OPERATED HERE
Nobody in our case files is documented as operating from Senegal yet.
KNOWN FOR
Online Ponzi schemesBusiness email compromiseRomance scamsMobile-money fraud
THE PICTURE

Senegal's national police recorded 3,902 cybercrime complaints in 2024 and 3,794 cybercrime offences in 2025, with 257 people referred for prosecution in 2025 (Police nationale annual report, via Osiris, Mar 2026). During INTERPOL's Operation Serengeti (Sep–Oct 2024), Senegalese police and INTERPOL arrested eight people, five of them Chinese nationals, over an online Ponzi scheme worth about 3.7bn FCFA (Dakaractu, 2024). INTERPOL's 2024 Africa cyberthreat assessment names Senegalese finance, import-export and trading businesses among those exposed to BEC and romance scams (Pulse Senegal, 2026). Senegal also took part in INTERPOL Operation Red Card 2.0 (INTERPOL, Feb 2026).

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
3,902 Cybercrime complaints registered by police in 2024 (Police nationale annual report, via Osiris.sn, Mar 2026)
3,794 Cybercrime offences recorded by police in 2025 (257 people referred to justice) (Police nationale annual report, via Osiris.sn, 13 Mar 2026)
3.7bn FCFA Alleged value of an online Ponzi scheme dismantled in Operation Serengeti (8 arrests) (Dakaractu, 2024)
WHO FIGHTS IT
The National Police cybersecurity division investigates online fraud under Law No. 2008-11 on cybercrime.
Senegal is a party to the Budapest Convention on Cybercrime.
It took part in INTERPOL Operation Serengeti (Sep–Oct 2024) and Red Card 2.0 (Dec 2025–Jan 2026).
SOURCES
Osiris.sn / Agence Ecofin, 'Sénégal : la cybercriminalité s'intensifie', Mar 2026
Dakaractu, Operation Serengeti arrests, 2024
Pulse Senegal on INTERPOL 2024 Africa Cyber Threat Assessment, 2026
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇨🇲
CAMEROON
Interpol flagged
CAPITAL Yaoundé · POPULATION 28.4M (2023, UN)
FRAUD TYPES
Romance scams, advance fee, mobile money fraud
KEY FACTS
Bilingual (French/English) operators target multiple markets. Limited cybercrime enforcement.
BORN HERE
Nobody in our case files was born in Cameroon yet.
OPERATED HERE
Nobody in our case files is documented as operating from Cameroon yet.
KNOWN FOR
Online pet-sale scamsAdvance-fee fraudMobile-money fraud
THE PICTURE

The Better Business Bureau's 2017 study of online puppy scams traced many of them to Cameroon-based operators (BBB, Sep 2017). We did not find an official breakdown of fraud by type in this research pass. Cameroon is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026), and online fraud is prosecuted under Law No. 2010/012 on cybersecurity and cybercrime. It took part in INTERPOL's Operation Red Card 2.0 (Dec 2025–Jan 2026), which targeted high-yield investment, mobile-money and fraudulent loan-app scams across 16 African countries (INTERPOL, Feb 2026).

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
651 Arrests across the 16 countries (including Cameroon) in INTERPOL Operation Red Card 2.0 (INTERPOL, 18 Feb 2026)
WHO FIGHTS IT
Law No. 2010/012 of 21 December 2010 on cybersecurity and cybercrime. The national ICT agency (ANTIC) supports investigations.
Cameroon is a party to the Budapest Convention on Cybercrime.
It took part in INTERPOL Operation Red Card 2.0 (Dec 2025–Jan 2026).
SOURCES
Better Business Bureau, 'Puppy Scams' study, Sep 2017
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇧🇯
BENIN
Interpol flagged
CAPITAL Porto-Novo (official); Cotonou (seat of government) · POPULATION 14.1M (2023, UN)
FRAUD TYPES
BEC, romance scams, advance fee fraud
KEY FACTS
Part of West Africa cybercrime belt. Named alongside Nigeria/Ghana/Côte d'Ivoire by Interpol.
BORN HERE
Nobody in our case files was born in Benin yet.
OPERATED HERE
Nobody in our case files is documented as operating from Benin yet.
KNOWN FOR
Online romance and advance-fee scamsMobile-money fraudCross-border cyber-fraud
THE PICTURE

Benin has taken part in INTERPOL's two Africa-wide operations against online fraud: Operation Red Card (Nov 2024–Feb 2025), which targeted cross-border scams, and Red Card 2.0 (Dec 2025–Jan 2026), which targeted investment, mobile-money and loan-app fraud (INTERPOL, 2025–2026). INTERPOL did not publish Benin-specific arrest figures for those operations. Benin is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026). We did not find an official by-type fraud breakdown or a well-documented court case in this research pass.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
306 Arrests across seven countries, including Benin, in INTERPOL Operation Red Card (INTERPOL, 24 Mar 2025)
WHO FIGHTS IT
Digital Code (Law No. 2017-20) covers cybercrime. The police Office central de répression de la cybercriminalité (OCRC) handles cyber-fraud.
Benin is a party to the Budapest Convention on Cybercrime.
It took part in INTERPOL Operations Red Card (2025) and Red Card 2.0 (2025–2026).
SOURCES
INTERPOL, 'More than 300 arrests as African countries clamp down on cyber threats' (Operation Red Card), 24 Mar 2025
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇿🇦
SOUTH AFRICA
#7 GI-TOC (7.43)
CAPITAL Pretoria (executive); Cape Town (legislative); Bloemfontein (judicial) · POPULATION 63.2M (2023, UN)
FRAUD TYPES
Cyber fraud, identity theft, card fraud, banking trojans, ransomware victim
KEY FACTS
570,000+ suspicious transaction reports in 2024/25. 17,849 ransomware detections in 2024 — #1 in Africa. Identity fraud growing.
BORN HERE
Nobody in our case files was born in South Africa yet.
OPERATED HERE
Nobody in our case files is documented as operating from South Africa yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Corporate accounting fraudCrypto Ponzi schemesDigital-banking social engineeringCard-not-present fraudVehicle-finance application fraud
THE PICTURE

South Africa has had some of the continent's largest corporate and investment frauds. They include the Steinhoff accounting fraud, where a PwC probe found over €6.5bn in fictitious or irregular income between 2009 and 2017 (Wikipedia/PwC), the looting of VBS Mutual Bank (about R1.89bn), and the Mirror Trading International crypto Ponzi scheme, where a US court ordered $1.7bn in restitution (Wikipedia, 2023). Retail fraud is rising fast. Banks reported 97,975 digital-banking fraud incidents in 2024, up 86%, with R1.888bn in gross losses, mostly through social engineering on banking apps (SABRIC, Aug 2025). Card-not-present fraud is the main card-fraud type (SABRIC, 2025). In INTERPOL's Operation Red Card, South African police made 40 arrests and seized more than 1,000 SIM cards (INTERPOL, Mar 2025).

TOP FRAUDSTERS FROM HERE
Markus Jooste DIED BEFORE TRIALREPORT PENDING
€6.5bn+ (fictitious/irregular income, 2009–2017, per PwC) · 2009–2017
Former Steinhoff CEO at the centre of an accounting fraud that inflated profits and assets; died by suicide the day before he was due to surrender to police.
SOURCE: Wikipedia (Markus Jooste; Steinhoff International), citing PwC 2019; died 21 Mar 2024
Johann Steynberg CHARGED (NOT TRIED)REPORT PENDING
$1.7bn (restitution ordered against MTI by a US court) · 2019–2020
Founder of Mirror Trading International, which the Western Cape High Court declared a Ponzi scheme in 2023. He was charged by the US CFTC and arrested in Brazil on forged-identity charges in December 2021.
SOURCE: Wikipedia (Mirror Trading International), citing US court order of 7 Sep 2023
Tshifhiwa Matodzi CONVICTEDREPORT PENDING
R1.89bn (transferred out of the bank, 2015–2018) · 2015–2018
Former VBS Mutual Bank chairperson, jailed for an effective 15 years for fraud, racketeering, money laundering and theft over the bank's looting.
SOURCE: Wikipedia (VBS Mutual Bank), sentenced Jul 2024
FRAUD BY CATEGORY
share of gross card-fraud losses on SA-issued credit and debit cards, by fraud type (computed from published rand values in SABRIC Table 17, all countries) · 2024
Card not present
74%
Lost and/or stolen
21.6%
Counterfeit
1.7%
False application
1.6%
Account takeover
0.9%
Not received issued
0.1%
SOURCE: SABRIC, Annual Crime Statistics 2024, Aug 2025
KEY NUMBERS
97,975 Digital-banking fraud incidents in 2024 (+86%), with R1.888bn in gross losses (SABRIC, Annual Crime Statistics 2024, Aug 2025)
65.3% Share of 2024 digital-banking fraud incidents that happened on banking apps (SABRIC, Annual Crime Statistics 2024, Aug 2025)
R1.466bn Gross card-fraud losses in 2024 (+26.2%) (SABRIC, Annual Crime Statistics 2024, Aug 2025)
R23bn Potential losses from vehicle-asset-finance application fraud in 2024 (+71.1%) (SABRIC, Annual Crime Statistics 2024, Aug 2025)
WHO FIGHTS IT
Directorate for Priority Crime Investigation (the Hawks), the National Prosecuting Authority and the FSCA handle major fraud. The Cybercrimes Act 19 of 2020 covers online fraud.
South Africa has signed but not ratified the Budapest Convention.
In INTERPOL Operation Red Card (Nov 2024–Feb 2025), South Africa made 40 arrests and seized more than 1,000 SIM cards (INTERPOL, Mar 2025).
SABRIC, the banks' risk centre, publishes industry crime statistics every year.
SOURCES
SABRIC, Annual Crime Statistics 2024 (report and media statement), Aug 2025
Wikipedia: Markus Jooste; Steinhoff International; VBS Mutual Bank; Mirror Trading International (accessed Sep 2026)
INTERPOL, 'More than 300 arrests as African countries clamp down on cyber threats' (Operation Red Card), 24 Mar 2025
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇰🇪
KENYA
Interpol flagged
CAPITAL Nairobi · POPULATION 55.3M (2023, UN)
FRAUD TYPES
SIM swap fraud, mobile money fraud (M-Pesa), banking hacks, sextortion
KEY FACTS
3,030 ransomware detections (2024). 130 arrest warrants for banking fraud. 657.8M cyber threats detected Jul-Sep 2024.
BORN HERE
Nobody in our case files was born in Kenya yet.
OPERATED HERE
Nobody in our case files is documented as operating from Kenya yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Fraudulent investment schemesMobile-money fraudPublic-procurement fraudExport-compensation fraud (historic)
THE PICTURE

Kenya's best-known historic fraud is the Goldenberg scandal (1990–1993): fictitious gold and diamond exports claimed inflated export compensation, costing the state the equivalent of more than 10% of GDP. The alleged architect, Kamlesh Pattni, was cleared by the High Court in 2013 (Wikipedia). More recent enforcement centres on online investment fraud. In INTERPOL's Operation Red Card 2.0, Kenyan police made 27 arrests linked to fraudulent investment schemes (INTERPOL, Feb 2026). Kenya is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026). We did not find an official by-type fraud breakdown in this research pass.

TOP FRAUDSTERS FROM HERE
Kamlesh Pattni ACQUITTEDREPORT PENDING
KSh 5.8bn (sum at issue in the charges) · 1990–1993
Head of Goldenberg International, accused of claiming export compensation on fictitious gold and diamond exports in the Goldenberg scandal.
SOURCE: Wikipedia (Kamlesh Pattni; Goldenberg scandal); High Court cleared him, Mar 2013
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
27 Arrests linked to fraudulent investment schemes in INTERPOL Operation Red Card 2.0 (INTERPOL, 18 Feb 2026)
>10% of GDP Estimated cost of the 1990s Goldenberg export-compensation fraud (Wikipedia, Goldenberg scandal)
WHO FIGHTS IT
The Directorate of Criminal Investigations (DCI) and the Ethics and Anti-Corruption Commission lead investigations. The Computer Misuse and Cybercrimes Act 2018 covers online fraud.
Kenya is a party to the Budapest Convention on Cybercrime.
It took part in INTERPOL Operation Red Card 2.0 (Dec 2025–Jan 2026): 27 arrests.
SOURCES
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia: Goldenberg scandal; Kamlesh Pattni (accessed Sep 2026)
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇹🇿
TANZANIA
#5 Sumsub
CAPITAL Dodoma · POPULATION 66.6M (2023, UN)
FRAUD TYPES
Mobile money fraud, SIM swap, identity fraud
KEY FACTS
SIM swap spreading from Kenya. Growing digital economy. Part of East Africa fraud corridor.
BORN HERE
Nobody in our case files was born in Tanzania yet.
OPERATED HERE
Nobody in our case files is documented as operating from Tanzania yet.
KNOWN FOR
Mobile-money fraudSMS and phone impersonation scams
THE PICTURE

We found little well-sourced, country-specific public data on fraud in Tanzania in this research pass. Tanzania was not among the countries listed in INTERPOL's 2025–2026 Red Card operations, and it is not a party to the Budapest Convention (Wikipedia, 2026). Online and mobile-money fraud is prosecuted under the Cybercrimes Act 2015. We did not find an official by-type breakdown or a well-documented court case.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
The Cybercrimes Act 2015 and the Tanzania Police Force handle cyber-fraud. The Tanzania Communications Regulatory Authority (TCRA) regulates SIM registration.
Tanzania is not a party to the Budapest Convention on Cybercrime (as of May 2026).
SOURCES
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇺🇬
UGANDA
#6 Sumsub
CAPITAL Kampala · POPULATION 48.7M (2023, UN)
FRAUD TYPES
Mobile money fraud, SIM swap, investment scams
KEY FACTS
SIM swap growing. Part of East Africa cybercrime hub. Interpol Operation Serengeti arrests.
BORN HERE
Nobody in our case files was born in Uganda yet.
OPERATED HERE
Nobody in our case files is documented as operating from Uganda yet.
KNOWN FOR
Mobile-money fraudInvestment scamsLoan-app fraud
THE PICTURE

Uganda took part in INTERPOL's Operation Red Card 2.0 (Dec 2025–Jan 2026), which targeted high-yield investment scams, mobile-money fraud and fraudulent loan apps in 16 African countries (INTERPOL, Feb 2026). INTERPOL did not publish Uganda-specific results. Uganda is not a party to the Budapest Convention (Wikipedia, 2026). Online fraud is prosecuted under the Computer Misuse Act 2011. We did not find an official by-type breakdown or a well-documented court case in this research pass.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$45M Losses linked to scams exposed in INTERPOL Operation Red Card 2.0 across 16 countries, including Uganda (INTERPOL, 18 Feb 2026)
WHO FIGHTS IT
The Uganda Police Force and the Computer Misuse Act 2011 cover online fraud.
Uganda took part in INTERPOL Operation Red Card 2.0 (Dec 2025–Jan 2026).
Uganda is not a party to the Budapest Convention on Cybercrime (as of May 2026).
SOURCES
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇪🇹
ETHIOPIA
Most targeted globally (2024)
CAPITAL Addis Ababa · POPULATION 128.7M (2023, UN)
FRAUD TYPES
Malware victim, identity fraud, telecom fraud
KEY FACTS
#1 globally for malware detections in 2024 (Interpol). Rapid digitization without matching security.
BORN HERE
Nobody in our case files was born in Ethiopia yet.
OPERATED HERE
Nobody in our case files is documented as operating from Ethiopia yet.
KNOWN FOR
Bank-system exploitationMobile-banking fraud
THE PICTURE

The most widely reported recent fraud-related incident in Ethiopia was a system glitch at the state-owned Commercial Bank of Ethiopia on 15 March 2024. For several hours, customers could transfer or withdraw more money than they held, and the bank did not disclose the full loss (Wikipedia/AP, 2024). Ethiopia is not a party to the Budapest Convention (Wikipedia, 2026) and was not listed in INTERPOL's 2025–2026 Red Card operations. We did not find an official by-type breakdown or a well-documented fraud prosecution in this research pass.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
The Computer Crime Proclamation No. 958/2016 covers computer-related fraud. The Federal Police investigate cyber-fraud.
Ethiopia is not a party to the Budapest Convention on Cybercrime (as of May 2026).
SOURCES
Wikipedia, 'Commercial Bank of Ethiopia' (March 2024 glitch; AP reporting)
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇷🇼
RWANDA
#8 Sumsub
CAPITAL Kigali · POPULATION 14.0M (2023, UN)
FRAUD TYPES
Investment fraud, social engineering, mobile fraud
KEY FACTS
45 arrests in Interpol's Operation Red Card; victims lost $305K+ in 2024 and $103K was recovered. Growing fintech sector.
BORN HERE
Nobody in our case files was born in Rwanda yet.
OPERATED HERE
Nobody in our case files is documented as operating from Rwanda yet.
KNOWN FOR
Social-engineering scamsMobile-money fraudCross-border online scams
THE PICTURE

Rwanda made 45 arrests, seized 292 devices and recovered $103,043 in INTERPOL's Operation Red Card (Nov 2024–Feb 2025), which targeted cross-border online scams (INTERPOL, Mar 2025). It also took part in Red Card 2.0 (Dec 2025–Jan 2026) (INTERPOL, Feb 2026). Rwanda is a party to the Budapest Convention on Cybercrime (Wikipedia, 2026). We did not find an official by-type breakdown or a well-documented court case in this research pass.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
45 Arrests in Rwanda during INTERPOL Operation Red Card (INTERPOL, 24 Mar 2025)
$103,043 Recovered in Rwanda during Operation Red Card (INTERPOL, 24 Mar 2025)
WHO FIGHTS IT
The Rwanda Investigation Bureau (RIB) investigates cyber-fraud under Law No. 60/2018 on the prevention and punishment of cyber crimes.
Rwanda is a party to the Budapest Convention on Cybercrime.
It took part in INTERPOL Operations Red Card (2025) and Red Card 2.0 (2025–2026).
SOURCES
INTERPOL, 'More than 300 arrests as African countries clamp down on cyber threats' (Operation Red Card), 24 Mar 2025
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇿🇼
ZIMBABWE
#21 Sumsub
CAPITAL Harare · POPULATION 16.3M (2023, UN)
FRAUD TYPES
Identity fraud, mobile money fraud, Ponzi schemes
KEY FACTS
Economic instability drives fraud. Zimbabwe Gold currency scams. Limited enforcement capacity.
BORN HERE
Nobody in our case files was born in Zimbabwe yet.
OPERATED HERE
Nobody in our case files is documented as operating from Zimbabwe yet.
KNOWN FOR
Mobile-money fraudInvestment scamsGold-smuggling and laundering allegations
THE PICTURE

Zimbabwe took part in INTERPOL's Operation Red Card 2.0 (Dec 2025–Jan 2026), which targeted investment, mobile-money and loan-app fraud across 16 African countries (INTERPOL, Feb 2026). INTERPOL did not publish Zimbabwe-specific figures. Zimbabwe is not a party to the Budapest Convention (Wikipedia, 2026), and cyber-fraud falls under the Cyber and Data Protection Act 2021. We did not find an official by-type fraud breakdown or a well-documented fraud conviction in this research pass.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
The Zimbabwe Republic Police and the Zimbabwe Anti-Corruption Commission investigate fraud. The Cyber and Data Protection Act 2021 covers online fraud.
Zimbabwe took part in INTERPOL Operation Red Card 2.0 (Dec 2025–Jan 2026).
Zimbabwe is not a party to the Budapest Convention on Cybercrime (as of May 2026).
SOURCES
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇦🇴
ANGOLA
Sumsub flagged
CAPITAL Luanda · POPULATION 36.7M (2023, UN)
FRAUD TYPES
Identity fraud, oil sector corruption, investment scams
KEY FACTS
Identity fraud up 300%+ (Sumsub). Isabel dos Santos: Angola froze her assets in Dec 2019 alleging $1.14B in state losses, which she denies. Luanda Leaks (ICIJ, 2020).
DOS SANTOS: ALLEGED
BORN HERE
Nobody in our case files was born in Angola yet.
OPERATED HERE
Nobody in our case files is documented as operating from Angola yet.
KNOWN FOR
State-asset embezzlement allegationsIllegal crypto miningOnline investment scams
THE PICTURE

Angola's highest-profile fraud case concerns Isabel dos Santos, daughter of the former president. After the 2020 Luanda Leaks, Angola alleged she caused the state $1.14bn in losses through deals with Sonangol and Sodiam. INTERPOL circulated an arrest warrant in November 2022, a London court froze up to £580M of her assets in December 2023, and the UK sanctioned her in November 2024 (Wikipedia). In INTERPOL's Serengeti 2.0 operation, Angolan authorities shut 25 illegal crypto-mining centres run by 60 Chinese nationals and seized 45 illicit power stations and equipment worth more than $37M (INTERPOL, Aug 2025). Angola also took part in Red Card 2.0 (INTERPOL, Feb 2026). It is not a party to the Budapest Convention (Wikipedia, 2026).

TOP FRAUDSTERS FROM HERE
Isabel dos Santos FUGITIVEREPORT PENDING
$1.14bn (alleged losses to the Angolan state) · 2019–2024
Accused by Angolan prosecutors of diverting state funds through Sonangol and Sodiam deals using offshore companies and fraudulent invoices; she denies wrongdoing and lives outside Angola.
SOURCE: Wikipedia (Isabel dos Santos): INTERPOL warrant Nov 2022; UK High Court freezing order Dec 2023; UK sanctions 21 Nov 2024; US State Dept entry ban Dec 2021
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
25 Illegal crypto-mining centres dismantled in Angola in Operation Serengeti 2.0 (60 Chinese nationals arrested) (INTERPOL, 22 Aug 2025)
>$37M Value of power stations and mining/IT equipment confiscated in Angola (INTERPOL, 22 Aug 2025)
£580M Assets of Isabel dos Santos frozen worldwide by London's High Court (Dec 2023) (Wikipedia, citing court reporting)
WHO FIGHTS IT
The Procuradoria-Geral da República (Attorney General's Office) leads asset-recovery cases against former officials.
Angola took part in INTERPOL Serengeti 2.0 (Jun–Aug 2025) and Red Card 2.0 (Dec 2025–Jan 2026).
Angola is not a party to the Budapest Convention on Cybercrime (as of May 2026).
SOURCES
INTERPOL, 'African authorities dismantle massive cybercrime and fraud networks' (Operation Serengeti 2.0), 22 Aug 2025
INTERPOL, 'Major operation in Africa targeting online scams nets 651 arrests' (Operation Red Card 2.0), 18 Feb 2026
Wikipedia, 'Isabel dos Santos' (accessed Sep 2026)
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇲🇿
MOZAMBIQUE
Emerging
CAPITAL Maputo · POPULATION 33.6M (2023, UN)
FRAUD TYPES
Hidden debt scandal, investment fraud
KEY FACTS
$2B hidden debt scandal. Growing digital fraud. Limited cybersecurity capacity.
BORN HERE
Nobody in our case files was born in Mozambique yet.
OPERATED HERE
Nobody in our case files is documented as operating from Mozambique yet.
KNOWN FOR
Sovereign hidden-debt fraudBribery and kickbacksBank-arranged loan fraud
THE PICTURE

Mozambique was the victim of the 'tuna bonds' or hidden-debt fraud. About $2bn of state-guaranteed loans to three state companies (Proindicus, Ematum and MAM), arranged by Credit Suisse and VTB between 2013 and 2016, were kept from parliament and the IMF, and at least $200M was diverted in bribes and kickbacks (Wikipedia, 'Tuna bonds'). Former finance minister Manuel Chang was convicted in New York in August 2024 and sentenced to 8.5 years in January 2025 (Wikipedia). Credit Suisse agreed in October 2021 to pay about $475M–$500M to US, UK and Swiss authorities and to forgive $200M of Mozambique's debt (Wikipedia). In 2024 London's High Court ordered shipbuilder Privinvest to pay Mozambique about $1.9bn in damages (Wikipedia).

TOP FRAUDSTERS FROM HERE
Manuel Chang CONVICTEDREPORT PENDING
~$2bn (hidden loans) · 2013–2016
As finance minister, he signed illegal secret state guarantees for the tuna-bond loans and took bribes; convicted of wire-fraud and money-laundering conspiracy in Brooklyn.
SOURCE: Wikipedia (Manuel Chang; Tuna bonds): convicted 8 Aug 2024, sentenced 17 Jan 2025
Armando Ndambi Guebuza CONVICTEDREPORT PENDING
~$2bn (hidden-loan scheme at issue) · 2013–2016
Son of former president Armando Guebuza, convicted in Maputo of taking bribes connected to the hidden-debt loans and sentenced to 12 years.
SOURCE: Reuters, 7 Dec 2022
Jean Boustani ACQUITTEDREPORT PENDING
~$2bn (hidden loans) · 2013–2016
Privinvest executive tried in Brooklyn over kickbacks in the tuna-bond deals; the jury acquitted him in 2019.
SOURCE: Wikipedia (Tuna bonds), acquitted Dec 2019
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
~$2bn Secret state-guaranteed loans in the tuna-bond scandal ($2.2bn hidden debt uncovered in 2016) (Wikipedia, 'Tuna bonds')
≥$200M Bribes and kickbacks diverted from the loans (Wikipedia, 'Tuna bonds')
~$1.9bn Damages Privinvest was ordered to pay Mozambique by London's High Court (2024) (Wikipedia, 'Tuna bonds')
WHO FIGHTS IT
US DOJ (E.D.N.Y.) prosecutions: Manuel Chang convicted (2024); Credit Suisse bankers Andrew Pearse, Surjan Singh and Detelina Subeva pleaded guilty; Jean Boustani acquitted (2019).
Credit Suisse settled with US, UK and Swiss authorities in Oct 2021, including a guilty plea to wire fraud, and forgave $200M of Mozambique's debt.
Mozambique's Procuradoria-Geral da República prosecuted the Maputo hidden-debt trial (verdicts Dec 2022). Mozambique is a party to the Budapest Convention on Cybercrime.
SOURCES
Wikipedia: 'Tuna bonds'; 'Manuel Chang' (accessed Sep 2026)
Reuters, 7 Dec 2022 (Maputo verdicts)
Wikipedia, 'Budapest Convention on Cybercrime' (list of parties as of May 2026)
UN population estimates (1 July 2023), via Wikipedia 'List of countries by population (United Nations)'
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇮🇷
IRAN
State-backed hacking
CAPITAL Tehran · POPULATION 91.6M (2024, UN WPP est.)
FRAUD TYPES
State-sponsored hacking (Charming Kitten APT), ransomware source, cyber espionage
KEY FACTS
More source than victim. APT groups such as Charming Kitten target crypto exchanges. Hacktivism.
BORN HERE
Nobody in our case files was born in Iran yet.
OPERATED HERE
Nobody in our case files is documented as operating from Iran yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
State-bank embezzlementOil-revenue diversionRansomware extortionCrypto-enabled sanctions evasion
THE PICTURE

Iran's best-documented fraud cases are huge insider bank and oil-revenue embezzlements, including the $2.6bn Bank Saderat forged-credit scandal, for which businessman Mahafarid Amir Khosravi was executed in 2014 (RFE/RL, 2014). Iranian-based cybercriminals have also run extortion schemes abroad: in 2018 US prosecutors charged two men in Iran over SamSam ransomware, which allegedly caused more than $30M in losses (US DOJ, 2018). Iran is on the FATF blacklist, and its crypto exchanges are now a focus of sanctions. In June 2026 OFAC sanctioned Nobitex and three other exchanges that together moved at least $40bn, citing sanctions evasion and payments linked to the IRGC and ransomware (Elliptic/Chainalysis, June 2026). Enforcement at home depends on the judiciary and the FATA cyber police, and has included death sentences for large-scale economic crimes.

TOP FRAUDSTERS FROM HERE
Babak Zanjani CONVICTEDREPORT PENDING
~$3bn (oil revenue not repaid, as reported; ~$2.1bn in assets later returned) · 2013–2024
Oil-sales middleman who failed to hand over billions in oil revenue he handled for the state while getting around sanctions; sentenced to death, which was later commuted.
SOURCE: Iran International, 30 Apr 2024
Mahafarid Amir Khosravi CONVICTEDREPORT PENDING
$2.6bn (fraudulent bank credit) · 2007–2011
Used forged documents to obtain credit from Bank Saderat and other lenders and used it to buy state-owned companies. It was Iran's largest fraud since 1979.
SOURCE: RFE/RL, 24 May 2014
Faramarz Shahi Savandi FUGITIVEREPORT PENDING
$6M+ ransom collected; $30M+ victim losses (per indictment) · 2015–2018
Charged with deploying SamSam ransomware from inside Iran against hospitals, cities and public bodies.
SOURCE: US DOJ, 28 Nov 2018
Mohammad Mehdi Shah Mansouri FUGITIVEREPORT PENDING
$6M+ ransom collected; $30M+ victim losses (per indictment) · 2015–2018
Co-defendant charged in the SamSam ransomware campaign against more than 200 victims.
SOURCE: US DOJ, 28 Nov 2018
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$2.6bn Bank Saderat forged-credit scandal, the largest fraud case since 1979 (RFE/RL, May 2014)
$40bn+ Crypto moved by Nobitex, Wallex, Bitpin and Ramzinex (OFAC-sanctioned June 2026) (Elliptic, June 2026)
200+ SamSam ransomware victims (US indictment) (US DOJ, Nov 2018)
~$2.1bn Assets Babak Zanjani returned before his sentence was commuted (Iran International, Apr 2024)
WHO FIGHTS IT
Judiciary and Revolutionary Courts have given death sentences for large economic crimes (Khosravi, executed 2014; Zanjani, commuted to 20 years in 2024).
FATA cyber police (set up 2011) handles online fraud and phishing cases.
External pressure: FATF blacklist; US DOJ indictments (SamSam, 2018); OFAC sanctions on Iranian crypto exchanges (June 2026) and on the Shelbit/Aban Tether network (Aug 2026).
SOURCES
US DOJ press release, 28 Nov 2018
RFE/RL, 24 May 2014
Iran International, 30 Apr 2024
Elliptic, OFAC sanctions Nobitex, June 2026
US Treasury press release sb0598, 7 Aug 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇮🇱
ISRAEL
#1 MENA target
CAPITAL Jerusalem (disputed; most embassies are in Tel Aviv) · POPULATION 9.4M (2024, UN WPP est.)
FRAUD TYPES
Target of hacktivism, cybercrime victim, but also crypto fraud source
KEY FACTS
33–38% of MENA cyberattacks target Israel. Also a past source: the binary-options industry, banned by the Knesset in Oct 2017, took an estimated $1B–$10B a year (Times of Israel).
BORN HERE
Nobody in our case files was born in Israel yet.
OPERATED HERE
Nobody in our case files is documented as operating from Israel yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Binary-options boiler roomsFake forex/crypto brokersCEO / fake-minister impersonation fraudRomance fraud
THE PICTURE

Israel was the hub of the global binary-options and fake-forex boiler-room industry of the 2010s. Israeli-run call centres at home and in Bulgaria, Serbia, Cyprus and Ukraine took money from victims worldwide, and the Knesset banned binary options outright in October 2017 (Haaretz, 2017). US and European courts have since convicted the industry's leaders, including Yukom CEO Lee Elbaz (22 years, US, 2019) and Gal Barak (4 years, Vienna, 2020). In 2025 an OCCRP-led 'Scam Empire' investigation reported that call centres in Israel, Europe and Georgia took about $275M from would-be investors between 2021 and 2025 (OCCRP partners, 2025; allegations). Israeli nationals were also behind the CEO/'fake minister' impersonation fraud in France (Chikli, 2020).

TOP FRAUDSTERS FROM HERE
Gal Barak CONVICTEDREPORT PENDING
€200M+ (investor losses, 30,000+ victims) · 2016–2019
Ran E&G Bulgaria, a network of fake binary-options and forex platforms (XtraderFX, SafeMarkets, OptionStars) with boiler rooms in Sofia and Belgrade.
SOURCE: Balkan Insight / EFRI, Sept–Oct 2020
Lee Elbaz CONVICTEDREPORT PENDING
$145M (scheme losses); $28M restitution · 2014–2017
CEO of Yukom Communications, whose BinaryBook and BigOption brands lied to investors about binary options.
SOURCE: Times of Israel, 20 Dec 2019
Gilbert Chikli CONVICTEDREPORT PENDING
~€55M (taken from 3 victims; ~€80M total attempted/obtained) · 2015–2017
Masterminded the scam in which a man in a silicone mask posed as French minister Jean-Yves Le Drian to get wealthy targets to pay 'hostage ransoms'.
SOURCE: CNN / France 24, 11–12 Mar 2020
Tal Prihar PLEADED GUILTYREPORT PENDING
$8.4M (kickbacks forfeited) · 2013–2019
Ran DeepDotWeb, which took kickbacks for referring users to darknet markets, and laundered the proceeds.
SOURCE: US DOJ, Jan 2022
Shimon Hayut CONVICTEDREPORT PENDING
NIS 150,000 (restitution ordered in Israel) · 2017–2019
The 'Tinder Swindler', who posed as the son of a diamond magnate to get money from women he met on dating apps; convicted in Israel of fraud under a plea deal.
SOURCE: Times of Israel, Dec 2019
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
Oct 2017 Knesset bans binary options (Amendment 66, Securities Law) (Haaretz / Globes, Oct 2017)
$145M Losses in the Yukom (BinaryBook/BigOption) fraud (US DOJ via Times of Israel, 2019)
$275M Deposits taken by call-centre groups in Israel, Europe and Georgia, 2021–2025 (alleged) (OCCRP 'Scam Empire' partners, Mar 2025)
22 years Lee Elbaz's US sentence (Times of Israel, Dec 2019)
WHO FIGHTS IT
Israel Securities Authority pushed through the 2017 ban; working in the industry carries up to two years in prison.
Lahav 433 (national serious-crime unit) and its cyber sub-unit investigate large fraud and laundering cases.
Many prosecutions happen abroad through extradition: US (Maryland Yukom case, 2018–2019), Austria (Barak, 2020), France (Chikli, 2020), Germany.
SOURCES
Haaretz, 24 Oct 2017
Times of Israel, 20 Dec 2019
Balkan Insight, 19 Oct 2020
EFRI, 2020
CNN, 12 Mar 2020
US DOJ, Jan 2022
Times of Israel, Dec 2019
OCCRP Scam Empire / Financial Mirror, Mar 2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇦🇪
UAE
#2 MENA target
CAPITAL Abu Dhabi · POPULATION 11.0M (2024, UN WPP est.)
FRAUD TYPES
Money laundering hub, crypto fraud, real estate fraud, scam compound presence
KEY FACTS
$2.9M average cost per cyber incident. Payment fraud loss $884 per consumer (up 270%). Scam compounds reported in the UAE.
BORN HERE
Nobody in our case files was born in UAE yet.
OPERATED HERE
Physically based or working in UAE — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Abu Dhabi, United Arab Emirates
WHAT THEY DID HERE, AND WHEN
2012–2013Deals with Aabar/IPIC executives through which, prosecutors say, 1MDB bond money was diverted.SOURCE: DOJ (alleged)
Dubai, United Arab Emirates
WHAT THEY DID HERE, AND WHEN
2019–2023Lives in Dubai and runs Binance from there; the DOJ says the exchange failed to run an anti-money-laundering programme in these years.SOURCE: DOJ plea agreement, Nov 2023
Dubai, United Arab Emirates
WHAT THEY DID HERE, AND WHEN
2015–2017OneCoin's Dubai base for events and money; a penthouse and company entities in the emirate.SOURCE: BBC The Missing ; DOJ
United Arab Emirates
WHAT THEY DID HERE, AND WHEN
2021–2024Also lives in the UAE, according to the DOJ, while directing the laundering network.SOURCE: DOJ
Dubai, United Arab Emirates
WHAT THEY DID HERE, AND WHEN
c.2017–2020Runs the business-email-compromise laundering network from a Palazzo Versace apartment; the FBI affidavit ties his phone and email to the accounts.SOURCE: FBI complaint, C.D. Cal. 2:20-cr-00322
Feb 2019Supplies bank accounts to receive ~$14.7M moved from a foreign bank (Forbes links it to Bank of Valletta, Malta).SOURCE: FBI affidavit; Forbes
June 2020Dubai Police raid the apartment in Operation Fox Hunt 2: ~$40M in cash, 13 cars, 21 laptops, 47 phones seized. Flown to the US on 3 July 2020.SOURCE: Dubai Police; DOJ
OUR CASES BY CATEGORY
Share of the 5 cases tied to UAE (born or operated here)
LAUNDERING
40%
CRYPTO
40%
BANK & WIRE
20%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Fugitive haven / laundering hubBusiness email compromise networksInvestment and crypto scam call centresPhishing / vishing / smishing
THE PICTURE

The UAE, and Dubai in particular, is both a base and a refuge for international fraudsters and a laundering route for their proceeds. It was on the FATF grey list from March 2022 to February 2024 (FATF, 2024). Dubai Police's 2020 'Fox Hunt 2' operation arrested Nigerian BEC figures Ramon '' Abbas and Olalekan Ponle, both later convicted in the US. The UAE also extradited Sanjay Shah, Denmark's biggest tax fraudster, in 2023, although a Dubai court refused South Africa's request for the Gupta brothers. The UAE FIU estimated domestic fraud losses at AED 1.2bn (~$326M) for 2021–2023 and named vishing, phishing and smishing as the top types (UAE FIU, 2024). In April 2026 a Dubai Police–FBI operation shut nine scam centres and made 276 arrests, many of them trafficked workers (US DOJ, 2026).

TOP FRAUDSTERS FROM HERE
Sanjay Shah CONVICTEDREPORT PENDING
~DKK 8–9bn (~$1.2–1.3bn) (tax refunds claimed) · 2012–2015
Dubai-based British hedge-fund founder whose Solo Capital network filed fraudulent cum-ex dividend-tax refund claims in Denmark; extradited from Dubai in 2023.
SOURCE: The National, 12 Dec 2024
Atul Gupta CHARGED (NOT TRIED)REPORT PENDING
Not quantified in extradition case (Nulane contract fraud charge) · 2010s
Accused in South Africa's state-capture corruption cases; arrested in Dubai in 2022, but a Dubai court refused extradition in 2023.
SOURCE: Al Jazeera, 7 Apr 2023
Rajesh Gupta CHARGED (NOT TRIED)REPORT PENDING
Not quantified in extradition case · 2010s
Co-accused with his brother Atul in the state-capture cases; UAE extradition refused in 2023.
SOURCE: Al Jazeera, 7 Apr 2023
Olalekan Jacob Ponle PLEADED GUILTYREPORT PENDING
$8M (BEC proceeds) · 2019–2020
'Mr Woodberry', arrested in Dubai with ; ran BEC/phishing that diverted company payments.
SOURCE: The National, 19 Jul 2023
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
AED 1.2bn (~$326M) Estimated fraud losses in the UAE, 2021–2023 (UAE FIU Strategic Analysis Report, 2024)
276 Arrests in the Dubai Police–FBI scam-centre takedown (9 centres) (US DOJ, 29 Apr 2026)
Mar 2022–Feb 2024 Period on the FATF grey list (FATF / Norton Rose Fulbright, Feb 2024)
AED 150M Seized in the Fox Hunt 2 raids (/Woodberry) (The National, 2020)
WHO FIGHTS IT
Dubai Police (eCrime platform) and the UAE Financial Intelligence Unit (goAML). Landmark operations: Fox Hunt 2 (June 2020) and the joint FBI scam-centre takedown (April 2026).
AML reforms led to FATF grey-list exit in February 2024, but the EU kept the UAE on its high-risk list until at least 2025.
Extradition record is mixed: Sanjay Shah to Denmark (2023), and Ponle to the US (2020), Gupta request refused (2023).
SOURCES
FATF / Norton Rose Fulbright, Feb 2024
UAE FIU Organized Financial Fraud report, 2024
US DOJ, 29 Apr 2026
US DOJ CDCA, 7 Nov 2022
The National, 19 Jul 2023
The National, 12 Dec 2024
Al Jazeera, 7 Apr 2023
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇸🇦
SAUDI ARABIA
#3 MENA
CAPITAL Riyadh · POPULATION 34.0M (2024, UN WPP est.)
FRAUD TYPES
Ransomware victim, identity theft victim, improving enforcement
KEY FACTS
CPI score rose 7 points to 59/100 (2024). Investing heavily in cybersecurity, but a growing ransomware target.
BORN HERE
Nobody in our case files was born in Saudi Arabia yet.
OPERATED HERE
Nobody in our case files is documented as operating from Saudi Arabia yet.
KNOWN FOR
Bank/government impersonation call fraudMoney-laundering rings using commercial frontsFake property and investment dealsPublic-sector corruption (Nazaha cases)
THE PICTURE

Fraud reported in Saudi Arabia is mostly domestic. It includes phone and SMS fraud by callers posing as banks or government agencies, fake property deals, and large laundering rings using commercial fronts. In 2021 a court jailed 24 people, for up to 20 years each, for laundering SR17bn (~$4.5bn) through factories, clinics and companies (Arab News, 2021). In 2024 two expatriates got 15 years for a call-centre fraud that took SR22M in 177 operations (Saudi Gazette, 2024). In December 2025 an 11-member ring was jailed for a combined 155 years for fake property scams worth about SR40M (Gulf News, 2025). The Public Prosecution says reported fraud comes from misuse of victims' personal data, not system breaches (SPA, 2024). The 2017 Ritz-Carlton anti-corruption campaign recovered about $106bn in settlements but was widely criticised as extra-judicial.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
SR17bn (~$4.5bn) Laundered by a 24-member ring, sentenced 2021 (Arab News, 14 Sep 2021)
~$106.6bn Settlements from the 2017–2019 Ritz-Carlton anti-corruption campaign (Al Jazeera / Gulf News, Jan 2019)
SR22M / 177 operations Call-centre impersonation fraud (2 expats, 15 years each) (Saudi Gazette, 2024)
155 years Combined sentences for an 11-member property-fraud ring (SR40M) (Gulf News, 29 Dec 2025)
WHO FIGHTS IT
Public Prosecution and the Anti-Fraud Prosecution unit; SAMA Counter-Fraud Rulebook requirements for banks.
Nazaha (Oversight and Anti-Corruption Authority) runs monthly arrest campaigns against public officials.
Anti-Money Laundering Law (2017) and Anti-Fraud and Breach of Trust law. 2017 Ritz-Carlton detentions: 381 people summoned, 87 settlements.
SOURCES
Arab News, 14 Sep 2021
Saudi Gazette, 2024
Gulf News, 29 Dec 2025
SPA (Saudi Press Agency), 2024
Al Jazeera, 30 Jan 2018
Gulf News, Jan 2019
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇹🇷
TURKEY
Top MENA ransomware target
CAPITAL Ankara · POPULATION 87.5M (2024, UN WPP est.)
FRAUD TYPES
Ransomware victim, crypto fraud, call center scams
KEY FACTS
Most ransomware-targeted country in the Middle East (CloudSEK). GI-TOC criminality score 7.20.
BORN HERE
Nobody in our case files was born in Turkey yet.
OPERATED HERE
Nobody in our case files is documented as operating from Turkey yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Crypto exchange collapsesOnline Ponzi schemesIllegal online betting networksSanctions-evasion money laundering
THE PICTURE

Turkey has had some of the largest retail-investor collapses in the region. The Thodex crypto exchange shut in April 2021, locking about 400,000 users out of their funds; its founder got 11,196 years in 2023 and died in prison in 2025 (Decrypt, 2025; Turkish Minute, 2025). The Çiftlik Bank farm-game Ponzi led to 45,376-year sentences in February 2025 (The National, 2025). Turkish figures also appear in cross-border cases, including the Halkbank/Zarrab Iran sanctions-evasion scheme prosecuted in New York and the $133M Washakie biodiesel laundering case in Utah. The Interior Ministry and gendarmerie regularly raid illegal-betting and online-fraud networks moving billions of lira (Hürriyet Daily News, 2024). Turkey left the FATF grey list in June 2024.

TOP FRAUDSTERS FROM HERE
Faruk Fatih Özer CONVICTEDREPORT PENDING
~$2bn reported user deposits frozen (media estimate); indictment damages TRY 356M (~$43M) · 2017–2021
Founder of the Thodex crypto exchange, which shut suddenly in 2021 and left users unable to withdraw; fled to Albania, was extradited and died in prison in November 2025.
SOURCE: Decrypt / Turkish Minute, 2025
Reza Zarrab PLEADED GUILTYREPORT PENDING
Billions of dollars (Iranian oil proceeds moved) · 2010–2016
Turkish-Iranian gold trader who laundered Iranian oil money through Halkbank as fake gold and food trades; became a cooperating witness.
SOURCE: OCCRP / Courthouse News, Jul 2026
Mehmet Hakan Atilla CONVICTEDREPORT PENDING
Billions of dollars (sanctions-evasion scheme) · 2012–2016
Former Halkbank deputy general manager convicted of helping Iran evade US sanctions.
SOURCE: US DOJ SDNY, Jan 2018
Sezgin Baran Korkmaz CHARGED (NOT TRIED)REPORT PENDING
$133M+ (alleged laundering) · 2013–2018
Turkish businessman accused of laundering proceeds of the Kingston family's $1bn+ Washakie biodiesel tax-credit fraud through accounts in Turkey and Luxembourg.
SOURCE: US DOJ D. Utah, Jul 2022
Mehmet Aydın CONVICTEDREPORT PENDING
Undisclosed (thousands of investors) · 2016–2018
Founder of Çiftlik Bank, an online 'farm' investment game that ran as a Ponzi scheme; fled to Brazil, returned 2021.
SOURCE: The National, 3 Feb 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
~400,000 Thodex users unable to withdraw when the exchange shut (April 2021) (Decrypt, 2025)
11,196 years Sentence for the Thodex founder and two siblings (Sept 2023) (Ubergizmo / Decrypt, 2023)
45,376 years Sentence for the Çiftlik Bank founder (Feb 2025) (The National, Feb 2025)
TRY 3.6bn Money flows linked to 35 suspects in one gendarmerie fraud/betting sweep (Hürriyet Daily News, 2024)
WHO FIGHTS IT
Turkish Penal Code arts. 157–158 (aggravated fraud, including via IT systems or banks); cybercrime departments of the police (EGM) and gendarmerie.
MASAK (financial intelligence unit); crypto-asset service provider law of 2024; FATF grey-list exit in June 2024.
Major operations: Thodex extradition from Albania (2023), repeated illegal-betting and online-fraud raids under Interior Minister Yerlikaya (2024–2025).
SOURCES
Decrypt, Jan 2025
Turkish Minute, 1 Nov 2025
The National, 3 Feb 2025
US DOJ SDNY, Jan 2018
Courthouse News / OCCRP, Jul 2026
US DOJ D. Utah, 2022
Hürriyet Daily News, 2024
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇪🇬
EGYPT
Interpol flagged
CAPITAL Cairo · POPULATION 116.5M (2024, UN WPP est.)
FRAUD TYPES
Ransomware victim, identity fraud, BEC participation
KEY FACTS
12,281 ransomware detections (2024) — #2 in Africa. Part of MENA cybercrime growth.
BORN HERE
Nobody in our case files was born in Egypt yet.
OPERATED HERE
Nobody in our case files is documented as operating from Egypt yet.
KNOWN FOR
App-based Ponzi / cloud-mining scams'Islamic investment' Ponzi schemesPublic-fund embezzlementOnline romance and marketplace fraud
THE PICTURE

Egypt keeps seeing Ponzi-style 'investment' schemes, from the 1980s Islamic investment companies to app-based crypto platforms. Ahmed al-Rayan's company drew more than 200,000 depositors before collapsing, and he was jailed in 1989 (Egyptian Streets, 2022). In 2023 police arrested 29 people, including 13 foreigners, behind the HoggPool cloud-mining app, which took about EGP 19M (Ministry of Interior / CBS, 2023). In 2025 police arrested 13 people over the FBC app, a referral Ponzi said to be led by foreign nationals, with loss estimates varying widely (Ahram Online, 2025). Grand corruption cases include the 2015–2016 'presidential palaces' embezzlement conviction of Hosni Mubarak and his sons.

TOP FRAUDSTERS FROM HERE
Ahmed al-Rayan CONVICTEDREPORT PENDING
~EGP 6bn (deposits held by mid-1980s) · 1980s
Ran an 'Islamic investment' company that paid old depositors with new deposits, promising far more than bank rates, until it collapsed.
SOURCE: Egyptian Streets, 22 Sep 2022
Hosni Mubarak CONVICTEDREPORT PENDING
EGP 125M (public funds embezzled) · 2002–2011
Former president convicted with his sons of diverting state money meant for presidential palaces to private family properties.
SOURCE: OCCRP / Egypt Independent, 2015–2016
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
EGP 19M (~$615k) Taken by the HoggPool cloud-mining scam; 29 arrested (13 foreigners) (Egypt Ministry of Interior via EgyptToday, Mar 2023)
200,000+ Depositors in al-Rayan's 1980s investment scheme (Egyptian Streets, 2022)
13 Arrested in the FBC app Ponzi case (1,135 SIM cards seized) (Ahram Online, 2025)
WHO FIGHTS IT
Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes; Ministry of Interior cybercrime units.
Public Prosecution and the Money Laundering and Terrorist Financing Combating Unit (EMLCU); Central Bank of Egypt licensing of payment and crypto activity.
Took part in INTERPOL Operation Ramz, the first MENA-wide cybercrime operation (Oct 2025 – Feb 2026).
SOURCES
Egyptian Streets, 22 Sep 2022
Library of Congress Global Legal Monitor, 30 Mar 2023
EgyptToday, Mar 2023
Ahram Online, 2025
OCCRP, May 2015
Egypt Independent, Jan 2016
INTERPOL, 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇲🇦
MOROCCO
Interpol flagged
CAPITAL Rabat · POPULATION 38.1M (2024, UN WPP est.)
FRAUD TYPES
Phishing, identity fraud, call center scams
KEY FACTS
5% of MENA cyberattacks. Part of North Africa fraud ecosystem. Operation Ramz participant.
BORN HERE
Nobody in our case files was born in Morocco yet.
OPERATED HERE
Nobody in our case files is documented as operating from Morocco yet.
KNOWN FOR
SextortionGift-card fraud (Storm-0539 / Atlas Lion)Phishing and carding kitsCard fraud
THE PICTURE

Morocco-based groups are tied to two well-documented types of online fraud. The first is webcam sextortion aimed at foreigners, concentrated around the town of Oued Zem (Morocco World News, 2019). The second is corporate gift-card theft: Microsoft and the FBI say the Morocco-based group Storm-0539 ('Atlas Lion') has stolen up to $100,000 a day from some retailers (Microsoft, 2024). INTERPOL, Group-IB and Moroccan police arrested the phishing and carding-kit seller 'Dr Hex' in 2021 (Operation Lyrebird). Morocco also took part in the MENA-wide Operation Ramz, which led to 201 arrests across 13 countries (INTERPOL, 2026). Morocco left the FATF grey list in February 2023.

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
Up to $100,000/day Stolen from some targeted retailers by Storm-0539 (Microsoft Cyber Signals, May 2024)
30% Rise in Storm-0539 intrusion activity, Mar–May 2024 (Microsoft, May 2024)
134 Websites attacked by 'Dr Hex', 2009–2018 (INTERPOL, Jul 2021)
500+ Victims of one El Jadida sextortion suspect tried in 2019 (Morocco World News, Jun 2019)
WHO FIGHTS IT
DGSN (national police) cybercrime units; Penal Code provisions on extortion and computer crime.
INTERPOL cooperation: Operation Lyrebird (arrest of 'Dr Hex', Jul 2021), Operation Ramz (Oct 2025 – Feb 2026), Operation First Light 2026.
Bank Al-Maghrib tracks card and cheque fraud and tightened payment-security oversight in 2024; ANRF is the financial intelligence unit.
SOURCES
Microsoft Cyber Signals Issue 7, May 2024
The Record, May 2024
INTERPOL, 2021
INTERPOL, 2026
Morocco World News, 2019 and 2026
Bank Al-Maghrib, 2024
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇮🇶
IRAQ
Interpol flagged
CAPITAL Baghdad · POPULATION 46.0M (2024, UN WPP est.)
FRAUD TYPES
Investment scams, telecom fraud, identity fraud
KEY FACTS
Part of MENA cybercrime growth. Limited enforcement capacity. Geopolitical instability.
BORN HERE
Nobody in our case files was born in Iraq yet.
OPERATED HERE
Nobody in our case files is documented as operating from Iraq yet.
KNOWN FOR
Public-fund embezzlementTax-deposit theftDollar-auction laundering and smugglingBank fronts for militia finance
THE PICTURE

Iraq's largest documented frauds involve the theft of public money through the banking system. In the 2021–2022 'heist of the century', 247 cheques drained 3.7 trillion dinars (~$2.5bn) of tax deposits from the General Tax Authority's account at Rafidain Bank (The National, 2024). Businessman Nour Zuhair Jassim and senior officials were sentenced in absentia in November 2024. In 2023–2024 the US cut 14 and then 8 more Iraqi banks off from the central bank's dollar auction over money laundering and dollar smuggling to Iran. In 2024 FinCEN named Al-Huda Bank a primary money-laundering concern (FinCEN, 2024). FATF added Iraq to its grey list in June 2026.

TOP FRAUDSTERS FROM HERE
Nour Zuhair Jassim CONVICTEDREPORT PENDING
~$2.5bn (IQD 3.7tn stolen); ~$125M returned · 2021–2022
Businessman who ran the scheme in which fake cheques drained the tax authority's deposits; released on bail in 2022 after returning part of the money.
SOURCE: The National, 25 Nov 2024
Raed Jouhi CONVICTEDREPORT PENDING
~$2.5bn (overall scheme) · 2021–2022
Former director of the prime minister's office, sentenced in absentia in the tax-deposit theft.
SOURCE: The National, 25 Nov 2024
Haitham al-Jubouri CONVICTEDREPORT PENDING
~$2.5bn (overall scheme) · 2021–2022
Former MP and head of parliament's finance committee, sentenced in absentia in the same case.
SOURCE: The National, 25 Nov 2024
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
~$2.5bn Stolen in the 2021–2022 tax-deposit 'heist of the century' (The National, Nov 2024)
22 Iraqi banks barred from the dollar auction (14 in Jul 2023, 8 in Feb 2024) (Al Jazeera / The New Arab, 2023–2024)
Aug 2024 FinCEN Section 311 final rule cutting Al-Huda Bank off from the US system (FinCEN, Jul 2024)
Jun 2026 Iraq added to the FATF grey list (FATF plenary outcomes, 19 Jun 2026)
WHO FIGHTS IT
Federal Commission of Integrity and Karkh/Rusafa criminal courts. Many top defendants have been convicted in absentia.
Central Bank of Iraq with the US Treasury and New York Fed: dollar-auction restrictions (2023–2024) and the FinCEN 311 action against Al-Huda Bank (2024).
Took part in INTERPOL Operation Ramz (Oct 2025 – Feb 2026).
SOURCES
The National, 25 Nov 2024 and 6 Dec 2024
Iraq Business News, 28 Nov 2024
FinCEN / Federal Register, 3 Jul 2024
Al Jazeera, 27 Jul 2023
The New Arab, Feb 2024
FATF, Jun 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇱🇧
LEBANON
GI-TOC 7.30
CAPITAL Beirut · POPULATION 5.8M (2024, UN WPP est.)
FRAUD TYPES
Financial fraud, Ponzi schemes, money laundering, crypto fraud
KEY FACTS
GI-TOC criminality score 7.30. The collapse of the financial system drove an increase in fraud. The US Treasury has sanctioned Hezbollah's Al-Qard Al-Hassan financial network.
BORN HERE
Nobody in our case files was born in Lebanon yet.
OPERATED HERE
Nobody in our case files is documented as operating from Lebanon yet.
KNOWN FOR
Central-bank 'Ponzi finance' collapsePublic-fund embezzlement (alleged)Trade-based and drug money launderingFugitive haven (no extradition of nationals)
THE PICTURE

The World Bank called Lebanon's pre-2019 financial model a 'Ponzi finance' scheme. The central bank attracted deposits with interest rates as high as 20%, and after the system collapsed in 2019 depositors lost around 80% of their savings' value, about $70bn (World Bank, 2022). Former central-bank governor Riad Salameh was charged in 2024 with embezzling at least $42M. He was released on a record bail in September 2025 and re-arrested in August 2026 in a new case (The National, 2025–2026), and he denies all allegations. Lebanon has also been a channel for drug-money laundering, notably through the Lebanese Canadian Bank network of Ayman Joumaa (US DOJ, 2011). FATF put Lebanon on its grey list in October 2024.

TOP FRAUDSTERS FROM HERE
Ayman Joumaa FUGITIVEREPORT PENDING
$850M+ (laundered, per indictment) · 2000s–2011
Accused of running a network that laundered Zetas cartel drug money through the Lebanese Canadian Bank and front companies.
SOURCE: US DOJ EDVA, 13 Dec 2011
Riad Salameh CHARGED (NOT TRIED)REPORT PENDING
$42M+ (alleged embezzlement, Optimum case); $330M alleged in Forry probe · 2002–2018
Ex-central bank governor accused of embezzling central-bank funds through the Optimum Invest and Forry Associates brokerages; denies wrongdoing.
SOURCE: The National, 26 Sep 2025
Carlos Ghosn FUGITIVEREPORT PENDING
~€15M (alleged suspect payments, French case) · 2009–2018
Ex-Nissan chairman who skipped bail in Japan in 2019 and fled to Lebanon; wanted in Japan for financial misconduct and in France over ~€15M in suspect payments.
SOURCE: The National, 19 May 2022
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
~$70bn Estimated financial-system losses; deposits lost ~80% of value (World Bank 'Ponzi Finance?' report, Aug 2022)
$14M Record bail posted by Riad Salameh (Sept 2025) (The National / AFP, Sep 2025)
Oct 2024 Lebanon added to the FATF grey list (FATF, 25 Oct 2024)
WHO FIGHTS IT
Special Investigation Commission (financial intelligence unit at Banque du Liban); Beirut investigating judges and the financial prosecutor.
European probes (France, Germany, Luxembourg, Switzerland) into Salameh-linked assets; about $92M in property frozen.
US actions: Section 311 finding against the Lebanese Canadian Bank (2011; $102M settlement) and Kingpin Act designations of the Joumaa network (2011).
SOURCES
World Bank press release, 2 Aug 2022
The National, 26 Sep 2025 and 1 Aug 2026
TIMEP, 26 Sep 2025
US DOJ EDVA, 13 Dec 2011
DEA, 26 Jan 2011
FATF, 25 Oct 2024
The National, 19 May 2022
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇯🇴
JORDAN
MENA target
CAPITAL Amman · POPULATION 11.6M (2024, UN WPP est.)
FRAUD TYPES
Ransomware victim, phishing, identity fraud
KEY FACTS
6% of MENA cyberattacks. Operation Ramz participant. Growing digital economy.
BORN HERE
Nobody in our case files was born in Jordan yet.
OPERATED HERE
Nobody in our case files is documented as operating from Jordan yet.
KNOWN FOR
Customs and tax evasion (counterfeit tobacco)Embezzlement of state enterprisesFake trading platformsPrize and aid impersonation scams
THE PICTURE

Jordan's biggest fraud cases involve tax and customs evasion and the embezzlement of state assets. In 2021 the State Security Court jailed tobacco magnate Awni Mutee and two others for 22 years each over a counterfeit-cigarette operation that cost the treasury about JD179M in unpaid taxes and duties (Jordan Times, 2021). In 2022 Walid al-Kurdi, a former Jordan Phosphate Mines chairman, was sentenced in absentia to 18 years and fined JD191M (Petra, 2022). Online, the Public Security Directorate's cybercrime unit warns about fake-prize and fake-trading-platform scams. During INTERPOL Operation Ramz, Jordanian police raided a fake trading platform staffed by 15 trafficked workers from Asia (INTERPOL, 2026). Jordan left the FATF grey list in October 2023.

TOP FRAUDSTERS FROM HERE
Majed Shamayleh CONVICTEDREPORT PENDING
JD350M (~$493M) (fraudulent loans) · 1994–2002
Businessman who admitted using forged documents to obtain bank loans in what was then Jordan's largest bank fraud.
SOURCE: Al Jazeera, 6 Sep 2003
Awni Mutee CONVICTEDREPORT PENDING
JD179M (~$252M) (unpaid taxes/customs, per court) · 2006–2018
Ran a counterfeit-cigarette manufacturing and smuggling operation that evaded taxes and customs duties.
SOURCE: Jordan Times, 29 Sep 2021
Walid al-Kurdi FUGITIVEREPORT PENDING
JD191M (~$269M) (fine) · 2006–2012
Former Jordan Phosphate Mines chairman convicted in absentia of corruption and abuse of office; living abroad.
SOURCE: Petra / Jordan Times, 27 Apr 2022
Mohammed al-Dahabi CONVICTEDREPORT PENDING
JD24M (~$34M) (embezzled) · 2005–2012
Former intelligence chief convicted of embezzling public funds and money laundering.
SOURCE: Times of Israel / RIA, 11 Nov 2012
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
JD179M Treasury losses in the 'tobacco case' (Jordan Times, Sep 2021)
29 defendants / 25 companies Scale of the tobacco case trial (Jordan Times, 2021)
15 Trafficked workers found staffing a fake trading-platform scam in Jordan (INTERPOL Operation Ramz, 2026)
WHO FIGHTS IT
Integrity and Anti-Corruption Commission; State Security Court and anti-corruption judicial panels (Amman Court of First Instance).
Public Security Directorate Anti-Cyber Crimes Unit (hotline 191); Cybercrime Law of 2023.
INTERPOL Operation Ramz (Oct 2025 – Feb 2026): two suspected organisers arrested in the fake-trading raid.
SOURCES
Jordan Times, 29 Sep 2021
Petra, 27 Apr 2022
OCCRP, 2022
Al Jazeera, 6 Sep 2003
Times of Israel, 11 Nov 2012
INTERPOL, 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇶🇦
QATAR
MENA target
CAPITAL Doha · POPULATION 3.0M (2024, UN WPP est.)
FRAUD TYPES
Ransomware victim, targeted by hacktivism
KEY FACTS
Growing target due to digitization. 2022 World Cup drove phishing spike. Improving CPI score (59/100).
BORN HERE
Nobody in our case files was born in Qatar yet.
OPERATED HERE
Nobody in our case files is documented as operating from Qatar yet.
KNOWN FOR
Grand corruption / public-fund launderingSports-governance bribery allegationsPhishing and cyber fraudInfluence-buying allegations (Qatargate)
THE PICTURE

Qatar's best-documented financial-crime cases are corruption and money-laundering cases involving senior officials. They are led by the January 2024 conviction of former finance minister Ali Sharif Al Emadi, who was jailed for 20 years for laundering more than $5.6bn and fined over QAR 61bn (Doha News, 2024). Qatari figures have also been named in foreign sports and political corruption probes. Swiss courts acquitted beIN/PSG chairman Nasser Al-Khelaifi three times in the FIFA TV-rights case. Belgian prosecutors' 2022 'Qatargate' investigation alleges that Qatar paid for influence at the European Parliament, which Qatar denies. At retail level, INTERPOL Operation Ramz found that Qatari devices had been compromised and used to spread malicious threats (INTERPOL, 2026).

TOP FRAUDSTERS FROM HERE
Ali Sharif Al Emadi CONVICTEDREPORT PENDING
$5.6bn+ (laundered); QAR 61bn+ (~$16.7bn) fines · 2013–2021
Former finance minister convicted of bribery, abuse of office, damaging public funds and money laundering.
SOURCE: Doha News, 18 Jan 2024
Nasser Al-Khelaifi ACQUITTEDREPORT PENDING
n/a (villa use alleged as benefit) · 2013–2015
beIN/PSG chairman charged in Switzerland over a villa allegedly given for Jérôme Valcke's use in the FIFA World Cup TV-rights case; acquitted at every level.
SOURCE: AP via SFGate, Dec 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$5.6bn+ Laundered by the former finance minister (court finding) (Doha News, Jan 2024)
20 years Al Emadi's prison sentence (Doha News, Jan 2024)
€1M+ Cash seized in Brussels 'Qatargate' raids (Dec 2022; allegations denied by Qatar) (Belgian federal prosecutor via Euronews, 2022)
WHO FIGHTS IT
Attorney General / Public Prosecution and the Criminal Court; Administrative Control and Transparency Authority.
Qatar Financial Information Unit and AML/CFT Law No. 20 of 2019; National Cyber Security Agency (Cybersecurity Strategy 2024–2030).
Took part in INTERPOL Operation Ramz (Oct 2025 – Feb 2026).
SOURCES
Doha News, 18 Jan 2024
Al Jazeera, 6 May 2021 and 19 Mar 2023
AP via SFGate, Dec 2025
Euronews, Dec 2022
INTERPOL, 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇩🇿
ALGERIA
#23 Sumsub
CAPITAL Algiers · POPULATION 46.8M (2024, UN WPP est.)
FRAUD TYPES
Identity fraud, telecom fraud, phishing
KEY FACTS
Part of North Africa fraud ecosystem. Growing internet penetration.
BORN HERE
Nobody in our case files was born in Algeria yet.
OPERATED HERE
Nobody in our case files is documented as operating from Algeria yet.
KNOWN FOR
Bank collapse fraudGrand corruption / state-contract fraudBanking malwarePhishing-as-a-service
THE PICTURE

Algeria's main fraud cases are the Khalifa Bank collapse of 2003, with losses estimated at up to $5bn, and a wave of post-2019 corruption trials of Bouteflika-era prime ministers, ministers and tycoons (Al Arabiya, 2022; Al Jazeera, 2019). The car-assembly scandal alone is said to have cost the treasury about $1bn. Algerian hacker Hamza Bendelladj was jailed for 15 years in the US in 2016 for his role in the SpyEye banking trojan. During INTERPOL Operation Ramz (2025–2026), Algerian authorities took down a phishing-as-a-service website (INTERPOL, 2026). Algeria was on the FATF grey list from October 2024 until June 2026.

TOP FRAUDSTERS FROM HERE
Abdelmoumen Rafik Khalifa CONVICTEDREPORT PENDING
Up to ~$5bn (estimated losses) · 1998–2003
Founder of Khalifa Bank, which collapsed in 2003; convicted of fraud, forgery and embezzlement after extradition from the UK.
SOURCE: Al Arabiya, 7 Jun 2022
Ahmed Ouyahia CONVICTEDREPORT PENDING
~$1bn (estimated cost to treasury of car-assembly scandal) · 2010s
Four-time prime minister convicted over corruption in the car-assembly sector and hidden campaign financing.
SOURCE: Al Jazeera, 10 Dec 2019; France 24, 28 Jan 2021
Abdelmalek Sellal CONVICTEDREPORT PENDING
~$1bn (estimated cost of overall scandal) · 2010s
Former prime minister convicted in the same car-assembly corruption case.
SOURCE: Al Jazeera, 10 Dec 2019
Chakib Khelil FUGITIVEREPORT PENDING
n/a (DZD 2M fine; contract value not stated) · 2000s
Former energy minister convicted in absentia over favouring Saipem for Sonatrach contracts; lives abroad.
SOURCE: Africanews / VOA, 2022
Ali Haddad CONVICTEDREPORT PENDING
Undisclosed (family assets seized) · 2000s–2019
Construction tycoon (ETRHB) convicted of corruption over public contracts; sentence cut from 18 to 12 years on appeal.
SOURCE: Al Arabiya / Asharq Al-Awsat, 2020
Hamza Bendelladj PLEADED GUILTYREPORT PENDING
~$100M+ (reported thefts via SpyEye) · 2009–2013
Co-developed and sold the SpyEye banking trojan used to steal from bank accounts worldwide; arrested in Thailand in 2013.
SOURCE: Al Jazeera, 23 Apr 2016
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
Up to ~$5bn Estimated losses from the 2003 Khalifa Bank collapse (Al Arabiya, Jun 2022)
~$1bn Estimated treasury cost of the car-assembly corruption scandal (Al Jazeera, Dec 2019)
Oct 2024–Jun 2026 Period on the FATF grey list (FATF, Jun 2026)
WHO FIGHTS IT
Sidi M'Hamed court and Algiers/Blida criminal courts ran the post-2019 anti-corruption trials. Several defendants were convicted in absentia.
Financial Intelligence Processing Unit (CTRF); AML reforms led to the FATF grey-list exit in June 2026.
INTERPOL Operation Ramz (Oct 2025 – Feb 2026): phishing-as-a-service site dismantled, one suspect detained.
SOURCES
Al Arabiya, 7 Jun 2022
Al Jazeera, 10 Dec 2019
France 24, 28 Jan 2021
Africanews, 1 Feb 2022
Asharq Al-Awsat, Nov 2020
Al Jazeera, 23 Apr 2016
INTERPOL, 2026
FATF, Jun 2026
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇺🇸
UNITED STATES
#4 WCI / #1 Victim
CAPITAL Washington, D.C. · POPULATION 345M (2024, UN est.)
FRAUD TYPES
Friendly fraud, CNP, identity theft, crypto fraud, insider fraud, PPP/PUA fraud
KEY FACTS
42% of global card fraud. $12.5B consumer losses. $8.6B investment fraud. 158M disputes filed. No SCA mandate.
BORN HERE
20 people in our case files were born in United States. Tap to open the report.
OPERATED HERE
Physically based or working in United States — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Houston, Texas, United States
WHAT THEY DID HERE, AND WHEN
1990–2001Joins Enron from McKinsey and builds its energy-trading business; president and COO from 1997, CEO from 12 Feb 2001.SOURCE: case brief; Wikipedia
2001Resigns as CEO on 14 Aug 2001; Enron discloses a $618M loss in October and files for bankruptcy on 2 Dec 2001.SOURCE: case brief
2004–2006Indicted in Houston in Feb 2004; convicted on 19 counts on 25 May 2006; sentenced to 24 years 4 months on 23 Oct 2006.SOURCE: DOJ S.D. Texas
2013–2019Resentenced in Houston to 14 years on 21 June 2013; released from a Texas halfway house on 21 Feb 2019.SOURCE: DOJ; Reuters
New York, United States
WHAT THEY DID HERE, AND WHEN
1960Founds Investment Securities in New York.SOURCE: SDNY sentencing record
1990s–2008Runs the investment-advisory Ponzi scheme from the 17th floor of the Lipstick Building; ~4,800 client accounts by Nov 2008.SOURCE: DOJ; SEC
11 Dec 2008Arrested at his Manhattan apartment after confessing to his sons.SOURCE: FBI; DOJ
Hattiesburg, then Clinton and Jackson, Mississippi, United States
WHAT THEY DID HERE, AND WHEN
1983–1998LDDS formed in Hattiesburg in 1983; CEO from 1985; grows it into WorldCom and buys MCI for ~$37B in 1998.SOURCE: case brief
2000–2002From WorldCom's Clinton headquarters, ~$3.8B of costs booked as capital; resigns April 2002.SOURCE: SDNY verdict, 2005
New York, United States
WHAT THEY DID HERE, AND WHEN
2001–2012Runs Tiger Asia, a hedge fund in the Tiger Management network; it settles insider-trading charges for ~$60M in 2012 and returns outside money.SOURCE: SEC / DOJ 2012
2013–2021Turns it into Capital Management, a family office on Seventh Avenue managing only his own money.SOURCE: DOJ SDNY
2020–Mar 2021Builds concentrated positions in ViacomCBS, Discovery and others through total-return swaps with about ten banks; the banks lose ~$10B when it unwinds on 26 March 2021.SOURCE: DOJ SDNY; Reuters
Apr 2022–Nov 2024Charged, tried and convicted in Manhattan; 18 years on 20 Nov 2024.SOURCE: DOJ SDNY
Berkeley, California, United States
WHAT THEY DID HERE, AND WHEN
2017Founds Alameda Research, the trading firm that later drains FTX's customer deposits.SOURCE: DOJ SDNY
United States
WHAT THEY DID HERE, AND WHEN
2017–2018Joins Alameda Research from Jane Street.SOURCE: Reuters
Houston, Texas, United States
WHAT THEY DID HERE, AND WHEN
1980s–2009Stanford Financial Group headquarters; the FBI raids Houston, Memphis and Tupelo on 18 Feb 2009.SOURCE: DOJ; SEC
2012Convicted in Houston and sentenced to 110 years.SOURCE: S.D. Tex.
New York and Hoboken, New Jersey, United States
WHAT THEY DID HERE, AND WHEN
2017–2022Runs Celsius Network from Hoboken; promotes it weekly on 'Ask Mashinsky Anything' while, he admitted, misleading customers about its safety and propping up the CEL token.SOURCE: DOJ SDNY plea, Dec 2024
June–July 2022Freezes withdrawals, then bankruptcy.SOURCE: case brief
New York and Los Angeles, United States
WHAT THEY DID HERE, AND WHEN
2012–2014Parties, art, property and the financing of The Wolf of Wall Street, allegedly with 1MDB money; the US later seizes the assets.SOURCE: DOJ forfeiture complaints (alleged)
Seattle, Washington, United States
WHAT THEY DID HERE, AND WHEN
Nov 2023–Sept 2024Pleads guilty in Seattle, serves four months at FCI Lompoc, California.SOURCE: W.D. Wash.
Minnetonka, Minnesota, United States
WHAT THEY DID HERE, AND WHEN
1994–2008Petters Group Worldwide sells investors fake purchase orders for electronics that never existed; ~$3.65B Ponzi.SOURCE: DOJ D. Minn.
24 Sept 2008About 100 federal agents search the Minnetonka headquarters and his Wayzata home.SOURCE: DOJ
Gainesville, Georgia, United States
WHAT THEY DID HERE, AND WHEN
Sept 2012From home, exploits Silk Road's withdrawal flaw and takes ~51,680 BTC.SOURCE: DOJ SDNY
2012–2021Sits on the coins for nine years; agents find them in a floor safe and a popcorn tin in Nov 2021.SOURCE: DOJ SDNY
Coudersport, Pennsylvania, United States
WHAT THEY DID HERE, AND WHEN
1952–2002Builds Adelphia from one cable franchise into the sixth-largest US cable company.SOURCE: case brief
1990s–2002Family entities co-borrow ~$2.3B on Adelphia's credit lines, kept off the company's books.SOURCE: SDNY verdict, 2004
Miami, Florida, United States
WHAT THEY DID HERE, AND WHEN
1998–2016Runs a chain of nursing and assisted-living facilities; ~$1.3B billed to Medicare and Medicaid on kickback-driven referrals, the largest health-care fraud case charged.SOURCE: DOJ S.D. Fla.
July 2016Arrested in Miami.SOURCE: DOJ
Austin, Texas, United States · San Francisco, California, United States
WHAT THEY DID HERE, AND WHEN
2011Launches Silk Road from Austin as a Tor hidden service taking Bitcoin.SOURCE: US v. Ulbricht, SDNY
2012–2013Runs the market as from rented rooms in San Francisco.SOURCE: trial record
1 Oct 2013Arrested by the FBI in the Glen Park public library with the laptop open.SOURCE: FBI
Palo Alto, California, United States · Arizona, United States
WHAT THEY DID HERE, AND WHEN
2003Founds Theranos at 19 after dropping out of Stanford.SOURCE: N.D. Cal. record
2013–2015Raises hundreds of millions on claims the Edison device could run full blood panels from a finger-prick; the claims were false.SOURCE: jury verdict, 3 Jan 2022
2015–2018WSJ exposé, regulators move, Theranos dissolved in 2018; indicted the same year.SOURCE: WSJ; DOJ
2013–2016Theranos testing centres inside Walgreens stores in Arizona give real patients results from the unreliable devices.SOURCE: trial record; Arizona AG settlement
Miami, Florida, United States
WHAT THEY DID HERE, AND WHEN
17 Jan 2023Arrested in Miami as Bitzlato is taken down.SOURCE: DOJ
Salt Lake City, Utah and Phoenix, Arizona, United States
WHAT THEY DID HERE, AND WHEN
2014–2020Founds Nikola in Utah, moves it to Phoenix; the 'in motion' video of a truck rolling downhill is filmed in 2016.SOURCE: SDNY verdict; case brief
Sept 2020Hindenburg report; resigns as executive chairman.SOURCE: case brief
Beverly Hills, California, United States
WHAT THEY DID HERE, AND WHEN
1978–1989Runs Drexel Burnham Lambert's high-yield bond desk from Wilshire Boulevard; the securities violations he admitted happened here.SOURCE: US v. Milken, SDNY plea 1990
Miami, Florida, United States
WHAT THEY DID HERE, AND WHEN
2015–2018From EmpowerHMS in Miami, bills ~$1.4B for lab tests through four rural hospitals in Florida, Georgia and Missouri; ~$400M paid.SOURCE: DOJ M.D. Fla.
Miami, Los Angeles and the Hamptons, United States
WHAT THEY DID HERE, AND WHEN
Oct 2023Arrives in the US on the visa-waiver programme and moves between Miami, Los Angeles and the Hamptons.SOURCE: DOJ D.D.C.; case brief
2023–2024Runs the social-engineering crew with roommates in Texas; the group grows to 14 members.SOURCE: superseding indictment, May 2025
Aug 2024The 4,100 BTC heist from a single investor, live-streamed; the money goes into cars, watches, a Miami mansion and nightclubs within weeks.SOURCE: DOJ; case brief
18 Sept 2024Arrested by the FBI in Miami; his phone is thrown into Biscayne Bay.SOURCE: DOJ
Miami, Florida, United States · New York and Kearny, New Jersey, United States
WHAT THEY DID HERE, AND WHEN
2003Arrested for hacking and turned into a Secret Service informant.SOURCE: DOJ; case brief
2005–2007From Miami, runs the intrusions into TJX, Heartland, Hannaford and 7-Eleven while still informing for the government.SOURCE: indictments, D. Mass. and D.N.J.
2000–2003Moves to New York, then Kearny; leads the ShadowCrew carding forum under the name CumbaJohnny.SOURCE: case brief
Lake Success, Long Island, New York, United States
WHAT THEY DID HERE, AND WHEN
1989–1996Runs Stratton Oakmont, a boiler room pumping and dumping penny stocks on 1,513 clients; expelled by the NASD in Dec 1996.SOURCE: SIPC v. Stratton Oakmont; DOJ E.D.N.Y.
1999Pleads guilty, wears a wire against his partners; 22 months.SOURCE: US v. Belfort, E.D.N.Y.
Atlanta, Georgia, United States
WHAT THEY DID HERE, AND WHEN
2016–2019LabSolutions bills Medicare ~$463M for genetic tests ordered through kickbacks to call centres and telemedicine doctors; ~$187M paid.SOURCE: DOJ S.D. Ga.
New York and Exeter, New Hampshire, United States
WHAT THEY DID HERE, AND WHEN
1975–2002Joins Tyco in 1975, CEO from 1992; the unauthorised pay, loans and the $6,000 shower curtain apartment on Fifth Avenue.SOURCE: Manhattan DA; NY Supreme Court
2002–2005Indicted in Manhattan; mistrial in 2004; convicted at retrial in June 2005.SOURCE: NY Supreme Court
New York, United States
WHAT THEY DID HERE, AND WHEN
18 May 2024Arrested at JFK Airport.SOURCE: DOJ
Atlanta, Georgia, United States
WHAT THEY DID HERE, AND WHEN
12 Apr 2024Arrested at Hartsfield-Jackson airport; flees in Dec 2025 after cutting off his ankle monitor.SOURCE: DOJ
New York (75 Wall Street), United States
WHAT THEY DID HERE, AND WHEN
2016–2022With Ilya Lichtenstein, launders bitcoin stolen from Bitfinex through fake identities, darknet markets and gold; performs as .SOURCE: DOJ D.D.C.; plea, Aug 2023
Feb 2022Arrested in New York; the government seizes most of the coins.SOURCE: DOJ
New York, United States
WHAT THEY DID HERE, AND WHEN
1997Founds Galleon Group.SOURCE: case brief
2003–2009Trades on tips from insiders at Intel, IBM, McKinsey and Goldman; ~$63.8M in profits and avoided losses.SOURCE: SDNY verdict, 2011
16 Oct 2009Arrested by the FBI in New York.SOURCE: DOJ
Manhattan, New York, United States · Miami, Florida, United States
WHAT THEY DID HERE, AND WHEN
Jan 2018Takes part in the SIM swap that drains ~$23.8M from Michael Terpin.SOURCE: DOJ SDNY plea
Nov 2018Arrested in Manhattan on California charges.SOURCE: case brief
2023Detained in Miami for moving money and luxury spending while owing $20.4M restitution; resentenced to 12 years in 2025.SOURCE: SDNY
Boston, United States
WHAT THEY DID HERE, AND WHEN
1903Arrives in Boston on the SS Vancouver, by his account with $2.50.SOURCE: his autobiography (self-serving)
1919–1920Runs the Securities Exchange Company on School Street, paying old investors with new deposits; up to ~$250,000 a day at the peak.SOURCE: In re Ponzi, 268 F. 997; Boston Post
Aug–Nov 1920Boston Post exposes him; bank run, bankruptcy, guilty plea to larceny in Suffolk County.SOURCE: Boston Post; court record
New York, Louisiana and Georgia, United States
WHAT THEY DID HERE, AND WHEN
1964–1965Passes bad cheques in New York; enters Great Meadow prison in July 1965.SOURCE: court and prison records cited in the brief
Feb 1969Arrested in Baton Rouge; convicted of theft and forgery.SOURCE: case brief
Nov 1970Arrested in Georgia over forged Pan Am cheques; federal sentence, paroled 1974.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 32 cases tied to United States (born or operated here)
CORPORATE
19%
CRYPTO
19%
PONZI
13%
STOCK
13%
LAUNDERING
13%
HEALTHCARE
9%
DARK WEB
6%
CARD
3%
SIM SWAP
3%
BANK & WIRE
3%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Investment and crypto scamsImposter scamsPonzi schemesSecurities and accounting fraudBusiness email compromise (victim)
THE PICTURE

The US is both the largest reported victim market and home to major domestic frauds. Consumers reported a record $15.9 billion in fraud losses to the FTC in 2025, up from $12.5 billion in 2024, with investment scams accounting for about $7.9 billion (FTC, 2026). The FBI's Internet Crime Complaint Center logged $20.9 billion in reported internet-crime losses for 2025 (FBI IC3 via AARP, 2026). Much of the investment and romance ('pig-butchering') fraud targeting Americans is run from scam compounds in Southeast Asia, while domestic cases range from Ponzi schemes to crypto-exchange collapses. Enforcement is led by the DOJ, FBI, SEC, FTC and CFTC, and federal courts have handed down some of the longest fraud sentences in the world.

TOP FRAUDSTERS FROM HERE
FRAUD BY CATEGORY
share of reported fraud losses (computed from category loss totals in the Data Book; total $12.54B) · 2024
Investment related
45.4%
Imposter scams
23.5%
All other categories
15.3%
Business and job opportunities
6%
Online shopping and negative reviews
3.4%
Prizes, sweepstakes and lotteries
2.8%
Travel, vacations and timeshares
2.2%
Internet services
1.3%
SOURCE: FTC, Consumer Sentinel Network Data Book 2024, March 2025
KEY NUMBERS
$15.9B Consumer fraud losses reported to the FTC in 2025 (record) (FTC, 2026)
3 million Fraud reports filed with the FTC in 2025 (FTC, 2026)
$7.9B Reported losses to investment scams in 2025 (FTC, 2026)
$20.9B Internet-crime losses reported to the FBI IC3 in 2025 (FBI IC3 via AARP, 2026)
WHO FIGHTS IT
DOJ (incl. Fraud Section and US Attorneys), FBI and Secret Service prosecute wire, securities and bank fraud; the SEC, CFTC and FTC bring civil actions.
FTC Impersonation Rule enforcement returned over $70M to consumers across a dozen actions (FTC, June 2026).
Scam Center Strike Force (DOJ/FBI/USSS, launched 2025) targets Southeast Asian crypto-investment scam compounds.
FinCEN and OFAC use anti-money-laundering orders and sanctions against scam and laundering networks.
SOURCES
FTC, Consumer Sentinel Network Data Book 2024, Mar 2025
FTC press release on 2025 imposter scams, Jun 2026
FTC/press reports on 2025 losses ($15.9B), Apr 2026
AARP summary of FBI IC3 2025 report, 2026
US DOJ press releases (Madoff 2009, Petters 2010, Stanford 2012, Holmes 2022, 2023–24)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇧🇷
BRAZIL
#12 Sumsub
CAPITAL Brasília · POPULATION 212M (2024, UN est.)
FRAUD TYPES
Banking trojans, Pix fraud, fintech exploitation, card fraud, ransomware victim
KEY FACTS
128 ransomware attacks in 2025 — #1 in Latin America. Social engineering up 155% (BioCatch). The Grandoreiro banking trojan has been exported abroad.
BORN HERE
1 person in our case files was born in Brazil. Tap to open the report.
OPERATED HERE
Physically based or working in Brazil — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
São Paulo and Salvador, Brazil
WHAT THEY DID HERE, AND WHEN
2009–2015As CEO, oversees the company whose Division of Structured Operations paid ~$788M in bribes across 12 countries.SOURCE: DOJ plea, 21 Dec 2016 (company admission)
19 June 2015Arrested in Operation Car Wash; sentenced in Curitiba to 19 years 4 months in March 2016.SOURCE: Federal court, Curitiba
Rio de Janeiro, Brazil
WHAT THEY DID HERE, AND WHEN
1939–1949After deportation to Italy, works for an Italian airline in Rio; dies there in 1949 with about $75.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 2 cases tied to Brazil (born or operated here)
BRIBERY
50%
PONZI
50%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Pix instant-payment scamsFake bank-agent and WhatsApp impersonationPyramid and crypto schemesPublic-contract bribery (Lava Jato)
THE PICTURE

Brazil has one of the world's highest volumes of recorded fraud: police registered about 2.2 million estelionato (fraud) cases in 2024, a 408% rise since 2018, including at least 281,200 electronic frauds (Fórum Brasileiro de Segurança Pública, Anuário 2025). Much of the growth is tied to Pix instant-payment scams, fake-bank-agent calls, WhatsApp impersonation and phishing. Brazil was also the centre of Operation Lava Jato, which exposed the Odebrecht bribery network across Latin America (US DOJ, 2016), and of large pyramid schemes such as TelexFree. Enforcement falls to the Federal Police, state civil police, the Central Bank (Pix security rules, the MED refund mechanism) and the CVM securities regulator.

TOP FRAUDSTERS FROM HERE
Odebrecht S.A. PLEADED GUILTYREPORT PENDING
At least $3.5B (combined US/Brazil/Swiss penalties, Odebrecht and Braskem) · 2001–2016
Construction group that ran a dedicated bribery department paying officials across Latin America and Africa; pleaded guilty in the US with petrochemical affiliate Braskem.
SOURCE: US DOJ, Dec 2016
Carlos Wanzeler FUGITIVEREPORT PENDING
About $3B scheme (alleged by US prosecutors) · 2012–2014
Brazilian co-founder of TelexFree, a VoIP 'advertising' business US prosecutors say was a pyramid scheme with most participants in Brazil and the US; fled to Brazil after being charged.
SOURCE: US DOJ (District of Massachusetts), 2014
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
~2.2 million Estelionato (fraud) cases registered by police in 2024 (Fórum Brasileiro de Segurança Pública, Anuário 2025 (Jul 2025))
+408% Growth in registered fraud cases, 2018–2024 (FBSP, Anuário 2025)
281,200+ Electronic fraud cases in 2024 (+17%; São Paulo, Rio and Ceará do not report this category) (FBSP, Anuário 2025)
WHO FIGHTS IT
Federal Police and state civil police investigate fraud; Law 14.155/2021 raised penalties for electronic fraud (estelionato eletrônico).
Banco Central do Brasil runs Pix security rules and the MED special-return mechanism for Pix scam refunds.
Operation Lava Jato (2014–2021) prosecuted Petrobras/Odebrecht bribery, though many convictions were later annulled by the Supreme Court.
CVM (securities regulator) issues stop orders against unlicensed investment and crypto offers.
SOURCES
Fórum Brasileiro de Segurança Pública, Anuário Brasileiro de Segurança Pública 2025, Jul 2025
CNN Brasil, 24 Jul 2025
Agência Lupa, 24 Jul 2025
US DOJ, Odebrecht and Braskem plea, 21 Dec 2016
US DOJ (D. Mass.), TelexFree indictments, 2014
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇲🇽
MEXICO
#3 GI-TOC (7.68)
CAPITAL Mexico City · POPULATION 131M (2024, UN est.)
FRAUD TYPES
Account takeover (+324%), ransomware, cartel-linked cybercrime, call center scams
KEY FACTS
78 ransomware attacks (2025). ATO quadrupled 2024-2026. Golden Mexican Wolf group uses physical penetration tactics.
BORN HERE
Nobody in our case files was born in Mexico yet.
OPERATED HERE
Nobody in our case files is documented as operating from Mexico yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Timeshare fraud tied to cartelsExtortion and virtual-kidnapping callsDiversion of public fundsMoney laundering for cartels
THE PICTURE

Fraud in Mexico ranges from extortion calls and fake-kidnapping ('virtual kidnapping') scams to timeshare fraud aimed at US and Canadian owners, which the FBI and US Treasury have linked to the Jalisco New Generation Cartel (FBI, 2024; OFAC, 2024). Large-scale diversion of public funds has also led to prosecutions of former state governors, and federal auditors documented the 'Estafa Maestra' scheme that routed ministry money through universities and shell companies (ASF / Animal Político, 2017). Enforcement involves the Fiscalía General de la República, the Financial Intelligence Unit (UIF), the CONDUSEF consumer-finance agency and close cooperation with US prosecutors.

TOP FRAUDSTERS FROM HERE
Javier Duarte CONVICTEDREPORT PENDING
Not quantified in sentence (fine of MXN 58,000) · 2010–2016
Former governor of Veracruz sentenced for money laundering and criminal association after diverting state funds; arrested in Guatemala in 2017.
SOURCE: Mexican federal court, 2018 (sentence upheld 2020)
Tomás Yarrington PLEADED GUILTYREPORT PENDING
Not fixed in plea; investigators alleged >$8.5M from cartels (allegation) · 1999–2004
Former governor of Tamaulipas who pleaded guilty in the US to money laundering tied to bribes taken in office.
SOURCE: US DOJ (SD Texas), Mar 2021
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Fiscalía General de la República (FGR) and state prosecutors; UIF freezes accounts linked to fraud and laundering.
US Treasury OFAC sanctions (2024) against individuals and companies running CJNG-linked timeshare fraud in Jalisco.
CONDUSEF handles consumer complaints on banking fraud and publishes fraud-claim statistics.
SOURCES
FBI, timeshare fraud warning, 2024
US Treasury OFAC, CJNG timeshare-fraud designations, 2024
Wikipedia summary of Javier Duarte court record
US DOJ, Yarrington plea, Mar 2021
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇨🇴
COLOMBIA
#2 GI-TOC (7.82)
CAPITAL Bogotá · POPULATION 53M (2024, UN est.)
FRAUD TYPES
Ransomware victim, SIM swap, mobile fraud, investment scams
KEY FACTS
51 ransomware attacks (2025). ATO +188%. Part of LATAM cybercrime surge. CPI declining.
BORN HERE
Nobody in our case files was born in Colombia yet.
OPERATED HERE
Nobody in our case files is documented as operating from Colombia yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Pyramid schemesExtortion calls from prisonsPublic-contract corruptionTrade-based money laundering
THE PICTURE

Colombia's fraud landscape includes pyramid schemes that drew in hundreds of thousands of savers in the 2000s (DMG, DRFE), 'carrusel' public-contract corruption in Bogotá, and extortion and phone scams run from prisons. Proceeds of drug trafficking are also laundered through trade-based schemes and front companies (FATF/GAFILAT, 2018). Enforcement falls to the Fiscalía General de la Nación, the Superintendencia Financiera and the UIAF financial-intelligence unit, with many cases extradited to the US.

TOP FRAUDSTERS FROM HERE
David Murcia Guzmán CONVICTEDREPORT PENDING
Not reliably quantified in public records · 2005–2008
Founder of DMG Grupo Holding, a prepaid-card 'investment' pyramid shut down in 2008; extradited to the US and sentenced for money laundering.
SOURCE: US DOJ (SDNY), 2010–2011
Samuel Moreno Rojas CONVICTEDREPORT PENDING
Not fixed in public summaries · 2008–2011
Former mayor of Bogotá convicted over the 'carrusel de la contratación' kickback scheme on city contracts.
SOURCE: Colombian Supreme Court / courts, 2016 and later
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Fiscalía General de la Nación and the Superintendencia Financiera (which ordered DMG's intervention in 2008).
UIAF financial-intelligence unit and the GAFILAT mutual evaluation (2018) on money laundering.
Frequent US extraditions for laundering and fraud.
SOURCES
US DOJ SDNY, Murcia Guzmán case, 2010–2011
Colombian press/court records on Samuel Moreno, 2016
GAFILAT Mutual Evaluation of Colombia, 2018
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇦🇷
ARGENTINA
#3 LATAM
CAPITAL Buenos Aires · POPULATION 45.7M (2024, UN est.)
FRAUD TYPES
Ransomware victim, banking fraud, identity theft, money muling
KEY FACTS
63 ransomware attacks (2025). Money mule accounts declining but other fraud rising. Chinese APT operations detected.
BORN HERE
Nobody in our case files was born in Argentina yet.
OPERATED HERE
Nobody in our case files is documented as operating from Argentina yet.
KNOWN FOR
Public-works fraudMoney laundering of state fundsCrypto and pyramid schemesPhishing and account takeover
THE PICTURE

Argentina's highest-profile fraud cases involve public works and the laundering of state money, above all the 'Vialidad' case in which former president Cristina Fernández de Kirchner was convicted of fraudulent administration of road contracts in Santa Cruz (federal court, Dec 2022; upheld by the Supreme Court, June 2025). High inflation has also fuelled crypto and 'high-yield' pyramid schemes such as Generación Zoe, as well as phishing and WhatsApp impersonation. Enforcement falls to the federal courts in Comodoro Py, the UIF financial-intelligence unit and the CNV securities regulator.

TOP FRAUDSTERS FROM HERE
Cristina Fernández de Kirchner CONVICTEDREPORT PENDING
Not fixed in public summaries (large forfeiture ordered) · 2003–2015
Former president convicted of fraudulent administration over road contracts steered to Lázaro Báez's companies; serving her sentence under house arrest.
SOURCE: Federal Oral Tribunal 2, Dec 2022; Supreme Court, Jun 2025
Lázaro Báez CONVICTEDREPORT PENDING
Not fixed in public summaries · 2010–2013
Businessman convicted of laundering public-works money in 'La ruta del dinero K' and co-convicted in the Vialidad case.
SOURCE: Federal Oral Tribunal 4, Feb 2021 (12-year sentence)
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Federal criminal courts (Comodoro Py) and the Public Prosecutor's economic crime office (PROCELAC).
UIF financial-intelligence unit; CNV warnings on unauthorised investment offers.
Supreme Court upheld the Vialidad conviction in June 2025.
SOURCES
Wikipedia summary of court record (Cristina Fernández de Kirchner), 2025
Argentine federal court rulings, 2021–2025
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇵🇪
PERU
LATAM flagged
CAPITAL Lima · POPULATION 34M (2024, UN est.)
FRAUD TYPES
Ransomware victim, identity fraud, telecom scams
KEY FACTS
27 ransomware attacks (2025). Scam compounds identified in Peru. Growing digital fraud.
BORN HERE
Nobody in our case files was born in Peru yet.
OPERATED HERE
Nobody in our case files is documented as operating from Peru yet.
KNOWN FOR
Odebrecht briberyMoney laundering of campaign fundsPhishing and fake-loan appsExtortion
THE PICTURE

Peru was one of the countries hit hardest by the Odebrecht bribery network: the company admitted paying about $29 million in bribes there (US DOJ, 2016), and several former presidents have since been prosecuted. Alejandro Toledo was sentenced to 20 years and 6 months in October 2024 for taking Odebrecht bribes, and Ollanta Humala received 15 years for money laundering in April 2025 (Peruvian courts). Everyday fraud includes phone and SMS phishing, fake-loan apps and extortion. Enforcement relies on the special Lava Jato prosecution team, the SBS/UIF financial regulator and the anti-corruption courts.

TOP FRAUDSTERS FROM HERE
Alejandro Toledo CONVICTEDREPORT PENDING
$35M (bribes) · 2004–2006
Former president convicted of taking Odebrecht bribes for the Interoceanic Highway; extradited from the US in 2023.
SOURCE: National Superior Court of Specialized Criminal Justice, Oct 2024
Ollanta Humala CONVICTEDREPORT PENDING
About $3M (alleged illicit campaign funds) · 2006–2011
Former president convicted with his wife Nadine Heredia of laundering illicit campaign contributions, including Odebrecht money.
SOURCE: Peruvian court, 15 Apr 2025
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$29M Bribes Odebrecht admitted paying in Peru (US DOJ, Dec 2016)
WHO FIGHTS IT
Special Lava Jato prosecution team (Equipo Especial) of the Public Ministry.
SBS and its UIF unit supervise banks and money-laundering controls.
US–Peru extradition of Alejandro Toledo (April 2023).
SOURCES
Wikipedia summaries of court records (Toledo, Humala), 2024–2025
US DOJ, Odebrecht plea agreement, Dec 2016
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇪🇨
ECUADOR
#4 GI-TOC (7.48)
CAPITAL Quito · POPULATION 18.1M (2024, UN est.)
FRAUD TYPES
Money laundering, fraud, organized crime crossover
KEY FACTS
7.48 GI-TOC criminality — tied #4 globally. Fraud volume more than doubled 2024-2025.
BORN HERE
Nobody in our case files was born in Ecuador yet.
OPERATED HERE
Nobody in our case files is documented as operating from Ecuador yet.
KNOWN FOR
Public-contract briberyDrug-proceeds launderingPyramid schemesPhishing
THE PICTURE

Ecuador's major fraud and corruption cases concern bribes for public contracts, including the 'Sobornos 2012-2016' case in which former president Rafael Correa was convicted in absentia (National Court of Justice, 2020), and Odebrecht, which admitted paying about $33.5 million in bribes in the country (US DOJ, 2016). The dollarised economy and a surge in organised crime have also made Ecuador a laundering channel for drug proceeds (US State Dept INCSR). Enforcement falls to the Fiscalía General del Estado, the UAFE financial-intelligence unit and the Superintendencia de Bancos.

TOP FRAUDSTERS FROM HERE
Rafael Correa FUGITIVEREPORT PENDING
Not quantified in public summaries · 2012–2016
Former president convicted in absentia of aggravated bribery for campaign money taken in exchange for public contracts; lives in Belgium, which granted him asylum.
SOURCE: National Court of Justice of Ecuador, Apr 2020 (8 years)
Jorge Glas CONVICTEDREPORT PENDING
Not quantified in public summaries · 2010s
Former vice-president convicted of illicit association in the Odebrecht case and later in the bribery case.
SOURCE: National Court of Justice of Ecuador, Dec 2017
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$33.5M Bribes Odebrecht admitted paying in Ecuador (US DOJ, Dec 2016)
WHO FIGHTS IT
Fiscalía General del Estado; UAFE financial-intelligence unit.
Court verdicts in the Sobornos (2020) and Odebrecht (2017) cases.
Superintendencia de Bancos rules on electronic banking fraud.
SOURCES
Wikipedia summary of court record (Rafael Correa)
US DOJ, Odebrecht plea agreement, Dec 2016
US State Department, International Narcotics Control Strategy Report (INCSR)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇵🇾
PARAGUAY
#4 GI-TOC (7.48)
CAPITAL Asunción · POPULATION 6.9M (2024, UN est.)
FRAUD TYPES
Money laundering, contraband, financial fraud
KEY FACTS
7.48 GI-TOC — tied with Ecuador. Tri-border area (Brazil/Argentina) = transit hub.
BORN HERE
Nobody in our case files was born in Paraguay yet.
OPERATED HERE
Nobody in our case files is documented as operating from Paraguay yet.
KNOWN FOR
Trade-based money launderingContraband and counterfeit goodsCorruption allegationsFront companies for drug proceeds
THE PICTURE

Paraguay's fraud and financial-crime risk centres on the Tri-Border Area (Ciudad del Este), long flagged for trade-based money laundering, cigarette smuggling and counterfeit goods (US State Dept INCSR). In 2022–2023 the US designated former president Horacio Cartes for 'significant corruption' and sanctioned him and his companies (US State Dept, July 2022; US Treasury OFAC, Jan 2023). The 2022 'A Ultranza Py' operation targeted a drug-trafficking and laundering network using front companies (Paraguayan Public Ministry, 2022). Enforcement relies on the Public Ministry, SEPRELAD (the financial-intelligence unit) and the Central Bank.

TOP FRAUDSTERS FROM HERE
Horacio Cartes SANCTIONEDREPORT PENDING
Not quantified (sanctions designation) · 2022–2023
Former president designated by the US for significant corruption and sanctioned for alleged bribery and links to Hezbollah-affiliated financiers (US allegations; he denies them).
SOURCE: US Treasury OFAC, 26 Jan 2023
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
SEPRELAD (Secretaría de Prevención de Lavado de Dinero o Bienes).
Public Ministry's 'A Ultranza Py' operation against a laundering network (2022).
US OFAC Global Magnitsky sanctions (2023).
SOURCES
US Treasury OFAC press release, 26 Jan 2023
US State Department, Section 7031(c) designation, Jul 2022
US State Department INCSR (Paraguay)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇻🇪
VENEZUELA
GI-TOC flagged
CAPITAL Caracas · POPULATION 28.4M (2024, UN est.)
FRAUD TYPES
Investment scams, crypto fraud, government corruption
KEY FACTS
Economic collapse drove crypto adoption AND crypto fraud. Limited enforcement.
BORN HERE
Nobody in our case files was born in Venezuela yet.
OPERATED HERE
Nobody in our case files is documented as operating from Venezuela yet.
KNOWN FOR
PDVSA embezzlement and launderingForeign-exchange bribery schemesSanctions evasionKleptocracy (sanctioned officials)
THE PICTURE

Venezuela's largest frauds involve the looting of state money through currency-exchange arbitrage and the national oil company PDVSA. US prosecutors describe schemes in which officials sold access to preferential exchange rates for bribes, and a network that laundered about $1.2 billion taken from PDVSA (US DOJ, 2018). In 2023–2024 Venezuelan authorities arrested former oil minister Tareck El Aissami over the 'PDVSA-Cripto' scandal involving diverted oil revenue. Much of the enforcement has come from US courts and OFAC sanctions rather than domestic prosecutors.

TOP FRAUDSTERS FROM HERE
Alejandro Andrade PLEADED GUILTYREPORT PENDING
Over $1B (bribes received) · 2008–2011
Former national treasurer who took over $1 billion in bribes to let businessmen profit from Venezuela's currency-exchange system.
SOURCE: US DOJ (SD Florida), plea Dec 2017; 10-year sentence Nov 2018
Raúl Gorrín CHARGED (NOT TRIED)REPORT PENDING
Over $1B (bribes paid, alleged) · 2008–2017
Owner of Globovisión charged in the US with paying the currency-exchange bribes to Andrade and another treasurer; sanctioned by OFAC in 2019 and reportedly detained in 2026.
SOURCE: US DOJ, Aug 2018; OFAC, Jan 2019
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
$1.2B PDVSA funds a US-charged network allegedly laundered (US DOJ (SD Florida), Jul 2018)
WHO FIGHTS IT
US DOJ Kleptocracy and FCPA prosecutions in Miami and Houston.
US Treasury OFAC sanctions on officials and business figures.
Venezuelan Public Ministry arrests in the PDVSA-Cripto case (2023–2024).
SOURCES
Wikipedia summaries of court records (Andrade, Gorrín)
US DOJ, Operation Money Flight press release, Jul 2018
US Treasury OFAC press release, Jan 2019
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇯🇲
JAMAICA
Interpol flagged
CAPITAL Kingston · POPULATION 2.8M (2024, UN est.)
FRAUD TYPES
Lottery scams ('lotto scams'), romance scams, investment fraud
KEY FACTS
Montego Bay lottery scam industry targeting US elderly. FBI and local enforcement operations.
BORN HERE
Nobody in our case files was born in Jamaica yet.
OPERATED HERE
Nobody in our case files is documented as operating from Jamaica yet.
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Lottery / advance-fee scamsElder fraud targeting the USInvestment fraudPonzi schemes
THE PICTURE

Jamaica is best known in fraud circles for advance-fee 'lottery scams' that phone older people in the US, claiming they have won a prize and must pay fees first; US authorities have prosecuted and extradited dozens of Jamaican participants (US DOJ, 2010s–2020s). Parliament passed the Law Reform (Fraudulent Transactions) (Special Provisions) Act in 2013 specifically to target these schemes. In 2023 the collapse of Stocks and Securities Ltd, after an employee allegedly diverted client funds including those of Usain Bolt, prompted regulatory reform (Financial Services Commission, 2023). Enforcement is led by the JCF's Major Organized Crime and Anti-Corruption Agency (MOCA) and the Financial Investigations Division.

TOP FRAUDSTERS FROM HERE
David Smith CONVICTEDREPORT PENDING
About $220M (investor funds) · 2000s
Ran Olint Corp, a foreign-exchange 'investment club' Ponzi scheme that took money from thousands of Jamaican and other investors.
SOURCE: US DOJ (MD Florida), 2013
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
2013 Year Jamaica passed the lottery-scam law (Law Reform (Fraudulent Transactions) Act) (Parliament of Jamaica, 2013)
WHO FIGHTS IT
Law Reform (Fraudulent Transactions) (Special Provisions) Act, 2013.
JCF Major Organized Crime and Anti-Corruption Agency (MOCA) and Financial Investigations Division.
US–Jamaica extraditions for lottery-scam prosecutions.
SOURCES
Wikipedia, Stocks and Securities Limited
US DOJ press releases on Jamaican lottery-scam prosecutions
US DOJ (MD Florida), David Smith sentencing, 2013
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇹🇹
TRINIDAD & TOBAGO
Regional flagged
CAPITAL Port of Spain · POPULATION 1.5M (2024, UN est.)
FRAUD TYPES
Identity fraud, card fraud, investment scams
KEY FACTS
Caribbean banking hub exploited. Growing cybercrime.
BORN HERE
Nobody in our case files was born in Trinidad & Tobago yet.
OPERATED HERE
Nobody in our case files is documented as operating from Trinidad & Tobago yet.
KNOWN FOR
Sports-governance bribery (FIFA)Financial-sector collapse (CL Financial)Money laundering riskOnline and phone scams
THE PICTURE

Trinidad & Tobago's fraud profile is shaped by financial-sector failures and corruption cases, including the 2009 collapse of the CL Financial conglomerate that required one of the Caribbean's largest government bailouts. Former FIFA vice-president Jack Warner has been fighting US charges of wire fraud, racketeering and money laundering since 2015 (US DOJ, 2015). The country has been on and off the FATF 'grey list' and the EU list of high-risk jurisdictions over anti-money-laundering weaknesses. Enforcement falls to the Trinidad and Tobago Police Service Fraud Squad, the Financial Intelligence Unit (FIUTT) and the Office of the DPP.

TOP FRAUDSTERS FROM HERE
Jack Warner CHARGED (NOT TRIED)REPORT PENDING
$79M (US civil default judgment, 2019) · 1990s–2015
Former FIFA vice-president and CONCACAF president indicted in the US FIFA corruption case; a US civil court also entered a $79M default judgment against him for taking CONCACAF funds.
SOURCE: US DOJ (EDNY), May 2015
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
TTPS Fraud Squad; Financial Intelligence Unit of Trinidad and Tobago (FIUTT).
Commission of Enquiry into the CL Financial collapse (2010s).
Extradition proceedings over the US FIFA indictment (ongoing since 2015).
SOURCES
US DOJ (EDNY), FIFA indictment, May 2015
Wikipedia summary of court record (Jack Warner)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇨🇦
CANADA
Low source / High target
CAPITAL Ottawa · POPULATION 39.7M (2024, UN est.)
FRAUD TYPES
Romance scam victim, card fraud victim, money muling
KEY FACTS
C$638M in reported fraud losses in 2024 (Canadian Anti-Fraud Centre). A major victim country.
BORN HERE
1 person in our case files was born in Canada. Tap to open the report.
OPERATED HERE
Physically based or working in Canada — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Montreal, Canada
WHAT THEY DID HERE, AND WHEN
1907–1911Works at Banco Zarossi, which paid depositors out of new deposits; jailed three years for forging a cheque.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 2 cases tied to Canada (born or operated here)
CORPORATE
50%
PONZI
50%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Investment and crypto scamsSpear phishingRomance scamsGrandparent / emergency scamsPonzi schemes
THE PICTURE

Canadians reported a record $704 million in fraud losses to the Canadian Anti-Fraud Centre in 2025 from more than 112,000 reports, and investment fraud alone accounted for about half of that ($351 million) (CAFC, Feb 2026). The CAFC estimates only 5–10% of fraud is reported. Canada has also seen large domestic frauds, from the Norbourg fund scandal in Quebec to the collapse of crypto exchange QuadrigaCX (Ontario Securities Commission, 2020), and Canadian call centres have been used in 'grandparent' scams against US seniors (US DOJ, 2023). Enforcement involves the RCMP, provincial police, the CAFC and provincial securities regulators.

TOP FRAUDSTERS FROM HERE
Gerald Cotten DIED BEFORE TRIALREPORT PENDING
About C$169M (client losses, OSC) · 2015–2018
Founder of QuadrigaCX, which the Ontario Securities Commission found he ran as a fraud using client assets; he died in 2018 before any charges.
SOURCE: Ontario Securities Commission, Jun 2020
Vincent Lacroix CONVICTEDREPORT PENDING
C$130M (missing from funds) · 2002–2005
Founder of Norbourg Financial Group who diverted client money from its funds, hurting about 9,200 Quebec investors.
SOURCE: Quebec courts, Dec 2007 and Oct 2009
Earl Jones PLEADED GUILTYREPORT PENDING
About C$50M (investor losses) · 1982–2009
Montreal financial adviser who ran a Ponzi scheme for decades, defrauding about 150 clients.
SOURCE: Quebec Superior Court, Feb 2010 (11 years)
FRAUD BY CATEGORY
share of reported fraud losses (computed from CAFC dollar losses; total $704M) · 2025
Investment
49.9%
Spear phishing
9.6%
Relationship (romance)
9%
All other
8.1%
Job
7.2%
Fraud investigator impersonation
4%
Recovery pitch
3.7%
Extortion
3.3%
Service
2.8%
Merchandise
1.7%
Prize
0.8%
SOURCE: Canadian Anti-Fraud Centre, 'Top 10 frauds in 2025', 25 Feb 2026
KEY NUMBERS
C$704M Fraud losses reported to the CAFC in 2025 (record) (CAFC, Feb 2026)
112,000+ Fraud reports received by the CAFC in 2025 (CAFC, Feb 2026)
C$351M Investment fraud losses in 2025 (~50% of total) (CAFC, Feb 2026)
5–10% Estimated share of fraud actually reported to the CAFC (CAFC)
WHO FIGHTS IT
RCMP, Ontario Provincial Police, Sûreté du Québec and the Canadian Anti-Fraud Centre (CAFC).
Provincial securities regulators (OSC, AMF) and the Canadian Investment Regulatory Organization.
Criminal Code s.380 fraud offences; FINTRAC anti-money-laundering supervision.
SOURCES
Canadian Anti-Fraud Centre, 'Top 10 frauds in 2025', 25 Feb 2026
Canadian Anti-Fraud Centre, 'The rise of fraud', Feb 2026
Ontario Securities Commission, QuadrigaCX report, Jun 2020
Wikipedia, Norbourg / Vincent Lacroix court record
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇬🇧
UNITED KINGDOM
#8 WCI
CAPITAL London · POPULATION 69.1M (2024, UN est.)
FRAUD TYPES
APP fraud, card fraud, money muling, romance scams, money laundering
KEY FACTS
£130M+ of London property frozen over Chen Zhi's Prince Group (Oct 2025). Qian Zhimin: 61,000 bitcoin (~£5B) seized; sentenced to 11 years 8 months (Nov 2025). APP (authorised push payment) fraud is a leading UK loss. A significant money-laundering hub.
BORN HERE
1 person in our case files was born in United Kingdom. Tap to open the report.
OPERATED HERE
Physically based or working in United Kingdom — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
London, United Kingdom
WHAT THEY DID HERE, AND WHEN
1983–2008Madoff Securities International, the London office, used to move money between the scheme and the family; wound up after the arrest.SOURCE: SFO; UK administrators' reports
London, United Kingdom
WHAT THEY DID HERE, AND WHEN
June 2016Headlines the OneCoin event at Wembley Arena, promising the coin would 'kill Bitcoin'.SOURCE: BBC
London, United Kingdom
WHAT THEY DID HERE, AND WHEN
Mar 1995The London meeting where the fake 'governor' is introduced to Sakaguchi.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 4 cases tied to United Kingdom (born or operated here)
PONZI
25%
CRYPTO
25%
STOCK
25%
BANK & WIRE
25%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Authorised push payment (APP) scamsCard-not-present fraudInvestment scamsMoney laundering through propertyRogue trading
THE PICTURE

Fraud is the most common crime in England and Wales, and UK banks and card firms reported £1.28 billion stolen through payment fraud in 2025, up 4%, including a record £576.4 million lost to authorised push payment (APP) scams (UK Finance, June 2026). Investment scams were the single largest APP category at £221.5 million, while card-not-present fraud remained the biggest unauthorised category. London is also a global hub for laundering fraud proceeds through property and companies, shown by the 61,000-bitcoin seizure in the Qian Zhimin case (Metropolitan Police / CPS, 2025). Mandatory reimbursement of APP victims (up to £85,000) has applied since October 2024 under Payment Systems Regulator rules.

TOP FRAUDSTERS FROM HERE
Qian Zhimin CONVICTEDREPORT PENDING
About £5B (bitcoin seized); ~£4.2B (investor losses in China) · 2014–2017
Ran a Chinese Ponzi scheme that took money from over 128,000 investors, then fled to the UK and tried to launder the proceeds in bitcoin; 61,000 BTC were seized.
SOURCE: Southwark Crown Court, Sep 2025 (sentenced 11 yrs 8 mths, Nov 2025)
Kweku Adoboli CONVICTEDREPORT PENDING
$2.3B (loss to UBS) · 2008–2011
UBS trader in London whose unauthorised trades caused the bank's losses.
SOURCE: Southwark Crown Court, Nov 2012
Achilleas Kallakis CONVICTEDREPORT PENDING
Over £760M (loans obtained) · 2000s
Used aliases and forged documents to obtain bank loans for London property in the UK's largest mortgage fraud.
SOURCE: Southwark Crown Court / SFO, Jan 2013
FRAUD BY CATEGORY
share of reported payment-fraud losses (computed from UK Finance loss values; total £1,279.8M) · 2025
Card fraud (unauthorised)
46.5%
APP: investment scams
17.3%
APP: purchase scams
9.2%
Remote banking fraud (unauthorised)
8.2%
APP: advance fee scams
4.6%
APP: bank/police impersonation
4.3%
APP: invoice and mandate scams
3.2%
APP: romance scams
3.1%
APP: other impersonation
2.9%
APP: CEO fraud
0.4%
Cheque fraud (unauthorised)
0.3%
SOURCE: UK Finance, Annual Fraud Report 2026, June 2026
KEY NUMBERS
£1.28B Payment fraud losses in 2025 (up 4%) (UK Finance, Jun 2026)
£576.4M APP scam losses in 2025 (up 19%) (UK Finance, Jun 2026)
£354.3M APP losses reimbursed to victims (61%) (UK Finance, Jun 2026)
£1.68B Unauthorised fraud prevented by firms in 2025 (UK Finance, Jun 2026)
WHO FIGHTS IT
Serious Fraud Office, National Crime Agency, City of London Police (national lead force) and Action Fraud / Report Fraud.
Payment Systems Regulator mandatory APP reimbursement (from 7 Oct 2024).
Economic Crime and Corporate Transparency Act 2023 created a 'failure to prevent fraud' offence (in force Sept 2025).
Dedicated Card and Payment Crime Unit (DCPCU) disrupts organised card fraud gangs.
SOURCES
UK Finance, Annual Fraud Report 2026, Jun 2026
Wikipedia summary of court record (Qian Zhimin), 2025
SFO / press on Kallakis, Jan 2013
Southwark Crown Court (Adoboli), Nov 2012
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇩🇪
GERMANY
Enforcement leader
CAPITAL Berlin · POPULATION 84.6M (2024, UN est.)
FRAUD TYPES
Ransomware victim, money laundering, Wirecard fraud
KEY FACTS
Hydra Market seized Apr 2022. Wirecard €1.9B scandal. Strong enforcement but growing target.
BORN HERE
Nobody in our case files was born in Germany yet.
OPERATED HERE
Physically based or working in Germany — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Frankfurt, Germany
WHAT THEY DID HERE, AND WHEN
2 Mar 1995Arrested at Frankfurt airport; held until extradition to Singapore in November.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 1 case tied to Germany (born or operated here)
STOCK
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Goods fraud (online shopping)Payment-card and account fraudCum-ex tax fraudAccounting fraud (Wirecard)Fake-police and grandchild scams
THE PICTURE

German police recorded 681,354 fraud offences committed inside the country in 2025 (down 8.4%), plus 549,385 fraud cases committed from abroad against German victims (up 7.0%), and the internet was used in 52.3% of fraud cases (BKA, PKS 2025). Germany was also the scene of two of Europe's largest white-collar scandals: the Wirecard collapse, in which €1.9 billion of reported cash did not exist (2020), and 'cum-ex' dividend-stripping trades that cost the treasury billions. Frauds against older people such as 'Enkeltrick' (grandchild) and fake-police calls are frequently run from call centres abroad. Enforcement involves the BKA, state police (LKA), BaFin and specialised prosecutors such as those in Cologne for cum-ex.

TOP FRAUDSTERS FROM HERE
Markus Braun CHARGED (NOT TRIED)REPORT PENDING
€1.9B (missing cash reported by Wirecard) · 2015–2020
Former Wirecard CEO on trial in Munich for fraud, breach of trust and accounting manipulation after the payments firm reported €1.9B in cash that did not exist.
SOURCE: Munich prosecutors, charges Mar 2022; trial ongoing since Dec 2022
Jan Marsalek FUGITIVEREPORT PENDING
€1.9B (missing cash reported by Wirecard) · 2015–2020
Former Wirecard chief operating officer who fled in June 2020 and is wanted on an international arrest warrant.
SOURCE: Munich prosecutors / BKA wanted notice, 2020
Hanno Berger CONVICTEDREPORT PENDING
About €14.6M confiscated (Bonn and Wiesbaden rulings) · 2006–2011
Tax lawyer seen as a mastermind of cum-ex trades that reclaimed dividend tax that was never paid.
SOURCE: Bonn Regional Court, Dec 2022; Wiesbaden, May 2023; combined 10-year sentence May 2026
FRAUD BY CATEGORY
share of police-recorded domestic fraud cases (computed from PKS case counts; total 681,354; secondary report of BKA data) · 2025
All other fraud
37.7%
Goods and goods-credit fraud
28.5%
Obtaining services by deception (incl. fare evasion)
19.6%
Fraud using unlawfully obtained cashless payment means
14.1%
SOURCE: BKA, Polizeiliche Kriminalstatistik 2025, April 2026 (as reported by diebewertung.de)
KEY NUMBERS
681,354 Domestic fraud cases recorded by police in 2025 (-8.4%) (BKA, PKS 2025)
549,385 Fraud cases committed from abroad against German victims in 2025 (+7.0%) (BKA, PKS 2025)
52.3% Share of fraud cases committed via the internet (BKA, PKS 2025)
WHO FIGHTS IT
Bundeskriminalamt (BKA), state criminal police (LKA) and public prosecutors; BaFin supervises financial firms.
Cologne prosecutors' cum-ex unit has charged hundreds of suspects since 2013 revelations.
Wirecard trial at Munich Regional Court (since Dec 2022) and a 2021 overhaul of financial supervision (FISG law).
SOURCES
BKA, Polizeiliche Kriminalstatistik 2025, Apr 2026
diebewertung.de summary of PKS 2025 fraud data, 2026
Wikipedia summaries of court records (Braun, Berger), 2024–2026
US DOJ / FBI, OneCoin case
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇫🇷
FRANCE
Moderate
CAPITAL Paris · POPULATION 66.5M (2024, UN est.)
FRAUD TYPES
Card fraud, phishing, ransomware victim, identity fraud
KEY FACTS
EU's second-largest economy = significant fraud target. Strong SCA (PSD2) reduces card fraud vs US.
BORN HERE
1 person in our case files was born in France. Tap to open the report.
OPERATED HERE
Physically based or working in France — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Paris La Défense, France
WHAT THEY DID HERE, AND WHEN
2000–2008Joins Société Générale's middle office in 2000, moves to the Delta One desk in 2005, builds €50B of hidden positions by Jan 2008.SOURCE: Paris tribunal, 2010
Jan 2008The positions are unwound at a loss of €4.9B.SOURCE: Société Générale, 24 Jan 2008
Montpellier, France
WHAT THEY DID HERE, AND WHEN
Sept 1969Arrested in Montpellier and jailed in France.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 2 cases tied to France (born or operated here)
STOCK
50%
BANK & WIRE
50%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Fake bank-adviser scamsCEO / fake-president fraudVAT carousel fraudRogue trading
THE PICTURE

Payment fraud in France reached €1.241 billion in 2025 (up 3.8%), and credit transfers overtook cards as the main source of fraud by value (Banque de France, OSMP 2025 report, Sept 2026). 'Fraud by manipulation', such as fake bank-adviser calls, CEO fraud and IBAN substitution, reached €516 million, just over 40% of the total and double its share four years earlier. France is also the origin of the 'fake president' (CEO fraud) technique and of the EU carbon-credit VAT fraud of 2008–2009. Enforcement is led by the Parquet national financier, the OCRGDF police office and the Banque de France observatory.

TOP FRAUDSTERS FROM HERE
Gilbert Chikli CONVICTEDREPORT PENDING
€44M and €10.6M (damages to principal victims) · 2015–2017
Pioneered the 'fake president' phone scam and later impersonated defence minister Jean-Yves Le Drian (with a silicone mask) to extract money from wealthy targets.
SOURCE: Paris Criminal Court, Mar 2020; Court of Appeal, 10 years
Arnaud Mimran CONVICTEDREPORT PENDING
About €283M (VAT lost in his case) · 2008–2009
Convicted for his role in the carbon-emissions-permit VAT fraud that cost the French treasury.
SOURCE: Paris Criminal Court, 2016
FRAUD BY CATEGORY
share of payment-fraud value by payment instrument · 2025
Credit transfer
39.1%
Card payment
34.9%
Cheque
18.5%
ATM withdrawal
3.4%
Direct debit
2.7%
Commercial bills
1.6%
SOURCE: Banque de France, Observatoire de la sécurité des moyens de paiement, Rapport annuel 2025, Sept 2026
KEY NUMBERS
€1.241B Payment fraud losses in 2025 (+3.8%) (Banque de France OSMP, Sept 2026)
€516M Fraud by manipulation (>40% of total) in 2025 (Banque de France OSMP, Sept 2026)
7.2M Fraudulent transactions in 2025 (-7.6%) (Banque de France OSMP, Sept 2026)
WHO FIGHTS IT
Parquet national financier (PNF) and OCRGDF (central office against serious financial crime).
Banque de France Observatoire de la sécurité des moyens de paiement sets anti-fraud action plans.
Anti-fraud measures such as IBAN-name checks (Verification of Payee) under the EU Instant Payments Regulation (2025).
SOURCES
Banque de France, OSMP Rapport annuel 2025, Sept 2026
French Wikipedia summary of court record (Chikli)
Paris Criminal Court (Kerviel), Oct 2010
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇳🇱
NETHERLANDS
Enforcement hub
CAPITAL Amsterdam · POPULATION 18.2M (2024, UN est.)
FRAUD TYPES
Money laundering, dark web hosting, ransomware
KEY FACTS
Dark web infrastructure hosted. Europol HQ = enforcement hub. Several major takedowns.
BORN HERE
Nobody in our case files was born in Netherlands yet.
OPERATED HERE
Physically based or working in Netherlands — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Netherlands
WHAT THEY DID HERE, AND WHEN
28 June 2012Arrested in the Netherlands; fights extradition for nearly three years.SOURCE: DOJ
OUR CASES BY CATEGORY
Share of the 1 case tied to Netherlands (born or operated here)
CARD
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Bank-helpdesk (spoofing) fraudPhishing and 'money mule' networksAnti-money-laundering failures at banksOnline marketplace fraud
THE PICTURE

Dutch payment fraud rose sharply in 2025: fraudulent transactions increased 30% to about 658,000 and losses 22% to €198 million, with credit transfers accounting for €148 million (De Nederlandsche Bank, June 2026). Bank-helpdesk fraud, in which criminals pose as bank staff, cost €25.8 million, and Dutch banks say about 70% of online fraud now begins on social media (Betaalvereniging Nederland, 2026). As a major financial and logistics hub, the Netherlands has also faced large anti-money-laundering cases against its biggest banks. Enforcement involves the Public Prosecution Service (OM), FIOD, the police and DNB.

TOP FRAUDSTERS FROM HERE
ING Bank SETTLEDREPORT PENDING
€775M (settlement) · 2010–2016
Settled with Dutch prosecutors after years of failing to spot money laundering through client accounts.
SOURCE: Openbaar Ministerie, Sept 2018
ABN AMRO SETTLEDREPORT PENDING
€480M (settlement) · 2014–2020
Settled with Dutch prosecutors over serious anti-money-laundering failures.
SOURCE: Openbaar Ministerie, Apr 2021
FRAUD BY CATEGORY
share of payment-fraud losses by payment method (DNB, as published; rounded) · 2025
Credit transfers
75%
Card payments
21%
ATM cash withdrawals
5%
SOURCE: De Nederlandsche Bank, 'Meer fraude bij betalingen in 2025', 30 June 2026
KEY NUMBERS
€198M Payment fraud losses in 2025 (+22%) (DNB, Jun 2026)
658,000 Fraudulent payment transactions in 2025 (+30%) (DNB, Jun 2026)
€25.8M Bank-helpdesk fraud losses in 2025 (Betaalvereniging Nederland, 2026)
70% Share of online fraud that starts on social media (Betaalvereniging Nederland, 2026)
WHO FIGHTS IT
Openbaar Ministerie, FIOD (fiscal intelligence and investigation service) and national police.
De Nederlandsche Bank supervises banks' AML controls and publishes payment-fraud statistics.
Landmark bank settlements: ING (2018), ABN AMRO (2021).
SOURCES
De Nederlandsche Bank, 30 Jun 2026
Betaalvereniging Nederland, 2026
Openbaar Ministerie press releases, Sept 2018 and Apr 2021
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇪🇸
SPAIN
Moderate
CAPITAL Madrid · POPULATION 47.9M (2024, UN est.)
FRAUD TYPES
Investment fraud, romance scams, crypto fraud
KEY FACTS
Pig butchering victims. Benidorm call center scams targeting UK retirees. Growing crypto fraud.
BORN HERE
Nobody in our case files was born in Spain yet.
OPERATED HERE
Nobody in our case files is documented as operating from Spain yet.
KNOWN FOR
Political kickback schemesPhishing and smishing networksInvestment-fraud call centresBank executive misuse of funds
THE PICTURE

Spain's best-known fraud cases involve political corruption and misuse of public or bank money, notably the Gürtel kickbacks network linked to the Partido Popular (National High Court, 2018) and the Bankia 'black cards' scandal (2017). Spain is also a base for organised fraud networks running phishing and 'smishing', fake-investment call centres and romance scams, which the Guardia Civil and Policía Nacional dismantle in regular operations, often with Europol. Enforcement is led by the Anti-Corruption Prosecutor's Office, the National High Court (Audiencia Nacional), the CNMV and SEPBLAC.

TOP FRAUDSTERS FROM HERE
Francisco Correa CONVICTEDREPORT PENDING
Not fixed in public summaries · 1999–2009
Businessman who led the Gürtel network of kickbacks for public contracts from Partido Popular-run administrations.
SOURCE: Audiencia Nacional, May 2018 (51 years)
Luis Bárcenas CONVICTEDREPORT PENDING
Not fixed in public summaries · 1999–2009
Former Partido Popular treasurer convicted in the Gürtel case over illegal party financing and money kept in Swiss accounts.
SOURCE: Audiencia Nacional, May 2018
Rodrigo Rato CONVICTEDREPORT PENDING
About €100K (card misuse); €568K ordered repaid to tax authorities (2024 case) · 2010–2011; 2000s
Former IMF chief and Bankia chairman convicted of misusing corporate credit cards and later of tax crimes and money laundering.
SOURCE: Audiencia Nacional, Feb 2017; Madrid court, Dec 2024
Iñaki Urdangarin CONVICTEDREPORT PENDING
Not fixed in public summaries · 2004–2006
Former Duke of Palma convicted over the Nóos Institute's diversion of public money.
SOURCE: Supreme Court of Spain, Jun 2018 (5 yrs 10 mths)
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Fiscalía Anticorrupción and the Audiencia Nacional.
Policía Nacional and Guardia Civil cybercrime units, frequent joint operations with Europol.
CNMV warnings on unauthorised investment firms; SEPBLAC financial-intelligence unit.
SOURCES
Audiencia Nacional, Gürtel ruling, May 2018
Wikipedia summary of court record (Rodrigo Rato)
Supreme Court of Spain, Nóos ruling, Jun 2018
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇮🇹
ITALY
Moderate
CAPITAL Rome · POPULATION 59.3M (2024, UN est.)
FRAUD TYPES
Mafia-linked financial fraud, card fraud, identity theft
KEY FACTS
'Ndrangheta financial crime operations. SIM swap growing. Traditional organized crime adapting to digital.
BORN HERE
1 person in our case files was born in Italy. Tap to open the report.
OPERATED HERE
Nobody in our case files is documented as operating from Italy yet.
OUR CASES BY CATEGORY
Share of the 1 case tied to Italy (born or operated here)
PONZI
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
VAT carousel fraudCorporate accounting fraudFraud against EU fundsTax-credit fraud
THE PICTURE

Italy's largest fraud cases include corporate accounting frauds such as Parmalat, whose 2003 collapse revealed a €14 billion hole in its accounts, and cross-border VAT carousel fraud: the EU Public Prosecutor's Office's 'Operation Admiral' (2024) exposed a VAT fraud network estimated at €2.2 billion run largely from Italy. Mafia groups are also involved in tax-credit and public-funds fraud, including EU recovery funds (EPPO annual reports). Enforcement is led by the Guardia di Finanza, the European Public Prosecutor's Office's Italian delegates, CONSOB and the UIF at the Bank of Italy.

TOP FRAUDSTERS FROM HERE
Calisto Tanzi CONVICTEDREPORT PENDING
€14B (hole in Parmalat's accounts); ~€800M (embezzled) · 1990s–2003
Founder of Parmalat, whose collapse exposed years of falsified accounts; he was also found to have diverted company money.
SOURCE: Milan court 2008; Parma court 2010 (18 years)
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
€2.2B Estimated damage in EPPO 'Operation Admiral' VAT fraud (European Public Prosecutor's Office, 2024)
WHO FIGHTS IT
Guardia di Finanza (financial police) and ordinary prosecutors.
European Public Prosecutor's Office (EPPO), which has handled more Italian cases than any other member state.
CONSOB (markets regulator) and UIF (Bank of Italy financial-intelligence unit).
SOURCES
Wikipedia summary of court record (Calisto Tanzi)
European Public Prosecutor's Office, Operation Admiral press release, 2024
EPPO Annual Reports
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇸🇪
SWEDEN
Low source
CAPITAL Stockholm · POPULATION 10.6M (2024, UN est.)
FRAUD TYPES
Ransomware victim, identity fraud
KEY FACTS
Nordics generally low fraud source. Growing target due to high digital adoption.
BORN HERE
Nobody in our case files was born in Sweden yet.
OPERATED HERE
Physically based or working in Sweden — lived, ran an office, met victims or was stationed here, per the record. Hacking a target here does not count.
Malmö, Sweden
WHAT THEY DID HERE, AND WHEN
1969–1970Serves time in Malmö before deportation to the US.SOURCE: case brief
OUR CASES BY CATEGORY
Share of the 1 case tied to Sweden (born or operated here)
BANK & WIRE
100%
FRAUD METHODS TIED HERE
From the Global Fraud Encyclopedia and the cases above. Tap a method for its page.
KNOWN FOR
Phone and BankID scamsWelfare-benefit fraud by criminal networksBank money-laundering failuresInvestment scams
THE PICTURE

Sweden has seen fast-growing fraud against older people, including phone scams in which callers pose as bank or police staff and ask victims to approve BankID logins, much of it linked to organised criminal networks (Swedish Police Authority). Welfare-benefit fraud by criminal groups has also been a political priority. In banking, Swedbank was fined SEK 4 billion in 2020 over anti-money-laundering failures in its Baltic branches, and former CEO Birgitte Bonnesen was convicted of gross fraud on appeal in 2024 for misleading statements (Svea Court of Appeal). Enforcement involves the Swedish Police, the Economic Crime Authority (Ekobrottsmyndigheten) and Finansinspektionen.

TOP FRAUDSTERS FROM HERE
Swedbank SANCTIONEDREPORT PENDING
SEK 4B (about $380M) (fine) · 2014–2019
Fined by the Swedish FSA over serious anti-money-laundering failures in its Baltic operations.
SOURCE: Finansinspektionen, Mar 2020
Birgitte Bonnesen CONVICTEDREPORT PENDING
Not applicable (15-month sentence) · 2018–2019
Former Swedbank CEO convicted of gross fraud for misleading investors about the bank's money-laundering exposure; acquitted at first instance in 2023.
SOURCE: Svea Court of Appeal, Sept 2024
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Swedish Police Authority and Ekobrottsmyndigheten (Economic Crime Authority).
Finansinspektionen (FSA) supervises banks' AML controls.
Tighter rules on BankID and fraud-related bank refunds under discussion since 2023.
SOURCES
Finansinspektionen, Swedbank sanction, Mar 2020
Wikipedia summary of court record (Birgitte Bonnesen), 2024
Swedish Police Authority fraud warnings
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇨🇭
SWITZERLAND
Money laundering hub
CAPITAL Bern · POPULATION 8.9M (2024, UN est.)
FRAUD TYPES
Money laundering, banking secrecy exploitation, crypto hub
KEY FACTS
Banking system historically exploited for laundering. Growing crypto industry = new fraud surface.
BORN HERE
Nobody in our case files was born in Switzerland yet.
OPERATED HERE
Nobody in our case files is documented as operating from Switzerland yet.
KNOWN FOR
Money laundering through private banksCommodity-trading briberyPonzi and investment fraudTax-evasion facilitation
THE PICTURE

As a global wealth-management and commodity-trading centre, Switzerland's fraud exposure lies mainly in laundering, corruption and investment fraud rather than retail scams. Commodity trader Glencore, based in Baar, pleaded guilty in 2022 to bribery and market-manipulation charges in the US and UK (US DOJ; UK SFO, 2022), and Credit Suisse paid about $475 million in 2021 over the Mozambique 'tuna bonds' loans (US DOJ, SEC and UK FCA, Oct 2021). Domestic cases include Dieter Behring's Ponzi scheme, which caused losses estimated at CHF 800 million (Federal Criminal Court, 2016). Enforcement falls to the Office of the Attorney General, FINMA and the MROS financial-intelligence unit.

TOP FRAUDSTERS FROM HERE
Glencore PLEADED GUILTYREPORT PENDING
About $1.5B (combined US, UK and Brazil penalties) · 2007–2018
Baar-based commodity trader that pleaded guilty to bribing officials in several countries and manipulating fuel-oil prices.
SOURCE: US DOJ, May 2022; UK SFO, Jun 2022
Credit Suisse SETTLEDREPORT PENDING
About $475M (settlement) · 2013–2016
Settled US, UK and Swiss cases over hidden loans to Mozambique state firms that were tied to bribes and misled investors.
SOURCE: US DOJ, SEC and UK FCA, Oct 2021
Dieter Behring CONVICTEDREPORT PENDING
About CHF 800M (investor losses) · 1998–2004
Ran a supposed trading system that was in fact a Ponzi scheme; he died in 2019 before serving his sentence.
SOURCE: Federal Criminal Court, Sept 2016 (5.5 years)
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Office of the Attorney General of Switzerland (OAG) and cantonal prosecutors.
FINMA (financial-market supervisor) and MROS (Money Laundering Reporting Office).
Federal Criminal Court in Bellinzona tries major economic-crime cases.
SOURCES
US DOJ, Glencore plea, May 2022
UK SFO, Glencore, Jun 2022
US DOJ / SEC / FCA, Credit Suisse Mozambique, Oct 2021
German Wikipedia summary of court record (Dieter Behring)
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇮🇪
IRELAND
Low
CAPITAL Dublin · POPULATION 5.3M (2024, UN est.)
FRAUD TYPES
Corporate tax arbitrage, emerging crypto fraud
KEY FACTS
Tech company headquarters = potential corporate fraud surface. Low street-level fraud.
BORN HERE
Nobody in our case files was born in Ireland yet.
OPERATED HERE
Nobody in our case files is documented as operating from Ireland yet.
KNOWN FOR
Authorised push payment scamsPhishing and smishingMoney mulesBanking-crisis fraud
THE PICTURE

Payment service providers in Ireland reported more than €179 million in fraudulent payments in 2025, up 27% on 2024, with authorised push payment scams worth €74.86 million, driven by impersonation and investment scams (Central Bank of Ireland data, via BPFI, Sept 2026). The biggest fraud prosecutions stem from the 2008 banking crisis, especially Anglo Irish Bank, where executives were convicted over schemes to disguise the bank's position (Irish courts, 2016–2018). As an EU base for tech and financial firms, Ireland also handles large volumes of phishing, 'smishing' and money-mule activity. Enforcement is led by the Garda National Economic Crime Bureau, the Corporate Enforcement Authority and the Central Bank.

TOP FRAUDSTERS FROM HERE
David Drumm CONVICTEDREPORT PENDING
€7.2B (circular deposits in the scheme) · 2008
Former Anglo Irish Bank CEO convicted of conspiracy to defraud and false accounting over a scheme to inflate the bank's deposits in 2008.
SOURCE: Dublin Circuit Criminal Court, Jun 2018 (6 years)
Denis Casey CONVICTEDREPORT PENDING
€7.2B (circular deposits in the scheme) · 2008
Former Irish Life & Permanent CEO convicted of conspiracy to defraud for the same deposit scheme with Anglo executives John Bowe and Willie McAteer.
SOURCE: Dublin Circuit Criminal Court, Jun 2016
Seán FitzPatrick ACQUITTEDREPORT PENDING
Not applicable · 2002–2007
Former Anglo Irish Bank chairman tried for misleading auditors about his loans; the judge directed his acquittal.
SOURCE: Dublin Circuit Criminal Court, May 2017
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
KEY NUMBERS
€179M Fraudulent payments reported by payment providers in 2025 (+27%) (BPFI / Central Bank of Ireland, Sept 2026)
€74.86M Authorised push payment fraud in 2025 (BPFI / Central Bank of Ireland, Sept 2026)
WHO FIGHTS IT
Garda National Economic Crime Bureau (GNECB) and the Garda National Cyber Crime Bureau.
Corporate Enforcement Authority (formerly ODCE) and the Central Bank of Ireland.
Communications Regulation (Amendment) Act 2023 and ComReg measures against SMS/phone spoofing.
SOURCES
BPFI, 'Consumers warned to be on alert for scams', 4 Sept 2026
Wikipedia summary of court record (David Drumm)
Irish court reports on Anglo Irish Bank trials, 2016–2018
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
🇱🇺
LUXEMBOURG
#1 Fraud Resilience (Sumsub)
CAPITAL Luxembourg City · POPULATION 0.67M (2024, UN est.)
FRAUD TYPES
Lowest fraud vulnerability in the world
KEY FACTS
0.8 Sumsub fraud index score — best in the world. Strong regulation, small population, advanced controls.
BORN HERE
Nobody in our case files was born in Luxembourg yet.
OPERATED HERE
Nobody in our case files is documented as operating from Luxembourg yet.
KNOWN FOR
Investment-fund domicile risksMoney-laundering exposureMadoff feeder fundsEspírito Santo holding collapse
THE PICTURE

Luxembourg is a major fund-management and private-banking centre, so its fraud exposure is mainly as a place where investment vehicles are domiciled and illicit money may pass through, rather than as a source of retail scams. It featured in the Madoff fallout through feeder funds domiciled there, and in the 2014 collapse of the Espírito Santo group, whose holding company was registered in Luxembourg. The FATF's 2023 mutual evaluation rated Luxembourg's anti-money-laundering framework as largely effective. Enforcement falls to the Luxembourg public prosecutor's economic and financial unit, the CSSF regulator and the Cellule de renseignement financier (CRF).

TOP FRAUDSTERS FROM HERE
No individual case from here is documented well enough to publish yet.
FRAUD BY CATEGORY
No official body here publishes a breakdown of fraud by type, so we show none rather than guess.
WHO FIGHTS IT
Parquet de Luxembourg (economic and financial section) and the Judicial Police.
CSSF (Commission de Surveillance du Secteur Financier) and the CRF financial-intelligence unit.
FATF mutual evaluation, 2023.
SOURCES
FATF, Mutual Evaluation of Luxembourg, 2023
CSSF public warnings
Case lists and figures compiled September 2026 from court records, regulators and major press; statuses change. Series reports above are fact-checked case files.
SINGLE PEOPLE
One person at the centre of the case. Ranked highest to lowest.
GROUPS
Organisations, gangs and state hacking units: many people, one name. Ranked highest to lowest.
FRAUD METHODS
110 methods from the TraceChain Global Fraud Encyclopedia, ranked worst to least. Tap one for where it came from and who used it. Loss figures are the Encyclopedia's and measure different things.
USED BY PEOPLE IN OUR CASE FILES
CATASTROPHIC
SEVERE
HIGH
MODERATE-HIGH
MODERATE
MODERATE-LOW
LOW-MODERATE
LOW
METHOD #1 OF 110
Pig Butchering (Romance-Investment Scam)
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$50-75B/year
WHERE IT'S CONCENTRATED
Myanmar, Cambodia, Laos (Chinese-led syndicates)
IN SHORT
Industrial-scale romance scams via forced labor compounds. 300,000+ trafficked workers from 66 countries. Victims manipulated into fake crypto investments. $8.6B US losses in 2025 (FBI). AI + deepfakes scaling operations. Fastest-growing fraud type on earth.
IN OUR CASE FILES — MOST TAKEN TO LEAST
For pig-butchering scam centres
WHERE IT CAME FROM
FIRST SEEN: c. 2016 · GOING FOR: About 10 years (since c. 2016); global since c. 2020

The name is a translation of the Chinese term 'sha zhu pan' ('killing-pig game'), used from about 2016-2017 for scams that 'fatten' a victim with attention and fake profits before taking everything. It began as a scam aimed mainly at Chinese-speaking victims and was run by organised crime groups linked to online gambling. After Cambodia's 2019 ban on online gambling and the COVID-19 border closures, many casino and gambling compounds in Cambodia, Myanmar and Laos turned to industrial-scale scamming, often staffed by trafficked workers held against their will (UN OHCHR, Aug 2023). From about 2020 the scripts were translated and aimed at victims worldwide, mostly paid in cryptocurrency. The FBI now calls crypto investment fraud the single largest source of reported losses to Americans.

HOW IT WORKS

A stranger makes contact through a 'wrong number' text, a dating app or social media, and builds a friendly or romantic relationship over weeks. The conversation moves to an encrypted messaging app, and the contact mentions how much they earn trading crypto, gold or forex. The victim is steered to a fake trading website or app that shows invented profits, so they invest more and may even be allowed a small early withdrawal. When the victim tries to take the money out, they are asked for 'taxes' or 'fees', and then the platform and the contact disappear. Many of the people typing the messages are themselves trafficking victims forced to work in scam compounds.

WARNING SIGNS
Unsolicited 'wrong number' message that turns into friendship or romanceNew online contact who never video-calls but talks about investingPressure to use a specific trading app or website you had never heard ofBig 'profits' on screen but fees or taxes demanded before you can withdrawRequest to move the chat to WhatsApp, Telegram or another private app
GOVERNMENTS LINKED TO IT
Myanmar (state-linked militia)
US Treasury designated the Karen National Army and its leader Saw Chit Thu as a transnational criminal organisation for providing security and leasing land to scam syndicates; the group was formerly the Karen State Border Guard Force, a militia aligned with the Myanmar military, and Saw Chit Thu held an army colonel's rank
SOURCE: US Treasury OFAC, 5 May 2025
Myanmar (Kokang Self-Administered Zone officials)
A Chinese court convicted Bai Suocheng, former chairman of the Kokang Self-Administered Zone, and family members of organised fraud, trafficking and homicide tied to scam centres, sentencing him to death; the Myanmar junta had handed the group to China in January 2024
SOURCE: Shenzhen Intermediate People's Court via Caixin and Global Times, Nov 2025
Cambodia (politically connected conglomerate)
US prosecutors allege Prince Group chairman Chen Zhi, a former adviser to Cambodian leaders, ran forced-labour scam compounds and used political influence and bribes to protect them; Prince Group denies wrongdoing, and Cambodia later arrested him and sent him to China
SOURCE: US DOJ indictment (E.D.N.Y.), Oct 2025; CNN, Jan 2026
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Chen Zhi (Prince Group) CHARGED (NOT TRIED)REPORT PENDING
About $15B (127,271 bitcoin the US moved to forfeit) · 2015-2025
Indicted in the US as the alleged head of Cambodia's Prince Group, accused of running forced-labour crypto-scam compounds; extradited from Cambodia to China in January 2026.
SOURCE: US DOJ and US Treasury, 14 Oct 2025; CNN, 7 Jan 2026
#2 Bai family syndicate (Bai Suocheng) CONVICTEDREPORT PENDING
Over 29B yuan (about $4.1B) in fraud losses found by the court · 2015-2023
Kokang, Myanmar crime family convicted in China of organised fraud, trafficking and homicide tied to scam centres; five death sentences, four members executed in early 2026.
SOURCE: Caixin Global, 4 Nov 2025; Global Times, Feb 2026
#3 Huione Group SANCTIONEDREPORT PENDING
At least $4B in illicit proceeds laundered, Aug 2021-Jan 2025 (FinCEN finding) · 2021-2025
Cambodia-based payments and 'guarantee' marketplace group that FinCEN found laundered proceeds of pig-butchering scams and North Korean hacks; cut off from the US financial system.
SOURCE: FinCEN final rule, Federal Register, 16 Oct 2025
#4 Ming family syndicate (Kokang) CONVICTEDREPORT PENDING
Over 10B yuan (about $1.4B) in gambling and fraud proceeds · 2015-2023
Myanmar crime family convicted by a Chinese court of fraud, killings and other crimes linked to scam compounds; 11 members executed in January 2026.
SOURCE: Wenzhou Intermediate People's Court via CNN, 30 Sep 2025; SCMP, Jan 2026
#5 She Zhijiang (Yatai) CHARGED (NOT TRIED)REPORT PENDING
Not published (Chinese media cite transactions worth billions of yuan) · 2017-2022
Businessman behind the Shwe Kokko development in Myanmar, a hub linked to scam compounds; sanctioned by the US and UK and extradited from Thailand to China.
SOURCE: ABC News (Australia), 12 Nov 2025
#6 Saw Chit Thu (Karen National Army) SANCTIONEDREPORT PENDING
No figure published · 2017-2025
Myanmar militia leader sanctioned by the US and UK for providing security and land to scam compounds in Karen State.
SOURCE: US Treasury OFAC, 5 May 2025
MOST RELEVANT COUNTRY
Cambodia (source)
US and UK authorities describe Cambodia-based networks such as Prince Group and Huione as among the largest operators and launderers of these scams, in the biggest action ever taken against Southeast Asian scam networks (US Treasury, Oct 2025).
COUNTRIES MOST TIED TO IT
Cambodia (scam compounds, laundering)
Myanmar (scam compounds in border areas)
Laos (Golden Triangle special economic zone compounds)
China (early victims; prosecutes kingpins)
United States (largest reported victim losses)
KEY NUMBERS
$7.2 billion Losses to crypto investment fraud reported to the FBI in 2025, the largest single loss category (FBI IC3 Internet Crime Report, 2026)
$15 billion Bitcoin the US moved to forfeit in the Prince Group case, its largest ever (US DOJ, Oct 2025)
120,000 + 100,000 People estimated to be held and forced to scam in Myanmar and Cambodia respectively (estimate) (UN OHCHR, Aug 2023)
SOURCES
FBI IC3 2025 Internet Crime Report, 2026
US DOJ press release on Chen Zhi indictment, 14 Oct 2025
US Treasury press release sb0278, 14 Oct 2025
US Treasury OFAC press release sb0312, 5 May 2025
FinCEN Huione final rule, Federal Register, 16 Oct 2025
US DOJ, sentencing, 9 Feb 2026
CNN, Chen Zhi extradition, 7 Jan 2026
CNN, Ming family sentencing, 30 Sep 2025
Caixin Global, Bai family sentencing, 4 Nov 2025
ABC News (Australia), She Zhijiang extradition, 12 Nov 2025
UN OHCHR report on online scam operations in Southeast Asia, Aug 2023
METHOD #2 OF 110
State-Sponsored Crypto Theft
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$6.75B cumulative
WHERE IT'S CONCENTRATED
North Korea ()
IN SHORT
Government military hackers targeting crypto exchanges. $2.02B in 2025 alone — 76% of all platform hacks. $1.5B Bybit hack (Feb 2025) = largest single crypto theft ever. Funds nuclear weapons program.
IN OUR CASE FILES — MOST TAKEN TO LEAST
State-run crypto theft (attributed)
WHERE IT CAME FROM
FIRST SEEN: 2017 (crypto); bank heists from 2016 · GOING FOR: About 9 years against crypto (since 2017)

This method has one well-documented state actor: North Korea. Hacking units the US and UN attribute to its Reconnaissance General Bureau (tracked as the , APT38 and 'TraderTraitor') first stole from banks, most notably the $81 million taken from Bangladesh Bank via SWIFT messages in 2016. From 2017 they turned to cryptocurrency exchanges in South Korea and elsewhere, then to crypto bridges, wallets and trading firms. Each year's haul has tended to set records, peaking with the roughly $1.5 billion Bybit theft in February 2025. The UN Panel of Experts has reported that the proceeds help fund the country's weapons programmes.

HOW IT WORKS

Attackers usually go after people, not code: they pose as recruiters or business contacts and send a fake job test, document or trading app that installs malware. Once inside, they steal the keys or sign-in sessions that control a company's wallets, or trick staff into approving a disguised transaction. The stolen coins are moved quickly through many wallets, swap services and mixers, often converted to bitcoin, and finally cashed out through brokers. Individuals are mainly at risk through fake job offers and fake remote IT workers.

WARNING SIGNS
Unsolicited job offer that asks you to download a coding test or appRecruiter who insists on a specific meeting or chat toolRemote job applicant who avoids video, uses a laptop shipped to someone else or pays into odd accountsWallet signing screen that shows something different from what you expectedUrgent requests to approve a large transfer outside the normal process
GOVERNMENTS LINKED TO IT
North Korea
US Treasury designated the , Bluenoroff and Andariel as controlled by the Reconnaissance General Bureau, North Korea's main intelligence agency; the FBI attributed the Ronin (2022), DMM Bitcoin (2024) and Bybit (2025) thefts to North Korea
SOURCE: US Treasury OFAC, 13 Sep 2019; FBI, 14 Apr 2022, 23 Dec 2024 and 26 Feb 2025
North Korea
The UN Panel of Experts investigated dozens of crypto thefts attributed to North Korea and reported the proceeds help fund its weapons programmes; after the panel's mandate ended, an 11-country monitoring team reported at least $2.84B stolen from Jan 2024 to Sep 2025
SOURCE: UN Panel of Experts, Mar 2024; Multilateral Sanctions Monitoring Team, 22 Oct 2025
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Park Jin Hyok, Jon Chang Hyok and Kim Il CHARGED (NOT TRIED)REPORT PENDING
Over $1.3B in cash and crypto they allegedly tried to steal or extort · 2014-2020
North Korean military intelligence hackers indicted in the US over bank and crypto thefts, the Sony hack and WannaCry; none is in custody.
SOURCE: US DOJ, 17 Feb 2021
#3 Tian Yinyin and Li Jiadong CHARGED (NOT TRIED)REPORT PENDING
Over $100M in stolen crypto allegedly laundered · 2018-2019
Chinese nationals charged in the US and sanctioned for allegedly laundering crypto stolen by North Korean hackers from an exchange in 2018.
SOURCE: US DOJ and US Treasury, 2 Mar 2020
#4 Ghaleb Alaumary PLEADED GUILTYREPORT PENDING
Tens of millions of dollars laundered (DOJ) · 2017-2020
Canadian-American launderer who pleaded guilty, including to laundering money for a North Korean-linked bank heist scheme, and was sentenced to over 11 years.
SOURCE: US DOJ, 8 Sep 2021
#5 Rim Jong Hyok CHARGED (NOT TRIED)REPORT PENDING
No total published · 2021-2023
Alleged member of North Korea's Andariel unit charged over ransomware attacks on US hospitals, with ransoms allegedly used to fund further hacking of defence and technology targets.
SOURCE: US DOJ, 25 Jul 2024
MOST RELEVANT COUNTRY
North Korea (source)
Chainalysis attributes about 60% or more of all crypto stolen in 2025 to North Korean hackers, a record $2.02 billion (Chainalysis, Dec 2025).
COUNTRIES MOST TIED TO IT
North Korea (state source)
United States (victims; leads indictments and sanctions)
South Korea (early exchange victims)
Japan (DMM Bitcoin victim, 2024)
United Arab Emirates (Bybit victim, 2025)
China (location of some front companies and launderers, per US filings)
KEY NUMBERS
$2.02 billion Crypto stolen by North Korea-linked hackers in 2025, a record (Chainalysis, Dec 2025)
About $1.5 billion Bybit theft, February 2025, the largest crypto theft ever recorded (FBI PSA, 26 Feb 2025)
$6.75 billion Estimated all-time crypto stolen by North Korean hackers (lower bound) (Chainalysis, Dec 2025)
At least $2.84 billion Crypto stolen by North Korea from Jan 2024 to Sep 2025 (Multilateral Sanctions Monitoring Team, 22 Oct 2025)
SOURCES
US Treasury OFAC press release, 13 Sep 2019
FBI statement on Ronin, 14 Apr 2022
FBI statement on DMM Bitcoin, 23 Dec 2024
FBI PSA on Bybit, 26 Feb 2025
US DOJ, indictment of Park Jin Hyok, Jon Chang Hyok and Kim Il, 17 Feb 2021
US DOJ and Treasury, Tian Yinyin and Li Jiadong, 2 Mar 2020
US DOJ, Ghaleb Alaumary sentencing, 8 Sep 2021
US DOJ, Rim Jong Hyok indictment, 25 Jul 2024
UN Panel of Experts on DPRK, Mar 2024
Multilateral Sanctions Monitoring Team report, 22 Oct 2025
Chainalysis, North Korea crypto theft analysis, Dec 2025
Infosecurity Magazine, Dec 2025
METHOD #3 OF 110
Ransomware
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$20B+ annual global cost
WHERE IT'S CONCENTRATED
Russia, Ukraine, Iran, China
IN SHORT
File encryption + extortion. LockBit, BlackCat, REvil — all Russian-speaking. 44% of confirmed breaches (Verizon 2025). Double/triple extortion (encrypt + leak + DDoS). Healthcare, schools, governments targeted.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Ransomware: WannaCry, Maui (attributed)
WHERE IT CAME FROM
FIRST SEEN: 1989 · GOING FOR: About 37 years (since 1989); a mass-scale crime since c. 2013

The first known ransomware was the 1989 'AIDS Trojan' by biologist Joseph Popp, mailed on floppy disks to AIDS researchers; it hid files and demanded $189 sent to a post box in Panama. It stayed rare until cryptocurrency made anonymous payment easy: CryptoLocker (2013), linked by the FBI to Evgeniy Bogachev's GameOver Zeus botnet, showed how profitable encrypting files could be. In 2017 WannaCry and NotPetya spread worldwide and were later attributed by the US and UK to North Korea and Russia's GRU respectively. Since about 2019 the model has become 'ransomware-as-a-service', where developers rent their tools to affiliates and add 'double extortion' by threatening to leak stolen data.

HOW IT WORKS

Criminals get into a network through a phishing email, stolen passwords, or an unpatched internet-facing system. They quietly spread, copy sensitive data, and then lock the organisation's files with encryption. A ransom note demands payment, usually in cryptocurrency, for a decryption key and a promise not to publish the stolen data. Hospitals, schools, councils and companies are hit because downtime puts them under pressure to pay.

WARNING SIGNS
Unexpected login from a new location or remote-access toolSecurity software suddenly disabled or backups deletedLarge unexplained data transfers out of the networkFiles renamed with odd extensions and ransom notes appearingPhishing emails with urgent invoices or shipping documents
GOVERNMENTS LINKED TO IT
North Korea
US and UK governments publicly attributed the 2017 WannaCry ransomware to North Korea; the US later charged Andariel member Rim Jong Hyok over ransomware attacks on US hospitals
SOURCE: White House and UK Foreign Office, Dec 2017; US DOJ, 25 Jul 2024
Russia
The US charged six officers of Russia's GRU Unit 74455 over the 2017 NotPetya attack, which posed as ransomware; US Treasury said Evil Corp leader Maksim Yakubets provided direct assistance to Russia's FSB
SOURCE: US DOJ, 19 Oct 2020; US Treasury OFAC, 5 Dec 2019
Iran
US Treasury sanctioned individuals and companies affiliated with the Islamic Revolutionary Guard Corps for ransomware activity, and US agencies warned that Iran-based actors linked to the government were working with ransomware affiliates
SOURCE: US Treasury OFAC, 14 Sep 2022; FBI/CISA advisory, Aug 2024
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Dmitry Khoroshev ('LockBitSupp') CHARGED (NOT TRIED)REPORT PENDING
At least $500M in ransom payments received by LockBit (DOJ) · 2019-2024
Alleged creator and administrator of LockBit, for years the most widely used ransomware service; charged in the US and sanctioned by the US, UK and Australia.
SOURCE: US DOJ, 7 May 2024
#2 Mikhail Matveev ('Wazawaka') CHARGED (NOT TRIED)REPORT PENDING
Up to $200M in ransoms paid by victims (DOJ) · 2020-2023
Russian national charged with LockBit, Babuk and Hive attacks on US victims including police and hospitals; sanctioned by the US.
SOURCE: US DOJ, 16 May 2023
#3 Maksim Yakubets (Evil Corp) SANCTIONEDREPORT PENDING
Over $100M allegedly stolen (Treasury/DOJ) · 2009-2024
Alleged leader of Evil Corp, behind the Dridex malware and later ransomware such as BitPaymer; $5M US reward offered.
SOURCE: US Treasury OFAC and US DOJ, 5 Dec 2019
#4 Evgeniy Bogachev FUGITIVEREPORT PENDING
Over $100M in losses from GameOver Zeus (FBI) · 2011-2014
Alleged administrator of the GameOver Zeus botnet that spread CryptoLocker, one of the first large crypto-ransom schemes; $3M FBI reward.
SOURCE: US DOJ, 2 Jun 2014
#5 Yaroslav Vasinskyi (REvil) PLEADED GUILTYREPORT PENDING
$16M restitution ordered; over $700M in ransoms demanded (DOJ) · 2019-2021
Ukrainian REvil affiliate behind the 2021 Kaseya attack; extradited from Poland and sentenced to 13 years 7 months.
SOURCE: US DOJ, 1 May 2024
#6 Joseph Popp CHARGED (NOT TRIED)REPORT PENDING
$189 demanded per victim · 1989
Created the 1989 AIDS Trojan, the first known ransomware; arrested but ruled unfit to stand trial in the UK.
SOURCE: Wikipedia (AIDS (Trojan horse)); BBC
MOST RELEVANT COUNTRY
Russia (source)
Most of the largest ransomware groups the US has charged or sanctioned, including LockBit, Conti and Evil Corp, are Russian-speaking and based largely in Russia (US DOJ and Treasury, 2019-2024).
COUNTRIES MOST TIED TO IT
Russia (most major groups based there)
North Korea (state-linked attacks)
Iran (state-linked actors)
United States (most reported victims)
United Kingdom and Germany (frequent victims)
KEY NUMBERS
Over $820 million On-chain ransomware payments in 2025 (Chainalysis, early estimate) (Chainalysis, Feb 2026)
28% Share of ransomware victims who paid in 2025, the lowest on record (Chainalysis, Feb 2026)
3,611 Ransomware complaints to the FBI in 2025 (reported losses $32.3M, excluding downtime) (FBI IC3 Internet Crime Report, 2026)
SOURCES
FBI IC3 2025 Internet Crime Report, 2026
Chainalysis 2026 Crypto Crime Report (ransomware chapter), Feb 2026
The Record, Feb 2026
US DOJ, LockBit/Khoroshev, 7 May 2024
US DOJ, Matveev, 16 May 2023
US State Department, Conti reward, 6 May 2022
US Treasury OFAC, Evil Corp, 5 Dec 2019
US DOJ, GameOver Zeus, 2 Jun 2014
US DOJ, Hive, 26 Jan 2023
US DOJ, Vasinskyi sentencing, 1 May 2024
US DOJ, GRU NotPetya indictment, 19 Oct 2020
US Treasury OFAC, IRGC-affiliated ransomware actors, 14 Sep 2022
FBI/CISA advisory on Iran-based actors, Aug 2024
White House statement on WannaCry, Dec 2017
Wikipedia, AIDS (Trojan horse)
METHOD #4 OF 110
Ponzi Scheme
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$65B in fake account balances (Madoff) · ~$17B cash lost
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
New investor money pays old investors. Madoff (~$17B in cash lost; $65B was the fake balances), Stanford ($7B), Petters ($3.65B). Crypto variants: YieldVault, BitConnect. Collapse inevitable when recruitment slows.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Paid old investors with new money
New deposits paid old investors
Paid CD holders with new deposits
Paid old lenders with new money
The original: paid early investors with later deposits
WHERE IT CAME FROM
FIRST SEEN: 1920 (named); earlier examples from 1899 · GOING FOR: Over 100 years (since 1920)

The scheme is named after , who in 1920 in Boston promised 50% returns in 45 days from arbitrage on international postal reply coupons, while in fact paying early investors with later investors' money. The idea was older: William '520 Per Cent' Miller ran a similar scheme in Brooklyn in 1899, and Charles Dickens described one in 'Little Dorrit' (1857). Ponzi's collapse after about eight months made his name the label. The method has repeated in every era, from Albania's pyramid-scheme collapse in 1997 to 's decades-long fraud revealed in 2008, and today often appears as crypto 'yield' or 'staking' programmes.

HOW IT WORKS

An operator promises unusually high or unusually steady returns from a secret or complicated strategy. Early investors are paid 'returns' that are really money from newer investors, which builds trust and word-of-mouth. The operator often discourages withdrawals by rolling profits over or offering bonuses for recruiting. The scheme collapses when new money slows or many investors ask for their money back at once.

WARNING SIGNS
Guaranteed high returns with little or no riskReturns that are suspiciously consistent regardless of the marketStrategy described as secret or too complex to explainUnregistered seller or investmentTrouble or delays getting your money out
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Scott Rothstein PLEADED GUILTYREPORT PENDING
About $1.2B · 2005-2009
Florida lawyer who sold fake legal settlements to investors; sentenced to 50 years.
SOURCE: US DOJ, Jun 2010
MOST RELEVANT COUNTRY
United States (source and victim)
The largest documented Ponzi schemes, including Madoff, Stanford and Petters, were prosecuted in the US (US DOJ, 2009-2012).
COUNTRIES MOST TIED TO IT
United States (largest documented cases)
Albania (1997 pyramid-scheme collapse)
Russia (MMM, 1990s)
Bulgaria and Germany (OneCoin base and operations)
Antigua and Barbuda (Stanford International Bank)
KEY NUMBERS
$64.8 billion Fictitious balances on Madoff client statements when the scheme collapsed (US DOJ, 2009)
Over $4.3 billion Paid back to more than 40,000 Madoff victims by the Madoff Victim Fund (US DOJ, 2024)
$8.65 billion All investment-fraud losses reported to the FBI in 2025 (includes Ponzi and other investment scams) (FBI IC3 Internet Crime Report, 2026)
SOURCES
US DOJ, Madoff sentencing, 29 Jun 2009
US DOJ, Madoff Victim Fund distributions, 2024
US DOJ, Stanford sentencing, 14 Jun 2012
US DOJ, Petters sentencing, Apr 2010
US DOJ, Rothstein sentencing, Jun 2010
US DOJ / FBI, Ten Most Wanted, 2022
Wikipedia,
Smithsonian Magazine,
FBI IC3 2025 Internet Crime Report, 2026
METHOD #5 OF 110
Business Email Compromise (BEC)
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$2.9B (FBI IC3 2023)
WHERE IT'S CONCENTRATED
Nigeria, Ghana, Global
IN SHORT
Spoofed/hacked corporate email → fraudulent wire instructions. CEO fraud, vendor impersonation, payroll diversion. Black Axe syndicate. Average loss: $137K per incident.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Posed as a real supplier by email
Business email compromise schemes
WHERE IT CAME FROM
FIRST SEEN: Mid-2000s (CEO fraud); tracked by the FBI since 2013 · GOING FOR: About 20 years (since the mid-2000s)

BEC grew from older 'fake boss' and invoice scams done by phone and fax. In France, 'fraude au president' (CEO fraud) cases were documented from the mid-2000s, including those linked to Gilbert Chikli. The FBI began tracking BEC as its own crime type in 2013, as criminals used hacked or look-alike email accounts to redirect business payments. It has since spread to real-estate closings, payroll and vendor payments, and now uses AI voice and video deepfakes. It is consistently one of the two largest loss categories in FBI reporting.

HOW IT WORKS

A criminal gets into, or imitates, the email of an executive, supplier, lawyer or title company. They watch real conversations, then send a well-timed message asking for a payment, often saying bank details have changed or a deal is urgent and confidential. The money goes to an account the criminal controls and is quickly moved on through 'money mule' accounts. Some versions ask for gift cards, employee tax records or payroll changes instead.

WARNING SIGNS
Email saying a supplier's or seller's bank details have changedUrgent, confidential payment request from a boss who 'can't talk now'Email address or domain that differs by one characterPressure to skip normal approval or call-back checksRequest to change your salary deposit account by email
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Gilbert Chikli CONVICTEDREPORT PENDING
About EUR 50-80M obtained (reported estimates) · 2015-2017
French-Israeli fraudster who impersonated French minister Jean-Yves Le Drian, sometimes using a silicone mask on video calls, to obtain 'ransom' money from wealthy targets; sentenced to 11 years in Paris.
SOURCE: CNN and France 24, 12 Mar 2020
#4 Obinwanne Okeke ('Invictus Obi') PLEADED GUILTYREPORT PENDING
Nearly $11M · 2015-2019
Nigerian entrepreneur who took part in a phishing and BEC fraud against Unatrac Holding, Caterpillar's export sales office; sentenced to 10 years.
SOURCE: US DOJ (E.D. Va.), 16 Feb 2021
MOST RELEVANT COUNTRY
United States (victim)
The FBI received 24,768 BEC complaints with $3.05 billion in losses in 2025 alone (FBI IC3, 2026).
COUNTRIES MOST TIED TO IT
United States (largest reported victim losses)
Nigeria (many prosecuted actors, per US DOJ cases)
United Kingdom (victims and mule accounts)
Hong Kong and China (common destinations of stolen wires, per FBI PSAs)
France (early 'CEO fraud' cases)
KEY NUMBERS
$3.05 billion BEC losses reported to the FBI in 2025 (FBI IC3 Internet Crime Report, 2026)
24,768 BEC complaints to the FBI in 2025 (FBI IC3 Internet Crime Report, 2026)
$55 billion Exposed BEC losses reported worldwide, Oct 2013-Dec 2023 (FBI IC3 PSA, Sep 2024)
SOURCES
FBI IC3 2025 Internet Crime Report, 2026
FBI IC3 PSA 'Business Email Compromise: The $55 Billion Scam', Sep 2024
CNBC, 27 Mar 2019
CyberScoop, Dec 2019
CNN, 12 Mar 2020
France 24, 11 Mar 2020
US DOJ (C.D. Cal.), Abbas sentencing, 7 Nov 2022
US DOJ (E.D. Va.), Okeke sentencing, 16 Feb 2021
CNN, 17 Feb 2021
METHOD #6 OF 110
Card-Not-Present (CNP) Fraud
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$28.1B projected 2026
WHERE IT'S CONCENTRATED
Global (Russia source, US victim)
IN SHORT
Stolen card credentials used for online purchases. 81% of all fraud cases. 269M+ stolen card records on dark web. US has no SCA mandate — 42% of global losses.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Market sold stolen card data (per the DOJ)
The stolen card numbers were sold for fraud
Stole card data from retailers' networks
Sold stolen card numbers
WHERE IT CAME FROM
FIRST SEEN: 1970s-1980s (mail/phone order); online from late 1990s · GOING FOR: About 50 years; online since the late 1990s

CNP fraud began with mail-order and telephone-order sales in the 1970s and 1980s, when a card number and expiry date were enough to buy goods. E-commerce in the late 1990s made it global, and online 'carding' forums such as CarderPlanet (2001) and ShadowCrew (shut down by the US Secret Service in 2004) created markets for stolen card data. Large data breaches, such as those at TJX and Heartland in the 2000s, fed those markets. When chip cards made in-store fraud harder (the US shift in 2015), fraud moved further online. Today stolen card data comes from phishing, fake shops and 'web skimming' code on real checkout pages.

HOW IT WORKS

Criminals obtain card details through data breaches, phishing messages, fake online shops or malicious code hidden on legitimate checkout pages. The details are sold in bulk on criminal marketplaces. Buyers then use them to shop online, buy gift cards, or pay for services, often shipping to drop addresses. The cardholder usually finds out only when unfamiliar charges appear.

WARNING SIGNS
Small 'test' charges you do not recogniseTexts or emails asking you to 'verify' your card or a delivery feeOnline shop with prices far below normal and no real contact detailsOne-time passcodes arriving for purchases you did not makeCard details requested through a link rather than a trusted app
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 FIN7 (Fedir Hladyr, Andrii Kolpakov and others) CONVICTEDREPORT PENDING
Over $1B in losses to US businesses (DOJ estimate) · 2015-2018
Hacking group that stole card data from thousands of restaurant and retail systems; several members convicted in the US.
SOURCE: US DOJ, 2021
#2 Infraud Organization (Sergey Medvedev and others) CONVICTEDREPORT PENDING
Over $530M in actual losses (DOJ) · 2010-2018
Online carding forum with the slogan 'In Fraud We Trust'; 36 people charged in 2018 and co-founder Medvedev sentenced to 10 years.
SOURCE: US DOJ, 7 Feb 2018 and 2021
#4 Aleksei Burkov PLEADED GUILTYREPORT PENDING
Over $20M in fraudulent purchases (DOJ) · 2009-2013
Ran the CardPlanet website that sold stolen card data, mostly of US cardholders; sentenced to 9 years.
SOURCE: US DOJ, 26 Jun 2020
MOST RELEVANT COUNTRY
United States (victim)
The US accounted for about 25% of card spending but 42% of global card fraud losses in 2023 (Nilson Report, Jan 2025).
COUNTRIES MOST TIED TO IT
United States (largest share of card fraud losses)
Russia (home of many major carding forums and hackers prosecuted by the US)
Ukraine (FIN7 members prosecuted)
United Kingdom and EU (large remote card fraud volumes)
KEY NUMBERS
$33.83 billion Worldwide payment card fraud losses in 2023 (all card fraud, not only CNP) (Nilson Report, Jan 2025)
42% US share of global card fraud losses, vs 25% of card spending (2023) (Nilson Report, Jan 2025)
About 80% Share of card fraud value in the EU/EEA from remote (card-not-present) payments, 2024 (as summarised) (EBA/ECB joint payment fraud report, Dec 2025)
$282.7 million Credit card/check fraud losses reported to the FBI in 2025 (FBI IC3 Internet Crime Report, 2026)
SOURCES
Nilson Report, card fraud losses worldwide 2023, Jan 2025
EBA/ECB joint report on payment fraud, Dec 2025 (via A&O Shearman summary)
FBI IC3 2025 Internet Crime Report, 2026
US DOJ, FIN7 sentencings, 2021
US DOJ, Infraud indictment, 7 Feb 2018
US DOJ, sentencing, Mar 2010
US DOJ, Drinkman sentencing (Heartland case), 2018
US DOJ, Seleznev sentencing, 21 Apr 2017
US DOJ, Burkov sentencing, 26 Jun 2020
METHOD #7 OF 110
Money Laundering
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
2-5% of global GDP ($2T+)
WHERE IT'S CONCENTRATED
Global — UAE, Switzerland, UK, Singapore hubs
IN SHORT
Concealing origin of criminal proceeds. Real estate, shell companies, crypto, trade-based. Chen Zhi (Prince Group): US forfeiture action over ~$15B in bitcoin (alleged, Oct 2025). UNODC estimate: $800B-$2T annually.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Laundering through mixers and brokers
Ran a crypto-mixing service
Money laundering (alleged)
Binance failed to run an anti-money-laundering programme (guilty plea)
Money laundering (charged)
Money laundering
Money laundering (convicted)
Money laundering (Brazil conviction)
Exchange with almost no customer checks
Money-laundering conspiracy
Laundered the proceeds
Laundered through exchanges and luxury spending
Laundered the proceeds
Hid money in Swiss accounts
Ran an in-site crypto "bank"
Laundered scam victims' money
Helped launder the Bitfinex bitcoin
Converted and passed on the stolen crypto
Laundered the proceeds
WHERE IT CAME FROM
FIRST SEEN: 1920s-1930s (modern form); term popularised 1970s · GOING FOR: About 100 years in its modern form

Hiding the source of criminal money is as old as crime, but the modern practice is usually traced to US Prohibition-era gangs; the popular story that the term comes from Mafia-owned laundromats is unproven folklore. Meyer Lansky is widely credited with moving mob money through offshore Swiss accounts from the 1930s, and the phrase 'money laundering' appeared in the press during the Watergate scandal in the 1970s. Governments responded with the US Bank Secrecy Act (1970), the Money Laundering Control Act (1986) and the creation of the Financial Action Task Force by the G7 in 1989. Today laundering runs through shell companies, trade invoices, real estate, 'money mule' accounts and, increasingly, cryptocurrency exchanges, mixers and stablecoins.

HOW IT WORKS

Laundering is usually described in three stages. 'Placement' puts criminal cash or crypto into the financial system, for example through small deposits, cash businesses or exchanges. 'Layering' moves it through many accounts, companies, countries or crypto wallets to hide the trail. 'Integration' brings it back as money that looks legitimate, such as property, luxury goods or company profits. Ordinary people are often drawn in as 'money mules' who let their accounts be used.

WARNING SIGNS
Job or online friend asking you to receive and forward moneyOffers to 'rent' your bank account or crypto walletCompany with no real business receiving large cross-border transfersMany cash deposits just under reporting limitsProperty or luxury purchases with money from unclear sources
GOVERNMENTS LINKED TO IT
North Korea
UN and US authorities document that North Korea's state hacking units launder stolen crypto through mixers, over-the-counter brokers and front companies; US Treasury has sanctioned mixers used for this
SOURCE: UN Panel of Experts, Mar 2024; US Treasury OFAC, 2022-2023
Iran
US Treasury has repeatedly sanctioned 'shadow banking' networks it says launder billions for Iran's government, including for the Islamic Revolutionary Guard Corps and Ministry of Defense
SOURCE: US Treasury OFAC, 2023-2025
Russia
US Treasury sanctioned the ruble stablecoin issuer A7A5's backers and the Garantex exchange's successor, saying they helped evade sanctions; A7 is described as partly owned by Russian state-owned Promsvyazbank
SOURCE: US Treasury OFAC, 14 Aug 2025
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Alexander Vinnik (BTC-e) PLEADED GUILTYREPORT PENDING
Over $4B allegedly laundered through BTC-e (DOJ) · 2011-2017
Russian operator of the BTC-e exchange, charged with laundering criminal proceeds including from the Mt. Gox hack; pleaded guilty in 2024 and was returned to Russia in a 2025 prisoner exchange.
SOURCE: US DOJ, 26 Jul 2017 and 3 May 2024
#3 Ilya Lichtenstein PLEADED GUILTYREPORT PENDING
About $3.6B in bitcoin seized in 2022 (value at seizure) · 2016-2022
Hacked the Bitfinex exchange in 2016 and, with his wife , laundered the stolen bitcoin; sentenced to 5 years.
SOURCE: US DOJ, 8 Feb 2022 and 14 Nov 2024
#4 TD Bank PLEADED GUILTYREPORT PENDING
About $3B in penalties · 2014-2023
Became the largest US bank to plead guilty to Bank Secrecy Act and money laundering conspiracy after its failures let networks move over $670M of illicit funds.
SOURCE: US DOJ, 10 Oct 2024
#5 Danske Bank PLEADED GUILTYREPORT PENDING
About $2B forfeiture · 2007-2016
Pleaded guilty in the US over its Estonian branch, which handled large volumes of suspicious non-resident money, largely from Russia and other former Soviet states.
SOURCE: US DOJ, 13 Dec 2022
#6 HSBC SETTLEDREPORT PENDING
$1.9B paid; at least $881M in drug proceeds laundered (DOJ) · 2006-2010
Admitted anti-money-laundering failures that let Mexican and Colombian drug cartels move money through its US operations.
SOURCE: US DOJ, 11 Dec 2012
MOST RELEVANT COUNTRY
United States (destination and enforcer)
Most of the largest laundering penalties and prosecutions, including Binance, TD Bank and 1MDB, were brought by the US because illicit money passes through US dollar banks (US DOJ, 2012-2024).
COUNTRIES MOST TIED TO IT
United States (dollar system; most large enforcement cases)
United Kingdom (property and company structures)
United Arab Emirates (reported destination for illicit funds)
Cambodia (Huione Group, per FinCEN)
Russia (BTC-e, Garantex, sanctions evasion)
Estonia (Danske Bank branch)
KEY NUMBERS
2-5% of global GDP Estimated money laundered worldwide each year (about $800B-$2T; estimate) (UNODC)
$154 billion Illicit cryptocurrency volume in 2025, under 1% of all crypto transactions (Chainalysis, Jan 2026)
At least $4 billion Illicit proceeds laundered by Cambodia's Huione Group, Aug 2021-Jan 2025 (FinCEN, Oct 2025)
$11.37 billion Losses in 2025 FBI complaints that involved cryptocurrency (FBI IC3 Internet Crime Report, 2026)
SOURCES
UNODC, Money laundering overview
FATF, history of the FATF
Chainalysis 2026 Crypto Crime Report, Jan 2026
FinCEN Huione final rule, Federal Register, 16 Oct 2025
FBI IC3 2025 Internet Crime Report, 2026
US DOJ, 1MDB civil and criminal actions, 2016-2018
US DOJ, Binance and pleas, 21 Nov 2023
US DOJ, BTC-e/Vinnik, 26 Jul 2017 and 3 May 2024
US DOJ, Bitfinex/Lichtenstein, 8 Feb 2022 and 14 Nov 2024
US DOJ, TD Bank plea, 10 Oct 2024
US DOJ, Danske Bank plea, 13 Dec 2022
US DOJ, HSBC deferred prosecution agreement, 11 Dec 2012
US Treasury OFAC, A7A5/Garantex/Grinex designations, 14 Aug 2025
US DOJ, sentencing, 9 Feb 2026
METHOD #8 OF 110
Securities Fraud / Insider Trading
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$74B (Enron alone)
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
Accounting manipulation, insider trading, market manipulation. Enron ($74B shareholder loss), Wirecard (€1.9B phantom), FTX ($8B customer funds). Sarbanes-Oxley created in response.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Accounting fraud: debt hidden off the balance sheet; earnings inflated
Misled investors about TerraUSD
Faked trades and statements
Accounting fraud: costs booked as investments
Concealed exposure and manipulated stock prices through swaps
Misled investors and lenders
Misled lenders
Misled investors
Unauthorised trading hidden by fake hedges
Misled customers; manipulated the CEL token
Hid debt from the accounts
Unauthorised trading hidden in account 88888
Misled investors about Theranos
Misled investors about Nikola's technology
Stock parking and false SEC filings
Securities fraud
Misled investors while selling shares
Insider trading on tips
WHERE IT CAME FROM
FIRST SEEN: 1720 (South Sea Bubble); insider-trading law from 1934 · GOING FOR: About 300 years (since the 1720s); modern insider-trading law since 1934

Market manipulation is as old as organised stock markets: the South Sea Bubble of 1720 and London's Great Stock Exchange Fraud of 1814, in which false news of Napoleon's death was spread to lift government bond prices, are early documented cases. Modern rules came after the 1929 crash, when the US Securities Act of 1933 and Securities Exchange Act of 1934 created the SEC and outlawed deceptive practices; the SEC's 1961 Cady, Roberts decision set out the modern ban on trading on inside information. Large accounting frauds (Enron 2001, WorldCom 2002, Wirecard 2020) showed that executives can falsify the books themselves, and rogue-trading losses at Barings (1995), Societe Generale (2008) and UBS (2011) showed how single traders could hide unauthorised positions. Today the same method includes crypto-token pump-and-dumps and social-media stock promotions.

HOW IT WORKS

Insiders or their contacts trade on confidential information, such as an upcoming merger or bad earnings, before the public knows. In accounting fraud, managers inflate revenue or hide debts so the company looks healthier than it is and the share price stays high. In rogue trading, an employee takes on unauthorised positions and hides losses with fake trades or booking tricks until they become too big to cover. In pump-and-dump schemes, promoters hype a thinly traded stock or token, then sell to the buyers they attracted.

WARNING SIGNS
Profits that grow far faster than cash flow or peersAuditor resignations or delayed filingsUnusual trading just before big announcementsA single trader or desk with steady, outsized profitsUnsolicited 'hot tips' on small stocks or tokens
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Kweku Adoboli CONVICTEDREPORT PENDING
$2.3bn (bank trading loss) · 2011-2012
UBS trader convicted of fraud over unauthorised trades that lost the bank about $2.3bn.
SOURCE: BBC, Nov 2012
#2 Markus Braun CHARGED (NOT TRIED)REPORT PENDING
EUR 1.9bn (missing cash reported by Wirecard, ~$2.1bn) · 2020-present
Former Wirecard CEO on trial in Munich since 2022 over the alleged fraud behind EUR 1.9bn of missing cash; he denies the charges.
SOURCE: Munich prosecutors / Reuters, 2022
#3 SAC Capital Advisors PLEADED GUILTYREPORT PENDING
$1.8bn (fines and forfeiture) · 2013
Hedge fund firm that pleaded guilty to insider trading and agreed to pay a record $1.8bn in penalties.
SOURCE: US DOJ, Nov 2013
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest market and enforcement)
United Kingdom (Barings, UBS London cases)
France (Societe Generale)
Germany (Wirecard)
Japan (Sumitomo copper, Olympus accounting cases)
KEY NUMBERS
$8.2bn Financial remedies obtained by the SEC in fiscal year 2024, a record (US SEC, Nov 2024)
$11bn Size of the WorldCom accounting fraud (US DOJ, 2005)
EUR 4.9bn Largest single rogue-trading loss (Societe Generale, 2008) (Societe Generale / BBC, 2008)
$1.8bn Record insider-trading penalty paid by a firm (SAC Capital) (US DOJ, Nov 2013)
SOURCES
US SEC, Nov 2024
US SEC, Nov 2011
US DOJ, July 2005
US DOJ, May 2006
US DOJ, Nov 2013
BBC, Oct 2010
BBC, Nov 2012
Bank of England Board of Banking Supervision report, July 1995
Reuters, Dec 2022
Wikipedia: Great Stock Exchange Fraud of 1814; Enron scandal
METHOD #9 OF 110
Healthcare Fraud
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$100B+/year (US alone)
WHERE IT'S CONCENTRATED
United States
IN SHORT
False billing, kickbacks, phantom patients, upcoding. FBI estimates $100B+ annual losses in US alone. Medicare/Medicaid most targeted. COVID accelerated telehealth fraud.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Billed Medicare and Medicaid through his facilities
Billed insurers for lab tests through rural hospitals
Genetic tests seniors didn't need
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #10 OF 110
Tax Evasion / Tax Fraud
CATASTROPHIC
SCALE (ENCYCLOPEDIA)
$600B+/year (US tax gap)
WHERE IT'S CONCENTRATED
Global
IN SHORT
Underreporting income, fake deductions, offshore hiding. US tax gap: $600B+. Panama Papers exposed global scale. Cum-ex scandal (Europe): €150B stolen via dividend tax fraud.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Helped file a false tax return
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #11 OF 110
Synthetic Identity Fraud
SEVERE
SCALE (ENCYCLOPEDIA)
$23B globally
WHERE IT'S CONCENTRATED
United States
IN SHORT
Fabricated identities (real SSN + fake name). 31% YoY growth. $3.3B credit extended to synthetic IDs (H1 2025). AI deepfakes bypass video KYC. Bust-out: max credit then abandon identity.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #12 OF 110
Account Takeover (ATO)
SEVERE
SCALE (ENCYCLOPEDIA)
$17B (2025)
WHERE IT'S CONCENTRATED
Global
IN SHORT
Credential stuffing, SIM swap, phishing → account hijack. 141% increase H1 2021-2025. 1.6B breached records (2024) fuel attacks. 42% target banking. AI chatbots managing multi-victim campaigns.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Took over the victim's accounts
Accounts taken over
WHERE IT CAME FROM
FIRST SEEN: Mid-1990s · GOING FOR: About 30 years (since the mid-1990s)

Account takeover began with the first online accounts: in the mid-1990s, AOL users were targeted with fake messages and tools such as AOHell to steal their logins. As banking, email and shopping moved online in the 2000s, stolen passwords were reused across sites, and the term 'credential stuffing' (automated testing of leaked username-password pairs) came into use around 2011. From about 2017, SIM swapping, where criminals get a victim's phone number moved to their own SIM, became a common way to beat text-message security codes, especially to empty crypto accounts. Groups such as Scattered Spider now mix phone-based social engineering, fake help-desk calls and SIM swaps to take over personal and corporate accounts.

HOW IT WORKS

Criminals get a victim's login details through phishing, data breaches, malware, or passwords reused from other sites. To beat extra security they may trick the victim into reading out a one-time code, pose as the bank's fraud team, or talk a phone carrier into moving the victim's number to a new SIM. Once inside, they change the email, phone and password so the real owner is locked out, then move money, buy goods, or use the account to scam the victim's contacts.

WARNING SIGNS
Unexpected password-reset or login alertsPhone suddenly loses signal ('No service') for no reasonA caller asks you to read out a one-time codeChanges to your email, phone or payee list you did not makeFriends receive odd messages or payment requests from your account
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Noah Michael Urban PLEADED GUILTYREPORT PENDING
$13m (restitution ordered) · 2022-2025
Scattered Spider member who stole crypto from at least 59 victims via SIM swaps; sentenced to 10 years.
SOURCE: US DOJ / The Record, Aug 2025
#2 Joel Ortiz PLEADED GUILTYREPORT PENDING
~$5m (crypto stolen) · 2018-2019
College student who SIM-swapped dozens of victims to steal cryptocurrency; sentenced to 10 years.
SOURCE: Santa Clara County DA / Motherboard, 2019
#3 Joseph James O'Connor ('PlugwalkJoe') PLEADED GUILTYREPORT PENDING
~$794,000 (crypto stolen via SIM swap) · 2019-2023
Took part in the 2020 Twitter account hijack and SIM-swap crypto thefts; sentenced to 5 years.
SOURCE: US DOJ, June 2023
#4 Graham Ivan Clark PLEADED GUILTYREPORT PENDING
~$117,000 (bitcoin sent by victims, reported) · 2020-2021
Teen who led the July 2020 takeover of high-profile Twitter accounts to push a bitcoin scam.
SOURCE: Hillsborough State Attorney, Mar 2021
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest reported victim base)
United Kingdom (Scattered Spider suspects charged)
Canada
Singapore (suspect nationality in largest single ATO case)
KEY NUMBERS
$359.7m Account-takeover losses reported to the FBI in 2025 (about 4,700 complaints) (FBI IC3 2025 report, Apr 2026 (via SpyCloud summary))
$262m+ Losses from account takeovers by fake bank-support impersonators, Jan-Nov 2025 (FBI IC3 PSA, Nov 2025)
$230m+ Largest single-victim social-engineering account takeover charged in the US (US DOJ, Sept 2024)
SOURCES
FBI IC3 Internet Crime Report 2025, Apr 2026
FBI IC3 Public Service Announcement, Nov 2025
US DOJ, Sept 2024
US DOJ, June 2023
US DOJ / The Record, Aug 2025
Fox News, Sept 2026
Wikipedia: AOHell; Credential stuffing
METHOD #13 OF 110
Gift Card Fraud / Draining
SEVERE
SCALE (ENCYCLOPEDIA)
$1B+ drained annually
WHERE IT'S CONCENTRATED
China (networks) → United States (targets)
IN SHORT
Cards tampered on retail racks, re-silvered, returned. Balance drained within 60 seconds of customer activation. Project Red Hook (DHS). $300M from Target customers alone.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #14 OF 110
Crypto Rug Pull
SEVERE
SCALE (ENCYCLOPEDIA)
$5B+ cumulative
WHERE IT'S CONCENTRATED
Global
IN SHORT
Token/NFT/DeFi projects that exit-scam. Liquidity pulled, token crashes to zero. Squid Game token, countless memecoins. pump.fun enabling low-barrier launches.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #15 OF 110
Friendly Fraud / Chargeback Abuse
SEVERE
SCALE (ENCYCLOPEDIA)
36% of all reported fraud
WHERE IT'S CONCENTRATED
United States, UK
IN SHORT
Legitimate customers disputing valid charges. 337M chargebacks projected 2026. Professional refund rings on Telegram. Merchants lose $4.61 per $1 of fraud.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #16 OF 110
Romance Scam (Traditional)
SEVERE
SCALE (ENCYCLOPEDIA)
$1.14B US losses (2023)
WHERE IT'S CONCENTRATED
Nigeria, Ghana, Global
IN SHORT
Emotional manipulation via dating apps → financial extraction. 64,000+ US victims (2023). Average loss varies widely. AI-generated daily messaging scales to hundreds of victims.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #17 OF 110
Investment Scam (General)
SEVERE
SCALE (ENCYCLOPEDIA)
$8.6B US losses (2025)
WHERE IT'S CONCENTRATED
Global
IN SHORT
Fake investment opportunities — crypto, forex, real estate, precious metals. FBI IC3: investment fraud is #1 loss category. Often combined with pig butchering or romance.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Fake loan listings on Ezubao
Sold Celsius as a safe yield product
WHERE IT CAME FROM
FIRST SEEN: 1920 (Ponzi); earlier schemes from the 1880s · GOING FOR: Over 100 years (since 1920, with roots in the 1880s)

The pay-old-investors-with-new-money scheme is named after , who in 1920 in Boston promised 50% returns in 45 days from postal reply coupons; earlier versions include William F. Miller's '520 Percent Miller' scheme (1899) and Sarah Howe's Ladies' Deposit Company (1880s). Boiler-room share frauds spread in the 20th century, and in 2008 's collapse became the largest Ponzi scheme on record. Online forex and binary-options platforms grew in the 2010s, followed by crypto schemes such as OneCoin. From about 2016 'pig-butchering' scams, which build a relationship before steering a victim to a fake trading app, spread from China-linked groups to industrial scam compounds in Southeast Asia, often staffed by trafficked workers.

HOW IT WORKS

Victims are promised high, steady returns, often from a secret strategy, a new technology or crypto trading. Early investors may be paid 'returns' out of later investors' money so the scheme looks real and spreads by word of mouth. Online versions show profits on a fake dashboard, then invent taxes, fees or 'unlock' charges when the victim tries to withdraw. The scheme collapses when new money slows down or the operators disappear.

WARNING SIGNS
Guaranteed high returns with little or no riskPressure to invest quickly or keep it secretAn online contact or new 'friend' who steers you to a trading platformFees or taxes demanded before you can withdrawFirm or platform not registered with a financial regulator
GOVERNMENTS LINKED TO IT
Myanmar (Karen National Army / Border Guard Force)
US Treasury designated the Karen National Army, a militia aligned with Myanmar's military, and its leader Saw Chit Thu as a transnational criminal organisation for enabling cyber scam compounds
SOURCE: US Treasury OFAC, May 2025
Cambodia
US and UK sanctioned Prince Group and its chairman Chen Zhi, who had served as an adviser to Cambodian leaders, over forced-labour scam compounds; the US charged Chen Zhi (allegations, not proven in court)
SOURCE: US DOJ and US Treasury, Oct 2025
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Chen Zhi CHARGED (NOT TRIED)REPORT PENDING
~$15bn (bitcoin in US forfeiture action) · 2015-2025
Chairman of Cambodia's Prince Group, charged by US prosecutors with running forced-labour crypto scam compounds; the US seeks forfeiture of 127,271 bitcoin.
SOURCE: US DOJ, Oct 2025
#4 Qian Zhimin (Zhimin Qian) PLEADED GUILTYREPORT PENDING
61,000 BTC seized (over GBP 5bn at 2025 prices) · 2014-2025
Ran a 2014-2017 investment fraud in China against about 128,000 victims, then laundered proceeds as bitcoin in the UK; UK police seized 61,000 bitcoin.
SOURCE: UK Crown Prosecution Service / Metropolitan Police, Nov 2025
#7 Scott Rothstein PLEADED GUILTYREPORT PENDING
$1.2bn (Ponzi scheme) · 2005-2009
Florida lawyer who sold investors fake legal settlements; sentenced to 50 years.
SOURCE: US DOJ, June 2010
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest reported victim losses)
Cambodia (scam compounds, source)
Myanmar (scam compounds, source)
China (victims and organiser networks)
United Kingdom (victims; largest bitcoin seizure)
Bulgaria (OneCoin base)
KEY NUMBERS
$8.65bn Investment-fraud losses reported to the FBI in 2025, the top category (FBI IC3 2025 report, Apr 2026)
$7.2bn+ Losses to crypto investment scams reported to the FBI in 2025 (FBI IC3 2025 report, Apr 2026)
120,000+ / 100,000+ People estimated held in scam operations in Myanmar and Cambodia respectively (UN OHCHR, Aug 2023)
127,271 BTC Bitcoin sought in the largest US forfeiture action (Prince Group case) (US DOJ, Oct 2025)
SOURCES
FBI IC3 Internet Crime Report 2025, Apr 2026
US DOJ, Oct 2025
US Treasury OFAC, May 2025 and Oct 2025
UN OHCHR report, Aug 2023
US DOJ, June 2009
US DOJ, June 2012
FBI, June 2022
UK CPS / Metropolitan Police, Nov 2025
Wikipedia:
METHOD #18 OF 110
Organized Retail Crime (ORC)
SEVERE
SCALE (ENCYCLOPEDIA)
$112B+ US shrink (2024)
WHERE IT'S CONCENTRATED
United States (all cities), South American theft groups, Chinese ORC
IN SHORT
Organized boosting crews, cargo theft, resale operations. 93% shoplifting increase 2019-2023. Violence up 17%. Transnational rings (67% of retailers report). Flash mob robberies.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #19 OF 110
Crypto Exchange Hack
SEVERE
SCALE (ENCYCLOPEDIA)
$3.4B stolen (2025)
WHERE IT'S CONCENTRATED
North Korea, Russia, Global
IN SHORT
Hot/cold wallet compromise, smart contract exploits, insider theft. Bybit $1.5B, Ronin $625M, WazirX $235M. Cross-chain laundering through bridges and mixers.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Exchange hacks (attributed)
Tricked Silk Road's withdrawal system
WHERE IT CAME FROM
FIRST SEEN: 2011 (Mt. Gox) · GOING FOR: About 15 years (since 2011)

Crypto exchange hacks began almost as soon as exchanges did: Mt. Gox, then the biggest bitcoin exchange, was breached in June 2011 and collapsed in 2014 after losing about 850,000 bitcoin, much of it stolen over several years. Other early cases included Bitfinex (2016, 119,754 BTC) and Coincheck (2018, about $530m in NEM tokens). From around 2017 North Korean state hackers, tracked as the and TraderTraitor, began targeting South Korean and then global exchanges, and later cross-chain bridges such as Ronin (2022). In February 2025, the FBI attributed the $1.5bn theft from Dubai-based Bybit, the largest crypto theft on record, to North Korea.

HOW IT WORKS

Attackers target the keys that control an exchange's 'hot' (online) wallets, or the software used to approve large transfers. Common routes in are phishing or fake job offers sent to staff, poisoned software updates, and compromised developer machines, which let attackers alter what signers see when they approve a transaction. Stolen coins are moved quickly through many wallets, token swaps, cross-chain bridges and mixers, then cashed out through brokers.

WARNING SIGNS
Exchange suddenly pauses withdrawals 'for maintenance'Unusually large outflows from an exchange's known walletsStaff approached with too-good-to-be-true job offers or test filesPlatform with no published proof of reserves or security audits
GOVERNMENTS LINKED TO IT
North Korea (DPRK)
FBI attributed the Feb 2025 $1.5bn Bybit theft to North Korean 'TraderTraitor' actors; US Treasury sanctioned the as controlled by the Reconnaissance General Bureau, North Korea's main intelligence agency
SOURCE: FBI, Feb 2025; US Treasury OFAC, Sept 2019
North Korea (DPRK)
UN Panel of Experts investigated 58 suspected DPRK cyberattacks on crypto firms from 2017-2023 worth about $3bn, said to help fund weapons programmes
SOURCE: UN Security Council Panel of Experts, Mar 2024
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Alexander Vinnik PLEADED GUILTYREPORT PENDING
$4bn+ (funds laundered through BTC-e, DOJ) · 2011-2024
Operator of the BTC-e exchange, which US prosecutors said laundered funds including proceeds of the Mt. Gox hack; released to Russia in a 2025 prisoner exchange.
SOURCE: US DOJ, May 2024
#3 Ilya Lichtenstein PLEADED GUILTYREPORT PENDING
119,754 BTC stolen (~$71m in 2016; ~$3.6bn when seized in 2022) · 2016-2024
Hacked Bitfinex in 2016 and laundered the stolen bitcoin with his wife ; sentenced to 5 years.
SOURCE: US DOJ, Feb 2022 and Nov 2024
#4 Park Jin Hyok, Jon Chang Hyok and Kim Il CHARGED (NOT TRIED)REPORT PENDING
$1.3bn+ (attempted and actual theft) · 2014-2021
North Korean military intelligence officers charged with a scheme to steal and extort more than $1.3bn from banks and crypto companies.
SOURCE: US DOJ, Feb 2021
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
North Korea (main source of attacks)
United Arab Emirates (Bybit, largest victim)
Japan (Mt. Gox, Coincheck, DMM Bitcoin victims)
South Korea (repeatedly targeted exchanges)
Russia (BTC-e laundering)
KEY NUMBERS
$3.4bn Crypto stolen worldwide in 2025 (Chainalysis, Dec 2025)
$2.02bn Stolen by North Korea-linked hackers in 2025, a record (Chainalysis, Dec 2025)
$1.5bn Bybit theft, largest crypto theft on record (FBI, Feb 2025)
~$3bn From 58 suspected DPRK attacks on crypto firms, 2017-2023 (UN Panel of Experts, Mar 2024)
SOURCES
Chainalysis, Dec 2025
FBI PSA on Bybit, Feb 2025
US Treasury OFAC, Sept 2019
UN Security Council Panel of Experts report, Mar 2024
US DOJ, Feb 2021
US DOJ, Feb 2022
US DOJ, Nov 2024
US DOJ, May 2024
Wikipedia: Mt. Gox
METHOD #20 OF 110
Wire Fraud
SEVERE
SCALE (ENCYCLOPEDIA)
$2.9B+ (FBI IC3)
WHERE IT'S CONCENTRATED
Nigeria, Global
IN SHORT
Fraudulent wire transfer instructions via deception. Overlaps with BEC. Federal wire fraud statute (18 USC 1343) carries 20 years. Most prosecuted federal fraud charge.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Wire fraud (plea)
Wire fraud
Wire fraud
Wire fraud
Wire fraud
Money moved by international wires
Wire fraud
Fraudulent wires
WHERE IT CAME FROM
FIRST SEEN: 1952 (US wire fraud statute); BEC tracked since 2013 · GOING FOR: More than 70 years as a legal offence (since 1952)

Wire fraud is a legal category rather than a single trick: it grew out of the US Mail Fraud Statute of 1872, and in 1952 Congress added a wire fraud law (18 U.S.C. 1343) covering schemes run over telegraph, telephone, radio or TV. As business moved to fax, email and online banking, the law came to cover most modern frauds, and prosecutors use it in cases from Ponzi schemes to crypto. The most common modern form is business email compromise (BEC), which the FBI began tracking in 2013: criminals impersonate executives, suppliers or lawyers to redirect bank transfers. Real-estate closing scams and fake 'change of bank details' requests are now routine versions.

HOW IT WORKS

The criminal gets a victim to send money by bank transfer under false pretences. In business email compromise, they hack or spoof an email account belonging to a boss, supplier or lawyer and send a convincing request to pay an invoice or deposit into a 'new' account. Because bank transfers settle fast and are hard to reverse, the money is usually moved on through mule accounts within hours.

WARNING SIGNS
Email asking to change bank details for a paymentUrgent, secret payment request from a 'CEO' or lawyerSender address that is slightly different from the usual onePressure to skip normal approval stepsHome-closing instructions arriving by email just before settlement
GOVERNMENTS LINKED TO IT
North Korea (DPRK)
US DOJ charged North Korean nationals and US-based facilitators with wire fraud conspiracy in schemes placing North Korean IT workers in US jobs under false identities to raise revenue for the DPRK
SOURCE: US DOJ, June 2025
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Billy McFarland PLEADED GUILTYREPORT PENDING
$26m (investor losses) · 2016-2018
Organiser of the Fyre Festival who defrauded investors and ticket buyers; sentenced to 6 years.
SOURCE: US DOJ SDNY, Oct 2018
#3 Christina Chapman PLEADED GUILTYREPORT PENDING
$17m+ (revenue generated for the scheme) · 2020-2025
Ran a US 'laptop farm' helping North Korean IT workers get remote jobs under stolen identities; sentenced to 102 months.
SOURCE: US DOJ, July 2025
#4 Obinwanne Okeke PLEADED GUILTYREPORT PENDING
~$11m (victim losses, mainly Unatrac Holding) · 2015-2021
Nigerian businessman who ran a phishing and business-email-compromise scheme; sentenced to 10 years.
SOURCE: US DOJ, Feb 2021
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest reported victim base)
Nigeria (many prosecuted BEC actors)
United Kingdom (victims)
Lithuania ( case)
Hong Kong / China (common destination of diverted funds)
KEY NUMBERS
$3.04bn Business email compromise losses reported to the FBI in 2025 (FBI IC3 2025 report, Apr 2026)
$55bn Global exposed losses from BEC reported to the FBI, Oct 2013 - Dec 2023 (FBI IC3 PSA, Sept 2024)
$121m Taken from Google and Facebook by a single fake-invoice scheme (US DOJ, Dec 2019)
SOURCES
18 U.S.C. 1343 (1952)
FBI IC3 Internet Crime Report 2025, Apr 2026
FBI IC3 PSA, Sept 2024
US DOJ SDNY, Nov 2023
US DOJ, Nov 2022
US DOJ SDNY, Dec 2019
US DOJ SDNY, Oct 2018
US DOJ, Feb 2021
US DOJ, June 2025 and July 2025
METHOD #21 OF 110
Advance Fee Fraud (419 Scam)
HIGH
SCALE (ENCYCLOPEDIA)
$700M+/year
WHERE IT'S CONCENTRATED
Nigeria, Ghana
IN SHORT
Pay upfront to receive larger sum (inheritance, lottery, contract). Named after Nigerian Criminal Code Section 419. Declining but still active. Email-based, now also WhatsApp/Telegram.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Promised a share of a fake airport contract
WHERE IT CAME FROM
FIRST SEEN: 19th century (Spanish Prisoner letters); '419' form in the 1980s · GOING FOR: Over 125 years (documented since at least the 1890s)

The method goes back at least to the 'Spanish Prisoner' letters of the 19th century, in which a writer claimed a wealthy man was jailed in Spain and asked for money to free him in exchange for a share of his fortune; the New York Times reported on such letters in 1898. The modern '419' name comes from Section 419 of Nigeria's Criminal Code, which covers obtaining property by false pretences, after the scheme spread from Nigeria by post and fax in the 1980s. It moved to email in the 1990s with the familiar 'foreign prince' and 'inheritance' messages, and is now run worldwide through lottery, loan, job, inheritance and recovery-scam variants. It also overlaps with romance scams, where a fake partner asks for fees to release money or travel.

HOW IT WORKS

The victim is told a large sum is waiting for them, such as an inheritance, lottery win, business deal or loan, but must first pay a small fee, tax or bribe to release it. Each payment is followed by a new obstacle and a new fee, so the victim keeps paying in hope of the big payout. Fake official documents, bank letters and stamps are used to make the story believable, and the promised money never arrives.

WARNING SIGNS
Unexpected message about money, a prize or inheritanceYou must pay a fee before receiving fundsRequests to keep the deal secretOfficial-looking documents from unfamiliar banks or 'ministries'Payment asked by wire, gift card or crypto
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Amaka Anajemba PLEADED GUILTYREPORT PENDING
$242m (same Banco Noroeste fraud) · 1995-2005
Co-defendant in the Banco Noroeste fraud; sentenced in Nigeria and ordered to return funds.
SOURCE: BBC, July 2005
#2 Fred Ajudua CHARGED (NOT TRIED)REPORT PENDING
$1.69m (alleged, Dutch victims) · 1999-2025
Lagos lawyer accused over decades of advance-fee frauds, including a case over $1.69m from two Dutch nationals; Nigeria's Supreme Court revoked his bail in a $1.43m case in 2025.
SOURCE: EFCC / Sahara Reporters, May 2025; Wikipedia 'Fred Ajudua'
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
Nigeria (origin of the '419' name, source)
Ghana (source)
United States (largest reported victim base)
United Kingdom (victims)
Brazil (Banco Noroeste victim)
KEY NUMBERS
$242m Largest single documented 419 fraud (Banco Noroeste) (BBC, 2005)
$12.7bn Estimated global losses to advance-fee fraud in 2013 (estimate) (Ultrascan AGI, 2014)
1898 Year the New York Times reported on 'Spanish Prisoner' swindle letters (New York Times, 1898 (via Wikipedia))
SOURCES
Wikipedia: Advance-fee scam; Spanish Prisoner; ; Fred Ajudua
BBC, 2005
Sahara Reporters, May 2025
Vanguard, May 2025
Ultrascan AGI, 2014
METHOD #22 OF 110
Phishing
HIGH
SCALE (ENCYCLOPEDIA)
90% of cyberattacks start here
WHERE IT'S CONCENTRATED
Global — Russia, China, Nigeria
IN SHORT
Fake emails/sites capturing credentials. 90% of successful cyberattacks begin with phishing. Spear phishing (targeted) vs mass phishing. AI making phishing more convincing.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Spear-phishing
WHERE IT CAME FROM
FIRST SEEN: 1995-1996 · GOING FOR: About 30 years (since 1996)

The word 'phishing' was first recorded in January 1996 on the Usenet group alt.2600, describing people who tricked AOL users into giving up passwords; the 1995 AOHell toolkit included a tool for this. In the 2000s phishing moved to fake bank and PayPal emails, and 'spear phishing' targeted named people at companies and governments. Smartphones brought SMS 'smishing' and voice 'vishing', and phishing-as-a-service kits such as 16Shop and LabHost let people with no skills run campaigns. Today generative AI helps make messages fluent and personalised, and phishing is still the most-reported cybercrime to the FBI.

HOW IT WORKS

The criminal sends a message by email, text, phone or social media that pretends to come from a trusted brand, bank, employer or government office. It creates urgency, such as a locked account, missed delivery or unpaid fine, and pushes the victim to click a link to a fake login page or open a harmful attachment. Details entered on the page, including passwords, card numbers and one-time codes, go straight to the criminal, who uses them to take over accounts or steal money.

WARNING SIGNS
Urgent warnings that your account will be closedLinks whose web address does not match the real companyRequests for passwords, card PINs or one-time codesUnexpected attachments or delivery/toll-fee textsSlight misspellings in sender addresses
GOVERNMENTS LINKED TO IT
Russia
US DOJ indicted 12 officers of Russia's GRU military intelligence for spear-phishing campaign staff and hacking in the 2016 US election
SOURCE: US DOJ, July 2018
North Korea (DPRK)
FBI and partners report that North Korean state hackers use spear phishing and fake job offers to gain access to crypto firms before stealing funds
SOURCE: FBI / CISA advisory, Apr 2022
Iran
US DOJ charged three hackers said to work for Iran's Islamic Revolutionary Guard Corps over a spear-phishing campaign against a US presidential campaign
SOURCE: US DOJ, Sept 2024
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Tejay Fletcher PLEADED GUILTYREPORT PENDING
GBP 43m+ (UK losses; ~$53m); estimated GBP 100m+ worldwide · 2020-2023
Ran the iSpoof website, which let users fake bank phone numbers to trick victims; sentenced to 13 years 4 months.
SOURCE: Metropolitan Police, May 2023
#3 Obinwanne Okeke PLEADED GUILTYREPORT PENDING
~$11m (victim losses) · 2015-2021
Used phishing emails to take over a company executive's email account, then diverted payments.
SOURCE: US DOJ, Feb 2021
#4 LabHost operators CHARGED (NOT TRIED)REPORT PENDING
480,000 card numbers and 64,000 PINs stolen (Met Police) · 2021-2024
Phishing-as-a-service platform shut down by UK police and Europol; 37 suspects arrested worldwide.
SOURCE: Metropolitan Police / Europol, Apr 2024
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (most reported victims)
United Kingdom (victims; iSpoof and LabHost takedowns)
Nigeria (source of many BEC/phishing prosecutions)
Russia (state-linked spear phishing)
China (smishing kit sellers, per researchers)
KEY NUMBERS
191,561 Phishing/spoofing complaints to the FBI in 2025, the most-reported crime type (FBI IC3 2025 report, Apr 2026)
$215.8m Phishing/spoofing losses reported to the FBI in 2025 (FBI IC3 2025 report, Apr 2026 (via SpyCloud summary))
37 Arrests in the LabHost phishing-platform takedown (Europol, Apr 2024)
SOURCES
FBI IC3 Internet Crime Report 2025, Apr 2026
US DOJ, July 2018
US DOJ, Sept 2024
FBI / CISA advisory, Apr 2022
US DOJ SDNY, Dec 2019
US DOJ, Feb 2021
Metropolitan Police, May 2023
Europol / Metropolitan Police, Apr 2024
Wikipedia: Phishing; AOHell
METHOD #23 OF 110
NFC Relay / Ghost Tap
HIGH
SCALE (ENCYCLOPEDIA)
300%+ surge H1 2025
WHERE IT'S CONCENTRATED
China (tooling), Global (deployment)
IN SHORT
Stolen card credentials relayed via NFC to remote POS terminal. Card in Thailand, transaction in Germany. Breaks contactless proximity assumption. Chinese FaaS.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #24 OF 110
Digital Skimming (Magecart)
HIGH
SCALE (ENCYCLOPEDIA)
443 merchants compromised (Europol)
WHERE IT'S CONCENTRATED
Global
IN SHORT
Malicious JavaScript on e-commerce checkout pages. Captures card data at point of entry. 6+ months average dwell time. Skimming-as-a-Service platforms.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Tools that captured card data inside networks
Point-of-sale malware on card terminals
WHERE IT CAME FROM
FIRST SEEN: mid-2000s (POS RAM scraping); c. 2015 (web skimming named 'Magecart') · GOING FOR: About 20 years for POS malware; about 10 years for online Magecart skimming (since c. 2015)

Card skimming began with physical devices glued onto ATMs and fuel pumps; its digital form started in retail tills. From the mid-2000s criminal crews planted RAM-scraping malware on point-of-sale (POS) systems, most famously the ring led by behind the TJX (2007) and Heartland (2008) breaches, and later BlackPOS in the 2013 Target breach. As shops moved online, attackers began injecting card-stealing JavaScript into checkout pages; researchers at RiskIQ named this activity 'Magecart' around 2015-2016 because early victims ran the Magento shopping platform. Magecart is now an umbrella label for many unrelated groups, and web skimmers are increasingly delivered through compromised third-party scripts (supply-chain attacks), as in the British Airways and Ticketmaster breaches of 2018.

HOW IT WORKS

Attackers break into a shop's payment environment, either a physical till or a website, rather than attacking the shopper directly. In POS attacks, malware reads card data from the till's memory in the split second before it is encrypted. In Magecart attacks, a few lines of hidden code on the checkout page (or in a third-party script it loads) copy what customers type and send it to a server the attackers control. The purchase still goes through normally, so neither shopper nor merchant notices until stolen cards are used or sold.

WARNING SIGNS
Unexpected charges soon after shopping at a particular siteCheckout page asks for card details twice or shows odd pop-upsUnfamiliar third-party scripts or domains on a merchant's payment pageBank or card-network notice of a 'common point of purchase'
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 FIN7 (Carbanak-linked crime group) CONVICTEDREPORT PENDING
More than $1 billion in estimated victim costs; 20+ million card records from 6,500+ POS terminals · 2015-2018
Crew that hid behind a fake security company and planted POS malware in US restaurants, casinos and retailers.
SOURCE: US DOJ, 16 Apr 2021 (Fedir Hladyr sentenced to 10 years)
#3 Magecart skimmer group (Operation Night Fury suspects) CHARGED (NOT TRIED)REPORT PENDING
Not quantified (hundreds of websites reported compromised) · 2017-2019
Three people arrested in Indonesia for injecting JavaScript skimmers into online shops, the first Magecart-linked arrests publicised.
SOURCE: INTERPOL, 27 Jan 2020
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (main victim market)
United Kingdom (victim: British Airways, Ticketmaster UK breaches)
Russia and Ukraine (origin of many convicted POS malware operators)
Indonesia (Magecart arrests, INTERPOL 2020)
KEY NUMBERS
20+ million card records stolen by FIN7 from 6,500+ US POS terminals (US DOJ, 16 Apr 2021)
40 million payment cards exposed in the 2013 Target POS breach (Target Corporation statement, Dec 2013)
£20 million UK ICO fine on British Airways after a 2018 web-skimming breach affecting about 429,000 customers and staff (UK Information Commissioner's Office, Oct 2020)
£1.25 million UK ICO fine on Ticketmaster over a 2018 chatbot-script skimming breach (UK Information Commissioner's Office, Nov 2020)
SOURCES
US DOJ press release on Fedir Hladyr/FIN7, 16 Apr 2021
US DOJ press releases on , 2009-2010
US DOJ press release on , 21 Apr 2017
INTERPOL, Operation Night Fury, 27 Jan 2020
UK ICO penalty notices, British Airways (Oct 2020) and Ticketmaster (Nov 2020)
Wikipedia, 'Web skimming' / 'Magecart', accessed Sep 2026
RiskIQ/Flashpoint 'Inside Magecart' report, Nov 2018
METHOD #25 OF 110
DeFi Protocol Exploit
HIGH
SCALE (ENCYCLOPEDIA)
$3B+ cumulative
WHERE IT'S CONCENTRATED
Global (often NK-linked)
IN SHORT
Smart contract vulnerabilities — re-entrancy, flash loans, oracle manipulation. Bridge hacks: Ronin ($625M), Wormhole ($320M). Audit gaps enable exploitation.
IN OUR CASE FILES — MOST TAKEN TO LEAST
DeFi and bridge exploits (attributed)
WHERE IT CAME FROM
FIRST SEEN: 2016 · GOING FOR: About 10 years (since the 2016 DAO attack)

Decentralised finance (DeFi) runs lending, trading and bridging on public smart contracts, so a coding or design flaw can be abused by anyone. The first landmark case was the June 2016 attack on 'The DAO' on Ethereum, where about 3.6 million ether (roughly $50-60 million at the time) was drained through a re-entrancy bug, leading to Ethereum's hard fork. Flash-loan attacks, which borrow huge sums within a single transaction to manipulate prices, appeared with the bZx incidents in February 2020. Cross-chain bridges became the biggest targets from 2021-2022 (Poly Network, Wormhole, Ronin, Nomad), and the FBI has attributed several of the largest bridge thefts to North Korean state hackers. Today the category also covers oracle and price manipulation, governance attacks and private-key compromise of protocol operators.

HOW IT WORKS

A DeFi protocol holds users' pooled funds in smart contracts that follow their code literally. Attackers look for a flaw, such as a bug in how withdrawals are counted, a price feed that can be pushed around, or a bridge whose signing keys can be stolen, and use it to withdraw far more than they put in. Many attacks happen in a single transaction or a few minutes, often funded with a flash loan. Stolen tokens are then swapped, bridged between blockchains and sent through mixers to obscure the trail.

WARNING SIGNS
Unaudited or recently changed contract codeVery high yields with thin liquidityPrice oracles that rely on one small trading poolBridges or protocols controlled by only a few signing keysSudden large outflows or paused withdrawals
GOVERNMENTS LINKED TO IT
North Korea (DPRK)
The FBI attributed the ~$620 million Ronin bridge theft (2022) and the ~$100 million Harmony Horizon bridge theft (2022) to the /APT38, which the US government ties to North Korea's Reconnaissance General Bureau; Treasury sanctioned a related address. North Korea denies involvement.
SOURCE: FBI, 14 Apr 2022 and 23 Jan 2023; US Treasury OFAC, Apr 2022
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Avraham Eisenberg ACQUITTEDREPORT PENDING
About $110 million withdrawn from Mango Markets · 2022
Pushed up the price of Mango Markets' MNGO token and borrowed against it, draining the platform.
SOURCE: CoinDesk / Bloomberg, 24 May 2025 (judge vacated April 2024 jury convictions)
#3 Andean Medjedovic FUGITIVEREPORT PENDING
About $65 million (alleged) · 2021-2023
Alleged to have exploited Indexed Finance and KyberSwap smart contracts and tried to extort the protocols.
SOURCE: US DOJ (EDNY), 3 Feb 2025
#4 Benjamin and Noah Peraire-Bueno CHARGED (NOT TRIED)REPORT PENDING
About $25 million (alleged) · 2023
Brothers accused of manipulating Ethereum block validation (MEV) to take funds from trading bots in about 12 seconds; their Nov 2025 trial ended in a mistrial.
SOURCE: US DOJ (SDNY), 15 May 2024; The Block, 8 Nov 2025 (mistrial, jury deadlocked)
#5 Shakeeb Ahmed PLEADED GUILTYREPORT PENDING
About $12 million · 2022
Security engineer who exploited flaws in the Crema Finance and Nirvana Finance protocols - the first US criminal conviction for a smart-contract hack.
SOURCE: US DOJ (SDNY), Dec 2023 (plea) and 2024 (sentencing)
MOST RELEVANT COUNTRY
North Korea (attributed source)
The FBI attributes the largest DeFi bridge thefts (Ronin, Harmony) to North Korean state hackers, and Chainalysis estimated North Korea-linked actors stole about $1.7 billion in crypto in 2022 (FBI 2022-2023; Chainalysis, Feb 2023).
COUNTRIES MOST TIED TO IT
North Korea (attributed state source)
United States (prosecutions; many victim users)
Vietnam (Sky Mavis/Axie Infinity, Ronin victim)
Canada (defendant in Indexed Finance/KyberSwap case)
KEY NUMBERS
$3.8 billion stolen in crypto hacks in 2022, 82% of it from DeFi protocols (Chainalysis, Feb 2023)
64% of 2022 DeFi hack losses came from cross-chain bridges (Chainalysis, 2023)
$2.2 billion stolen in crypto hacks in 2024 (Chainalysis, Dec 2024)
~$620 million Ronin bridge theft (Mar 2022), one of the largest DeFi thefts; FBI-attributed to (FBI, 14 Apr 2022)
SOURCES
FBI statements, 14 Apr 2022 (Ronin) and 23 Jan 2023 (Harmony)
US Treasury OFAC, Apr 2022
Chainalysis Crypto Crime reports, Feb 2023 and Dec 2024
US DOJ SDNY press releases (Eisenberg Jan 2023; Ahmed Dec 2023; Peraire-Bueno 15 May 2024)
US DOJ EDNY, 3 Feb 2025 (Medjedovic)
CoinDesk / Bloomberg, 24 May 2025
The Block, 8 Nov 2025
Wikipedia, 'The DAO', accessed Sep 2026
METHOD #26 OF 110
Return Fraud / Refund Abuse
HIGH
SCALE (ENCYCLOPEDIA)
$103.8B (15% of all US returns)
WHERE IT'S CONCENTRATED
United States
IN SHORT
Empty box returns, wardrobing, false non-delivery claims. Noir ring on Telegram (5,900 followers). First-party fraud jumped from 7.6% to 30.4% of cases.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #27 OF 110
Impersonation Scam (Government)
HIGH
SCALE (ENCYCLOPEDIA)
$1.1B+ (FTC)
WHERE IT'S CONCENTRATED
India (call centers), Jamaica, Nigeria
IN SHORT
IRS, SSA, Medicare, law enforcement impersonation. Demand payment via gift cards, wire, or crypto. Elder targeting. AI voice cloning making impersonation more convincing.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #28 OF 110
Tech Support Scam
HIGH
SCALE (ENCYCLOPEDIA)
$1.3B+ (FBI IC3 2023)
WHERE IT'S CONCENTRATED
India (call centers)
IN SHORT
Fake virus alerts → remote access → account draining. Pop-up warnings on computers. Primarily targets elderly. Call centers in India targeting US/UK/Australia.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #29 OF 110
Pyramid Scheme / MLM Fraud
HIGH
SCALE (ENCYCLOPEDIA)
Billions cumulative
WHERE IT'S CONCENTRATED
Global
IN SHORT
Recruitment-based schemes where income comes from recruiting, not product sales. OneCoin ($4B+), Herbalife allegations, LuLaRoe. Often disguised as legitimate MLM.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Multi-level marketing sales network (alleged)
WHERE IT CAME FROM
FIRST SEEN: late 19th century (chain-letter style); 1960s-70s (MLM form) · GOING FOR: Over 100 years; the MLM form about 60 years

Pyramid schemes trace back at least to the late 19th century, and chain letters promising money to those who recruit others were common by the 1930s. The modern multi-level marketing (MLM) disguise grew in the US in the 1960s-70s with firms such as Holiday Magic and Glenn Turner's Koscot Interplanetary; the US Federal Trade Commission's 1975 Koscot ruling set the classic legal test - money paid mainly for the right to recruit others rather than for sales to real customers. In 1979 the FTC found that Amway was not a pyramid, and that ruling shaped how legitimate MLMs are distinguished from frauds. Mass collapses followed elsewhere, including Romania's Caritas (1992-94) and Albania's schemes of 1996-97, whose collapse contributed to civil unrest. Today many pyramids are pitched online, often as 'digital products', crypto or 'passive income' clubs.

HOW IT WORKS

Members pay to join, buy starter kits or meet monthly purchase quotas, and are told they will earn by building a 'downline' of recruits. Most of the money flowing up the chain comes from new members' fees and required purchases, not from selling products to outside customers. Because recruitment cannot grow forever, the scheme stalls and most participants - often the large majority - lose money, while early joiners and organisers at the top keep the gains.

WARNING SIGNS
Earnings depend on recruiting rather than retail salesUp-front fees, costly starter packs or monthly buying quotasPressure to buy inventory to 'stay qualified'Income claims based on lifestyle photos, not audited figuresLittle or no sales to customers outside the network
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 TelexFree (Carlos Wanzeler and James Merrill) PLEADED GUILTYREPORT PENDING
About $3 billion scheme (DOJ estimate) · 2012-2014
Internet-phone 'VoIP' MLM that paid members to post ads and recruit, collapsing in 2014.
SOURCE: US DOJ (D. Mass.), Mar 2017 (Merrill pleaded guilty, sentenced to 6 years; Wanzeler fled to Brazil, fugitive in US)
#2 Zeek Rewards (Paul Burks) CONVICTEDREPORT PENDING
More than $850 million from more than 700,000 victims · 2010-2012
Online 'penny auction' affiliate scheme that paid returns from new members' money.
SOURCE: US DOJ (W.D.N.C.), Mar 2017 (14 years 7 months)
#3 Vemma Nutrition Company SETTLEDREPORT PENDING
$238 million settlement judgment (mostly suspended) · 2015-2016
FTC alleged the drinks MLM was an illegal pyramid targeting college students.
SOURCE: US FTC, Dec 2016
#4 Herbalife SETTLEDREPORT PENDING
$200 million paid to consumers · 2016
FTC said its compensation rewarded recruitment over retail sales; company agreed to restructure.
SOURCE: US FTC, 15 Jul 2016
#5 AirBit Club (Pablo Renato Rodriguez and others) CONVICTEDREPORT PENDING
About $100 million from victims · 2015-2020
Crypto 'mining and trading' MLM that recruited in the US and Latin America.
SOURCE: US DOJ (SDNY), 2022
#6 Caritas (Ioan Stoica) CONVICTEDREPORT PENDING
Not reliably quantified; losses widely reported in the hundreds of millions of dollars · 1992-1994
Romanian scheme that promised eightfold returns and drew millions of participants before collapsing in 1994.
SOURCE: Wikipedia 'Caritas (Ponzi scheme)', citing contemporary press
#7 MMM (Sergei Mavrodi) CONVICTEDREPORT PENDING
Not reliably quantified (millions of investors) · 1994; relaunched 2011-2016
Russian scheme that drew millions of investors before collapsing in 1994; Mavrodi later launched MMM Global.
SOURCE: Wikipedia 'MMM (Ponzi scheme company)'; Moscow court, 2007 (4.5 years)
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (MLM origin and main enforcement)
Albania (1996-97 scheme collapse)
Romania (Caritas)
Russia (MMM)
Brazil (TelexFree victims and fugitive)
KEY NUMBERS
Almost half of GDP nominal liabilities of Albania's pyramid schemes at their 1996-97 peak (IMF (Chris Jarvis, 'The Rise and Fall of Albania's Pyramid Schemes'), 2000)
700,000+ victims of the Zeek Rewards scheme (US DOJ, Mar 2017)
$200 million Herbalife payment to consumers after FTC action (US FTC, Jul 2016)
SOURCES
US FTC, In re Koscot Interplanetary (1975) and Amway (1979) decisions
US FTC press releases on Herbalife (15 Jul 2016) and Vemma (Dec 2016)
US DOJ press releases on TelexFree (2017) and Zeek Rewards (2017)
US DOJ SDNY on AirBit Club, 2022
IMF, Jarvis, Finance & Development / Working Paper, 1999-2000
Wikipedia, 'Pyramid scheme', 'Caritas (Ponzi scheme)', 'MMM (Ponzi scheme company)', accessed Sep 2026
METHOD #30 OF 110
Embezzlement
HIGH
SCALE (ENCYCLOPEDIA)
$50B+/year globally
WHERE IT'S CONCENTRATED
Global
IN SHORT
Theft by trusted employee/official. Corporate, government, nonprofit. Average scheme: $125K (ACFE). Median duration: 12 months before detection. Smaller organizations hit hardest.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Misused FTX customer deposits
Alameda spent FTX customer deposits
Diverted money from the 1MDB state fund (alleged)
Company money used by the family
Took unapproved pay and loans
Kept users' deposits at the exit
WHERE IT CAME FROM
FIRST SEEN: Ancient; codified as a crime in England in 1799 · GOING FOR: Centuries (a distinct statutory crime for over 200 years)

Embezzlement - stealing money one has been trusted to look after - is as old as bookkeeping, and English law made it a distinct crime in the 18th century (the Embezzlement Act 1799 addressed clerks and servants who took their employers' money). It remains the most common form of workplace fraud, from bookkeepers skimming petty cash to officials diverting public budgets. Its largest modern forms are grand corruption, where state or sovereign funds are siphoned (1MDB in Malaysia, the Abacha loot in Nigeria), and the misappropriation of customer deposits, as in the FTX collapse (2022) and Vietnam's Van Thinh Phat / SCB case. Digital banking and crypto have made hidden transfers faster but also leave audit trails investigators increasingly follow.

HOW IT WORKS

Someone with legitimate access to money - an employee, finance officer, company founder or public official - quietly diverts it for personal use. Common routes include fake vendors or payroll entries, altered records, personal spending on company cards, or moving client or state funds into accounts the insider controls, often disguised as loans or investments. Because the person is trusted and often controls the records, the theft can continue for years until an audit, a cash crunch or a whistleblower exposes it.

WARNING SIGNS
One person controls both payments and bookkeepingResistance to audits or refusal to take holidaysLifestyle far beyond known incomeUnexplained related-party loans or transfersCustomer withdrawals delayed or frozen without clear reason
GOVERNMENTS LINKED TO IT
Malaysia (former government leadership)
US DOJ alleged that over $4.5 billion was misappropriated from state fund 1MDB by high-level officials and associates; a Malaysian High Court convicted former Prime Minister Najib Razak in Dec 2025 of abuse of power and money laundering over about $568 million from 1MDB (under appeal).
SOURCE: US DOJ, 20 Jul 2016; Malaysian High Court via SCMP/PBS, 26 Dec 2025
Nigeria (Abacha military government, 1993-98)
US DOJ forfeited more than $480 million that it said General Sani Abacha and associates embezzled from Nigeria's public funds and laundered abroad.
SOURCE: US DOJ, 7 Aug 2014
Equatorial Guinea (Vice-President Teodoro Nguema Obiang Mangue)
French courts convicted the vice-president of laundering embezzled public funds and ordered assets in France confiscated.
SOURCE: Paris Criminal Court, Oct 2017; upheld on appeal 2020
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Truong My Lan CONVICTEDREPORT PENDING
About $12.5 billion embezzled (304 trillion dong, per court); total bank losses reported near $27 billion · 2012-2022
Van Thinh Phat chairwoman convicted in Vietnam of embezzling from Saigon Commercial Bank, which she secretly controlled.
SOURCE: Ho Chi Minh City People's Court, 11 Apr 2024; Al Jazeera, 3 Dec 2024; death sentence commuted to life after a 2025 law change (Malay Mail/AP, Jun 2025)
#3 Najib Razak CONVICTEDREPORT PENDING
About $568 million (RM2.3 billion) from 1MDB per the 2025 verdict · 2009-2015
Former Malaysian Prime Minister convicted over funds diverted from state fund 1MDB and its former unit SRC International.
SOURCE: South China Morning Post / PBS, 26 Dec 2025 (15 years; appeal filed)
#4 Sani Abacha DIED BEFORE TRIALREPORT PENDING
More than $480 million forfeited in the US alone; total estimated in the billions · 1993-1998
Nigerian military ruler whose family and associates moved looted state funds through Western banks.
SOURCE: US DOJ, 7 Aug 2014
#5 Teodoro Nguema Obiang Mangue CONVICTEDREPORT PENDING
Assets in France estimated at over €100 million confiscated (Paris mansion, cars) · 1997-2011
Equatorial Guinea vice-president convicted in France over luxury assets bought with embezzled public money.
SOURCE: Paris Criminal Court, 27 Oct 2017; Paris Court of Appeal, Feb 2020
#6 Rita Crundwell PLEADED GUILTYREPORT PENDING
$53.7 million stolen from the city · 1990-2012
Comptroller of Dixon, Illinois, who secretly moved city money into a hidden account for 22 years to fund a horse-breeding empire.
SOURCE: US DOJ (N.D. Ill.) / FBI, 14 Feb 2013 (19 years 7 months; sentence commuted Dec 2024)
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (most occupational-fraud cases studied; FTX)
Malaysia (1MDB state-fund embezzlement)
Vietnam (SCB / Van Thinh Phat)
Nigeria (Abacha funds)
Equatorial Guinea (Obiang case, tried in France)
KEY NUMBERS
89% of occupational fraud cases involve asset misappropriation (embezzlement-type theft) (ACFE, Occupational Fraud 2024: A Report to the Nations)
$120,000 median loss per asset-misappropriation case (ACFE, 2024)
5% of annual revenue estimated lost to occupational fraud by a typical organisation (ACFE, 2024 (survey-based estimate))
$4.5 billion+ allegedly misappropriated from Malaysia's 1MDB state fund (US DOJ, 2016)
SOURCES
ACFE, Occupational Fraud 2024: A Report to the Nations
US DOJ press releases on 1MDB (20 Jul 2016) and Abacha forfeiture (7 Aug 2014)
US DOJ SDNY on , Nov 2023 and Mar 2024
US DOJ N.D. Ill. / FBI on Rita Crundwell, 14 Feb 2013
South China Morning Post and PBS, 26 Dec 2025 (Najib verdict)
Al Jazeera, 3 Dec 2024; RFA, Apr 2025; Malay Mail, 25 Jun 2025 (Truong My Lan)
Paris Criminal Court ruling reported by Reuters/Le Monde, Oct 2017 (Obiang)
Wikipedia, 'Embezzlement', accessed Sep 2026
METHOD #31 OF 110
Credential Stuffing
HIGH
SCALE (ENCYCLOPEDIA)
Part of $17B ATO losses
WHERE IT'S CONCENTRATED
Global (automated)
IN SHORT
Automated login attempts using breached username/password pairs. 1.6B records breached (2024). Bots test across multiple sites. Exploits password reuse.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #32 OF 110
SIM Swap Fraud
HIGH
SCALE (ENCYCLOPEDIA)
$68M+ (FBI IC3 2023)
WHERE IT'S CONCENTRATED
Kenya, South Africa, Colombia, US
IN SHORT
Phone number hijacked → 2FA intercepted → account drained. Mobile banking targeted. Spreading from East Africa globally. Carrier employees sometimes complicit.
IN OUR CASE FILES — MOST TAKEN TO LEAST
SIM swap on the victim's phone number
WHERE IT CAME FROM
FIRST SEEN: c. 2010s (surged 2017-2018) · GOING FOR: About 10-15 years

SIM swapping grew out of the telecom practice of moving a phone number to a new SIM card when a phone is lost, combined with banks' reliance on text-message codes for security. Reports of criminals porting victims' numbers to intercept bank codes appeared in the UK and South Africa around 2010-2013. From about 2017-2018 young crews in the US and elsewhere turned it on cryptocurrency holders, with thefts such as the $24 million taken from investor Michael Terpin in January 2018. High-profile takeovers followed, including Twitter CEO Jack Dorsey's account in 2019 and the SEC's X account in January 2024, and SIM swaps have been used as an entry point by groups such as 'Scattered Spider' against large companies.

HOW IT WORKS

A criminal gathers the victim's personal details from data leaks or phishing, then persuades or bribes a phone-company employee - or uses a fake ID in store - to move the victim's number onto a SIM card the criminal controls. The victim's phone suddenly loses service, while the criminal receives their calls and text messages. They use these to reset passwords and pass SMS-based two-factor checks on email, bank and crypto accounts, then drain funds quickly.

WARNING SIGNS
Phone suddenly shows 'No service' or 'SOS only' in a normal coverage areaAlerts that your SIM or number was changed or portedPassword-reset or login notices you did not requestBeing locked out of email or financial accounts
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Robert Powell, Carter Rohn and Emily Hernandez CHARGED (NOT TRIED)REPORT PENDING
About $400 million stolen from FTX (alleged) · 2021-2023
Charged over a SIM-swap ring that prosecutors say enabled the theft of about $400 million from FTX on the day it collapsed; Hernandez pleaded guilty, Powell and Rohn pleaded not guilty.
SOURCE: US DOJ (D.D.C.) indictment unsealed 24 Jan 2024; Krebs on Security, Feb 2024
#2 Ellis Pinsky SETTLEDREPORT PENDING
$22 million civil settlement/judgment · 2018
Alleged ringleader of the Terpin SIM swap as a 15-year-old; never criminally charged, agreed to a civil judgment.
SOURCE: CoinDesk, 14 Oct 2022; SDNY judgment, Nov 2022
#3 Joel Ortiz PLEADED GUILTYREPORT PENDING
About $5 million in cryptocurrency · 2017-2018
College student who used SIM swaps to steal crypto from dozens of victims, one of the first SIM-swap prison sentences.
SOURCE: Santa Clara County District Attorney / press (Motherboard), 2019 (10 years)
#4 Eric Council Jr. PLEADED GUILTYREPORT PENDING
No direct theft quantified · 2024
SIM-swapped the phone tied to the SEC's X account, used to post a fake Bitcoin ETF approval.
SOURCE: US DOJ (D.D.C.), 2025
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (main victim and prosecuting country)
United Kingdom (victims; home of some 'Scattered Spider' suspects)
South Africa (early bank SIM-swap cases)
Nigeria (SIM-swap bank fraud reported)
KEY NUMBERS
$68 million+ losses from 1,611 SIM-swap complaints to the FBI in 2021 (FBI IC3 PSA, 8 Feb 2022)
$12 million losses from 320 SIM-swap complaints to the FBI over 2018-2020 (FBI IC3 PSA, 8 Feb 2022)
~$400 million FTX theft allegedly enabled by a SIM swap in Nov 2022 (US DOJ indictment, Jan 2024)
SOURCES
FBI IC3 Public Service Announcement 'Criminals Increasing SIM Swap Schemes', 8 Feb 2022
US DOJ (SDNY) on , 1 Dec 2022
Decrypt / Cointelegraph, Jul 2025
US DOJ (D.D.C.) indictment of Powell, Rohn, Hernandez, Jan 2024; Krebs on Security, Feb 2024
CoinDesk, 14 Oct 2022
Wikipedia, 'SIM swap scam', accessed Sep 2026
METHOD #33 OF 110
Money Mule Recruitment
HIGH
SCALE (ENCYCLOPEDIA)
Part of money laundering
WHERE IT'S CONCENTRATED
Nigeria, Global
IN SHORT
Recruiting individuals to move stolen funds. Job post scams, romance-based recruitment. Students, elderly, immigrants targeted. Criminal liability for mules.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #34 OF 110
Cargo Theft
HIGH
SCALE (ENCYCLOPEDIA)
$200K+ per incident
WHERE IT'S CONCENTRATED
United States (I-10, I-45, I-95 corridors)
IN SHORT
Stolen shipping loads. 27% increase 2024. Fake documents, address rediversion, GPS jamming. ORC-connected. Multi-state in hours.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #35 OF 110
Cryptocurrency Ponzi / HYIP
HIGH
SCALE (ENCYCLOPEDIA)
$14B+ crypto scam revenue (2025)
WHERE IT'S CONCENTRATED
Global
IN SHORT
Cloud mining, staking, arbitrage bot scams. Guaranteed returns impossible to sustain. HYIP lifecycle: 90-day average before collapse. $28M YieldVault example.
IN OUR CASE FILES — MOST TAKEN TO LEAST
OneCoin, a crypto investment scheme (alleged)
WHERE IT CAME FROM
FIRST SEEN: Late 1990s (HYIPs); 2011 (first known bitcoin Ponzi) · GOING FOR: About 25 years for HYIPs; about 15 years in crypto (since 2011)

High-yield investment programs (HYIPs) are online Ponzi schemes promising daily or weekly returns; they spread in the late 1990s and 2000s using digital payment systems such as e-gold and Liberty Reserve. Bitcoin gave them a new rail: the first widely cited bitcoin Ponzi was Trendon Shavers' 'Bitcoin Savings and Trust' (2011-2012), charged by the SEC in 2013. The model then scaled with MLM-style recruitment and 'mining', 'trading bot' or 'staking' stories - OneCoin (2014-2017), BitConnect (2016-2018), PlusToken (2018-2019) and HyperFund (2020-2022). Chainalysis still counts high-yield investment scams among the largest categories of crypto scam revenue.

HOW IT WORKS

The scheme promises fixed, high returns - often 1% a day or more - supposedly from mining, arbitrage, a trading bot or a new coin. Early investors are paid out of later investors' deposits, which builds trust and online testimonials; referral bonuses reward people for bringing in friends. Withdrawals are eventually limited, 'paused' or paid in the scheme's own token, and the operators disappear with the remaining funds.

WARNING SIGNS
Guaranteed daily or weekly returnsVague 'trading bot', mining or arbitrage story with no audited proofBig referral bonuses and rank levelsReturns paid in the scheme's own coinWithdrawal limits or fees appearing suddenly
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Satish Kumbhani (BitConnect) FUGITIVEREPORT PENDING
About $2.4 billion from investors · 2016-2018
Founder of BitConnect, which claimed a 'volatility trading bot' paid huge returns.
SOURCE: US DOJ, 25 Feb 2022 (indictment)
#3 PlusToken operators (Chen Bo and others) CONVICTEDREPORT PENDING
About 14.8 billion yuan (~$2.2 billion) per Chinese court; Chainalysis estimated ~$2 billion · 2018-2019
Wallet app promising high returns that took in billions in crypto, largely from users in China and South Korea.
SOURCE: Yancheng Intermediate People's Court via Chinese state media, Nov-Dec 2020; Chainalysis, 2020
#4 Xue 'Sam' Lee (HyperFund/HyperVerse) CHARGED (NOT TRIED)REPORT PENDING
More than $1.7 billion raised · 2020-2022
Charged as co-founder of HyperFund, sold as crypto-mining 'memberships' with guaranteed returns.
SOURCE: US SEC and DOJ, 29 Jan 2024
#5 Mirror Trading International (Johann Steynberg) CIVIL JUDGMENTREPORT PENDING
At least 29,421 BTC (about $1.7 billion at the time of the CFTC action) · 2018-2021
South African bitcoin 'forex trading' club; the CFTC said it was a fraudulent pooled scheme.
SOURCE: US CFTC, 30 Jun 2022
#6 Forsage founders (Vladimir Okhotnikov and others) CHARGED (NOT TRIED)REPORT PENDING
About $340 million (alleged) · 2020-2022
Charged over a smart-contract 'matrix' scheme paying earlier investors with newer investors' crypto.
SOURCE: US DOJ, 22 Feb 2023; US SEC, Aug 2022
#7 Karl Sebastian Greenwood (OneCoin) CONVICTEDREPORT PENDING
Part of OneCoin's $4 billion+; ordered to forfeit $300 million · 2014-2018
OneCoin co-founder who ran its global MLM sales network.
SOURCE: US DOJ (SDNY), 12 Sep 2023 (20 years)
#8 Trendon Shavers (Bitcoin Savings and Trust) PLEADED GUILTYREPORT PENDING
About 700,000 BTC raised (roughly $4.5 million at the time) · 2011-2012
Ran what the SEC called the first bitcoin Ponzi scheme, promising 7% weekly.
SOURCE: US SEC, Jul 2013; US DOJ (SDNY), Jul 2016 (18 months)
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
Bulgaria (OneCoin base)
China (PlusToken victims and prosecution)
India (BitConnect founder; many victims)
United States (victims and main prosecutions)
South Africa (Mirror Trading International)
Australia (HyperFund founder; victims)
KEY NUMBERS
Over half of 2024 crypto scam revenue came from high-yield investment scams (Chainalysis, Feb 2025)
$9.9 billion crypto scam revenue identified in 2024 (projected to reach ~$12.4 billion) (Chainalysis, Feb 2025)
$1.5 billion crypto received in 2024 by Smart Business Corp., a long-running Ponzi scheme (Chainalysis, Feb 2025)
$4 billion+ taken by OneCoin, the largest documented crypto Ponzi (US DOJ, 2019-2023)
SOURCES
US DOJ / FBI on OneCoin (Mar 2019; Ten Most Wanted Jun 2022; Greenwood sentencing 12 Sep 2023)
US DOJ, BitConnect indictment, 25 Feb 2022
US SEC and DOJ, HyperFund charges, 29 Jan 2024
US CFTC, Mirror Trading International, 30 Jun 2022
US DOJ and SEC, Forsage (2022-2023)
US SEC v. Shavers, 2013; US DOJ SDNY, 2016
Chainalysis, 2025 Crypto Crime Report (scams chapter), Feb 2025
Chinese state media on PlusToken verdict, 2020
METHOD #36 OF 110
Counterfeit Currency
HIGH
SCALE (ENCYCLOPEDIA)
$70M+ seized annually (US)
WHERE IT'S CONCENTRATED
Colombia, Peru, North Korea (Superdollar)
IN SHORT
Fake banknotes. North Korea produced 'Superdollars' (near-perfect $100 bills). Colombia/Peru produce majority of counterfeit USD. Digital payments reducing impact.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Market sold counterfeit money (per the DOJ)
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #37 OF 110
Insurance Fraud
HIGH
SCALE (ENCYCLOPEDIA)
$308B+/year (US, Coalition Against)
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
Staged accidents, phantom injuries, arson, inflated claims. Auto, health, property, workers comp. Estimated 10% of insurance payouts are fraudulent.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #38 OF 110
Real Estate Fraud
HIGH
SCALE (ENCYCLOPEDIA)
$350M+ (FBI IC3 2023)
WHERE IT'S CONCENTRATED
Global — US, UK, Canada
IN SHORT
Title fraud, mortgage fraud, seller impersonation, wire diversion at closing. Crypto laundering through property (Chen Zhi: 19 London properties). Growing rapidly.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #39 OF 110
Banking Trojan
HIGH
SCALE (ENCYCLOPEDIA)
$1B+ losses estimated
WHERE IT'S CONCENTRATED
Brazil, Russia
IN SHORT
Malware targeting mobile/online banking. Grandoreiro, Guildma (Brazil), TrickBot (Russia). Intercepts credentials, modifies transactions. Brazil exports trojans globally.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #40 OF 110
Check Fraud
HIGH
SCALE (ENCYCLOPEDIA)
$27B+ (2023, FinCEN)
WHERE IT'S CONCENTRATED
United States
IN SHORT
Mail theft, check washing, counterfeit checks. Surged 2020-2024 despite digital payments growth. FinCEN: $27B in suspicious activity reports. USPS mail theft fueling.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Forged payroll checks (documented)
WHERE IT CAME FROM
FIRST SEEN: 17th century · GOING FOR: Over 350 years (since the 1600s)

Cheques developed from bills of exchange and were in use in England by the 17th century (a surviving cheque dates from 1659), and forged or altered cheques followed almost immediately. In the US, check forgery, 'paper hanging' (writing bad checks) and check kiting - exploiting the float between banks - were staple frauds through the 20th century; the investment bank E.F. Hutton pleaded guilty in 1985 to 2,000 counts over a kiting-style overdraft scheme, and 's widely publicised (and partly disputed) story made check forgery famous. Desktop publishing in the 1990s made counterfeit checks easy, and remote deposit by phone added new tricks. Since about 2020 US check fraud has surged again, driven by checks stolen from the mail and 'washed' or altered, and by counterfeit checks sold on social media and messaging apps.

HOW IT WORKS

Fraudsters steal real checks - often from mailboxes - and chemically 'wash' or alter the payee and amount, or copy the account details onto counterfeit checks. They deposit them into accounts they control or recruit 'money mules' to do so, then withdraw cash before the bank discovers the check is bad. Related scams send victims a fake check for more than they are owed and ask them to wire back the difference before it bounces. Kiting moves money between accounts at different banks to create a false balance during clearing delays.

WARNING SIGNS
Checks you mailed never arrive or clear to a different payeeSomeone overpays with a check and asks for money backStrangers online offering to 'flip' money through your bank accountChecks with altered ink, smudges or mismatched fontsFunds available before the check has truly cleared
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Charlie Banks Green Jr. CONVICTEDREPORT PENDING
More than $10 million in checks stolen (face value); $1.62 million restitution · c. 2019-2023
Los Angeles postal worker who stole Treasury and other checks from the mail for a fraud ring over four years.
SOURCE: US DOJ (C.D. Cal.) via CBS Los Angeles, 2024
#2 E.F. Hutton & Co. PLEADED GUILTYREPORT PENDING
$2 million fine plus up to $8 million restitution · 1980-1982
Brokerage that deliberately overdrew bank accounts to gain interest-free funds, a large-scale kiting-style scheme.
SOURCE: US DOJ plea, May 1985 (New York Times, 3 May 1985)
#3 Treyvon Alexander CONVICTEDREPORT PENDING
1,480 stolen checks with a face value of about $7.4 million · 2022-2023
Led what prosecutors called the largest known theft of checks from the mail in Cincinnati.
SOURCE: US DOJ (S.D. Ohio), 2024 (6 years)
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (by far the main victim market)
Canada (cheque and counterfeit-cheque scams)
United Kingdom (historic origin; fake-cheque overpayment scams)
KEY NUMBERS
680,000+ check-fraud suspicious activity reports filed by US financial institutions in 2022 (FinCEN Alert FIN-2023-Alert003, 27 Feb 2023)
350,000+ check-fraud SARs filed in 2021, up 23% on 2020 (FinCEN, 27 Feb 2023)
$688 million+ suspicious activity reported in mail-theft-related check fraud in the six months after FinCEN's alert (FinCEN Financial Trend Analysis, Sep 2024)
SOURCES
FinCEN Alert on Mail Theft-Related Check Fraud (FIN-2023-Alert003), 27 Feb 2023
FinCEN Financial Trend Analysis on mail theft-related check fraud, Sep 2024
US DOJ (S.D. Ohio) on Treyvon Alexander, 2024
US DOJ (C.D. Cal.) / CBS Los Angeles on Charlie Banks Green Jr., 2024
New York Times, 3 May 1985 (E.F. Hutton plea)
Britannica, ''; Alan C. Logan, 2020
Wikipedia, 'Cheque' and 'Cheque fraud', accessed Sep 2026
METHOD #41 OF 110
Forex Fraud
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$2B+/year
WHERE IT'S CONCENTRATED
Global — unregulated brokers
IN SHORT
Fake forex platforms, signal groups, robot trading scams. Unregulated brokers manipulate spreads. Often combined with pig butchering. CFTC active enforcement.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #42 OF 110
PPP/COVID Relief Fraud
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$236B+ estimated
WHERE IT'S CONCENTRATED
United States
IN SHORT
Paycheck Protection Program + EIDL + PUA fraud. 3,500+ charged (DOJ). $1.4B seized. Statute extended to 2032. Blueacorn processed $4.7B with 1 reviewer for 1.7M apps.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #43 OF 110
Lottery / Sweepstakes Scam
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$300M+/year (FTC)
WHERE IT'S CONCENTRATED
Jamaica, Nigeria, Costa Rica
IN SHORT
'You've won!' → pay fees to collect. Jamaican lotto scam industry targeting US elderly. Gift card or wire payment demanded. Repeat victimization common.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #44 OF 110
Bribery / Corruption
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$1T+/year globally (World Bank)
WHERE IT'S CONCENTRATED
Global — developing nations highest
IN SHORT
Public official corruption, corporate bribery, procurement fraud. FCPA (US), UK Bribery Act enforcement. Transparency International CPI tracks. $1T+ in bribes annually.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Bribed Antigua's bank regulator
Bribery (alleged)
A company department for bribes
WHERE IT CAME FROM
FIRST SEEN: Ancient; modern foreign-bribery law since 1977 · GOING FOR: Thousands of years; modern anti-bribery enforcement for nearly 50 years (since 1977)

Bribery has no single inventor: early legal codes and religious texts already prohibited paying officials for favours. The modern fight against cross-border bribery began with the US Foreign Corrupt Practices Act of 1977, passed after SEC inquiries in the mid-1970s (including the Lockheed scandal) revealed that US companies had paid officials abroad to win contracts. The OECD Anti-Bribery Convention (1997) and the UK Bribery Act (2010) extended the model internationally. Large 21st-century cases such as Siemens (2008), Odebrecht/Operation Car Wash (2014-2016) and Malaysia's 1MDB fund show bribes routed through consultants, shell companies and offshore accounts. In the crypto era the method also targets insiders: in May 2025 Coinbase disclosed that overseas support contractors had been bribed to leak customer data later used in impersonation scams.

HOW IT WORKS

Someone offers money, gifts, jobs or other benefits to a person with decision-making power, such as an official, procurement officer or company insider, in exchange for a contract, licence, favourable ruling or confidential data. Payments are usually disguised as consulting fees, commissions, donations or inflated invoices, and are often routed through intermediaries and shell companies. The cost is later recovered through overpriced contracts or poor-quality work, so taxpayers, shareholders or customers ultimately pay. Insider bribery can also leak customer data that fuels other scams.

WARNING SIGNS
Unexplained 'consulting' or 'success' fees to third partiesAgents insisting on payment to offshore or unrelated accountsContracts awarded without competition or at inflated pricesOfficials or staff living well beyond their meansRequests for cash, gifts or favours to 'speed things up'
GOVERNMENTS LINKED TO IT
Malaysia (1MDB state fund)
Former Prime Minister Najib Razak was convicted by Malaysian courts (2020, upheld 2022; and again in December 2025) over funds diverted from the state investment fund 1MDB; the US DOJ alleges over $4.5bn was misappropriated from the fund.
SOURCE: US DOJ, 2016-2018; Malaysian High Court via CNN, 26 Dec 2025
Venezuela
Former national treasurer Alejandro Andrade admitted in a US court to receiving over $1bn in bribes to steer government currency-exchange business; Alex Saab, an ally of the Maduro government, pleaded guilty in 2026 to a laundering scheme involving bribes to officials over state food-import (CLAP) contracts.
SOURCE: US DOJ, Nov 2018; US DOJ (S.D. Fla.), Sept 2026
Brazil (Petrobras)
Operation Car Wash (from 2014) documented bribes paid by contractors, including Odebrecht, to executives of state oil company Petrobras and to politicians; some convictions were later annulled on procedural grounds.
SOURCE: US DOJ Odebrecht plea, Dec 2016
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Airbus SE SETTLEDREPORT PENDING
$3.9bn (global penalties) · 2020
Aerospace company that paid bribes via third-party agents in multiple countries; resolved with France, the UK and the US.
SOURCE: US DOJ / UK SFO, Jan 2020
#3 Siemens AG PLEADED GUILTYREPORT PENDING
About $1.4bn (bribe payments per SEC) · 2001-2007 (resolved 2008)
Made thousands of corrupt payments worldwide to win government contracts.
SOURCE: US SEC / DOJ, Dec 2008
#4 Alejandro Andrade PLEADED GUILTYREPORT PENDING
Over $1bn (bribes received) · 2008-2011 (sentenced 2018)
Former Venezuelan national treasurer who accepted bribes to award currency-exchange deals.
SOURCE: US DOJ, Nov 2018
#5 Odebrecht S.A. PLEADED GUILTYREPORT PENDING
About $788m (bribes paid) · 2001-2016
Brazilian construction group that ran a dedicated bribery department paying officials in 12 countries.
SOURCE: US DOJ, Dec 2016
#6 Najib Razak CONVICTEDREPORT PENDING
About $568m (RM2.3bn, per Dec 2025 verdict) · 2009-2015 (convicted 2020, 2025)
Former Malaysian prime minister convicted of abuse of power and money laundering over 1MDB funds.
SOURCE: CNN / SCMP, Dec 2025
#7 Glencore PLEADED GUILTYREPORT PENDING
Over $100m (bribes); over $1.1bn US penalties · 2007-2018 (resolved 2022)
Commodity trader that paid bribes to officials in several African and Latin American countries for oil deals.
SOURCE: US DOJ, May 2022
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
Brazil (source: Odebrecht / Car Wash)
Malaysia (victim state fund: 1MDB)
Venezuela (officials bribed: treasury, PDVSA, CLAP)
United States (main enforcer under the FCPA)
Germany and France (home of large corporate bribery cases: Siemens, Airbus)
KEY NUMBERS
$1.5-2 trillion Estimated bribes paid worldwide each year (about 2% of global GDP; estimate) (IMF Staff Discussion Note, May 2016)
57% Share of foreign bribery cases involving bribes to win public contracts (OECD Foreign Bribery Report, Dec 2014)
$3.5bn Combined global penalty in the Odebrecht/Braskem resolution (then a record) (US DOJ, Dec 2016)
4,283 Corrupt payments made by Siemens, totalling about $1.4bn (US SEC, Dec 2008)
SOURCES
US DOJ, Odebrecht and Braskem plea, 21 Dec 2016
US SEC, Siemens settlement, 15 Dec 2008
US DOJ, 1MDB charges (), Nov 2018
US DOJ, Alejandro Andrade sentencing, 27 Nov 2018
US DOJ, Glencore guilty pleas, May 2022
US DOJ / UK SFO, Airbus resolution, Jan 2020
CNN, Najib Razak 1MDB verdict, 26 Dec 2025
South China Morning Post, Najib sentencing, Dec 2025
US DOJ (S.D. Fla.), Alex Saab guilty plea, Sept 2026
IMF, Corruption: Costs and Mitigating Strategies, May 2016
OECD Foreign Bribery Report, Dec 2014
Coinbase SEC Form 8-K disclosure, May 2025
METHOD #45 OF 110
Counterfeiting (Products)
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$509B/year (OECD)
WHERE IT'S CONCENTRATED
China (source), Global
IN SHORT
Fake luxury goods, pharmaceuticals, electronics, automotive parts. China produces 63% of seized counterfeits. Amazon/eBay marketplace problem. Health/safety risks.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #46 OF 110
Invoice / Procurement Fraud
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$121M ( case)
WHERE IT'S CONCENTRATED
Global — Lithuanian targeted Google/Facebook
IN SHORT
Fake invoices impersonating real suppliers. invoiced Google + Facebook for $121M — both paid. Internal procurement manipulation. Difficult to detect.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Fake purchase orders for goods that didn't exist
Fake invoices to Google and Facebook
WHERE IT CAME FROM
FIRST SEEN: 1860s (US Civil War contractor fraud); online form c. 2013 · GOING FOR: Over 160 years (since the 1860s); email-based version for over a decade

Billing governments and businesses for goods never delivered, or at inflated prices, is as old as organised procurement. Contractor fraud during the American Civil War prompted the US False Claims Act of 1863 (the 'Lincoln Law'), which still underpins US procurement enforcement. In the late 1980s the FBI's Operation Ill Wind exposed bribery and bid-rigging in Pentagon purchasing. From around 2013 the method moved online as Business Email Compromise, where criminals send fake or altered supplier invoices by email; the FBI began tracking BEC as a category in 2013. The case (2013-2015), in which fake invoices mimicking a real hardware supplier fooled Google and Facebook, showed that even large tech firms were exposed.

HOW IT WORKS

A fraudster sends an invoice that looks like it comes from a real supplier, or tells the finance team that a supplier's bank details have changed, so payment goes to an account the criminal controls. Inside procurement, a corrupt employee or contractor may inflate prices, bill for work not done, split contracts to avoid oversight or rig bids with fake competing quotes. Criminals often first take over or imitate a genuine email account so the request fits an existing conversation. Funds are quickly moved through mule or shell-company accounts, often abroad.

WARNING SIGNS
Supplier 'changes bank details' by emailUrgent payment request that bypasses normal approvalInvoice from a lookalike domain or slightly altered email addressRound-number or duplicate invoices, or bills for undelivered goodsSame small group always winning contracts, or bids just under approval limits
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Leonard Francis ('Fat Leonard') PLEADED GUILTYREPORT PENDING
At least $35m (Navy overbilling) · 2004-2013 (sentenced 2024)
Ship-husbanding contractor who overbilled the US Navy and bribed officers; fled in 2022 and was returned from Venezuela.
SOURCE: CNN / USNI News, 5 Nov 2024
#3 Obinwanne Okeke PLEADED GUILTYREPORT PENDING
About $11m (losses) · 2015-2019 (sentenced 2021)
Led a phishing and fake-invoice scheme that diverted payments from Unatrac, Caterpillar's export sales office.
SOURCE: US DOJ (E.D. Va.), Feb 2021; CNN, Feb 2021
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest reported victim losses)
United Kingdom (victim companies, e.g. Unatrac)
Nigeria (origin of several prosecuted BEC schemes, per DOJ)
Hong Kong and mainland China (frequent destination for diverted wires, per FBI)
Lithuania and Latvia ( scheme accounts)
KEY NUMBERS
$3.05bn Business Email Compromise losses reported to the FBI in 2025 (24,768 complaints) (FBI IC3 Annual Report, 2025)
$2.77bn BEC losses reported to the FBI in 2024 (FBI IC3 Annual Report, 2024)
$122m Stolen from Google and Facebook with fake supplier invoices (US DOJ (SDNY), 2019)
$35m Minimum overbilling of the US Navy in the 'Fat Leonard' case (US DOJ via CNN, Nov 2024)
SOURCES
FBI IC3 Annual Report 2025 (published 2026)
FBI IC3 Annual Report 2024
US DOJ (SDNY), plea Mar 2019 and sentencing Dec 2019
CyberScoop, Dec 2019
CNN, 'Fat Leonard' sentencing, 5 Nov 2024
USNI News, 5 Nov 2024
US DOJ (E.D. Va.), Okeke sentencing, Feb 2021
US DOJ (C.D. Cal.), Abbas sentencing, Nov 2022
US False Claims Act (31 U.S.C. 3729), enacted 1863
METHOD #47 OF 110
Crypto Mining Fraud
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$500M+
WHERE IT'S CONCENTRATED
Global
IN SHORT
Fake cloud mining operations. No actual hardware. Guaranteed returns from 'mining.' HashPower Pro example: $5.2M stolen. Often structured as Ponzi.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #48 OF 110
ATM Skimming / Jackpotting
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$1B/year (FBI estimate)
WHERE IT'S CONCENTRATED
Romania, Russia, Global
IN SHORT
Physical card readers on ATMs. Shimming attacks on EMV chips. Jackpotting: malware forces ATM to dispense cash. FBI estimates $1B annually.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #49 OF 110
Trade-Based Money Laundering
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
$2T+ (linked to money laundering)
WHERE IT'S CONCENTRATED
China, Hong Kong, Global
IN SHORT
Over/under-invoicing trade to move value across borders. Misrepresenting goods/services. Difficult to detect — looks like legitimate commerce. FATF priority.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #50 OF 110
Deepfake Fraud
MODERATE-HIGH
SCALE (ENCYCLOPEDIA)
456% increase in AI scam reports
WHERE IT'S CONCENTRATED
Global (emerging)
IN SHORT
AI-generated video/audio for impersonation. CEO deepfake: Hong Kong firm lost $25M to deepfake video call (2024). Voice cloning for phone scams. FaaS making accessible.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #51 OF 110
Sextortion
MODERATE
SCALE (ENCYCLOPEDIA)
$1.8B+ (FBI IC3)
WHERE IT'S CONCENTRATED
Philippines, Nigeria, Côte d'Ivoire
IN SHORT
Threatening to share intimate images unless payment. Digital sextortion targeting teens increasing. Growing in East Africa. Often cryptocurrency payment demanded.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #52 OF 110
Smishing (SMS Phishing)
MODERATE
SCALE (ENCYCLOPEDIA)
Part of phishing losses
WHERE IT'S CONCENTRATED
Global
IN SHORT
Fraudulent text messages with malicious links. Package delivery scams, bank alerts, toll notices. Growing as SMS trusted more than email. AI-generated at scale.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #53 OF 110
Vishing (Voice Phishing)
MODERATE
SCALE (ENCYCLOPEDIA)
$1B+
WHERE IT'S CONCENTRATED
India, Global
IN SHORT
Phone-based social engineering. Bank impersonation, IRS scams, tech support. AI voice cloning emerging. South Korea: $1.3B annual vishing losses.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Fake support calls to the victim
WHERE IT CAME FROM
FIRST SEEN: Mid-2000s (term); phone fraud long before · GOING FOR: About 20 years as 'vishing' (since the mid-2000s); phone scams for over a century

Telephone confidence tricks are as old as the telephone, and high-pressure 'boiler room' telemarketing fraud flourished in the US from the 1980s. The term 'vishing' emerged in the mid-2000s as cheap internet (VoIP) calling and caller-ID spoofing let criminals impersonate banks at scale. From around 2013 to 2016, call centres in Ahmedabad, India impersonated the IRS and US immigration officials, leading to a 2016 US indictment of 61 people and entities. Fake 'tech support' calls and pop-ups (often claiming to be Microsoft or Apple) grew in parallel. Since 2022 the method has shifted to fake crypto-exchange and wallet support calls and to calls impersonating IT help desks to break into companies, as in the Scattered Spider intrusions.

HOW IT WORKS

The caller pretends to be a trusted organisation such as a bank, tax agency, police, tech company, crypto exchange or your employer's IT help desk, often with a spoofed caller ID. They create urgency: an account 'hack', a warrant, a refund or a security alert. The victim is then pushed to read out one-time codes or passwords, install remote-access software, move money or crypto to a 'safe' account, or buy gift cards. With help-desk calls, attackers use personal details found online to get passwords or multi-factor authentication reset for an employee's account.

WARNING SIGNS
Unsolicited call claiming your account or computer is compromisedRequest to read out a one-time code or seed phrasePressure to install remote-access softwareDemand for payment by gift card, crypto ATM or wireThreats of arrest, deportation or account closure
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Jeandiel Serrano PLEADED GUILTYREPORT PENDING
About $263m (theft he helped launder) · 2024 (sentenced 2025)
Co-defendant who laundered proceeds of the same social-engineering bitcoin theft; sentenced to 70 months.
SOURCE: US DOJ (D.D.C.)
#2 Thalha Jubair CHARGED (NOT TRIED)REPORT PENDING
$115m+ (ransom payments by victims, alleged) · 2022-2025
UK national alleged to be part of Scattered Spider, which called company help desks to reset passwords, including at a US court system.
SOURCE: US DOJ (D.N.J.), Sept 2025
#3 Hitesh Madhubhai Patel CONVICTEDREPORT PENDING
$25m-$65m (admitted net proceeds) · 2013-2016 (sentenced 2020)
Ran Ahmedabad call centres that impersonated the IRS and US immigration officials; sentenced to 20 years.
SOURCE: US DOJ, Nov 2020
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest reported victim losses)
India (hub of prosecuted call centres; FBI works with India's CBI)
United Kingdom (victims and suspects in help-desk vishing cases)
Canada (victims of tax-agency impersonation calls)
KEY NUMBERS
$2.13bn Tech/customer-support scam losses reported to the FBI in 2025 (47,794 complaints) (FBI IC3 Annual Report, 2025)
$798m Government-impersonation scam losses reported in 2025 (FBI IC3 Annual Report, 2025)
80,000+ / $2.9bn Call-centre fraud complaints and losses (tech support plus government impersonation), 2025 (FBI IC3 Annual Report, 2025)
215+ Arrests in 2024 from joint FBI-India CBI operations against call-centre fraud (FBI IC3 Annual Report, 2024)
SOURCES
FBI IC3 Annual Report 2025 (published 2026)
FBI IC3 Annual Report 2024
US DOJ, Hitesh Patel sentencing, Nov 2020
US DOJ (D.D.C.), guilty plea, Sept 2026
US DOJ (D.D.C.), Jeandiel Serrano sentencing, 2025
US DOJ (D.N.J.), Thalha Jubair complaint, Sept 2025
The Record, Sept 2025
METHOD #54 OF 110
Subscription Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$1B+
WHERE IT'S CONCENTRATED
Global
IN SHORT
Stolen cards used to create streaming/service accounts. Sold on dark web for $2-5 each. Low-value recurring charges avoid detection for months.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #55 OF 110
Utility Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$200M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Fake utility company calls threatening disconnection. Payment demanded via gift card/wire. Targets vulnerable populations. Seasonal spikes (winter heating).
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #56 OF 110
Timeshare Fraud / Resale Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$300M+
WHERE IT'S CONCENTRATED
Mexico, Costa Rica
IN SHORT
Fake resale offers for timeshare owners. Upfront fees collected, no sale executed. Targeting elderly timeshare owners. Mexican cartel involvement reported.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #57 OF 110
Charity Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$200M+/year during disasters
WHERE IT'S CONCENTRATED
Global
IN SHORT
Fake charities after disasters/events. GoFundMe fraud. Exploits empathy. Spikes after hurricanes, earthquakes, wars. FTC + state AGs enforce.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #58 OF 110
Employment / Job Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$500M+ (FTC)
WHERE IT'S CONCENTRATED
Nigeria, Global
IN SHORT
Fake job offers → personal info theft or money mule recruitment. Work-from-home payment processing. Reshipping scams. Indeed/LinkedIn exploitation.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Fake job offers as a lure
WHERE IT CAME FROM
FIRST SEEN: Decades old (work-at-home schemes); task scams c. 2022; hacking lures c. 2019-2020 · GOING FOR: Decades; the crypto-era task scam and hacking-lure forms for about 4-6 years

Fake job offers are an old trick: US regulators have warned for decades about 'work-at-home' schemes such as envelope stuffing that required an upfront fee. Online, fake recruiters and 'reshipping' or 'payment processing' jobs later turned job seekers into unwitting money mules. Since about 2022, 'task scams' pay small sums for rating products or apps, then demand crypto deposits to 'unlock' earnings. Fake jobs are also a hacking lure: North Korea-linked campaigns (dubbed 'Operation Dream Job' by researchers from 2020) send tailored job offers with malicious files, and a fake offer is reported to have opened the door to the $625m Ronin/Axie Infinity theft in 2022. Fake overseas job ads are also used to recruit people into scam compounds in Southeast Asia.

HOW IT WORKS

Scammers post or send attractive job offers, often remote, high-paying and requiring little experience, via job sites, LinkedIn, WhatsApp or text. The 'employer' then asks for money for training, equipment or to unlock task earnings, collects ID and bank details, or has the new 'employee' move money that turns out to be stolen. In the hacking version, a fake recruiter runs convincing interviews and sends a document, coding test or app that installs malware giving access to the target's employer systems or crypto wallets. Some overseas job ads lead to trafficking into forced-scam operations.

WARNING SIGNS
Job offer without a real interview, or for a job you did not apply forYou must pay upfront or deposit crypto to 'unlock' payAsked to receive and forward money or packagesRecruiter sends a file or coding test to run on a work deviceOverseas job with travel paid but vague employer details
GOVERNMENTS LINKED TO IT
North Korea
The FBI attributed the March 2022 Ronin Network theft (reportedly begun via a fake job offer) to /APT38; the US Treasury designated in 2019 as controlled by North Korea's Reconnaissance General Bureau. DOJ cases also show North Korean IT workers using false identities to obtain remote jobs, generating revenue for the regime.
SOURCE: FBI, 14 Apr 2022; US Treasury OFAC, 13 Sept 2019; US DOJ, July 2025
NOTABLE PEOPLE WHO USED IT — RANKED
#1 Chen Zhi (Prince Group) CHARGED (NOT TRIED)REPORT PENDING
About $15bn (bitcoin targeted in US forfeiture action) · 2015-2025
Charged by US prosecutors as head of a conglomerate running forced-labour scam compounds in Cambodia whose workers were often lured by fake job offers; extradited to China in January 2026.
SOURCE: US DOJ (E.D.N.Y.), 14 Oct 2025; CNN, 7 Jan 2026
#2 Christina Chapman PLEADED GUILTYREPORT PENDING
$17m+ (revenue generated for North Korea) · 2020-2023 (sentenced 2025)
Ran a 'laptop farm' in Arizona that let North Korean IT workers pose as US-based remote employees at 309 US companies.
SOURCE: US DOJ (D.D.C.), July 2025
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest reported victim losses)
North Korea (state-linked fake-recruiter hacking lures and IT-worker fraud)
Cambodia and Myanmar (scam compounds recruiting via fake job ads, per UN OHCHR)
India and other Asian countries (source of many trafficked job seekers, per UN reporting)
KEY NUMBERS
$501m Reported US job-scam losses in 2024, up from $90m in 2020 (FTC, Dec 2024 / 2025)
$363m Employment-scam losses reported to the FBI in 2025 (24,688 complaints) (FBI IC3 Annual Report, 2025)
~40% Estimated share of 2024 US job-scam reports that were 'task scams' (FTC Data Spotlight, Dec 2024)
$625m Ronin/Axie Infinity theft reportedly initiated through a fake job offer (FBI, Apr 2022; The Block, July 2022)
SOURCES
FTC Data Spotlight, 'Paying to get paid: gamified job scams', Dec 2024
FBI IC3 Annual Report 2025 (published 2026)
FBI statement on Ronin attribution, 14 Apr 2022
The Block, 'How a fake job offer took down the world's most popular crypto game', July 2022
US Treasury OFAC, designation, 13 Sept 2019
US DOJ (D.D.C.), Christina Chapman sentencing, July 2025
US DOJ (E.D.N.Y.), Chen Zhi indictment, Oct 2025
CNN, Chen Zhi extradition, 7 Jan 2026
UN OHCHR report on online scam operations in Southeast Asia, Aug 2023
METHOD #59 OF 110
Warranty / Extended Warranty Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Robocalls offering fake extended warranties. 'Your car warranty is expiring.' Targets vehicle owners. One of most complained-about robocall topics.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #60 OF 110
Pension / Retirement Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$1B+
WHERE IT'S CONCENTRATED
United Kingdom, United States
IN SHORT
Pension liberation scams, fake retirement investments, advisor fraud. UK pension freedoms (2015) opened new attack surface. ERISA violations.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #61 OF 110
Student Loan Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$200M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Fake student loan forgiveness services. Upfront fees for free government programs. Identity theft via application data. Targeting recent graduates.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #62 OF 110
Foreclosure Rescue Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$150M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Fake mortgage modification/rescue services targeting homeowners in distress. Upfront fees, deed theft, equity stripping.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #63 OF 110
Moving Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Hostage goods (low estimate → huge bill on delivery), fake movers, stolen belongings. FMCSA enforcement. Targets military families and interstate moves.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #64 OF 110
Online Auction Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
Romania, Nigeria, Global
IN SHORT
Fake eBay/marketplace listings. Non-delivery, counterfeit goods, shill bidding. Escrow scams. Romania's 'Hackerville' historically known for this.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #65 OF 110
Ticket Fraud / Scalping Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$200M+
WHERE IT'S CONCENTRATED
Global
IN SHORT
Fake concert/event tickets. Counterfeit barcodes. Resale at inflated prices. Social media selling. Growing with AI-generated fake ticket images.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #66 OF 110
Contractor / Home Repair Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$200M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Fake contractors collecting deposits and disappearing. Storm chasing after natural disasters. Targeting elderly homeowners. State licensing fraud.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #67 OF 110
Grandparent Scam
MODERATE
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
Jamaica, Canada (source), US (target)
IN SHORT
'Grandma, I'm in jail, need bail money.' Impersonating grandchild in distress. AI voice cloning making more convincing. Wire/gift card payment. Targets 70+.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #68 OF 110
Payroll Diversion Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$300M+ (FBI IC3)
WHERE IT'S CONCENTRATED
Global
IN SHORT
HR phishing → change employee direct deposit to attacker account. Subset of BEC targeting payroll departments. Average diversion: $7,904.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #69 OF 110
Supply Chain Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$100B+ impact
WHERE IT'S CONCENTRATED
Global — China, India
IN SHORT
Counterfeit components, substituted materials, falsified certifications. Automotive, aerospace, pharmaceutical, electronics supply chains affected.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #70 OF 110
Binary Options Fraud
MODERATE
SCALE (ENCYCLOPEDIA)
$10B+ cumulative
WHERE IT'S CONCENTRATED
Israel (pre-crackdown), Eastern Europe
IN SHORT
Fake trading platforms with rigged algorithms. Israel banned industry 2017 after $10B+ estimated global losses. Operations relocated to Eastern Europe, SE Asia.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #71 OF 110
Crop / Agricultural Insurance Fraud
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
False claims on crop losses. Prevented planting fraud. USDA RMA investigations. Often involves complicit insurance agents.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #72 OF 110
Debt Collection Scam
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
United States, India
IN SHORT
Fake debt collectors threatening arrest for non-existent debts. Phantom debt. Bought aged debt for pennies and collected aggressively. FTC enforcement.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #73 OF 110
Recovery Scam (Double Victimization)
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$500M+
WHERE IT'S CONCENTRATED
Global
IN SHORT
Scammers target prior fraud victims offering to 'recover' lost funds for upfront fees. Google Ads, Reddit posts, FBI impersonation. The cruelest fraud type.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #74 OF 110
Crowdfunding Fraud
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
Global
IN SHORT
GoFundMe, Kickstarter fraud. Fake medical emergencies, fake products, misuse of funds. Limited regulatory oversight. Community reporting primary detection.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #75 OF 110
Domain Spoofing / Typosquatting
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
Part of phishing
WHERE IT'S CONCENTRATED
Global
IN SHORT
Registering domains similar to legitimate sites (gooogle.com, arnazon.com). Redirect to phishing pages or malware. Millions of typosquat domains registered.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #76 OF 110
Prize / Award Notification Scam
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
Nigeria, Jamaica
IN SHORT
'You've been selected for an award / prize' → pay processing fee. Targeting professionals, academics. LinkedIn-based variations growing.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #77 OF 110
Odometer Fraud
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$1B+ (NHTSA estimate)
WHERE IT'S CONCENTRATED
Global
IN SHORT
Rolling back vehicle mileage to increase sale price. NHTSA estimates affects 450K vehicles/year in US. CARFAX helps but not foolproof.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #78 OF 110
Scholarship / Grant Scam
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$50M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Fake scholarship applications collecting fees and personal data. Targeting students and parents. Legitimate scholarships never require upfront payment.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #79 OF 110
Immigration Scam
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$200M+
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
Fake immigration lawyers/consultants. Notario fraud targeting Spanish-speaking immigrants. Visa lottery scams. USCIS impersonation.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #80 OF 110
Elder Financial Abuse
MODERATE-LOW
SCALE (ENCYCLOPEDIA)
$28.3B/year (US)
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
Financial exploitation by caregivers, family members, or strangers. $28.3B annual losses (US). Includes many other fraud types targeting elderly specifically.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #81 OF 110
Affinity Fraud
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
$1B+
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
Targeting religious, ethnic, or professional communities. Trust-based. Madoff targeted Jewish communities. Church-based Ponzis. Military-targeted investment scams.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Recruited through community and social ties
WHERE IT CAME FROM
FIRST SEEN: Long-standing; named by US regulators by the 1990s · GOING FOR: Decades as a recognised category (since at least the 1990s)

Affinity fraud is not a separate trick but a way of targeting: the fraudster exploits the trust inside a religious, ethnic, professional or community group. US securities regulators were using the term by the 1990s, when church-linked schemes such as Greater Ministries International and the Baptist Foundation of Arizona collapsed, each costing investors hundreds of millions. 's Ponzi scheme, exposed in 2008, drew heavily on trust within Jewish communities and charities and is often cited as the largest affinity fraud. In the crypto era, schemes such as AirBit Club targeted Latino and immigrant communities with promises of crypto mining profits. Regulators including NASAA continue to warn about frauds using religion and community ties.

HOW IT WORKS

The promoter is, or poses as, a member of a group such as a congregation, ethnic community, language group or professional network, and often recruits respected leaders first. Their endorsement makes others invest without checking, and members are discouraged from going to outside regulators. The 'investment' is usually a Ponzi scheme, fake crypto or trading programme, or an unregistered security with promised high, steady returns. Because victims feel loyalty or shame, fraud is reported late and losses spread through whole communities.

WARNING SIGNS
Investment pitched through church, community or cultural group'Trust me, I'm one of you' in place of documentsGuaranteed high returns with little or no riskPressure to keep it within the group or avoid outside advicePromoter not registered with securities regulators
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#1 William Crotts (Baptist Foundation of Arizona) CONVICTEDREPORT PENDING
About $580m (investor losses) · 1990s (collapse 1999; convicted 2006)
President of a Baptist foundation whose collapse wiped out about 11,000 mostly church-member investors.
SOURCE: NBC News / Associated Press, 2006
#2 Gerald Payne (Greater Ministries International) CONVICTEDREPORT PENDING
Nearly $500m (taken from about 18,000 people) · 1990s (convicted 2001)
Church leader who promised to 'double' members' money through a religious 'gifting' programme; sentenced to 27 years.
SOURCE: Christianity Today, 2001
#3 Pablo Renato Rodriguez (AirBit Club) PLEADED GUILTYREPORT PENDING
Over $100m (taken from investors) · 2015-2020 (sentenced 2023)
Co-founder of a fake crypto-mining scheme that targeted Latino communities in the US and abroad; sentenced to 12 years.
SOURCE: US DOJ (SDNY), Mar and Sept 2023
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (largest documented cases and victims)
Latin American countries (AirBit Club victims across the region, per DOJ)
European countries such as Spain, Switzerland and the UK (Madoff feeder-fund investors)
KEY NUMBERS
$17.5bn Principal lost by Madoff investors (US DOJ / Madoff Victim Fund)
11,000 / $580m Investors and losses in the Baptist Foundation of Arizona collapse (Associated Press / NBC News, 2006)
18,000 People who gave nearly $500m to Greater Ministries International (Christianity Today / Wikipedia summary of court record, 2001)
$100m+ Taken by AirBit Club, a crypto scheme targeting Latino communities (US DOJ (SDNY), 2023)
SOURCES
US SEC investor alert on affinity fraud
NASAA, 'Investment frauds using religion on the rise'
US DOJ, Madoff plea, Mar 2009; Madoff Victim Fund
NBC News / Associated Press, Baptist Foundation convictions, 2006
Christianity Today, Greater Ministries convictions and sentences, 2001
US DOJ (SDNY), AirBit Club pleas Mar 2023 and sentencing Sept 2023
Cointelegraph, AirBit sentencing, Sept 2023
METHOD #82 OF 110
Bust-Out Scheme
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
$1B+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Build legitimate business credit over months, max out all credit lines simultaneously, disappear. Business version of synthetic identity bust-out.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #83 OF 110
Shell Company Fraud
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
Part of money laundering
WHERE IT'S CONCENTRATED
Global — Panama, BVI, Delaware
IN SHORT
Creating entities with no real operations to layer transactions. Panama Papers exposed scale. Beneficial ownership rules tightening but enforcement lags.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Special-purpose entities used to hide debt
Shell companies (alleged)
Offshore accounts to route payments
Shell company named after the real supplier
US shell-company bank accounts
WHERE IT CAME FROM
FIRST SEEN: 1880s-1890s (permissive incorporation laws); offshore boom from the 1980s · GOING FOR: Over 130 years (since the 1880s-1890s)

Companies that exist only on paper became easy to create after US states such as New Jersey (1889) and Delaware (1899) passed permissive incorporation laws; offshore centres followed, notably the British Virgin Islands' International Business Companies Act of 1984. Shell companies are legal in themselves, but anonymous ownership makes them a favoured tool for hiding bribes, stolen money and sanctions evasion. The Panama Papers (2016) and Pandora Papers (2021) leaks, published by ICIJ, showed how widely they were used by officials and criminals. Cases such as Moldova's $1bn bank theft (2014) and Malaysia's 1MDB used chains of shells to move money. In the crypto era, shell companies with US bank accounts are used to receive and launder scam victims' funds, as in the case.

HOW IT WORKS

A company is registered with nominee directors or hidden owners and no real business, often in a jurisdiction that does not publish ownership. It is used to open bank accounts, sign fake contracts or invoices, or pose as a legitimate supplier or investment. Money is passed through several such companies across countries so it becomes hard to trace to its criminal source. Victims may be sent to pay a 'company' account that looks legitimate but is controlled by fraudsters.

WARNING SIGNS
Company with no staff, website or physical officeOwners hidden behind nominees or offshore registrationsRecently formed company handling very large paymentsPayments routed through several unrelated jurisdictionsBeing asked to pay a company whose name differs from the one you dealt with
GOVERNMENTS LINKED TO IT
North Korea
UN Security Council Panel of Experts reports and US Treasury designations document North Korea's use of front and shell companies abroad to evade sanctions and launder funds, including stolen crypto.
SOURCE: UN Panel of Experts reports, 2019-2024; US Treasury OFAC
Venezuela
Alex Saab, an ally of the Maduro government, pleaded guilty in a US court to a scheme using entities secretly controlled by conspirators, fake companies and false invoices to win and skim state food-import contracts after bribing officials.
SOURCE: US DOJ (S.D. Fla.), Sept 2026
Malaysia (1MDB)
The US DOJ alleges funds from state fund 1MDB were diverted through shell companies, including one named to resemble a real Abu Dhabi fund; former PM Najib Razak was convicted in Malaysia over the funds.
SOURCE: US DOJ, 2016-2018; CNN, Dec 2025
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Ilan Shor FUGITIVEREPORT PENDING
About $1bn (bank theft) · 2014 (convicted 2023)
Convicted in absentia in Moldova over the 2014 disappearance of about $1bn from Moldovan banks via loans to connected companies; sanctioned by the US.
SOURCE: AP / Times of Israel, Apr 2023; US Treasury, Oct 2022
#3 Alex Saab PLEADED GUILTYREPORT PENDING
About $350m (alleged siphoned); $195m forfeiture agreed · 2011-2020 (plea 2026)
Used fake and front companies and false invoices to skim Venezuelan state food contracts; freed in a 2023 prisoner swap, then re-indicted and pleaded guilty in 2026.
SOURCE: US DOJ (S.D. Fla.), Sept 2026
#4 Paul Manafort CONVICTEDREPORT PENDING
More than $30m (laundered, per DOJ) · 2006-2015 (convicted 2018)
Hid income from Ukrainian political work in offshore shell-company accounts in Cyprus and elsewhere; later pardoned (2020).
SOURCE: US DOJ (Special Counsel), 2018
#5 Jürgen Mossack (Mossack Fonseca) ACQUITTEDREPORT PENDING
n/a · 2016-2024
Co-founder of the Panamanian law firm at the centre of the Panama Papers; acquitted of money laundering by a Panama court in 2024.
SOURCE: AP / Reuters, June 2024
MOST RELEVANT COUNTRY
British Virgin Islands
More than half of the roughly 214,000 offshore entities in the Panama Papers were registered in the BVI (ICIJ, 2016).
COUNTRIES MOST TIED TO IT
British Virgin Islands (major registry of offshore shells)
Panama (Mossack Fonseca, Panama Papers)
United States (easy anonymous formation in some states, e.g. Delaware)
Cyprus (routing hub in the Manafort and other cases)
Moldova (victim of the 2014 $1bn bank theft)
KEY NUMBERS
214,000+ Offshore entities exposed in the Panama Papers (11.5m documents) (ICIJ, Apr 2016)
11.9m Records in the Pandora Papers leak on offshore companies and trusts (ICIJ, Oct 2021)
$1bn Stolen from Moldovan banks in 2014, about 12% of Moldova's GDP (AP, Apr 2023)
2-5% Estimated share of global GDP laundered each year (estimate) (UNODC)
SOURCES
ICIJ, Panama Papers, Apr 2016
ICIJ, Pandora Papers, Oct 2021
US DOJ, 1MDB actions, 2016-2018
US DOJ (S.D. Fla.), Alex Saab guilty plea, Sept 2026
AP / Times of Israel, Ilan Shor sentence, Apr 2023
CoinDesk / The Record, sentencing, Feb 2026
US DOJ Special Counsel, Manafort, 2018
AP / Reuters, Panama Papers trial verdict, June 2024
UN Security Council Panel of Experts on DPRK reports
UNODC, money-laundering estimates
METHOD #84 OF 110
Wash Trading
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
$2B+ in crypto
WHERE IT'S CONCENTRATED
Global
IN SHORT
Buying and selling to yourself to inflate volume/price. Rampant in crypto and NFT markets. Used to attract legitimate buyers to manipulated assets.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #85 OF 110
Pump and Dump
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
$500M+
WHERE IT'S CONCENTRATED
Global
IN SHORT
Inflate asset price through false hype → sell at peak → price crashes. Penny stocks, crypto, memecoins. Wolf of Wall Street (Belfort) is the iconic case.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Propped up CEL while selling his own
Pumped penny stocks and sold
WHERE IT CAME FROM
FIRST SEEN: 1920s (stock pools); crypto form c. 2017 · GOING FOR: About 100 years (since the 1920s); crypto version since about 2017

Organised price manipulation flourished in 1920s US stock markets, where 'pools' of traders bid up shares, talked them up in the press and sold to the public, as exposed by the Senate's Pecora hearings (1932-1934). The Securities Exchange Act of 1934 outlawed such manipulation. In the 1980s-1990s 'boiler room' brokerages such as 's Stratton Oakmont cold-called investors to push penny stocks they then sold. The internet moved the pitch to message boards and spam emails, and from around 2017 to crypto: Telegram 'pump groups', paid influencer touting of ICOs, and market makers faking trading volume. In October 2024 the FBI created its own token in 'Operation Token Mirrors' to catch crypto market-manipulation firms.

HOW IT WORKS

Insiders or promoters quietly buy a cheap, thinly traded stock or token. They then hype it with false or exaggerated claims through calls, social media, influencers, chat groups or fake trading volume (wash trading), so the price rises as new buyers pile in. Once the price is up, the promoters sell their holdings, the price collapses, and late buyers are left with large losses. With new crypto tokens, creators may also control most of the supply or the liquidity pool and pull it out (a 'rug pull').

WARNING SIGNS
Sudden hype about an obscure stock or new token'Buy now before it moons' pressure in chats or from influencersHuge volume spikes with no real newsSmall group of wallets holding most of the token supplyPromoters paid to promote without clear disclosure
GOVERNMENTS LINKED TO IT
No government is documented as using this method.
NOTABLE PEOPLE WHO USED IT — RANKED
#2 Avraham Eisenberg ACQUITTEDREPORT PENDING
About $110m (drained from Mango Markets) · 2022
Manipulated the price of the MNGO token to borrow against inflated collateral on Mango Markets; jury convictions were vacated by the judge in 2025.
SOURCE: CoinDesk / TRM Labs, May 2025
#3 Aleksei Andriunin (Gotbit) PLEADED GUILTYREPORT PENDING
About $23m (crypto forfeited) · 2018-2024 (sentenced 2025)
Founder of a crypto market maker that sold wash trading and price manipulation to token issuers; caught in Operation Token Mirrors.
SOURCE: US DOJ (D. Mass.); Reuters via US News, June 2025
#4 John McAfee DIED BEFORE TRIALREPORT PENDING
More than $13m (alleged proceeds) · 2017-2018 (charged 2021)
Charged with using his Twitter account to tout crypto tokens he had secretly bought, then selling into the rise; died in a Spanish prison before trial.
SOURCE: US DOJ (SDNY), Mar 2021
#5 Jonathan Lebed SETTLEDREPORT PENDING
About $285,000 plus interest (disgorged to SEC) · 1998-2000
Teenager who posted hype messages about small stocks online, then sold; settled with the SEC in 2000.
SOURCE: US SEC, Sept 2000
MOST RELEVANT COUNTRY
COUNTRIES MOST TIED TO IT
United States (main victim market and enforcer)
Hong Kong and mainland China (issuers in several US small-cap 'ramp-and-dump' alerts, per US regulators)
Global / online (crypto pump groups on Telegram and Discord operate across borders)
KEY NUMBERS
74,037 (3.59%) Tokens launched in 2024 showing suspected pump-and-dump traits (Chainalysis Crypto Crime Report, 2025)
~90% Share of suspected pump-and-dump DEX pools 'rugged' by the pool creator (Chainalysis, 2025)
$2.57bn Estimated wash-trading volume on Ethereum, BNB Chain and Base in 2024 (Chainalysis, 2025)
18 Individuals and entities charged in the FBI's Operation Token Mirrors (US DOJ (D. Mass.), Oct 2024)
SOURCES
Chainalysis, 2025 Crypto Crime Report (pump-and-dump chapter)
US DOJ (D. Mass.), Operation Token Mirrors charges, Oct 2024
Reuters via US News, Andriunin sentencing, June 2025
US DOJ (SDNY), McAfee indictment, 5 Mar 2021
CoinDesk / TRM Labs, Eisenberg convictions vacated, May 2025
US SEC, Jonathan Lebed settlement, Sept 2000
US Senate Pecora hearings, 1932-1934
Securities Exchange Act of 1934
METHOD #86 OF 110
Click Fraud / Ad Fraud
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
$84B+/year
WHERE IT'S CONCENTRATED
China, Southeast Asia, Global
IN SHORT
Fake clicks/impressions on digital ads. Bot farms. 22% of all ad spend estimated wasted on fraud. Affects every advertiser.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #87 OF 110
Telemarketing Fraud
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
$500M+
WHERE IT'S CONCENTRATED
United States, India, Jamaica
IN SHORT
Robocalls selling fake products/services. Auto warranty, debt relief, vacation packages. 50B+ robocalls annually in US. Do Not Call violations.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #88 OF 110
Spoofed Website / Clone Site
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
Part of phishing
WHERE IT'S CONCENTRATED
Global
IN SHORT
Exact copies of legitimate websites (banks, exchanges, retailers). MetaMask, Coinbase, Amazon clones. Google Ads promoting fake sites.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #89 OF 110
Price Tag Switching
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
$200M+
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
Swapping price tags in retail stores. Self-checkout exploitation. Tag switching in fitting rooms. Organized rings at scale.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #90 OF 110
Kickback Scheme
LOW-MODERATE
SCALE (ENCYCLOPEDIA)
Part of bribery
WHERE IT'S CONCENTRATED
Global
IN SHORT
Payments to insiders for favorable treatment — contracts, approvals, referrals. Construction, healthcare, government procurement. Often paired with invoice fraud.
IN OUR CASE FILES — MOST TAKEN TO LEAST
Kickbacks for patient referrals
Kickbacks to marketers and doctors
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #91 OF 110
Coupon Fraud
LOW
SCALE (ENCYCLOPEDIA)
$300M-$600M/year
WHERE IT'S CONCENTRATED
United States
IN SHORT
Counterfeit coupons, extreme couponing abuse, digital coupon manipulation. Costs manufacturers hundreds of millions. Organized rings print counterfeit coupons.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #92 OF 110
Skimming (Employee Cash)
LOW
SCALE (ENCYCLOPEDIA)
Part of embezzlement
WHERE IT'S CONCENTRATED
Global
IN SHORT
Employee takes cash before it enters accounting system. Small amounts over time. Difficult to detect without camera/POS correlation.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #93 OF 110
Lapping Scheme
LOW
SCALE (ENCYCLOPEDIA)
Part of embezzlement
WHERE IT'S CONCENTRATED
Global
IN SHORT
Accounts receivable employee steals payment from Customer A, covers it with Customer B's payment, and so on. Requires ongoing access and concealment.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #94 OF 110
Ghost Employee
LOW
SCALE (ENCYCLOPEDIA)
Part of payroll fraud
WHERE IT'S CONCENTRATED
Global
IN SHORT
Fake employees on payroll — paychecks go to fraudster. Government and large organizations. Requires HR/payroll access.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #95 OF 110
Vendor Fraud
LOW
SCALE (ENCYCLOPEDIA)
Part of procurement fraud
WHERE IT'S CONCENTRATED
Global
IN SHORT
Fake vendor companies billing for goods/services never delivered. Employee creates fake vendor, approves fake invoices. Requires accounts payable access.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #96 OF 110
Kiting (Check Kiting)
LOW
SCALE (ENCYCLOPEDIA)
Part of check fraud
WHERE IT'S CONCENTRATED
United States
IN SHORT
Exploiting float time between banks. Writing checks between accounts to create artificial balances. Detected through banking automation improvements.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #97 OF 110
Structuring (Smurfing)
LOW
SCALE (ENCYCLOPEDIA)
Part of money laundering
WHERE IT'S CONCENTRATED
Global
IN SHORT
Breaking transactions into amounts below reporting thresholds ($10K in US). Criminal offense in itself. Banks trained to detect patterns.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #98 OF 110
Sweetheart Deal
LOW
SCALE (ENCYCLOPEDIA)
Part of employee fraud
WHERE IT'S CONCENTRATED
Global
IN SHORT
Employee gives unauthorized discounts or free goods to friends/family. Retail and service industries. POS exception monitoring detects.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #99 OF 110
Warranty Fraud (Product)
LOW
SCALE (ENCYCLOPEDIA)
$200M+
WHERE IT'S CONCENTRATED
Global
IN SHORT
Filing false warranty claims for products. Returning stolen items under warranty. Manufacturing defect fraud.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #100 OF 110
Diploma / Credential Fraud
LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
Pakistan, India, Global
IN SHORT
Fake degrees, professional licenses, certifications. Diploma mills. Affects hiring, healthcare (fake doctors), professional services.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #101 OF 110
Social Media Account Hijacking
LOW
SCALE (ENCYCLOPEDIA)
Part of ATO
WHERE IT'S CONCENTRATED
Global
IN SHORT
Hacking social media accounts for resale, impersonation, or scam promotion. Crypto giveaway scams via hijacked verified accounts.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #102 OF 110
QR Code Fraud (Quishing)
LOW
SCALE (ENCYCLOPEDIA)
Emerging
WHERE IT'S CONCENTRATED
Global
IN SHORT
Malicious QR codes on parking meters, restaurant menus, flyers. Redirect to phishing or malware. Growing with QR adoption.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #103 OF 110
Valet Key Scam
LOW
SCALE (ENCYCLOPEDIA)
$10M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Valet copies car key or accesses garage door opener. Home burglary follows. Or valet steals from car. Primarily luxury areas.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #104 OF 110
Rental Scam
LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
United States, Global
IN SHORT
Listing properties for rent that the scammer doesn't own. Collecting deposits and first month rent. Craigslist/Facebook Marketplace listings.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #105 OF 110
Refund Anticipation Fraud
LOW
SCALE (ENCYCLOPEDIA)
$50M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Tax preparer fraud using refund anticipation loans. Inflated deductions, fake W-2s, identity theft for tax refunds.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #106 OF 110
Crypto Dust Attack
LOW
SCALE (ENCYCLOPEDIA)
Emerging
WHERE IT'S CONCENTRATED
Global
IN SHORT
Sending tiny crypto amounts to wallets to track transactions and de-anonymize holders. Reconnaissance for larger attacks.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #107 OF 110
Juice Jacking
LOW
SCALE (ENCYCLOPEDIA)
Emerging
WHERE IT'S CONCENTRATED
Global
IN SHORT
Compromised public USB charging stations installing malware or stealing data. Airports, hotels, cafes. FBI advisory issued.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #108 OF 110
Pig Butchering (Crypto ATM Variant)
LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
United States
IN SHORT
Scammer directs victim to crypto ATM to deposit funds. Bypasses bank fraud alerts. Growing variant. Elderly targeted.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #109 OF 110
Drop Shipping Fraud
LOW
SCALE (ENCYCLOPEDIA)
$100M+
WHERE IT'S CONCENTRATED
Global
IN SHORT
Selling items you don't own at markup. Legitimate business model exploited — fake stores, never ship, or ship counterfeits.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
METHOD #110 OF 110
Gift Card Reshipping
LOW
SCALE (ENCYCLOPEDIA)
Part of ORC
WHERE IT'S CONCENTRATED
China, United States
IN SHORT
Purchasing goods with fraudulently obtained gift cards → reshipping internationally → resale. Part of gift card draining pipeline.
IN OUR CASE FILES — MOST TAKEN TO LEAST
No case in our files uses this method yet.
Full profile (origin, governments, ranked notable cases) not researched yet for this method.
CORPORATE & INVESTOR FRAUD
Lying to investors about a company — 6 cases, highest to lowest.
CRYPTO FRAUD
Exchanges, tokens, coins and crypto theft — 9 cases, highest to lowest.
PONZI & INVESTMENT FRAUD
Fake returns paid out of new investors' money — 5 cases, highest to lowest.
STOCK FRAUD & ROGUE TRADING
Pump-and-dump, market manipulation and hidden trading losses — 6 cases, highest to lowest.
DARK WEB
Illegal online marketplaces — 3 cases, highest to lowest.
MONEY LAUNDERING & STATE FUND FRAUD
Public money diverted and laundered — 4 cases, highest to lowest.
HEALTHCARE FRAUD
Billing Medicare and insurers for care that wasn't needed or given — 3 cases, highest to lowest.
BRIBERY & CORRUPTION
Paying officials for contracts and favours — 1 case, highest to lowest.
CARD FRAUD
Stolen payment card data — 3 cases, highest to lowest.
BANK & WIRE FRAUD
Business email compromise and fraudulent wires — 4 cases, highest to lowest.
SIM SWAP FRAUD
Hijacking a phone number to take over accounts — 1 case, highest to lowest.
#1 OF 45
Jeffrey Skilling
SINGLE PERSON
CASE 046 · CORPORATE FRAUDCONVICTED
Enron · 14 years · released 2019
~$74B
WHAT WAS TAKEN
Nothing taken in cash. ~$74B is the market value Enron's shareholders lost; employees lost ~$2B of retirement money.
HOW
Enron moved debt into partnerships its balance sheet did not show and booked projected profits as earned, while telling investors the picture was sound.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1990–2001Joins Enron from McKinsey and builds its energy-trading business; president and COO from 1997, CEO from 12 Feb 2001.SOURCE: case brief; Wikipedia
2001Resigns as CEO on 14 Aug 2001; Enron discloses a $618M loss in October and files for bankruptcy on 2 Dec 2001.SOURCE: case brief
2004–2006Indicted in Houston in Feb 2004; convicted on 19 counts on 25 May 2006; sentenced to 24 years 4 months on 23 Oct 2006.SOURCE: DOJ S.D. Texas
2013–2019Resentenced in Houston to 14 years on 21 June 2013; released from a Texas halfway house on 21 Feb 2019.SOURCE: DOJ; Reuters
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
JEFFREY SKILLING
ENRON · THE FRAUD THAT NAMED THE CRIME · CASE 046 · CORPORATE FRAUD · 19 COUNTS · 24Y4M, CUT TO 14 · RELEASED 2019
MARKET VALUE LOST
~$74B — not theft
PENSIONS
~$2B of employees’ retirement money
COUNTS
19 · jury, May 25, 2006 · 9 acquitted
SENTENCE
24y4m → 14 years (2013)
FORFEITED
~$42M for victims
RELEASED
Feb 21, 2019
THREE DIFFERENT THINGS: $74B = market value destroyed. $2B = employee pension losses. Ken Lay: convicted, died before sentencing, conviction vacated by law — never “cleared”.
FULL PROFILE

IDENTITY

NAME
Jeffrey Keith Skilling
BORN
Nov 25, 1953 · Pittsburgh, Pennsylvania
COMPANY
Enron Corporation, Houston — CEO Feb–Aug 2001
BEFORE
McKinsey partner; joined Enron in 1990 to build its trading business

CASE RECORD

INDICTED
Feb 19, 2004 · S.D. Texas
CONVICTED
May 25, 2006 · 19 counts
SENTENCED
Oct 23, 2006 · 24 years 4 months · Judge Sim Lake
SUPREME COURT
June 24, 2010 · honest-services statute narrowed
RESENTENCED
June 21, 2013 · 168 months; ~$42M forfeited
RELEASED
Feb 21, 2019
KNOWN AS
Jeff Skilling
STATUS
Convicted
COURT
US District Court, Southern District of Texas (Houston)
JUDGE
Sim Lake
CHARGES
Conspiracy · Securities fraud · Wire fraud · Insider trading · False statements to auditors (19 counts)
PLEA
Not guilty — convicted by a jury on 19 counts, 25 May 2006; acquitted on 9 insider-trading counts
THE PEOPLE AROUND ENRON
THE FOUNDERVACATED
Kenneth Lay
Chairman
Convicted May 25, 2006; died July 5, 2006; conviction vacated by law on Oct 17, 2006. Not an acquittal.
SOURCE: DOJ; S.D. Texas
THE CFO6 YEARS
Andrew Fastow
Architect of the partnerships
Pleaded guilty in 2004 and testified for the government.
SOURCE: DOJ
THE AUDITORDESTROYED
Arthur Andersen
Big Five firm
Convicted of obstruction in 2002; overturned later, but the firm was gone.
SOURCE: Supreme Court 2005
THE LAWJULY 30, 2002
Sarbanes-Oxley
Congress
Enron and WorldCom produced it: CEOs now certify the accounts personally.
SOURCE: Public law 107-204
CASE TIMELINE
1990
Joins Enron
From McKinsey, to run trading.
SOURCE: Wikipedia
Feb 12, 2001
CEO
Takes over from Lay.
SOURCE: Wikipedia
Aug 14, 2001
Resigns
Lay returns.
SOURCE: Wikipedia
Dec 2, 2001
Bankrupt
Then the largest in US history.
SOURCE: Wikipedia
May 25, 2006
Guilty
19 counts; Lay convicted the same day.
SOURCE: DOJ
Oct 23, 2006
24y4m
Judge Lake.
SOURCE: DOJ
June 24, 2010
Supreme Court
Honest-services statute narrowed.
SOURCE: 561 U.S. 358
June 21, 2013
14 years
Resentenced; ~$42M forfeited.
SOURCE: DOJ
Feb 21, 2019
Released
After a Texas halfway house.
SOURCE: Reuters
HOW IT WORKED

HOW ENRON HID THE DEBT — DEFENSIVE LEVEL

01
The partnerships: Debt moved into entities the balance sheet did not consolidate
02
The accounting: Projected profits booked the day contracts were signed
03
The statements: Investors told the picture was sound
04
The warning sign: Profits nobody outside could reconstruct
HOW A BALANCE SHEET LIED
Debt moved off the books
-->
Earnings inflated
-->
Stock above $90
-->
Disclosures begin
-->
Bankruptcy

WHAT THIS CASE ESTABLISHED

A conviction vacated because the defendant died is not innocence.
Enron and WorldCom produced Sarbanes-Oxley.
Series link: Cases 024, 037, 038.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — ENRON (1,600 WORDS)
Sources: DOJ/SD Texas — indictment 2004; conviction May 25, 2006 (19 counts); sentencing October 23, 2006 (24y4m) · US Supreme Court — Skilling v. United States, 560 U.S. 358 (2010) · District court resentencing, June 21, 2013 (168 months — 14 years) · SEC civil actions · Enron bankruptcy December 2, 2001 · Bethany McLean & Peter Elkind — The Smartest Guys in the Room (2003/2005 film, definitive account). METRIC DISCIPLINE: ~$74B = market value destroyed (not theft). ~$2B = employee pension losses (different, more concrete figure). Never conflate.
· PROLOGUE ·
The Name Everyone Knows

Everyone knows the name. Fewer know what the charges were.

Enron Corporation was the seventh-largest company in the United States at its peak in 2000 — an energy trading and utilities conglomerate with revenues that made it appear to be one of the most successful businesses in the country. Its stock had risen tenfold through the 1990s. Wall Street analysts rated it a buy. Its management were celebrated as the smartest people in the room.

The charges: structures built to move debt off the balance sheet where investors could not see it, and statements to investors and analysts that the company's financial picture was sound when, per the government, the people making those statements knew it was not.

The corporate fraud category of this series had three cases before Enron was added: Ebbers (024, WorldCom), Rigas (037, Adelphia), Kozlowski (038, Tyco). Enron is the fourth and most significant — not because the mechanism was more sophisticated, but because the scale was larger, the name became a word, and the case produced the law that the entire series' compliance thesis rests on.

· PART ONE ·
What Enron Actually Did — The Mechanism

Enron's fraud had two primary components, stated plainly per the DOJ and the trial record.

The first: special-purpose entities. Enron created dozens of partnerships and SPEs — including entities known as LJM Cayman, LJM2, and the Raptors — and used them to move debt off Enron's consolidated balance sheet. The debt was real; the balance sheet did not show it. The entities were structured to appear independent while effectively being controlled by Enron. Under accounting rules of the period, if a structure was sufficiently independent, Enron could exclude it from its consolidated financial statements.

Andrew Fastow, Enron's CFO, was the architect of the SPE structure and the primary government witness at trial after pleading guilty in 2004. He was sentenced to 6 years. [SOURCE: DOJ Fastow plea; court record]

The second component: false statements. While the debt was being moved off the balance sheet and trading operations were presented as generating profits that the underlying economics did not support, Skilling, Lay, and others made public statements — to analysts, investors, and in SEC filings — that affirmed Enron's financial health. The government's case was that these statements were knowingly false.

Enron also used mark-to-market accounting — a method that allows a company to book the projected future value of a contract at the time it is signed, rather than as cash is received. Legitimately applied, this is an accepted accounting method. The government alleged that Enron used it to inflate earnings by booking projected profits from contracts whose actual economics were poor.

· PART TWO ·
The Collapse — December 2001

Jeffrey Skilling resigned as CEO on August 14, 2001 — approximately six months after taking the position — citing personal reasons. Kenneth Lay, the company's founder, returned to the CEO role. Analysts began asking harder questions. In October 2001, Enron disclosed a $618 million third-quarter loss and the unwinding of some of the SPE structures. Fastow was placed on leave.

The stock — which had traded above $90 in August 2000 — had fallen to approximately $15 by October 2001. It continued falling as each new disclosure arrived. On December 2, 2001, Enron filed for Chapter 11 bankruptcy — at the time, the largest corporate bankruptcy in US history, with assets of approximately $63 billion.

The human consequences: approximately 4,000 to 5,700 Enron employees lost their jobs, depending on how the accounting is made (the figures vary by source — verify before asserting a specific number). Many had been encouraged to hold concentrated Enron stock in their 401(k) retirement accounts — and did, because the company's leadership was saying the stock was safe. When the stock collapsed, those accounts were worthless. Employee pension losses are estimated at approximately $2 billion. [SOURCE: Enron retirement-plan litigation; Congressional testimony]

Arthur Andersen, Enron's auditor, was indicted for obstruction of justice related to the shredding of Enron documents. It was convicted in 2002. The Supreme Court later overturned the conviction — but by then Andersen had effectively ceased to exist. One of the Big Five accounting firms was destroyed.

· PART THREE ·
The Conviction and Its Stages

Skilling was indicted in 2004 in the Southern District of Texas. He was convicted on May 25, 2006 on 19 counts — including conspiracy, securities fraud, wire fraud, and a smaller number of insider trading counts. He was acquitted on nine insider-trading counts. [SOURCE: DOJ; trial record]

On October 23, 2006, Judge Simeon Lake sentenced Skilling to 24 years and 4 months in federal prison.

He appealed. In 2010, the United States Supreme Court issued a ruling in Skilling v. United States, 560 U.S. 358 (2010), that narrowed the interpretation of the 'honest services' fraud statute (18 U.S.C. § 1346). The Court held that the statute covers only bribery and kickbacks — not, as it had been more broadly applied, any breach of fiduciary duty. Skilling's honest-services conspiracy count was affected by this ruling.

On remand, the Fifth Circuit found the honest-services count error harmless as to the overall conviction — Skilling remained convicted. But the resentencing produced a reduction. On June 21, 2013, as part of a negotiated settlement in which Skilling agreed not to pursue further appeals and to forfeit approximately $42 million for the victims, Judge Lake resentenced him to 168 months — 14 years.

He was released from federal custody on February 21, 2019, after about 12 years in prison and six months in a halfway house in Texas. He served at FCI Englewood, Colorado, and later at the Federal Prison Camp in Montgomery, Alabama. [SOURCE: BOP; Reuters; Houston Chronicle]

· PART FOUR ·
Ken Lay — The Sequence Exactly

Kenneth Lay founded the company that became Enron in 1985. He was its chairman throughout, and returned as CEO after Skilling's resignation in August 2001.

He was charged separately. He was convicted on May 25, 2006 — the same day as Skilling — on 6 counts of conspiracy and fraud in the corporate fraud trial. He was separately convicted on 4 bank fraud charges in an individual trial. [SOURCE: DOJ]

He died on July 5, 2006, at his vacation home in Aspen, Colorado — of a massive heart attack. He was 64 years old. He had not yet been sentenced. His appeal had not yet been heard.

On October 17, 2006, Judge Sim Lake of the Southern District of Texas vacated Lay's conviction — not because the evidence was re-examined, and not because of any finding of innocence. The vacatur was automatic under the legal doctrine of 'abatement ab initio': in US law, when a defendant dies before exhausting appeals, the case is treated as if it never reached final judgment. The conviction is vacated, the indictment is dismissed, and any forfeiture orders are dissolved.

This means: the jury's verdict of guilty was never made final by the appellate process. It does not mean the jury was wrong. It does not mean Lay was innocent. It means he died before the case was concluded, and US law treats an unconcluded case as no case at all.

The brief for this case flags the Lay vacatur as the most commonly botched fact in Enron coverage. Coverage that describes Lay as 'cleared,' 'acquitted,' or 'found innocent' is wrong. The accurate description: convicted, died before sentencing, conviction vacated as a matter of law. That is the sequence.

· PART FIVE ·
What Enron Built — The Legal Legacy

Enron collapsed in December 2001. WorldCom collapsed in June 2002. Between them, they produced Sarbanes-Oxley — the Public Company Accounting Reform and Investor Protection Act, signed by President Bush on July 30, 2002.

Sarbanes-Oxley requires CEOs and CFOs to personally certify the accuracy of their companies' financial statements. It imposes criminal penalties for knowingly false certifications. It established the Public Company Accounting Oversight Board. It strengthened protections for whistleblowers. It mandated new audit committee independence requirements.

The series' thesis about governance — that the compliance function must be independent of the party it checks, and that the CEO must bear personal accountability for what the financial statements say — is, in large part, Sarbanes-Oxley's thesis. Sarbanes-Oxley is, in turn, Enron's thesis.

And Skilling's appeal produced a narrowing of the honest-services fraud statute that matters beyond his own case: the Supreme Court's ruling in Skilling v. United States limits how broadly the government can use the honest-services theory in future corporate fraud prosecutions. The case changed the law it was tried under, which is why the sentence dropped.

VERIFIED SOURCES
[1] DOJ / SD Texas — indictment 2004; conviction May 25, 2006 (Skilling 19 counts, Lay 6 counts); Skilling sentencing October 23, 2006 (24y4m).
[2] US Supreme Court — Skilling v. United States, 560 U.S. 358 (2010). Narrowed honest-services statute to bribery/kickbacks only.
[3] S.D. Texas — resentencing June 21, 2013 (168 months); Skilling agreed to forfeit ~$42M for victims and waive further appeals.
[4] S.D. Texas (Judge Lake) — Ken Lay vacatur, October 17, 2006. Doctrine of abatement ab initio.
[5] SEC civil actions — against Enron, Skilling, Lay, Fastow, and others.
[6] DOJ — Fastow plea agreement 2004; sentenced 6 years, testified for government.
[7] Bethany McLean & Peter Elkind — The Smartest Guys in the Room (2003 book; 2005 documentary film). Definitive secondary account.
[8] Reuters — Skilling release February 21, 2019; FPC Montgomery, Alabama.
TO VERIFY Exact conviction/acquittal count split (19 guilty of what? acquitted on what?) · Pension loss figure (~$2B most cited — verify to bankruptcy/litigation record) · Job loss figure (4,000-5,700 depending on source — state range) · Exact resentencing terms including $42M victim fund · Lay vacatur exact date and court citation
SOURCES
[1] PRIMARY — US DOJ: conviction and sentence (2006)
[2] PRIMARY — Skilling v. United States, 561 U.S. 358 (2010)
[3] PRIMARY — US DOJ: resentencing (June 21, 2013)
[4] SECONDARY — Reuters / Houston Chronicle: release (2019)
END OF REPORT
#2 OF 45
Kwon Do-hyung (Do Kwon)
SINGLE PERSON
CASE 003 · CRYPTO / ALGO STABLECOINSENTENCED
@stablekwon · crypto king · 15 years · SDNY Dec 2025
~$40B
WHAT WAS TAKEN
Nothing taken directly. It's the value of the TerraUSD and LUNA coins people held, wiped out.
HOW
Told investors TerraUSD fixed its own peg in 2021. It didn't. The coins collapsed in 2022.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2018–2022Terraform Labs' Korean base; UST and LUNA are built and promoted from here.SOURCE: US v. Kwon, 23 Cr. 151; case brief
May 2022UST breaks its peg for good and LUNA collapses; ~$40B of market value is wiped out.SOURCE: DOJ; BBC
2018Co-founds Terraform Labs, incorporated in Singapore.SOURCE: case brief
May 2021After the first depeg, tells investors the algorithm restored the peg; court documents say a trading firm was secretly buying the coin.SOURCE: court documents cited by BBC
2023Arrested at Podgorica airport travelling on false documents; held until extradition to the US.SOURCE: DOJ; AP
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: FAQX™ We mining it. · CC BY 3.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
KWON DO-HYUNG
DO KWON · @STABLEKWON · CRYPTO / ALGO STABLECOIN · CASE 003 · SENTENCED DEC 11 2025
MARKET VALUE DESTROYED
~$40B
METRIC
Market collapse — not direct theft
SENTENCE
15 years · SDNY
PLEA
Guilty Aug 2025 · wire fraud + conspiracy
JUDGE
Hon. Paul A. Engelmayer · SDNY
SENTENCING DATE
December 11, 2025
AGE AT SENTENCING
34
SOUTH KOREA
Separate proceedings — up to 40 yrs
READ THIS FIRST: $40B = estimated market value destroyed in the Terra-LUNA collapse. Nobody stole $40B from an account. LUNA and UST holders watched token value evaporate. This is market collapse, not direct theft. Two depegs: May 2021 (hidden, lie told) and May 2022 (terminal). Most coverage conflates them. This case file does not.
FULL PROFILE

IDENTITY

LEGAL NAME
Kwon Do-hyung
KNOWN AS
Do Kwon · @stablekwon · "crypto king"
NATIONALITY
South Korean
EDUCATION
Stanford University · Computer Science degree
FIRM
Terraform Labs Pte Ltd · co-founded 2018 · Singapore
PRODUCTS
TerraUSD (UST) · LUNA · Anchor Protocol (20% yield)
COMMUNITY
Lunatics — devoted online following built on founder confidence
AGE AT SENTENCING
34 years old · December 2025

CASE RECORD

CASE
US v. Kwon, 23 Cr. 151 (PAE) · SDNY
FIRST DEPEG
May 2021 · propped secretly · lie told publicly
TERMINAL COLLAPSE
May 7–12, 2022 · $40B destroyed in five days
ARREST WARRANT
South Korea Sep 2022 · Interpol Red Notice issued
ARRESTED
March 23, 2023 · Podgorica Airport, Montenegro
DOCUMENTS SEIZED
Costa Rican + Belgian passports (forged) · South Korean passport · laptops
EXTRADITED TO US
After Montenegro court proceedings — 2024
INITIAL PLEA
Not guilty · January 2025
GUILTY PLEA
August 2025 · wire fraud + conspiracy to defraud
SENTENCED
December 11, 2025 · 15 years · Judge Engelmayer
CREDIT
17 months 8 days pre-extradition (US + Montenegro)
COURT RECORD — THE JUDGE SPOKE

JUDGE ENGELMAYER — SENTENCING DEC 11 2025 — SDNY

“This was a fraud on an epic, generational scale.”
“In the history of federal prosecutions, there are few frauds that have caused as much harm as you have.”
“You chose to lie. You chose poorly.”
“You have been bitten by the crypto bug and I don't think that's changed. You must be incapacitated.”
SOURCE: Decrypt / Inner City Press courtroom reporting, December 11, 2025 · Judge compared Kwon to a cult leader who traded on victims’ trust
COURT EXHIBITS — HIS OWN WORDS

MAY 9, 2022 — AS UST COLLAPSED

“Deploying more capital — steady lads.”
@stablekwon · May 9 2022 · cited by Judge Engelmayer at sentencing as devastating to investors [SOURCE: court record]

RESPONSE TO CRITICS

“I don't debate the poor.”
@stablekwon · cited by Judge Engelmayer as emblematic of Kwon’s posture toward critics [SOURCE: Decrypt / Inner City Press]
HOW THE FRAUD WORKED

THE TWO DEPEGS — ONE LIE

01
May 2021 — First depeg (hidden): TerraUSD lost its dollar peg. A trading firm secretly purchased millions of dollars of UST to artificially restore the price. Do Kwon then publicly told investors the algorithm had fixed it. It had not. A human had bought the coin to fake the recovery. That is the fraud — not the collapse, but the lie about what caused the recovery.
02
May 2022 — Terminal collapse: Large Anchor Protocol withdrawals triggered UST falling below $1. The mint-and-burn mechanism activated — exactly as designed — but triggered a death spiral: more LUNA minted to absorb UST, LUNA price falls, mechanism value falls, more depegging, more minting. Over five days LUNA fell from $80+ to fractions of a cent. ~$40B in market value destroyed. UST never recovered.
03
The Anchor trap: Anchor Protocol offered 20% annual yield on UST deposits — when US savings accounts paid under 1%. The yield attracted ordinary retail investors who did not understand algorithmic DeFi mechanics. A man from Ukraine placed 17 years of savings — approximately $200,000 — trusting Kwon’s public assurances. [SOURCE: victim testimony at sentencing, Decrypt Dec 2025]
COLLAPSE TIMELINE — MAY 2022
May 2021
First depeg. Trading firm secretly buys UST. Kwon publicly attributes recovery to algorithm. [Court documents / BBC]
May 7–12 2022
Terminal depeg begins. Large Anchor withdrawals trigger UST falling below $1. LUNA death spiral activates.
May 9 2022
"Deploying more capital — steady lads." Posted as collapse accelerates. [Court exhibit / Decrypt]
May 12–13 2022
LUNA collapses from ~$80 (pre-collapse price, May 2022) to fractions of a cent. UST loses peg permanently. ~$40B market value destroyed. [BBC / DOJ]
Aftermath
Contagion: Celsius Network freezes withdrawals Jun 2022, bankruptcy Jul 2022. Three Arrows Capital liquidated 2022. Both tied to Terra exposure.
KNOWN ASSOCIATES
CFO · ARRESTED ALONGSIDE KWONSTATUS UNCLEAR
Han Chang-joon
Terraform Labs · Chief Financial Officer
Arrested alongside Do Kwon at Podgorica Airport, Montenegro, March 23, 2023. Both were attempting to board a flight to Dubai carrying forged documents. His subsequent legal proceedings are ongoing — status as of September 2026 is unconfirmed in available sources and is labeled accordingly.
SOURCE: Coindesk / The Block / widely documented [STATUS: UNVERIFIED beyond arrest]
CASE TIMELINE
UNDATED
Do Kwon born, South Korea
attends Stanford
SOURCE: case brief (sources listed in its SOURCES part)
2018
Co-founds Terraform Labs (Singapore)
UST + LUNA launched
SOURCE: case brief (sources listed in its SOURCES part)
May 2021
First depeg. Kwon attributes recovery to the algorithm
court docs allege a trading firm secretly bought millions to prop it up
SOURCE: case brief (sources listed in its SOURCES part)
May 2022
Terminal collapse. UST breaks and does not recover
LUNA collapses. ~$40B lost
SOURCE: case brief (sources listed in its SOURCES part)
2023
Arrested in Montenegro
SOURCE: case brief (sources listed in its SOURCES part)
2023
Indicted
US v. Kwon, 23 Cr. 151 (PAE), SDNY
SOURCE: case brief (sources listed in its SOURCES part)
Jan 2025
Pleads not guilty in US court
SOURCE: case brief (sources listed in its SOURCES part)
Aug 2025
Pleads guilty
conspiracy to defraud + wire fraud
SOURCE: case brief (sources listed in its SOURCES part)
Dec 2025
Sentenced to 15 years
Judge Engelmayer, SDNY
SOURCE: case brief (sources listed in its SOURCES part)

WHAT THIS CASE ESTABLISHED

The product was the lie. Not Do Kwon as a person, but the algorithmic stablecoin as a mechanism. When the mechanism failed, he replaced it with a buy order and told the world the machine had done it.
Two depegs, not one. May 2021 is the fraud — the lie. May 2022 is the consequence. Most coverage conflates them. This case file does not.
The Anchor 20% yield was the recruitment mechanism. It required no technical understanding — only the belief that the number was real.
A Stanford-educated CS founder describing a mechanism he had designed gave critics no platform. "I don't debate the poor" is a statement about the substitution of authority for verification.
The series argument (Part 13): 001 = the persona. 002 = the speed. 004 = the duration. 003 = the product was the lie. The code was real. The promise was not.
Judge Engelmayer: "fraud on an epic, generational scale." Prosecutors sought 12 years. Kwon sought 5. The court delivered 15 — calling it the least it could impose under the circumstances.
THE FULL STORY — 13 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — $40 BILLION. FIVE DAYS. TWO DEPEGS, ONE LIE. (3,900 WORDS)
TRACECHAIN FORENSICS · FRAUD EXPOSED SERIES · CASE 003
$40 BILLION.
The Complete Story of Do Kwon — Stanford Graduate, Self-Styled Crypto King, and the Algorithmic Stablecoin That Erased $40 Billion in Five Days
SEPTEMBER 2026
$40B Destroyed · Five Days · Two Depegs, One Lie · 15 Years — SDNY
Sources: US v. Kwon, 23 Cr. 151 (PAE), SDNY · DOJ/US Attorney SDNY press releases · SDNY sentencing record, Judge Engelmayer, December 11, 2025 · BBC (Peter Hoskins, Dec 12 2025) · AP News · Decrypt · The Block · Fortune · The Register. $40B = market value destroyed in the collapse — not direct theft. Two depegs: May 2021 (allegedly hidden) and May 2022 (terminal). Kwon is a living person, sentenced, with ongoing South Korean proceedings possible.
THE METRIC — READ THIS FIRST: $40 billion is the estimated value destroyed in the Terra-LUNA collapse. Nobody 'took $40 billion from an account.' LUNA and UST holders watched token value evaporate. This is market collapse, not direct theft — and the distinction matters. Two depegs, not one. May 2021: first depeg, allegedly propped up in secret, told publicly the algorithm fixed it. May 2022: terminal collapse, no recovery. Most coverage blurs them. This piece does not.
· PROLOGUE ·
Steady Lads

On May 9, 2022, as TerraUSD began to lose its dollar peg and the price of LUNA started the free-fall that would erase tens of billions of dollars in the coming days, Do Kwon posted on X — then Twitter.

@stablekwon (public post — court exhibit)

"Deploying more capital — steady lads."

Posted May 9, 2022, as UST began its terminal depeg. Cited by Judge Engelmayer at sentencing as devastating to investors. [SOURCE: court record / Decrypt sentencing coverage]

The message landed on hundreds of thousands of followers who had built their savings in an ecosystem he had spent years promoting as mathematically sound, self-correcting, and engineered to hold its value regardless of market conditions. The algorithm was the product. Steady lads was the assurance.

Within five days, approximately $40 billion in value had been wiped from the Terra ecosystem. [SOURCE: BBC, Dec 2025] UST never recovered its dollar peg. LUNA collapsed from its all-time high of over $100 (April 2022) to fractions of a cent. The algorithm — the thing the product was supposed to be — had failed.

And before that terminal collapse, the algorithm had already failed once. In May 2021. And when it failed that first time, Do Kwon had not told investors the algorithm had been bailed out by a trading firm secretly buying millions of dollars of the coin. He had told them the algorithm had fixed it. [SOURCE: court documents cited by BBC]

That lie — not the collapse itself, but the lie about what had caused the recovery — is the crime. The code was real. The promise was not.

He sold a mathematical promise. When the math failed, he replaced it with a buy order and told the world the machine had done it. That is the fraud.

· PART ONE ·
From Seoul to Stanford to Singapore

Kwon Do-hyung — Do Kwon, as the world knew him — grew up in South Korea and attended Stanford University, the California institution that has produced a disproportionate share of the technology industry's most significant founders, products, and failures.

He graduated with a computer science degree. The academic credentials gave him something that proved useful in the world he moved toward: the appearance of technical authority. When he described how TerraUSD worked, how the algorithm maintained the peg, how the mathematics guaranteed stability, he was not describing it as a layman speculating about what computers could do. He was describing it as a Stanford-educated computer scientist who had designed the system himself.

He co-founded Terraform Labs in 2018 and based it in Singapore — a jurisdiction with established crypto infrastructure, regulatory sophistication, and access to global capital. The firm built two linked products: TerraUSD (UST), an algorithmic stablecoin intended to hold a stable value of one US dollar, and LUNA, a companion token whose value was designed to absorb UST's volatility and maintain the peg through a mint-and-burn mechanism.

He called himself the 'crypto king.' His followers, who called themselves Lunatics, were devoted in the way that online communities devoted to a founder who speaks their language tend to be devoted — with the specific intensity of people who have bet money on the vision and need the vision to be true.

He was 34 years old when he was sentenced. [SOURCE: Decrypt, Dec 2025] He had built a multi-billion dollar ecosystem, attracted institutional investors, and established himself as one of the most prominent figures in the cryptocurrency world. He had also, according to the court that sentenced him, chosen to lie. [SOURCE: Judge Engelmayer, sentencing record]

· PART TWO ·
The Product — What UST Was Supposed to Be

A stablecoin is a cryptocurrency designed to hold a stable value — typically pegged to one US dollar. The utility is obvious: in a market where Bitcoin can move 20% in a day, an asset that reliably equals one dollar lets you hold crypto exposure without the volatility.

There are two main ways to build a stablecoin. The first is to back every token with real dollars or dollar-equivalent assets held in reserve. This works reliably — USDC and Tether operate roughly this way — but requires capital, creates counterparty risk, and places control with whoever holds the reserves.

The second way is to use an algorithm. This was UST's proposition. Instead of reserves, UST would maintain its dollar peg through a mathematical relationship with LUNA. When UST traded below a dollar, market participants could burn UST and receive LUNA at a profit — reducing UST supply and pushing the price back up. When UST traded above a dollar, participants could mint new UST by burning LUNA — increasing supply and pushing the price back down. Automatic. Decentralized. No human custodian of reserves. The code does it.

This was the product. Not just a stablecoin — an algorithmic stablecoin. A mechanism that maintained value through code rather than custody. The entire value proposition rested on the mechanism working.

The Anchor Protocol — Terra's own savings product — offered 20% annual yields on UST deposits. [SOURCE: Decrypt sentencing coverage, citing victim testimony] For context, US savings accounts in the same period offered under 1%. A man from Ukraine testified at Kwon's sentencing that he had placed 17 years of savings into the system after Kwon's assurances convinced him it was safe. [SOURCE: Decrypt, Dec 2025]

The 20% yield required that the algorithm sustain the peg. If the peg broke, the yield was fiction. If the algorithm was fiction, the peg was fiction. If the peg was fiction, 17 years of savings was fiction.

· PART THREE ·
May 2021 — The First Depeg and the Lie

In May 2021, TerraUSD lost its dollar peg for the first time.

What happened next is the core of the fraud as stated in the court documents. According to those documents, when UST fell below $1, Kwon arranged for a trading firm to secretly purchase millions of dollars of the coin to artificially restore its price. [SOURCE: BBC Peter Hoskins, Dec 12 2025, citing court documents]

Then he told investors that a computer algorithm had restored the value.

That was false.

The distinction is not subtle. The entire pitch of an algorithmic stablecoin — the reason people chose UST over a reserve-backed stablecoin — was that no human intervention was required. The code did it. That was the product. When the code failed in May 2021 and a trading firm had to step in and buy the coin to prop the price, the product had demonstrably not worked as described.

Kwon knew this. He said the algorithm had fixed it. The investors who read that, who saw the price recover, who kept their UST deposits in Anchor Protocol, who told their friends the system worked — they believed something that was not true. And they kept believing it for another year.

When the algorithm failed, he used a human to fake it — then told the world the machine had done it. That is the moment the product became a lie, and telling it is the crime.

· PART FOUR ·
"I Don't Debate the Poor" — The Persona

Do Kwon had an online presence that Judge Engelmayer would later characterise — from the bench at sentencing — as that of a cult leader who traded on victims' trust. [SOURCE: Decrypt sentencing coverage, Dec 2025]

The characterisation was not invented by the judge. It was observable from the public record of Kwon's own posts.

@stablekwon (public post — court exhibit)

"I don't debate the poor."

Posted publicly on X. Cited by Judge Engelmayer at sentencing as emblematic of Kwon's posture toward critics. [SOURCE: Decrypt / Inner City Press sentencing coverage]

Critics who raised technical concerns about the stability of the UST-LUNA mechanism — and there were credible ones, documented publicly — were often dismissed, mocked, or ignored. Kwon's confidence was absolute and performed. The community around Terra reflected that confidence. The Lunatics believed because their leader believed, and their leader communicated belief with the specific certainty of someone who had either done the mathematics or decided the mathematics could be safely ignored.

The Anchor Protocol's 20% yield attracted retail investors who would not normally have engaged with algorithmic DeFi products. It attracted them because 20% is a number that needs no technical explanation. 20% sounds real regardless of whether the mechanism that produces it is real.

Kwon promoted the ecosystem constantly. He promoted it on Twitter. He promoted it in interviews. He promoted it to institutional investors, to retail depositors, to the Korean community that had adopted Terra with particular enthusiasm. The persona was the marketing. The marketing was the confidence. The confidence was, in the end, a lie about what the algorithm had done in May 2021.

· PART FIVE ·
May 2022 — Five Days, $40 Billion

The terminal collapse began in the first week of May 2022.

Large withdrawals from the Anchor Protocol began. UST started trading below its dollar peg. The mint-and-burn mechanism activated — exactly as designed — but the scale of the depegging triggered a dynamic that the algorithm was not built to handle: as LUNA was minted to absorb UST's excess supply, LUNA's price fell, which reduced the value of the mechanism that was supposed to restore the peg, which caused more depegging, which required more LUNA to be minted, which further reduced LUNA's value.

It was a death spiral. Not a bug — a structural vulnerability in the design that critics had identified publicly before the collapse. The faster the algorithm tried to fix the peg, the faster it destroyed the value of the mechanism doing the fixing.

Steady lads was posted into this.

Over five days, LUNA fell from approximately $80 (its pre-collapse trading price in early May 2022) to fractions of a cent. UST broke and did not recover. Approximately $40 billion in market value was destroyed. [SOURCE: BBC; DOJ/SDNY] The figure is market value lost — the aggregate decline in the value of tokens people held. It is not a theft figure. Nobody took $40 billion from an account. But the people holding UST because they believed a dollar would always be a dollar, and the people holding LUNA because the ecosystem had always recovered, watched the numbers go to near zero and did not get them back.

TIMELINE OF COLLAPSE
DETAIL / SOURCE
May 2021

First depeg. Trading firm secretly buys UST to prop price. Kwon publicly attributes recovery to the algorithm. [Court documents / BBC]

May 7–12, 2022

Terminal depeg begins. Large Anchor withdrawals trigger UST falling below $1. LUNA death spiral activates.

May 9, 2022

'Deploying more capital — steady lads.' Posted to Twitter as the collapse accelerates. [Court exhibit / Decrypt]

May 12–13, 2022

LUNA collapses from ~$80 (pre-collapse price, May 2022) to fractions of a cent. UST loses peg permanently. ~$40B in market value destroyed. [BBC / DOJ]

Aftermath

Terra's collapse triggers contagion across the crypto market. Several other firms including Celsius and Three Arrows Capital subsequently fail in part due to Terra exposure.

· PART SIX ·
The Flight — Fake Passports in Montenegro

After the collapse, Do Kwon went on the run.

He denied it publicly. Asked in interviews whether he was hiding, he said he was not. He maintained that he was cooperating with authorities, that the collapse was a market event rather than a fraud, that the code had done what it was designed to do. South Korean authorities disagreed. In September 2022, they issued an arrest warrant. Interpol issued a Red Notice — the international alert used for wanted fugitives. [SOURCE: Interpol / widely documented]

South Korean prosecutors believed he was in Serbia, which had no extradition treaty with South Korea. Montenegro, which borders Serbia, has dramatic coastline and mountains and, according to reporting at the time, a politician with whom Kwon had a long-standing association and whose campaigns he may have funded. [SOURCE: Fortune, June 2023 — cited as allegation from reporting] Whether Montenegro felt like a safe harbour or simply the next stop on a route, he ended up there.

On March 23, 2023, Kwon attempted to board a flight at Podgorica Airport — Montenegro's capital — bound for Dubai. He was carrying a Costa Rican passport. Montenegro police detained him. His identity was confirmed through photographic and biometric data. Also found in his luggage: Belgian passports, a South Korean passport, laptop computers, and other devices. [SOURCE: Coindesk / The Block / widely documented from police statement]

Han Chang-joon, Terraform Labs' former chief financial officer, was arrested alongside him.

Kwon told the Montenegrin court that he had acquired the Costa Rican passport through a legitimate agency in Singapore, recommended by a friend. He acquired the Belgian passport through another agency. A Montenegro court sentenced him to four months for using forged documents — time he had already largely served in pretrial detention. [SOURCE: The Register, June 2023; widely documented] The extradition battle between South Korea and the United States took longer.

The US won. Kwon arrived in American custody and appeared before Judge Paul A. Engelmayer in the Southern District of New York. In January 2025 he pleaded not guilty. In August 2025 he changed his plea — guilty to wire fraud and conspiracy to defraud. [SOURCE: DOJ/SDNY; Reuters]

· PART SEVEN ·
The Courtroom — What the Judge Said

On December 11, 2025, Do Kwon stood before Judge Paul A. Engelmayer in a Manhattan courtroom wearing a yellow prison jumpsuit. He was 34 years old.

The victims spoke first. A man from Ukraine described losing nearly $200,000 — seventeen years of savings — after Kwon's public assurances had convinced him that the system was safe. He had invested through Anchor Protocol, attracted by the 20% annual yield, trusting the man who had told him and hundreds of thousands of others that the algorithm held. [SOURCE: Decrypt sentencing coverage, Dec 2025]

Then the judge spoke.

JUDGE ENGELMAYER — FROM THE BENCH: "This was a fraud on an epic, generational scale."

"In the history of federal prosecutions, there are few frauds that have caused as much harm as you have."

"You chose to lie." — "You chose poorly."

"You have been bitten by the crypto bug and I don't think that's changed. You must be incapacitated."

The judge compared Kwon to the leader of a cult, who traded on victims' trust.

He described the $40B figure as 'eye-popping,' even for the Southern District of New York, where some of the largest financial crimes in history have been prosecuted.

SOURCE: Decrypt / Inner City Press courtroom reporting, December 11, 2025

Engelmayer described Kwon's famous tweets — 'Deploying more capital — steady lads' and 'I don't debate the poor' — as devastating to investors and emblematic of the posture that had made the fraud possible. He compared Kwon to a cult leader not as a rhetorical flourish but as a characterisation of how the scheme had functioned: by substituting the leader's authority for the independent verification that might have revealed the product's failure.

Prosecutors had sought 12 years. Kwon's lawyers had sought 5 years. Kwon himself, in written submissions, had deemed 5 years a fair punishment. [SOURCE: Forklog / The Block, Dec 2025]

Kwon addressed the court.

DO KWON — TO THE COURT: "I have spent almost every waking moment of the last few years thinking of what I could have done different and what I can do now to make things right."
SOURCE: Brief citing court record; BBC Dec 12 2025

Judge Engelmayer acknowledged the letter Kwon had written to the court, noting it was 'beautifully written, for your daughter one day.' He gave credit for 17 months and 8 days served in pre-extradition custody. He stated that 15 years was the least he could impose under the circumstances. And he delivered it.

THE SENTENCE — DECEMBER 11, 2025

15 YEARS

US District Court · Southern District of New York · Judge Paul A. Engelmayer

Credit: 17 months and 8 days served pre-extradition (US + Montenegro)

South Korea, separately, faces Kwon with proceedings that could produce a sentence of up to 40 years. The Manhattan sentence does not preclude further accountability in his home country. [SOURCE: Sharpe.ai aggregating Korean Times reporting, Dec 2025]

· PART NINE ·
Who Lost — The Scale of the Wreckage

The Ukraine victim is one person. There were hundreds of thousands.

Terra's ecosystem was estimated to have drawn in well over a million users across the Anchor

Protocol and the wider Terra applications before the collapse. The number of individual holders

of UST and LUNA ran into the hundreds of thousands. When both tokens went to near zero, every

one of them was holding a claim on value that no longer existed.

The geographic concentration was not uniform. South Korea, Kwon's home country, had adopted

Terra with particular enthusiasm — the community was large, vocal, and heavily invested. After

the May 2022 collapse, reporting from Korea documented a surge in distress, including a

documented spike in calls to suicide-prevention services and multiple suicides attributed by

local media to the losses. [SOURCE: Korean media reporting, 2022 — verify before publication]

That is the part the numbers hide. A 20% yield, marketed to people who had never touched

decentralised finance, promising a dollar that would always be a dollar — and behind it, a

mechanism that could not hold. The people who trusted it were not sophisticated arbitrageurs.

They were the ordinary end of the market, attracted by a number they understood.

· PART TEN ·
The Anchor Trap — 20% and the Mathematics of Doom

Anchor Protocol was Terra's own savings product. It offered approximately 20% annual yield on

UST deposits — in a period when US savings accounts paid under 1%. [SOURCE: Decrypt; court

testimony]

That single number is the reason the scheme grew as fast as it did. A 20% return needs no

technical explanation. It does not require the depositor to understand mint-and-burn mechanics,

algorithmic peg restoration, or the difference between a reserve-backed stablecoin and a

synthetic one. It requires only the belief that the number is real — and the authority of the

man saying it.

The mathematics, however, were always against it. The yield had to come from somewhere. In

Anchor's design, it was subsidised — meaning it was paid from capital that had to keep arriving.

A 20% rate paid from fresh deposits is, structurally, a Ponzi-shaped obligation regardless of

whether anyone intends a fraud: it works exactly as long as inflows exceed the cost of the

yield, and stops the moment they do not.

In May 2022, inflows reversed. The largest withdrawals in Anchor's history began. That is the

trigger — not a hack, not a bug, but depositors doing what depositors do when confidence shifts.

· PART ELEVEN ·
The Contagion — One Collapse, an Industry Broken

Terra did not fall alone.

The $40 billion destroyed inside the Terra ecosystem was the headline. The secondary damage was

larger and harder to price. Firms that held Terra exposure, or that had borrowed against it, or

that had built strategies around its yield, failed in the months that followed:

Celsius Network — the crypto lender — froze withdrawals in June 2022 and filed for bankruptcy

in July 2022. Its collapse is directly tied to the post-Terra credit contraction. Its founder,

, later pleaded guilty to fraud in a separate case.

Three Arrows Capital (3AC) — one of the largest crypto hedge funds — collapsed into

liquidation in 2022, having held substantial LUNA exposure.

A wave of smaller lenders, funds, and projects followed through 2022, each failure

compounding the next as the credit that had flowed freely in the bull market reversed.

The chain reaction matters to the story because it reframes the scale. Terra's own collapse was

a $40 billion event. The industry damage it set off was larger — and it happened because tens of

thousands of market participants had treated an algorithmic promise as a foundation. One broken

product, used as an assumption by an entire sector, collapsed a chain no single fraudster

controlled.

· PART TWELVE ·
The Warnings Nobody Read

The mechanism that destroyed Terra was not discovered in May 2022. It was described publicly,

in technical terms, by critics long before the collapse.

The core objection was always the same, and it was correct: the design worked only while LUNA

had value. In a depeg, the protocol would mint LUNA to absorb excess UST supply — but minting

LUNA dilutes it, which lowers its price, which reduces the value of the mechanism meant to

restore the peg, which causes more depegging, which requires more LUNA. The death spiral was

not an unforeseen failure. It was the design's predictable end state, articulated by critics

before the token was ever large.

Those critics were dismissed. Kwon's own public posture — "I don't debate the poor" — was a

statement not about poverty but about the refusal to engage. Technical challenges were met with

the founder's confidence rather than with independent verification. The community around Terra

adopted the founder's certainty as its own.

The parallel to is exact in structure, if opposite in scale. In Madoff, a whistleblower

spent eight years telling the regulator the numbers were impossible, and the warning did not

land before the collapse. In Terra, the warning was public, technical, and repeated — and it was

mocked. In both cases, the failure was not that nobody knew. It was that the knowing was not

enough against a founder's authority.

· PART THIRTEEN ·
The Series Argument — The Product Was the Lie

Each case in this series is built on a thesis.

(): the persona was the marketing. A crafted identity, sold so convincingly

that the fraud was invisible inside it.

(): the speed. Twenty years old, caught within a month, because the spending

was louder than the theft.

(Madoff): the duration. Forty-eight years, built on the trust of a name nobody thought

to question.

Case 003 (Do Kwon): the product was the lie. The others sold themselves. He sold a mechanism —

an algorithmic stablecoin that was advertised to work by mathematics, with no human in the loop.

When the machine failed in May 2021, a human bought the coin to fake the recovery, and he told

the world the machine had done it. That is the fraud, and it is the whole fraud.

The code was real. The promise was not.

END OF REPORT
#3 OF 45
Bernard Lawrence Madoff
SINGLE PERSON
CASE 004 · PONZIDIED IN CUSTODY
Bernie Madoff · 150 years · died Apr 14 2021
~$17B
WHAT WAS TAKEN
Investors' cash: the savings people handed him and never got back.
HOW
Paid old investors with new investors' money for decades. The trades on their statements never happened.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1960Founds Bernard L. Madoff Investment Securities in New York.SOURCE: SDNY sentencing record
1990s–2008Runs the investment-advisory Ponzi scheme from the 17th floor of the Lipstick Building; ~4,800 client accounts by Nov 2008.SOURCE: DOJ; SEC
11 Dec 2008Arrested at his Manhattan apartment after confessing to his sons.SOURCE: FBI; DOJ
1983–2008Madoff Securities International, the London office, used to move money between the scheme and the family; wound up after the arrest.SOURCE: SFO; UK administrators' reports
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: U.S. Department of Justice · Public domain · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
BERNARD LAWRENCE MADOFF
BERNIE MADOFF · PONZI SCHEME · CASE 004 · CONVICTED 2009 · DIED IN CUSTODY 2021
FABRICATED VALUE
$64.8B
PRINCIPAL LOST
~$17B
FORFEITURE ORDERED
$170.8B
SENTENCE
150 years
DURATION
48 years
STATUS
Died in custody Apr 14 2021
BORN
April 29, 1938 · Queens, NY
ACCOUNTS
~4,800 client accounts
THREE FIGURES — THREE MEANINGS: $64.8B = fabricated statement value · $17B = principal lost (Picard trustee) · $170.8B = forfeiture ordered (not restitution). These are not the same number.
FULL PROFILE

IDENTITY

LEGAL NAME
Bernard Lawrence Madoff
BORN
April 29, 1938 · Queens, New York
DIED
April 14, 2021 · Federal Medical Center, Butner, NC · Age 82
CAUSE OF DEATH
Hypertension · heart and kidney disease
FIRM
Bernard L. Madoff Investment Securities LLC · founded 1960
LEGITIMATE ROLE
Market maker · former NASDAQ chairman
FRAUD VEHICLE
Investment advisory business · split-strike conversion (fabricated)
COVER STORY
Consistent market-beating returns via legitimate options strategy

CASE RECORD

SCHEME BEGAN
Approximately 1970s (DiPascali testimony) — Madoff claimed 1990s
ARRESTED
December 11, 2008 · New York apartment
TURNED IN BY
His sons Mark and Andrew Madoff
JURISDICTION
US District Court · SDNY
JUDGE
Hon. Denny Chin
PLEA
Guilty · March 12, 2009 · 11 felony counts
CHARGES
Securities fraud · investment adviser fraud · mail fraud · wire fraud · money laundering · perjury · false SEC filings
SENTENCED
June 29, 2009 · 150 years (maximum)
TRUSTEE
Irving Picard (SIPC) — ongoing victim recovery
KNOWN NETWORK & CO-CONSPIRATORS
CFO · FRAUD FOREMANDIED BEFORE SENTENCING
Frank DiPascali Jr.
Director of options trading · CFO · born Queens NY 1956
Madoff's right-hand man and the operational engine of the fraud. Pleaded guilty 2009 to 10 felony counts. Cooperated extensively with prosecutors — testified for two weeks at the 2014 trial of five employees, describing in detail how the fraud ran. Told investigators the fraud dated to the 1970s — earlier than Madoff claimed. Died of lung cancer May 7, 2015 before sentencing.
SOURCE: SDNY · FBI case file · Wikipedia / DiPascali
BROTHER · CHIEF COMPLIANCE OFFICERSENTENCED — 10 YEARS
Peter Madoff
Senior managing director · chief compliance officer
Bernard's younger brother, serving as the firm's compliance chief — the person theoretically responsible for catching exactly this kind of fraud. Pleaded guilty 2012 to falsifying records and conspiracy to commit securities fraud. Sentenced to 10 years. His role was the appearance of compliance, not its substance.
SOURCE: US v. Peter Madoff, S7 10 Cr. 228 (LTS), SDNY
FIVE EMPLOYEES · 2014 TRIALALL CONVICTED
Bongiorno · Bonventre · Crupi · O'Hara · Perez
Secretary · operations director · account manager · two computer programmers
Annette Bongiorno (secretary), Daniel Bonventre (director of operations), JoAnn Crupi (account manager), Jerome O'Hara and George Perez (computer programmers). Convicted at the first criminal trial arising from the scheme — March 2014, after a six-month trial. All five convicted on all counts of conspiracy and fraud.
SOURCE: SDNY · NBC News · Fox News trial coverage
AUDITOR · FAILURE OF OVERSIGHTPLEADED GUILTY
David Friehling
Friehling & Horowitz CPA · sole auditor of multi-billion operation
The auditor of a multi-billion dollar investment advisory operation was a small, obscure two-person firm. Friehling pleaded guilty in 2009 — he maintained he did not know of the Ponzi scheme, which was itself an indictment: he had certified records he never examined. Sentenced in 2015 to one year of home detention for his cooperation.
SOURCE: SDNY · CourtDocket · Ethics Reporter
WHISTLEBLOWER · NEVER HEARD IN TIMEVINDICATED
Harry Markopolos
Financial fraud examiner · Boston · warned SEC from 1999
Identified the fraud in 1999 — four hours with the numbers. Submitted formal complaints to the SEC in 2000, 2001, 2005 (titled "The World's Largest Hedge Fund Is a Fraud"), and further. The SEC investigated and found nothing — multiple times over eight years. Markopolos continued warning. The scheme ran eight more years after his first submission. When it collapsed it was not because of the SEC. It was because of the financial crisis.
SOURCE: Markopolos Congressional testimony · SEC record · public record
SONS · REPORTED THEIR FATHERBOTH DECEASED
Mark Madoff & Andrew Madoff
Mark (1964–2010) · Andrew (1966–2014)
Both worked in the legitimate trading operation, separated from the fraud. On December 10, 2008, their father told them the advisory business was "one big lie." They called their attorney that night. The next morning they turned him in to federal authorities. Neither was charged. Mark died by suicide December 11, 2010 — exactly two years after his father's arrest. Andrew died September 3, 2014 from mantle cell lymphoma diagnosed in 2003.
SOURCE: DOJ · public record · widely documented
HOW THE FRAUD WORKED

PONZI MECHANISM — THREE STEPS

01
The cover strategy: Madoff described a legitimate options technique called the split-strike conversion — buying large-cap stocks, selling call options above price, buying put options below. It is a real strategy that produces modest, consistent, low-volatility returns. He used it as a story. He never executed it.
02
The fabrication: DiPascali and back-office staff generated fake account statements showing the strategy working. The seventeenth floor of the Madoff building existed to produce paper — trade confirmations, account statements, tax documents — for positions that were never opened. No trading occurred for at least 13 years, per court-appointed trustee findings.
03
The payment: Withdrawals were paid from new investor deposits — the fundamental Ponzi mechanic. As long as inflows exceeded outflows the scheme survived. The mathematics are simple: it ends when it cannot pay withdrawals from new money. The 2008 financial crisis produced $7 billion in redemption requests the scheme could not meet.
RED FLAGS THAT WERE NOT READ AS FLAGS
Returns too consistent
Markets do not move that smoothly — but consistency is not alarming when you trust the reporter
Tiny auditor
A two-person CPA firm auditing a multi-billion operation — any institution that looked it up could find this
Strategy unverifiable
Described in general terms, never in enough detail for outsiders to independently verify
SEC warned 8 years
Markopolos submitted formal mathematical proof — the regulator investigated and did not find it
Exclusivity as signal
Madoff turned people away — which made being accepted seem like proof of the operation's quality
CASE TIMELINE
29 Apr 1938
Born, Queens, NY
SOURCE: case brief (sources listed in its SOURCES part)
1960
Founds Bernard L. Madoff Investment Securities LLC
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Rises to Nasdaq chairman
SOURCE: case brief (sources listed in its SOURCES part)
30 Nov 2008
Snapshot date for the 4,800 client accounts ($64.8B figure)
SOURCE: case brief (sources listed in its SOURCES part)
11 Dec 2008
Arrested
alerted by his sons
SOURCE: case brief (sources listed in its SOURCES part)
12 Mar 2009
Pleads guilty to 11 federal crimes
SOURCE: case brief (sources listed in its SOURCES part)
29 Jun 2009
Sentenced 150 years ($170.8B forfeiture ordered 26 Jun)
SOURCE: case brief (sources listed in its SOURCES part)
11 Dec 2010
Mark Madoff dies by suicide
exactly two years after the arrest
SOURCE: case brief (sources listed in its SOURCES part)
2021
Bernie Madoff dies in prison
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Peter Madoff sentenced to 10 years
SOURCE: case brief (sources listed in its SOURCES part)

WHAT THIS CASE ESTABLISHED

The largest Ponzi scheme in history ran for approximately 48 years — inside a legitimate firm, by a NASDAQ chairman, in plain sight of regulators.
Duration was the disguise. Every year the scheme survived added credibility. Trust compounded the way the returns claimed to.
The SEC was warned formally, in writing, with mathematical proof, eight years before the collapse. It did not act in time. The Dodd-Frank whistleblower program was a direct legislative response.
Exclusivity was weaponised — being turned away made acceptance more desirable. The scheme recruited through scarcity, not salesmanship.
The arrest came not from regulators but from his own sons, who turned him in twelve hours after he confessed to them.
The three-case series argument: () — the persona. () — the speed. Case 004 (Madoff) — the duration. How long you can sustain fraud depends less on method than on the trust you have built and the institutions that fail to check it.
THE FULL STORY — 9 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — 48 YEARS. NOBODY ASKED. (3,800 WORDS)
Sources: US v. Bernard L. Madoff, 09 Cr. 213 (DC), SDNY · SEC Press Release 2008-293 · SDNY Sentencing, June 29, 2009 · DOJ · Bureau of Prisons · Associated Press · Wikipedia (aggregator — claims verified to primary where possible). Figures labelled by what they measure. Three different numbers, three different meanings — see Part 3.
· PROLOGUE ·
The Man Nobody Questioned

For 48 years, nobody asked the question that would have ended it.

The question was simple enough. The returns Bernie Madoff reported — steady, consistent, market-defying — should have attracted scrutiny from the first year they appeared implausible. Instead they attracted more investors. The more consistent the returns, the more people wanted in. The more people who wanted in, the more legitimate the operation appeared to those who were already there. Trust compounded the way the returns claimed to.

Bernard Lawrence Madoff founded his investment firm in 1960. He was arrested on December 11, 2008. In between: 48 years of fabricated account statements, approximately 4,800 client accounts showing $64.8 billion that did not exist, and a reputation so solid that when a whistleblower told the SEC what he had found, the regulator did not act in time to prevent the collapse. [SOURCE: SEC Press Release 2008-293; SDNY]

When the scheme finally ended, it ended not because regulators caught it, not because an investigator broke it, but because the 2008 financial crisis forced redemption demands that exceeded what the scheme could pay. And even then, the arrest came not from outside — it came from his own sons.

· PART ONE ·
Queens, 1938 — The Self-Made Man

Bernard Lawrence Madoff was born on April 29, 1938, in Queens, New York.

He was not born into money. He was not a legacy admission at a white-shoe firm. He did not inherit a seat on any exchange. The Madoff story — the one he told and the one that made him — was the story of a man who built something from nothing, who understood the markets before the markets understood themselves, who earned every credential through intelligence and application and relentless, patient work.

He founded Bernard L. Madoff Investment Securities LLC in 1960 with $5,000 he had saved from working as a lifeguard and a sprinkler installer — as Madoff himself described it and as widely repeated in the federal record. [SOURCE: Madoff's own account; widely reported in federal record commentary] He was twenty-two years old.

He built the firm into a legitimate force. Madoff Investment Securities became a market maker — a firm that stood ready to buy and sell securities, providing liquidity to the market, operating in the space between the buyer and seller that most people never think about. The firm was real. The market making operation was real. The trades were real.

And Bernie Madoff became, through decades of legitimate operation, one of the most respected figures on Wall Street. He served as chairman of Nasdaq — the electronic stock exchange — a position that placed him at the very centre of the American financial system's infrastructure. When regulators sought industry input on market structure, Madoff was the kind of person they called.

This is the detail that makes everything else possible: he was not an outsider running a scam. He was an insider, fully embedded in the system, trusted by the system, decorated by the system. The fraud did not fool Wall Street from outside. It ran in Wall Street, wearing Wall Street's own credentials.

· PART TWO ·
The Operation — What He Was Actually Doing

The investment advisory side of the business was the fraud. Not the market making. Not the trading operation. A separate function, kept deliberately apart, in which Madoff accepted money from clients and promised to invest it using a strategy he called the split-strike conversion.

The split-strike conversion is a real options strategy. It involves buying a basket of large-cap stocks while simultaneously selling call options above the current price and buying put options below it, limiting both the upside and the downside. It is a legitimate technique that produces modest, consistent returns with reduced volatility.

Madoff used it as a story. He never executed the strategy. He never bought the stocks. He never executed the options. He simply described the strategy, fabricated the account statements showing it working, and paid withdrawals from new investor deposits. [SOURCE: US v. Madoff, 09 Cr. 213 (DC) — guilty plea; SDNY]

The mechanism of a Ponzi scheme is precisely this simple:

The scheme survived for reasons that are, in retrospect, a catalogue of institutional failure. The returns were too consistent — markets do not move that smoothly — but consistency is not alarming when you trust the person reporting it. The strategy was described but never independently verified. The auditor was a tiny, obscure firm, not the Big Four accountant a firm of this scale should have used. [SOURCE: SEC / DOJ record] These were all flags. They were not read as flags.

· PART THREE ·
The Family in the Firm

The compliance officer was his brother.

Peter Madoff — Bernard's younger brother — served as senior managing director and chief compliance officer of Bernard L. Madoff Investment Securities. The chief compliance officer is, in theory, the internal guard. The person whose job is to ensure the firm follows the law. The check on the founder. [SOURCE: US v. Peter Madoff, S7 10 Cr. 228 (LTS), SDNY]

In this firm, the check on the founder was the founder's brother. The result was not compliance — it was the appearance of compliance, maintained by the same family loyalty that ran everything else in the operation.

Peter Madoff pleaded guilty and was sentenced to 10 years in federal prison. [SOURCE: SDNY]

Shana Madoff — Peter's daughter, Bernard's niece — served as the firm's rules and compliance attorney. She has maintained that she had no knowledge of the fraud.

Mark Madoff and Andrew Madoff — Bernard's sons — both worked at the firm in the legitimate trading business, separated from the investment advisory operation their father ran. On December 10, 2008, their father told them the investment advisory business was 'one big lie.' They went home. The next morning, December 11, 2008, they called their attorney and turned their father in to federal authorities. [SOURCE: DOJ; widely reported from federal record]

The sons did not know. When they found out, they reported him. They spent the years that followed living under the weight of a name they shared with the man who had built one of the largest frauds in history, and who had been exposed by them.

· PART FOUR ·
The Victims — Who He Took From

The 4,800 client accounts held a combined $64.8 billion in fabricated value as of November 30, 2008. That number — $64.8 billion — is the prosecutors' estimate of the fraud. [SOURCE: SDNY prosecutors, cited in sentencing] It is the number in the account statements. It is not what investors actually lost.

The actual principal lost — money that went in and did not come back — was approximately $17 billion, based on the Irving Picard trustee's calculations. [SOURCE: SIPC / Trustee record] Some investors had already withdrawn more than they put in, having received years of fake returns that came from other investors' deposits. Those investors made money — from other victims. The moral accounting is not clean.

The victims were not all institutions. They were not all sophisticated investors who should have known better. Many were retirees, charitable foundations, and individuals who had trusted Madoff with their savings over decades. Jewish communities in particular were heavily targeted — Madoff operated extensively within Jewish philanthropic and social circles, which gave the scheme a warm referral network built on community trust. [SOURCE: DOJ / widely documented in federal record commentary]

The charities that lost money did not simply lose returns. They lost principal. Some could not make grant payments. Some closed. The damage ran downstream from the account statements into hospitals that did not get funded, scholarships that were not awarded, organisations that had built their endowments over decades and discovered those endowments were fiction.

Forfeiture ordered: $170.8 billion. [SOURCE: SDNY preliminary forfeiture order, June 26, 2009] This is a legal figure: what prosecutors said flowed through the scheme's main account. It is not restitution and not assets he held. It is not the same as the fabricated account value or the actual principal lost. Three numbers, three meanings.

· PART FIVE ·
Harry Markopolos — The Man Who Knew

In 1999, a financial analyst named Harry Markopolos was asked by his employer to reverse-engineer Bernie Madoff's investment strategy. His employer wanted to replicate the returns.

Markopolos looked at the numbers for — by his own account, in Congressional testimony — four hours, and determined they were mathematically impossible. [SOURCE: Markopolos Congressional testimony; widely documented from public record] The consistency of the returns, the strategy as described, the market conditions during the periods in question — they did not add up. He concluded that Madoff was either front-running — trading on advance knowledge of customer orders — or running a Ponzi scheme. [SOURCE: Markopolos testimony; widely documented]

He went to the SEC. In 2000. He told them what he had found. He submitted a formal complaint in 2005 entitled 'The World's Largest Hedge Fund Is a Fraud' — naming Madoff directly, providing the mathematical analysis, explaining exactly what the numbers showed. [SOURCE: widely documented from SEC record]

The SEC investigated. They did not find the fraud.

They investigated again. They did not find the fraud.

Markopolos continued warning. The SEC continued not finding. By 2008, he had submitted his findings multiple times over eight years. The regulator charged with protecting investors from exactly this kind of fraud had been told, explicitly, in writing, with the mathematics laid out, that the largest Ponzi scheme in history was operating on their watch.

The scheme collapsed anyway. Not because of the SEC. Because of the financial crisis.

· PART SIX ·
The Collapse — December 2008

The 2008 financial crisis was the specific event that ended it.

As markets collapsed in the autumn of 2008, investors everywhere needed cash. The redemption requests that came into Bernard L. Madoff Investment Securities in November and December 2008 were approximately $7 billion — more than the scheme had available to pay. [SOURCE: widely documented from SDNY record] For 48 years, inflows had exceeded or matched outflows. Now they did not. The mathematics of a Ponzi scheme are simple: it ends when it cannot pay withdrawals from new deposits.

Madoff confessed to his sons on December 10, 2008. He told them the investment advisory business was a fraud. He said he intended to surrender to authorities in a week, after distributing approximately $300 million in remaining assets to employees, family, and select investors. [SOURCE: DOJ record / federal complaint]

His sons did not wait a week. They called their attorney that night. The next morning — December 11, 2008 — federal agents arrested Bernard Madoff at his New York apartment. He did not resist. He said he knew why they were there.

The arrest was quiet. Forty-eight years of the largest Ponzi scheme in history ended with a door opening and federal agents standing in a hallway.

· PART SEVEN ·
The Human Cost

The numbers are easier to state than what happened to the people.

On December 11, 2010 — exactly two years to the day after his father's arrest — Mark Madoff died by suicide. He was 46 years old. He had cooperated with authorities. He had turned his father in. He spent the two years following the arrest under public scrutiny, named in civil lawsuits as a consequence of bearing the Madoff name, separated from his family by the weight of what the name now meant. [SOURCE: widely documented from public record]

Andrew Madoff, Bernard's younger son, was diagnosed with mantle cell lymphoma in 2003 — before the arrest. He died on September 3, 2014, from that disease. He was 48 years old. Like his brother, he had turned his father in. He lived to see his father imprisoned but not to see the full legal proceedings conclude. [SOURCE: public record; widely documented]

Peter Madoff — the brother, the chief compliance officer — was sentenced to 10 years in federal prison. He cooperated with investigators. His daughter Shana, the compliance attorney, was not charged.

Ruth Madoff, Bernard's wife of 49 years, was not charged. She initially attempted to keep $70 million in assets. Under a settlement with prosecutors, she was permitted to keep $2.5 million. She has lived under the Madoff name since. [SOURCE: DOJ / SEC record]

The investors — the charities, the retirees, the foundations — rebuilt where they could and did not where they could not. The Irving Picard trustee appointed to recover assets eventually distributed billions to victims over more than a decade of litigation. The accounting is ongoing.

· PART EIGHT ·
The Sentence — 150 Years

On June 29, 2009, Judge Denny Chin sentenced Bernard Lawrence Madoff to 150 years in federal prison.

It was the maximum. Prosecutors had asked for it. The victims who spoke at sentencing had asked for it. Judge Chin delivered it.

In the sentencing, Chin noted that the crimes were 'extraordinarily evil,' that Madoff had 'coldly and deliberately hurt thousands of people,' and that a severe sentence was required both for punishment and to send a message about the seriousness of financial fraud at this scale. [SOURCE: SDNY sentencing record, June 29, 2009]

Madoff spoke at sentencing. He apologised. He said he had lived for decades in fear and torment, that the pressure had been 'unbearable,' that he would live with the regret for the rest of his life. Whether any of this was true or performed, the victims present had no obligation to receive it as true, and most did not.

He was 71 years old at sentencing. The 150-year term was symbolic in the way that only mathematics makes something symbolic — he would serve the rest of his natural life regardless of the specific number. But the number mattered to the victims, who needed the court to say, in the language courts speak, that what had been done to them was of a scale and a deliberateness that required the maximum the law allowed.

He was housed at the Federal Medical Center in Butner, North Carolina — a facility for inmates with serious medical conditions. In 2020, his attorney requested compassionate release, stating that Madoff suffered from end-stage renal disease and other chronic conditions and had less than 18 months to live. The request was denied. Judge Chin noted that the criminal conduct went on for decades and he was caught only because the scheme unravelled — not because he stopped. [SOURCE: AP / Bureau of Prisons; court denial record]

· PART NINE ·
What It Meant — Duration as Disguise

The series argument sharpens here. and were both about visibility — the compulsion to display the crime, to have an audience for it, to post it, stream it, flex it into the public record.

Madoff was the opposite.

He did not display the fraud. He concealed it inside a respectable operation, surrounded it with credentials and family and institutional legitimacy, and then let time do the rest. Every year the scheme survived was a year that added credibility to it. Every consistent return was evidence, in the minds of the investors receiving it, that the returns were real. The longer it ran, the more impossible it became to question.

ran for nine years and built a brand that 2.5 million people followed. ran for fourteen months and spent faster than he could count. Madoff ran for 48 years and never once posted a photo of the money.

The mechanism of trust is what the Madoff case documents. Not the mechanism of deception — the mechanism of trust. How trust compounds over time. How a reputation, once established, becomes self-reinforcing. How institutions designed to check that trust can fail to do so for decades. How the very qualities that make someone trustworthy — consistency, patience, restraint, the refusal to make spectacular claims — can be the disguise.

Harry Markopolos told the SEC. Eight years of warnings. The scheme ran eight more years after the first one. That is not a story about one man's cleverness. It is a story about institutional failure at scale — the failure of the regulator, the failure of the auditor, the failure of the due diligence that sophisticated investors are supposed to perform and did not.

· EPILOGUE ·
Butner, North Carolina

On April 14, 2021, Bernard Lawrence Madoff died at the Federal Medical Center in Butner, North Carolina.

He was 82 years old. Cause of death: hypertension caused by heart and kidney disease. [SOURCE: Associated Press / Bureau of Prisons confirmation, April 14, 2021]

He had been imprisoned for twelve years. He died having served approximately 8% of his 150-year sentence — which was the entirety of his remaining life, as the mathematics of the sentence had always intended.

His attorney had tried to get him out in 2020. The court denied it. Judge Chin's words at the denial: he was caught only because his scheme began to unravel with the financial crisis, when he was unable to keep up with the increasing requests for redemptions. He had not stopped. He had been stopped.

Mark was already gone. Andrew was already gone. Peter had served his time. Ruth was living under what the name now meant.

The victims were still in court. The Picard trustee was still recovering assets. The foundations that had lost their endowments were still trying to rebuild. The accounting that a 48-year scheme produces does not resolve quickly, and it does not resolve completely. Some losses are permanent.

He died in a federal medical facility in North Carolina. Not in the apartment on the Upper East Side. Not at the Palm Beach house. Not in the French Alps property his firm had paid for. In a federal medical facility, from kidney disease, at 82, with a 150-year sentence that had always been a statement rather than a calculation.

VERIFIED SOURCES

Three figures, three meanings: $64.8B (fabricated account value), $50B (Madoff's own liability statement), $170.8B (forfeiture ordered). Do not conflate them. Markopolos warning timeline verified from public record. Andrew Madoff death (September 2014, lymphoma) verified from public record. Mark Madoff death (December 11, 2010) verified from public record — handled in the text with appropriate weight.

[1] PRIMARY — GUILTY PLEA US v. Bernard L. Madoff, 09 Cr. 213 (DC), US District Court, SDNY — March 12, 2009 guilty plea, 11 federal crimes
[2] PRIMARY — SENTENCING SDNY sentencing, June 29, 2009 — 150 years; $170.8B forfeiture ordered June 26, 2009
[3] PRIMARY — PETER MADOFF US v. Peter Madoff, S7 10 Cr. 228 (LTS), SDNY — 10 years
[4] SEC CHARGE SEC Press Release 2008-293, December 11, 2008 — 'SEC Charges Bernard L. Madoff'
[5] DEATH — CONFIRMED Associated Press, April 14, 2021 — death at Federal Medical Center, Butner, North Carolina, confirmed by attorney and Bureau of Prisons. Cause: hypertension caused by heart and kidney disease. Age 82.
[6] COMPASSIONATE RELEASE DENIAL Judge Denny Chin denial, 2020 — 'caught only because his scheme began to unravel... he was unable to keep up with increasing redemption requests'
[7] MARK MADOFF December 11, 2010 — public record, widely confirmed
[8] ANDREW MADOFF September 3, 2014 — mantle cell lymphoma — public record, widely confirmed
[9] MARKOPOLOS Harry Markopolos — multiple SEC submissions from 1999; 2005 submission titled 'The World's Largest Hedge Fund Is a Fraud' — public record, Congressional testimony
[10] WIKIPEDIA 'Madoff investment scandal' — aggregator, cross-referenced to primary sources above
END OF REPORT
#4 OF 45
Bernie Ebbers
SINGLE PERSON
CASE 024 · CORPORATE FRAUDCONVICTED
WorldCom · 25 years · died 2020
~$11B
WHAT WAS TAKEN
Nothing taken in cash. $11B is the costs WorldCom hid to look profitable; investors and ~30,000 staff paid the price.
HOW
Booked everyday running costs as long-term investments, so a failing company kept reporting profits.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1983–1998LDDS formed in Hattiesburg in 1983; CEO from 1985; grows it into WorldCom and buys MCI for ~$37B in 1998.SOURCE: case brief
2000–2002From WorldCom's Clinton headquarters, ~$3.8B of costs booked as capital; resigns April 2002.SOURCE: SDNY verdict, 2005
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
BERNIE EBBERS
THE LEDGER · WORLDCOM · CASE 024 · CORPORATE FRAUD · CONVICTED 2005 · 25 YEARS · DIED 2020
ACCOUNTING FRAUD
~$11B in hidden costs — not cash taken
BANKRUPTCY
$107B in assets · July 21, 2002
PEAK VALUE
~$180B market value (mid-1999), wiped out
JOBS
Nearly 30,000 lost
SENTENCE
25 years · July 13, 2005
ENDED
Released Dec 21, 2019 · died Feb 2, 2020
THREE DIFFERENT NUMBERS: ~$11B = the accounting fraud (costs hidden as investments) · $107B = WorldCom’s assets at bankruptcy · ~$180B = its peak market value. None of them is cash he took.
FULL PROFILE

IDENTITY

NAME
Bernard John Ebbers
BORN
August 27, 1941 · Edmonton, Alberta, Canada
BEFORE
Milkman, bouncer, basketball coach (Mississippi College, 1967), motel owner
COMPANY
LDDS (1983) → WorldCom (1995) → MCI WorldCom (1998)
BASE
Clinton and Jackson, Mississippi
PEAK WORTH
~$1.4B (1999, Forbes 400)

CASE RECORD

INDICTED
March 2, 2004 · SDNY
CONVICTED
March 15, 2005 · jury · all 9 counts (conspiracy, securities fraud, 7 false filings)
SENTENCED
July 13, 2005 · 25 years · Judge Barbara S. Jones
APPEAL
Affirmed, 2nd Circuit, July 28, 2006
PRISON
FCI Oakdale, Louisiana, from Sept 26, 2006
RELEASED
Dec 21, 2019 · compassionate release (Judge Valerie Caproni) after ~13 years
DIED
Feb 2, 2020 · Brookhaven, Mississippi, aged 78
THE PEOPLE AROUND THE LEDGER
THE WHISTLEBLOWERTIME 2002
Cynthia Cooper
VP of internal audit
Her team traced the entries at night and took them to the audit committee in June 2002. TIME named her a Person of the Year.
SOURCE: TIME · ABC News
THE CFO5 YEARS
Scott Sullivan
Pleaded guilty 2004
Ran the accounting entries and was the star witness against Ebbers. Sentenced August 11, 2005.
SOURCE: NBC News
THE CONTROLLER1 YEAR 1 DAY
David Myers
Pleaded guilty 2002
Controller who carried out the entries; resigned June 25, 2002.
SOURCE: Wikipedia
ACCOUNTING5 MONTHS
Betty Vinson
Pleaded guilty 2002
Accounting manager who said she pulled numbers “out of the air” on instruction.
SOURCE: NBC News
THE LOANS~$408M
Ebbers’ personal loans
WorldCom board-approved
The company lent or guaranteed about $408M so he would not have to sell stock to meet margin calls.
SOURCE: WorldCom SEC filings 2002
THE LAWJULY 30, 2002
Sarbanes-Oxley
Signed by President Bush
CEOs and CFOs must now personally certify their accounts. Passed in the wake of Enron and WorldCom.
SOURCE: Sarbanes-Oxley Act
WHERE THE MONEY WENT
INVESTORS
Class actions settled for more than $6.13B (Sept 2005)
EBBERS
Handed over nearly all his assets (~$25–40M est.) to investors
DIRECTORS
11 former directors paid $20.25M out of their own pockets
WORLDCOM
$750M SEC penalty; renamed MCI, bought by Verizon in 2006
CASE TIMELINE
Sept 1983
LDDS is born
A Hattiesburg coffee-shop meeting starts a long-distance reseller.
SOURCE: Wikipedia
1998
MCI
~$37B takeover makes MCI WorldCom.
SOURCE: Wikipedia
June 1999
The peak
Stock ~$64; company worth ~$180B.
SOURCE: secondary
July 2000
Sprint blocked
Regulators kill the Sprint merger. Growth stalls.
SOURCE: Wikipedia
~2000–2002
The entries
Reserves released; line costs booked as capital.
SOURCE: SEC
April 30, 2002
Ebbers resigns
Owing WorldCom ~$408M in loans.
SOURCE: SEC filings
June 25, 2002
$3.8B disclosed
Cooper’s findings go public. Sullivan fired.
SOURCE: SEC
July 21, 2002
Bankruptcy
$107B in assets: biggest in US history.
SOURCE: Motley Fool
March 15, 2005
Guilty
All nine counts.
SOURCE: NBC News
July 13, 2005
25 years
Judge Barbara S. Jones.
SOURCE: NPR
Dec 21, 2019
Released
Compassionate release after ~13 years.
SOURCE: CNBC
Feb 2, 2020
Dies
Brookhaven, Mississippi, aged 78.
SOURCE: Daily Leader
HOW IT WORKED

HOW THE BOOKS WERE COOKED — DEFENSIVE LEVEL

01
The pressure: Wall Street expected growth every quarter; the stock price backed Ebbers’ personal loans
02
The costs: WorldCom paid other carriers to use their networks (“line costs”) — ordinary expenses
03
The move: Those costs were booked as long-term investments, so they vanished from the profit line
04
The result: A loss-making company reported profits, quarter after quarter: ~$11B in all
05
The catch: Internal audit traced the entries to their source and went straight to the audit committee
HOW A COST BECAME A “PROFIT”
Line costs (expenses)
-->
Booked as capital assets
-->
Profit looks healthy
-->
Stock holds up

WHAT THIS CASE ESTABLISHED

The biggest accounting fraud in US history was a filing decision, repeated.
A CEO who “is not an accountant” can still be convicted: the jury found he knew.
Internal auditors can stop a fraud that outside auditors missed.
Series link: (Petters) and (Holmes) — fraud inside a real company.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEDGER (1,000 WORDS)
Sources: DOJ/SDNY (2005) · SEC WorldCom restatement · WorldCom bankruptcy July 21, 2002 · FT/Bloomberg/Reuters contemporaneous · Sarbanes-Oxley Act (2002). DISCIPLINE: $11B = accounting overstatement (NOT cash stolen). $107B = assets at bankruptcy. ~30,000 = jobs lost. Never conflate these three figures.
· PROLOGUE ·
Nobody Hid a Dollar

The fraud was a filing decision.

WorldCom paid other telecommunications carriers to use their networks — a cost called 'line costs.' Line costs are expenses. They reduce profit. If a company is under pressure to hit a quarterly earnings target, line costs are the number standing between the reported result and the target.

The accounting decision, as the DOJ and SEC later established, was to book those expenses as capital expenditure — turning operating costs into investments spread across future years. This transformed losses into reported profits. Nobody moved money to an offshore account. Nobody invented a product that did not exist. The fraud was entries in a spreadsheet — line costs, classified as capital expenditure, quarter after quarter.

The entries added up to approximately $11 billion in overstated earnings. When they were found — by an internal auditor named Cynthia Cooper who refused to stop asking questions — the company was already insolvent. [SOURCE: DOJ; SEC; widely reported from trial record]

On July 21, 2002, WorldCom filed for bankruptcy — then the largest in US history, with assets of approximately $107 billion. Approximately 30,000 people lost their jobs. Employees who held WorldCom stock in retirement accounts saw it fall to nothing. [SOURCE: DOJ; widely reported]

· PART ONE ·
WorldCom — The Growth and the Pressure

Bernard John Ebbers was born August 27, 1941, in Edmonton, Alberta, Canada. He co-founded LDDS — Long Distance Discount Service — in 1983. Through a series of acquisitions across the 1990s, most significantly the 1998 acquisition of MCI (then America's second-largest long-distance carrier), LDDS became WorldCom and WorldCom became a major force in telecommunications.

At its peak, WorldCom had a market capitalisation of approximately $180 billion. It was America's second-largest long-distance carrier, a major data and internet provider, and — to Wall Street — a model of the new communications economy. Ebbers was its face: a physically imposing, folksy CEO who drove pickup trucks and wore cowboy boots.

The pressure to sustain the stock price of a $180 billion company was the context in which the fraud began. Quarter after quarter, the company had to hit its numbers. When the numbers could not be hit legitimately, they were made to appear hit through accounting.

· PART TWO ·
The Ledger

The fraud was operated primarily by Scott Sullivan, WorldCom's CFO, who pleaded guilty and cooperated with prosecutors. The prosecution's theory: Ebbers set the targets and created the culture of pressure; Sullivan made the accounting decisions to meet those targets. The entries reclassified 'line costs' — fees paid to other carriers for network access — as capital expenditure.

This is called capitalisation of operating expenses. Some expenses can legitimately be capitalised when they produce long-lived assets. Line costs do not qualify — they are purely operating costs that reduce the current period's profit. Reclassifying them as capital expenditure hid them from the profit-and-loss statement and put them on the balance sheet as assets instead.

The result: a company that was losing money appeared to be making money. Quarter after quarter, from approximately 1999 to 2002, for a total overstatement of approximately $11 billion. Analysts had targets. The targets appeared to be met. The stock held.

Cynthia Cooper, vice president of internal audit, discovered the fraud in 2002. She and her team worked nights and weekends, avoiding advance notice to senior management, tracing entries back to their source. When she brought the findings to the audit committee in June 2002, the company had no survivable path. The bankruptcy filing came July 21, 2002.

· PART THREE ·
The Trial and the Sentence

Ebbers' defence was that he was not an accountant. That he had trusted his CFO. That he had not known the specific entries were being made. The prosecution's theory was different: he had set the targets, maintained the pressure, and received fabricated results, knowing or recklessly disregarding that they could not be legitimate.

The jury found the prosecution's theory compelling. Ebbers was convicted on all counts in March 2005 — securities fraud, conspiracy, and seven counts of false regulatory filings. He was sentenced to 25 years in federal prison in July 2005.

The appellate courts upheld the conviction through multiple rounds of appeal.

In December 2019, after serving about 13 years, Ebbers was released on compassionate grounds: Judge Valerie Caproni ordered it on 18 December and he walked out on 21 December. He was 78, legally blind and in failing health. He died on February 2, 2020 — approximately six weeks after release.

· PART FOUR ·
What It Cost and What It Built

Approximately 30,000 WorldCom employees lost their jobs when the company entered bankruptcy. Many held WorldCom stock in their 401(k) retirement accounts — accounts the company had encouraged them to concentrate in WorldCom equity. When the stock went to nothing, those accounts went with it. People who had worked for decades lost their retirement savings. [SOURCE: widely reported from congressional testimony and DOJ record]

The legislative response was Sarbanes-Oxley — the Public Company Accounting Reform and Investor Protection Act, signed July 30, 2002. It required CEOs and CFOs to personally certify the accuracy of financial statements, imposed criminal penalties for false certifications, strengthened audit committee independence, and mandated enhanced internal controls. The corporate governance regime governing US public companies today was substantially shaped by WorldCom. [SOURCE: Sarbanes-Oxley Act, 2002]

The biggest accounting fraud in US history was a filing decision. Repeated.

VERIFIED SOURCES
[1] DOJ/SDNY — conviction March 2005 (all counts), sentencing July 2005, 25 years.
[2] SEC — WorldCom restatement record. $11B overstatement characterisation.
[3] WorldCom bankruptcy filing, July 21, 2002. Assets ~$107B (verify exact figure).
[4] FT / Bloomberg / Reuters / WSJ — contemporaneous 2002 coverage.
[5] Sarbanes-Oxley Act (2002) — legislative response and its controls.
TO VERIFY Exact restatement figure · jobs figure (some sources say higher) · peak market cap (~$180B approx) · exact release date December 2019 · Scott Sullivan sentencing term
SOURCES
[1] PRIMARY — SEC Litigation Release 19301 (July 13, 2005)
[2] PRIMARY — US v. Ebbers, 458 F.3d 110 (2d Cir., July 28, 2006)
[3] SECONDARY — NBC News: verdict and settlements (March 2005)
[4] SECONDARY — NPR: 25-year sentence (July 13, 2005)
[5] SECONDARY — CNBC / Daily Leader: release and death (Dec 2019 / Feb 2020)
[6] AGGREGATOR — Wikipedia: Bernard Ebbers; MCI Inc.; WorldCom scandal
END OF REPORT
#5 OF 45
Bill Hwang
SINGLE PERSON
CASE 023 · SECURITIES FRAUDCONVICTED
Archegos Capital · 18 years · SDNY 2024
~$10B
WHAT WAS TAKEN
Nothing taken for himself. ~$10B is what ten banks lost liquidating Archegos's positions; Credit Suisse alone ~$5.5B.
HOW
Built $100B+ of stock exposure through swaps with ten banks so none could see the total; the jury found he also propped up the prices.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2001–2012Runs Tiger Asia, a hedge fund in the Tiger Management network; it settles insider-trading charges for ~$60M in 2012 and returns outside money.SOURCE: SEC / DOJ 2012
2013–2021Turns it into Archegos Capital Management, a family office on Seventh Avenue managing only his own money.SOURCE: DOJ SDNY
2020–Mar 2021Builds concentrated positions in ViacomCBS, Discovery and others through total-return swaps with about ten banks; the banks lose ~$10B when it unwinds on 26 March 2021.SOURCE: DOJ SDNY; Reuters
Apr 2022–Nov 2024Charged, tried and convicted in Manhattan; 18 years on 20 Nov 2024.SOURCE: DOJ SDNY
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
BILL HWANG
THE TOTAL PICTURE · ARCHEGOS CAPITAL · CASE 023 · SECURITIES FRAUD · 10 OF 11 COUNTS · 18 YEARS 2024
BANK LOSSES
~$10B when the banks liquidated
POSITIONS
over $100B at the peak (prosecutors) — exposure, not theft
CREDIT SUISSE
~$5.5B of the loss
COUNTS
10 of 11 · jury, July 10, 2024
SENTENCE
18 years · Nov 20, 2024
STATUS
Free on bail pending appeal
HE STOLE NOTHING. $100B = the market value of positions no single bank could see the size of. $10B = what the banks lost. $5.5B = Credit Suisse’s share.
FULL PROFILE

IDENTITY

NAME
Sung Kook “Bill” Hwang
BORN
1964 · South Korea
FIRM
Archegos Capital Management, New York — a family office
BEFORE
Tiger Asia: settled insider-trading charges for ~$60M in 2012

CASE RECORD

CHARGED
Apr 27, 2022 · SDNY · 11 counts
CONVICTED
July 10, 2024 · 10 of 11 counts
SENTENCED
Nov 20, 2024 · 18 years · Judge Alvin Hellerstein
APPEAL
Pending; free on bail
KNOWN AS
Bill Hwang
STATUS
Convicted
CUSTODY
Never detained
COURT
US District Court, Southern District of New York
JUDGE
Alvin K. Hellerstein
CHARGES
Racketeering conspiracy · Securities fraud · Wire fraud · Market manipulation (11 counts charged)
NOT CHARGED WITH
Theft or misappropriation — nothing was stolen; the case is concealment and manipulation
PLEA
Not guilty — convicted by a jury on 10 of 11 counts, 10 July 2024; acquitted on one market-manipulation count
THE BANKS THAT HELD THE PIECES
THE BIGGEST LOSS~$5.5B
Credit Suisse
Swiss bank
Its share of the Archegos loss; taken over by UBS in 2023.
SOURCE: Credit Suisse disclosure; FT
THE SECOND~$2B
Nomura
Japanese bank
Loss on its Archegos positions.
SOURCE: Reuters
THE CFOCONVICTED
Patrick Halligan
Archegos CFO
Convicted alongside Hwang in July 2024.
SOURCE: DOJ SDNY
CASE TIMELINE
2012
Tiger Asia
Settles insider-trading charges; becomes Archegos.
SOURCE: SEC / DOJ
2020–2021
The swaps
Positions built across ~10 banks.
SOURCE: DOJ
Mar 26, 2021
Collapse
ViacomCBS falls; banks liquidate; ~$10B lost.
SOURCE: Reuters
Apr 27, 2022
Charged
11 counts, SDNY.
SOURCE: DOJ
July 10, 2024
Guilty
10 of 11 counts.
SOURCE: CNBC
Nov 20, 2024
18 years
Judge Hellerstein.
SOURCE: DOJ
HOW IT WORKED

HOW THE EXPOSURE WAS HIDDEN — DEFENSIVE LEVEL

01
The instrument: Total-return swaps: the bank owns the shares, the client takes the gains and losses
02
The split: The same stocks through ~10 banks, each seeing only its own piece
03
The pressure: Buying kept the prices up, the jury found
04
The unwind: One stock fell, every bank sold at once, the losses landed in ten places
HOW ONE FALL BECAME TEN LOSSES
Concentrated swaps
-->
Stock falls
-->
Margin calls
-->
Banks liquidate together
-->
~$10B lost

WHAT THIS CASE ESTABLISHED

A control that only sees its own slice is not a control.
Nothing was stolen; the concealment was the fraud.
Series link: (Leeson).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE TOTAL PICTURE (1,300 WORDS)
Sources: DOJ/SDNY — charged April 2022; conviction July 10, 2024 (10 of 11 counts; acquitted on one market-manipulation count); sentencing November 2024 (18 years) · SEC civil action · Reuters/Bloomberg/WSJ/FT Archegos coverage · Credit Suisse / UBS disclosures. STATUS: convicted, sentenced, free on bail pending appeal. He is NOT currently serving the sentence — appeal is pending.
· PROLOGUE ·
Nobody Had the Total

In March 2021, several of the world's largest banks received margin calls on positions they had built for a family office called Archegos Capital Management. Each bank had lent the family office exposure to the same stocks — large, concentrated positions in a handful of companies. When those stocks fell, the banks were forced to liquidate. Because several of them were liquidating the same names at the same time, the selling accelerated the decline. The losses were counted in ten places.

The largest single loss: Credit Suisse, approximately $5.5 billion. Nomura: approximately $2 billion. Morgan Stanley: approximately $1 billion. UBS and Mizuho: hundreds of millions each. The total across all counterparties: approximately $10 billion. [SOURCE: Reuters/Bloomberg/FT; per-bank disclosures — verify exact figures before publication]

Bill Hwang, the founder of Archegos, had used a financial instrument called a total-return swap — a derivative that gave him the economic exposure to a stock's performance without owning the stock directly. The bank owned the shares; Hwang received the returns or absorbed the losses. The arrangement allowed him to build enormous, concentrated positions across multiple banks simultaneously, with each bank seeing only its own piece. None of them could see the total.

That is the whole case. The positions were enormous — a notional market value that prosecutors described as exceeding $100 billion. The exposure was concealed — not through one hidden account but through the structure of the swaps and the fact that no institution had a consolidated view. When it unwound, the losses cascaded. And one bank did not survive it in recognizable form.

· PART ONE ·
The Structure — Why the Swaps Mattered

Archegos Capital Management was a family office — a vehicle that manages the personal wealth of a single family, without outside investors. This structure carries significantly lighter regulatory disclosure obligations than a hedge fund or investment manager with outside clients. A family office is not required to report its positions to the SEC in the same way a fund manager is. The structure was not illegal; it was a permission slip.

Hwang had managed outside money before. Tiger Asia, his hedge fund, was a protégé operation from the Tiger Management network founded by Julian Robertson. In 2012, Tiger Asia settled insider-trading charges with the DOJ and SEC for approximately $60 million and agreed to return outside capital. Hwang subsequently converted the operation into Archegos — a family office, managing only his own money, operating with less transparency. [SOURCE: SEC/DOJ 2012 settlement; public record]

The total-return swap is a legitimate instrument: a bank buys shares, a client pays a fee and receives the economic return on those shares (or absorbs the loss). The swap allows leverage — the client can control a large position with a smaller cash outlay — and because the bank holds the shares, the client's position is not visible in public stock-ownership filings. Used across multiple banks for the same underlying stocks, the aggregate exposure is invisible to any single counterparty.

This is what the DOJ and SEC allege Hwang did: he built concentrated positions in a small number of stocks — ViacomCBS, Discovery, GSX Techedu, and others — through swaps with approximately ten banks. Each bank understood it had its own exposure. None knew the others' exposures. The banks' individual risk models did not flag what the aggregate model would have found: a single actor with enormous, undisclosed, concentrated leverage in the same names across their entire counterparty roster.

· PART TWO ·
The Collapse — March 2021

The event that triggered it was a stock offering. ViacomCBS announced a share offering in March 2021. The share price began to fall. Archegos's positions — largely in ViacomCBS and Discovery — came under pressure. Margin calls arrived from the banks.

Archegos could not meet them. The banks began liquidating. Because multiple banks were selling the same stocks at the same time — all of them holding concentrated positions in the same names for the same client — the selling pressure was self-reinforcing. The stocks fell further. The margin calls increased. The positions unwound over days.

Credit Suisse was the bank most severely exposed. Its loss of approximately $5.5 billion from the Archegos collapse was the largest single counterparty loss from the event and represented a significant fraction of its total equity. Credit Suisse had been weakened by several concurrent events in early 2021 — including its exposure to the Greensill Capital collapse — and the Archegos losses compounded an already fragile situation. [SOURCE: Credit Suisse disclosure; FT/Bloomberg]

Credit Suisse did not recover. In March 2023 — two years after the Archegos collapse — it required emergency intervention from the Swiss National Bank, and was taken over in a government-brokered rescue merger by UBS. Multiple investigations attributed the Archegos losses as a contributing factor to the bank's deterioration. A family office had contributed to the end of one of the oldest banks in Switzerland. [SOURCE: Bloomberg; FT; Reuters 2023]

· PART THREE ·
The Conviction — July 2024

Hwang was charged in April 2022 by the SDNY on 11 counts: one of racketeering conspiracy, three of fraud and seven of market manipulation. The government's case: Hwang and associates concealed Archegos's true exposure from counterparty banks, and separately manipulated the prices of the stocks Archegos held — pumping prices through coordinated buying to maintain the inflated values that justified keeping the positions open.

The jury convicted him on 10 of the 11 counts on July 10, 2024, acquitting him on one market-manipulation count. Judge Alvin Hellerstein sentenced him to 18 years in federal prison on November 20, 2024. He is currently free on bail pending appeal. He has not reported to prison. [SOURCE: DOJ July 2024; DOJ/court November 2024; Reuters]

The governance lesson the case teaches is the same as Leeson (), scaled to the modern global banking system: a control that is siloed is not a control. Leeson's losses were visible to nobody because he controlled both the trading and the back office. Hwang's exposure was visible to nobody because each bank held a fragment it could not see the aggregate of. The mechanism of failure is identical — the person taking the risk is also, in effect, the person recording it, because no external party has the consolidated picture.

The series' thesis about governance — that the check must be independent of the party it checks, and must have the complete picture — is proven here, at the scale of ten global prime brokers and $10 billion in losses.

VERIFIED SOURCES
[1] DOJ/SDNY — indictment April 2022 (11 counts: racketeering conspiracy, fraud and market manipulation). Conviction July 10, 2024 (10 of 11 counts). Sentencing November 20, 2024 (18 years, Judge Hellerstein).
[2] SEC — civil action against Hwang and Archegos Capital Management.
[3] Reuters/Bloomberg/FT — Archegos collapse, March 2021; bank loss disclosures; Credit Suisse attribution. [Verify per-bank figures before publication — amounts in various reports differ slightly]
[4] Credit Suisse disclosure statements — ~$5.5B loss figure. Also UBS 2023 rescue merger as context.
[5] SEC/DOJ — Tiger Asia 2012 settlement (~$60M). Source for the prior insider-trading record.
STATUS NOTE As of September 2026, Hwang is free on bail pending appeal. He has not reported to prison. Do not describe him as 'serving' the 18-year sentence.
TO VERIFY Birth date (1964 commonly cited) · Exact sentencing date (November 2024) · Exact per-bank loss figures · The prosecutors' exact language on the $100B figure · Appeal court and expected timeline · Credit Suisse's precise attribution of Archegos as a contributing factor to its 2023 failure
SOURCES
[1] PRIMARY — US Attorney SDNY: sentencing (Nov 20, 2024)
[2] SECONDARY — CNBC / Bloomberg: verdict (July 10, 2024)
[3] SECONDARY — Reuters / FT: the collapse and bank losses (2021)
[4] PRIMARY — SEC / DOJ: Tiger Asia settlement (2012)
END OF REPORT
#6 OF 45
Ding Ning
SINGLE PERSON
CASE 031 · PONZILIFE SENTENCE
Ezubao · life imprisonment · Beijing 2017
¥59.8B
WHAT WAS TAKEN
About $9B (59.8B yuan, official figure) from ~900,000 ordinary Chinese savers.
HOW
Ran Ezubao, an online lending site where ~95% of the loan listings were fake; new deposits paid old investors.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
July 2014–Dec 2015Runs Ezubao from Yucheng Group; fake leasing projects raise ¥50B+ from ~900,000 investors.SOURCE: Beijing No.1 Intermediate People's Court, Sept 2017
Jan 2016Arrested; sentenced to life in Sept 2017.SOURCE: Xinhua
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
DING NING
THE NINE HUNDRED THOUSAND · 丁宁 · EZUBAO · CASE 031 · PONZI · LIFE IMPRISONMENT 2017
RAISED
59.8B yuan (~$9B) · officially reported
UNPAID
~38B yuan (~$5.8B)
INVESTORS
~900,000
FAKE PROJECTS
~95% (prosecutors)
SENTENCE
Life · Sept 12, 2017
FINE
100 million yuan
OFFICIAL FIGURES: all numbers come from Chinese prosecutors, courts and state media. Yuan converted at 2015–16 rates (~6.5 per dollar).
FULL PROFILE

IDENTITY

NAME
Ding Ning (丁宁)
BORN
~1982 · Anhui province, China (34 in Feb 2016)
BEFORE
Left school at 17; worked in his mother’s hardware factory
COMPANY
Anhui Yucheng Holding Group · the Ezubao (e租宝) lending platform
THE PROMISE
9–14.6% a year on “loans” to listed companies

CASE RECORD

STOPPED
December 2015 · police investigation
ARRESTED
Jan 14, 2016 · 21 people formally arrested
COURT
Beijing No. 1 Intermediate People’s Court
SENTENCED
Sept 12, 2017 · life imprisonment + 100M yuan fine
ALSO
Illegal gun possession; smuggling precious metals
OTHERS
Brother Ding Dian: life · 24 others: 3–15 years
THE PEOPLE AND THE PLATFORM
THE BROTHERLIFE
Ding Dian
Co-defendant
Also sentenced to life, with a 70 million yuan fine.
SOURCE: Xinhua / China Daily
THE PRESIDENTCONVICTED
Zhang Min
Yucheng Global
Given a Singapore villa, a 12M yuan diamond ring and 550M yuan in cash, state media said. Called it a Ponzi scheme.
SOURCE: CBS · state media
THE EVIDENCE6 METRES DOWN
1,200 documents
80 bags
Buried outside Hefei; two excavators took 20 hours to dig them up.
SOURCE: Wikipedia
THE COMPANYFINED
Yucheng Global
1.8B yuan fine
Anhui Yucheng Holding Group also fined 100M yuan.
SOURCE: Xinhua
THE INVESTORS~900,000
Ordinary savers
Across China
Many put in small sums they believed were in a supervised product; protests followed.
SOURCE: Reuters
THE AFTERMATH2020
China’s P2P industry
Shut down
Thousands of online lending platforms failed; regulators closed the sector.
SOURCE: Bloomberg
BY NUMBER OF VICTIMS
MADOFF (004)
~37,000 investors
STANFORD (010)
~18,000 CD holders
EZUBAO (031)
~900,000 investors, officially reported
ONECOIN (008)
Millions claimed; disputed
CASE TIMELINE
July 2014
Launch
Ezubao goes online.
SOURCE: Xinhua
2015
Boom
Among China’s biggest online lenders.
SOURCE: Reuters
Dec 2015
Stopped
Police investigation; platform halts.
SOURCE: Xinhua
Jan 14, 2016
Arrests
21 formally arrested.
SOURCE: Xinhua
Feb 1, 2016
Exposed
95% of projects fake, state media says.
SOURCE: People’s Daily
Sept 12, 2017
Life
Beijing court sentences Ding Ning.
SOURCE: Xinhua
HOW IT WORKED

HOW EZUBAO WORKED — DEFENSIVE LEVEL

01
The shop window: An online marketplace listing companies that wanted loans
02
The listings: About 95% were fake, prosecutors said
03
The returns: Paid out of new deposits, not real interest
04
The spending: Gifts, property and luxury goods for insiders
05
The warning sign: High fixed returns and listings you can’t check independently
HOW THE MONEY MOVED
Savers’ deposits
-->
Fake loan listings
-->
Old investors paid
-->
Insiders’ spending

WHAT THIS CASE ESTABLISHED

By the official count, one of the largest Ponzi schemes ever by number of victims.
A whole industry was shut down after it.
Series link: (Madoff) and (Stanford) — the Ponzi pattern at three scales.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE NINE HUNDRED THOUSAND (1,400 WORDS)
· PROLOGUE ·
The Number That Does Not Fit

Madoff () defrauded approximately 37,000 investors. That figure appears throughout his case file as a marker of scale.

Ding Ning's Ezubao operation is estimated to have defrauded approximately 900,000 investors — twenty-four times that number. By the official victim count, it is one of the largest Ponzi schemes ever recorded. [SOURCE: Chinese state media / official court record]

The platform raised 59.8 billion yuan — approximately $9 billion at 2015-2016 exchange rates — through a peer-to-peer lending operation that ran from 2014 to December 2015. Most of the investment projects listed on the platform were fabricated. Investors were promised returns of 9 to 14.6 percent annually. The money that came in was used to pay the returns of earlier investors — the Ponzi cycle — and to fund a lifestyle of extraordinary personal extravagance that included gifts such as a pink diamond ring reportedly worth 12 million yuan and a Singapore villa worth 130 million yuan for the company's president, Zhang Min. [SOURCE: CBS; Chinese state media]

In December 2015 Chinese police moved on Ezubao; 21 people, including Ding Ning, were formally arrested in January 2016. On 12 September 2017 a Beijing court sentenced him to life imprisonment and a fine of 100 million yuan. His brother Ding Dian also received life; 24 other defendants received 3 to 15 years.

· PART ONE ·
What Ezubao Was — P2P Lending in China 2014-2015

Peer-to-peer lending — P2P — was one of the fastest-growing financial sectors in China between 2012 and 2018. The model: an online platform connects borrowers who need capital with investors who want returns. The platform takes a fee. The investor gets interest from the borrower.

The appeal in China was specific to the moment. Traditional Chinese banks channeled credit primarily to state-owned enterprises and large corporations. Small businesses and individuals struggled to access loans. Retail investors, simultaneously, had limited high-yield options — bank deposit rates were low, the stock market volatile. P2P platforms offered both sides of this equation a solution: borrowers could get capital, investors could earn 9 to 15 percent. Thousands of platforms emerged.

Regulation was minimal and slow to develop. The industry grew faster than oversight could follow. At its peak, there were estimated to be over 3,000 active P2P lending platforms in China. Most were legitimate. Some were not. Ezubao, operated by Anhui Yucheng Holdings Group under Ding Ning's leadership, was the largest and the most fraudulent.

Ezubao launched in 2014. Within a year it had grown to one of the country's largest P2P platforms by volume, attracting investors with promises of returns between 9 and 14.6 percent annually. The platform appeared to be matching investors with real financing projects — equipment leasing, infrastructure loans, business credit. Most of these projects, per the prosecution, were fictional. Ding Ning's company created fake project listings to give investors the appearance of understandable, specific investments.

· PART TWO ·
The Fraud — What Was Real and What Was Not

The prosecution established that approximately 95 percent of Ezubao's listed investment projects were fabricated. [SOURCE: Chinese state media citing prosecution; Reuters — verify exact percentage and its source]

The mechanism was a classic Ponzi: early investors received their promised returns, funded by the influx of new investor capital rather than by real investment returns. The platform appeared healthy and transparent. Its marketing emphasized the specific, real-world nature of its lending — names, addresses, and details for projects that did not exist.

The scale of personal enrichment was also documented in the prosecution: Ding Ning spent hundreds of millions of yuan on luxury goods, real estate, and personal expenses. Chinese state media reported that he spent more than 1 billion yuan on gifts, including 550 million yuan in cash, a Singapore villa and a 12 million yuan pink diamond ring for Zhang Min, president of Yucheng Global. He and his family received hundreds of millions in transfers from the Ezubao operation. [SOURCE: Chinese state media — treat as official prosecution account]

The collapse came in December 2015 when police moved in; 21 people were formally arrested in January 2016. Investigators later dug up about 1,200 documents, in 80 bags, buried six metres underground outside Hefei. The platform froze and hundreds of thousands of investors could not access their funds. The human consequence was severe — many investors had placed life savings, retirement funds, or borrowed money into the platform. Reports at the time documented protests outside government buildings in multiple cities by investors demanding their money back.

· PART THREE ·
The Series Context — What Makes This Case Different

Every other Ponzi case in this series involves a relatively contained investor group: Madoff's clients were wealthy individuals and institutions. Stanford's () were CD buyers. at least targeted people with some financial sophistication.

Ding Ning's victims were mass market. P2P platforms in China targeted ordinary wage earners who were depositing small amounts — some as little as a few hundred yuan — into what they understood to be supervised investment products. The ~900,000 investor count reflects that reality. It is not 900,000 sophisticated investors who should have known better. It is ordinary people who had few alternatives and trusted a regulated-looking online platform.

This is the Ponzi case where the victim count is the thesis. In every other case in this series — Madoff, Stanford, Ponzi himself — the dollar figure is the defining number. Ezubao's dollar figure (~$9 billion) is significant but comparable to Stanford ($7.2 billion). The victim count is not comparable to anything else. It is the largest in history.

· PART FOUR ·
The Conviction and the P2P Aftermath

On 12 September 2017, the Beijing No. 1 Intermediate People's Court sentenced Ding Ning to life imprisonment and a 100 million yuan fine; he was also convicted of illegally possessing guns and smuggling precious metals. His brother Ding Dian received life and a 70 million yuan fine. 24 other defendants received 3 to 15 years. The court put the fraud at more than 50 billion yuan from about 900,000 investors. [SOURCE: Reuters; Xinhua — verify exact sentencing date and court]

The prosecution was the highest-profile output of China's crackdown on P2P lending fraud. The broader P2P collapse — thousands of platforms failing between 2016 and 2020 — generated additional prosecutions across the country, but none reached the scale of Ezubao.

By 2020, the Chinese government had effectively closed or converted the entire P2P lending sector. Every platform operating in the space was required to either obtain a banking licence — a bar very few could meet — or shut down. The regulatory response was total: an entire financial sector was eliminated as a consequence, in part, of what Ding Ning had done to the most visible platform in it.

The investor recovery was limited. The assets Ding Ning and his co-defendants accumulated were seized and distributed through a restitution process, but the amounts recovered represent a fraction of what investors lost. The gap between the fraud's scale and the recovery is the usual story of a Ponzi — by the time the scheme collapses, most of the money is gone.

VERIFIED SOURCES AND SOURCE CAUTION
PRIMARY SOURCES ARE CHINESE STATE MEDIA AND COURT RECORDS. This is the only available primary record. Treat all official figures as officially reported and note the source type throughout. Secondary coverage from Reuters and Bloomberg is limited.
[1] Xinhua / People's Daily — official Chinese state coverage of the arrest (December 2015), prosecution, and conviction (12 September 2017). Primary source for official figures. Treat as official state reporting.
[2] Reuters — international coverage of Ezubao collapse and initial arrests. December 2015. Limited but secondary verification of scale and arrest details.
[3] Beijing No. 1 Intermediate People's Court — 12 September 2017. Life imprisonment for Ding Ning; 100 million yuan fine. Brother Ding Dian life. 24 others 3–15 years. [SOURCE: Xinhua / China Daily]
[4] Bloomberg — P2P lending industry context and regulatory response. 2016-2020 coverage.
CURRENCY NOTE 59.8 billion yuan at 2015-2016 exchange rate (~6.5 yuan/USD) = approximately $9.2 billion. Label as approximate conversion with date. Do not use current exchange rates.
TO VERIFY Exact sentencing date and court name · Exact victim count (official sources vary between 'approximately 900,000' and 'nearly one million') · Percentage of projects that were fabricated (95% is the widely reported prosecution figure — verify to court record) · Co-defendant sentence details · Amount recovered and distributed to investors · Ding Ning's current incarceration status
SOURCES
[1] PRIMARY — Xinhua / People’s Daily: Ezubao investigation (Feb 1, 2016)
[2] PRIMARY — Xinhua / China Daily: Beijing verdict (Sept 12, 2017)
[3] SECONDARY — CBS / Reuters: collapse and gifts
[4] AGGREGATOR — Wikipedia: Ezubao
END OF REPORT
#7 OF 45
Samuel Bankman-Fried
SINGLE PERSON
CASE 005 · CRYPTO / EXCHANGE FRAUDCONVICTED
SBF · FTX founder · 25 years · SDNY Mar 2024
~$8B
WHAT WAS TAKEN
FTX customers' deposits, their cash and crypto.
HOW
Secretly moved the deposits to his hedge fund, Alameda, and spent them.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2017Founds Alameda Research, the trading firm that later drains FTX's customer deposits.SOURCE: DOJ SDNY
2019–2021Founds FTX and runs both companies from Hong Kong.SOURCE: DOJ SDNY; case brief
2021–2022Moves FTX headquarters to the Bahamas; customer funds flow to Alameda through the exchange's hidden credit line.SOURCE: DOJ SDNY; trial record
Nov–Dec 2022FTX collapses; arrested in Nassau on 12 Dec 2022 and extradited to the US on 21 Dec.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: Cointelegraph · CC BY 3.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
SAMUEL BANKMAN-FRIED
SBF · FTX FOUNDER · CASE 005 · CONVICTED NOV 2023 · SENTENCED 25 YEARS MAR 2024
CUSTOMER LOSSES
$8B
METRIC
Customer funds misappropriated
SENTENCE
25 years · SDNY
FORFEITURE
$11B ordered
VERDICT
Guilty all 7 counts · Nov 2, 2023
JUDGE
Hon. Lewis Kaplan · SDNY
BORN
March 6, 1992 · Stanford, CA
EDUCATION
MIT · Physics degree 2014
FULL PROFILE

IDENTITY

LEGAL NAME
Samuel Benjamin Bankman-Fried
KNOWN AS
SBF
BORN
March 6, 1992 · Stanford, California
EDUCATION
MIT · Physics · graduated 2014
FTX FOUNDED
2019 · Bahamas HQ
ALAMEDA RESEARCH
Co-founded 2017 · crypto hedge fund
PUBLIC PERSONA
Effective altruism advocate · political donor · "King of Crypto"
VALUATION (PEAK)
FTX valued ~$32B · SBF net worth estimated $26B at peak [SOURCE: Forbes]

CASE RECORD

CASE
US v. Bankman-Fried · SDNY
FTX COLLAPSED
November 2022 · $8B customer fund shortfall
ARRESTED
December 12, 2022 · Nassau, Bahamas
EXTRADITED
December 21, 2022 · US custody
CHARGES
2x wire fraud · 2x conspiracy wire fraud · conspiracy securities fraud · conspiracy commodities fraud · conspiracy money laundering
TRIAL
October 3 – November 2, 2023 · one month
VERDICT
Guilty all 7 counts · November 2, 2023
SENTENCED
March 28, 2024 · 25 years · Judge Lewis Kaplan
FORFEITURE
$11B ordered
LOSSES FOUND
$8B customers · $1.7B equity investors · $1.3B Alameda lenders [SOURCE: Judge Kaplan at sentencing]
HOW THE FRAUD WORKED

THE MECHANISM — CUSTOMER FUNDS TO ALAMEDA

01
The public lie: SBF repeatedly told customers, investors, and the public that customer deposits to FTX were kept safe, held separately from company assets, and would never be used by FTX. These statements were false. [SOURCE: DOJ/SDNY]
02
The backdoor: SBF directed co-conspirators to alter FTX’s computer code to give Alameda Research an effectively unlimited credit line — allowing Alameda to withdraw customer funds from the exchange without triggering the same checks applied to other users. [SOURCE: DOJ]
03
The use of funds: Billions in FTX customer deposits flowed to Alameda, which used them for trading (poorly), real estate in the Bahamas, political contributions, bribery of Chinese government officials (~$40M alleged), and personal expenditure. When crypto prices fell in 2022, the hole became visible. [SOURCE: DOJ · AP]
04
The cover: Fabricated balance sheets for Alameda lenders. False financial statements. Backdated contracts. A public persona built on effective altruism and philanthropy that functioned as credibility capital. Celebrity endorsements (Tom Brady, Larry David, Super Bowl advertising). [SOURCE: DOJ · AP · PBS]
05
The collapse: CoinDesk published Alameda’s balance sheet in November 2022 showing its primary asset was FTT — FTX’s own token. Binance CEO announced sale of FTT holdings. Customer withdrawal run began. Within days: $8B shortfall confirmed. FTX filed for bankruptcy November 11, 2022. [SOURCE: widely documented]
NETWORK & CO-CONSPIRATORS
CO-FOUNDER FTX · CTOPLEADED GUILTY
Gary Wang
Co-founder and CTO of FTX
Co-founder who built the code. Pleaded guilty and cooperated with prosecutors — his testimony explained the technical backdoor that gave Alameda unlimited credit. Sentencing scheduled 2024, pending cooperation credit. [SOURCE: DOJ · CNBC]
SOURCE: DOJ · CNBC · trial record
HEAD OF ENGINEERING FTXPLEADED GUILTY
Nishad Singh
Head of Engineering · FTX
Pleaded guilty and cooperated. Testified at trial. Singh wrote much of the exchange’s code and helped implement changes that allowed Alameda’s privileged access. Cooperation credit applied at sentencing. [SOURCE: DOJ · trial record]
SOURCE: DOJ · trial record
CEO FTX DIGITAL MARKETSSENTENCED — 7.5 YEARS
Ryan Salame
CEO FTX Digital Markets (Bahamas entity)
Sentenced to 7 years and 6 months for campaign finance violations and operating an unlicensed money transmitting business. Made political donations using FTX funds funneled through his name to evade contribution limits and reporting requirements — at SBF’s direction. [SOURCE: DOJ · The Register]
SOURCE: DOJ · widely documented
JUDGE KAPLAN — SENTENCING MARCH 28 2024

FROM THE BENCH

“Sam Bankman-Fried perpetrated one of the biggest frauds in American history — a multibillion-dollar scheme designed to make him the King of Crypto.” — US Attorney Damian Williams [SOURCE: DOJ statement]
“I keep coming back to Ms. Ellison’s testimony that he knew it was wrong. He knew it was criminal.” — Judge Kaplan at sentencing [SOURCE: CNBC]
“The cryptocurrency industry might be new and the players like Sam Bankman-Fried might be new. But this kind of corruption is as old as time. This case has always been about lying, cheating, and stealing.” [SOURCE: DOJ / US Attorney Williams]
Prosecutors had sought 40–50 years. Defense sought 5–6 years. Judge Kaplan sentenced 25 years. Perjury enhancement applied after judge found SBF had lied under oath at trial. [SOURCE: Variety / AP]
CASE TIMELINE
UNDATED
Born; parents are Stanford Law professors
attends MIT
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Works at Jane Street (quant trading)
SOURCE: case brief (sources listed in its SOURCES part)
2017
Founds Alameda Research
SOURCE: case brief (sources listed in its SOURCES part)
2019
Founds FTX
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Ellison becomes CEO of Alameda
she and SBF are in a relationship
SOURCE: case brief (sources listed in its SOURCES part)
2022
FTX collapses
bankruptcy filed; SBF arrested in the Bahamas
SOURCE: case brief (sources listed in its SOURCES part)
Dec 2022
Extradited to the US
charged
SOURCE: case brief (sources listed in its SOURCES part)
Nov 2023
Convicted on 7 counts
Ellison's testimony central
SOURCE: case brief (sources listed in its SOURCES part)
Mar 2024
Sentenced to 25 years
SOURCE: case brief (sources listed in its SOURCES part)
Sept 2024
Ellison sentenced to 2 years + $11B forfeiture
SOURCE: case brief (sources listed in its SOURCES part)
Nov 2025–Jun 2026
Appeal argued and decided (2nd Circuit, 24-961-cr)
SOURCE: case brief (sources listed in its SOURCES part)

WHAT THIS CASE ESTABLISHED

The flagship case for crypto exchange accountability: customer funds are not company funds, and a segregation claim that is false is fraud.
The effective altruism persona — political donations, charity, media access — functioned as credibility infrastructure and did not mitigate the sentence.
Celebrity endorsements and a Super Bowl ad validated the exchange in the public eye. The credibility transferred; the due diligence did not happen.
’s cooperation and testimony was the prosecution’s core. "He knew it was wrong. He knew it was criminal." — the key line from the key witness.
Judge found SBF perjured himself at trial, triggering a sentencing enhancement. The decision to testify and maintain innocence cost him additional years against the guidelines.
$8B in customer losses. $11B forfeiture ordered. 25 years. The numbers define one of the largest financial frauds in American history, prosecuted in one month of trial.
THE FULL STORY — 10 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — “FTX IS FINE” (3,600 WORDS)
Sources: US v. Bankman-Fried, 22 Cr. 673 (LAK), SDNY · US v. Bankman-Fried, No. 24-961-cr, Second Circuit (affirmed June 12, 2026 — unanimous) · DOJ sentencing letter on Ellison, September 17, 2024 · DOJ/SDNY conviction and sentencing releases · AP · Reuters · Fortune · CoinDesk · Al Jazeera timeline. $8B = customer funds misappropriated. Not the same as Ellison's $11B forfeiture order.
· PROLOGUE ·
"FTX Is Fine"

On November 7, 2022, as the collapse of his empire began in earnest, Sam Bankman-Fried posted on Twitter.

Four days later, on November 11, 2022, FTX filed for bankruptcy. The exchange had run out of money after customers tried to withdraw approximately $6 billion in 72 hours and discovered the funds were not there. [SOURCE: Axios/Reuters collapse timeline]

The assets were not fine. The assets were in Alameda Research, the connected trading firm that had been using FTX customer deposits to cover its own losses, service its own obligations, and fund the lifestyle of an operation that had purchased at least 19 properties in the Bahamas worth $121 million while its CEO slept on a beanbag and told the world he didn't care about material things. [SOURCE: Fortune, November 2022; DOJ trial record]

Samuel Benjamin Bankman-Fried — SBF, to everyone who followed him — had been the person the cryptocurrency industry most wanted to believe was the good one. He was MIT, Jane Street, effective altruism, the beanbag, the cargo shorts, the billions pledged to charity. He was the billionaire who made you think maybe the whole thing was serious after all.

He was convicted by a unanimous jury in November 2023 on all seven counts of fraud, conspiracy, and money laundering. He was sentenced to 25 years. His appeal was denied. He is serving time at a federal prison in California. He is eligible for release in 2044.

· PART ONE ·
Stanford Hospital, MIT, and the Flip of a Coin

Samuel Benjamin Bankman-Fried was born on March 6, 1992, at the hospital on the campus of Stanford University in California.

His parents, Joseph Bankman and Barbara Fried, were — and remain — law professors at Stanford Law School. He was, quite literally from birth, inside the academic establishment that produces the credentialed elite of American professional life. The family is not incidental background. The family is the foundation of every door that opened.

He attended the Massachusetts Institute of Technology, where he studied physics. He has said he chose MIT over Caltech by flipping a coin. [SOURCE: Fortune trial timeline] He majored in physics and minored in mathematics. He was less interested in his classes, by his own account, than in spending time in the Epsilon Theta fraternity — a group whose members would later include several future FTX employees, among them co-founder Gary Wang.

At MIT he also encountered effective altruism — the philosophical framework developed in part by William MacAskill that holds that the right way to do good in the world is to reason carefully about which interventions produce the most benefit per dollar and direct your money and energy accordingly. One strand of effective altruism, called 'earning to give,' holds that someone capable of earning large amounts in finance should do so and donate most of the proceeds, rather than taking lower-paying work directly in the nonprofit sector.

Bankman-Fried found this argument compelling. He graduated in 2014 and took a job at Jane Street Capital — the quantitative trading firm — and reportedly gave away half his salary. [SOURCE: biography.com citing multiple sources] He had not yet made much money. He was already planning what he would do when he did.

· PART TWO ·
Effective Altruism — The Philosophy That Made Him Untouchable

The effective altruism framing was the most important thing about Sam Bankman-Fried that was not about money. It was the thing that made the money story different.

Most people who get rich in finance are not particularly interesting to the public as moral characters. They make money, they spend money, they give some of it away. The story is familiar enough to be unremarkable.

Bankman-Fried's story was different because the explicit, loudly-stated purpose of making money was to give it away. He had taken a philosophical position — not vaguely charitable, but specifically reasoned — that the highest use of his capabilities was to earn as much as possible in order to donate as effectively as possible to causes that reduced the most suffering. He had committed to giving away his entire wealth. He had signed the Giving What We Can pledge. He talked about pandemic prevention and animal welfare and the long-term future of humanity.

He also dressed badly. The T-shirts and cargo shorts and uncombed hair were not an accident. They were a signal: I am not doing this for the lifestyle. I do not care about the markers of success. I am accumulating money as a tool, not as an end.

He slept on a beanbag at the office. He took investor meetings while playing video games. He was vegan. He occasionally cooked vegan meals for the ten FTX employees who lived with him in the Bahamas penthouse that the company had purchased for $30 million. [SOURCE: Fortune / biography.com] The beanbag and the penthouse coexisted without apparent discomfort, because the penthouse was framed as a business necessity and the beanbag was the real him.

The effective altruism community celebrated him. He was profiled in magazines as proof that the framework produced good actors. He was the case study that 80,000 Hours and similar organisations pointed to when people asked whether 'earning to give' was a viable path to doing good. He donated $5 million to Joe Biden's 2020 presidential campaign. He donated approximately $40 million to Democratic politicians in the 2022 midterms, making him one of the largest political donors in the party. He said he had given similar sums to Republicans through dark money, because he feared liberal backlash. [SOURCE: biography.com; widely documented]

He was also — prosecutors at trial alleged, and a jury agreed — directing the misappropriation of $8 billion in customer funds into a trading firm that he controlled, while telling the world the exchange was fine.

· PART THREE ·
Alameda Research and FTX — Building the Empire

He left Jane Street in 2017. He worked briefly at the Centre for Effective Altruism as development director. Then he started trading Bitcoin.

The opportunity he spotted was arbitrage — the same coin trading at different prices on different exchanges in different countries. In Japan, Bitcoin was trading for roughly 10% more than it was elsewhere. If you could buy it cheaply, move it to Japan, and sell it there, the margin was significant. Within months, Alameda Research — the quantitative trading firm he co-founded — was at times making approximately a million dollars a day. [SOURCE: Encyclopaedia Britannica; Cointelegraph]

He founded FTX in April 2019 with Gary Wang, his MIT fraternity housemate, as co-founder. The exchange launched the following month. FTX was built to be better than the existing crypto exchanges — more sophisticated derivatives products, a cleaner interface, better risk management. It signed naming rights to the Miami Heat's arena in a deal reportedly worth $135 million. [SOURCE: Al Jazeera timeline] Tom Brady and Gisele Bundchen appeared in its advertising. In July 2021, it raised $900 million at an $18 billion valuation. In January 2022, it raised $400 million at $32 billion. [SOURCE: Al Jazeera / Axios timelines]

By 2021, Forbes had named Bankman-Fried the richest person under 30 in the world, with a net worth of approximately $22.5 billion. By the peak it was $26.5 billion. [SOURCE: Forbes / Effective Altruism Forum]

He moved operations to Hong Kong, then in 2021 to the Bahamas. The Bahamas offered a tax environment and a regulatory posture that suited his purposes. He and his colleagues purchased at least 19 properties in the country worth approximately $121 million in total. [SOURCE: Fortune, November 2022] He lived in a $30 million penthouse at the Albany resort compound — a 600-acre property on New Providence island that had hosted Tiger Woods and Justin Timberlake at its grand opening and sold individual homes for tens of millions.

Ten FTX employees lived in the penthouse. One of them was .

· PART FOUR ·
— The Full Section

The brief for this case contains an explicit instruction: must be covered in full detail. She ran Alameda Research, she was his girlfriend, and she was the prosecution's key witness. That is not a side note. This is that section.

was born in November 1994 in Boston, Massachusetts. Her parents — Glenn Ellison and Sara Fisher Ellison — are both MIT economics professors. Like Bankman-Fried, she did not come from nowhere. She came from a household where quantitative economic reasoning was the intellectual medium of daily life.

She attended Stanford University. She then went to Jane Street Capital — the same firm where Bankman-Fried had worked, and where the two had met. This is where she built the trading skills she would later bring to Alameda.

Bankman-Fried persuaded her to join Alameda Research. She was, like him, attracted to the effective altruism framing — the idea that they were earning money in order to give it away to causes that mattered. She rose to become co-CEO of Alameda in 2021. When her co-CEO Sam Trabucco stepped down in August 2022 — three months before the collapse — she became sole CEO.

She and Bankman-Fried were romantically involved. On and off, across years. They lived in the Bahamas penthouse together. The relationship was not beside the work. It was inside it. She ran the firm he had founded. He was, per the DOJ's own sentencing letter, exercising the real control while she held the nominal title of CEO. [SOURCE: DOJ sentencing letter, September 17, 2024]

She directed the use of FTX customer funds to cover Alameda's losses and obligations. She knew the real balance sheet. She knew the gap between what the public statements said and what the numbers actually showed. That knowledge — of the mechanics and the reasoning and the decisions — is what made her testimony at trial decisive.

When FTX collapsed in November 2022 and the federal investigation began, she started speaking to the government before she was charged. She pleaded guilty in December 2022, immediately. She underwent extensive document review. She helped identify evidence in an investigation that was, in the government's words, 'hamstrung by Bankman-Fried's systematic destruction of evidence.' [SOURCE: DOJ sentencing letter, September 17, 2024]

He responded by leaking her private personal writings to the press while they were both facing charges. A federal judge found that this likely amounted to witness tampering and revoked his bail. [SOURCE: Yahoo News / Fortune reporting on the bail revocation] The government's sentencing letter states that she 'persevered despite harsh media and public scrutiny and Bankman-Fried's efforts to publicly weaponize her personal writings to discredit and intimidate her.' [SOURCE: DOJ sentencing letter, September 17, 2024]

She testified in open court in October 2023 and named him. She described what he had directed. She explained the why — the decisions, the reasoning, the conversations. The jury convicted on all seven counts.

On September 24, 2024, Judge Kaplan sentenced her to two years in federal prison. She was tearful in the courtroom. [SOURCE: AP News, September 24, 2024] She was ordered to forfeit $11 billion — a legal forfeiture figure, not a personal theft amount. She has been released.

Bankman-Fried was sentenced to 25 years. Ellison to 2 years. The cooperation credit was 23 years.

· PART FIVE ·
How It Worked — Two Companies, One Pool

The mechanism is simple to state and catastrophic in consequence.

FTX was a cryptocurrency exchange. When customers deposited money on FTX, that money was supposed to sit in FTX's custody — available for trading, available for withdrawal. It was customer money. The exchange held it on their behalf.

Alameda Research was a connected trading firm founded and controlled by Bankman-Fried. It made speculative bets in cryptocurrency markets. A trading firm is not supposed to have access to an exchange's customer deposits. The two entities are supposed to be entirely separate.

At FTX, they were not separate. Alameda borrowed from the FTX customer pool — billions of dollars, used for speculative investments, for political donations, for expensive real estate in the Bahamas, for loans to executives, for obligations the trading firm could not otherwise meet. [SOURCE: Second Circuit opinion, June 12, 2026; DOJ trial record]

The public-facing balance sheets showed a different picture. Investors and customers saw statements that did not reflect the reality of where their money was. When crypto markets fell in 2022 and Alameda's speculative positions lost value, the customer deposits it had been using as a backstop were insufficient. When customers tried to withdraw from FTX, the money was not there.

The new CEO appointed after the bankruptcy — John J. Ray III, who had overseen the Enron bankruptcy — said in a court filing: 'Never in my career have I seen such a complete failure of corporate controls and such a complete absence of trustworthy financial information as occurred here.' [SOURCE: People Matters / court filing, November 2022]

Ray had supervised one of the most notorious corporate collapses in American history. He had not seen anything like this.

· PART SIX ·
Nine Days in November — The Collapse

It took nine days to end it.

Nine days from the CoinDesk article to the bankruptcy filing. Three years of building — the exchange, the Bahamas empire, the effective altruism brand, the political donations, the magazine covers — collapsed in nine days when customers tried to take their money out and discovered it was not there.

· PART SEVEN ·
The Arrest — Bahamas, December 2022

He did not flee. Not right away. After the bankruptcy filing he remained in the Bahamas, giving interviews, posting online, texting journalists, attempting to articulate a version of events in which the collapse was a liquidity crisis rather than a fraud.

He was scheduled to testify before Congress on December 13, 2022. On December 12 — the day before — Bahamian authorities arrested him at the request of the US government, based on a sealed indictment filed by the Southern District of New York. [SOURCE: PBS / AP / SDNY statement]

He was extradited to the United States. He appeared before a federal court in Manhattan. He pleaded not guilty to the charges — wire fraud, securities fraud conspiracy, commodities fraud conspiracy, money laundering conspiracy, and related counts.

Gary Wang and had already pleaded guilty and begun cooperating. Nishad Singh, FTX's engineering director, also pleaded guilty and cooperated. [SOURCE: trial record; Second Circuit opinion]

While on bail, he was accused of sharing Ellison's private personal writings with a reporter, in what a federal judge found 'likely amounted to witness tampering.' His bail was revoked and he was held in pretrial detention. [SOURCE: Fortune / Yahoo News citing federal court record]

· PART EIGHT ·
The Trial — October 2023

The trial opened in October 2023 before Judge Lewis A. Kaplan in the Southern District of New York.

Bankman-Fried's defense strategy was built around a single claim: he had not intended to defraud anyone. He believed FTX was solvent. He believed the customer funds could be returned. The things that went wrong went wrong because of market conditions and poor accounting, not because of fraudulent intent.

The prosecution's response was the people who were there.

Gary Wang, the co-founder who built the code, testified about how the system worked. Nishad Singh, the engineering director, testified about what he had witnessed. And , CEO of Alameda Research and Bankman-Fried's former girlfriend, testified about the decisions, the directions, the conversations, the reasoning. She told the court not just what had happened but why — which is the specific knowledge that only the person closest to the decision-maker possesses.

The government described her testimony as 'a cornerstone of the trial.' [SOURCE: DOJ sentencing letter on Ellison, September 17, 2024]

He testified in his own defense. He maintained he had not intended to defraud. The jury deliberated and returned a verdict.

November 2, 2023 — one year to the day after the CoinDesk balance sheet article — the jury convicted Samuel Bankman-Fried on all seven counts.

· PART NINE ·
25 Years — What the Court Said

On March 28, 2024, Judge Lewis A. Kaplan sentenced Samuel Bankman-Fried to 25 years in federal prison.

Prosecutors sought 40 to 50 years. The defense sought 5 to 6.5 years. Judge Kaplan sentenced him to 25 — below what the prosecution asked for, and roughly four times what the defense asked for. [SOURCE: SDNY sentencing; widely documented]

Bankman-Fried spoke at sentencing. He expressed remorse. He maintained, through lawyers and directly, that he had not acted with the intent the fraud statute requires — that he had genuinely believed the customers could be made whole.

The Second Circuit addressed this directly when it affirmed his conviction in June 2026. Circuit Judge Barrington Parker wrote for the three-judge panel: 'FTX customers were defrauded as soon as Bankman-Fried transferred their money to Alameda regardless of how strongly he believed he might later return the money.' [SOURCE: Bloomberg / Second Circuit, No. 24-961-cr, June 12, 2026]

Temporary misappropriation is still fraud. The intended repayment is not a defence.

· PART TEN ·
What It Means — The Trust of the Smart

Each case in this series has a thesis. A single thing it documents about how fraud works at scale.

: the persona was the marketing. : the speed. : the product was the lie. Madoff: duration was the disguise. Sam Bankman-Fried: the trust of the smart.

He was not just trusted. He was trusted by the people who were most careful about trust. The institutional investors who did due diligence on him. The magazine editors who wrote about him. The effective altruism community that held him up as proof of concept. The senators who invited him to testify about crypto regulation. These were not naive people who simply believed what they were told. They were people who thought about credibility seriously and concluded that his was real.

The fraud ran inside that credibility. It ran inside MIT and Jane Street and the giving pledges and the beanbag and the cargo shorts. It ran inside the persona of the person who was doing this for the right reasons.

And it was exposed not by a regulator, not by an auditor, not by a sophisticated institutional investor who looked past the persona. It was exposed by a balance sheet that a journalist obtained and published. And it was prosecuted successfully because the people closest to him — his co-founder, his engineering director, the woman who ran his trading firm and had been his girlfriend — chose to tell the truth.

She told the truth despite him leaking her diary to the press to stop her. That is the last detail of the case that belongs here.

He is in California, eligible for release in 2044, having applied for a presidential pardon that the White House has signalled it will not grant. The effective altruism community that celebrated him has had to reckon with what he represented and what the framework was actually being used for. The $8 billion in customer funds is the subject of ongoing bankruptcy proceedings. Some customers may recover some of their money.

He broke the trust of the people who were most certain he was the good one. That is the sentence the case leaves behind, beyond the 25 years.

VERIFIED SOURCES

$8B = customer funds misappropriated (loss figure, DOJ/trial record). Different from the $11B forfeiture ordered against Ellison. Bankman-Fried: convicted, sentenced 25 years, appeal denied June 2026, serving California, eligible 2044. Ellison: cooperated, sentenced 2 years, released. Both are in the record. The cooperation credit is 23 years.

[1] US v. Bankman-Fried, 22 Cr. 673 (LAK), SDNY — trial record, 7 counts conviction November 2023, 25-year sentence March 2024
[2] US v. Bankman-Fried, No. 24-961-cr, Second Circuit — June 12, 2026: conviction and sentence affirmed UNANIMOUSLY. Judge Barrington Parker: 'FTX customers were defrauded as soon as Bankman-Fried transferred their money to Alameda regardless of how strongly he believed he might later return the money.' Mandate issued August 4, 2026.
[3] US v. , 22 Cr. 673 (LAK), SDNY — DOJ sentencing letter to Judge Kaplan, September 17, 2024 (source of all Ellison cooperation and diary-weaponisation quotes)
[4] DOJ/SDNY — SBF conviction press release (November 2023); sentencing press release (March 2024)
[5] AP News — 'Tearful gets 2 years in prison over her role in FTX fraud,' September 24, 2024
[6] Reuters — Ellison sentencing, September 24, 2024
[7] CNBC — Ellison $11B forfeiture, September 24, 2024
[8] CoinDesk — original Alameda balance sheet publication, November 2, 2022
[9] Fortune — SBF Bahamas lifestyle / $121M property portfolio (Leo Schwartz, November 2022)
[10] Axios / Al Jazeera / People Matters — FTX collapse timeline; John J. Ray III 'complete failure of corporate controls' quote
[11] The Defiant / Bloomberg / Cointelegraph — Second Circuit ruling and mandate, June–August 2026
[12] Yahoo News / Fortune — bail revocation; judge finding that diary leak 'likely amounted to witness tampering'
[13] biography.com / Encyclopaedia Britannica / Effective Altruism Forum — SBF background, Jane Street, effective altruism, Alameda founding
END OF REPORT
#8 OF 45
Caroline Ellison
SINGLE PERSON
CASE 006 · COOPERATION / FTX INNER CIRCLERELEASED 2026
CEO Alameda Research · star witness · sentenced 2 years · served ~14 months
~$8B
WHAT WAS TAKEN
FTX customers' deposits, their cash and crypto.
HOW
Ran Alameda, the fund that spent the customers' money. Then testified against .
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2017–2018Joins Alameda Research from Jane Street.SOURCE: Reuters
2019–2021Runs Alameda alongside FTX from Hong Kong; rises to co-CEO, then CEO.SOURCE: DOJ sentencing letter; Reuters
2021–Nov 2022As Alameda's CEO, directs the use of FTX customer money to cover Alameda's losses and lenders; keeps the real balance sheet from the public.SOURCE: DOJ sentencing letter, 17 Sept 2024
Nov 2022Tells staff the truth as FTX collapses, then speaks to the government before she is charged.SOURCE: DOJ sentencing letter
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
CAROLINE ELLISON
CEO ALAMEDA RESEARCH · FTX INNER CIRCLE · CASE 006 · SENTENCED 2 YEARS · RELEASED 2026
ROLE
CEO Alameda Research
SENTENCE
2 years · minimum security
FORFEITURE
$11B
PLEA
Guilty Dec 2022 · 7 charges
SENTENCED
September 24, 2024
RELEASED
Released 2026 · sentenced 2 yrs · served ~14 months [Wikipedia]
JUDGE
Hon. Lewis Kaplan · SDNY
KEY ROLE
Star prosecution witness — 3 days testimony
FULL PROFILE

IDENTITY

LEGAL NAME
Caroline Ellison
AGE AT SENTENCING
29 years old (September 2024)
EDUCATION
Stanford University · Mathematics
ROLE AT FTX
CEO of Alameda Research · FTX’s sister hedge fund
RELATIONSHIP
On-and-off girlfriend of
PLEA DATE
December 2022 — one month after FTX collapse

CASE RECORD

CHARGES
2x wire fraud · 2x conspiracy wire fraud · conspiracy securities fraud · conspiracy commodities fraud · conspiracy money laundering — 7 counts total
MAX EXPOSURE
~110 years
COOPERATION
Pleaded guilty Dec 2022 · cooperated fully · testified 3 days at trial
PROBATION REC.
Time served (no prison) — recommendation rejected by judge
SENTENCE
24 months · minimum-security prison
FORFEITURE
$11B ordered
SERVED
14 months in federal custody
RELEASED
2026 [Wikipedia / case record]
HER ROLE IN THE FRAUD

WHAT ELLISON DID — AND WHAT SHE SAID AT TRIAL

01
She ran the fund that received the stolen money. As CEO of Alameda Research, Ellison oversaw the hedge fund that received billions in FTX customer deposits funneled through the backdoor had built. Alameda’s trading losses and obligations were covered with customer money. [SOURCE: DOJ · NBC News]
02
She fabricated the balance sheets. Ellison admitted she falsified Alameda’s quarterly balance sheets to hide the billions FTX was lending to Alameda from its lenders. A specific spreadsheet she produced — identified by her cooperation — became the centrepiece of the government’s case. [SOURCE: The Register · trial record]
03
She testified for three days. Her testimony at ’s October 2023 trial described in detail how directed the scheme. The key line: she told prosecutors “knew it was wrong” and “knew it was criminal.” Judge Kaplan cited this specifically at sentencing. [SOURCE: CNBC · trial record]
04
She said she should have left. Her defense attorney argued she had “recovered her moral compass” and “profoundly regrets not having left ’s orbit.” Ellison addressed the court directly — read a statement, apologized to those she hurt, expressed shame. [SOURCE: NBC News · Al Jazeera]
JUDGE KAPLAN — SENTENCING SEPTEMBER 24 2024

FROM THE BENCH

“I’ve seen a lot of cooperators in 30 years here. I’ve never seen one quite like Ms. Ellison.” [SOURCE: CNBC · Al Jazeera]
“There’s no way you’re ever going to do something like this again, I am persuaded. But here’s the thing: this was, if not the very greatest financial fraud ever perpetrated in this country or anywhere else, close to it.” [SOURCE: Al Jazeera]
“I keep coming back to Ms. Ellison’s testimony that he knew it was wrong. He knew it was criminal.” — Kaplan at ’s sentencing, citing Ellison [SOURCE: CNBC]
Probation dept. recommended: no prison. Defense sought: no prison. Judge sentenced: 24 months. The magnitude of the fraud overrode the cooperation discount — but the cooperation reduced 110 possible years to 2. [SOURCE: CNBC · NBC News · The Register]
CASE TIMELINE
Nov 1994
Born, Boston, Massachusetts
both parents MIT economics professors
SOURCE: Reuters / Boston Globe
UNDATED
Stanford University (BS)
then Jane Street, quantitative trading
SOURCE: Reuters
2017
Alameda Research founded by
she joins and later rises to run it
SOURCE: Reuters
UNDATED
Becomes CEO of Alameda Research
the DOJ's "nominal CEO"
SOURCE: DOJ sentencing letter, 17 Sept 2024
Nov 2022
FTX collapses
she speaks to the government before she is charged
SOURCE: DOJ sentencing letter
Dec 2022
Charged on 7 counts
pleads guilty at once and begins cooperating
SOURCE: US v. Ellison, 22 Cr. 673 (LAK)
Oct 2023
Testifies in open court against
SOURCE: Trial record, US v.
17 Sept 2024
Government's sentencing letter
her testimony "a cornerstone of the trial"
SOURCE: DOJ sentencing letter
24 Sept 2024
Sentenced to 2 years
$11 billion forfeiture ordered — Judge Kaplan, SDNY
SOURCE: AP / CNBC / court record
UNDATED
Released (per public record)
SOURCE: Case-file card

WHAT THIS CASE ESTABLISHED

Cooperation is the strongest mitigating factor in a financial fraud prosecution — and has limits. 110 years possible became 2 years delivered. The fraud’s scale set the floor even cooperation couldn’t remove.
Her testimony — three days — was the prosecution’s core evidence. "He knew it was wrong. He knew it was criminal." The line that convicted came from Ellison.
She ran the fund that received the stolen money and signed the false balance sheets. Cooperation did not erase participation — it altered the consequence.
The probation department’s recommendation of no prison was rejected. The judge found the fraud’s scale required a custodial sentence regardless of cooperation quality.
$11B forfeiture was ordered alongside the 2-year sentence — the financial accountability is separate from the prison term and is not reduced by cooperation.
She served 14 months and was released January 2026. The cooperation that made ’s 25-year conviction possible cost her 14 months of freedom.
CROSS-REFERENCE

CONNECTED CASE

and Case 006 are the same fraud, two different roles, two different choices. maintained his innocence, testified, and was convicted on all 7 counts. Ellison pleaded guilty immediately, cooperated fully, testified against him for three days, and served 14 months. The outcomes — 25 years vs 14 months — are the clearest illustration in this series of what cooperation means inside the federal sentencing system.

BIOGRAPHY & FULL CONTEXT

BACKGROUND

FULL NAME
Caroline Ellison
BORN
November 1994 · Boston, Massachusetts · age 31
PARENTS
Glenn Ellison (MIT economics professor) · Sara Fisher Ellison (MIT economics professor)
EDUCATION
Stanford University · undergraduate degree
PRE-ALAMEDA
Jane Street Capital — elite quantitative trading firm · same firm where previously worked · met there
THE JANE STREET PIPELINE
MIT/Stanford → Jane Street → crypto was the specific pipeline that produced several FTX inner circle members
RELATIONSHIP
Romantic partner of — on and off across years the operation ran · relationship was inside the work, not beside it
EFFECTIVE ALTRUISM
Both she and subscribed to the EA framework — 'earning to give' — which framed the operation's stated purpose

THE COOPERATION — EVERY DETAIL

TIMING
Began cooperating BEFORE she was charged — started talking to government during FTX collapse
PLEA
Guilty · December 2022 · immediately · 7 counts
DOCUMENT REVIEW
Extensive — identified key evidence in investigation 'hamstrung by 's systematic destruction of evidence' [DOJ]
CONSISTENCY
Her statements were 'notably consistent' with what she said during FTX collapse — before she knew of any investigation [DOJ]
TESTIMONY
Testified for multiple days at trial · October 2023 · held account under cross-examination
DOJ CHARACTERISATION
"Cornerstone of the trial" · "uniquely positioned to explain not only the what and how...but also the why" [DOJ Sept 17 2024]
THE DIARY
leaked her private personal writings to press to discredit/intimidate her while facing same charges · judge found this 'likely amounted to witness tampering' · bail revoked [Yahoo News / Fortune]
RESPONSE TO DIARY LEAK
She testified anyway. That is the complete sentence.

THE 23-YEAR MATH

: 25 years. Ellison: 2 years. The gap is 23 years. That is the cooperation credit in this case.
She cooperated before charges. Pleaded guilty immediately. Underwent extensive document review. Testified in open court. Held her account under cross-examination. Did all of this after he tried to destroy her credibility with her own diary.
The DOJ's sentencing letter lists every element: started before charges, document review in hamstrung investigation, notable consistency from before any investigation, remarkable candor and remorse. Each is a tick on the credit ledger.
She committed, in the government's own language, 'grave misconduct.' She directed the use of FTX customer funds. She knew the real balance sheet while the public statement said something different. Both of these things are true about the same person — the misconduct and the cooperation.
She has been released. She is 31 years old. The record is the record and it is complete.
THE FULL STORY — 9 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — SHE TESTIFIED ANYWAY (2,700 WORDS)
Sources: US v. Caroline Ellison, 22 Cr. 673 (LAK), SDNY · DOJ sentencing letter to Judge Kaplan, September 17, 2024 · Ellison sentencing memorandum, September 10, 2024 · AP News · Reuters · CNBC · Boston Globe · New York Times · Wikipedia (aggregator — verified to primary). $11B = forfeiture ordered (legal figure, not a personal theft amount). Different from the $8B FTX customer-fund loss figure. She is a living person, released, who cooperated. Report per the court record only.
· PROLOGUE ·
The One Who Could Explain the Why

She was the only person who could explain the why.

Not the what — the mechanics of how FTX customer funds moved to Alameda Research could eventually be reconstructed from the code, the financial records, the blockchain. Not the how — the documents and digital trail, even the ones had allegedly destroyed, could be recovered with forensic effort. The what and the how were things investigators could, in principle, piece together from evidence.

The why required her.

She had run his firm. She had been his girlfriend. She had sat in the rooms where the decisions were made and understood the reasoning — what he had believed, what he had decided not to believe, what he had said and done when the math started not adding up. She was, in the government's precise phrase, 'uniquely positioned to explain not only the what and how of 's crimes, but also the why.' [SOURCE: DOJ sentencing letter, September 17, 2024]

She pleaded guilty in December 2022 — immediately, before the year was out. She began cooperating before she was charged. She testified in open court in October 2023 and named him. She told the court everything she knew.

While she was preparing to testify, he leaked her private diary to a reporter.

She testified anyway.

· PART ONE ·
Boston, November 1994 — Where She Came From

Caroline Ellison was born in November 1994 in Boston, Massachusetts.

Her parents are Glenn Ellison and Sara Fisher Ellison — both professors of economics at MIT. [SOURCE: CNBC / Reuters / case brief] The family is not background detail. It is essential context. She grew up in a household where quantitative economic reasoning was the medium of daily intellectual life. Where the way you evaluated a claim was to ask what the evidence showed and how the mechanism worked. Where rigour was a household value before it was a professional one.

She attended Stanford University for her undergraduate degree. From Stanford she went directly to Jane Street Capital — the elite quantitative trading firm that has a specific kind of reputation in financial circles: selective, sophisticated, producing people who are exceptionally good at a particular kind of numerical reasoning under uncertainty. It is where had also worked. It is where the two of them met.

She was drawn to the effective altruism framework that and others in their circle subscribed to — the idea that the right way to do the most good in the world was to earn as much as possible and donate it as effectively as possible to causes that reduced the most suffering. As a fellow effective altruist, she was attracted to the prospect of earning money in order to give it to charity. [SOURCE: Yahoo News / Fortune]

He persuaded her to join Alameda Research, the quantitative cryptocurrency trading firm he had founded in 2017. She did. She rose through the organisation. She became co-CEO of Alameda in 2021. When her co-CEO Sam Trabucco stepped down in August 2022 — three months before the collapse — she became sole CEO.

She was 28 years old when FTX filed for bankruptcy. She was 28 when she pleaded guilty. She was 28 when she testified. She was 29 when she was sentenced. She is 31 now.

· PART TWO ·
The Relationship — Inside the Operation

The relationship between Caroline Ellison and was not beside the operation. It was inside it.

They had met at Jane Street. He recruited her to Alameda. She ran the firm he had founded. He founded and ran the exchange, FTX, that the firm he had founded was secretly borrowing from. They lived together in the Bahamas — in the $30 million penthouse at the Albany compound on New Providence island where and ten FTX colleagues lived and worked. [SOURCE: Fortune / biography.com]

The romantic relationship was on and off across years — from approximately 2018 until mid-2022, in the period before the collapse. [SOURCE: biography.com; Yahoo News] It was, throughout, concurrent with the professional relationship: she ran his firm, he ran the empire, and the two companies they each led were secretly entangled in a way that would eventually consume both of them.

The DOJ's sentencing letter describes her as Alameda's 'nominal CEO' — the government's own language establishing that while she held the CEO title, the decision-making authority ran to . [SOURCE: DOJ sentencing letter, September 17, 2024] That distinction is part of her legal record, part of her cooperation, and part of the context of the relationship. She ran the firm. He controlled it.

She was, before the collapse, unhappy. The New York Times published an article in July 2022 — based on her personal writings — in which she described feeling 'unhappy and overwhelmed' at work and 'hurt/rejected' by a breakup with . [SOURCE: Yahoo News citing NYT]

Those writings would become the instrument he used against her.

· PART THREE ·
What She Did — The Fraud Role, Stated Plainly

Alameda Research was the vehicle through which FTX customer deposits were misappropriated. She ran Alameda Research.

Customer funds deposited on FTX — the exchange — were used by Alameda to cover the trading firm's losses, service its obligations, and fund an operation that included expensive real estate in the Bahamas, speculative investment positions, and political donations. The two entities were not kept separate as they were supposed to be. [SOURCE: DOJ trial record; Second Circuit opinion, June 2026]

She directed the use of customer funds to cover Alameda's losses and obligations. She knew the real balance sheet — the one that showed the true state of things — while the public-facing disclosures said something different. That gap between private knowledge and public statement is the core of the fraud she participated in.

The government's sentencing letter is precise about this: she was 'forthcoming about her own grave misconduct and the role she played in furthering 's scheme and its concealment.' [SOURCE: DOJ sentencing letter, September 17, 2024]

Grave misconduct. That is the government's language. She committed it. That is in the record and it belongs in this piece. So is the full context of what she did with that record when the operation ended.

· PART FOUR ·
The Cooperation — Before She Was Charged

When FTX collapsed in November 2022 and the federal investigation began, Caroline Ellison started talking to the government.

Not after her lawyer negotiated a deal. Not after she understood the full scope of what she was facing. Before she was charged. [SOURCE: DOJ sentencing letter, September 17, 2024 — stated directly in the filing]

She was charged in December 2022 with seven counts: wire fraud, securities fraud, money laundering conspiracy, and related charges. She pleaded guilty the same month. Immediately. She did not contest the charges. She did not seek to litigate the facts. She said she had done what the government said she had done and began helping them build the case.

Over the months that followed, she participated in what the government described as extensive document review — work that identified key corroborating evidence in an investigation that had been hamstrung by 's systematic destruction of evidence. He had tried to eliminate the record. She helped reconstruct it. [SOURCE: DOJ sentencing letter, September 17, 2024]

Her statements during the cooperation were, the government noted, 'notably consistent' with what she had said during the collapse of FTX — before she had any reason to believe she was being investigated. She had not changed her story to fit a plea deal. Her account of what had happened was the same before and after the federal investigation began. [SOURCE: DOJ sentencing letter]

· PART FIVE ·
The Diary — What He Did

While Caroline Ellison was cooperating with federal investigators and preparing to testify against , he leaked her private personal writings to a reporter.

The New York Times published an article in July 2022 — before the collapse — based on her personal writings in which she described feeling unhappy and overwhelmed at work. [SOURCE: Yahoo News citing NYT, July 2022] Those writings were personal. They were not intended for publication.

After the collapse, after the charges, after she had pleaded guilty and was cooperating with the government, allegedly shared her personal writings with a reporter — this time to try to damage her credibility as a witness. A federal judge found that this action 'likely amounted to witness tampering' and revoked his bail. He was held in pretrial detention for the remainder of the pre-trial period. [SOURCE: Yahoo News / Fortune, citing federal court record]

The government's sentencing letter to Judge Kaplan addresses this directly.

This piece does not quote her private writings. It will not. The government's own filing documents that those writings were weaponised against her. Quoting them would repeat that act. What this piece reports is that he did it, that a federal judge found it was likely witness tampering, that it was documented in a government filing, and that she testified anyway.

She was publicly humiliated with her own words. By the man she had loved. By the man she had worked for. By the man she was about to testify against in open federal court. He did it while facing the same charges she did.

She went to court and named him anyway.

· PART SIX ·
The Testimony — October 2023

On October 10, 2023, Caroline Ellison took the stand in the trial of in the Southern District of New York.

She testified about the mechanics of what had happened — how Alameda had used FTX customer funds, how the balance sheets had been constructed, how the gap between the private reality and the public statements had been maintained. She provided the kind of granular, first-hand account of decisions and conversations and reasoning that only someone who was there and paying attention could provide.

She also testified about the relationship. About the conversations between her and . About what he had known, what he had directed, what he had said when things were going wrong. The government had called her 'uniquely positioned' to explain the why — and that uniqueness rested on the fact that she had been both his closest professional partner and his romantic partner. She knew the public man and the private one. She knew what he said in the rooms that mattered.

She testified for multiple days. She was cross-examined by his defense lawyers. She held to her account.

The jury convicted on all seven counts on November 2, 2023 — one year to the day after the CoinDesk balance sheet article that had started the collapse.

· PART SEVEN ·
The Sentencing — September 24, 2024

On September 24, 2024, Caroline Ellison stood before Judge Lewis A. Kaplan in the Southern District of New York.

She was tearful. The AP's headline: 'Tearful Caroline Ellison gets 2 years in prison over her role in FTX fraud.' [SOURCE: AP News, September 24, 2024]

Her parents had written to the judge ahead of sentencing — Glenn Ellison and Sara Fisher Ellison, both MIT economics professors, writing on behalf of their daughter. The New York Times published the letter. [SOURCE: NYT — verify contents before quoting directly]

She spoke to the court. She expressed remorse. The government's letter had already described her as showing 'remarkable candor, remorse, and seriousness' throughout the cooperation period.

· PART EIGHT ·
What the Court Said About Her

The government's sentencing letter to Judge Kaplan, dated September 17, 2024, is the primary document on her cooperation. It runs through every element of what she did and why it mattered. The direct quotes are the record. They belong here in full.

· PART NINE ·
What It Means — The One Who Told

This series has a thesis for each case. A single thing the case documents about how fraud works at scale, and about the people inside it.

: the persona was the marketing. : the speed. : the product was the lie. Madoff: duration was the disguise. : the trust of the smart. Caroline Ellison: the one who knew, and told.

She is not the usual template for a case in this series. She is not primarily the fraudster, though she committed grave misconduct. She is not primarily the victim, though she was betrayed by the person she had worked for and loved. She is not primarily the hero, though the prosecution's most important witness is the closest the criminal justice system gets to one.

She is something more complicated: a person who made catastrophically wrong choices, who recognised them for what they were when she had the chance to do so, and who chose to tell the truth when telling the truth was both the legally optimal and the most costly personal choice available to her.

The legally optimal part: she understood that full cooperation was the fastest path to the shortest sentence. The most costly personal part: she was cooperating against the man she had loved, who was also weaponising her private writings to try to stop her. She did both things simultaneously. The cooperation track and the personal betrayal ran at the same time.

Her testimony is the reason the jury had what it needed to convict. Her document review is the reason the prosecution had evidence in a case where the defendant had systematically destroyed it. Her pre-investigation statements are the reason the government could establish that she had not changed her story to fit a deal.

She was the only person who could explain the why. And she did. In open court. On the record. Under cross-examination. While her former partner's lawyers tried to pick apart what she said.

She was sentenced to two years. She has been released. She is 31 years old. She has the rest of her life ahead of her, carrying the things she did and the things she chose when it ended.

VERIFIED SOURCES

Her private writings are not quoted in this piece. The DOJ filing documents that they were weaponised against her. Quoting them would repeat the act. What is reported: that it happened, that a judge found it was likely witness tampering, that it is in the government filing. She is a living person, released, who cooperated. Report per the court record only.

[1] PRIMARY US v. Caroline Ellison, 22 Cr. 673 (LAK), SDNY — plea, cooperation, sentence
[2] DOJ SENTENCING LETTER Government's sentencing letter to Judge Kaplan, September 17, 2024 — source of all direct quotes in this document. Contains: 'cornerstone,' 'uniquely positioned,' 'nominal CEO,' 'before she was ever criminally charged,' 'systematic destruction of evidence,' 'grave misconduct,' 'weaponize her personal writings,' 'remarkable candor.'
[3] SENTENCING MEMO Ellison sentencing memorandum, September 10, 2024, SDNY
[4] AP NEWS 'Tearful Caroline Ellison gets 2 years in prison over her role in FTX fraud,' September 24, 2024
[5] CNBC Ellison sentenced to 2 years, ordered to forfeit $11 billion, September 24, 2024
[6] REUTERS ''s ex-girlfriend Ellison gets two-year sentence over FTX fraud,' September 24, 2024
[7] NEW YORK TIMES Parents' letter to Judge Kaplan (verify contents before quoting directly)
[8] YAHOO NEWS / FORTUNE Bail revocation — judge found diary leak 'likely amounted to witness tampering'
[9] YAHOO NEWS / BOSTON GLOBE Background on Ellison — MIT professor parents, Stanford, Jane Street, Alameda role
[10] SECOND CIRCUIT US v. , No. 24-961-cr — June 12, 2026 (names Ellison, Wang, Singh as cooperating witnesses)
END OF REPORT
#9 OF 45
Allen Stanford
SINGLE PERSON
CASE 010 · CD FRAUD / PONZI110 YEARS
Sir Allen (knighthood stripped) · Stanford International Bank
$7.2B
WHAT WAS TAKEN
Investors' savings, put into certificates of deposit at his bank in Antigua.
HOW
Promised safe, high returns, then used the money as his own.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1990s–2009Stanford International Bank sells ~$7B of certificates of deposit with returns paid from new money; he is knighted by Antigua.SOURCE: SEC complaint, 17 Feb 2009
Aug 2008Lands a helicopter at Lord's with a $20M prize for the Stanford Super Series.SOURCE: case brief
1980s–2009Stanford Financial Group headquarters; the FBI raids Houston, Memphis and Tupelo on 18 Feb 2009.SOURCE: DOJ; SEC
2012Convicted in Houston and sentenced to 110 years.SOURCE: S.D. Tex.
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
ROBERT ALLEN STANFORD
SIR ALLEN STANFORD (KNIGHTHOOD STRIPPED) · CD FRAUD · CASE 010 · CONVICTED 2012 · SERVING 110 YEARS
INVESTOR LOSSES
$7.2B
METRIC
Investor funds defrauded · DOJ/jury verdict
VICTIMS
20,000+ · 100+ countries
SENTENCE
110 years · June 14, 2012
SERVING AT
USP Coleman II · Florida · high security
RELEASE DATE
March 13, 2103 [BOP record]
BORN
March 24, 1950 · Mexia, Texas
KNIGHTHOOD
Antigua 2006 · stripped post-conviction
FULL PROFILE

IDENTITY

LEGAL NAME
Robert Allen Stanford
BORN
March 24, 1950 · Mexia, Texas
EDUCATION
Baylor University · Finance · 1974
FIRM
Stanford International Bank · Antigua · Stanford Financial Group (US)
PRODUCT
Certificates of deposit · promised 10–15%+ returns
COVER
Cricket sponsorship · Antiguan knighthood · political donations · stadium
ANTIGUAN CITIZEN
Acquired Antiguan citizenship · “Sir Allen” from 2006

CASE RECORD

CASE
US v. Stanford, 4:09-cr-00342-001 · S.D. Texas (Houston)
INDICTED
June 2009 · 21 counts
ARRESTED
June 18, 2009 (surrendered)
TRIAL
January–March 2012 · Houston
JUDGE
Hon. David Hittner · S.D. Texas
VERDICT
Guilty · 13 of 14 counts · March 6, 2012
SENTENCED
110 years · June 14, 2012
KEY COOPERATOR
James Davis · CFO · former college roommate · pleaded guilty & testified
SCHEDULE RELEASE
March 13, 2103 [Bureau of Prisons]
HOW THE FRAUD WORKED

THE CD FRAUD — LEGITIMACY AS ARCHITECTURE

01
The product: Certificates of deposit at Stanford International Bank, Antigua. A CD is among the most conservative financial instruments that exist. Stanford’s CDs offered 10–15%+ returns when conventional CDs paid 3–4%. The pitch: a sophisticated team generating above-market returns through a diversified liquid portfolio. [SOURCE: DOJ/SEC trial record]
02
The reality: The investment portfolio did not exist as described. Investor money funded Stanford’s personal lifestyle — private jets, yachts, real estate, political donations, cricket sponsorship — and paid earlier investors’ returns from new deposits. Classic Ponzi mechanics inside a legitimate banking charter. [SOURCE: DOJ sentencing; SEC civil filings]
03
The architecture of legitimacy: A real bank, a real charter, real employees, real regulatory oversight. The Antiguan knighthood. The cricket stadium. Millions in political donations to US and Caribbean politicians. The Lord’s moment: a Perspex box with $20M in cash, on the pitch at Lord’s Cricket Ground. Each real element made questioning the bank feel like ingratitude. [SOURCE: widely documented]
04
The SEC failure: The SEC had examined Stanford’s operation — late 1990s and subsequently — and found returns similar to a Ponzi scheme. It did not act decisively. The scheme ran for years longer. This is documented in the public record and belongs in the case history alongside the fraud itself. [SOURCE: SEC civil proceedings; widely documented]
THE LORD’S MOMENT — AUGUST 2008

THE $20M BOX AT LORD’S CRICKET GROUND

In August 2008, Allen Stanford landed a helicopter on the outfield at Lord’s — the most famous cricket venue in the world — carrying a Perspex box containing $20 million in cash. He announced the Stanford Super Series: West Indies XI vs England, $20M prize, the largest in cricket history. His West Indies team won. The prize was paid. Six months later, federal agents were chasing him through Houston streets. The $20M had come from investors who believed their money was in conservative CDs generating steady returns. [SOURCE: widely documented from collapse timeline]

CASE TIMELINE
24 Mar 1950
Born, Mexia, Texas
SOURCE: case brief (sources listed in its SOURCES part)
1974
Graduates Baylor
BA finance
SOURCE: case brief (sources listed in its SOURCES part)
1980s
Enters financial services
gymnasium business in Waco fails; moves into banking in the Caribbean
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Establishes Stanford International Bank in Antigua
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Knighted by Antigua
takes "Sir Allen"
SOURCE: case brief (sources listed in its SOURCES part)
Aug 2008
Lord's helicopter + $20M cash prize
the Stanford Super Series
SOURCE: case brief (sources listed in its SOURCES part)
17 Feb 2009
SEC charges him
"massive ongoing fraud," ~$7B in CDs
SOURCE: case brief (sources listed in its SOURCES part)
18 Feb 2009
FBI raids offices in Houston, Memphis, Tupelo
SOURCE: case brief (sources listed in its SOURCES part)
27 Feb 2009
SEC amends complaint
calls it a "massive Ponzi scheme"
SOURCE: case brief (sources listed in its SOURCES part)
18 Jun 2009
Surrenders voluntarily
SOURCE: case brief (sources listed in its SOURCES part)
Oct–Nov 2009
Knighthood revoked
SOURCE: case brief (sources listed in its SOURCES part)
Feb 2011
Issues a $7.2B counter-claim against the FBI and SEC (his claim
rejected)
SOURCE: case brief (sources listed in its SOURCES part)
6 Mar 2012
Convicted
all charges except one wire fraud count
SOURCE: case brief (sources listed in its SOURCES part)
14 Jun 2012
Sentenced to 110 years · forfeiture $5.9B
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Incarcerated at Coleman II, Florida
SOURCE: case brief (sources listed in its SOURCES part)

WHAT THIS CASE ESTABLISHED

Legitimacy was the architecture. A real bank, a real charter, a real knighthood, a real cricket stadium — every authentic element made the fraudulent centre harder to question.
The SEC examined Stanford and found Ponzi-like characteristics. It did not act. The scheme ran longer. This is the second case in this series (after Madoff) where documented regulatory examination preceded collapse without decisive intervention.
The cricket connection was not incidental. Stanford understood that cultural investment in the Caribbean — cricket, the sport through which islands found collective identity — bought a form of credibility no certificate could.
His victims were primarily middle-class investors from Latin America and the Caribbean who put savings into something that looked like the most conservative investment available: a bank CD.
Stanford’s 2016 BBC interview: refuses to apologise. Describes the receivership as “a court-sanctioned theft of unimaginable proportions.” Still working on his case from Coleman II. Scheduled release: March 13, 2103.
Series thesis, Case 010: legitimacy was the architecture. The fraud ran inside something real. The question the architecture was designed to produce: “How can this be a fraud? Look at the stadium, the employees, the charter.”
THE CRICKET, THE KNIGHTHOOD & THE COVER

CULTURAL INFRASTRUCTURE

KNIGHTHOOD
2006 · Knighted by Antigua and Barbuda · Sir Allen Stanford · stripped post-conviction
CRICKET STADIUM
Built Stanford Cricket Ground in Antigua · hosted international matches · community anchor
THE LORD'S MOMENT
August 2008 · helicopter landed at Lord's Cricket Ground London · Perspex box containing $20M cash
STANFORD SUPER SERIES
Announced $20M prize — largest in cricket history · his West Indies XI beat England · paid from investor funds
POLITICAL DONATIONS
Contributions to Antiguan government officials · US politicians in both parties · cultivated regulatory protection
CHARITABLE WORKS
Schools, hospitals, community projects in Antigua · integral to island economy · major employer
THE FUNCTION
The knighthood, stadium, charities, cricket were not vanity — they were the legitimacy architecture that made questions feel disrespectful

THE SEC FAILURE & COLLAPSE

SEC EXAMINATION
Late 1990s and subsequent years — SEC found concerns 'similar to a Ponzi scheme' [SEC record]
FAILURE TO ACT
Despite examination and documented concerns, SEC did not halt the scheme — parallel to Madoff/Markopolos
2008 CRISIS
Financial crisis triggered massive CD redemption requests · scheme could not pay · same mechanism as Madoff
FEB 2009 COLLAPSE
SEC filed civil charges · federal agents dispatched · Stanford fled · arrested June 2009
COOPERATING WITNESS
James Davis — Baylor roommate turned CFO — pleaded guilty 2009 and testified against Stanford
RECOVERY
Ralph Janvey appointed receiver · years of asset recovery · partial victim distribution ongoing
BBC INTERVIEW 2016
Stanford from prison: calls receivership 'court-sanctioned theft' · refuses to admit wrongdoing · still working on case
SUPREME COURT
Filed No. 23A401 — application for extension · Justice Alito granted to February 2024 · outcome unconfirmed

SERIES DISTINCTION — LEGITIMACY AS ARCHITECTURE

Stanford did not build a fake institution and pretend it was real. He built REAL institutions — a real bank with a real charter, real staff, real Antiguan regulatory relationships — and used the authentic structure as the container for a fraudulent core.
The cricket sponsorship was real. The stadium was real. The knighthood was real. All of it served the same function: it made questioning the bank feel like questioning a man who had devoted himself to cricket and the Caribbean. Doubt became ingratitude.
Compare to Ignatova (): there was no blockchain. The product had nothing beneath it. Stanford's fraud was the opposite: a real institution with a fraudulent centre. Both arrived at the same result — billions stolen. The architecture differed.
The SEC had looked. It had found concerns similar to a Ponzi scheme. It did not act decisively. This is the same dynamic as Madoff/Markopolos: an institution with enough authentic complexity that regulatory examination produced uncertainty rather than clarity.
THE FULL STORY — 10 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE BOX AT LORD’S (3,500 WORDS)
Sources: US v. Stanford, 4:09-cr-00342-001, S.D. Tex. Houston · DOJ/US Attorney S.D. Tex. conviction and sentencing releases · SEC v. Stanford (civil proceedings) · Reuters · AP · CNN · BBC (interview January 2016) · Cayman News Service · Nation News (Barbados) · Wikipedia (aggregator — verified to primary where possible). $7.2B = investor funds defrauded per DOJ/jury verdict. SEC had previously investigated and found similar concerns — the regulatory failure is part of the record.
· PROLOGUE ·
The Man Who Landed a Helicopter at Lord's

In August 2008, Allen Stanford landed a helicopter on the outfield at Lord's Cricket Ground in London — the most famous cricket venue in the world, the spiritual home of the sport, a ground so steeped in tradition that its rules and conventions are maintained by an institution that has existed since 1787.

He stepped out carrying a Perspex box. Inside the box was $20 million in cash.

He was announcing a cricket tournament. The Stanford Super Series: a one-off match between his West Indies XI and England, for $20 million. The winning team would split the prize. Players on the winning side would receive approximately $1 million each. It was the largest prize in cricket history at the time. It was framed as a transformative gesture — a Texan billionaire who loved cricket so much he was willing to pay the biggest prize ever seen to celebrate it.

The Antiguan government had knighted him. The English cricket establishment welcomed him. The players were photographed laughing with him at the ground, some of them sitting in his helicopter. The image of the Perspex box and the $20 million was on the front pages.

Six months later, in February 2009, federal agents were chasing him through the streets of Houston. He was accused of running a $7.2 billion fraud. The $20 million prize was funded by the Stanford International Bank operation — money raised from CD investors whose principal was not invested as described, but used to fund the lifestyle and marketing of a man presenting himself as the Caribbean’s most significant financier.

· PART ONE ·
Mexia, Texas — The Fifth-Generation Texan

Robert Allen Stanford was born on March 24, 1950, in Mexia, Texas — a small city in Limestone County, in the central part of the state, the kind of place that produces people who describe themselves, with pride, as being from somewhere real.

He described himself as a fifth-generation Texan. He was Baylor University educated — a degree in finance, 1974. He was large, physically imposing, gregarious, a man who occupied space with the specific confidence of someone who had decided early that the rooms he was in should know he was there.

He got into financial services in the early 1980s, starting with a gymnasium business in Waco, Texas, that eventually folded. He moved toward banking and investment. By the mid-1980s, he had established himself in Montserrat — a small Caribbean island — with a bank. The bank in Montserrat was later closed by regulators.

He moved to Antigua. He built Stanford International Bank there. He built a relationship with Antigua that would sustain his operation for decades, providing the offshore banking jurisdiction, the regulatory environment, and the political relationships that the scheme required to function.

He acquired Antiguan citizenship. He contributed millions to Antiguan politicians and to politicians in the United States and elsewhere. He sponsored cricket — building a stadium in Antigua, funding matches, positioning himself as the man who brought serious money to the sport that the Caribbean took most seriously.

In 2006, Antigua knighted him. He was Sir Allen thereafter.

· PART TWO ·
Stanford International Bank — The CD Fraud

The product was a certificate of deposit. A certificate of deposit — a CD — is among the most conservative financial instruments that exist. You deposit money with a bank. The bank holds it for a fixed term and pays you a fixed interest rate. At maturity, you get your principal back with interest. It is low-risk. It is simple. It is the savings instrument of choice for people who do not want complexity, do not want exposure, and do not want to think about it.

Stanford International Bank offered CDs. What made them attractive: the yields. In an environment where conventional CDs paid 3–4%, Stanford's CDs paid 10–15% or more. The pitch was that the bank's investment team was sophisticated enough to generate these returns through a diversified portfolio of liquid assets. [SOURCE: DOJ / SEC / widely documented from trial record]

Investors were told the CDs were safe, backed by a genuine investment portfolio, managed by a skilled team. The bank's financial statements were provided. The statements showed the returns being generated. The statements were fabricated.

What was actually happening: investor money was used to pay earlier investors — the classic Ponzi mechanism — and to fund Stanford's personal lifestyle. The personal lifestyle included private jets, yachts, a $20 million cricket tournament, real estate, political donations, and the comprehensive infrastructure of a man presenting himself as one of the richest and most significant figures in the Caribbean. [SOURCE: DOJ sentencing; SEC civil filings]

More than 20,000 investors across more than 100 countries put approximately $7.2 billion into Stanford International Bank CDs. [SOURCE: DOJ conviction release; Reuters] Many of them were from Latin America and the Caribbean — middle class investors who trusted the institution, trusted the returns, and trusted the man who was building cricket stadiums and getting knighted by island governments.

· PART THREE ·
Antigua — The Island He Built and Used

Antigua is a small island of about 80,000 people in the Eastern Caribbean. It is beautiful — coral beaches, warm water, the kind of landscape that makes people who visit wonder why they live where they do. It is also, as a financial jurisdiction, a place where a sophisticated operator with money and political connections could arrange matters to his advantage.

Stanford arranged matters to his advantage. He was one of the largest private employers on the island. He built Stanford International Bank there. He built a cricket stadium — the Stanford Cricket Ground — that could host international matches. He funded charitable works. He cultivated deep relationships with the Antiguan government, contributing millions to politicians and political causes.

The Antigua Financial Services Regulatory Commission was responsible for overseeing his bank. It did not detect the fraud. This is consistent with the pattern visible in both the Madoff and Stanford cases: the regulatory body responsible for oversight failed to identify what was happening until the scheme collapsed.

Stanford's Antiguan citizenship was practical as well as symbolic. His position as a major figure in Antiguan economic life gave him a form of protection and credibility that a straightforward foreign operator would not have had. He was not a visitor running a scheme from the island. He was part of the island's economic fabric — which made the scheme harder to question and harder to close.

He was knighted by the Antiguan government in 2006 — 'Sir Allen' was how he was addressed and how he introduced himself. The knighthood was later stripped following his conviction.

· PART FOUR ·
The SEC — Who Looked and Did Not See

The Securities and Exchange Commission had looked at Allen Stanford before the fraud was exposed. More than once.

This is the second case in this series — after Madoff — where the regulatory body charged with protecting investors investigated the fraudster and failed to halt the scheme. In both cases, the scheme ran for years longer than it might have, in part because an investigation produced no action. In both cases, the eventual collapse came from market forces rather than regulatory action.

The SEC examined Stanford's operation and found that the above-market returns he was generating raised concerns similar to a Ponzi scheme. This examination occurred in the late 1990s and again in subsequent years. The SEC did not find the fraud. The scheme continued.

When the 2008 financial crisis triggered massive redemption requests that the scheme could not meet — the same mechanism that exposed Madoff — the SEC and other regulators moved in February 2009. By then, the fraud had been running for years with regulators having previously examined it without decisive action.

This is not a footnote. It is a structural failure that belongs in the case record alongside the fraud itself. The investors who put $7.2 billion into Stanford International Bank CDs did so in part because the institution had not been shut down despite examinations that had raised concerns. The regulatory failure is part of what the case documents.

· PART FIVE ·
The Cricket Box — Culture, Sport, and the Cover

The cricket connection was not incidental to the fraud. It was part of the same apparatus as the Antiguan knighthood, the charitable works, and the political donations: the infrastructure of a man who was spending money on things that made him look serious, embedded, and legitimate.

Cricket in the Caribbean is not just a sport. It is a cultural institution that carries specific weight — the game through which the Caribbean islands found a shared identity in the era of West Indies cricket dominance, when players from tiny island nations were the best in the world and the West Indies team was a source of collective pride for people who had otherwise been told they were peripheral.

Stanford understood this. He sponsored cricket matches in Antigua. He built a stadium. He funded development programs. He positioned himself as the man who was putting real money into the sport because he genuinely loved it — or at least into the appearance of a man who genuinely loved it.

The Lord's moment in August 2008 was the peak of the cricket chapter. He was at Lord's — the home of cricket — with a Perspex box containing $20 million, announcing the largest prize in the sport's history. The England cricket board had agreed to participate. Players from both teams were photographed with him. The image of the box circulated globally. He was, for a moment, the most famous cricket patron on earth.

He won the match — his West Indies XI beat England. The $20 million was paid. Then the financial crisis hit. The redemption requests came in at a scale the scheme could not meet. And the box that had appeared at Lord's, and the money it contained, turned out to have been funded by investors who had trusted their savings to a certificate of deposit in an Antiguan bank.

· PART SIX ·
The Collapse — February 2009

The 2008 financial crisis was the trigger here, as it was for Madoff. When markets collapsed in the autumn of 2008, investors across the world needed liquidity. The redemption requests that came into Stanford International Bank could not be met from the assets the bank claimed to hold, because those assets did not exist as described.

In February 2009, the SEC filed civil charges. Federal agents were dispatched. The news broke that day. Stanford, who had been trying to flee — running from federal agents in a car — eventually gave himself up. He was taken into federal custody on June 18, 2009 — surrendering to US Marshals in Fredericksburg, Virginia, after agents had been searching for him. [SOURCE: Wikipedia citing primary record]

The Stanford Financial Group — the US entity that had sold the offshore CDs to American and international investors — was seized. A receiver, Ralph Janvey, was appointed to recover assets for victims. The Antiguan bank was placed in receivership by Antiguan authorities.

What the receiver found: the investment portfolio that Stanford had described — the diversified, liquid, sophisticated assets supposedly generating the above-market returns — did not exist as represented. The bank's financial statements were fraudulent. The money was gone: spent on the lifestyle, on political donations, on cricket, on the other costs of maintaining the appearance of one of the Caribbean's most significant financial institutions.

A grand jury indicted Stanford on 21 counts in June 2009. He pleaded not guilty. His case then became complicated by a specific and unusual circumstance: while in pretrial detention, he became addicted to anti-anxiety medication prescribed in prison. A federal judge eventually declared him temporarily unfit for trial due to this addiction and related psychiatric issues, and he was sent to a federal hospital for evaluation. [SOURCE: Stabroek News / Reuters]

He was ultimately found fit for trial. The trial took place in early 2012 in Houston, Texas.

· PART SEVEN ·
The Trial — January–March 2012

Stanford's trial opened in January 2012 in Houston before Judge David Hittner. Stanford had been in custody since 2009 — nearly three years — due to the fitness proceedings and related delays.

He maintained his innocence throughout. His defence argued that the government's case misrepresented how Stanford International Bank operated — that it was a real bank with real assets generating real returns, and that the prosecution's theory was wrong.

The prosecution presented evidence of the fabricated financial statements, the movement of investor funds to Stanford personally, the absence of the investment portfolio as described, and the classic mechanics of a Ponzi scheme operating across decades. Former Stanford insiders — including James Davis, his chief financial officer and former college roommate, who pleaded guilty and cooperated — testified against him. [SOURCE: widely documented from trial record]

James Davis, who had shared a dorm room with Stanford at Baylor University, became the government's most significant cooperating witness. He pleaded guilty in 2009 and testified about the mechanics of the fraud — how the financial statements were fabricated, how investor money was used, how the scheme was maintained across years of operation.

The jury convicted Stanford on 13 of 14 counts on March 6, 2012. [SOURCE: DOJ conviction release / Reuters] The counts included wire fraud, mail fraud, obstruction, and conspiracy to commit money laundering, among others.

· PART EIGHT ·
110 Years — Coleman II, Florida

On June 14, 2012, Judge David Hittner sentenced Robert Allen Stanford to 110 years in federal prison.

He was 62 years old at sentencing. He is 76 years old as of this writing. His scheduled release date is March 13, 2103. [SOURCE: Bureau of Prisons / Wikipedia citing BOP record]

He is serving his sentence at the United States Penitentiary, Coleman II, in Sumter County, Florida — a high-security penitentiary near Wildwood, about 50 miles northwest of Orlando. [SOURCE: Nation News Barbados / BOP]

He has not stopped claiming innocence. In a BBC interview in January 2016, he said he spends every day in prison working on his case. He refused to apologise to his victims and described the court-appointed receivership as 'a court-sanctioned theft of unimaginable proportions.' [SOURCE: Cayman News Service citing BBC 5Live, January 2016]

In 2023, he filed an application with the US Supreme Court seeking an extension of time to challenge the receivership — the legal proceeding through which Ralph Janvey manages the recovery and distribution of assets to victims. Justice Samuel Alito granted the extension to February 2024. [SOURCE: Supreme Court docket No. 23A401]

As of this writing, there is no indication that any appeal has succeeded. The 110-year sentence stands. The receivership continues its work. The victims have received some recovery — a fraction of what they put in.

· PART NINE ·
The Victims — 20,000 People, $7.2 Billion, 100 Countries

The victims of Allen Stanford's fraud were not primarily hedge fund managers or institutional investors. They were people who had put their savings into something that looked safe.

More than 20,000 investors across more than 100 countries put money into Stanford International Bank certificates of deposit. [SOURCE: DOJ conviction release] A significant proportion were from Latin America and the Caribbean — Venezuela, Mexico, Panama, Ecuador, Colombia. Countries where the offshore CD in a respected Caribbean bank, with a credentialed American banker behind it and an Antiguan knighthood on the wall, looked like exactly the kind of solid, conservative, sensible investment that protects you from the instability of your own country's financial system.

Many of them were middle class or retired. They were not taking a speculative risk. They were doing what careful people do: putting their savings somewhere safe. The promised returns were higher than local rates, which was appealing, but not so high as to be obviously implausible. Stanford's operation was designed to be exactly plausible enough.

When the bank collapsed in February 2009, they could not access their money. The receivership began the long process of recovering and distributing what could be found. Years of litigation followed. Some victims received partial recovery. Many did not get back what they put in.

Stanford's BBC interview position — that the receivership was 'a court-sanctioned theft' — was the position of a man who had lost his case in court and had not changed his account of events. His victims had a different account.

· PART TEN ·
What It Means — Legitimacy Was the Architecture

The series thesis for is this: legitimacy was the architecture.

Every case in this series has a thesis — a single thing it documents about how fraud at scale works. Stanford's thesis is about the specific power of legitimate structures as fraud infrastructure.

He did not build a fake institution and pretend it was real. He built real institutions — a real bank with a real charter, real staff, real operations in a real country — and used the authentic structure as the container for a fraudulent core. Stanford International Bank was a functioning bank. It processed real transactions. It had real employees. It operated in a real regulatory environment. Inside that real structure, the investment portfolio was fabricated and investor money was being redirected.

The cricket sponsorship was real. The stadium was real. The knighthood was real. The political donations and the relationships with Antiguan and American politicians were real. All of it was real, and all of it served the same function: it made questioning the bank feel like questioning a person who had devoted themselves to the Caribbean, to cricket, to the community. Doubt became not a form of due diligence but a form of ingratitude.

Compare this to : there was no blockchain. The product had nothing beneath it. OneCoin was a number in a database and a brand. Stanford's fraud was the opposite in structure: a real institution with real operations and a fraudulent centre. The question 'how can this be a fraud — look at the stadium, the employees, the charter' was exactly the question the structure was designed to produce.

The SEC had looked. It had found similarities to a Ponzi scheme. It had not acted decisively. This is not a coincidence of the same form appearing twice in this series. It is the same dynamic: an institution with enough authentic complexity that the regulatory examination produced uncertainty rather than clarity, and the scheme ran.

He is at Coleman II. He is 76. His scheduled release is 2103. He is still working on his case, by his own account. The investors who put $7.2 billion into his certificates of deposit have received partial recovery from a receivership that has been working since 2009. The cricket ground in Antigua is still there.

· TIMELINE ·
VERIFIED SOURCES
$7.2B = investor funds defrauded per DOJ/jury verdict. Stanford's claims of innocence are documented in the record and noted; they have not been upheld by any court. Scheduled release date March 13, 2103 from Bureau of Prisons. The SEC regulatory failure is part of the public record and is included as documented institutional context, not editorial opinion.
[1] US v. Stanford, 4:09-cr-00342-001, S.D. Tex. Houston — conviction March 6, 2012 (13 of 14 counts); sentence June 14, 2012 (110 years). Judge David Hittner.
[2] DOJ/US Attorney S.D. Tex. — conviction press release (March 2012); sentencing press release (June 2012). Source for: $7.2 billion, 20,000+ investors, 100+ countries.
[3] SEC v. Stanford et al. (civil proceedings) — source for the CD fraud mechanics and SEC prior examination history.
[4] Reuters / AP / CNN — collapse February 2009, arrest, trial coverage.
[5] Bureau of Prisons / Wikipedia citing BOP — Coleman II location; scheduled release date March 13, 2103.
[6] Cayman News Service citing BBC 5Live, January 2016 — Stanford BBC interview. Source for: Coleman II is maximum security, 'every day in jail working on my case,' refuses apology, 'court-sanctioned theft' quote.
[7] Nation News (Barbados) — 'Stanford moved to high security prison,' July 2012. Coleman II, 50 miles northwest of Orlando.
[8] Stabroek News (Guyana) — anti-anxiety medication addiction; judge declared unfit for trial.
[9] US Supreme Court docket No. 23A401 — Stanford application and Justice Alito extension to February 2024. Source: supremecourt.gov docket.
[10] TO VERIFY BEFORE PUBLICATION: exact SEC investigation dates and findings (late 1990s and subsequent); James Davis cooperation plea date; exact final asset recovery figures from the Janvey receivership.
END OF REPORT
#10 OF 45
Jérôme Kerviel
SINGLE PERSON
CASE 030 · ROGUE TRADINGCONVICTED
Société Générale · 5 years (2 suspended) · Paris 2010
€4.9B
WHAT WAS TAKEN
Nothing taken for himself. €4.9B (~$7.2B at 2008 rates) is what Société Générale lost closing his hidden bets.
HOW
Hid about €50B of stock-index bets behind fake offsetting trades and forged emails.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2000–2008Joins Société Générale's middle office in 2000, moves to the Delta One desk in 2005, builds €50B of hidden positions by Jan 2008.SOURCE: Paris tribunal, 2010
Jan 2008The positions are unwound at a loss of €4.9B.SOURCE: Société Générale, 24 Jan 2008
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: Nicolas Richoffer · CC BY-SA 4.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
JÉRÔME KERVIEL
THE UNWINDING · SOCIÉTÉ GÉNÉRALE · CASE 030 · ROGUE TRADING · 5 YEARS (2 SUSPENDED) · DAMAGES CUT TO €1M
LOSS
€4.9B to Société Générale (Jan 2008)
POSITION
~€50B of hidden bets — exposure, not money
2007 GAIN
~€1.4B hidden paper profit
SENTENCE
5 years, 2 suspended · Paris 2010
PRISON
May–Sept 2014, then a tag
DAMAGES
€4.9B → annulled 2014 → €1M in 2016
€50B = the size of his bets (exposure) · €4.9B = the bank’s loss from closing them · €1.4B = a paper gain at end-2007. Three different numbers.
FULL PROFILE

IDENTITY

NAME
Jérôme Kerviel
BORN
January 11, 1977 · Pont-l’Abbé, Brittany, France
STUDIED
Université de Nantes; master’s, Université Lumière Lyon 2 (2000)
CAREER
Société Générale middle office (2000) → Delta One trading desk (2005)
PERSONAL GAIN
None found: the courts found no personal enrichment

CASE RECORD

CONVICTED
Oct 5, 2010 · Paris · breach of trust, forgery, false computer entries
SENTENCE
5 years, 2 suspended · lifetime ban from finance · €4.9B damages
APPEAL
Oct 24, 2012 · all upheld
TOP COURT
Mar 19, 2014 · conviction upheld; €4.9B damages annulled
PRISON
Jailed May 18, 2014 · released Sept 8, 2014 with an electronic tag
DAMAGES
Sept 23, 2016 · Versailles appeal court: €1M; the bank shared the blame
THE BANK AND THE COURTS
THE BANK€4.9B LOSS
Société Générale
Paris La Défense
Survived the loss but raised emergency capital. Said Kerviel acted alone.
SOURCE: Wikipedia
THE UNWINDINGJAN 21–23, 2008
Three days of selling
~€50B of futures
Sold into a falling market; the Fed made an emergency rate cut on Jan 22.
SOURCE: Wikipedia
THE LABOUR CASEREVERSED
~€455,000 award
Unfair dismissal, June 2016
Reversed on appeal in Dec 2018; his final appeal failed in March 2021.
SOURCE: fr.wikipedia
HIS BOOK2010
L’Engrenage
Memoir
His own account: the bank knew or should have. Treated as a claim.
SOURCE: Kerviel
LATESTDEC 2024
Revision request
“New evidence”
He asked again for his conviction to be reviewed; no ruling found.
SOURCE: fr.wikipedia
LEESON (CASE 022) VS KERVIEL (CASE 030)
HID
Leeson: losses · Kerviel: gains, then losses
BANK
Barings collapsed · Société Générale survived
SENTENCE
Leeson: 6½ years in Singapore · Kerviel: 5 years, 2 suspended
THE TWIST
French courts later found the bank partly to blame for the loss
CASE TIMELINE
2000
Joins the bank
Middle office: learns how trades are checked.
SOURCE: Wikipedia
2005
Delta One
Moves to the trading desk.
SOURCE: Wikipedia
End 2007
€1.4B up
Hidden positions show a big paper gain.
SOURCE: BBC
Jan 18, 2008
Found
An anomaly leads to ~€50B of hidden bets.
SOURCE: Wikipedia
Jan 21–23, 2008
Unwound
Sold into a falling market.
SOURCE: Wikipedia
Jan 24, 2008
€4.9B
The bank announces the loss.
SOURCE: Société Générale
Oct 5, 2010
Convicted
5 years, 2 suspended; €4.9B damages.
SOURCE: Paris court
Oct 24, 2012
Appeal
All upheld.
SOURCE: Reuters
Mar 19, 2014
Top court
Damages annulled.
SOURCE: Cour de cassation
May–Sept 2014
Prison
Four months, then a tag.
SOURCE: France 24
Sept 23, 2016
€1M
Bank shares the blame.
SOURCE: Versailles court
HOW IT WORKED

HOW THE BETS STAYED HIDDEN — DEFENSIVE LEVEL

01
The desk: Delta One trades index futures that should be hedged
02
The trick: Real bets offset by fake hedging trades in the bank’s systems
03
The cover: Forged emails answered questions, including from the Eurex exchange
04
The size: ~€50B of exposure — more than the bank was worth
05
The lesson: Unexplained profits need the same questions as losses
WHY THE CHECKS DIDN’T SEE IT
Real futures bets
-->
Fake offsetting trades
-->
Desk looks hedged
-->
Risk limits look fine

WHAT THIS CASE ESTABLISHED

One trader can build a position bigger than his bank.
Courts can convict the trader and still find the bank at fault.
Series link: (Leeson) — same mechanism, opposite ending.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE UNWINDING (1,500 WORDS)
Sources: Société Générale internal investigation (January 2008) · Paris Tribunal Correctional (October 2010 conviction) · French Court of Appeal (various appeals) · French Cour de Cassation · SocGen annual reports · FT / Le Monde / Reuters contemporaneous coverage. PAIRS WITH: ( / Barings) — same mechanism, different scale, different institutional response, profoundly different legal outcome.
· PROLOGUE ·
The Difference Between Leeson and Kerviel

() lost £827 million at Barings and the bank collapsed. Jérôme Kerviel built a position ten times larger and Société Générale survived. The difference is not a matter of audacity. It is a matter of which institution was on the other side.

Barings had been a distinguished private bank. It could not absorb the loss. ING bought it for £1.

Société Générale was — and remains — one of France's largest banks, a publicly listed institution with a market capitalisation that, in January 2008, was smaller than the position Kerviel had built. The position Kerviel had built — €49.9 billion in notional exposure to European equity index futures — was larger than the bank's entire market cap. When the bank unwound it in three days in January 2008, amid a falling market, the realized loss was approximately €4.9 billion. SocGen survived. It had to raise emergency capital, but it survived.

The mechanism is the same as Leeson: unauthorized trading, hidden through falsified records, in an institution where the compliance function failed to catch it in time. The scale is larger. The legal aftermath is dramatically different — because Kerviel raised a question Leeson never seriously contested: what if the bank knew?

· PART ONE ·
Who He Was and How He Got There

Jérôme Kerviel was born on January 11, 1977, in Pont-l'Abbé, Finistère, in Brittany. He earned a finance degree at the Université de Nantes and a master's in financial market operations at the Université Lumière Lyon 2 in 2000 — a respectable but not elite French university trajectory in an industry where the highest desks tend to go to graduates of the grandes écoles.

He joined Société Générale in 2000, initially in the compliance and middle-office function — the back office that processed and recorded trades. This is the same critical detail as Leeson at Barings: he had direct knowledge of how trades were recorded, how reconciliations were done, and where the gaps in monitoring were. In 2005 he moved to the bank's Delta One trading desk — the proprietary trading operation that handled index futures and structured products.

Delta One traders take positions linked to market indices. Their trades are typically hedged — for every long position, there is a corresponding short. The hedge is what keeps the net exposure within limits and what allows risk managers to verify that the desk is doing what it says it is doing.

Kerviel's positions were not hedged. The hedges were fictitious. He created fake counterparty entries in the bank's systems — entries that appeared to offset his real trades but pointed to accounts that did not exist or to transactions that were never executed. The result: on paper, the desk looked properly hedged. In reality, Kerviel held an enormous naked long position on European equity indices.

· PART TWO ·
The Position — €49.9 Billion

By early January 2008, Kerviel's unauthorized positions had grown to approximately €49.9 billion in notional value — primarily futures on the DAX, EUROSTOXX, and FTSE indices. This was larger than Société Générale's entire market capitalisation at the time.

The position had been profitable through 2007. Kerviel later said, and has always maintained, that his trading had produced gains for the bank — gains the bank accepted without asking where they came from. In 2007 he had generated profits of approximately €1.4 billion from his unauthorized positions. No one from the bank's risk or compliance function asked how those profits had been made.

He falsified the offsetting entries to stay below the bank's risk limits. He created fictitious forward transactions with existing SocGen counterparties — transactions large enough to appear to hedge his real positions but that never settled because they were never real. When Eurex, the German derivatives exchange, sent an inquiry about one of these positions in late 2007, Kerviel created a forged email response. The inquiry was absorbed without escalation.

In the second week of January 2008, the bank's back office identified an irregular transaction and raised it with compliance. On January 18, 2008, a junior employee flagged an anomaly. The investigation that followed revealed the full scale of the position in the days that followed.

· PART THREE ·
The Unwinding — Three Days in January

On January 19, 2008, Société Générale's senior management understood what they had. Over the weekend of January 19-20, they made the decision to unwind the position — to close every one of Kerviel's unauthorized trades as quickly as possible.

The unwinding ran from January 21 to January 23, 2008. These were not quiet days in the market. Global equities were falling sharply — European markets plunged on January 21 while US markets were closed for a holiday, and on January 22 the Fed made an emergency 75 basis point rate cut. Into this falling market, Société Générale was selling approximately €50 billion in equity index futures — an operation of such scale that some market participants later speculated that the selling itself contributed to the week's market movements.

The realized loss: approximately €4.9 billion. This was the market impact of selling an enormous long position into a falling market over three days. If the positions had been unwound more slowly, or if the market had been rising, the loss would have been different. Kerviel has argued since his conviction that the bank's decision to unwind quickly — and secretly, before informing the regulator — maximized the loss. The bank disputes this.

SocGen disclosed the fraud and the loss on January 24, 2008. The bank's share price fell approximately 4 percent on the day of disclosure. Kerviel was arrested that week. He has spent the years since disputing the attribution of the loss.

· PART FOUR ·
The Legal History — The Numbers Changed

The conviction in October 2010: 5 years in prison (2 suspended, 3 to serve), and €4.9 billion in damages — the full amount of the unwinding loss. The damages figure was controversial from the start.

The 2016 damages ruling is the most distinctive element of this case in the series. French courts found that SocGen had received warning signals — internal alerts from exchanges and compliance processes — that, if properly investigated, could have halted Kerviel's trading earlier. The bank's own incentive structure, which rewarded the profits Kerviel was generating without asking hard questions, was found to constitute contributory fault.

Kerviel's defense from the beginning was that he was not a rogue element but a product of the institution — that the bank knew enough to ask questions and chose not to, because the money was coming in. The 2016 ruling gave that argument legal weight in the civil damages context, without reversing the criminal finding that he had forged documents and concealed positions.

· PART FIVE ·
What It Teaches — The Institutional Fault Line

Leeson (): one person, no oversight, bank died. The lesson was unambiguous.

Kerviel: one person, apparently no oversight — but the oversight question turned out to be more complicated. The bank received signals that, in retrospect, should have been investigated. The profits were accepted. The losses were called fraud. The French judiciary, eventually, found the causal chain messier than a simple bad-actor story.

This is not a defense of Kerviel's conduct. He forged documents. He created fictitious hedges. He lied to compliance when confronted. The criminal conviction reflects that conduct accurately. But the series' interest in this case is the institutional question, because it is the question that the series' entire compliance section is built around: what does a working compliance function actually require?

The Kerviel case answers it in reverse. A bank that paid out €1.4 billion in profits generated by positions it could not fully explain, without asking where those profits came from, built a compliance gap large enough to hide €50 billion. The warning signals were there. The culture that produces them also has to produce the investigation.

VERIFIED SOURCES
[1] Paris Tribunal Correctional — conviction October 2010. 5 years (2 suspended), €4.9B damages. Primary criminal record.
[2] Paris Court of Appeal — 2012. Prison sentence upheld. [Verify exact appeal outcome on damages — sources vary]
[3] Versailles Court of Appeal — 23 September 2016. Damages reduced to €1M. SocGen contributory fault finding. [SOURCE: Le Monde / Reuters 2016]
[4] FT / Le Monde / Reuters — contemporaneous coverage of the January 2008 collapse and unwinding.
[5] SocGen internal investigation report — January 2008. Published summary. Source for warning signals received.
[6] Kerviel — 'L'engrenage: Mémoires d'un trader' (memoir, 2010). Self-account. Treated as a claim, not a source.
TO VERIFY Exact 2016 court name and ruling date · Whether any later rulings further modified the damages · Kerviel's current legal status and activities · Precise warning signals documented in the 2010 trial record · Amount SocGen recovered vs the final judgment
SOURCES
[1] PRIMARY — Tribunal correctionnel de Paris: judgment (Oct 5, 2010)
[2] SECONDARY — Reuters / Le Monde / France 24: appeal, top court, prison (2012–2014)
[3] SECONDARY — Reuters / Le Monde: Versailles €1M ruling (Sept 23, 2016)
[4] AGGREGATOR — Wikipedia (en/fr): Jérôme Kerviel; 2008 Société Générale trading loss
[5] SELF-SERVING — Kerviel, L’Engrenage (2010)
END OF REPORT
#11 OF 45
Lazarus Group
GROUP
CASE 027 · CRYPTO THEFT · GROUPCHARGED
North Korean state hackers (attributed) · 4 charged · none caught
~$6.75B
WHAT WAS TAKEN
Crypto stolen from exchanges, wallets and bridges (Chainalysis estimate to 2025), plus $81M from Bangladesh's central bank. Attributed by the FBI and UN; North Korea denies it.
HOW
Fake job offers and poisoned downloads trick staff into handing over the keys; the coins are then laundered through mixers and brokers.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2014–presentReconnaissance General Bureau units run the operations; Sony (2014), Bangladesh Bank (2016), Ronin (2022), Bybit (2025).SOURCE: US Treasury designation, 13 Sept 2019; DOJ
2011–2013Park Jin Hyok works at Chosun Expo, a front company in Dalian, according to the DOJ.SOURCE: DOJ complaint, Sept 2018
variousIndicted members were 'at times stationed' in Russia, the DOJ says.SOURCE: DOJ indictment, Feb 2021
METHODS USED
Tap a method to see where it came from and everyone who used it.
Illustration: Kaspersky
TAP A SECTION TO OPEN IT
KEY FACTS
LAZARUS GROUP
GROUP ENTRY · NORTH KOREAN STATE HACKERS (ATTRIBUTED) · CASE 027 · 4 MEMBERS CHARGED · LAUNDERER SENTENCED · CASE OPEN
CRYPTO STOLEN
$6.75B all-time (Chainalysis estimate, to end-2025)
2025
$2.02B — a record year
BIGGEST
~$1.5B · Bybit · Feb 21, 2025
BANKS
$81M from Bangladesh Bank, 2016
CHARGED
4 North Koreans · none in custody
REWARD
Up to $10M (Rim Jong Hyok)
A GROUP, AND AN ATTRIBUTION: governments and security firms say these units work for North Korea’s military intelligence. North Korea denies it. No member has been tried. Totals are lower-bound estimates.
FULL PROFILE

WHO THEY ARE

NAME
“Lazarus Group” — coined by researchers in 2016 (Operation Blockbuster)
ALSO CALLED
Hidden Cobra (US gov) · APT38 (Mandiant) · BlueNoroff (Kaspersky) · TraderTraitor (FBI) · Andariel
CONTROLLED BY
Reconnaissance General Bureau, North Korea’s military intelligence (US Treasury, 2019)
ESTABLISHED IN
Pyongyang, North Korea — units of the Reconnaissance General Bureau; activity traced back to ~2009 (Operation Blockbuster)
WORKED FROM
Dalian and Shenyang (China), Vladivostok (Russia), IT workers abroad
LOGO
The red mummy roundel is Kaspersky’s artwork, not the group’s

CASE RECORD

SANCTIONED
Sept 13, 2019 · US Treasury (Lazarus, BlueNoroff, Andariel)
CHARGED
Park Jin Hyok · complaint unsealed Sept 6, 2018 (Los Angeles)
INDICTED
Park, Jon Chang Hyok, Kim Il · unsealed Feb 17, 2021 · >$1.3B scheme
INDICTED
Rim Jong Hyok · July 25, 2024 (Kansas) · hospital ransomware
IN CUSTODY
None. North Korea denies involvement
CONVICTED HELPERS
Launderer Ghaleb Alaumary (11 yrs 8 mos, 2021); US “laptop farm” hosts
MEMBERS — CHARGED, NOT CONVICTED
MEMBER 01 · RGBCHARGED · AT LARGE
Park Jin Hyok
박진혁 · the original indictee · Chosun Expo
Charged Sept 6, 2018 (Los Angeles) over Sony Pictures, the Bangladesh Bank heist and WannaCry; indicted again in 2021. Worked for front company Chosun Expo in China, per the DOJ. North Korea calls him a “non-existent entity”. On the FBI Cyber Most Wanted list.
SOURCE: DOJ 2018 complaint · 2021 indictment · FBI
MEMBER 02 · RGBCHARGED · AT LARGE
Jon Chang Hyok
전창혁 · the developer · ~31 in 2021
Indicted Feb 2021: malicious crypto apps with hidden backdoors and the Marine Chain Token, a blockchain “investment” the DOJ says secretly raised money for North Korea. Reported at times to work from China and Russia.
SOURCE: DOJ Feb 17, 2021 indictment · FBI
MEMBER 03 · RGBCHARGED · AT LARGE
Kim Il
김일 · the marketer · “Julien Kim”, “Tony Walker”
Indicted Feb 2021. The DOJ says he used Western-sounding aliases to market the fraudulent crypto apps and the Marine Chain Token to investors.
SOURCE: DOJ Feb 17, 2021 indictment · FBI
MEMBER 04 · RGBCHARGED · AT LARGE
Rim Jong Hyok
Andariel unit · reward up to $10M
Indicted July 25, 2024 (Kansas) over ransomware attacks on US hospitals and health firms; the DOJ says the ransoms paid for more hacking.
SOURCE: DOJ July 25, 2024 · Rewards for Justice
THE LAUNDERERSENTENCED 11 YRS 8 MOS
Ghaleb Alaumary
Canadian-American launderer · not North Korean
Pleaded guilty; sentenced Sept 8, 2021 to 140 months and over $30M restitution for laundering North Korean bank-heist money, including the 2019 Bank of Valletta heist, and for BEC schemes with ().
SOURCE: DOJ Sept 8, 2021
THE BIGGEST HEISTS (AS ATTRIBUTED)
FEB 21, 2025~$1.5B
Bybit
Dubai exchange
Staff approved a disguised transfer after a supplier’s laptop was hacked. Largest crypto theft on record.
SOURCE: FBI PSA, Feb 26, 2025
MARCH 2022~$625M
Ronin Network
Axie Infinity game
A fake job offer gave access to validator keys. About $30M later seized.
SOURCE: FBI, Apr 14, 2022
MAY 2024~$308M
DMM Bitcoin
Japan
A fake recruiter’s “test” hacked a wallet supplier’s employee. The exchange later closed.
SOURCE: FBI · Japan NPA, Dec 23, 2024
JULY 2024~$235M
WazirX
India
Multisig wallet drained; named in a US–Japan–South Korea statement (Jan 2025).
SOURCE: Elliptic · joint statement
FEB 2016$81M
Bangladesh Bank
New York Fed account
$951M attempted over SWIFT; $81M vanished through Manila casinos.
SOURCE: DOJ, 2018
2014NOT A THEFT
Sony Pictures
Guardians of Peace
Computers wiped and emails leaked over the film The Interview.
SOURCE: FBI, Dec 19, 2014
WHY IT MATTERS
THE MONEY
Stolen crypto funds weapons programmes, according to the US government and a UN panel
THE METHOD
People, not code: fake job offers, poisoned downloads, hacked suppliers
THE LIMIT
Charged but out of reach: no extradition from North Korea
SERIES LINK
() — DOJ says he laundered for the 2019 Bank of Valletta heist
CASE TIMELINE
Nov 2014
Sony Pictures
Wiped and leaked; FBI blames North Korea.
SOURCE: FBI
Feb 2016
Bangladesh Bank
$81M taken of $951M attempted.
SOURCE: DOJ
Feb 24, 2016
The name
Operation Blockbuster names “Lazarus”.
SOURCE: Novetta
May 2017
WannaCry
Ransomware hits 150 countries; US attributes it in Dec 2017.
SOURCE: White House
Sept 6, 2018
First charge
Park Jin Hyok charged in Los Angeles.
SOURCE: DOJ
Sept 13, 2019
Sanctioned
US Treasury names three groups.
SOURCE: Treasury
Feb 17, 2021
Indictment
Three members; >$1.3B scheme.
SOURCE: DOJ
March 2022
Ronin
~$625M.
SOURCE: FBI
May 2024
DMM Bitcoin
~$308M.
SOURCE: FBI
July 25, 2024
Rim Jong Hyok
Charged; reward up to $10M.
SOURCE: DOJ
Feb 21, 2025
Bybit
~$1.5B: largest crypto theft on record.
SOURCE: FBI
2025
Record year
$2.02B stolen; $6.75B all-time.
SOURCE: Chainalysis
HOW IT WORKED

HOW THE HEISTS WORK (PER THE FBI) — DEFENSIVE LEVEL

01
The approach: A recruiter or trading partner reaches out with a great job or deal
02
The hook: A “test”, app or file to download — carrying malware
03
The keys: From the infected machine they reach the wallets or the signing process
04
The transfer: A large transfer is approved that looks routine
05
The laundering: Swaps, mixers, bridges, then brokers who pay out cash
06
The defence: Never run a stranger’s file; separate key machines; require several people and devices for big transfers
HOW STOLEN CRYPTO MOVES (PER CHAINALYSIS / FBI)
Exchange or bridge wallet
-->
Swapped to ETH / BTC
-->
Mixers & bridges
-->
Brokers → cash

WHAT THIS CASE ESTABLISHED

The biggest thieves in the series never touch a bank — they send an email.
A charge is not a capture: four indicted, none in custody.
Attribution is a claim by governments and firms. We name who makes it every time.
Series link: () · () — stolen crypto, traced.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE GOVERNMENT THAT DECIDED THEFT WAS CHEAPER THAN TRADE (2,100 WORDS)
Sources: DOJ indictment Park Jin Hyok (Sep 2018) · DOJ indictment Jon Chang Hyok, Kim Il (Feb 2021) · FBI PSA February 26, 2025 (Bybit/TraderTraitor) · FBI Cyber Most Wanted pages · US Treasury OFAC sanctions · UN Panel of Experts DPRK · Chainalysis 2023 Crypto Crime Report · OpenSanctions · Wikipedia (aggregator — all claims verified to primary). Attribution discipline: every dollar figure carries source type. The three indicted are never described as convicted. All operations labelled with attributing body only.
· PROLOGUE ·
The Case That Cannot Close

Every other case in this series ends.

Not tidily, not always justly — but it ends. There is an arrest, a plea, a verdict, a sentence. A person is moved from one side of a courtroom to the other. The legal system does the thing legal systems do, and we record the outcome.

ends on December 11, 2025, in a federal courtroom in New York, when a judge says 'You chose to lie. You chose poorly,' and a 34-year-old man who destroyed $40 billion in market value is led from the courtroom. ends in a house in Gainesville, Georgia, with federal agents lifting a popcorn tin from a bathroom closet.

Case 027 does not end. Four North Korean men are charged. They are in Pyongyang. They will not be extradited. They are employees of a state that does not extradite its employees. The unit they work for continues to operate. The operations continue to run. The proceeds continue to flow — into a state, into a nuclear programme, into the budget line that pays for the next operation.

You cannot arrest a government. You can only describe it accurately — and say, every time, that the description is an assessment.

· PART ONE ·
What Lazarus Is — The Organizational Structure

Lazarus Group is the name used by researchers, governments, and intelligence agencies to describe cyber units attributed to the Reconnaissance General Bureau — the RGB — North Korea's primary foreign intelligence apparatus.

It is a label applied from outside — not a name they chose for themselves.

The name 'Lazarus' is an umbrella. It covers Bureau 121 and its sub-units under different analytical frameworks used by different researchers and governments. The FBI uses TraderTraitor for the crypto-specific sub-unit; Kaspersky Labs coined BlueNoroff; Symantec and others use APT38 for the financial theft arm. The inconsistency in naming reflects the fact that the attribution assessments come from competing sources working with different intelligence.

· PART TWO ·
The Known Members — Full Profiles

Every individual listed below is a LEGAL STATUS NOTE. The three DPRK nationals are indicted — not convicted. Ghaleb Alaumary pleaded guilty and his status is documented separately. North Korea denies the existence of Park Jin Hyok. All conduct attributed to DPRK nationals is alleged in the indictment and assessed by intelligence agencies — it has not been proven at trial.

· MEMBER 01 ·
Park Jin Hyok · 박진혁 · THE ORIGINAL INDICTEE

KEY FACTS: First charged September 6, 2018 in criminal complaint (CDCA). First North Korean national publicly indicted for financial cybercrime. North Korea issued an official denial of his existence. Travelled to China and conducted legitimate IT work under Chosun Expo cover — the dual-use front company model the DPRK uses across multiple operatives. On FBI Cyber Most Wanted list. [SOURCE: DOJ; FBI; OpenSanctions; US Treasury OFAC]

· MEMBER 02 ·
Jon Chang Hyok · 전창혁 · THE DEVELOPER

KEY FACTS: Charged in the February 17, 2021 unsealing of the expanded indictment. The Marine Chain Token is a specific and documented example of the Lazarus Group creating financial fraud products — a blockchain-based token designed to appear legitimate while secretly funding the DPRK state. This represents a distinct capability: not just theft, but fraud product development. [SOURCE: DOJ Feb 2021 indictment]

· MEMBER 03 ·
Kim Il · 김일 · THE MARKETER

KEY FACTS: The alias pattern (Julien Kim, Tony Walker) reflects a specific operational technique: constructing Western-friendly identities for marketing fraudulent financial products. This distinguishes Kim Il's documented role — the outward-facing, investor-targeting component — from the technical infrastructure roles attributed to the other indicted members. His aliases suggest he engaged with Western targets directly as part of the fraud product marketing. [SOURCE: DOJ 2021 indictment; Infosecurity-Magazine citing DOJ]

· MEMBER 04 ·
Ghaleb Alaumary · THE LAUNDERER

KEY FACTS: Alaumary is the series connection point. He bridges (/) and Case 027 (Lazarus Group). His role was to organise teams of money laundering co-conspirators in the US and Canada to process proceeds attributed to North Korean cyber theft. He is the only individual in this case file who is NOT a North Korean national and who has entered a guilty plea in US proceedings. He was sentenced on 8 September 2021 to 140 months (11 years 8 months) and ordered to pay more than $30 million in restitution (DOJ). [SOURCE: DOJ plea agreement; DOJ Feb 2021 press release]

· PART THREE ·
Front Companies and Operational Cover

The Lazarus Group does not operate from a building labelled 'DPRK Cyberattack Centre.' It operates through front companies that provide legitimate IT services as cover for RGB operations — a dual-use model the DPRK uses systematically to generate both revenue and operational cover.

· PART FOUR ·
Operations — Full Record, Attributed As Such

Attribution discipline mandatory throughout. Each operation is labelled with its attributing body. No operation has been proven in court. Dollar figures labelled with what they measure and their source. 'Stolen' means 'attributed as stolen by' — the attribution is an intelligence assessment.

· PART FIVE ·
The Money — Figures, Sources, Discipline

Aggregated figures for Lazarus-attributed theft circulate widely and vary significantly. The variations are not errors; they reflect different methodologies, time periods, and attribution decisions. Every figure below carries its source.

· PART SIX ·
How Lazarus Group Connects to the Rest of This Series

of this series is — . His co-conspirator Ghaleb Alaumary — now Member 04 of this case file — laundered proceeds from North Korean-linked cyber operations including the Bank of Valletta SWIFT heist. The Instagram influencer's laundering network was downstream of this state programme.

is and Binance. Binance admitted to failing to run an effective anti-money-laundering programme; exchanges with weak controls are the kind of channel launderers of stolen crypto rely on. (The DOJ's Binance findings name sanctioned-country users and terrorist-linked transactions; this file does not claim they name North Korea.)

The series' foundational category on BEC includes the case (): the principle that the attack surface in financial fraud is human verification applies equally to SWIFT social engineering and invoice fraud.

Lazarus Group is not a separate thread in the series. It is the thread that was already running through 's network and 's compliance failures. The individual fraudsters commit their crimes. The exchange failures create the channels. The state-sponsored unit uses all of it.

· PART SEVEN ·
The IT-Worker Revenue Stream — A Separate Operation

Beyond direct heists, US government agencies and private security firms have documented a parallel Lazarus-adjacent operation: the systematic placement of North Korean IT workers at technology companies globally, generating income assessed to flow back to the DPRK state.

The operation, documented in joint advisories from the US Departments of Justice, State, and Treasury, involves DPRK nationals securing remote employment at technology companies — cryptocurrency-adjacent firms in particular — under false identities and with falsified credentials. [SOURCE: US Departments of Justice, State, Treasury joint advisory — verify exact dates and title]

The technique: a North Korean national secures remote work as a software developer, graphic designer, or IT contractor. They perform genuine work. The salary is paid to accounts that route back to the DPRK state. The cover is plausible, the work is real, and the revenue is generated without any intrusion or heist.

This operation connects to the front company model documented in Part Three. Chosun Expo Joint Venture was Park Jin Hyok's cover for legitimate IT work — the IT-worker operation scales that model to thousands of individuals operating globally through diverse cover identities.

The dollar amounts generated through this channel are not established with the same precision as the direct heists. The programme is documented as existing and ongoing; its aggregate scale is assessed rather than audited.

· PART EIGHT ·
Why It Doesn't Stop — The Structural Argument

The individual cases in this series have psychological explanations. Madoff ran his scheme because he could not face the moment it ended. built a framework of self-justification. Holmes told the story long enough that she started to believe it.

The Lazarus Group does not have a psychology. It has a budget line.

North Korea operates under comprehensive international sanctions — the response to its nuclear weapons programme. The sanctions have not ended the programme. What they have produced is an intensification of the need for hard currency through channels sanctions cannot reach. The Lazarus clusters are the assessed solution.

The operations follow the hardening of targets. Banks hardened their SWIFT infrastructure after 2016. The group moved to exchanges. Centralised exchanges hardened direct custody. The group moved to bridges. Bridges hardened. The group moved to supply-chain attacks on the software those bridges depended on — as in Bybit, where the entry point was a developer's compromised machine.

The technical escalation is not the story. The story is structural: every time a target hardens, the unit adapts, because the state still needs the money and the capability exists to find the next soft point. This will continue until either the sanctions regime changes, the nuclear programme concludes, or the capability is degraded by means outside the scope of this case file.

· EPILOGUE ·
What Can Be Said and What Cannot

What can be said: the US government has charged four North Koreans as members of the unit — Park Jin Hyok, Jon Chang Hyok, Kim Il and, in July 2024, Rim Jong Hyok (reward up to $10 million). Ghaleb Alaumary pleaded guilty to laundering for the operation and was sentenced to 11 years 8 months. The unit is attributed by the US, UK, and other governments to have conducted operations assessed to have generated billions of dollars in proceeds. Those proceeds fund the North Korean state.

What cannot be said: that any of this has been proven in a court of law through an adversarial proceeding. Attribution is an intelligence judgment. The indictments are criminal charges, not convictions. The figures are assessments, not audited accounts. Park Jin Hyok's existence is denied by the North Korean government.

Every other case in this series ends with a person in a cell or a person on the run. This one ends with four charged men beyond reach, an operational unit still working, a UN Panel of Experts writing its next annual report, and a fresh FBI attribution for a fresh $1.5 billion theft.

You cannot indict a government. You can charge four of its employees, and imprison its money launderer, and watch them stay exactly where they are.

VERIFIED SOURCES — FULL CITATION RECORD
Every operation attributed, not adjudicated. Three indicted (Park, Jon, Kim) are never described as convicted. Alaumary pleaded guilty — that is a distinct legal status. DPRK denies Park Jin Hyok's existence.
[1] DOJ — criminal complaint, Park Jin Hyok, unsealed September 6, 2018. CDCA. Sony, Bangladesh Bank, WannaCry. Chosun Expo Joint Venture identified.
[2] DOJ — federal indictment, Jon Chang Hyok, Kim Il, Park Jin Hyok, filed December 8, 2020, unsealed February 17, 2021. CDCA. Marine Chain Token, malicious crypto apps, full operation list.
[3] DOJ — Ghaleb Alaumary charging, February 2021. CD California. Money laundering plea. Bank of Valletta connection. Teams in US and Canada. network link.
[4] FBI PSA — February 26, 2025. TraderTraitor / Bybit. $1.5B. Bitcoin conversion and multi-chain dispersal. PRIMARY SOURCE for Bybit attribution.
[5] FBI — Cyber Most Wanted pages: Park Jin Hyok, Jon Chang Hyok, Kim Il. Ages at indictment. Front companies. Charge descriptions.
[6] SafeWallet forensic review statement, February/March 2025. Confirmed: compromised developer machine. Disguised malicious transaction. SafeWallet infrastructure as attack vector.
[7] FBI April 2022 — Ronin/Axie Infinity attribution. FBI January 2023 — Harmony attribution.
[8] FBI/UK NCSC/multiple governments — WannaCry 2017 attribution. UK NCSC confirmed separately.
[9] Chainalysis Crypto Crime Report 2023 — $1.7B estimate for 2022. Label as private analytics estimate throughout.
[10] UN Panel of Experts on DPRK — cumulative theft assessments. VERIFY exact report year and dollar language before publication.
[11] OpenSanctions citing US Treasury OFAC — Park Jin Hyok full sanctions record including passport number, education (Kim Chaek University), aliases.
[12] Wikipedia: Park Jin Hyok · Jon Chang Hyok · Bureau 121 · Reconnaissance General Bureau (aggregators — cross-verified to primary sources above).
[13] Infosecurity-Magazine / SecurityAffairs / ThreatPost / SecurityWeek — DOJ 2021 indictment reporting. Kim Il aliases (Julien Kim, Tony Walker). Alaumary details.
[14] ChinaFile citing defector Kim Heung-Kwang — Shenyang Bureau 121 presence. Treat as reported defector testimony, not confirmed by US government statements.
TO VERIFY IT-worker advisory exact dates and issuing agencies · Current status of all three indicted individuals · Jon Chang Hyok and Kim Il birth dates (ages at indictment used as approximations) · UN Panel exact dollar figure and report year
SOURCES
[1] PRIMARY — DOJ: Park Jin Hyok charged (Sept 6, 2018)
[2] PRIMARY — DOJ: three North Korean military hackers indicted (Feb 17, 2021)
[3] PRIMARY — DOJ: Rim Jong Hyok charged (July 25, 2024)
[4] PRIMARY — FBI: Ronin (Apr 14, 2022); DMM Bitcoin (Dec 23, 2024); Bybit PSA (Feb 26, 2025)
[5] PRIMARY — US Treasury: sanctions (Sept 13, 2019)
[6] SECONDARY — Chainalysis crypto crime reports (Dec 2025)
[7] SECONDARY — The Record: UN Panel of Experts (Mar 2024)
[8] SECONDARY — Novetta: Operation Blockbuster (Feb 24, 2016)
[9] IMAGE — Lazarus roundel: Kaspersky artwork (apt.securelist.com)
END OF REPORT
#12 OF 45
Stanislav Moiseyev
SINGLE PERSON
CASE 035 · DARK WEBLIFE SENTENCE
Hydra Market · life · Moscow 2024
~$5.2B
WHAT WAS TAKEN
Nothing stolen: ~$5.2B in crypto flowed through Hydra, a market for drugs, stolen card data and fake documents (US DOJ).
HOW
Ran Hydra, a Russian-language darknet market with dead-drop deliveries and a crypto-mixing service.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2015–2022Runs Hydra, the Russian-language darknet market supplying drugs across Russia and Belarus by dead drop; >$5.2B in crypto passed through it.SOURCE: Moscow Regional Court, 2 Dec 2024; DOJ
2 Dec 2024Convicted in Moscow and sentenced to life.SOURCE: Moscow Regional Court, per TASS
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
STANISLAV MOISEYEV
THE STORE · HYDRA MARKET · CASE 035 · DARK WEB · LIFE IMPRISONMENT · MOSCOW DEC 2, 2024
THROUGH HYDRA
~$5.2B in crypto (US DOJ) — not theft
MARKET SHARE
~80% of darknet crypto in 2021 (Chainalysis)
ACCOUNTS
~17M customers · 19,000+ vendors
SEIZED
~$25M in bitcoin (Germany, 2022)
SENTENCE
Life · Moscow Regional Court
OTHERS
15 accomplices · 8–23 years
MARKET MONEY, NOT STOLEN MONEY: $5.2B is crypto that flowed through Hydra (sales, fees and mixing). The $25M is what Germany seized. Different numbers.
FULL PROFILE

IDENTITY

NAME
Stanislav Moiseyev (Moiseev)
ROLE
Named by TASS and Interfax as Hydra’s founder; the court: organiser of a criminal community
PLATFORM
Hydra Market, Russian-language darknet market, 2015–2022
SOLD
Drugs (dead drops), stolen card data, fake documents, a crypto-mixing service

CASE RECORD

SEIZED
Apr 5, 2022 · Germany takes the servers; US sanctions Hydra
US CHARGES
Dmitry Pavlov, alleged server host (Promservice), 2022
COURT
Moscow Regional Court
SENTENCED
Dec 2, 2024 · life, special-regime colony · 4M rouble fine
A FIRST
First life sentence in Russia for such a case, per Russian media
THE WALLET
He refused to give investigators his crypto wallet password (Interfax)
THE TAKEDOWN AND THE COURT
GERMANYAPR 5, 2022
BKA & Frankfurt prosecutors
Servers in Germany
Seized the servers and 543 bitcoin (~€23M).
SOURCE: BKA
UNITED STATESSANCTIONS
Treasury & DOJ
Same day
Sanctioned Hydra and charged Russian national Dmitry Pavlov over its hosting.
SOURCE: DOJ
RUSSIALIFE
Moscow Regional Court
Dec 2, 2024
Convicted Moiseyev and 15 others for a criminal community selling drugs.
SOURCE: Interfax
ACCOMPLICES8–23 YEARS
15 people
16M roubles in fines
Sent to special- and strict-regime colonies.
SOURCE: Interfax
AFTER HYDRA$1.7B
Darknet markets, 2023
Chainalysis
New Russian-language markets grew in Hydra’s place.
SOURCE: Chainalysis
THE ORIGINAL
Silk Road
Two life terms, then pardoned in January 2025.
SOURCE: Series
SILK ROAD (CASE 013) VS HYDRA (CASE 035)
MARKET
Silk Road: English, global · Hydra: Russian-speaking
YEARS
Silk Road: 2011–2013 · Hydra: 2015–2022
TAKEDOWN
Silk Road: FBI · Hydra: Germany with the US
OPERATOR
Ulbricht: life, then pardoned · Moiseyev: life in Moscow
CASE TIMELINE
2015
Hydra opens
Russian-language darknet market.
SOURCE: DOJ
2021
Dominant
~80% of darknet-market crypto.
SOURCE: Chainalysis
Apr 5, 2022
Seized
Germany takes the servers; US sanctions.
SOURCE: BKA · DOJ
Dec 2, 2024
Life
Moscow Regional Court.
SOURCE: Interfax
HOW IT WORKED

HOW HYDRA WORKED — DEFENSIVE LEVEL

01
The shop: Vendors listed goods; buyers paid in crypto through escrow
02
Dead drops: Drugs hidden at locations instead of posted, per the Russian court
03
Extra services: Stolen card data, fake documents and a mixing service
04
The weakness: Its servers were in Germany, within reach of European police
HOW MONEY MOVED THROUGH HYDRA
Buyer’s crypto
-->
Hydra escrow
-->
Vendor paid
-->
Mixing / cash-out
KNOWN NETWORK & CONNECTED CASES

WHAT THIS CASE ESTABLISHED

Closing one market doesn’t close the trade: successors grew within a year.
Two countries acted: Germany took the servers, Russia tried the man.
Series link: (Ulbricht) — the same model, a very different ending.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE STORE (1,300 WORDS)
Sources: US DOJ press release April 5, 2022 (takedown) · US Treasury/OFAC sanctions · German BKA / Frankfurt prosecutors (takedown) · Moscow Regional Court December 2, 2024 (conviction — Russian court record as reported by TASS / Interfax / Cointelegraph) · Chainalysis Crypto Crime Reports · Wikipedia (Hydra Market — aggregator, verify primary). METRIC DISCIPLINE: $5.2B = cryptocurrency revenue taken in by the marketplace (DOJ figure) — NOT theft. The marketplace charged fees; it did not steal. Seizure figures (crypto taken in the April 2022 operation) are separate and much smaller.
· PROLOGUE ·
The One That Got Big

Silk Road () launched in 2011, was shut down in 2013, and its operator received two consecutive life sentences — then was pardoned by President Trump in January 2025. The prosecution of Silk Road established the legal framework for darknet-market enforcement in the United States. The platform itself had processed approximately $200 million in revenue before it was taken down.

Hydra processed more than $5.2 billion. [SOURCE: US DOJ]

Silk Road was the original. Hydra was what the model became after a decade of iteration — larger, better organised, more deeply embedded in the Russian-language market, and in operation for seven years before it was taken down. By the time German authorities seized its servers on April 5, 2022, Hydra had some 17 million customer accounts and had handled an estimated 80 percent of all darknet-related cryptocurrency transactions worldwide in 2021. [SOURCE: US DOJ, April 2022; Chainalysis]

Stanislav Moiseyev, identified as the founder and organiser of the operation, was convicted by the Moscow Regional Court on December 2, 2024 and sentenced to life imprisonment. Fifteen accomplices received sentences ranging from 8 to 23 years. [SOURCE: TASS / Interfax as reported by Cointelegraph / BankInfoSecurity]

Two governments came for Hydra: Germany seized the infrastructure; Russia convicted the operator. The marketplace was treated as a serious crime on both sides of the jurisdictional divide.

· PART ONE ·
What Hydra Was — The Platform at Scale

Hydra Market founded approximately 2015, was a Russian-language darknet marketplace. The core business was illegal drugs — its vendors supplied narcotics to buyers across Russia and Belarus using a dead-drop model, where purchased items were left at predetermined locations rather than mailed. [SOURCE: Moscow Regional Court per TASS; BankInfoSecurity]

What made Hydra distinctive was not the business model — which was the same escrow-and-rating structure that Silk Road had established — but the scale of its integration into the Russian-speaking market and the sophistication of its financial services layer. Beyond drug sales, Hydra offered ransomware-as-a-service, hacking tools, stolen payment card data, counterfeit currency, and fake identity documents. It also operated as a cryptocurrency mixer — a service to obscure the origin of cryptocurrency transactions. [SOURCE: DOJ; BankInfoSecurity; Wikipedia]

The cryptocurrency volume reflects both the marketplace's size and its mixing function: much of the $5.2 billion figure represents money flowing through Hydra for obscuring purposes, not only for direct purchases on the market. This distinction matters: $5.2 billion is the total assessed flow, not the total value of goods sold.

Hydra's drug-supply chain operated through a network of vendors, clandestine production facilities, and storage sites hidden in vehicles, garages, and homes with secret compartments — per the Russian prosecution's account. The scale of the physical operation was documented when authorities seized approximately one tonne of illegal narcotics during raids. [SOURCE: Moscow Regional Court per TASS; BankInfoSecurity]

· PART TWO ·
The Takedown — April 5, 2022

On April 5, 2022, the German Federal Criminal Police Office (BKA), working with US Department of Justice and Treasury counterparts, announced the seizure of Hydra's Germany-based servers and the confiscation of cryptocurrency. The US Treasury's OFAC simultaneously sanctioned Hydra, cutting it off from the US financial system and any institutions with US connections. [SOURCE: DOJ announcement April 5, 2022; US Treasury]

The cryptocurrency seized in the operation amounted to approximately $25 million — the assets directly accessible on the seized infrastructure. This is the seizure figure. It is separate from the $5.2 billion in revenue the marketplace had processed over its lifetime; the vast majority of that revenue had long since been distributed or moved.

The servers were located in Germany — which explains the German-led jurisdiction. The choice of Germany for hosting was presumably not accidental; Hydra's operators sought hosting infrastructure with limited visibility to Russian authorities, though the eventual Russian prosecution of Moiseyev suggests that calculation did not hold.

The DOJ's parallel action designated Hydra as a significant transnational criminal organisation and charged Dmitry Olegovich Pavlov, a Russian national, with conspiring to run Hydra's servers through his hosting company, Promservice. [SOURCE: DOJ April 5, 2022]

· PART THREE ·
The Russian Conviction — December 2024

The Moscow Regional Court convicted Stanislav Moiseyev and 15 co-defendants on December 2, 2024. The charges: organising a criminal community and the illegal production and distribution of psychotropic substances and drugs — the Russian criminal code's framing of what the marketplace had enabled. [SOURCE: TASS / Interfax as reported; Cointelegraph; BankInfoSecurity]

The life sentence was imposed by a judge, with a fine of 4 million rubles (approximately $38,000). His accomplices received sentences of 8 to 23 years and collective fines of 16 million rubles. Moiseyev's life term is served in a special-regime colony, the strictest in the Russian system; his accomplices were sent to special- and strict-regime colonies. It was the first life sentence in Russia for a crime of this kind, according to Russian media.

The Russian conviction is independent of and parallel to the US and German actions. The Russian state prosecuted Moiseyev not under US law but under Russian criminal code, for harm done to Russia — the narcotics supplied within Russia and Belarus. The international dimension (the German server seizure, the US sanctions) provided the backdrop, but the prosecution was a domestic Russian action.

During the investigation, Moiseyev refused to disclose the password to his confiscated cryptocurrency wallet. [SOURCE: Forklog citing Interfax] The value of that wallet is not established in public reporting — it represents an unknown quantity of digital assets beyond the reach of the court's confiscation orders.

The conviction is being appealed by the defence. [SOURCE: Bitdefender citing reports] The life sentence stands pending appeal.

· PART FOUR ·
What It Means — The Model Did Not End

The Silk Road case is often framed as the founding and closing of the darknet marketplace model. The Hydra case is why that framing is wrong.

The model did not close when Ulbricht was convicted in 2015. It migrated — to other platforms, other jurisdictions, other languages. Hydra was not a successor that respected the boundaries of the original; it operated at a completely different scale in a completely different market. The Russian-language darknet economy that Hydra dominated was largely invisible to Western coverage until the April 2022 takedown made it visible.

Since Hydra's closure, per Chainalysis reporting, new Russian-language darknet markets have emerged and grown. Darknet markets generated $1.7 billion in revenue in 2023, surpassing 2022 levels even in Hydra's absence. The closure of the dominant platform created a fragmented market of successor operations, and a 'Russian darknet market conflict' among those successors. [SOURCE: Chainalysis / cryptometer.io citing Chainalysis]

The marketplace was never the crime scene. It was the infrastructure — the store, not the supply chain, not the cash-out. Moiseyev built the store and ran the community. The vendors, the producers, the customers, the money mixers: a much wider ecosystem fed through the same platform. A life sentence for the infrastructure operator does not close the supply chain.

VERIFIED SOURCES
[1] DOJ press release, April 5, 2022 — Hydra takedown. $25M crypto seized. $5.2B revenue figure. OFAC sanctions simultaneously.
[2] US Treasury/OFAC — Hydra sanctions designation, April 5, 2022.
[3] German BKA / Frankfurt prosecutors — server seizure announcement, April 5, 2022.
[4] Moscow Regional Court — conviction December 2, 2024. Life sentence. 15 accomplices 8-23 years. [SOURCE: TASS/Interfax as reported by Cointelegraph / BankInfoSecurity / Forklog / BNE IntelliNews]
[5] Chainalysis — 80% of darknet crypto transactions in 2021; $1.7B revenue in 2023 post-Hydra. Label as analytics estimate.
[6] Wikipedia — Hydra Market. 17 million registered users. Source for platform scale. [Aggregator — verify primary citations]
[7] Forklog citing Interfax — Moiseyev refused to disclose cryptocurrency wallet password during investigation.
TO VERIFY DOJ exact seizure amount vs the $25M commonly cited · The co-indictee for server infrastructure (separate DOJ case) · Moiseyev's exact dates of birth and prior record · Appeal status of the December 2024 conviction · Whether any portion of Hydra proceeds were recovered or returned
SOURCES
[1] PRIMARY — US DOJ: Hydra takedown and Pavlov charges (Apr 5, 2022)
[2] PRIMARY — German BKA: server seizure (Apr 5, 2022)
[3] PRIMARY — Moscow Regional Court verdict, as reported by TASS / Interfax (Dec 2, 2024)
[4] SECONDARY — Kommersant, Cointelegraph, The Record
[5] SECONDARY — Chainalysis darknet reports (2022–2024)
END OF REPORT
#13 OF 45
Alex Mashinsky
SINGLE PERSON
CASE 028 · CRYPTO LENDINGCONVICTED
Celsius Network · 12 years · SDNY 2025
~$4.7B
WHAT WAS TAKEN
Customers' crypto frozen when Celsius shut withdrawals in 2022 (FTC figure). He personally made $48M selling his own token.
HOW
Sold Celsius as safer than a bank while making risky bets with deposits and propping up its CEL token as he sold his own.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2017–2022Runs Celsius Network from Hoboken; promotes it weekly on 'Ask Mashinsky Anything' while, he admitted, misleading customers about its safety and propping up the CEL token.SOURCE: DOJ SDNY plea, Dec 2024
June–July 2022Freezes withdrawals, then bankruptcy.SOURCE: case brief
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: Piaras Ó Mídheach / Web Summit · CC BY 2.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
ALEX MASHINSKY
UNBANK YOURSELF · CELSIUS NETWORK · CASE 028 · CRYPTO LENDING · PLEADED GUILTY 2024 · 12 YEARS 2025
FROZEN
~$4.7B in customer assets (FTC)
HIS CUT
$48M from selling his CEL tokens
HOLE
$1.2B at bankruptcy
CUSTOMERS
~1.7 million
SENTENCE
12 years · May 8, 2025
PEAK
~$25B in assets (DOJ)
FOUR DIFFERENT NUMBERS: ~$4.7B = customer assets frozen · $1.2B = the balance-sheet hole · $48M = what he personally made selling CEL · ~$25B = Celsius at its peak (DOJ).
FULL PROFILE

IDENTITY

NAME
Alexander Mashinsky
BORN
October 1965 · Soviet Union (Ukrainian SSR); grew up in Israel
BEFORE
Serial tech entrepreneur; claims to have invented VoIP (disputed)
COMPANY
Celsius Network, founded 2017 · Hoboken, New Jersey
SLOGAN
“Unbank Yourself” · weekly “Ask Mashinsky Anything” livestreams

CASE RECORD

ARRESTED
July 13, 2023 · New York · 7 counts
PLEA
Dec 3, 2024 · commodities fraud + securities fraud (CEL manipulation)
SENTENCED
May 8, 2025 · 12 years · Judge John G. Koeltl
ASKED FOR
DOJ: 20 years · defence: 1 year and 1 day
FORFEITURE
~$48M (plea agreement)
FTC
$4.7B settlement with Celsius (2023, suspended) · $10M from Mashinsky (July 2026)
THE PEOPLE AND THE MONEY
CO-DEFENDANTTIME SERVED
Roni Cohen-Pavon
Chief revenue officer
Pleaded guilty in Sept 2023 and cooperated. Sentenced May 14, 2026 to time served, a $40,000 fine and over $1M forfeiture.
SOURCE: Cointelegraph
THE TOKENCEL
Celsius’s own coin
Propped up with customer money
Celsius bought CEL to hold its price up while Mashinsky sold his own.
SOURCE: DOJ · plea
THE PROMISE5–18% A YEAR
“Safer than a bank”
Livestream claims
No uncollateralised loans, he said. False: Celsius made them and made risky DeFi bets.
SOURCE: DOJ · plea
THE FREEZEJUNE 12, 2022
1.7M customers locked out
“Extreme market conditions”
Withdrawals, swaps and transfers halted after the Terra collapse ().
SOURCE: Celsius
THE BANKRUPTCYJULY 13, 2022
Chapter 11
$1.2B hole
Celsius left bankruptcy on Jan 31, 2024 and began paying out more than $3B to creditors.
SOURCE: Wikipedia
THE VICTIMS200+ STATEMENTS
Depositors
Retail savers
Life savings and retirement funds. Suicides were reported in victim statements and coverage.
SOURCE: Fortune · AP
SBF (CASE 005) VS MASHINSKY (CASE 028)
WHAT
: moved customer deposits to Alameda · Mashinsky: hid the risk and cashed out his token
PLEA
: convicted at trial, 7 counts · Mashinsky: pleaded guilty, 2 counts
SENTENCE
: 25 years · Mashinsky: 12 years
SAME RESULT
Withdrawals frozen, bankruptcy, customers waiting years
CASE TIMELINE
2017
Celsius founded
Crypto lending with high yields.
SOURCE: Wikipedia
Late 2021
The peak
~$25B in assets, per the DOJ.
SOURCE: DOJ
May 2022
Terra collapses
The crash spreads across crypto.
SOURCE:
June 12, 2022
Frozen
Withdrawals halted; ~$4.7B trapped.
SOURCE: Celsius
July 13, 2022
Bankruptcy
$1.2B hole.
SOURCE: court filings
July 13, 2023
Arrested
Charged in New York; FTC settlement the same day.
SOURCE: DOJ · FTC
Dec 3, 2024
Guilty
Two counts; $48M forfeiture.
SOURCE: DOJ
May 8, 2025
12 years
Judge Koeltl, SDNY.
SOURCE: DOJ
July 20, 2026
FTC
$10M settlement from Mashinsky.
SOURCE: FTC
HOW IT WORKED

HOW CELSIUS WORKED — DEFENSIVE LEVEL

01
The pitch: Deposit crypto, earn 5–18% a year, “safer than a bank”
02
The reality: Customer coins lent without enough collateral and put into risky DeFi bets
03
The token: Customer money used to buy CEL, holding its price up
04
The cash-out: Mashinsky sold his own CEL at those prices: about $48M
05
The warning sign: High fixed yields on deposits with no clear source of the return
WHERE THE DEPOSITS WENT
Customer deposits
-->
Loans & DeFi bets
-->
CEL buy-backs
-->
Frozen withdrawals

WHAT THIS CASE ESTABLISHED

“Safer than a bank” is a claim, not a guarantee: crypto deposits have no deposit insurance.
Pleading guilty to two counts still meant 12 years.
Series link: () set off the collapse; () is its mirror.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — UNBANK YOURSELF (1,300 WORDS)
Sources: DOJ/SDNY arrest July 2023 · Guilty plea December 2024 · Sentencing May 8, 2025 · Judge John G. Koeltl · FTC $4.7B settlement · Celsius bankruptcy filing July 2022 · NBC Washington / Fortune / Yahoo Finance / Reuters / The Block. METRIC DISCIPLINE: ~$4.7B = customer assets frozen (FTC figure) · ~$4.7B is also roughly what Celsius owed customers · $48M+ = Mashinsky's personal gain from CEL sales · ~$25B = peak Celsius assets under management. These are four different numbers.
· PROLOGUE ·
Safer Than a Bank

The slogan was 'Unbank Yourself.'

Celsius Network, the cryptocurrency yield platform founded and led by Alex Mashinsky, built its brand on the proposition that it was better than a traditional bank. It paid higher interest — 5 to 20 percent annually on deposited crypto, depending on the asset and the tier. It did not require credit checks. It was available globally. And it was, according to Mashinsky in his weekly 'Ask Mashinsky Anything' livestreams, safe.

'Celsius does not do non-collateralized loans,' he told customers in those livestreams. 'That would be taking too much risk on your behalf.' [SOURCE: Reuters / guilty plea record]

It was false. Celsius did make non-collateralized loans. It made risky, undisclosed bets in decentralized finance protocols. When those bets turned against it in the crypto market collapse of 2022, the hole in the balance sheet was approximately $1.2 billion. The company froze customer withdrawals on June 12, 2022 — trapping approximately $4.7 billion in customer assets. It filed for bankruptcy on July 13, 2022.

Mashinsky was arrested on July 13, 2023, exactly one year after the bankruptcy filing. He pleaded guilty on December 3, 2024, to two counts: commodities fraud and a scheme to manipulate the price of Celsius's native CEL token. He was sentenced to 12 years in federal prison on May 8, 2025, by US District Judge John G. Koeltl in Manhattan's Southern District of New York. [SOURCE: NBC Washington; Yahoo Finance; DOJ]

· PART ONE ·
What Celsius Was and What It Did

Alexander Mashinsky was born in October 1965 in the Soviet Union (the Ukrainian SSR); his family emigrated in the 1970s and he grew up in Israel. He is a serial entrepreneur who moved to the United States and built a career in technology. He claims to have invented Voice over Internet Protocol (VoIP) — a claim that is disputed but that he deployed as a credential for the Celsius brand.

Celsius Network was founded in 2017. The model was crypto lending: customers deposited Bitcoin, Ethereum, stablecoins, and other digital assets with Celsius. Celsius paid them interest — returns substantially higher than any conventional bank was offering. The interest was funded by Celsius lending those assets out to institutional borrowers and deploying them in DeFi protocols.

At its peak in late 2021, Celsius purportedly held approximately $25 billion in assets, according to the DOJ and was one of the largest crypto yield platforms in the world. It had approximately 1.7 million customers. The customer base was heavily retail — ordinary individuals who had deposited life savings, retirement funds, and emergency reserves in what Mashinsky had repeatedly told them was a safe, conservative, regulated alternative to traditional banking.

The reality, per the DOJ's charges and Mashinsky's own guilty plea: Celsius was taking risks it never disclosed. It made uncollateralized loans — which Mashinsky had specifically denied on livestream. It deployed customer assets into highly volatile DeFi protocols. The risks were not disclosed to customers in a way that would have allowed them to make informed decisions.

· PART TWO ·
The CEL Token — The Specific Fraud

The CEL token was Celsius's native cryptocurrency — its own coin, with a specific function within the platform: customers could receive higher interest rates if they held CEL, and Celsius used it as part of its yield payment structure. CEL's price mattered to Celsius's business model and to its appearance of solvency.

Mashinsky's specific plea covers what he admitted doing to the CEL token: he directed Celsius to purchase CEL in the open market to prop up its price — using customer funds to create artificial demand for a token that was also a significant part of his personal wealth. While doing this, he was personally selling his own CEL holdings. [SOURCE: DOJ; guilty plea record]

At sentencing, the court heard that Mashinsky made more than $48 million from selling CEL at inflated prices he had helped create. [SOURCE: Fortune / Yahoo Finance / NBC Washington] While he was telling customers on livestreams that he was not selling his CEL tokens, he was selling his CEL tokens.

In court in December 2024, Mashinsky stated: 'I said that Celsius had approval from regulators. It was false. I falsely said I was not selling my CEL tokens. I accept full responsibility for my actions. I did not know which law it was violating, but I knew it was wrong — and illegal.' [SOURCE: Inner City Press / Reuters, December 2024]

· PART THREE ·
The Collapse — June to July 2022

The crypto market began its major decline in May 2022. The collapse of TerraLUNA ( in this series) triggered a liquidity crisis across the sector. Celsius's positions — heavily concentrated in illiquid DeFi protocols that were themselves collapsing — created a hole in the balance sheet that the company could not cover.

On June 12, 2022, Celsius halted all withdrawals, swaps, and transfers. The platform froze. Approximately 1.7 million customers could not access their funds. The announcement cited 'extreme market conditions' — language that revealed nothing about the underlying insolvency.

The bankruptcy filing came on July 13, 2022. The $1.2 billion gap in the balance sheet became public. Customers who had deposited in good faith — retirees, families, individuals who had moved their life savings onto the platform — were now unsecured creditors in a bankruptcy proceeding.

More than 200 victim impact statements were submitted at sentencing. The judge acknowledged reports of suicides connected to the collapse. [SOURCE: Fortune; DOJ press statement at sentencing] These are the human consequences of the gap between 'safer than a bank' and the reality of what the platform was doing with deposited assets.

· PART FOUR ·
The Sentence and the Series Comparison

DOJ sought 20 years. His lawyers sought 1 year and 1 day. Probation recommended 15 years. Judge Koeltl imposed 12. [SOURCE: The Block; NBC Washington; Yahoo Finance]

Judge Koeltl described the crimes as 'extremely serious' and said a substantial sentence was needed because some customers lost everything and suffered severe psychological harm (as reported by AP). The 12-year sentence for Mashinsky sits between Ellison's 2 years (full cooperation, no personal theft) and 's 25 years (direct misappropriation of $8B, zero cooperation). The DOJ characterized the $4.7B FTC settlement with Celsius as one of the largest in the FTC's history.

The co-defendant Roni Cohen-Pavon, Celsius's former Chief Revenue Officer, pleaded guilty in September 2023 and cooperated. On 14 May 2026 Judge Koeltl sentenced him to time served, a $40,000 fine and forfeiture of over $1 million.

The Mashinsky case closes the crypto yield platform category. Every major platform of this type that was prominent in 2021 has now produced a criminal case: FTX (), Celsius (Case 028), Binance/ (). The model was the same — take depositor funds, promise yield, deploy in risky strategies — and the regulation that would have required disclosure of those risks was what each platform had spent years trying to avoid.

VERIFIED SOURCES
[1] DOJ/SDNY — arrest July 13, 2023. 7 original counts: securities fraud, commodities fraud, wire fraud, CEL manipulation conspiracy.
[2] DOJ/SDNY — guilty plea December 3, 2024. 2 counts: commodities fraud + scheme to manipulate CEL token price. Court quote from Inner City Press / Reuters.
[3] DOJ/SDNY — sentencing May 8, 2025. Judge John G. Koeltl, courtroom 14A, 500 Pearl Street, SDNY. 12 years. [SOURCE: NBC Washington; Fortune; Yahoo Finance]
[4] FTC — $4.7B settlement with Celsius Network. Contingent on bankruptcy asset distribution. [SOURCE: NBC Washington citing FTC]
[5] Celsius bankruptcy filing — July 13, 2022. $1.2B balance sheet gap. Chapter 11.
[6] The Block — DOJ sought 20 years; defense sought 1 year and 1 day; probation recommended 15 years.
[7] AP / Fortune — Judge Koeltl: 'extremely serious'; some customers lost everything and suffered severe psychological harm (reported, not verbatim). $48M+ personal gain figure.
TO VERIFY Celsius asset recovery status in bankruptcy · Mashinsky's exact net worth and asset forfeiture orders
SOURCES
[1] PRIMARY — US Attorney SDNY: arrest (July 13, 2023) and sentencing (May 8, 2025)
[2] PRIMARY — FTC: $4.7B Celsius settlement (July 13, 2023); founders settlements (July 20, 2026)
[3] SECONDARY — AP / Fortune / CNBC: plea and sentence
[4] SECONDARY — Cointelegraph: Cohen-Pavon sentenced (May 14, 2026)
[5] AGGREGATOR — Wikipedia: Alex Mashinsky; Celsius Network
END OF REPORT
#14 OF 45
Taek Jho Low / 1MDB
SINGLE PERSON
CASE 014 · SOVEREIGN FUND FRAUDFUGITIVE [ALLEGED — NOT CONVICTED]
Jho Low · alleged 1MDB mastermind · last seen Dec 24 2019
$4.5B
WHAT WAS TAKEN
Malaysian public money from the 1MDB state fund (alleged; never tried).
HOW
The US says he moved it out through shell companies and spent it on yachts, art and property.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2009Helps set up 1MDB, the state fund prosecutors say he later drained.SOURCE: DOJ forfeiture complaints
2009–2015Allegedly diverts over $4.5B from 1MDB through offshore companies.SOURCE: DOJ (alleged; never tried)
2012–2015Accounts at BSI and Falcon in Singapore allegedly move 1MDB money; the banks are later shut by the regulator.SOURCE: MAS; DOJ (alleged)
2012–2014Parties, art, property and the financing of The Wolf of Wall Street, allegedly with 1MDB money; the US later seizes the assets.SOURCE: DOJ forfeiture complaints (alleged)
2012–2013Deals with Aabar/IPIC executives through which, prosecutors say, 1MDB bond money was diverted.SOURCE: DOJ (alleged)
24 Dec 2019Reportedly last seen at Shanghai Disneyland; a fugitive since.SOURCE: press reports; Malaysian police
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
TAEK JHO LOW — 1MDB
JHO LOW · 1MALAYSIA DEVELOPMENT BERHAD · CASE 014 · SOVEREIGN FUND FRAUD · FUGITIVE
ALLEGED SCALE
$4.5B+ [ALLEGED — DOJ civil complaints]
METRIC
ALLEGED — Low never tried. Najib convicted separately.
FUND
1MDB — Malaysian sovereign fund — 30M citizens
STATUS
FUGITIVE — last seen Dec 24, 2019
NAJIB RAZAK
PM convicted — 7 counts — DOCUMENTED FACT
FILM CONNECTION
Wolf of Wall Street funded via Red Granite [ALLEGED]
BORN
November 4, 1981 · Penang, Malaysia
EDUCATION
Harrow (London) · Wharton / UPenn 2005
CRITICAL LEGAL DISCIPLINE: Jho Low is alleged. Najib Razak is convicted. Every dollar figure attached to Low is from DOJ civil forfeiture complaints — allegations, not adjudication. Najib’s 7-count conviction is Malaysian court record — documented fact. These two things must not blur anywhere in this case file. Low maintains his innocence. He has never been tried.
FULL PROFILE

IDENTITY

NAME
Taek Jho Low (Jho Low)
BORN
November 4, 1981 · George Town, Penang, Malaysia
EDUCATION
Harrow School, London · Wharton School, UPenn · graduated 2005
CONNECTIONS
Riza Aziz (stepson of PM Najib) · sovereign fund officials · politicians across multiple countries
LAST SEEN
Shanghai Disneyland · December 24, 2019
CITIZENSHIP
St Kitts & Nevis (acquired 2011, revoked 2019) · Cyprus (acquired 2015, revoked 2024)

CASE RECORD [ALLEGED / DOCUMENTED]

DOJ CHARGES
Criminal charges filed 2018 · conspiracy money laundering + related [ALLEGED]
INTERPOL
Wanted notice issued 2016 [verify notice type]
RED GRANITE
DOJ forfeiture settlement · ~$60M without admission · 2017 [VERIFY exact figure]
EQUANIMITY
~$250M superyacht · seized Indonesia · transferred to Malaysia [WSJ / DOJ]
NAJIB CONVICTION
7 counts: abuse of power · money laundering · criminal breach of trust · FACT [Malaysian court]
LOW’S DEFENSE
Maintains innocence · charges are “political persecution” · has never been tried
THE WOLF OF WALL STREET LOOP

FROM MALAYSIA’S SOVEREIGN FUND TO DICAPRIO’S OSCAR PLATFORM [ALLEGED]

Red Granite Pictures — the production company that made The Wolf of Wall Street — was co-founded by Riza Aziz, the stepson of Malaysian PM Najib Razak. The US government alleged Red Granite was funded in part with money looted from 1MDB. Red Granite settled a DOJ forfeiture action for approximately $60 million without admitting wrongdoing in 2017. The settlement is documented. The source of the funds is alleged.

(Belfort) → $200M fraud → Wolf of Wall Street film → $390M gross → funded via Red Granite [ALLEGED] → Red Granite connected to Riza Aziz → Riza = stepson of PM Najib → 1MDB [ALLEGED] → Case 014 (Jho Low / 1MDB)
The film that made a $200M boiler-room operator into a global icon was allegedly funded with a sovereign fund’s money. [SOURCE: DOJ forfeiture filings — allegation]
CASE TIMELINE
4 Nov 1981
Born, George Town, Penang
SOURCE: case brief (sources listed in its SOURCES part)
2005
Graduates University of Pennsylvania
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Builds relationships with Gulf royalty, Brunei, and Riza Aziz in London
SOURCE: case brief (sources listed in its SOURCES part)
2009
1MDB established as a Malaysian state fund
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
1MDB scandal develops
billions allegedly diverted
SOURCE: case brief (sources listed in its SOURCES part)
2011
Acquires St Kitts and Nevis citizenship (revoked 2019)
SOURCE: case brief (sources listed in its SOURCES part)
2013
The Wolf of Wall Street released via Red Granite
SOURCE: case brief (sources listed in its SOURCES part)
2015
Acquires Cyprus citizenship (revoked 2024)
SOURCE: case brief (sources listed in its SOURCES part)
2015
Scandal breaks publicly
Bersih protests in Kuala Lumpur
SOURCE: case brief (sources listed in its SOURCES part)
2016
Interpol issues a wanted notice for Low
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Equanimity superyacht seized (allegedly bought with 1MDB funds)
SOURCE: case brief (sources listed in its SOURCES part)
2018
Najib Razak arrested and charged
SOURCE: case brief (sources listed in its SOURCES part)
24 Dec 2019
Low disappears
reportedly last seen at Shanghai Disneyland
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Najib convicted on 7 counts
SOURCE: case brief (sources listed in its SOURCES part)
2024
Cyprus revokes his citizenship
SOURCE: case brief (sources listed in its SOURCES part)
HOW THE FRAUD WORKED

THE STORY ON BOTH SIDES — FROM THE CASE BRIEF

01
The allegation (US prosecutors called Low the "mastermind"): 1MDB was a state investment fund
02
Low is alleged to have siphoned over $4.5 billion from it
03
The proceeds allegedly funded: luxury real estate, art, jewellery, celebrity parties, and the yacht Equanimity (seized)
04
He moved through multiple citizenships — Malaysia, St Kitts (revoked 2019), Cyprus (revoked 2024)
05
His defence (must be included — it's part of the record): Low maintains his innocence
06
He contends the Malaysian authorities are engaged in a "campaign of harassment and political persecution" tied to his prior support of Najib Razak
07
He has never been tried
08
The Najib side (convicted, not alleged): Former PM Najib Razak was convicted on seven counts — abuse of power, money laundering, criminal breach of trust
09
His role in 1MDB is why he fell
10
The scale of consequence: a sitting government fell, a prime minister was convicted, and the alleged architect vanished — and is still gone.
DEFENSIVE LEVEL ONLY · THE SHAPE OF THE SCHEME, NOT A PLAYBOOK

WHAT THIS CASE ESTABLISHED

The fund: every other case in this series is a private fraud. 1MDB’s money was never offered to investors. It was raised in the name of a country — by a government vehicle — and allegedly diverted. The 30 million people of Malaysia had not chosen anything. They did not know the fund existed. The money was theirs by virtue of citizenship.
A sitting prime minister was convicted. Malaysia had never before convicted a sitting or former prime minister. Najib Razak: 7 counts, documented fact. The fraud had an electoral consequence — it contributed to Najib’s coalition losing power in 2018 for the first time since Malaysian independence.
Second fugitive in the series (after Ignatova). But where Ignatova may be dead, Low is almost certainly alive, likely in a jurisdiction with limited extradition, and almost certainly in contact with legal advisors. Different kinds of disappeared.
The connection to is documented in DOJ filings: the film that turned a convicted boiler-room operator into a cultural icon was allegedly funded with money looted from Malaysia’s people. The loop from the sovereign fund to the Hollywood production to the Oscar nominations is one of the more vertiginous connections in the history of financial fraud.
Series thesis, Case 014: The Fund. Not a private fraud — a sovereign one. The country was the victim. The government was the vehicle. The people had no choice.
BACKGROUND & BIOGRAPHY

EARLY LIFE & EDUCATION

FULL NAME
Low Taek Jho (刘特佐)
BORN
4 November 1981 · George Town, Penang, Malaysia
FAMILY
Wealthy Penang business family · father a successful businessman
SECONDARY SCHOOL
Harrow School · England · built critical UK elite connections
UNIVERSITY
University of Pennsylvania · Wharton School · graduated 2005
WHARTON NETWORK
Met Riza Aziz (stepson of PM Najib) · developed international elite relationships
EARLY CAREER
Advisor to Gulf royalty · leveraged Wharton connections in Middle East and Southeast Asia
PERSONA
Presented himself as dealmaker with access to sovereign wealth · ultra-connected financier

THE LIFESTYLE (ALLEGED)

PROPERTIES
Luxury residences in New York, Los Angeles, Las Vegas, London, Abu Dhabi [DOJ civil forfeiture]
YACHT
Equanimity · 300-ft superyacht · ~$250M · seized 2018 by Indonesian authorities [WSJ / DOJ]
ART COLLECTION
Monet, Picasso, Basquiat, Van Gogh — hundreds of millions [DOJ forfeiture]
CELEBRITY PARTIES
Hosted parties for DiCaprio, Paris Hilton, Jamie Foxx · rented out clubs in New York and Las Vegas
GAMBLING
Reportedly spent millions at Las Vegas casinos · one night reportedly $1M at tables
HOLLYWOOD
Co-financed The Wolf of Wall Street (2013) via Red Granite Pictures [DOJ — alleged]
JEWELLERY
Diamonds purchased allegedly for PM Najib's wife Rosmah Mansor [DOJ — alleged]
NOTE
All above are ALLEGED conduct from DOJ civil forfeiture filings. Low denies wrongdoing.
1MDB — THE FUND & THE ALLEGED FRAUD

1MDB OVERVIEW

FULL NAME
1Malaysia Development Berhad
TYPE
Malaysian sovereign investment fund · wholly owned by Ministry of Finance
ESTABLISHED
2009 · under PM Najib Razak's government
PURPOSE (STATED)
Attract foreign investment · develop national infrastructure · long-term returns for Malaysian citizens
PURPOSE (ALLEGED)
DOJ alleges fund was used to siphon >$4.5B through shell companies [DOJ civil forfeiture]
VICTIM
30 million Malaysian citizens — the fund belonged to the people, not to the government
SERIES DISTINCTION
Unlike every other case: the money had an owner before it was stolen. No one opted in.

NAJIB RAZAK — THE CONVICTION SIDE

FULL NAME
Dato' Sri Haji Mohammad Najib bin Tun Haji Abdul Razak
ROLE
6th Prime Minister of Malaysia · in office 2009–2018
RELATIONSHIP TO LOW
Political enabler — Low developed close ties via Riza Aziz (Najib's stepson)
CONVICTED
7 counts — abuse of power, money laundering, criminal breach of trust [Malaysian courts — FACT]
ELECTION RESULT
Najib's coalition lost 2018 Malaysian general election — first time in history ruling coalition lost
SIGNIFICANCE
First Malaysian prime minister ever convicted · historically unprecedented
NOTE — LEGAL DISCIPLINE
Najib is CONVICTED. Low is ALLEGED and never tried. These are categorically different.

THE FUGITIVE STATUS — WHERE IS HE NOW

Last confirmed sighting: Shanghai Disneyland, December 24, 2019. He was 38 years old. He has not been publicly located since.
Citizenship history: Malaysia (original) · St Kitts and Nevis (acquired 2011, revoked 2019) · Cyprus (acquired 2015, revoked 2024). Each revocation removed a travel document. The infrastructure of mobility is being dismantled.
Interpol Red Notice issued 2016 — well before his disappearance. He went underground while the notice was already active.
FBI has not confirmed his death. He remains an active fugitive on Interpol and DOJ wanted lists.
Murder hypothesis: BIRD (Bulgarian investigative outlet) published February 2023 a police document claiming a Bulgarian crime figure ordered a hit on Ignatova on a yacht — but that is Ignatova, not Low. Low's disappearance has no equivalent confirmed hypothesis. He is believed alive.
His defense position: maintains innocence. Calls the case a 'campaign of harassment and political persecution' tied to his support of Najib. Has never appeared in court to contest the charges.
THE FULL STORY — 8 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE FUND (3,000 WORDS)
Sources: US DOJ 1MDB civil forfeiture actions · DOJ charges against Low, 2018 · Interpol wanted notice, 2016 · Malaysian courts — Najib Razak convictions (7 counts) · US Red Granite forfeiture settlement · Bloomberg (May 2026) · BBC · AP · Reuters · WSJ (Equanimity) · Wikipedia (aggregator). DISCIPLINE: $4.5B+ is ALLEGED — Low was never tried. Najib's 7-count conviction is DOCUMENTED FACT. These two things must not blur anywhere in this document.
· PROLOGUE ·
The Loop

In of this series, : the fraud cost $200 million, the film made him immortal, and the legend outlasted the crime by every measure.

The film was The Wolf of Wall Street. Martin Scorsese directed it. Leonardo DiCaprio played Belfort. It grossed over $390 million worldwide. Five Academy Award nominations.

The production company was Red Granite Pictures. Red Granite was co-founded by Riza Aziz — the stepson of Malaysian Prime Minister Najib Razak.

The United States government alleged that Red Granite was funded, in part, with money looted from 1Malaysia Development Berhad — a Malaysian state investment fund known as 1MDB. In 2017, Red Granite settled a US forfeiture action for approximately $60 million without admitting wrongdoing. [SOURCE: DOJ forfeiture settlement — verify exact figure before publication]

The alleged architect of the 1MDB fraud — the man the US Department of Justice called the 'mastermind' — was Taek Jho Low. A Malaysian financier, born in Penang, educated at the University of Pennsylvania, who built relationships with royalty and politicians across multiple continents and who, the US government alleged, siphoned over $4.5 billion from a fund that belonged to the Malaysian people. [SOURCE: DOJ civil forfeiture complaints — allegation, not adjudication; Low has never been convicted]

He was last reportedly seen on December 24, 2019, at Shanghai Disneyland. He has not been found since.

· PART ONE ·
From Penang to Pennsylvania — Who He Was

Taek Jho Low was born on November 4, 1981, in George Town, Penang, Malaysia. He came from a wealthy family — his father was a businessman — and his early trajectory was the trajectory of a certain kind of ambitious, globally mobile young man from Southeast Asia: elite secondary school in England (Harrow), then the United States for university.

He attended the University of Pennsylvania's Wharton School and graduated in 2005. Wharton is one of the most selective business schools in the world. The network it produces — the classmates, the professors, the alumni, the events — was part of what Low leveraged in the years that followed. He was good at building relationships. He was good at inserting himself into rooms where the people with power were, and presenting himself as someone who also had power.

While in London and later internationally, he developed a close relationship with Riza Aziz — whose mother, Rosmah Mansor, would later marry Najib Razak, the man who became Prime Minister of Malaysia. These relationships — the British school, the American university, the political connections through Riza — were the infrastructure Low built before 1MDB existed.

By his late twenties he was moving between Kuala Lumpur, Abu Dhabi, Singapore, London, and New York, attending events that mixed finance, politics, and entertainment with a specific kind of aspiration. He was present at parties with celebrities. He was present in rooms with sovereign wealth fund officials. He was present at the kind of gathering where a young man who presents himself as having access to serious money is treated as someone who has access to serious money.

He had not yet committed any crime. He was building the access that would, according to US prosecutors, later be used to commit one.

· PART TWO ·
1MDB — The Fund, the Purpose, the Promise

1Malaysia Development Berhad was established in 2009 as a Malaysian state strategic development company — a sovereign fund intended to attract foreign investment, develop infrastructure, and generate long-term returns for the Malaysian people. It was a government vehicle, wholly owned by the Malaysian Ministry of Finance. The money it raised was public money. The people it was supposed to serve were Malaysian citizens.

Sovereign wealth funds of this kind are not inherently unusual. Countries around the world — Norway, Singapore, Abu Dhabi, Kuwait — manage large state funds that invest nationally and internationally, generating returns that benefit the country's citizens. The model is legitimate and well-established. 1MDB was established in that tradition.

What allegedly happened to it was not in that tradition. According to the United States Department of Justice's civil forfeiture complaints and criminal charges, approximately $4.5 billion was siphoned from 1MDB through a complex network of transactions, shell companies, and international banking relationships. [SOURCE: DOJ civil forfeiture complaints — these are allegations; Low has not been convicted]

The mechanism, at its most basic: 1MDB raised money through bond issuances and joint ventures. The money raised was supposed to be invested. Instead, the DOJ alleged, a substantial portion was diverted — moved through intermediary accounts, converted into assets, and spent on things that had nothing to do with Malaysian infrastructure or development. [SOURCE: DOJ civil forfeiture filings — alleged]

The money had an owner from the beginning. That is what makes 1MDB distinct in this series. Madoff's victims were investors who had chosen to trust him. Holmes's investors were sophisticated funds and wealthy individuals. Ignatova's victims were millions of people who had opted into OneCoin. The money in 1MDB had a different character: it was the Malaysian people's money, administered by a government vehicle, and the Malaysian people had not chosen anything. It was simply taken — allegedly.

· PART THREE ·
The Alleged Spending — What the DOJ Says It Bought

The United States government filed civil forfeiture actions beginning in 2016, seeking the recovery of assets it alleged were purchased with money stolen from 1MDB. The complaints describe, in considerable detail, what the money allegedly bought. [SOURCE: DOJ civil forfeiture complaints — all figures below are allegations]

Real estate. Multiple high-end properties in New York, Los Angeles, London, and elsewhere were among the assets the DOJ alleged were purchased with 1MDB proceeds. The New York properties included luxury apartments in buildings that represent the most expensive residential real estate in the United States.

Art. The DOJ alleged that works by Monet, Picasso, Basquiat, and others — a collection valued at hundreds of millions of dollars — were purchased with proceeds. These were not financial investments in the conventional sense. They were physical assets that could be held, displayed, lent, and sold.

The Equanimity. A 300-foot superyacht, valued at approximately $250 million, was alleged to have been purchased with 1MDB funds. The yacht was eventually seized by Indonesian authorities at the request of the US government and transferred to Malaysia. [SOURCE: WSJ reporting; DOJ filings — allegation]

Jewellery. The DOJ alleged that jewellery purchased for Rosmah Mansor — the wife of Prime Minister Najib Razak — was paid for with 1MDB money. This allegation intersects with the Najib case.

The film. Red Granite Pictures — the production company that made The Wolf of Wall Street — was alleged to have been funded with 1MDB proceeds. Red Granite settled a US forfeiture action for approximately $60 million without admitting wrongdoing. The settlement is documented. The source of the funds is alleged. [SOURCE: DOJ forfeiture settlement — verify exact $60M figure before publication]

Parties. Celebrity events. The kinds of gatherings that generate photographs and social media footage — people with extraordinary wealth in rooms where that wealth is displayed — were allegedly funded with this money. The optics were the point. The presence at these events was itself a form of credential.

· PART FOUR ·
Red Granite — The Wolf of Wall Street Connection

This is the loop the case closes. State it plainly.

Red Granite Pictures was a Hollywood production company co-founded by Riza Aziz, the stepson of Malaysian Prime Minister Najib Razak. Low had developed a close relationship with Riza in London, in the years before 1MDB became the dominant fact of both their lives.

Red Granite produced The Wolf of Wall Street in 2013. The film that made — in this series, a man who defrauded 1,513 clients of approximately $200 million — into a global cultural icon was produced by a company that the US government alleged was funded with money stolen from Malaysia's people.

The United States Department of Justice filed a civil forfeiture action targeting, among other assets, money that had flowed through Red Granite. In 2017, Red Granite settled the action for approximately $60 million without admitting wrongdoing. [SOURCE: DOJ forfeiture settlement — exact figure needs primary verification]

Riza Aziz was separately charged in Malaysia. His case proceeded through Malaysian courts.

The Wolf of Wall Street, the film, received no formal sanction. It continues to exist as a film. It continues to be watched. It continues to make Belfort famous. The money that allegedly funded its production has been the subject of a settled forfeiture action. The relationship between the production and the alleged fraud is documented in the DOJ filings. What the audience sees when they watch the film — DiCaprio screaming on a yacht, Belfort living a life of extraordinary excess — was made possible by financing that the US government alleged came from an extraordinary theft.

· PART FIVE ·
Najib Razak — The Prime Minister Who Fell

Najib Abdul Razak was the sixth Prime Minister of Malaysia. He served from 2009 to 2018. 1MDB was established under his government in 2009. He sat on its advisory board. His stepson was connected to the production company the DOJ alleged was funded with 1MDB money. His wife was alleged to have received jewellery purchased with 1MDB proceeds.

These are allegations about the 1MDB case. What is not an allegation is the verdict.

In 2018, after the ruling coalition he had led for decades lost a general election — the first time in Malaysian history that the coalition had lost power since independence — Najib was arrested and charged. The case against him proceeded through the Malaysian court system.

He was convicted on seven counts: criminal breach of trust, money laundering, and abuse of power. [SOURCE: Malaysian court record] These are convictions. They are facts in the same sense that Madoff's guilty plea is a fact or that 's jury verdict is a fact. Najib Razak was convicted on seven counts by a Malaysian court. His appeal processes have proceeded.

The precedent is historical. Malaysia had never before convicted a sitting or former prime minister. The conviction was, in the context of Malaysian political history, an event without equivalent.

This is the specific dual structure that makes Case 014 unusual in the series. () is also a fugitive — but her co-defendants were convicted, not her government. Here the alleged architect remains free, the alleged political enabler was convicted, and the country itself was the victim.

· PART SIX ·
The Disappearance — Shanghai Disneyland

On December 24, 2019, Taek Jho Low was reportedly seen at Shanghai Disneyland.

It is Christmas Eve. He is reportedly at a theme park in China. By this point he has been a named subject of DOJ investigation since 2016, has had an Interpol notice issued against him, has had his St Kitts and Nevis citizenship revoked, and is a global fugitive by any reasonable characterisation of the word.

He has not been publicly confirmed as located anywhere since.

This is the second case in this series — after Ignatova — where a central subject has vanished. But where Ignatova's disappearance has a possible murder hypothesis attached to it, Low's disappearance has a different character: he is almost certainly alive, likely in a jurisdiction with limited extradition arrangements with the countries seeking him, and almost certainly in contact with lawyers and advisors. He is not gone in the way Ignatova might be gone. He is hidden.

China has been consistently suggested as his location of refuge, given the Shanghai Disneyland sighting and the complexity of extradition arrangements. [SOURCE: widely reported — secondary sources; not confirmed by any official body] China has not extradited him. He has not surfaced in any court.

His St Kitts and Nevis citizenship, acquired in 2011 to provide an additional travel document, was revoked in 2019. His Cyprus citizenship, acquired in 2015, was revoked in 2024. The citizenship revocations represent the systematic removal of the travel infrastructure he had built — passport by passport.

He remains on Interpol's wanted list. He remains subject to US criminal charges. He remains, as of this writing, at large.

· PART SEVEN ·
His Defense — What Jho Low Says

Jho Low maintains his innocence.

Through statements issued by his representatives — typically through lawyers and press agents rather than in-person appearances — he has consistently denied the allegations against him. His position, stated publicly and consistently: the charges are part of a 'campaign of harassment and political persecution' connected to his prior association with and support of Najib Razak and the political faction that Najib represented.

He contends that the 1MDB investigation, as conducted by the Malaysian authorities who came to power after Najib's coalition lost the 2018 election, is politically motivated — an attempt by a new government to use the legal system against figures associated with the old government.

He has never been tried. He has never had the opportunity to present a full defense in court, because he has not been present in any court to present one. The allegations the DOJ has made against him are, in the strict legal sense, unproven — not because evidence does not exist but because no trial has occurred.

This defense must be included and stated clearly. It is part of the record. He is a living person who has not been convicted of anything. The discipline of alleged/convicted that runs through this entire document requires that his denial be given the same weight as the allegation.

· PART EIGHT ·
What It Means — The Fund

The series thesis for Case 014 is this: the fund.

Every other case in this series is a private fraud. defrauded individuals and institutions who had chosen to trust him. Madoff defrauded investors who had opted in. Holmes defrauded investors who had written checks. Ignatova defrauded 3.5 million people who had bought a product. Even Stanford's fraud — the case this most closely resembles in scale and geography — targeted individual investors who had purchased certificates of deposit.

1MDB was different. The money was never offered to investors in the ordinary sense. It was raised in the name of a country — by a government fund, through bond issuances that committed the Malaysian state — and then allegedly diverted. The 30 million people of Malaysia had not chosen anything. They had not purchased anything. They did not know the fund existed in any meaningful sense. The money was theirs by virtue of being citizens of a country whose government controlled it.

That is the specific character of this case that distinguishes it. And the consequence was proportionate: not just financial losses to identifiable investors, but a political catastrophe — the fall of a government, the conviction of a prime minister, the exposure of state-level corruption at a scale that Malaysia had not seen before.

The 1MDB scandal is one of the reasons Najib Razak's coalition lost the 2018 election. It is one of the reasons he was subsequently arrested and convicted. The fraud — if proven in Low's case, which it has not been — had an electoral consequence. It changed a country's government.

And it allegedly funded a movie. The Wolf of Wall Street. The film that took a fraud that cost $200 million and made it into a legend. The money that was supposed to develop Malaysia built DiCaprio's award platform.

That loop — from Malaysian infrastructure fund to Hollywood production to global celebrity for a convicted boiler-room operator — is one of the more vertiginous connections in the history of financial fraud. It is documented in DOJ filings. It is alleged in the sense that Low has not been convicted. The settlement is real. The film exists.

FULL TIMELINE
VERIFIED SOURCES AND VERIFICATION TARGETS

The central discipline: Low is alleged. Najib is convicted. Every dollar figure attached to Low is from DOJ civil forfeiture complaints — allegations, not adjudication. Najib's seven-count conviction is Malaysian court record — documented fact. Low maintains innocence throughout.

[1] US DOJ — 1MDB civil forfeiture actions and complaints (filed from 2016). Source for all 'alleged' figures and conduct attributed to Low.
[2] DOJ charges against Low — 2018. Source for criminal allegations.
[3] Interpol — wanted notice for Low, issued 2016. Type of notice: verify (Red Notice or standard wanted) before publication.
[4] Malaysian courts — Najib Razak conviction, 7 counts: abuse of power, money laundering, criminal breach of trust. FACT. Verify current status of sentencing and any appeals.
[5] DOJ — Red Granite Pictures forfeiture settlement, 2017. Amount: ~$60 million without admission of wrongdoing. Verify exact figure against primary DOJ press release.
[6] Bloomberg — 'All About Jho Low, the Alleged Mastermind of the 1MDB Scandal' (May 2026).
[7] BBC — '1MDB: The playboys, PMs and partygoers around a global financial scandal.'
[8] WSJ — Equanimity superyacht reporting. AP — '1MDB: The fund at the center of a scandal in Malaysia.'
[9] Reuters / NST — Najib explainer (Dec 2025).

VERIFY BEFORE PUBLICATION Red Granite settlement exact figure ($60M) · Najib's current sentence/appeal status · Shanghai Disneyland sighting — confirm sourcing (widely reported, secondary only) · Interpol notice type · Exact citizenship revocation dates for St Kitts (2019) and Cyprus (2024)

END OF REPORT
#15 OF 45
Changpeng Zhao (CZ)
SINGLE PERSON
CASE 015 · CRYPTO / COMPLIANCEPARDONED OCT 2025
Binance founder · world’s largest crypto exchange · 4 months · pardoned
$4.3B
WHAT WAS TAKEN
Nothing stolen. This is the fine Binance paid the US government.
HOW
Let Binance run without real anti-money-laundering checks.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2017Founds Binance in Shanghai; leaves after China bans crypto exchanges that autumn.SOURCE: case brief
2017–2018Binance operates from Japan until the regulator warns it is unlicensed.SOURCE: case brief; FSA warning 2018
2019–2023Lives in Dubai and runs Binance from there; the DOJ says the exchange failed to run an anti-money-laundering programme in these years.SOURCE: DOJ plea agreement, Nov 2023
Nov 2023–Sept 2024Pleads guilty in Seattle, serves four months at FCI Lompoc, California.SOURCE: W.D. Wash.
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
CHANGPENG ZHAO
CZ · BINANCE FOUNDER · CASE 015 · BSA VIOLATION · PARDONED OCT 2025
BINANCE PENALTY
$4.3B [COMPANY — not CZ personally]
CZ PERSONAL FINE
$50M [DOJ plea agreement]
CHARGE
1 count · Bank Secrecy Act violation (AML failure)
NOT CHARGED WITH
Fraud · theft · misappropriation
SENTENCE
4 months · Judge Richard A. Jones · Seattle
PARDONED
October 23, 2025 · President Trump
BORN
September 10, 1977 · Jiangsu, China
FIRST
First person sentenced to prison for single BSA violation
THREE FIGURES — THREE THINGS: $4.3B = Binance company penalty · $50M = CZ personal fine · 4 months = prison sentence. Never combine. He was NOT charged with fraud, theft, or misappropriation of customer funds. The distinction between this case and () is the entire moral and legal difference between the two outcomes.
FULL PROFILE

IDENTITY

LEGAL NAME
Changpeng Zhao
KNOWN AS
CZ
BORN
September 10, 1977 · Jiangsu, China
RAISED
Vancouver, Canada
EDUCATION
McGill University · Computer Science
CITIZENSHIP
UAE · Canada
BINANCE FOUNDED
2017 · via ICO · initially Hong Kong
BINANCE SCALE
World’s largest crypto exchange by trading volume

CASE RECORD

PLEA
Guilty · November 21, 2023 · Seattle
CHARGE
1 count failing to maintain effective AML program (Bank Secrecy Act)
BINANCE SETTLEMENT
$4.3B · DOJ + Treasury/FinCEN + CFTC
PERSONAL FINE
$50M
JUDGE
Hon. Richard A. Jones · Seattle
SENTENCED
4 months · April 30, 2024
DOJ SOUGHT
36 months · defense sought zero prison
SERVED
FCI Lompoc, California · Jun–Sep 2024
PARDONED
October 23, 2025 · President Trump · full and unconditional
CEO STATUS
Resigned as CEO per plea agreement · Richard Teng now runs Binance · CZ retained equity
SBF VS CZ — THE SAME ERA, THE DIFFERENT CRIME

NOT THE SAME CASE

/ FTX ()
Took $8B in customer funds. Used them at Alameda. Customers lost savings. Convicted all 7 counts. 25 years.
CZ / Binance (Case 015)
Failed to build adequate AML controls. Criminals used the exchange. Exchange customers were NOT the victims. 1 count BSA. 4 months. Pardoned.
THE DIFFERENCE
FTX harm: customers deposited money expecting safety — it was taken. Binance harm: criminals moved proceeds of their crimes because controls were inadequate. Both real. Not the same harm. The legal system reflected the distinction: 25 years vs 4 months.
“You had the wherewithal, the finance capabilities, and the people power to make sure that every single regulation had to be complied with, and so you failed at that opportunity.”
Judge Richard A. Jones · Seattle · April 30, 2024 [SOURCE: CNBC / AP]
THE PARDON — OCTOBER 23 2025

FULL AND UNCONDITIONAL — PRESIDENT TRUMP

“Deeply grateful for today’s pardon and to President Trump for upholding America’s commitment to fairness, innovation, and justice.”
CZ via X · October 23, 2025 [SOURCE: Axios / AP]

The pardon erases his conviction and restores his civil rights. It does NOT affect the $4.3B Binance company penalty — the corporate settlement stands. The DOJ’s findings about what Binance allowed to happen are part of the historical record. The pardon removes the personal criminal conviction. It does not change what the exchange did. White House: “no allegations of fraud or identifiable victims” — a framing contested by the DOJ’s own filings. [SOURCE: AP / Reuters / Axios, Oct 23 2025]

Part of a broader pattern: Trump also pardoned () and three BitMEX founders who had also pleaded guilty to BSA violations. [SOURCE: Fortune, May 2025]

CASE TIMELINE
1977
Born Jiangsu, China
raised partly in Canada
SOURCE: public record
2013
Enters crypto
joins Blockchain.info team
SOURCE: public record
2017
Founds Binance
ICO, Hong Kong
SOURCE: public record
2018–2023
Binance grows to largest exchange by volume
SOURCE: public record
2023
DOJ + CFTC + Treasury actions against Binance and CZ
SOURCE: DOJ
21 Nov 2023
CZ pleads guilty to BSA charge
steps down as CEO; $50M fine
SOURCE: DOJ / W.D. Wash.
Nov 2023
Binance agrees to $4.3B resolution
SOURCE: DOJ
30 Apr 2024
Judge Jones imposes 4 months (DOJ had sought 36)
SOURCE: W.D. Wash.
June 2024
Reports to FCI Lompoc
SOURCE: BOP-reported
27 Sept 2024
Released
≈4 months served
SOURCE: BOP-reported
HOW THE FRAUD WORKED

THE POINT OF THIS CASE — FROM THE CASE BRIEF

01
is . Case 015 is CZ. They are opposite poles of the same industry.
02
Charge: () — Fraud, conspiracy, misappropriation · CZ (Case 015) — AML compliance failure
03
Customer funds stolen?: () — Yes — $8B · CZ (Case 015) — No — never alleged
04
What went wrong: () — He took the money · CZ (Case 015) — He let dirty money move
05
Sentence: () — 25 years · CZ (Case 015) — 4 months
06
What Binance actually did wrong (DOJ, Nov 2023): Failed to register as a money services business as required
07
Failed to maintain an effective AML program
08
Allowed transactions with sanctioned entities — including, per DOJ, transactions connected to Hamas, al-Qaeda, ISIS, and darknet markets
09
Processed transactions for US customers while claiming to block them
10
Violated the Bank Secrecy Act and U.S. sanctions law
11
What Binance did NOT do (per the record): misappropriate customer funds, run a fractional reserve, or steal deposits. This is not a bankruptcy case. It is a compliance case.
stole his customers' money. CZ failed to stop other people's money from moving through his exchange. One is theft. One is a failure to police theft. The series must never blur these, because blurring them is exactly the lie the industry tells about itself — and the lie the public assumes.
DEFENSIVE LEVEL ONLY · THE SHAPE OF THE SCHEME, NOT A PLAYBOOK
KNOWN NETWORK & CONNECTED CASES

WHAT THIS CASE ESTABLISHED

The door. He built Binance — the world’s largest crypto exchange — without building adequate compliance infrastructure around it. The door was real. The exchange was real. The controls were not.
First person ever sentenced to prison for a single Bank Secrecy Act violation. The BSA has been law since 1970. Nobody had served prison time for a single BSA count before CZ. The novelty of the precedent is a data point about the scale of the failure.
The transactions that moved through the non-compliant exchange had real-world consequences — Hamas-connected, ISIS-connected, darknet market transactions. The compliance failure was a material contribution to harm even though CZ was not the person doing the harm.
The ratio: $4.3B from the company, $50M from the individual, 4 months in minimum-security prison, then a full pardon. Whether that reflects proportionate justice for running the world’s largest exchange without required AML controls is a question this case file leaves for the reader.
The pardon connects to : both Ulbricht and CZ — the Silk Road founder and the Binance founder — were pardoned by Trump in his second term. Different crimes, different sentences, same executive action.
Series thesis, Case 015: The Door. He built it. He did not guard it. The company paid $4.3 billion. He served 4 months. Then a president pardoned him.
BIOGRAPHY & BINANCE BACKGROUND

EARLY LIFE & CAREER

FULL NAME
Changpeng Zhao
BORN
10 September 1977 · Jiangsu, China
EMIGRATED
Late 1980s · Vancouver, Canada · grew up Canadian
EDUCATION
McGill University · Montreal · computer science degree
EARLY CAREER
Tokyo Stock Exchange · Bloomberg Tradebook (futures trading systems) · OKCoin (crypto exchange)
CRYPTO ENTRY
2013 · joined Blockchain.info · built trading expertise in the emerging crypto space
BINANCE FOUNDED
2017 · ICO in Hong Kong · timed the 2017 bull market perfectly · grew faster than any exchange before
PEAK
Binance became largest cryptocurrency exchange by volume · CZ net worth estimated billions at peak

THE COMPLIANCE FAILURE — WHAT BINANCE DID WRONG

THE CHARGE
Bank Secrecy Act — failure to maintain an effective anti-money-laundering program
NOT CHARGED WITH
Fraud · theft · misappropriation of customer funds — these were never alleged
FAILURE 1
Did not register as a money services business as required while serving US customers [DOJ]
FAILURE 2
Inadequate Know Your Customer program — users transacted without meaningful identification [DOJ]
FAILURE 3
Processed transactions connected to Hamas, al-Qaeda, ISIS, darknet markets [DOJ plea agreement]
FAILURE 4
Claimed to block US customers via geo-restrictions · DOJ found the implementation was ineffective
THE DISTINCTION
took his customers' money. CZ failed to stop other people's dirty money from moving. One is theft. One is a failure to police theft.
CUSTOMER FUNDS STATUS
Binance customers could access and withdraw their funds — no collapse, no bankruptcy, no $8B hole
THE PARDON & THE RATIO

THE UNPRECEDENTED SENTENCE

JUDGE
Hon. Richard A. Jones · SDNY
DOJ SOUGHT
36 months
SENTENCED
4 months
HISTORIC FIRST
First person EVER sentenced to prison for a single BSA violation in American history [AP / Fortune]
PRISON
FCI Lompoc · California · low security · reported June 2024
RELEASED
September 27, 2024 [BOP-reported · verify exact dates]
STEPPED DOWN
Resigned as Binance CEO as part of plea · Richard Teng became CEO · CZ retained equity
POST-RELEASE
Active in crypto community · investor · advisor · brand remained intact

THE PARDON — OCTOBER 23, 2025

DATE
October 23, 2025
TYPE
Full and unconditional presidential pardon · President Trump
ANNOUNCED BY
White House Press Secretary Karoline Leavitt
WHITE HOUSE FRAMING
Biden administration 'war on cryptocurrency' · 'no allegations of fraud or identifiable victims'
CZ STATEMENT
'Deeply grateful for today's pardon and to President Trump for upholding America's commitment to fairness, innovation, and justice.' [CZ via X]
WHAT PARDON CHANGES
Erases his personal criminal conviction · restores civil rights
WHAT PARDON DOES NOT CHANGE
$4.3B Binance company penalty stands · historical record of what Binance allowed stands
PATTERN
Trump also pardoned Ulbricht (life sentence) and BitMEX founders in same crypto-friendly administration

THE $4.3B vs $50M RATIO

Binance paid $4.3 billion. CZ paid $50 million. The company paid 86 times what the individual paid personally. He served 4 months. Then he was pardoned.
That ratio — $4.3B corporate penalty, $50M personal fine, 4 months minimum security, then a full pardon — is the structure of accountability for the world's largest crypto exchange running an inadequate AML program for years while sanctioned-entity money moved through it.
The pardon removes his conviction. It does not change what happened on the exchange. Hamas connected transactions moved through Binance. ISIS-connected transactions moved through Binance. That is in the plea agreement. The pardon changed his status. It did not change the facts.
He built the door. He did not guard it. The company paid $4.3 billion. That ratio is American justice in the crypto age.
THE FULL STORY — 7 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE DOOR (2,600 WORDS)
Sources: US DOJ plea agreement and press release, Binance/CZ (21 Nov 2023) · W.D. Wash. sentencing, Judge Richard A. Jones (Apr 2024) · US Treasury/FinCEN and CFTC actions · BOP custody records (reported) · Presidential pardon, October 23, 2025 (White House / Axios / Reuters / AP) · Reuters, Bloomberg, CNBC coverage. NOT CHARGED WITH: fraud, theft, misappropriation of customer funds. $4.3B = Binance company penalty. $50M = CZ's personal fine. Never combine or conflate.
· PROLOGUE ·
Two Men. Two Exchanges. Two Crimes.

In November 2022, FTX collapsed. had taken $8 billion in customer funds and used them to cover losses at his trading firm. He was convicted on all seven counts. He is serving 25 years in federal prison in California.

The man whose tweet — announcing Binance would sell its FTT holdings — triggered the bank run that ended FTX was Changpeng Zhao. CZ. The founder and CEO of Binance, the largest cryptocurrency exchange in the world by trading volume.

One year after FTX collapsed, on November 21, 2023, CZ pleaded guilty in federal court in Seattle. His charge: one count of failing to maintain an effective anti-money-laundering program, in violation of the Bank Secrecy Act. Binance simultaneously agreed to a resolution with the US Department of Justice totalling $4.3 billion — one of the largest corporate penalty settlements in American history.

He was sentenced to four months in federal prison. He served them. He was released in September 2024.

On October 23, 2025, President Donald Trump granted him a full and unconditional presidential pardon. [SOURCE: AP / Reuters / Axios / White House, October 23, 2025]

These two men — and CZ — are the two dominant figures in the crypto exchange story of this era. Their cases are not the same case. The series treats them as separate because they are separate. committed fraud. CZ failed at compliance. The distinction is not a technicality. It is the entire moral and legal difference between the two outcomes.

· PART ONE ·
From Jiangsu to Montreal to the World's Largest Exchange

Changpeng Zhao was born on September 10, 1977, in Jiangsu province, China. He emigrated to Canada with his family in the late 1980s and grew up in Vancouver. He attended McGill University in Montreal, where he studied computer science.

His career before crypto was in finance and technology: he worked at the Tokyo Stock Exchange, at Bloomberg Tradebook on their futures-trading systems, and eventually at firms with cryptocurrency exposure including OKCoin. By 2017 he had enough understanding of both the technology and the trading mechanics to found his own exchange.

He founded Binance in 2017 with an initial coin offering, originally based in Hong Kong. The timing was exceptional: the 2017 crypto bull market was accelerating, retail interest in cryptocurrency was exploding globally, and there was genuine demand for an exchange that offered more tokens with lower fees than the existing platforms. Binance grew with extraordinary speed.

By the early 2020s, Binance was the largest cryptocurrency exchange in the world by trading volume. Not one of the largest — the largest. It processed more trades, in more currencies, with more users, than any other platform. CZ was one of the wealthiest people in the world, with a net worth estimated in the tens of billions at peak, though most of that wealth was tied to the value of BNB, Binance's own token. He was, by any reasonable measure, one of the most powerful individuals in cryptocurrency.

· PART TWO ·
What Binance Did Wrong — The DOJ's Case

The Bank Secrecy Act requires US financial institutions to know who their customers are, to monitor their transactions, and to file reports of suspicious activity. This is the foundational anti-money-laundering framework for American finance — the infrastructure that makes the financial system harder to use for drug trafficking, terrorism financing, sanctions evasion, and other illicit purposes.

Binance violated it. That is the plea. That is the conviction — or rather, the conviction before the pardon. What the DOJ found:

First: Binance failed to register as a money services business as required under US law, even while serving US customers. The company claimed, including through geolocation restrictions and IP blocking measures, that it did not serve US customers. The DOJ found this claim was not implemented effectively — US customers continued to transact on the platform. [SOURCE: DOJ press release, November 2023]

Second: Binance failed to implement an adequate Know Your Customer programme. For years, users could open accounts and trade without providing meaningful identifying information. The 'know your customer' requirement exists specifically to prevent the exchange from becoming a conduit for illicit finance. Binance's implementation of this requirement was, per the DOJ, inadequate.

Third: As a consequence of these failures, Binance processed transactions connected to entities and activities that US sanctions law prohibited. The DOJ stated that Binance processed transactions for users with connections to Hamas, al-Qaeda, ISIS, and darknet markets. [SOURCE: DOJ plea agreement; AP coverage of sentencing] These are not allegations in the uncertain sense — they are part of a guilty plea. They happened.

The scale of these failures — across the world's largest exchange, over years of operation, while the company actively sought to avoid US regulatory oversight — is what made this the largest corporate settlement the DOJ had reached with a cryptocurrency business at the time. [SOURCE: DOJ November 2023]

· PART THREE ·
What He Did NOT Do — The Discipline of This Case

He was not charged with fraud. He was not charged with misappropriation. He was not charged with stealing customer deposits. He was not accused of taking money that belonged to his customers and using it for anything.

This distinction matters because the public narrative around CZ — particularly in the period after FTX's collapse, when he was the most prominent remaining figure in major crypto exchanges — sometimes carried the implication that he was the same kind of actor as . He was not.

Binance's customers, as of this writing, can access and withdraw their funds. The exchange did not collapse. There was no bankruptcy. There was no $8 billion hole in the balance sheet. The compliance failures were real and serious — the transactions that moved through Binance included proceeds of crimes that harmed real people — but the mechanism of the harm was different from the mechanism in the FTX case.

The FTX harm: customers deposited money expecting it to be held safely, and it was taken. The customers were the direct victims.

The Binance harm: criminals used the exchange to move proceeds of their crimes because the exchange did not implement adequate controls to stop them. The exchange's customers were not the victims. The victims of the underlying crimes were the victims — and the exchange's failure made it easier for those crimes to continue profiting.

Both harms are real. They are not the same harm. The legal system recognised this, and the sentence reflects it: 25 years for , 4 months for CZ. The White House, when announcing the pardon, stated that CZ's prosecution involved 'no allegations of fraud or identifiable victims.' [SOURCE: White House / Axios, October 23, 2025] That framing is contested by the DOJ's own filing, which identifies specific categories of crime enabled. But the structural difference between the two cases is accurately stated.

· PART FOUR ·
The Numbers — $4.3 Billion and $50 Million

The penalty structure is where this case is most unusual in the series. The gap between the company's payment and the individual's fine is the story.

Binance agreed to pay $4.3 billion to resolve the DOJ, Treasury/FinCEN, and CFTC actions. This is one of the largest corporate penalty resolutions in the history of financial enforcement. It included fines and forfeiture across multiple agencies. [SOURCE: DOJ November 2023; Bloomberg analysis]

CZ's personal fine: $50 million. [SOURCE: DOJ plea agreement]

The ratio: the company paid 86 times what CZ paid personally. This structure — massive corporate penalty, relatively modest personal fine, short prison term — reflects the DOJ's assessment of the case as a compliance failure by a business that had grown faster than its regulatory infrastructure, rather than a personal fraud committed by an individual who set out to steal.

The $4.3 billion is a company number. It belongs to Binance. It represents the value the DOJ assessed for years of inadequate controls at the world's largest crypto exchange. It must not be attributed to CZ as a personal liability or a personal theft figure. He personally paid $50 million. These are different numbers measuring different things.

He also stepped down as CEO of Binance as part of the plea. Richard Teng has run the exchange since. CZ retained his equity stake.

· PART FIVE ·
The First — Nobody Had Ever Done This Before

When Judge Richard A. Jones sentenced Changpeng Zhao to four months in federal prison in April 2024, he was sentencing the first person in American history to receive a prison term for a single violation of the Bank Secrecy Act.

This is not a minor historical footnote. The Bank Secrecy Act has been in existence since 1970. It is the foundational anti-money-laundering law of the United States. Violations of it have resulted in corporate fines, regulatory actions, and civil penalties across the entire history of the modern financial system. Nobody had ever gone to prison for a single count of BSA violation before CZ.

The DOJ sought 36 months. CZ's lawyers sought no prison time. Judge Jones imposed 4 months — below the DOJ's request, above zero, and historically unprecedented for the specific charge. [SOURCE: AP / Reuters sentencing coverage, April 2024]

The unprecedented nature of the prison sentence is itself a data point about the scale of the failure. The DOJ had determined that the world's largest crypto exchange had operated in violation of anti-money-laundering law for years, at a scale and with consequences — the Hamas, al-Qaeda, ISIS, darknet market transactions — that justified a penalty that had never been applied to this charge before.

He reported to FCI Lompoc in California in June 2024. He was released in September 2024 after serving approximately four months. The prison was minimum security.

· PART SIX ·
The Pardon — October 23, 2025

On October 23, 2025, President Donald Trump granted Changpeng Zhao a full and unconditional presidential pardon.

CZ had applied for the pardon in 2025, after serving his sentence. He acknowledged the application publicly, noting that he was 'the only one in US history who was ever sentenced to prison for a single BSA charge.' [SOURCE: Fortune, May 2025; CZ via X]

White House Press Secretary Karoline Leavitt announced the pardon and characterised Zhao's prosecution as part of the Biden administration's 'war on cryptocurrency.' She stated there had been 'no allegations of fraud or identifiable victims' in the case. [SOURCE: Axios / AP, October 23, 2025]

The pardon erases his conviction and restores his civil rights. He posted on social media: 'Deeply grateful for today's pardon and to President Trump for upholding America's commitment to fairness, innovation, and justice.' [SOURCE: CZ via X, October 23, 2025]

What the pardon does not erase: the $4.3 billion Binance penalty. The company's settlement stands. The DOJ's findings about what Binance allowed to happen — the sanctioned-entity transactions, the BSA violations, the inadequate AML programme — are part of the historical record. The pardon removes CZ's personal criminal conviction. It does not change what the exchange did.

The pardon also fits a broader pattern. In his second term, Trump pardoned multiple crypto industry figures including (whose life sentence for the Silk Road dark web marketplace was terminated), and three founders and an executive of BitMEX — who had also pleaded guilty to BSA violations. [SOURCE: Fortune, May 2025] CZ's pardon was the highest-profile of these, given Binance's scale.

· PART SEVEN ·
What It Means — The Door

The thesis for Case 015 is the door.

He built Binance — the world's largest cryptocurrency exchange — without building the controls that the law requires to prevent that exchange from being used for money laundering, sanctions evasion, and the financing of organisations designated as terrorist by the United States government. The controls were inadequate. The door, in the relevant sense, was not guarded.

The series argument: every other case in this collection is about people who took money, or built a fake product, or ran a scheme. CZ's case is about what happens when you build something real and powerful and don't build the compliance infrastructure around it.

Binance processed genuine transactions for genuine users. It was a real exchange running real trades in real currencies for real people who wanted to trade cryptocurrency. The compliance failures were failures of an institution that was growing faster than its regulatory framework — not a fraud designed to steal from customers.

That is not an excuse. The transactions that moved through Binance because the controls were inadequate — the Hamas-connected transactions, the ISIS-connected transactions, the darknet market transactions — had real-world consequences. The people whose crimes were made easier by a non-compliant exchange were doing things that harmed people. The exchange's compliance failure was a material contribution to that harm, even though CZ was not the person doing the harm.

He built the door. He did not guard it. The company paid $4.3 billion. He served 4 months. Then a president pardoned him, framing the prosecution as the prior administration's 'war on cryptocurrency' and characterizing the BSA violation — a compliance failure without direct victims in the FTX sense — as regulatory overreach.

The ratio is the story: $4.3 billion from the company, $50 million from the individual, 4 months in a minimum-security prison, then a full pardon. That is the structure of accountability for the world's largest crypto exchange running an inadequate anti-money-laundering programme for years. Whether that ratio reflects proportionate justice is a question this series leaves for the reader — but the numbers are the record and they speak plainly.

FULL TIMELINE
VERIFIED SOURCES

$4.3B = Binance company penalty. $50M = CZ personal fine. Never combine. NOT charged with fraud, theft, or misappropriation. Conviction erased by pardon October 23, 2025 — $4.3B company penalty not affected. He was the first person ever sentenced to prison for a single BSA violation.

[1] US DOJ plea agreement and press release — Binance/CZ, November 21, 2023. Source for: guilty plea, BSA charge, $50M personal fine, $4.3B company resolution, DOJ findings on sanctioned-entity transactions (Hamas, al-Qaeda, ISIS, darknet).
[2] W.D. Wash. sentencing — Judge Richard A. Jones, April 30, 2024. Source for: 4-month sentence. DOJ had sought 36 months.
[3] US Treasury / FinCEN and CFTC — parallel enforcement actions against Binance, November 2023.
[4] BOP (Bureau of Prisons) — reported entry June 2024; reported release September 27, 2024. Verify exact dates against primary BOP record.
[5] Presidential pardon — October 23, 2025. SOURCE: AP ('Trump pardons convicted Binance founder Changpeng Zhao') · Reuters · Axios · White House statement by Karoline Leavitt.
[6] AP — sentencing coverage, April 2024; pardon coverage, October 2025. Source for 'first person ever sentenced to prison for a single BSA charge.'
[7] Fortune, May 2025 — CZ pardon application. Source for: CZ acknowledged applying; 'only one in US history... sentenced to prison for a single BSA charge' quote; Trump's broader crypto pardons pattern (Ulbricht, BitMEX founders).
[8] Reuters / Bloomberg / CNBC — Binance $4.3B resolution analysis; sentencing and release coverage.

VERIFY BEFORE PUBLICATION Exact BOP entry and release dates · $1.8B forfeiture vs fine breakdown within the $4.3B · Exact sanctioned entity names in the DOJ plea agreement · Exact Binance user count cited in DOJ filings

END OF REPORT
#16 OF 45
Ruja Ignatova
SINGLE PERSON
CASE 008 · CRYPTO FRAUDFUGITIVE — NOT CONVICTED
The CryptoQueen · OneCoin · FBI Ten Most Wanted · $5M reward
~$4B
WHAT WAS TAKEN
Investors' money paid for OneCoin packages (alleged; never tried).
HOW
Sold OneCoin worldwide. Prosecutors say the coin had no real blockchain.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2014Founds OneCoin in Sofia; the 'blockchain' investors were sold never existed.SOURCE: US indictment, SDNY 2019
2014–2017Runs the OneCoin sales machine from Sofia; ~€4B raised worldwide according to prosecutors.SOURCE: DOJ; BBC
25 Oct 2017Boards a Ryanair flight Sofia–Athens and disappears.SOURCE: FBI; BBC
2015–2017OneCoin's Dubai base for events and money; a penthouse and company entities in the emirate.SOURCE: BBC The Missing Cryptoqueen; DOJ
June 2016Headlines the OneCoin event at Wembley Arena, promising the coin would 'kill Bitcoin'.SOURCE: BBC
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
RUJA IGNATOVA
THE CRYPTOQUEEN · ONECOIN FOUNDER · CASE 008 · FUGITIVE — FBI TEN MOST WANTED
FRAUD SCALE
~$4B [DOJ/FBI estimate]
METRIC
Investor funds paid into a fake cryptocurrency
VICTIMS
~3.5 million in 90+ countries
STATUS
FUGITIVE — FBI Ten Most Wanted
LAST SEEN
October 25, 2017 · Sofia → Athens
REWARD
up to $5,000,000 · since June 2024 (was $100,000 in 2022)
BORN
1980 · Ruse, Bulgaria
NOTE
INDICTED ONLY — NOT CONVICTED
LEGAL STATUS: Ruja Ignatova is indicted, not convicted. Every statement about her conduct in this case file is drawn from the indictment, FBI press releases, and DOJ sentencing statements about co-defendants. All her conduct is alleged. She has not been tried. She has not been found.
FULL PROFILE

IDENTITY

LEGAL NAME
Ruja Ignatova
ALIAS
The CryptoQueen
BORN
1980 · Ruse, Bulgaria
NATIONALITY
Bulgarian · German citizenship
EDUCATION
University of Konstanz · PhD European private law · Oxford (period of study — verify credential to primary)
CAREER
McKinsey & Company · Walch Management (fraud allegations pre-OneCoin)
PRODUCT
OneCoin — claimed cryptocurrency — no blockchain existed
LAST KNOWN
Ryanair flight Sofia → Athens, October 25, 2017

CASE RECORD [ALLEGED]

CASE
US v. Ignatova, 17 Cr. 630 (ER), SDNY
INDICTED
October 12, 2017 (sealed) · superseding 2018
CHARGES
Conspiracy wire fraud · wire fraud · conspiracy money laundering · conspiracy securities fraud · securities fraud
STATUS
Fugitive · FBI Ten Most Wanted since June 30, 2022
REWARD
up to $5,000,000 · FBI · for information leading to arrest
TIPPED OFF
Believed tipped off about sealed indictment 13 days before flight [SOURCE: FBI/SDNY]
CO-DEFENDANTS — CONVICTED
CO-FOUNDER · PRIMARY CO-CONSPIRATOR20 YEARS
Karl Sebastian Greenwood
Swedish / UK national · arrested Thailand July 2018
Co-founded OneCoin with Ignatova. Sentenced September 12, 2023 to 20 years federal prison and fined $300M. Personally misappropriated $300M+ on five-star resorts, villas, private jet, and a yacht. Judge Edgardo Ramos, SDNY. US Attorney Williams: "OneCoins were entirely worthless, and investors were left with nothing." [SOURCE: CNN / DOJ Sep 2023]
SOURCE: DOJ · CNN · Forklog · KTVZ
IGNATOVA’S BROTHER · FORKLIFT TO FIGUREHEADTIME SERVED — 34 MO
Konstantin Ignatov
Arrested LAX March 2019 · cooperated
Recruited by his sister from a forklift driving job in Germany. After her disappearance, became the de facto face of OneCoin. Arrested March 2019, pleaded guilty, cooperated extensively. Sentenced March 5, 2024 to time served (34 months) + $118,000 forfeiture. Sentencing quote: "I have only myself to blame." [SOURCE: Bloomberg March 2024]
SOURCE: Bloomberg Mar 5 2024 · Forklog
LAWYER · MONEY LAUNDERER10 YEARS
Mark Scott
Former Locke Lord partner · convicted Nov 2019
Former partner at Locke Lord law firm. Laundered approximately $400M in OneCoin proceeds through a network of investment funds. Convicted at jury trial November 2019. Sentenced January 25, 2024 to 10 years federal prison. [SOURCE: Forklog / Bloomberg]
SOURCE: Forklog · DOJ
THE MURDER HYPOTHESIS — REPORTED AS HYPOTHESIS ONLY

WHAT THE JOURNALISM SAYS — AND WHAT IT DOESN’T

In February 2023, Bulgarian investigative outlet BIRD published a police document found in the safe of a dead police officer. The document described an informant account from a yacht trip in Cuba, in which a Bulgarian crime figure’s brother-in-law claimed a hit had been ordered on Ignatova.

“It’s a hypothesis. It’s not conclusive.” — Atanas Tchobanov, BIRD journalist, to Fortune Magazine [SOURCE: Fortune, February 24, 2023]

The FBI has not confirmed her death. She remains on the Ten Most Wanted list. The reward is active. The FBI’s official position: she is a living fugitive. This case file reports the hypothesis as exactly that: a hypothesis sourced to named investigative journalism, not confirmed fact.

WHAT THIS CASE ESTABLISHED

The brand was the blockchain. No blockchain existed. OneCoin was numbers in an internal database. The coin had no external market, no public ledger, no mining. The credential, the events, the rhetoric, the CryptoQueen persona — these were the product.
Multi-level marketing turned victims into recruiters. The structure meant the people being defrauded were also, structurally, defrauding the next level down. Everyone was simultaneously victim and recruiter.
Everyone around her got sentenced. Greenwood 20 years. Scott 10 years. Her brother: time served. She is the only person at the centre of this case who has not been found.
The case has no resolution. The architect is gone. The central question — where is she? — remains open. It is the only case in this series where it does.
Series thesis, Case 008: the brand was the blockchain. Not fraud layered over something real — the appearance of something real with nothing beneath it at all.
BACKGROUND & RISE

EARLY LIFE & EDUCATION

BORN
1980 · Ruse, Bulgaria · on the Danube · Romanian border
EMIGRATION
Age ~10 · family moved to Schramberg, Germany · Baden-Württemberg manufacturing town
LANGUAGE
Fluent German · later English and other European languages · essential to her multi-jurisdiction operation
LAW DOCTORATE
University of Konstanz · European private law · one of Germany's strong research universities
OXFORD PERIOD
Period of study at Oxford University in European law [widely reported — verify exact credential]
MCKINSEY
Worked for McKinsey and Company before OneCoin [widely reported]
PRE-ONECOIN CONTROVERSY
Involved with Walch Management in Bulgaria — ended in fraud allegations · documented pattern [public record]
THE CREDENTIAL
Like Holmes and Madoff: the educational and professional credentials were real, and were weaponised

ONECOIN — THE OPERATION

CO-FOUNDED WITH
Karl Sebastian Greenwood · 2014 · Greenwood: arrested 2018, sentenced 20 years + $300M fine
THE PITCH
OneCoin as 'Bitcoin killer' — better, faster, more practical · targeted people who felt they missed Bitcoin
THE REALITY
No blockchain · OneCoin was numbers in an internal company database [SDNY / DOJ]
MLM STRUCTURE
Multi-level marketing — investors recruited investors · commissions on recruitment · pyramid economics
THE STAGE SHOW
Large events in conference centres and arenas · designer clothes · credential performance · FBI: targeted people who 'may not have fully understood crypto but were moved by her impressive resume'
VICTIM PROFILE
3.5 million investors · Eastern Europe, Southeast Asia, Africa, Americas · many first-time investors
THE BRAND
Called herself the CryptoQueen · events produced like concerts · footage of crowds, speeches, standing ovations
TOTAL SCALE
~$4B raised [DOJ/FBI estimate] · co-defendants sentenced to totals exceeding 30 years combined
THE DISAPPEARANCE & OPEN STATUS

THE VANISHING

US INDICTMENT FILED
October 12, 2017 — sealed · she was allegedly tipped off [FBI / SDNY]
LAST CONFIRMED LOCATION
October 25, 2017 · Ryanair flight · Sofia, Bulgaria → Athens, Greece
AFTER ATHENS
Not publicly located. FBI believes she may use German passport · may be in UAE, Bulgaria, Russia, Greece, Eastern Europe
FBI MOST WANTED
Added June 30, 2022 · fugitive #527 · only woman on Ten Most Wanted list
ORIGINAL REWARD
$100,000 (2022) — raised to $5,000,000 in June 2024 · reflects increased urgency
INTERPOL
Red Notice issued (German authorities) — international wanted alert active
CITIZENSHIPS REVOKED
No known active passports — countries have systematically revoked her citizenship documents
MURDER HYPOTHESIS
February 2023 · BIRD (Bulgarian) reported police document suggesting she was killed on yacht 2018 by 'Taki' crime figure. Journalist: 'a hypothesis — not conclusive.' FBI has NOT confirmed death.

CO-DEFENDANTS — THE ONES WHO WERE CAUGHT

GREENWOOD · CO-FOUNDER
Karl Sebastian Greenwood · arrested Thailand July 2018 · sentenced September 2023 · 20 years + $300M fine [SDNY]
KONSTANTIN · BROTHER
Her brother Konstantin Ignatov · forklift driver she recruited · ran OneCoin after her disappearance · arrested LAX March 2019 · pleaded guilty · sentenced March 2024 · time served (34 months) · cooperated [Bloomberg]
MARK SCOTT · LAWYER
Former Locke Lord partner · laundered ~$400M in OneCoin proceeds · convicted November 2019 · sentenced January 2024 · 10 years [Forklog]
IRINA DILKINSKAYA
Indicted · faces up to 40 years · proceedings ongoing
THE CONTRAST
Everyone who built OneCoin with her is convicted, sentenced, or serving. She boarded a flight and has not come back.
SERIES NOTE
Case 008 is the ONLY case in this series with no resolution. Every other case ends. This one is still open.
CASE TIMELINE
1980 · c.1990
Ruse to Schramberg
Born in Ruse, Bulgaria; the family moves to Schramberg, Germany when she is about ten.
SOURCE: Widely reported
2000s
Konstanz, Oxford, McKinsey
Law doctorate from the University of Konstanz; a period of study at Oxford (exact credential to verify); works for McKinsey.
SOURCE: Widely reported
2014
OneCoin
Co-founds OneCoin with Karl Sebastian Greenwood. Prosecutors say it had no blockchain; sold through multi-level marketing.
SOURCE: FBI · SDNY
October 12 & 25, 2017
Indicted, Then Gone
A sealed US indictment is filed. Thirteen days later she flies Sofia to Athens and is not seen publicly again.
SOURCE: FBI · SDNY
2018 – 2019
The Others Are Caught
Greenwood arrested in Thailand (July 2018). Her brother Konstantin arrested at LAX (March 2019). Lawyer Mark Scott convicted of laundering ~$400M (November 2019).
SOURCE: CNN · Bloomberg
June 30, 2022
Ten Most Wanted
The FBI adds her to its Ten Most Wanted list with a $100,000 reward — raised to up to $5 million in June 2024.
SOURCE: FBI · State Department
February 2023
The Murder Hypothesis
Bulgarian outlet BIRD publishes a police document suggesting she was killed in 2018. Its journalist calls it “a hypothesis”. The FBI has not confirmed her death.
SOURCE: Fortune · BIRD
2023 – 2024
Sentences
Greenwood: 20 years and a $300M fine. Scott: 10 years. Konstantin: time served (34 months).
SOURCE: DOJ · Bloomberg
HOW IT WORKED

HOW ONECOIN WORKED — AS PROSECUTORS DESCRIBE IT

01
The pitch: The “Bitcoin killer”: a chance to be early to the thing that would beat the thing you missed
02
The product: “Coins” were numbers in a company database. Prosecutors say there was no blockchain, no mining, no public ledger
03
The sales machine: Multi-level marketing: investors earned by selling packages to friends and family
04
The show: Arena events, designer clothes, a McKinsey-and-doctorate résumé: the CryptoQueen brand
05
The money: About $4B from some 3.5 million people, per the DOJ; moved through launderers such as Mark Scott
WHERE THE MONEY WENT
Investors worldwide
-->
OneCoin packages (MLM)
-->
Company accounts
-->
Launderers & offshore funds
THE FULL STORY — 10 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE ONE WHO VANISHED (4,200 WORDS)
Sources: FBI Ten Most Wanted (June 30, 2022) · US v. Ignatova, 17 Cr. 630 (ER), SDNY · US v. Greenwood, same case · DOJ/US Attorney SDNY sentencing releases · Bloomberg (Konstantin Ignatov sentencing, March 2024) · Forklog / CNN / KTVZ (Greenwood sentencing, September 2023) · Fortune (murder hypothesis, February 2023) · BIRD / Bulgarian investigative journalism. $4B = DOJ/FBI characterisation of fraud scale. She has not been convicted. She is indicted, not tried. Everything about her conduct is allegation from the indictment and case record, framed as such throughout.
· PROLOGUE ·
October 25, 2017 — The Last Known Sighting

On October 25, 2017, Ruja Ignatova boarded a flight in Sofia, Bulgaria, bound for Athens, Greece.

She was 37 years old. She had, according to the US government's indictment, spent the preceding three years building one of the largest financial fraud schemes in modern history — a fake cryptocurrency called OneCoin, marketed to millions of people in dozens of countries as the investment that would make them rich the way Bitcoin had made others rich, if only they had been early enough.

She had not been early enough. She had been smarter. She had skipped the part where you actually need a blockchain and gone directly to the part where you collect the money.

The sealed US indictment against her had been filed on October 12, 2017 — thirteen days before she left. She had, authorities believe, been tipped off. [SOURCE: FBI / SDNY]

She landed in Athens. She has not been seen publicly since.

When the FBI added her to its Ten Most Wanted Fugitives list in 2022, she was the only woman on it. The reward for information leading to her arrest, first set at $100,000, now stands at up to $5 million. [SOURCE: FBI, June 30, 2022; US State Department, June 26, 2024] Her co-founder is in prison for 20 years. Her brother was released after 34 months. The lawyer who laundered OneCoin money is serving 10 years. Her other partners are in custody, convicted, or cooperating.

Ruja Ignatova is the only person at the centre of this case who has not been found.

Almost every other case in this series ends. is in prison. pleaded guilty. is sentenced. Madoff died in custody. is in California. Holmes is in Texas. Case 008 has no ending yet. She left on a flight and has not come back.

· PART ONE ·
From Ruse to Schramberg to Oxford

Ruja Ignatova was born in 1980 in Ruse, Bulgaria — a city on the Danube, on the border with Romania, the kind of mid-sized Eastern European provincial capital that produced people who were either very good at finding their way out of it or very determined to stay.

She was very good at finding her way out. When she was ten years old, her family emigrated to Germany — to Schramberg, a small manufacturing town in Baden-Württemberg in the south of the country. She learned the language. She integrated. She was, by all accounts, academically exceptional.

She studied law. She obtained a doctorate in European private law from the University of Konstanz in Germany — a research university with a strong reputation in European law. She is sometimes described as having studied at Oxford; what can be confirmed is a period of study there as part of her European legal education. [SOURCE: widely reported — verify exact Oxford credential against primary before publication]

She worked for McKinsey and Company — the management consulting firm — and for a Bulgarian company called Walch Management, which ended in legal controversy and fraud allegations that preceded OneCoin. [SOURCE: widely reported from public record] She had, before OneCoin, already had a confrontation with questions about her business conduct.

She was intelligent, credentialed, multilingual, and comfortable in rooms where serious people talked about serious money. She was also, by the time she created OneCoin, someone who understood how to use the appearance of legitimacy to open doors that would otherwise remain closed.

In 2014, she and Karl Sebastian Greenwood co-founded OneCoin.

· PART TWO ·
The Bitcoin Killer — The Product That Was Not a Product

Bitcoin had already made some people very rich. Not most people. The people who had been early enough, who had believed in the thing before belief was the obvious position, who had held through the years when nobody treated it seriously — those people were now sitting on returns that made any conventional investment look embarrassing.

The people who had missed that window were looking for the next one. They were looking for someone who could tell them, credibly, that the next window was open and that they were not too late.

Ruja Ignatova told them she was that person. OneCoin, she said, was better than Bitcoin. It was faster, more scalable, more practical, more suitable for real-world commercial use. It would not just match Bitcoin — it would replace it. It was the Bitcoin killer. [SOURCE: CNN citing US Attorney Williams / SDNY sentencing statement]

To invest in OneCoin was to be early to the thing that would dwarf the thing you had already missed. The pitch addressed the specific regret of the people who had watched Bitcoin's rise from the outside. You were not too late. You had found it.

OneCoin did not have a blockchain. This is not a technical critique of its design. It is the fact that defines the fraud: a cryptocurrency — by definition — is a digital asset recorded on a distributed public ledger called a blockchain. Every transaction is verified by the network and recorded permanently. This is what makes cryptocurrency cryptocurrency rather than a number in a database.

OneCoin had no blockchain. The 'coins' that investors received were numbers entered into an internal company database. There was no public ledger. There was no mining. There was no verification network. There was no cryptocurrency. There was a number in a spreadsheet with a name next to it, and the name next to the number belonged to someone who had paid real money for it. [SOURCE: SDNY / DOJ / widely documented from case record]

She knew this. According to the US government's case, Greenwood knew it too. 'The pair knew it was a scam from the start,' US prosecutors said at sentencing. [SOURCE: CNN citing DOJ, September 2023]

There was no blockchain. The product that was going to beat Bitcoin did not share the one property that makes Bitcoin what it is. The investment opportunity of a lifetime was a number in a database with no external verification, no public ledger, and no value beyond the belief that the next person would also believe.

· PART THREE ·
The CryptoQueen — Building the Brand

She called herself the CryptoQueen. And she performed the role with the kind of commitment that distinguishes a fraud that runs for three years from one that is detected in three months.

She held events — large, staged events in conference centres and arenas, where she appeared in designer clothes, with a polished presentation, explaining why OneCoin was the future of finance. The events were productions: the graphics, the rhetoric, the crowd energy, the sense of being present at something historic.

She spoke about her credentials: the education, the McKinsey background, the legal expertise. She positioned herself as someone who understood finance and technology at a level that most investors did not, and who was therefore in a position to see what they could not see: that the next wave was already forming, and that the people in this room were about to ride it.

The multi-level marketing structure compounded the effect. OneCoin was sold through a network in which investors were also sellers — they were incentivised to bring in new investors, who in turn were incentivised to bring in more. The structure turned believers into salespeople. The more people you recruited, the more you earned. Your returns depended not just on the coin's value but on the performance of the people you had brought in below you.

This is the classic pyramid structure. The FBI, in its formal description of the scheme, used the phrase 'multi-level marketing strategy that urged OneCoin investors to sell additional packages to friends and family.' [SOURCE: FBI press release, June 30, 2022] The people who were being defrauded were also, structurally, the people doing the defrauding of the next level down. Everyone was simultaneously victim and recruiter.

Special Agent Ronald Shimko of the FBI described Ignatova as targeting people 'who may not have fully understood the ins and outs of cryptocurrencies but were moved by Ignatova's impressive resume and the marketing strategies used by OneCoin.' [SOURCE: FBI press release, June 30, 2022] The credential and the pitch were designed for each other.

· PART FOUR ·
Karl Sebastian Greenwood — The Co-Founder

Karl Sebastian Greenwood was the other architect of OneCoin. A citizen of Sweden and the United Kingdom, 46 years old at sentencing, a salesman whose 'mastery as a salesman' federal prosecutors credited with helping build OneCoin's initial success. [SOURCE: CNN citing DOJ, September 2023]

He worked alongside Ignatova from the beginning. Together they pitched OneCoin as the Bitcoin killer — 'promising a financial revolution' and selling the story of a coin that would replace the one that everyone had already heard about. The investors who had missed Bitcoin were the audience. Greenwood was part of the delivery mechanism for the message.

When Ignatova disappeared in October 2017, Greenwood continued. He ran the operation with what remained of the leadership. Nine months after Ignatova vanished, he was arrested in Thailand in July 2018. [SOURCE: CNN / KTVZ]

He pleaded guilty to wire fraud and money laundering. The government presented evidence that he had personally misappropriated more than $300 million — to five-star resorts, villas, a private jet, and a yacht. [SOURCE: DOJ/Forklog, citing sentencing statement, September 2023]

On September 12, 2023, Judge Edgardo Ramos sentenced Karl Sebastian Greenwood to 20 years in federal prison and fined him $300 million. US Attorney Damian Williams: 'Greenwood and his co-conspirators, including fugitive Ruja Ignatova, conned unsuspecting victims out of billions of dollars with promises of a financial revolution... In fact, OneCoins were entirely worthless, and investors were left with nothing.' [SOURCE: CNN citing DOJ, September 2023]

· PART FIVE ·
Konstantin — The Brother She Hired Away From a Forklift

Ruja Ignatova recruited her brother to work as her personal assistant. Konstantin Ignatov had been working as a forklift driver in Germany. She offered him a job. He took it.

After she disappeared in October 2017, Konstantin became the de facto leader of the OneCoin operation — the face who appeared at events, the person who managed the remaining structure, the one who kept the machine running for the two years between her disappearance and his arrest. [SOURCE: Bloomberg, March 2024]

He was arrested in March 2019 at Los Angeles International Airport. He pleaded guilty to conspiracy to commit wire fraud and money laundering, and began cooperating with prosecutors. His cooperation included testimony in the case against Mark Scott, the lawyer who laundered hundreds of millions of dollars for the OneCoin operation.

His sentencing was delayed for years as prosecutors worked their way through related cases. On March 5, 2024, Judge Edgardo Ramos sentenced Konstantin Ignatov to time served — the 34 months he had already spent in custody. He was also ordered to forfeit $118,000. [SOURCE: Bloomberg, March 5, 2024; The Informer Post]

At sentencing, he took full responsibility: 'I have only myself to blame. The last five years have been a very painful period in my life, but I am grateful for the lessons I have learned.' [SOURCE: ForkLog citing Law360, sentencing hearing]

He was ordered to spend two years under court supervision. He was a forklift driver before his sister called him. He cooperated against her operation and walked out of the courtroom.

· PART SIX ·
Mark Scott and the $400 Million Laundry

Mark Scott was a lawyer. He handled the laundering.

Scott was a former partner at the law firm Locke Lord — a real, established American law firm. He agreed to launder nearly $400 million in OneCoin proceeds, moving the money through a network of investment funds he controlled, disguising its origin through layers of transactions across jurisdictions. [SOURCE: Forklog; Bloomberg citing DOJ]

He was convicted in November 2019 after a jury trial in New York — testimony at his trial came from Konstantin Ignatov, among others. He was sentenced on January 25, 2024 to 10 years in federal prison. [SOURCE: Forklog]

The $400 million he laundered is not the total scale of the fraud. It is the amount that passed through his specific operation. The broader OneCoin fraud is characterised by the DOJ as exceeding $4 billion. Scott handled one piece of the money movement.

· PART SEVEN ·
The Disappearance — October 2017

The sealed indictment against Ruja Ignatova was filed on October 12, 2017, by the US Attorney's Office for the Southern District of New York. [SOURCE: SDNY / FBI] It was sealed — meaning it was not publicly disclosed. Someone told her it existed.

Thirteen days later, on October 25, 2017, she boarded a Ryanair flight from Sofia, Bulgaria to Athens, Greece. This is the last confirmed sighting — the last time her location is known with certainty from any public record.

She landed in Athens. She has not been seen publicly since.

What happened next is, in the strictest sense, unknown. The FBI believes she may travel on a German passport to the United Arab Emirates, Bulgaria, Germany, Russia, Greece, and/or Eastern Europe. [SOURCE: FBI official listing] This is not a confirmed location — it is an assessment of where she might go based on her known connections and travel history.

A superseding indictment was issued in 2018, adding charges. The charges now include: conspiracy to commit wire fraud, wire fraud, conspiracy to commit money laundering, conspiracy to commit securities fraud, and securities fraud. [SOURCE: FBI; SDNY]

In June 2022, the FBI added her to its Ten Most Wanted Fugitives list. She became the only woman on the list. A $100,000 reward was announced; the US State Department raised it to up to $5 million in June 2024. [SOURCE: FBI press release, June 30, 2022; US State Department, June 26, 2024]

She has been on that list for over four years as of this writing. She has not been found.

THE DEPARTURE — CONFIRMED FACTS ONLY: October 12, 2017: Sealed US indictment filed against Ignatova. [SDNY]

October 25, 2017: Ignatova boards Ryanair flight from Sofia to Athens. [FBI]

After Athens: location unknown. FBI believes she may travel on German passport to UAE, Bulgaria, Germany, Russia, Greece, Eastern Europe.

What is NOT confirmed: why she left, who tipped her off, where she went after Athens, whether she is still alive.

She has not been arrested, extradited, or found. The FBI has not confirmed her death.

· PART EIGHT ·
The Murder Theory — A Hypothesis, Not a Fact

In February 2023, the Bulgarian investigative outlet BIRD — the Bureau for Investigative Reporting and Data — published a police document.

The document had been found in a safe in the apartment of a Bulgarian police officer who had been shot dead in March 2022. Inside the safe was a one-page report describing an exchange during a yacht trip in Cuba. An informant had reported that the brother-in-law of Christophoros Amanatidis — known as 'Taki,' described as a Bulgarian crime boss — had been drinking and had told the informant that Taki had ordered a successful hit on Ruja Ignatova. According to this account, she was killed on another yacht.

Atanas Tchobanov — a journalist at BIRD who has worked with the International Consortium of Investigative Journalists — told Fortune Magazine directly: it is 'a hypothesis.' 'It's not conclusive.' [SOURCE: Fortune, February 24, 2023, citing BIRD / Tchobanov]

The FBI has not confirmed that Ruja Ignatova is dead. She remains on the Ten Most Wanted list. The reward remains active. The FBI's official position is that she is a fugitive at large.

This piece reports the hypothesis as a hypothesis. It is documented. It is sourced to named journalism. It is also — in the word of the journalist who reported it — not conclusive.

EDITORIAL STANDARD ON THIS SECTION: The murder hypothesis is sourced to BIRD (Bulgarian investigative outlet) and confirmed by a named journalist (Tchobanov) to Fortune as 'not conclusive' and 'a hypothesis.'

The FBI has NOT confirmed Ignatova's death. She remains an active fugitive on the Ten Most Wanted list.

This piece states: the hypothesis exists, the source is credible investigative journalism, the FBI's position is that she remains at large.

We do not state she is dead. We do not state she is alive. The record does not allow either conclusion.

· PART NINE ·
The Scale — 3.5 Million People, $4 Billion Alleged

The numbers in this case require the same labelling discipline applied to every case in this series.

$4 billion: this is the FBI's and DOJ's characterisation of the total amount defrauded across the OneCoin scheme. [SOURCE: FBI press release; DOJ/Williams statement] It represents money that investors around the world paid into the OneCoin system in exchange for coins that were, in the government's characterisation, worthless.

$300 million: the amount Greenwood personally misappropriated, per the DOJ, spent on five-star resorts, villas, private jet, and a yacht. [SOURCE: DOJ, September 2023]

$400 million: the amount Mark Scott laundered — one piece of the money movement, not the total fraud.

3.5 million: the number of people who invested in OneCoin, per the DOJ at Greenwood's sentencing. [SOURCE: DOJ/Williams; CNN] These were people in dozens of countries — in Europe, in Asia, in Africa, in the Americas. Many of them were not sophisticated investors. Many of them were people who had heard about Bitcoin and believed they had found the next version of it, backed by a credentialed professional who spoke to them at events and told them the future of finance was here.

They were left with nothing. The coins they had were numbers in a database with no external value and no market. When the operation collapsed, there was nothing to redeem them against.

FIGURE

WHAT IT MEASURES / SOURCE

$4B+

Total alleged investor losses — DOJ/FBI characterisation of the OneCoin fraud [SDNY; FBI June 2022]

$300M

Greenwood's personal misappropriation (resorts, jets, yacht) — DOJ sentencing statement [SDNY, Sept 2023]

$400M

Amount laundered by lawyer Mark Scott — his case specifically [SDNY; Forklog]

$118K

Konstantin Ignatov forfeiture ordered — time-served sentence [Bloomberg, March 2024]

3.5 million

Number of OneCoin investors worldwide — DOJ at Greenwood sentencing [CNN / SDNY]

$100,000

Original FBI reward for information leading to Ignatova's arrest [FBI, June 30, 2022] — raised to up to $5 million by the US State Department, June 26, 2024

· PART TEN ·
What It Means — The Case That Has No Ending

Almost every case in this series has a resolution. Someone was convicted. Someone was sentenced. The machine stopped.

Case 008 has no resolution. The architect of the fraud is gone. The co-founder is serving 20 years. The brother is out. The lawyer who laundered the money is in. The head of compliance was prosecuted too. And the person who built the thing, who called herself the CryptoQueen, who persuaded 3.5 million people across dozens of countries to invest in a cryptocurrency that was not a cryptocurrency — she left on a flight in October 2017 and has not come back.

The series thesis for this case: the brand was the blockchain. Every other case in this series had, at some level, a real product — had a real Instagram, had a real heist, had a real (if flawed) algorithm, Madoff had a real investment firm, had a real exchange, Holmes had a real laboratory. In each case the fraud ran inside something that existed.

Ruja Ignatova's fraud had nothing inside it. No blockchain. No mining. No verification. No market. An internal database and a name: OneCoin. The name, the events, the credential, the rhetoric — these were the product. The coin itself was a number in a spreadsheet. The only thing that gave it value was the belief that the next person would also believe.

That is the purest form of the scam this series documents: not fraud layered over something real, but the appearance of something real with nothing beneath it at all. The Bitcoin killer had no Bitcoin. The CryptoQueen had no crypto.

She is still, as of this writing, wherever she is. The FBI has a reward out. Europol has a listing. The question of whether she is in a villa somewhere with money she moved before the collapse, or whether she is dead on a yacht in a story that Bulgarian investigative journalists cannot confirm, is unanswered.

The case has a $4 billion price tag, per the DOJ, 3.5 million victims, and no defendant in the dock for the original crime. It is one of only two cases in this series — with , — where the central question, where are they, is still open.

The brand was the blockchain. The CryptoQueen had no crypto. And she is one of only two people in this series who left before anyone could stop them.

FULL TIMELINE

DATE

EVENT

1980

Born in Ruse, Bulgaria

c.1990

Family emigrates to Schramberg, Germany. She grows up in Germany, learns the language, integrates.

2000s

Obtains law doctorate from University of Konstanz. Studies period at Oxford. Works for McKinsey. Bulgarian company ends in fraud allegations (pre-OneCoin).

2014

Co-founds OneCoin with Karl Sebastian Greenwood. Begins selling to investors. No blockchain. Multi-level marketing structure.

2014–2017

Builds the CryptoQueen brand. Holds events globally. Attracts 3.5 million investors. $4B+ collected. She and Greenwood knew it was fraudulent, per DOJ.

Oct 12, 2017

Sealed US indictment filed against Ignatova. SDNY. She is allegedly tipped off. [FBI / SDNY]

Oct 25, 2017

LAST KNOWN LOCATION: boards Ryanair flight, Sofia to Athens. Not seen publicly since. [FBI]

2018

Superseding indictment adds charges. Konstantin Ignatov takes over OneCoin operations. Greenwood arrested in Thailand, July 2018.

Mar 2019

Konstantin Ignatov arrested at LAX. Pleads guilty. Cooperates.

Nov 2019

Mark Scott convicted by jury — laundering ~$400M in OneCoin proceeds.

Jun 30, 2022

FBI adds Ignatova to Ten Most Wanted Fugitives list. Only woman on the list. $100,000 reward (raised to up to $5 million by the US State Department, June 2024). [FBI press release; State Department]

Feb 2023

BIRD (Bulgarian investigative outlet) publishes police document suggesting Ignatova was killed on a yacht, 2018 — ordered by crime boss 'Taki.' Journalist: 'a hypothesis... not conclusive.' FBI has not confirmed her death. [Fortune, Feb 24, 2023]

Sep 12, 2023

Greenwood sentenced: 20 years federal prison + $300M fine. Judge Ramos. SDNY. [CNN / DOJ]

Jan 25, 2024

Mark Scott sentenced: 10 years federal prison. [Forklog / DOJ]

Mar 5, 2024

Konstantin Ignatov sentenced: time served (34 months). Released. Forfeits $118,000. [Bloomberg]

Now

Ruja Ignatova: whereabouts unknown. FBI Ten Most Wanted. Reward up to $5 million. Europol listing. No arrest. No confirmation of death. The case remains open.

VERIFIED SOURCES
Ignatova is indicted, not convicted. All her conduct is alleged from the indictment and case record. The murder hypothesis is from named investigative journalism — reported as a hypothesis, not a fact. FBI position: she is a living fugitive. $4B is DOJ/FBI characterisation of the fraud. All figures labelled by what they measure.
[1] US v. Ignatova, 17 Cr. 630 (ER), SDNY — indictment filed October 12, 2017 (sealed); superseding indictment 2018. Five charges including conspiracy to commit wire fraud, wire fraud, conspiracy to commit money laundering, conspiracy to commit securities fraud, securities fraud.
[2] US v. Greenwood, same case — arrested Thailand July 2018; sentenced September 12, 2023, 20 years federal prison, $300M fine. Judge Edgardo Ramos, SDNY. SOURCE: CNN Faith Karimi (KTVZ); Forklog.
[3] US v. Ignatov (Konstantin), same case — arrested LAX March 2019; pleaded guilty; sentenced March 5, 2024, time served (34 months), $118,000 forfeiture. SOURCE: Bloomberg March 5, 2024; The Informer Post.
[4] US v. Scott (Mark) — convicted November 2019; sentenced January 25, 2024, 10 years federal prison. SOURCE: Forklog; Bloomberg.
[5] FBI press release, June 30, 2022 — Ignatova added to Ten Most Wanted. $100,000 reward. FBI Special Agent Shimko quote. Last known location: Sofia to Athens, October 25, 2017.
[6] DOJ/US Attorney Damian Williams — statement at Greenwood sentencing, September 2023. Source for: '$4 billion,' '3.5 million victims,' 'conned unsuspecting victims out of billions,' 'entirely worthless.'
[7] Fortune — 'The CryptoQueen who made FBI's most wanted after $4 billion heist was rumored killed — but evidence leaves more questions than answers,' February 24, 2023. Ben Weiss. Source for the murder hypothesis. Tchobanov quote: 'a hypothesis... not conclusive.'
[8] BIRD (Bureau for Investigative Reporting and Data, Bulgaria) — original reporting on police document / murder hypothesis, February 2023.
[9] Forklog — 'Brother of OneCoin Founder Released from Prison' (March 2024); 'OneCoin co-founder sentenced to 20 years' (September 2023).
[10] TO VERIFY BEFORE PUBLICATION: exact Oxford credential — what course/qualification she completed there vs University of Konstanz doctorate; Walch Management fraud allegations (pre-OneCoin history).
END OF REPORT
#17 OF 45
Tom Petters
SINGLE PERSON
CASE 018 · PONZICONVICTED
Petters Group Worldwide · 50 years · D. Minn. 2010
$3.65B
WHAT WAS TAKEN
Lenders' and investors' money, raised for electronics deals that didn't exist.
HOW
Faked purchase orders from Sam's Club and Costco, and paid old lenders with new lenders' money.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1994–2008Petters Group Worldwide sells investors fake purchase orders for electronics that never existed; ~$3.65B Ponzi.SOURCE: DOJ D. Minn.
24 Sept 2008About 100 federal agents search the Minnetonka headquarters and his Wayzata home.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
TOM PETTERS
THE INVISIBLE · CASE 018 · PONZI · CONVICTED DEC 2009 · SENTENCED 50 YEARS APR 2010 · STILL SERVING
SCHEME SIZE
$3.65B
METRIC
DOJ trial figure — size of the scheme, not net investor losses
SENTENCE
50 years · D. Minn.
VERDICT
Guilty on all 20 counts · Dec 2, 2009
RAN FOR
~14 years · about 1994–2008
PROSECUTORS SOUGHT
335 years · defense asked for 4
JUDGE
Richard H. Kyle · St. Paul
PROJECTED RELEASE
April 25, 2052 · age ~95 [AP; BOP to confirm]
$3.65B = the DOJ’s trial figure for the scheme. Some sources say $3.5B or $3.7B. Net investor losses after recoveries are a different, smaller number, still being verified.
FULL PROFILE

IDENTITY

NAME
Thomas Joseph Petters · Tom Petters
BORN
1957 (reported) · St. Cloud, Minnesota
AGE AT SENTENCING
52
HOLDING COMPANY
Petters Group Worldwide · Minnetonka, Minnesota
THE FRAUD VEHICLE
Petters Company, Inc. (PCI)
STANDING
Prominent in the Twin Cities · charity boards · thousands of employees in real businesses

CASE RECORD

CASE
US v. Petters, Crim. No. 08-364 (RHK/AJB) · D. Minn.
RAIDED
September 24, 2008 · ~100 FBI, IRS and Postal Inspection agents
CONVICTED
December 2, 2009 · jury · all 20 counts
COUNTS
10 wire fraud · 3 mail fraud · conspiracy to commit mail and wire fraud · conspiracy to commit money laundering · 5 money laundering
SENTENCED
April 8, 2010 · 50 years · longest fraud sentence in Minnesota history [FBI]
2013
Admitted guilt seeking a shorter sentence; denied
COMMUTATION
None confirmed in any primary source as of September 2026
THE REAL BUSINESSES — WHAT INVESTORS COULD SEE
CONSUMER CREDIT CATALOGUEREAL COMPANY
Fingerhut
Acquired early 2000s
Hundreds of thousands of customers buying merchandise on credit. Real employees, real inventory. Bought, at least in part, with investor money.
SOURCE: Star Tribune · Reuters
PHOTOGRAPHY BRANDREAL COMPANY
Polaroid
Acquired 2005
The iconic camera brand. When Petters owned it, the cameras existed, were sold and worked.
SOURCE: Star Tribune · Reuters
AIRLINEREAL COMPANY
Sun Country Airlines
Minnesota discount carrier
Real planes, real flights, real passengers. The visible proof that the man behind the deals was serious and solvent.
SOURCE: Star Tribune · Reuters
KNOWN NETWORK & CO-CONSPIRATORS
INSIDER · COOPERATORCOOPERATED
Deanna Coleman
Long-time Petters associate
Went to the FBI in 2008, recorded conversations with Petters and gathered evidence. The collapse came from inside.
SOURCE: Star Tribune · MPR News
CO-CONSPIRATORPROSECUTED
James Fry
Investor-side associate
Prosecuted separately in the District of Minnesota. His exact role, firm and sentence are being verified.
SOURCE: DOJ · US Attorney D. Minn.
CO-CONSPIRATORPLEADED GUILTY
Frank Vennes
Brought investors in
Pleaded guilty to lying to investors in the Petters Ponzi scheme [US Attorney, D. Minn.].
SOURCE: US Attorney D. Minn.
CO-CONSPIRATORPROSECUTED
Larry Reynolds
Part of the paperwork chain
Prosecuted separately in the District of Minnesota. His exact role and sentence are being verified.
SOURCE: DOJ · US Attorney D. Minn.
CASE TIMELINE
About 1994
The Scheme Begins
Petters Company, Inc. starts raising money to finance electronics deals that were largely fiction. It runs for about fourteen years.
SOURCE: DOJ · Star Tribune
2000s
The Empire
Petters Group Worldwide buys Fingerhut and, in 2005, Polaroid; Sun Country Airlines joins the portfolio. Investor money helps pay for them.
SOURCE: Star Tribune · Reuters
September 24, 2008
The Raid
After Deanna Coleman goes to the FBI and records him, about 100 agents search his Minnetonka headquarters and Wayzata home. He is arrested; his businesses go into bankruptcy.
SOURCE: Star Tribune · MPR News
December 2, 2009
Guilty on All 20 Counts
A jury rejects his defense that trusted associates ran the fraud behind his back.
SOURCE: FBI · DOJ
April 8, 2010
50 Years
Judge Richard Kyle: “Mr. Petters was captain of the ship.” Prosecutors had sought 335 years.
SOURCE: AP · CBS News
2013
The Admission
“This is my only chance to clear my conscience and soul.” Kyle denies a shorter sentence: Petters “tried to pull off one final con.”
SOURCE: ABI Journal citing WSJ · MPR News
HOW THE FRAUD WORKED

THE SUPPLY CHAIN THAT WASN’T — FIVE STEPS

01
The pitch: Lend to PCI to buy TVs, DVD players and other electronics in bulk for resale to big-box retailers such as Sam’s Club and Costco.
02
The promise: Principal back plus returns, sometimes around 35% [DOJ; MPR News].
03
The paperwork: Purchase orders were largely fabricated; associates posing as suppliers and brokers produced the documents.
04
The loop: New investors’ money paid earlier investors — the Ponzi mechanic.
05
The cover: The rest bought real companies. Anyone who checked found Polaroid and Sun Country, which were real.
WHERE THE MONEY WENT
Investors & hedge funds
-->
Petters Company, Inc.
-->
Fake electronics deals
-->
Earlier investors repaid · Fingerhut, Polaroid, Sun Country bought
MADOFF (CASE 004) VS PETTERS (CASE 018)
CLAIMED ACTIVITY
Madoff: an options trading strategy · Petters: buying and reselling consumer electronics
WAS ANY OF IT REAL?
Madoff: no trades at all · Petters: partly — real companies and brands, a fake supply chain
DURATION
Madoff: decades · Petters: ~14 years
SCALE
Madoff: ~$17B cash lost ($64.8B on statements) · Petters: $3.65B scheme size
SENTENCE
Madoff: 150 years · Petters: 50 years
RECOVERY
Madoff: trustee recoveries ongoing · Petters: limited — the money was spent on real businesses
IN THEIR WORDS
JUDGE RICHARD KYLE
“Mr. Petters was captain of the ship.” [AP, April 8, 2010]
US ATTORNEY B. TODD JONES
“Tom Petters was a fraud. Tom Petters built his life on deceit and lies, and today the check came due.” [AP]
PETTERS, 2013
“This is my only chance to clear my conscience and soul. I made a horrible mess of things.” [ABI Journal citing WSJ]
JUDGE KYLE, 2013
Petters “tried to pull off one final con.” [MPR News]

WHAT THIS CASE ESTABLISHED

Respectability as camouflage: the stores were open and the planes were flying. The fraud was the one part investors could not see — the supply chain.
Victims were not only funds: hedge funds, pastors, missionaries and retirees lost money, some reached through church networks built on trust.
It ended the way Madoff’s did (): an insider talked. Deanna Coleman’s recordings did what fourteen years of paperwork checks had not.
Recovery is hard when the money was spent on real businesses: it bought Polaroid, kept Sun Country flying and paid Fingerhut’s staff.
Series thesis, Case 018: the invisible. Often ranked the third-largest Ponzi scheme in US history — and a name most people have never heard.
THE FULL STORY — 5 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE INVISIBLE (2,000 WORDS)
Sources: US v. Petters, D. Minn. St. Paul · Judge Richard H. Kyle · DOJ/US Attorney, District of Minnesota · AP at sentencing April 8, 2010 · MPR News · Minneapolis Star Tribune · ABI Journal citing WSJ. $3.65B = DOJ trial figure. Some sources cite $3.5B or $3.7B. Label with source when quoting. Commutation reported in brief — NOT CONFIRMED at time of writing. See Part Five.
· PROLOGUE ·
The Stores Were Open and the Planes Were Flying

Tom Petters owned Polaroid. He owned a stake in Sun Country Airlines. He had previously owned Fingerhut, the consumer credit catalogue company. He sat on charity boards in Minnesota. He employed thousands of people in real businesses that made real products.

Behind all of it — running simultaneously for approximately fourteen years, from 1994 to 2008 — was a $3.65 billion Ponzi scheme. Investors were told their money was being used to buy consumer electronics from suppliers and resell them to big-box retailers at guaranteed profit margins. The purchase orders they were shown were largely fabricated. The supplier relationships were largely fictitious. The money from new investors was paying old investors and funding the acquisition of real companies — Polaroid, Sun Country, Fingerhut. [SOURCE: DOJ; Minneapolis Star Tribune]

The businesses were real. The employees were real. The stores were open. The planes were flying. The paychecks cleared. Tom Petters was convicted on 20 counts of wire fraud, mail fraud, money laundering, and conspiracy in December 2009 and sentenced to 50 years in federal prison on April 8, 2010.

He was 52 years old at sentencing. Judge Richard Kyle: 'Mr. Petters was captain of the ship.' [SOURCE: AP sentencing coverage] His projected release date is April 25, 2052. He would be 95.

Madoff fabricated returns. Petters fabricated a supply chain. Both showed investors a business that was never there. The difference: Petters used the fraud proceeds to buy real companies with actual employees. The legitimacy was operational. The fraud was the thing you could not see.

· PART ONE ·
Minnesota — The Real Businesses

Thomas Joseph Petters was born in 1957 and built his career in Minnesota's consumer products and retail sector. By standard measures he was a success: connected, charitable, prominent in the Twin Cities, associated with significant consumer brands.

Petters Group Worldwide was his holding company, based in Minnetonka, Minnesota. Through it he acquired real businesses with real operations:

Fingerhut — a consumer credit catalogue company acquired in the early 2000s. Genuine business, hundreds of thousands of customers, merchandise sold on credit terms. Real employees. Real products. Real inventory.

Polaroid — the iconic photography brand, acquired in 2005. Global recognition. A history of genuine technological innovation. When Petters owned Polaroid, Polaroid cameras existed and were sold and worked.

Sun Country Airlines — a Minnesota-based discount carrier. Real planes. Real flights. Real passengers travelling between real destinations. When Petters was associated with Sun Country, Sun Country flew. [SOURCE: Reuters; Star Tribune]

All of this is relevant to how the fraud ran for fourteen years. The visible, functioning businesses were the evidence that the man behind them was serious and solvent. Investors who wanted to verify found Polaroid and Sun Country — things they could confirm. The fraud was the piece of the operation they could not see: the supply chain.

· PART TWO ·
Petters Company Inc. — The Fraud

Petters Company Inc., known as PCI, was the investment vehicle. It was the fraud.

PCI told investors it was purchasing consumer electronics — televisions, DVD players, the kind of household goods that big-box retailers stocked — from a supplier and reselling them at guaranteed profit margins. Investors funded the purchases. When the goods sold, they received principal plus returns, sometimes as high as approximately 35%. [SOURCE: DOJ; MPR News]

The purchase orders backing these transactions were, per the trial record, largely fabricated. Associates who posed as the suppliers and brokers generated bogus documentation for transactions that either did not occur or did not occur as described; several were separately prosecuted in the District of Minnesota. [SOURCE: DOJ; Star Tribune]

New investor money paid earlier investors — the fundamental Ponzi mechanic — and funded Petters' other businesses and personal expenses. The acquisitions of Fingerhut, Polaroid, and Sun Country were funded, at least in part, with investor capital. The money did not vanish into private accounts; it purchased operating companies. That is what made the fraud durable. The companies it bought kept the operation looking legitimate.

MADOFF () vs PETTERS (Case 018)

Claimed activity

Madoff: options trading strategy · Petters: buying and reselling consumer electronics

Was any of it real?

Madoff: No — no trades, fabricated statements · Petters: Partly — real companies, real brands, bogus supply chain

Duration

Madoff: ~17 years active Ponzi · Petters: ~14 years (1994–2008)

Scale

Madoff: $64.8B fabricated / ~$17B principal · Petters: ~$3.65B scheme size [DOJ] — not net investor loss

Sentence

Madoff: 150 years · Petters: 50 years

Recovery

Madoff: Picard trustee ongoing · Petters: limited — spent on acquisitions and operations

· PART THREE ·
The Collapse — Deanna Coleman and the FBI

The collapse came from inside. A long-time Petters associate named Deanna Coleman agreed to cooperate with the FBI in 2008. She recorded conversations. She gathered evidence.

The FBI raided Petters Group Worldwide headquarters in Minnetonka in September 2008. Petters was arrested. His businesses entered bankruptcy proceedings. [SOURCE: MPR News; Star Tribune]

Co-conspirators who built the scheme with him — including James Fry, Frank Vennes, and Larry Reynolds — each faced separate proceedings in the District of Minnesota. Each played a role in the documentation infrastructure: the bogus purchase orders, the fake invoices, the appearance of a functioning supply chain that sustained the fraud through fourteen years and investor rounds.

Petters was convicted by a jury on 20 counts — wire fraud, mail fraud, money laundering, conspiracy — on December 2, 2009. He initially maintained his innocence, claiming he had been betrayed by trusted associates who had turned a legitimate business into a Ponzi scheme without his knowledge. This defense was rejected by the jury and by Judge Kyle at sentencing.

Years later, in a 2013 hearing seeking a shorter sentence, Petters finally admitted guilt: 'This is my only chance to clear my conscience and soul. I made a horrible mess of things.' [SOURCE: ABI Journal citing WSJ; MPR News] Judge Kyle dismissed his request, writing that Petters had 'tried to pull off one final con.' [SOURCE: MPR News / KROC News]

· PART FOUR ·
50 Years — The Captain of the Ship

On April 8, 2010, Judge Richard H. Kyle sentenced Thomas Joseph Petters to 50 years in federal prison before a packed courtroom in St. Paul, Minnesota.

Prosecutors had sought the statutory maximum of 335 years. The defense argued four years would be sufficient. Kyle chose 50. He recommended the Bureau of Prisons house Petters in Minnesota, to allow him to remain close to his family including two young sons. [SOURCE: AP sentencing; MPR News]

US Attorney B. Todd Jones at sentencing: 'Tom Petters was a fraud. Tom Petters built his life on deceit and lies, and today the check came due.' [SOURCE: AP sentencing coverage, April 8, 2010]

Judge Kyle: 'Mr. Petters was captain of the ship.' [SOURCE: AP] The phrase is precise. Petters did not claim he was absent while associates committed the fraud. He was there. The judge found he knew. The jury had found the same.

His victims included hedge funds — institutional money from sophisticated investors — and pastors, missionaries, and retirees. The range reflects both the scale and the structure of the scheme: PCI targeted a wide network through multiple channels, including religious community networks where trust was built on shared belief rather than financial diligence. [SOURCE: AP sentencing]

His projected release date: April 25, 2052. He would be 95 years old. Even with maximum good-conduct credit, he would spend approximately 41 more years in prison from the date of sentencing. US Attorney Jones called the 50-year term 'fair and just' and described it as 'tantamount to a life sentence.' [SOURCE: AP]

COMMUTATION — STATUS: The brief for this case noted a potential commutation in 2025 and flagged it for verification.

No confirmed commutation of Tom Petters' sentence has been found in primary sources as of September 2026.

This piece does not state a commutation occurred.

If a commutation is confirmed by primary source (DOJ / BOP / White House), update this section with specific date, authority, and scope of the commutation before publication.

Current documented status: serving 50-year sentence, federal prison.

· PART FIVE ·
What It Means — Respectability as Camouflage

The series thesis for Case 018 is built into the prologue: the stores were open and the planes were flying. The specific thing Petters did differently from Madoff was use the fraud proceeds to buy operating companies.

Madoff's fraud ran inside the credibility of Wall Street's institutional establishment. Stanford's ran inside Antigua's political relationships and cricket culture. Holmes's ran inside the California tech mythology of the Stanford dropout visionary. Petters' ran inside working businesses with real employees, recognisable brand names, and operating revenue.

The investors who wanted to verify were shown things they could verify. Polaroid was real. Sun Country flew. The chairman was charitable and prominent in a community that knew him. The documentation looked like documentation. The fraud was specifically what was not there: the supply chain, the purchase orders, the consumer electronics changing hands between PCI and the retailers.

This is why it lasted fourteen years. And this is why recovery has been limited for victims: unlike Madoff, where money was invested but never deployed and could theoretically be clawed back as uninvested principal, Petters' money was spent. It bought Polaroid. It kept Sun Country flying. It paid Fingerhut's employees. The money was in the businesses.

His is often ranked as the third-largest Ponzi scheme in US history, after Madoff's and Stanford's. You have likely not heard his name before this series. That is the precise thesis: the invisible. He ran a fraud behind real companies in a state that does not think of itself as a fraud capital, and when it collapsed the businesses collapsed with it, and the name did not stick the way Madoff's did.

The stores were open. The planes were flying. And then they were not.

Tom Petters built a warehouse. invented a trade. Both showed investors a supply chain that was never there — and Petters used the proceeds to build something real enough that nobody needed to look at the supply chain for fourteen years.

VERIFIED SOURCES
$3.65B = DOJ trial figure. Some sources cite $3.5B or $3.7B. Brief uses $3.65B. Label when quoting. Commutation in brief: NOT CONFIRMED — omitted. Do not include unless verified to primary source.
[1] US District Court, D. Minn. St. Paul — trial record. Conviction December 2, 2009. 20 counts. Judge Richard H. Kyle.
[2] AP sentencing coverage, April 8, 2010 — 'Judge sentences Petters to 50 years.' Judge Kyle quotes ('captain of the ship'). US Attorney Jones quotes. Victim categories. Release date calculation (age 95). Family recommendation to BOP.
[3] DOJ/US Attorney, District of Minnesota — charging documents, press releases, co-conspirator cases (Fry, Vennes, Reynolds).
[4] MPR News (Minnesota Public Radio) — Petters prison interview April 2012; sentencing coverage; 2013 appeal denial coverage.
[5] Minneapolis Star Tribune — trial and receivership coverage. Deanna Coleman cooperation; FBI raid September 2008.
[6] ABI Journal citing WSJ — 2013 guilty admission ('This is my only chance to clear my conscience and soul').
[7] KROC News / MPR News — Judge Kyle appeal denial: 'tried to pull off one final con.'
COMMUTATION NOT CONFIRMED. Brief flagged this for verification. No primary source found as of September 2026. Omit until confirmed by DOJ/BOP/White House.
END OF REPORT
#18 OF 45
James Zhong
SINGLE PERSON
CASE 016 · DARK WEB / COMPUTER FRAUDRELEASED 2023
Individual X · Silk Road thief · 1 year and 1 day
$3.36B
WHAT WAS TAKEN
51,680 bitcoin from the Silk Road market. $3.36B is what it was worth when seized.
HOW
Tricked Silk Road's withdrawal system into paying him the bitcoin in 2012.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
Sept 2012From home, exploits Silk Road's withdrawal flaw and takes ~51,680 BTC.SOURCE: DOJ SDNY
2012–2021Sits on the coins for nine years; agents find them in a floor safe and a popcorn tin in Nov 2021.SOURCE: DOJ SDNY
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
JAMES ZHONG
INDIVIDUAL X · SILK ROAD THIEF · CASE 016 · DARK WEB / COMPUTER FRAUD · RELEASED 2023
BITCOIN STOLEN
51,680 BTC (Sept 2012)
METRIC
BTC count is the fact — dollar value depends on date
VALUE AT SEIZURE
~$3.4B (Nov 2021 prices) [DOJ]
HELD FOR
9 years — Sep 2012 to Nov 2021
SENTENCE
1 year and 1 day
STOLEN FROM
Silk Road — a criminal marketplace
BORN
May 24, 1990 · New Jersey
STATUS
RELEASED 2023 — served ~1 year
THREE BITCOIN FIGURES — THREE THINGS: 51,680 BTC = total stolen (Sept 2012) · 50,676 BTC = seized from his home (Nov 2021) · 51,680.32 BTC = total in final forfeiture orders (seizure + voluntary surrender). Every valuation carries a date. The dollar amounts are not fixed — the coin count is the fact.
FULL PROFILE

IDENTITY

NAME
James Zhong · also known as “Individual X” in blockchain forensics
BORN
May 24, 1990 · New Jersey
EDUCATION
University of Georgia
RESIDENCE
Gainesville, Georgia
THE THEFT
September 2012 · exploited Silk Road withdrawal system flaw
METHOD
Created ~9 fraud accounts · rapid-succession withdrawals exceeding deposit · e.g. 500 BTC deposited → 5 × 500 BTC withdrawn within 1 second = 2,000 BTC gain
SEIZED WHERE
Gaming computer · underground floor safe · single-board computer under blankets in a popcorn tin in a bathroom closet · Gainesville, Georgia

CASE RECORD

CASE
US v. Zhong, 22 Cr. 606 (PGG) · SDNY
SEIZURE
November 9, 2021 · ~50,676 BTC · ~$3.4B (Nov 2021 value) [DOJ]
ALSO SEIZED
$661,900 cash · 25 Casascius coins (~174 BTC) · gold + silver bars · also 80% interest in RE&D Investments LLC (Memphis real estate)
VOLUNTARY SURRENDER
~1,004 BTC surrendered in stages (Mar – May 2022)
TOTAL FORFEITED
51,680.32 BTC in final forfeiture orders [US Attorney SDNY, Apr 14 2023]
PLEA
Guilty · 1 count wire fraud · November 4, 2022
JUDGE
Paul G. Gardephe · SDNY
SENTENCED
1 year and 1 day · April 14, 2023
THE PATIENCE — 9 YEARS OF NOTHING

WHAT HE DID AND DIDN’T DO

Sep 2012
Stole 51,680 BTC from Silk Road — worth a fraction of later valuations at the time of theft
Oct 2013
FBI shut down Silk Road. Ulbricht arrested. Zhong’s coins were not among what they found.
2013–2021
He did not spend it. Did not convert it. Did not post it. Did not buy cars or watches or mansions. Lived in Gainesville, Georgia.
Dec 2017
Bitcoin reached $19,000 peak. Zhong’s 50,000+ coins were worth ~$1B. He did not sell.
Nov 2021
Government executes search warrant. Bitcoin near all-time high. 50,676 BTC found — worth ~$3.4B. On a computer. In a popcorn tin. In a bathroom.

Every other case in this series is about people who could not stop spending. posted every purchase. bought 31 cars in a month. lived in a $30M penthouse. James Zhong spent almost nothing. The patience was the strategy. The patience was not enough — because the blockchain does not forget, and nine years is only a long time for a person. For a ledger, it is nothing.

THE ZHONG–ULBRICHT LOOP

+ CASE 016 — THE SAME STORY, TWO POSITIONS

Ulbricht (013)
Built Silk Road. Two life sentences + 40 years. Pardoned January 21, 2025.
Zhong (016)
Exploited the flaw in what Ulbricht built. Stole 51,680 BTC. 1 year and 1 day. Released 2023.
THE CONTRAST
The architect received a harsher sentence than the burglar. Building the machine that enables the crime is punished more severely than exploiting a flaw in the machine. Ulbricht was pardoned. Zhong served his time. Both are free.
CASE TIMELINE
~1991
Born
SOURCE: public record
Sept 2012
Exploits Silk Road withdrawal flaw
takes ~51,680 BTC
SOURCE: DOJ
Oct 2013
Silk Road shut down
Ulbricht arrested ()
SOURCE: DOJ
2013–2021
Holds the Bitcoin in the "Individual X" wallet
largely untouched
SOURCE: chain analysis
Nov 2021
DOJ seizes ~50,676 BTC from Zhong's residence (announced later)
SOURCE: DOJ
7 Nov 2022
DOJ reveals "Individual X" = James Zhong
he pleads guilty
SOURCE: SDNY
2023
Sentenced to 1 year + 1 day
SOURCE: SDNY
2023–2024
Sentence served (verify exact release per BOP)
SOURCE: BOP-reported
HOW THE FRAUD WORKED

THE CONNECTION TO — FROM THE CASE BRIEF

01
is , who BUILT Silk Road. Case 016 is James Zhong, who ROBBED it.
02
The flaw (as described in DOJ filings): Silk Road's system required a deposit before a withdrawal. In September 2012, Zhong exploited the withdrawal-processing logic — creating transactions that let him withdraw far more Bitcoin than he had deposited. He took ~51,680 BTC.
03
Then he did almost nothing with it for nine years.: He moved it into a single Bitcoin address that became famous in blockchain forensics: the "Individual X" wallet — one of the largest crypto holdings linked to a single person.
04
The chain to : Silk Road was shut down in October 2013 (Ulbricht arrested, )
05
The FBI seized Silk Road's servers — but most of the Bitcoin was already gone
06
In November 2021: , the DOJ announced it had seized ~50,676 BTC from "Individual X"
07
In November 2022: , the DOJ revealed Individual X was James Zhong — and he pleaded guilty
08
Ulbricht built the machine. Zhong gamed it. The government took the money from both of them.: That is the piece.
The government shut down the darknet marketplace in 2013. Eight years later it announced it had found $3.4 billion the marketplace had lost — stolen by a man who beat the house at its own game, then sat on the loot while the world's largest crypto forensics teams hunted for it.
DEFENSIVE LEVEL ONLY · THE SHAPE OF THE SCHEME, NOT A PLAYBOOK

WHAT THIS CASE ESTABLISHED

Largest single seizure of cryptocurrency by the US government at the time — ~50,676 BTC, ~$3.4B at Nov 2021 prices. The seizure value is a date-specific figure, not a fixed fact.
The blockchain does not forget. The Individual X wallet was tracked for nearly a decade by blockchain forensics firms. The coins never moved. Time is not a defence against a public ledger.
Lightest sentence-to-dollar ratio in this entire series: 1 year and 1 day for a theft valued at ~$3.4B (Nov 2021). Three factors: cooperation, victim character (Silk Road was itself a crime scene), and near-complete asset recovery.
Stolen from criminals. The “victim” of the theft was a drug marketplace whose founder was sentenced to life in prison. The moral weight the court assigns to a theft is influenced by the character of the thing stolen from.
The “and one day” is a technical feature of federal sentencing: a sentence of exactly one year is served in full; one year and one day qualifies for good-time credit that can reduce actual time served. The extra day is, paradoxically, a benefit.
Series thesis, Case 016: The Patience. He robbed the robbers. He held $3.4B (Nov 2021 value) in a popcorn tin for nine years. The ledger found him anyway. The state took the loot.
THE FULL STORY — 8 PARTS + EPILOGUE — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE POPCORN TIN (3,000 WORDS)
Sources: US DOJ / SDNY — press release revealing "Individual X" = James Zhong (7 Nov 2022); DOJ plea agreement, wire fraud (4 Nov 2022); SDNY sentencing (2023); US forfeiture filings; CNBC; Reuters; Bloomberg; Chainalysis. Every figure traces to a named source. Every Bitcoin valuation carries a date. This involves a living person who has been convicted, sentenced, and has served his sentence.
· PROLOGUE ·
The Popcorn Tin

In November 2021, federal agents executed a search warrant at a residence in Gainesville, Georgia.

They found a gaming computer. Inside it, on a single-board computer and various storage devices: approximately 50,676 Bitcoin. [SOURCE: DOJ forfeiture filings]

They found $661,900 in cash. [SOURCE: DOJ]

They found gold and silver bars. Hidden in a popcorn tin. Buried under blankets in a bathroom closet. [SOURCE: DOJ / reporting]

The Bitcoin, at the time of seizure in November 2021, was worth approximately $3.4 billion. [SOURCE: DOJ — value at Nov 2021 prices]

50,676 Bitcoin — $3.4 billion at November 2021 prices. In a house in Georgia. On a computer. Next to a popcorn tin full of gold bars in a bathroom.

The man who lived in the house was James Zhong. He had stolen the Bitcoin nine years earlier — from a website the FBI had already shut down, from an operator the federal government had already sentenced to die in prison, from a marketplace that was itself a crime scene.

He stole from the criminals. Then he sat on it. For nine years. And then the government came and took it all.

· PART ONE ·
Individual X

Before the world knew his name, the blockchain knew his wallet.

In the years after Silk Road was shut down — after was arrested in a San Francisco library in October 2013, after the FBI seized the marketplace's servers, after the federal government catalogued what it had taken — a question persisted in the forensic record. The Bitcoin did not add up.

Silk Road had processed an enormous volume of transactions during its two and a half years of operation. When the government seized the servers, it expected to find the Bitcoin that had flowed through the marketplace's escrow system. It found some. It did not find all of it. A substantial amount was missing — not misplaced in the accounting but absent from the wallets the government now controlled.

Somebody had taken it before they got there.

The wallet that held the missing Bitcoin became known in blockchain forensics circles as the "Individual X" wallet. It was one of the largest single holdings of Bitcoin linked to an identifiable — if unnamed — person. Chainalysis and other blockchain analysis firms tracked its existence. The coins sat. They did not move. Year after year, the wallet held still while Bitcoin's price climbed from hundreds of dollars to thousands to tens of thousands, and the value of the coins inside it grew from a curiosity into a fortune into something that could only be described with a B.

For eight years, Individual X was a ghost in the ledger. A wallet with no face. A theft with no suspect. The largest known haul from the most famous darknet marketplace in history, sitting in a single address, untouched, while the man who built Silk Road sat in a federal prison cell and the man who robbed it sat in a house in Georgia.

· PART TWO ·
September 2012 — The Nine Seconds That Made a Fortune

The theft happened in September 2012. Silk Road was still operational. Ulbricht was still free, still running the marketplace under the name , still a year away from the library and the handcuffs.

What James Zhong found was a flaw in the withdrawal system.

Silk Road operated on a deposit-then-withdraw model — users deposited Bitcoin into internal accounts, transacted on the marketplace, and withdrew their balances. The system was designed so that a user could not withdraw more than they had deposited. That was the assumption. It was also wrong.

Zhong discovered that the withdrawal-processing logic could be exploited — that by structuring his transactions in a specific way, he could withdraw far more Bitcoin than he had put in. [SOURCE: DOJ plea agreement / press release]

He exploited the flaw. He took approximately 51,680 Bitcoin. [SOURCE: DOJ]

51,680 Bitcoin. In September 2012, that was worth a fraction of what it would later become — Bitcoin was trading in single digits to low double digits for much of 2012. The dollar value at the time of theft was modest by the standards of this series. The value of the same coins nine years later, when the government seized them, was approximately $3.4 billion. [SOURCE: DOJ — Nov 2021 valuation]

The gap between those two numbers — the value at theft and the value at seizure — is the specific financial phenomenon that makes this case unusual. He did not steal $3.4 billion (Nov 2021 value). He stole 51,680 Bitcoin, which became worth $3.4 billion (Nov 2021 value) while he held it. The distinction matters because precision matters, and because the raw number — 51,680 BTC — is the fact, and the dollar amount depends entirely on which date you attach to it.

· PART THREE ·
The Patience — Nine Years of Nothing

This is the part that makes the case.

He had 51,680 Bitcoin. He had taken it from a marketplace that, at the time of the theft, was still the most actively monitored criminal enterprise on the internet. Every law enforcement agency with a cyber mandate was watching Silk Road. The FBI was building the case that would shut it down a year later. The blockchain was public — every transaction visible to anyone with the tools to read it.

And James Zhong did nothing.

He moved the Bitcoin into a consolidated holding. He sat on it. He did not spend it. He did not convert it. He did not buy houses or cars or watches or Birkin bags. He did not throw a $75,000 birthday party or rent a mansion for $68,000 a month or stream himself on Discord celebrating the moment the coins arrived.

He lived in Gainesville, Georgia. He held the Bitcoin. He waited.

One year. The FBI shut down Silk Road. Ulbricht was arrested. The government seized servers and wallets. Zhong's coins were not among what they found.

Two years. Bitcoin climbed. The coins sat.

Five years. Bitcoin entered the mainstream. Futures were listed on the CME. The price passed $19,000 in December 2017. Zhong's 50,000-plus coins were worth, briefly, nearly a billion dollars. He did not sell.

Seven years. Bitcoin crashed, recovered, crashed again. The coins sat.

Nine years. November 2021. Bitcoin reached its all-time high near $69,000. Zhong's holding was worth approximately $3.4 billion (Nov 2021 value). [SOURCE: DOJ — Nov 2021 valuation]

And then the government knocked on his door.

Every other case in this series is about people who could not stop spending. posted every purchase. bought 31 cars in a month. Madoff maintained the lifestyle for decades. lived in a penthouse in the Bahamas. The spending is always the evidence, and the evidence is always the spending.

James Zhong spent almost nothing. He held the largest stolen Bitcoin fortune in history and he waited, quietly, in a house in Georgia, while the value grew from thousands to millions to billions. The patience was the strategy. The patience was also, in the end, not enough — because the blockchain does not forget, and nine years is only a long time for a person. For a ledger, it is nothing.

· PART FOUR ·
The Seizure — November 2021

The United States government seized approximately 50,676 Bitcoin from James Zhong's residence in November 2021. [SOURCE: DOJ forfeiture filings]

The seizure was not announced immediately. The government held the information for a year — conducting its investigation, building its case, confirming the chain of evidence that connected the Individual X wallet to the man in the house in Georgia.

The specifics of the seizure, as described in DOJ filings: the Bitcoin was stored on devices in his home. A gaming computer. Storage devices. The $661,900 in cash and the gold and silver bars in the popcorn tin were also seized. [SOURCE: DOJ]

The popcorn tin is not a footnote. It is the image the case produces — a man with 50,676 BTC — $3.4 billion at November 2021 prices — on a computer, with gold bars hidden in a tin that once held caramel corn, under blankets in a bathroom closet. The juxtaposition between the scale of the digital fortune and the smallness of the physical hiding place tells you something about the man's relationship to the money. He did not live like a man who had billions in Bitcoin. He lived like a man who had a secret.

A note on the numbers: he stole approximately 51,680 BTC. The government seized approximately 50,676 BTC. The difference — roughly 1,004 BTC — is itself a detail. Per DOJ, those coins were not spent: Zhong voluntarily surrendered them to the government (1,004.15 BTC in total, beginning in March 2022). By his sentencing in April 2023, the government held final forfeiture orders for 51,680.32 BTC. [SOURCE: US Attorney SDNY, April 14, 2023, US v. Zhong, 22 Cr. 606 (PGG)]

· PART FIVE ·
The Reveal — November 7, 2022

On November 7, 2022, the Department of Justice announced that "Individual X" — the ghost in the Silk Road ledger, the wallet that blockchain forensic firms had tracked for nearly a decade — was James Zhong. [SOURCE: DOJ / SDNY press release, 7 Nov 2022]

He had pleaded guilty three days earlier, on November 4, 2022, to one count of wire fraud. [SOURCE: DOJ plea agreement]

One count. Wire fraud. For the theft of 51,680 Bitcoin from the most famous darknet marketplace in history — a theft that, measured by the value of the assets at seizure, was the largest individual cryptocurrency recovery the US government had ever executed.

The charge was not computer fraud, not money laundering, not conspiracy. Wire fraud. A single count that carried the entire weight of a $3.4 billion (Nov 2021 value) seizure.

· PART SIX ·
The Sentence — One Year and One Day

James Zhong was sentenced to one year and one day in federal prison. [SOURCE: SDNY sentencing, 2023]

One year and one day.

In a series where Madoff received 150 years, where Stanford received 110, where Ulbricht received two life sentences, where received 25 years, where Gonzalez received 20 and was released in 2023 — Zhong received one year and one day for the largest Bitcoin seizure in American history.

The sentence requires explanation, because the number on its face appears absurd relative to the dollar figure. The explanation has three parts.

First, cooperation. Zhong cooperated with the government. He did not flee. He did not destroy evidence — no phone tossed into Biscayne Bay, as did when the FBI came for him in . When the agents arrived at Zhong's door, the Bitcoin was there, the cash was there, and the gold was in the popcorn tin. He pleaded guilty. He assisted the government in recovering assets. Cooperation, in the federal system, is the single most powerful mitigating factor at sentencing.

Second, the victim. Silk Road was not a legitimate business. It was a criminal marketplace whose founder was convicted on five federal counts including running a continuing criminal enterprise. The "victim" of Zhong's theft was a crime scene. The moral weight that a judge assigns to a theft is influenced by the character of the thing stolen from — and stealing from a drug marketplace does not carry the same weight as stealing from pensioners or a sovereign fund.

Third, recovery. The government got the money back. Nearly all of it. 50,676 of 51,680 Bitcoin. The forfeiture was almost complete. In cases where restitution is the goal and the restitution is achieved, the punitive element of the sentence is reduced. The government did not need to punish Zhong into returning the money. He had already returned it — or, more precisely, the government had already taken it.

One year and one day. The "and one day" is a technical feature of federal sentencing: a sentence of exactly one year is served in full, but a sentence of one year and one day qualifies the defendant for good-time credit, which can reduce the actual time served. The extra day is, paradoxically, a benefit.

· PART SEVEN ·
The Loop — Ulbricht Built It, Zhong Beat It, the Government Emptied It

and Case 016 are the same story told from two positions.

built Silk Road. He created the anonymous marketplace, the Bitcoin escrow, the Tor hidden service. He ran it for two and a half years under the name . He was arrested in October 2013, convicted on five counts, and sentenced to two life sentences plus forty years. In January 2025, he was pardoned by President Trump. [SOURCE: Executive pardon, 21 January 2025]

James Zhong found the flaw in what Ulbricht built. He exploited the withdrawal system, took 51,680 Bitcoin, and held it for nine years while the government shut down the marketplace, arrested its founder, and spent nearly a decade trying to account for where the money had gone.

Ulbricht received two life sentences. Zhong received one year and one day.

Ulbricht built the infrastructure for anonymous criminal commerce and was sentenced to die in prison. Zhong exploited a bug in that infrastructure, stole from it, returned the money when caught, and served twelve months.

The contrast is not a commentary on justice — it is a fact of how the federal system weighs different kinds of conduct. Building the machine that enables the crime is punished more severely than exploiting a flaw in the machine. The architect receives a harsher sentence than the burglar. The system that processed millions of illegal transactions was judged more dangerous than the man who found the one transaction the system got wrong.

Ulbricht was pardoned. Zhong served his time. The Bitcoin went to the US government, which sold portions of it at public auction. The marketplace is gone. The money is accounted for. The two men who defined its history — the builder and the thief — are both free.

· PART EIGHT ·
What This Case Established

The largest single seizure of cryptocurrency by the US government at the time of announcement — approximately 50,676 Bitcoin, valued at approximately $3.4 billion (Nov 2021 prices). [SOURCE: DOJ]

The "Individual X" investigation demonstrated that blockchain forensics can identify wallet holders years or decades after a transaction, even when the coins are not moved. The ledger does not forget. Time is not a defence against a public blockchain.

A sentence of one year and one day for a theft valued in the billions — the lightest sentence-to-dollar ratio in this entire series — established that cooperation, victim character, and asset recovery weigh more heavily in federal sentencing than the raw dollar figure.

The case recovered the Bitcoin the FBI could not find when it shut down the marketplace in 2013 — accounted for nine years later, in a house in Georgia, in a popcorn tin and a gaming computer. Zhong voluntarily surrendered an additional ~1,004 BTC beyond what agents seized, bringing the total under final forfeiture orders to ~51,680.3 BTC.

· EPILOGUE ·
The Tin

He stole 51,680 Bitcoin from a darknet marketplace in September 2012.

He put it on a computer. He put gold bars in a popcorn tin. He put the tin under blankets in a bathroom closet. He lived in Gainesville, Georgia.

He waited nine years. The Bitcoin went from being worth thousands to being worth $3.4 billion (Nov 2021 value). He did not spend it. He did not post it. He did not celebrate it. He did not tell anyone — as far as the record shows — what was sitting on the hard drive in his house.

The blockchain did not care about his patience. The ledger recorded the theft in 2012 and held the record until 2021, when the government matched the wallet to the man and drove to Georgia with a warrant.

He cooperated. He pleaded guilty. He served one year and one day.

stole $200 million and served 22 months. stole 4,100 BTC from a single victim and faces decades. stole 170 million card numbers and received a twenty-year sentence. James Zhong stole 51,680 BTC — valued at $3.4 billion (Nov 2021 value) — and served a year.

The difference is not the amount. The difference is who you steal from and whether the government gets it back.

He robbed the robbers. The state took the loot. The popcorn tin is in an evidence locker somewhere, and the Bitcoin is in the US Treasury's account.

· VERIFIED SOURCES ·

Every Bitcoin valuation carries a date. The theft total (51,680 BTC) and the initial seizure (50,676 BTC) are distinguished throughout — the additional ~1,004 BTC was voluntarily surrendered by Zhong, bringing total forfeiture to ~51,680.3 BTC. This involves a living person who has been convicted, sentenced, and has served his sentence.

[1] US DOJ / SDNY — Press release: "Individual X" revealed as James Zhong, 7 November 2022.
[2] DOJ PLEA AGREEMENT — Wire fraud, guilty plea, 4 November 2022.
[3] SDNY SENTENCING — One year and one day, 2023.
[4] US FORFEITURE FILINGS — Approximately 50,676 BTC seized, November 2021. Value at seizure: ~$3.4 billion.
[5] DOJ — $661,900 cash, gold and silver bars seized from residence.
[6] CNBC — "Individual X" reveal and Silk Road connection coverage.
[7] REUTERS — Silk Road Bitcoin seizure reporting.
[8] BLOOMBERG — Blockchain forensics analysis of Individual X wallet.
[9] CHAINALYSIS — Wallet tracing and "Individual X" identification methodology.
*TraceChain Forensics · Fraud Exposed Series · Case 016*
*Every claim sourced. Every Bitcoin figure dated. Theft total ≠ seizure total.*
*He robbed the robbers. The state took the loot.*
*Closes the loop with : Ulbricht built it. Zhong beat it. The government emptied it.*
*What would prove it wrong?*
END OF REPORT
#19 OF 45
John Rigas
SINGLE PERSON
CASE 037 · CORPORATE FRAUDCONVICTED
Adelphia · 15 years · died 2021
~$2.3B
WHAT WAS TAKEN
Nothing taken in cash: ~$2.3B of family debt hidden off Adelphia's books. Shareholders lost when it collapsed.
HOW
Borrowed through shared credit lines and left the family's share out of Adelphia's accounts.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1952–2002Builds Adelphia from one cable franchise into the sixth-largest US cable company.SOURCE: case brief
1990s–2002Family entities co-borrow ~$2.3B on Adelphia's credit lines, kept off the company's books.SOURCE: SDNY verdict, 2004
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
JOHN RIGAS
THE FAMILY BANK · ADELPHIA COMMUNICATIONS · CASE 037 · CORPORATE FRAUD · 15 YEARS · DIED 2021
HIDDEN DEBT
~$2.3B kept off the books — not cash stolen
BANKRUPT
June 25, 2002
COUNTS
18 · jury, July 2004
SENTENCE
15 years · son Timothy 20
RELEASED
Feb 2016 · compassionate
DIED
Sept 30, 2021 · aged 96
WHAT $2.3B IS: debt the family ran up through Adelphia and hid from its books. The personal spending was a separate, smaller amount.
FULL PROFILE

IDENTITY

NAME
John J. Rigas
BORN
Nov 14, 1924 · Wellsville, New York
COMPANY
Adelphia Communications, Coudersport, Pennsylvania
ALSO
Owner of the Buffalo Sabres hockey team

CASE RECORD

CONVICTED
July 8, 2004 · 18 counts (with son Timothy)
SENTENCED
June 2005 · 15 years
SON
Timothy Rigas: 20 years, cut to 17; released 2019
RELEASED
Feb 2016 · aged 91, terminal cancer
DIED
Sept 30, 2021
KNOWN AS
John Rigas
STATUS
Convicted
COURT
US District Court, Southern District of New York
JUDGE
Leonard B. Sand
CHARGES
Conspiracy · Securities fraud · Bank fraud (18 counts)
PLEA
Not guilty — convicted by a jury, 8 July 2004
THE FAMILY AND THE FIRM
THE CFO20 YEARS
Timothy Rigas
His son
Convicted with him; sentence later cut to 17 years.
SOURCE: DOJ
THE COMPANYBANKRUPT 2002
Adelphia
Coudersport, PA
Once one of the biggest US cable operators.
SOURCE: Wikipedia
THE TEAMSOLD 2003
Buffalo Sabres
NHL
The family’s hockey team went into bankruptcy with the company.
SOURCE: WIVB
CASE TIMELINE
1952
The start
Buys a cable franchise in Coudersport.
SOURCE: Wikipedia
Mar 2002
Disclosed
Hidden co-borrowing revealed.
SOURCE: SEC
June 25, 2002
Bankrupt
Adelphia files.
SOURCE: Wikipedia
July 8, 2004
Guilty
18 counts.
SOURCE: DOJ
June 2005
15 years
Timothy: 20.
SOURCE: DOJ
Feb 2016
Released
Aged 91.
SOURCE: CNBC
Sept 30, 2021
Dies
Aged 96.
SOURCE: Washington Post
HOW IT WORKED

HOW THE DEBT WAS HIDDEN — DEFENSIVE LEVEL

01
Co-borrowing: Family companies borrowed alongside Adelphia under shared credit lines
02
Off the books: The family’s share was left out of Adelphia’s accounts
03
The use: Money went to family purposes
04
The warning sign: Related-party deals and a founding family on every side of them
HOW $2.3B DISAPPEARED FROM THE BOOKS
Shared credit lines
-->
Family draws money
-->
Left off the accounts
-->
Shareholders misled

WHAT THIS CASE ESTABLISHED

A family on both sides of the table is a warning sign.
Hiding debt is fraud even if the debt is real.
Series link: (Ebbers).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE FAMILY BANK (600 WORDS)
Sources: DOJ/SDNY indictment and trial · Conviction July 8, 2004 · Sentencing June 2005 · Adelphia bankruptcy filing June 2002 · SEC civil actions · Reuters/Bloomberg/NYT/Philadelphia Inquirer coverage. METRIC DISCIPLINE: ~$2.3B = off-balance-sheet debt concealed (the concealment figure). This is NOT cash stolen. Family personal benefit is a separate, smaller figure. Never write 'Rigas stole $2.3B.' Pairs with Ebbers (024) and Kozlowski (038): three versions of the same corporate-fraud category.
· PROLOGUE ·
The Hole in the Books

The debt was real. It was just not on the books.

Adelphia Communications, founded by John Rigas in 1952 in Coudersport, Pennsylvania, grew over five decades into one of the largest cable operators in the United States. By the late 1990s, it was a publicly traded company with millions of subscribers, thousands of employees, and a balance sheet that — as it turned out — showed approximately $2.3 billion less in obligations than the company actually had.

The concealment mechanism: the Rigas family used co-borrowing arrangements — credit facilities that they drew on for personal and family purposes but that were structured to appear as Adelphia corporate obligations or were not reported on Adelphia's books at all. When the SEC began investigating in 2002 and the disclosures followed, the gap was visible and the company was not survivable.

Adelphia filed for bankruptcy in June 2002 — one of the largest corporate bankruptcies in US history at the time. John Rigas and his son Timothy Rigas were convicted at trial on July 8, 2004, on 18 counts of securities fraud, bank fraud, and conspiracy. John Rigas was sentenced in June 2005 to 15 years in federal prison. He was released in 2016 on compassionate grounds at age 91. He died on September 30, 2021, aged 96. [SOURCE: DOJ; Reuters; Wikipedia]

· PART ONE ·
The Mechanism — Off-Book Debt and Self-Dealing

Adelphia's founding family held executive positions across the company. John Rigas was founder and CEO; Timothy Rigas was CFO; other family members held senior roles. The family also had substantial personal ownership.

The fraud operated on two tracks. The first: the Rigas family used Adelphia's credit to borrow money for personal purposes — real estate, investment losses, and other family expenses — without disclosing the borrowing on Adelphia's public financial statements. The off-balance-sheet obligations grew to approximately $2.3 billion. Investors who read Adelphia's financial statements could not see these obligations; the company appeared substantially healthier than it was.

The second track: direct personal benefit. The prosecution documented specific instances of company resources flowing to family purposes — personal expenses paid, assets used, money moving from the public company into family accounts. The personal benefit figure was smaller than the off-balance-sheet debt figure; they are different numbers measuring different things.

The concealment was the offence. Spending company money can be a breach of fiduciary duty and a civil matter; concealing it in the books is securities fraud and bank fraud, because investors and lenders made decisions based on financial statements that were materially false.

· PART TWO ·
The Corporate Trio — The Series Context

Three companies. Three CEOs. Three different places they put the lie.

In all three cases, the company's financial statements did not reflect reality. In all three cases, the fraud required falsification — not just misconduct, but concealment. In all three cases, the victims were shareholders and employees who made decisions based on statements that had been altered to hide the truth.

John Rigas was 79 years old when he was convicted. He was 91 when he was released. He died at 96. Timothy Rigas, his son and co-defendant, received 20 years, later reduced to 17; he was released in 2019. The case is closed by death. The record is as above.

VERIFIED SOURCES
[1] DOJ/SDNY — indictment; conviction July 8, 2004, 18 counts; sentencing June 2005, 15 years (John and Timothy Rigas).
[2] SEC — civil actions against Adelphia and the Rigas family.
[3] Adelphia bankruptcy filing — June 2002. One of the largest US bankruptcies at the time.
[4] Reuters/Philadelphia Inquirer — trial and conviction coverage; release (2016) and death (September 30, 2021) reporting.
TO VERIFY Exact sentencing date · Release exact date and basis · Timothy Rigas sentence and release status · Shareholder loss estimate · Exact personal benefit figure (separate from the $2.3B off-book debt)
SOURCES
[1] PRIMARY — US Attorney SDNY: conviction (2004) and sentence (2005)
[2] PRIMARY — SEC: Adelphia civil action (2002)
[3] SECONDARY — CNBC: release (2016); Washington Post: obituary (2021)
END OF REPORT
#20 OF 45
Nick Leeson
SINGLE PERSON
CASE 022 · ROGUE TRADINGCONVICTED
Barings Bank · account 88888 · 6½ years · Singapore 1995
£827M
WHAT WAS TAKEN
Barings Bank's money (~$1.3B), lost in hidden trades — a loss, not money he pocketed. The bank failed.
HOW
Ran the trading desk and its records; hid losses in account 88888 and kept doubling down.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1990–1992Sent by Barings to sort out its Jakarta back office before the Singapore posting.SOURCE: case brief
1992–1995Runs Barings Futures Singapore; hides losses in account 88888 until they reach £827M.SOURCE: Bank of England report; Singapore court
Feb 1995Leaves Singapore with a note reading 'I'm sorry'; Barings collapses three days later.SOURCE: case brief
Dec 1995–1999Returned from Frankfurt; sentenced in Singapore to 6½ years, released in 1999.SOURCE: Singapore court
2 Mar 1995Arrested at Frankfurt airport; held until extradition to Singapore in November.SOURCE: case brief
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
NICK LEESON
THE 88888 ACCOUNT · CASE 022 · ROGUE TRADING · BARINGS BANK · SENTENCED 6½ YEARS SINGAPORE 1995
LOST
£827M · ~$1.3B
THE BANK
Barings · founded 1762 · 232 years
SOLD FOR
£1 · to ING, March 1995
SENTENCE
6 years 6 months · Singapore
RELEASED
July 3, 1999
THE ACCOUNT
88888 · the hidden error account
POUNDS, NOT DOLLARS: £827M is the bank’s trading loss (~$1.3B at 1995 rates) — not money he took. It was more than Barings’ capital, which is why the bank failed.
FULL PROFILE

IDENTITY

NAME
Nicholas William Leeson
BORN
February 25, 1967 · Watford, England
CAREER
Left school at 18; bank clerk; joined Barings in 1989; Jakarta, then Singapore
THE ROLE
Ran both the trading floor and the back office that recorded the trades
LATER
Memoir Rogue Trader (1996); film of the same name (1999, Ewan McGregor); CEO of Galway United FC; speaker on risk
TODAY
Living, 59

CASE RECORD

FLED
February 23, 1995 · Singapore → Kuala Lumpur → Brunei → Frankfurt · a note: “I’m sorry”
ARRESTED
March 2, 1995 · Frankfurt
EXTRADITED
November 1995 · to Singapore
PLEA
Guilty · deceiving auditors and cheating the Singapore exchange (SIMEX)
SENTENCED
December 2, 1995 · 6 years 6 months
RELEASED
July 3, 1999 · after treatment for colon cancer in prison
INQUIRY
UK Board of Banking Supervision report, July 1995
THE BANK, THE BUYER & THE WATCHDOGS
THE VICTIMCOLLAPSED 1995
Barings Bank
Founded 1762
Financed the Louisiana Purchase; outlasted the Napoleonic Wars and two world wars. Placed into administration February 26, 1995.
SOURCE: Britannica · CNBC
THE BUYER£1
ING
Dutch financial group
Took over Barings and about 1,200 staff for one pound. Shareholders lost everything.
SOURCE: CNBC
THE CENTRAL BANKNO RESCUE
Bank of England
February 1995
Barings asked for emergency support; the Bank of England declined to organise a rescue.
SOURCE: Wikipedia · FT
THE INQUIRYJULY 1995
Board of Banking Supervision
UK regulator’s report
Found the core failure: the same person took the risk and kept the record, and London kept funding margin calls without asking why.
SOURCE: BoBS report
THE EXCHANGETHE MARKET
SIMEX
Singapore International Monetary Exchange
Where Leeson traded Nikkei futures and options. He was convicted of cheating it.
SOURCE: Washington Post
THE TRIGGERJAN 17, 1995
Kobe earthquake
Japan
The Nikkei fell hard. Positions he had doubled up on became unrecoverable within weeks.
SOURCE: CNBC · FT
LEESON (CASE 022) VS MADOFF (CASE 004)
CONTROL FAILURE
Leeson: no separation of trading and record-keeping · Madoff: no independent check of returns
DURATION
Leeson: ~3 years (1992–1995) · Madoff: decades
WHAT WAS DESTROYED
Leeson: Barings, a 232-year-old bank · Madoff: his own firm and his investors’ savings
HOW IT ENDED
Leeson: the market · Madoff: the 2008 crisis
SENTENCE
Leeson: 6½ years · Madoff: 150 years
CASE TIMELINE
1989
Joins Barings
SOURCE: Wikipedia
1992
Singapore
Runs trading and the back office. Opens account 88888 to hide a small error.
SOURCE: BoBS report
1993–94
Doubling down
Hidden losses grow; London posts profits and pays bonuses.
SOURCE: BoBS report
January 17, 1995
Kobe earthquake
The Nikkei falls; the losses become terminal.
SOURCE: CNBC
February 23, 1995
Gone
Leaves Singapore with his wife and a note: “I’m sorry.”
SOURCE: Washington Post
February 26, 1995
Barings fails
Placed into administration; £827M lost.
SOURCE: Britannica
March 2, 1995
Arrested
Frankfurt.
SOURCE: Washington Post
March 1995
Sold for £1
ING takes over.
SOURCE: CNBC
July 1995
The inquiry
Board of Banking Supervision report.
SOURCE: BoBS
December 2, 1995
Sentenced
6 years 6 months in Singapore.
SOURCE: Washington Post
July 3, 1999
Released
After cancer treatment in prison.
SOURCE: CBS News
1999
The film
Rogue Trader, starring Ewan McGregor.
SOURCE: Wikipedia
HOW IT WORKED

HOW ONE TRADER BROKE A BANK

01
One person, two jobs: He placed the trades and kept the records of them — nobody independent checked
02
The hidden account: A small 1992 loss went into account 88888 instead of being reported
03
Doubling down: He bet bigger to win it back; every loss made the next bet larger
04
Fake profits: London saw profits, paid bonuses and funded ever-larger margin calls
05
The collapse: After the Kobe earthquake the losses passed £800M — more than the bank’s capital
HOW THE LOSS GREW
Nikkei futures & options
-->
Account 88888
-->
Margin calls funded by London
-->
£827M loss

WHAT THIS CASE ESTABLISHED

Separation of duties is not paperwork: the person taking the risk must never be the person recording it.
Warning signs were there — huge margin calls from a “profitable” desk — and nobody asked.
Not a theft: a loss hidden and doubled until it destroyed a 232-year-old bank.
Series link: (Madoff) — the check that should have caught it did not exist.
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE 88888 ACCOUNT (1,900 WORDS)
Sources: Singapore court records · Barings insolvency record, 26 February 1995 · UK Board of Banking Supervision inquiry (July 1995) · ING acquisition record · Reuters / FT contemporaneous coverage · Nick Leeson, Rogue Trader (1996) — self-account, treated as claim not fact · Wikipedia (aggregator). CURRENCY: £827M is pounds sterling. Converting to US dollars requires labelling the date and rate (~US$1.3–1.4B at February 1995 exchange rates).
· PROLOGUE ·
One Man. One Account. Three Years.

Barings Bank was founded in 1762. It financed the Louisiana Purchase. It helped the British government fund the Napoleonic Wars. By the time Nick Leeson arrived in Singapore in the early 1990s, Barings had been operating for 232 years — longer than the United States had existed.

It lasted three more.

On February 26, 1995, Barings Bank was declared insolvent. The cause: £827 million in losses accumulated by a single trader in a hidden account called 88888 — a number considered lucky in Chinese culture, chosen by Leeson originally to book a small accounting error he wanted to make disappear. [SOURCE: Singapore court record; Board of Banking Supervision inquiry, July 1995]

The losses did not disappear. They grew. For approximately three years, Leeson took increasingly large positions on Japanese interest-rate futures and options, booked his losses into account 88888, and reported profits to London. London paid him a bonus for his reported performance. The bonus was based on profits that did not exist.

When the Kobe earthquake struck Japan on January 17, 1995, the Nikkei fell sharply and kept falling. The positions in account 88888 — which Leeson had been building larger, trying to trade his way back to even — became unrecoverable. The losses were terminal before London even understood the scale. [SOURCE: FT; Wikipedia citing sources]

On February 23, 1995, Leeson left Singapore. Three days later, Barings was insolvent. ING, the Dutch bank, acquired it for £1. [SOURCE: widely reported; ING acquisition record]

Barings had survived empires and financed wars. It was destroyed in three years by one trader — because the person taking the risk was the person recording it. The fraud was not clever. It was a missing control, exploited by a man who did not stop.

· PART ONE ·
Who He Was and How He Got There

Nicholas William Leeson was born on February 25, 1967, in Watford, England. He left school at 18 and took a job as a clerk in a bank. He was good with numbers, ambitious, and — in the specific culture of 1980s London banking — the kind of person who could rise fast if given the chance.

He joined Barings in 1989. Within a few years he was posted to Indonesia, then to Singapore, where Barings had a futures trading operation. In Singapore, Leeson was given an unusual degree of responsibility: he was both the head of the trading operation and the head of the back office — the settlement and record-keeping function. These two roles should never sit with the same person. The person who makes a trade should not be the person who records it. That separation is one of the foundational controls in regulated financial institutions.

At Barings Singapore, the control was absent. Leeson was, in effect, marking his own homework. When he made a mistake in 1992 — a junior trader on his team made an error that cost roughly £20,000 — he did not report it. He opened a new account to park the loss and told himself he would recover it. The account was numbered 88888. [SOURCE: Singapore court record; Wikipedia citing Board of Banking Supervision inquiry]

That decision — to hide a small error rather than report it — is the moment the fraud began. Everything that followed was the arithmetic consequence of that choice: conceal, trade to recover, lose more, conceal more, trade larger, lose larger.

· PART TWO ·
Account 88888 — How the Losses Grew

From 1992 to 1995, account 88888 accumulated what Leeson could not recover. He was trading Nikkei futures and options — derivatives contracts linked to the performance of the Japanese stock market. His strategy: bet on stability. Buy contracts when the market fell, expecting it to recover. When it fell further, buy more.

The strategy is called 'doubling down' and it is the mechanism by which a recoverable mistake becomes an unrecoverable one. The position grows larger with each losing trade, because each new trade is sized to win back all the previous losses in a single recovery. If the market never recovers enough, the position grows until the institution cannot absorb it.

The Nikkei did not recover enough. By late 1994, the losses in account 88888 were in the hundreds of millions of pounds. Leeson was reporting profits. London was posting record results. His bonus for 1994 was approximately £130,000. [SOURCE: Wikipedia citing sources — verify figure] The profits were fabricated. The bonus was paid on fiction.

The control that should have caught this — an independent back office that reconciled trading positions against external records — did not exist in the form that would have been required. Internal auditors reviewed Barings Singapore's books. External auditors signed off on accounts. Neither caught the discrepancy between the positions in account 88888 and the external clearing house records, despite the fact that, by 1994, Barings was posting enormous margin calls to cover 88888's positions — margin calls that London was funding without fully understanding why. [SOURCE: Board of Banking Supervision inquiry, July 1995]

The Kobe earthquake of January 17, 1995 was not the cause of the fraud. It was the event that made the consequences irreversible. The quake sent the Nikkei down sharply in the days following. Leeson's existing positions — already billions of yen underwater — became terminal. He bought more contracts, trying to move the market. The market did not move. The losses became £827 million. [SOURCE: FT; Wikipedia; Singapore court record]

LEESON (Case 022) vs MADOFF ()

Control failure

Leeson: no separation between trading and back office. Madoff: no independent audit of returns. Both: the check did not exist.

Duration

Leeson: ~3 years (1992–1995). Madoff: ~17 years active Ponzi phase. Both: nobody looked.

Institution destroyed

Leeson: Barings — 232 years, one of Britain's most respected banks. Madoff: his own firm.

Discovery mechanism

Leeson: market moved against him until losses were terminal. Madoff: financial crisis forced redemption requests he could not meet. Both: not caught by auditors.

Sentence

Leeson: 6.5 years (Singapore). Madoff: 150 years (SDNY).

· PART THREE ·
The Collapse — February 1995

On February 23, 1995, Nick Leeson left Singapore with his wife. He left a note: 'I'm sorry.' He flew to Kuala Lumpur, then to Brunei, then to Frankfurt, where German authorities arrested him on March 2, 1995. [SOURCE: widely reported; Singapore court record]

In Singapore, the scale of the losses became clear to Barings in the days after he left. The margin calls — the cash required to maintain the positions in account 88888 — exceeded anything the bank could fund. Barings Bank went to the Bank of England and asked for emergency support. The Bank of England declined to organize a rescue. On February 26, 1995, Barings was placed into administration. [SOURCE: FT; Wikipedia citing sources]

ING, the Dutch financial group, acquired Barings and its approximately 1,200 employees for £1. [SOURCE: widely reported] The employees retained their jobs, largely. The shareholders — the people who owned Barings, including some long-serving employees with equity stakes — lost everything. Some pensioners lost portions of their retirement savings. A 232-year-old institution transferred ownership for one pound.

Leeson was extradited to Singapore. He pleaded guilty in December 1995 and was sentenced to six years and six months in prison. He served approximately three years and five months before being released in July 1999 for good behaviour. During his imprisonment, he was diagnosed with colon cancer and treated in prison. [SOURCE: Wikipedia citing sources — verify exact release basis and date]

After release, he wrote a memoir, became a speaker and commentator on risk management, and later became CEO of Galway United Football Club in Ireland. He is 59 years old. He is a living private individual and public commentator. This piece reports the record of the fraud and the sentence; it does not speculate about his current circumstances.

· PART FOUR ·
The Lesson — What Was Missing

The Board of Banking Supervision — the UK regulatory body that investigated the Barings collapse — published its inquiry in July 1995. Its findings documented specifically what controls had been absent and how those absences allowed the losses to accumulate undetected for three years. [SOURCE: Board of Banking Supervision inquiry, July 1995 — verify title]

The primary failure: separation of duties. Leeson combined the roles of trader and head of back office. The back office settles trades and records positions — it is supposed to be independent of the trading desk so that errors and fraud can be detected before they compound. At Barings Singapore, the same person did both. The check did not exist.

The secondary failures compounded the primary one. Internal audits did not catch the discrepancy. External auditors did not catch it. London management noticed that Barings Singapore was requiring unusually large margin calls — funding requests to cover positions — but did not investigate why with sufficient rigour to discover account 88888. The signals were present. The investigation was not.

This is the lesson the brief asks to be stated plainly, because it applies directly to every case in this series that involves an institution that failed to check: the compliance function is not a formality. It is the institution's only protection against the person inside it who decides not to stop. When the compliance function does not function, the only remaining check is the market — and the market checks through collapse.

Barings was 232 years old. It had never lost a war. It lost one employee.

It took one man, one account, and three years. Barings had outlived empires and financed wars. It did not survive a trader who booked his own losses and kept trading to hide them. Nobody separated the risk from the record. The bank was older than America. The control was missing the whole time.

VERIFIED SOURCES
£827M is pounds sterling — label currency and label the conversion rate/date if converting. The loss exceeded total capital — that is why the bank failed. Do not write it as a caper. Human cost: ~1,200 jobs, shareholder equity, some pension exposure. Living person — Leeson is a public commentator. Report the record.
[1] Singapore court records — plea and sentencing, December 1995. 6 years 6 months. [Verify exact sentencing date and charge specifics]
[2] Board of Banking Supervision — 'Report of the Board of Banking Supervision Inquiry into the Circumstances of the Collapse of Barings' (July 1995). Primary document for the control-failure analysis. [VERIFY exact title and availability]
[3] Barings insolvency record — 26 February 1995. ING acquisition for £1. [VERIFY exact acquisition terms and date]
[4] Reuters / FT — contemporaneous coverage of the collapse, arrest, trial, and sentencing. 1995. Primary secondary record.
[5] Nick Leeson — Rogue Trader (memoir, 1996). SELF-ACCOUNT. Used as a claim, not a source of fact.
[6] Wikipedia — Nick Leeson / Barings Bank. Aggregators. Source for: release date July 1999; cancer diagnosis in prison; Galway United FC. [Verify primary]
TO VERIFY Exact sentencing and release dates · £208M capital figure and its source · Whether £827M is the definitive final figure or later revised · Employee and pensioner impact figures · Leeson's bonus for 1994 (reported as ~£130,000) · Board of Banking Supervision inquiry exact conclusions
SOURCES
[1] PRIMARY — Singapore court: plea and sentence, December 2, 1995
[2] PRIMARY — Report of the Board of Banking Supervision Inquiry into the Collapse of Barings (July 1995)
[3] SECONDARY — The Washington Post, December 2, 1995
[4] SECONDARY — CNBC, February 26, 2020: The Barings collapse 25 years on
[5] SECONDARY — Britannica: Bankruptcy of Barings Bank
[6] AGGREGATOR — Wikipedia: Nick Leeson
[7] SELF-SERVING — Rogue Trader (memoir, 1996)
END OF REPORT
#21 OF 45
Philip Esformes
SINGLE PERSON
CASE 045 · HEALTHCARE FRAUDCOMMUTED
Miami nursing homes · 20 years · commuted 2020
~$1.3B
WHAT WAS TAKEN
Claims billed to Medicare and Medicaid through his nursing homes (DOJ) — billed, not all paid.
HOW
Paid doctors and hospital staff to steer patients into his facilities, then billed for their care.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1998–2016Runs a chain of nursing and assisted-living facilities; ~$1.3B billed to Medicare and Medicaid on kickback-driven referrals, the largest health-care fraud case charged.SOURCE: DOJ S.D. Fla.
July 2016Arrested in Miami.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
PHILIP ESFORMES
THE REFERRAL MACHINE · NURSING HOMES · CASE 045 · HEALTHCARE FRAUD · 20 YEARS · COMMUTED 2020
CLAIMS
~$1.3B to Medicare & Medicaid (DOJ)
COUNTS
20 · jury, Apr 2019
SENTENCE
20 years · Sept 2019
COMMUTED
Dec 22, 2020 · not pardoned
STATUS
Conviction stands
LATER
2024 plea on remaining counts
COMMUTED, NOT PARDONED: the sentence was cut; the conviction remains. ~$1.3B is claims, not money paid.
FULL PROFILE

IDENTITY

NAME
Philip Esformes
FROM
Miami, Florida (family business from Chicago)
BUSINESS
Skilled nursing and assisted-living facilities in Miami

CASE RECORD

ARRESTED
July 2016 · Miami
CONVICTED
Apr 5, 2019 · 20 counts
SENTENCED
Sept 12, 2019 · 20 years
COMMUTED
Dec 22, 2020 · President Trump
LATER
Feb 2024 plea deal on retrial counts (CNBC)
BORN
1968
STATUS
Commuted
CUSTODY
Released
COURT
US District Court, Southern District of Florida
JUDGE
Robert Scola
CHARGES
Conspiracy to defraud the US · Health care fraud · Kickbacks · Money laundering · Obstruction (20 counts)
PLEA
Not guilty — convicted by a jury on 20 counts, 5 April 2019
THE HEALTHCARE TRIO
THE CLEMENCYDEC 2020
Commutation
Not a pardon
Released after about four years in custody.
SOURCE: White House
CASE TIMELINE
July 2016
Arrested
Miami.
SOURCE: DOJ
Apr 5, 2019
Guilty
20 counts.
SOURCE: DOJ
Sept 12, 2019
20 years
Sentenced.
SOURCE: DOJ
Dec 22, 2020
Commuted
President Trump.
SOURCE: White House
Feb 2024
Plea
On counts the jury hadn’t decided.
SOURCE: CNBC
HOW IT WORKED

HOW THE REFERRAL MACHINE WORKED — DEFENSIVE LEVEL

01
The payments: Kickbacks to doctors and discharge staff
02
The referrals: Patients steered into his facilities
03
The billing: Medicare and Medicaid billed for care, some unnecessary
04
The warning sign: Where a patient goes is decided by who got paid
HOW A KICKBACK BECAME A CLAIM
Kickback to doctor
-->
Patient referred
-->
Facility bills
-->
Medicare pays

WHAT THIS CASE ESTABLISHED

A commutation shortens a sentence; it does not erase a conviction.
Series link: Cases 043 and 044.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE REFERRAL MACHINE (700 WORDS)
Sources: DOJ/US Attorney S.D. Fla. · Trial conviction April 2019 · Sentencing 2019 · White House commutation December 2020. CRITICAL DISTINCTION: COMMUTED ≠ PARDONED. A commutation reduces the sentence. The conviction remains on the record. He is still convicted.
· PROLOGUE ·
The Referral Machine

Perez (043) faked the patients. Patel (044) faked the need. Esformes faked the reason they came.

Philip Esformes owned and operated a network of approximately 30 nursing homes and assisted-living facilities in Florida — a real network providing real care to real residents. The fraud was in the pipeline that brought those residents into the facilities: Esformes paid physicians, hospital discharge workers, and others to refer patients into his network, in violation of the anti-kickback provisions that govern Medicare referrals. Once the patients were in his facilities, the network billed Medicare for services — including services that were unnecessary or not provided as billed.

The total fraudulent claims figure: approximately $1.3 billion — described by the DOJ at the time of charging in 2016 as one of the largest individual healthcare fraud cases ever brought. [SOURCE: DOJ / US Attorney S.D. Fla., 2016]

Esformes was convicted at trial on April 5, 2019 and sentenced to 20 years in federal prison on September 12, 2019. In December 2020, President Trump commuted his sentence. The commutation shortened the sentence. It did not erase the conviction. He was convicted. He still is. [SOURCE: DOJ; White House clemency record December 2020]

· PART ONE ·
The Referral Chain — Patients as Inventory

The anti-kickback statute exists because referrals must be made in the patient's interest, not in the financial interest of the person making the referral. A physician who refers a patient to a facility because the facility has paid them is making a financial decision, not a clinical one. The patient may not receive care that is appropriate for them; the facility bills Medicare regardless.

Esformes's network operated this way at scale. Physicians received payments for sending patients to his facilities. Discharge workers at hospitals were paid to direct patients into the network when they were ready to leave acute care. The patients — elderly, often vulnerable, in transition from hospital care — were the inventory that moved through the referral chain and generated the billing claims.

Approximately 30 facilities processed those patients and billed Medicare for their care — including, per the DOJ, services that were unnecessary or not provided as documented. The residents were real. The care was at least partially real. The fraud was in the kickbacks that determined which facility they went to and in the billing for services beyond what was genuinely provided.

The human cost is the most delicate aspect of this case: nursing-home and assisted-living residents are among the most vulnerable people in the healthcare system. They rely on the facilities that care for them. When those facilities are selected through a kickback arrangement rather than on clinical merit, the residents' welfare is secondary to the financial transaction. State this with care, without sensationalism.

· PART TWO ·
The Commutation — December 2020

The commutation was issued by President Trump on December 22, 2020. A commutation reduces or eliminates a sentence; it does not reverse the conviction or constitute a finding of innocence.

This is the precise legal distinction the brief for this case flags: Esformes was convicted. His sentence was commuted. The conviction stands. He is not 'pardoned' (which would erase the conviction record); he is convicted with a commuted sentence.

Esformes's commutation is legally distinct from every pardon in the series: Milton (041), pardoned in March 2025 (a full pardon affects his conviction record differently); Milken (034), pardoned in February 2020; Ulbricht (013), pardoned in January 2025; (015), pardoned in October 2025. State the instrument precisely.

The healthcare trio is now complete. Perez (043): fabricated claims. Patel (044): manufactured demand through kickbacks. Esformes (045): purchased referral pipeline. Together they document every major engine of large-scale healthcare fraud: the billing licence, the kickback network, and the referral chain.

VERIFIED SOURCES
COMMUTED ≠ PARDONED — use the precise term. ~$1.3B billed; verify paid amount. Living person. Nursing-home residents are vulnerable — state harm with restraint.
[1] DOJ / US Attorney S.D. Fla. — charging documents 2016; trial conviction April 2019; sentencing 2019, 20 years.
[2] White House clemency record — commutation December 22, 2020. [Verify exact date and terms of commutation]
[3] Miami Herald — extensive local coverage; the definitive secondary account.
TO VERIFY Exact network size (~30 facilities) · Exact charge counts · Billed ($1.3B) vs paid split · Commutation exact date and terms · Esformes's current legal status under the commutation · Co-defendant outcomes
SOURCES
[1] PRIMARY — US DOJ / US Attorney S.D. Fla.: conviction and sentence (2019)
[2] PRIMARY — White House clemency grants (Dec 22, 2020)
[3] SECONDARY — CNBC / NBC News (2024)
END OF REPORT
#22 OF 45
Ross Ulbricht
SINGLE PERSON
CASE 013 · DARK WEB MARKETPLACEPARDONED JAN 2025
Dread Pirate Roberts · Silk Road · pardoned · the only ending that changed
~$1.2B
WHAT WAS TAKEN
Nothing stolen. $1.2B is the drugs and illegal goods sold on his site; he took ~$80M in fees.
HOW
Ran Silk Road, a dark-web drug market, and took a cut of every sale.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2011Launches Silk Road from Austin as a Tor hidden service taking Bitcoin.SOURCE: US v. Ulbricht, SDNY
2012–2013Runs the market as Dread Pirate Roberts from rented rooms in San Francisco.SOURCE: trial record
1 Oct 2013Arrested by the FBI in the Glen Park public library with the laptop open.SOURCE: FBI
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: Gage Skidmore · CC BY-SA 3.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
ROSS WILLIAM ULBRICHT
DREAD PIRATE ROBERTS · SILK ROAD · CASE 013 · DARK WEB · PARDONED JANUARY 2025
SENTENCE
2 life terms + 40 years
NOTE
No headline dollar figure — Silk Road was a marketplace
SILK ROAD RAN
2011–2013 — approximately 2.5 years
CONVICTED
5 counts · SDNY · 2015
PARDONED
January 21, 2025 · President Trump
SERVED
~10 years before pardon
BORN
March 27, 1984 · Austin, Texas
STATUS
PARDONED — FREE — 2025
NOTE: No headline dollar figure in this case. Silk Road was a marketplace — not a direct theft. Any volume figure is an estimate of marketplace turnover. Murder-for-hire = evidence considered at sentencing, never charged as a count at trial. Not a conviction. This involves a living person who has been pardoned and released.
FULL PROFILE

IDENTITY

NAME
Ross William Ulbricht
HANDLE
Dread Pirate Roberts · Frosty · Altoid
BORN
March 27, 1984 · Austin, Texas
EDUCATION
University of Texas at Dallas · BS · Penn State · Master’s 2009
RANK
Eagle Scout — highest Boy Scouts rank
BEFORE SILK ROAD
Day trading (failed) · video game company (failed)
PLATFORM
Silk Road — Tor hidden service · Bitcoin payments · darknet marketplace

CASE RECORD

CASE
US v. Ulbricht · S.D.N.Y.
ARRESTED
October 2013 · San Francisco public library — logged in, laptop open
CONVICTED
5 counts · 2015: continuing criminal enterprise · narcotics distribution · money laundering · ID documents · computer hacking
SENTENCE
2 life terms + 40 years (concurrent) · no parole
APPEALS
Second Circuit 2017 (upheld) · Supreme Court cert denied 2018
PARDON
Full and unconditional · January 21, 2025 · President Trump
SERVED
Approximately 10 years before pardon
MURDER-FOR-HIRE
Evidence at sentencing only — never charged, never convicted [CRITICAL]
SENTENCING NOTE — MURDER-FOR-HIRE

EVIDENCE AT SENTENCING — NOT A CHARGE, NOT A CONVICTION

Evidence presented at Ulbricht’s sentencing hearing indicated he had commissioned murder-for-hire deals targeting individuals. This evidence was considered by the judge and influenced the severity of the sentence. He was not charged with murder-for-hire. It was not a count at trial. It is not a conviction. Sentencing courts may consider conduct not independently charged; the standard of proof is different from trial. To state it as a conviction is inaccurate. To omit it is incomplete — it shaped the sentence. The framing above is the correct one.

THE PARDON — JANUARY 21 2025

THE ENDING THAT CHANGED

Full and unconditional pardon · January 21, 2025 · President Trump’s first full day in office [SOURCE: Executive pardon]

A pardon is not an acquittal. It does not reverse the conviction. It does not say the courts were wrong. It is executive clemency — the president’s constitutional authority to release a person from the consequences of a federal conviction. The legal system spoke at trial, appeal, and Supreme Court. All three times: you will die in federal prison. A signature undid it. He is the only person in this series whose ending changed.

CASE TIMELINE
27 Mar 1984
Born, Austin, Texas
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Eagle Scout
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
UT Dallas (BS)
SOURCE: case brief (sources listed in its SOURCES part)
2009
Graduates Penn State (MS)
returns to Austin
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Tries day trading
starts a video game company — neither venture succeeded
SOURCE: case brief (sources listed in its SOURCES part)
2011
Silk Road launches
Tor hidden service, Bitcoin payments
SOURCE: case brief (sources listed in its SOURCES part)
Oct 2013
FBI arrests Ulbricht
Silk Road taken offline
SOURCE: case brief (sources listed in its SOURCES part)
2015
Convicted on 5 counts
sentenced to two life terms + 40 years
SOURCE: case brief (sources listed in its SOURCES part)
2017
Second Circuit appeal
unsuccessful
SOURCE: case brief (sources listed in its SOURCES part)
2018
Supreme Court appeal
unsuccessful
SOURCE: case brief (sources listed in its SOURCES part)
21 Jan 2025
PARDONED by President Trump
SOURCE: case brief (sources listed in its SOURCES part)
HOW THE FRAUD WORKED

THE CONVICTIONS — FROM THE CASE BRIEF

01
Convicted in 2015 of:
02
Engaging in a continuing criminal enterprise: (the most serious — the "kingpin" statute)
03
Distributing narcotics by means of the internet
04
Conspiracy to commit money laundering
05
Conspiracy to traffic fraudulent identity documents
06
Conspiracy to commit computer hacking
07
THE SENTENCE: two life terms plus 40 years, to run concurrently — effectively life without parole.
DEFENSIVE LEVEL ONLY · THE SHAPE OF THE SCHEME, NOT A PLAYBOOK
KNOWN NETWORK & CONNECTED CASES

WHAT THIS CASE ESTABLISHED

Silk Road proved that a commercial platform could operate outside the jurisdiction of any nation-state by combining Tor for anonymity with Bitcoin for payment. It worked. Every darknet marketplace that followed is a copy of that architecture.
The “continuing criminal enterprise” (kingpin) statute was applied to a marketplace operator — not a drug trafficker. Building and operating the infrastructure for illegal commerce is itself the crime, separate from any individual transaction.
The most severe sentence in this series — two life terms plus forty years — applied to a first-time offender with no prior record. The sentence addressed the infrastructure, not the violence.
The only executive pardon in this series. The separation between judicial and executive power extends to sentences the judicial system upheld at every level.
The technology Ulbricht combined — Tor + Bitcoin + escrow — became the standard architecture for every subsequent darknet marketplace. The model survived his arrest, conviction, sentence, and pardon. It is operational today.
Series thesis, Case 013: The Pardoned. He built a market nobody could find, named himself after a fictional pirate, was sentenced to die in prison — and a signature undid it. The only case in this series whose ending changed.
BACKGROUND & BIOGRAPHY

EARLY LIFE & IDEOLOGY

FULL NAME
Ross William Ulbricht
BORN
27 March 1984 · Austin, Texas
EDUCATION
University of Texas at Dallas · physics BS · Penn State · materials science (did not complete masters)
IDEOLOGY
Libertarian · Austrian economics · free-market philosophy · believed in individual sovereignty
SILK ROAD VISION
Created as an experiment in free-market economics — a space without government interference, operating on consent
ONLINE ALIAS
Dread Pirate Roberts (DPR) — named after the Princess Bride character
PERSONA SEPARATION
Ulbricht maintained strict separation between Ross Ulbricht and Dread Pirate Roberts — until mistakes began
THE CONTRADICTION
A libertarian philosophy project became a marketplace processing millions in drug sales and, allegedly, murder-for-hire

SILK ROAD — THE MARKETPLACE

LAUNCHED
February 2011 · accessible only via Tor browser
PAYMENT
Bitcoin only — pseudonymous, censorship-resistant
PRODUCTS
Primarily illegal drugs — cannabis, MDMA, heroin, cocaine · also fake documents, counterfeit money
VOLUME
~$1.2 billion in sales · ~$79.8 million in commissions before seizure [DOJ / FBI]
VENDORS
~3,900 active vendors at peak · customer reviews · escrow system · sophisticated trust infrastructure
INNOVATION
First large-scale crypto marketplace · pioneered the Bitcoin-Tor dark web model that all successors copied
SHUTDOWN
October 2, 2013 · FBI seized servers · Ulbricht arrested San Francisco Public Library
HOW FBI FOUND HIM
Investigative chain: forum posts, a CAPTCHA misconfiguration that revealed real server IP, and a LinkedIn-connected Gmail account
THE ARREST, TRIAL & AFTERMATH

TRIAL & SENTENCING

ARRESTED
October 2, 2013 · Glen Park Branch, San Francisco Public Library
METHOD OF ARREST
FBI agent grabbed laptop mid-session before Ulbricht could encrypt/close it — evidence secured
JURISDICTION
US District Court · SDNY · Judge Katherine Forrest
CHARGES
Drug trafficking · continuing criminal enterprise · money laundering · computer hacking · attempted murder-for-hire
VERDICT
Guilty on all counts · February 4, 2015
SENTENCE
May 29, 2015 · LIFE + 40 years · no possibility of parole
JUDGE'S WORDS
"Silk Road was a drug superstore" · noted that 6 deaths were linked to purchases on the site
MURDER-FOR-HIRE
Paid ~$650,000 in Bitcoin for murder contracts against employees / threats — no evidence killings occurred [FBI]

THE PARDON — 2025

PARDON DATE
January 21, 2025 — first day of Trump's second term
TYPE
Full and unconditional presidential pardon
ADVOCATE
Libertarian community · Free Ross movement · Elon Musk publicly supported pardon
TRUMP STATEMENT
Commuted sentence of Ross Ulbricht
FREE ROSS CAMPAIGN
Over a decade of advocacy · million+ signatures · Ulbricht's mother central figure
REACTION
Ulbricht released · reunited with family · spoke publicly for first time in 11+ years
CONTEXT
Trump also pardoned (Binance) and BitMEX founders in crypto-friendly administration
CONVICTION STATUS
Conviction stands — pardon removes punishment, not the guilty verdict

WHAT SILK ROAD ESTABLISHED

Silk Road was the first proof that Bitcoin could serve as the payment layer for a functioning economy outside state control. Everything that followed — AlphaBay, Hansa, Dream Market, Hydra — is Silk Road's descendant.
The FBI's technical investigation into Silk Road was among the first major examples of blockchain analysis applied to criminal investigation. The techniques used to trace Bitcoin transactions to Ulbricht became standard investigative methodology.
The site processed $1.2 billion in transactions, primarily in drug sales, using a review and escrow system more sophisticated than most legitimate e-commerce platforms of 2011. Vendors were rated. Disputes were mediated. Trust was built through reputation.
The murder-for-hire charges: Ulbricht paid in Bitcoin for contracts on people he believed threatened him. The FBI established that the 'hitmen' were scammers who took his Bitcoin and fabricated proof of completion. No murders occurred — but the attempt established intent in the court record.
Trump's pardon on his first day in office was simultaneously symbolic (the libertarian community's long-awaited win) and political (crypto industry support for Trump's 2024 campaign was substantial). The pardon removed his sentence but not his conviction.
THE FULL STORY — 10 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PARDONED (3,100 WORDS)
Sources: US v. Ross William Ulbricht — S.D.N.Y. (conviction 2015); Second Circuit appeal (2017); US Supreme Court cert denial (2018); Executive pardon (21 January 2025); NYT; Washington Post; Ars Technica; USA Today. Every figure traces to a named source. There is no headline dollar figure in this case — Silk Road was a marketplace, not a direct theft. Any volume figure is an estimate of marketplace turnover, not money Ulbricht personally took. This involves a living person who has been pardoned and released.
· PROLOGUE ·
Two Life Sentences and a Signature

Two life sentences plus forty years, to run concurrently. No possibility of parole.

That was the sentence handed down in 2015 by a federal judge in the Southern District of New York. It was the harshest sentence in this entire series — harsher than Madoff's 150 years, which at least contained a number that could be spoken as something other than forever. Two life sentences is not a number. It is a period at the end of a life.

He appealed to the Second Circuit in 2017. He lost. [SOURCE: Second Circuit decision, 2017]

He appealed to the Supreme Court in 2018. They declined to hear the case. [SOURCE: Supreme Court cert denial, 2018]

The legal system had spoken three times. Trial. Appeal. Final appeal. The answer was the same each time: you will die in federal prison.

On January 21, 2025, President Trump signed a full and unconditional pardon. [SOURCE: Executive pardon, 21 January 2025]

Ross Ulbricht walked out.

He is the only person in this series whose ending changed.

· PART ONE ·
Eagle Scout — Austin, Texas

He was born on March 27, 1984, in Austin, Texas. [SOURCE: Court record]

The family was comfortable, educated, the kind of household that produced children who went to good universities and joined organisations that valued self-reliance and service. Ross Ulbricht became an Eagle Scout — the highest rank in the Boy Scouts of America, earned by fewer than four percent of scouts who enter the program. It requires years of sustained commitment, community service projects, and the specific discipline of completing a long series of requirements that most teenagers abandon.

He completed it. He was, by every metric his community offered, the kind of young man the system was designed to produce.

He went to the University of Texas at Dallas. Bachelor of Science. Then Penn State — a master's degree, graduated 2009. [SOURCE: Court record / reporting] Two degrees, two institutions, the credentials of a person building something conventional.

He returned to Austin after graduation. He was twenty-five years old, educated, credentialed, and looking for something to build.

He tried day trading. It did not work.

He started a video game company. It did not work either. [SOURCE: Reporting]

Two failures. Two attempts at the entrepreneurial path that Austin, with its tech scene and its startup culture, seemed to promise to anyone with the right education and the right ambition. He had both. The ventures failed anyway. The market was not interested in what he was selling through legitimate channels.

The detail matters because it is the same arc that appears in and . Holmes tried a legitimate medical device before Theranos became a fraud. Stanford ran real businesses before the Ponzi consumed everything. The legitimate attempt comes first. The failure of the legitimate attempt is not the cause of the crime — but it is always in the room.

· PART TWO ·
The Idea — A Market Nobody Could Find

What Silk Road was, stated plainly: an online marketplace, accessible only through the Tor network, where buyers and sellers could transact using Bitcoin, without revealing their identities to each other, to the platform, or to law enforcement.

What it sold, also stated plainly: primarily illegal drugs. Also fraudulent identity documents. Also other goods and services that could not be sold through conventional channels.

What made it different from every illegal marketplace that had existed before it: it worked. [SOURCE: DOJ / court record]

The Tor network — originally developed by the US Naval Research Laboratory — routes internet traffic through layers of encryption and relay nodes, making it extremely difficult to determine who is communicating with whom or where a particular service is hosted. A Tor hidden service has no physical address, no IP address visible to the public internet, no location that can be raided without first being discovered through other means.

Bitcoin — which in 2011 was still a niche technology understood by a small number of people — provided the payment layer. No bank accounts. No wire transfers. No payment processor that could be subpoenaed. Buyer sends Bitcoin to escrow. Seller ships product. Buyer confirms receipt. Escrow releases payment. The entire transaction occurs between pseudonymous parties through encrypted channels.

Ulbricht built both layers into a functioning marketplace. He did not invent Tor. He did not invent Bitcoin. What he invented was the combination — the realisation that these two technologies, designed for privacy and decentralisation, could be assembled into a commercial platform that operated beyond the reach of the systems that regulated every other marketplace on earth.

He ran it under the name Dread Pirate Roberts — taken from *The Princess Bride*, the 1987 film in which the name is passed from one pirate to another, so that the identity persists even as the person behind it changes. The name was a statement of intent: the market is not the man. The man can be replaced. The market endures.

He also used, at various points, the handles Frosty and Altoid. [SOURCE: Court record / FBI investigation]

· PART THREE ·
2011 to 2013 — Two and a Half Years

Silk Road launched in 2011. [SOURCE: Court record]

It operated for approximately two and a half years. In the context of this series, that is a short run. Madoff operated for decades. Stanford ran his Ponzi for years. built his Instagram over nine years. Silk Road existed for roughly the same amount of time it takes to complete an associate's degree.

In those two and a half years, it changed the world.

Not because of the drugs sold through it — illegal drug markets existed long before the internet and will exist long after. But because it proved a concept that had been theoretical: a marketplace could function with no physical infrastructure, no banking relationship, no identity verification, and no geographic jurisdiction. A market could exist in the space between encrypted networks, accessible to anyone who knew how to find it, invisible to anyone who did not.

Every darknet market that followed — and there have been dozens, some lasting months, some lasting years, each one taken down and replaced by another — is a copy of the architecture Ulbricht built. He did not steal money. He built infrastructure. The infrastructure outlived him, outlived Silk Road, and continues to operate in evolved forms across the Tor network today.

That is what the sentence was for. Not for the drugs — any drug dealer can be sentenced for drugs. For building the machine that made the drugs untraceable, the sellers anonymous, and the buyers invisible. For proving it could be done.

· PART FOUR ·
The Arrest — October 2013

The FBI arrested Ross Ulbricht in October 2013. Silk Road was taken offline simultaneously. [SOURCE: FBI / DOJ]

The investigation that led to the arrest was a multi-agency operation that had been building for months. The specific details of how agents identified Ulbricht and connected him to the Dread Pirate Roberts pseudonym involve operational security failures — moments where the wall between his real identity and his pseudonymous one became thin enough for investigators to see through.

He was arrested in a public library in San Francisco. The agents needed him to be logged in — to have his laptop open and the Silk Road administrative interface active on screen — so that the evidence of his control over the platform would be captured in real time, not reconstructed from forensic analysis of an encrypted device after the fact.

They got what they needed. He was logged in. The laptop was open. The Dread Pirate Roberts was sitting in a library, running a market, when the FBI introduced themselves.

· PART FIVE ·
The Trial — Five Counts

The trial took place in the Southern District of New York. He was convicted in 2015 on five counts. [SOURCE: SDNY / court record]

The counts, stated precisely:

One. Engaging in a continuing criminal enterprise. This is the most serious charge — the federal "kingpin" statute, reserved for leaders of large-scale criminal operations. It carries a mandatory minimum of twenty years and a maximum of life.

Two. Distributing narcotics by means of the internet.

Three. Conspiracy to commit money laundering.

Four. Conspiracy to traffic fraudulent identity documents.

Five. Conspiracy to commit computer hacking.

Five counts. One trial. One verdict: guilty on all counts.

The sentence: two life terms plus forty years, to run concurrently. No parole. [SOURCE: SDNY sentencing]

The judge, at sentencing, spoke to the scale of what Silk Road had enabled. Not the individual transactions — each one a drug sale, each one a crime, but none of them individually the kind of crime that produces a life sentence. The scale. The infrastructure. The marketplace itself as the criminal act. The judge sentenced the architect, not the dealers.

· PART SIX ·
The Evidence That Was Not Charged

This section must be handled with precision, because it is the most misunderstood element of the case.

Evidence was presented at Ulbricht's sentencing hearing indicating that he had commissioned murder-for-hire deals targeting at least five individuals. [SOURCE: Sentencing hearing / court record]

This evidence was considered by the judge as part of the sentencing determination. It influenced the severity of the sentence.

He was not charged with murder-for-hire. It was not a count at trial. It is not a conviction.

The distinction is not technical — it is fundamental. Evidence considered at sentencing is not the same as a crime proven at trial. Sentencing courts may consider a broader range of conduct than trial courts, including conduct that has not been independently charged or tried. The standard of proof is different. The procedural protections are different.

To state it as a conviction would be inaccurate. To omit it entirely would be incomplete — it shaped the sentence, and the sentence is a central fact of the case. The correct framing is the one just given: evidence presented at sentencing, considered by the judge, never charged as a separate crime.

That framing holds for any discussion of this case. It is the framing the record supports.

· PART SEVEN ·
The Appeals — Two Courts, One Answer

In 2017, Ulbricht appealed to the United States Court of Appeals for the Second Circuit. The appeal raised multiple issues, including the severity of the sentence and the conduct of the investigation. The Second Circuit upheld the conviction and sentence. [SOURCE: Second Circuit, 2017]

In 2018, his attorneys petitioned the Supreme Court of the United States for a writ of certiorari — a request for the Court to hear the case. The Supreme Court declined. [SOURCE: Supreme Court, 2018]

The legal system had now spoken at every level available to it. Trial court. Appellate court. The highest court in the country. Each time, the answer was the same.

Ross Ulbricht was going to die in federal prison. That was not speculation or editorialising — it was the mathematical consequence of two life sentences with no possibility of parole, upheld through every avenue of appeal the American legal system provides.

A movement formed. The Free Ross campaign argued that the sentence was disproportionate — that two life terms for a non-violent first offence, by a man with no prior criminal record and an Eagle Scout badge, exceeded what the crime warranted. Libertarian and cryptocurrency communities adopted him as a cause. Petitions circulated. His mother became a public advocate. The campaign ran for years, through multiple administrations, building a constituency that believed the sentence was unjust regardless of the crime.

The movement did not change the legal outcome. The courts had ruled. The sentence stood.

What changed it was something the courts could not provide.

· PART EIGHT ·
January 21, 2025 — The Signature

On January 21, 2025 — his first full day in office — President Trump signed a full and unconditional pardon for Ross William Ulbricht. [SOURCE: Executive pardon, 21 January 2025]

A pardon is not an acquittal. It does not reverse the conviction. It does not say the courts were wrong. It does not address the evidence, the trial, or the legal reasoning that produced the sentence. It is an act of executive clemency — the president's constitutional authority to release a person from the consequences of a federal conviction, for any reason or no stated reason at all.

Ulbricht was released. He had served approximately ten years of a sentence that was designed to last the rest of his life.

He walked out of federal custody and into a country where the technology he had pioneered — anonymous marketplaces, cryptocurrency payments, encrypted communication — had become orders of magnitude larger, more sophisticated, and more consequential than anything Silk Road had been.

The market he built in 2011 with Tor and Bitcoin was a prototype. By the time he walked out in 2025, the darknet marketplace ecosystem had evolved through dozens of successors — each one learning from the last, each one refining the model, each one demonstrating that the concept Ulbricht proved could not be un-proved by taking down its creator.

· PART NINE ·
The Name — Dread Pirate Roberts

The name deserves its own section because it was not arbitrary.

In *The Princess Bride*, the Dread Pirate Roberts is not a person. It is a title. The original Roberts retired years ago, passing the name and the ship to his first mate, who passed it to the next, who passed it to the next. The reputation — the fear, the legend, the brand — persists because it was never attached to a single human being. The pirate is immortal because the pirate is an idea.

Ulbricht chose this name for Silk Road's administrator. The choice was a declaration: this market is not me. If I am taken, the market continues. The name passes to the next. The pirate endures.

He was half right. He was taken. The market did not endure — Silk Road specifically was seized and shut down. But the model endured. The idea endured. Every darknet marketplace that launched after Silk Road's closure was the next person picking up the name and the ship.

The Dread Pirate Roberts was arrested in a library. The pirate's descendants are still operating.

· PART TEN ·
What This Case Established

Silk Road was the first modern darknet marketplace to achieve scale, demonstrating that a commercial platform could operate outside the jurisdiction of any nation-state by combining the Tor network with cryptocurrency payments. [SOURCE: DOJ / court record]

The "continuing criminal enterprise" charge — the kingpin statute — was applied to a marketplace operator, not a drug trafficker. The legal precedent established that building and operating the infrastructure for illegal commerce is itself the crime, separate from any individual transaction conducted on the platform.

The sentence — two life terms plus forty years — was the most severe in this series, applied to a first-time offender with no prior criminal record. It reflected a judicial determination that the scale of the infrastructure, not the violence of the conduct, warranted the maximum penalty.

The pardon — signed January 21, 2025 — is the only instance in this series of an executive action reversing a final federal sentence. It demonstrated that the separation between the judicial and executive branches extends to the most severe sentences the system produces.

The technology Ulbricht combined — Tor for anonymity, Bitcoin for payment, escrow for trust between anonymous parties — became the standard architecture for every darknet marketplace that followed. The model survived his arrest, his conviction, his sentence, and his pardon. It is operational today.

· EPILOGUE ·
The Prototype

Every case in this series ends with a sentence that holds. Madoff died in prison. is serving twenty-five years. is serving eleven. Gonzalez served thirteen of twenty. Stanford is serving a hundred and ten. Greenwood is serving twenty. Holmes reported to prison. Ignatova may be dead.

Ross Ulbricht was sentenced to die in federal prison. He appealed twice and lost twice. The legal system closed every door it had.

A president opened a different one.

He is forty-two years old. He is free. He built a marketplace that operated for two and a half years, was convicted on five federal counts, served ten years of a life sentence, and walked out of a federal facility on the strength of a signature.

The market he built is gone. The model he proved is everywhere.

He was an Eagle Scout from Austin, Texas, who earned a master's degree, failed at day trading, failed at a video game company, built the most consequential illegal marketplace in the history of the internet, named himself after a fictional pirate whose identity could never be captured because it was never a person — and then discovered that the identity could be captured, and the person sentenced, and the sentence reversed by a power the courts could not override.

He built a market nobody could find, ran it as a pirate, and was sentenced to die in prison — until a signature undid it.

· VERIFIED SOURCES ·

All figures labelled by what they measure. There is no headline dollar figure in this case — Silk Road was a marketplace, not a direct theft. Murder-for-hire evidence was considered at sentencing but never charged. This involves a living person who has been pardoned and released.

[1] US v. ROSS WILLIAM ULBRICHT — S.D.N.Y. Conviction 2015. Five counts: continuing criminal enterprise, narcotics distribution via internet, money laundering conspiracy, fraudulent identity documents conspiracy, computer hacking conspiracy.
[2] SECOND CIRCUIT — Appeal upheld conviction and sentence, 2017.
[3] US SUPREME COURT — Certiorari denied, 2018.
[4] EXECUTIVE PARDON — Signed by President Trump, 21 January 2025. Full and unconditional.
[5] NEW YORK TIMES — Arrest, trial, and sentencing coverage.
[6] WASHINGTON POST — Pardon coverage, January 2025.
[7] ARS TECHNICA — Technical and legal analysis of Silk Road operation and prosecution.
[8] USA TODAY — Sentencing and appeal coverage.
*TraceChain Forensics · Fraud Exposed Series · Case 013*
*Every claim sourced. Estimates labelled. Murder-for-hire = evidence at sentencing, never charged.*

*The only case in the series whose ending changed.*

*What would prove it wrong?*

END OF REPORT
#23 OF 45
Elizabeth Holmes
SINGLE PERSON
CASE 007 · MEDTECH FRAUDCONVICTED
Theranos · Edison device · 11 yrs 3 mo · serving Bryan TX
$945M
WHAT WAS TAKEN
Investors' money put into Theranos, lost when it collapsed. A court ordered $452M paid back.
HOW
Told investors Theranos blood tests worked when they didn't.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2003Founds Theranos at 19 after dropping out of Stanford.SOURCE: N.D. Cal. record
2013–2015Raises hundreds of millions on claims the Edison device could run full blood panels from a finger-prick; the claims were false.SOURCE: jury verdict, 3 Jan 2022
2015–2018WSJ exposé, regulators move, Theranos dissolved in 2018; indicted the same year.SOURCE: WSJ; DOJ
2013–2016Theranos testing centres inside Walgreens stores in Arizona give real patients results from the unreliable devices.SOURCE: trial record; Arizona AG settlement
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: Max Morse for TechCrunch · CC BY 2.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
ELIZABETH ANNE HOLMES
THERANOS FOUNDER · MEDTECH FRAUD · CASE 007 · CONVICTED JAN 2022 · SERVING 11 YEARS
COMPANY VALUATION (PEAK)
$9B [PAPER VALUE]
RESTITUTION ORDERED
$452M (Judge Davila)
TOTAL INVESTOR EXPOSURE
~$945M [DOJ case estimate]
SENTENCE
135 months (11 yrs 3 mo)
CONVICTED
4 counts · investors only
ACQUITTED
Patient counts — jury split
BORN
February 3, 1984 · Washington D.C.
SERVING AT
FPC Bryan, Texas
THREE FIGURES — THREE MEANINGS: $9B = company valuation (paper, not money stolen) · $452M = restitution ordered by judge · ~$945M = total investor exposure per government case. These are not the same number. Holmes convicted on investor counts only — acquitted on patient counts. Balwani, tried separately, convicted on all 12 counts including patients.
FULL PROFILE

IDENTITY

LEGAL NAME
Elizabeth Anne Holmes
BORN
February 3, 1984 · Washington D.C.
EDUCATION
Stanford University (2002) — dropped out at 19 to found Theranos
FIRM
Theranos Inc. · founded 2003 · Palo Alto CA
PRODUCT
Edison device — claimed: hundreds of blood tests from one finger-prick drop
PEAK VALUATION
~$9B (2014) · Holmes net worth listed ~$4.5B (Forbes, 2015)
PERSONA
Black turtleneck · baritone voice · "the next Steve Jobs"
STATUS
Serving sentence · FPC Bryan, Texas · enrolled May 2023

CASE RECORD

CASE
US v. Holmes, 5:18-cr-00258-EJD-1 · N.D. California (San Jose)
INDICTED
2018 (with Balwani)
WSJ EXPOSÉ
October 2015 · John Carreyrou · Wall Street Journal
TRIAL
August – December 2021 · San Jose · 4 months
JUDGE
Hon. Edward J. Davila · N.D. California
VERDICT
January 3, 2022 · 4 counts guilty (investors) · acquitted on patient counts
COUNTS
3x wire fraud against investors · 1x conspiracy to defraud investors
SENTENCED
November 18, 2022 · 135 months
RESTITUTION
$452M ordered (Judge Davila)
APPEAL
9th Circuit affirmed Feb 24, 2025 · en banc denied May 8, 2025
NINTH CIRCUIT
No. 22-10312 · Judge Jacqueline Nguyen writing for unanimous panel
CO-DEFENDANT
PRESIDENT & COO · CO-FOUNDER · TRIED SEPARATELYCONVICTED — 12 COUNTS
Ramesh “Sunny” Balwani
Theranos President & COO · Holmes’s former partner
Tried separately from Holmes — cases severed procedurally. Convicted July 2022 on all 12 counts, including patient-related fraud counts that Holmes was acquitted on. His jury reached a different conclusion about patient harm than Holmes’s jury. Sentenced December 2022 to 13 years. Joined Theranos in 2009 and managed laboratory operations and customer-facing testing business. Romantic relationship with Holmes during the fraud period.
SOURCE: DOJ · Fox4/KTVU · case record N.D. Cal.
JOURNALIST · EXPOSÉ AUTHORVINDICATED
John Carreyrou
Wall Street Journal · Bad Blood (2018)
Published the October 2015 WSJ exposé that broke the Theranos story: “Hot Startup Theranos Has Struggled With Its Blood-Test Technology.” Based on interviews with former employees who described the gap between the public claims and internal reality. Theranos fought the story aggressively — cease-and-desist letters, press conferences, Holmes called it factually inaccurate. The story was accurate. Without Carreyrou’s reporting, the fraud might have run to natural collapse. His 2018 book Bad Blood became the definitive account. Journalism is in the causal chain of this prosecution.
SOURCE: WSJ · Bad Blood (2018) · DOJ indictment timeline
HOW THE FRAUD WORKED

THE MECHANISM — THE STORY AS PRODUCT

01
The claim: The Edison device could run hundreds of medical tests from a single finger-prick drop of blood — faster, cheaper, and more accurately than conventional labs requiring a full venipuncture draw. The technology was ready. The results were trustworthy. [SOURCE: trial record / DOJ]
02
The reality: The Edison could not reliably perform the full claimed menu of tests. Many tests were run on conventional third-party laboratory machines (Siemens and others) — the kind Theranos had publicly disparaged as inferior to its own technology. Lab director Dr. Kenneth Das ultimately voided all results run on Edison machines. [SOURCE: Ninth Circuit opinion Feb 2025; trial record]
03
The investor presentations: Investors were shown financial projections and technology demonstrations that did not reflect operational reality. The company was presented as having a working, proven product when, by trial evidence, it was neither. Revenue projections shown to the DeVos family showed $990M profit in 2015. [SOURCE: trial testimony / BiSpace]
04
The frame that made it work: Henry Kissinger. George Shultz. James Mattis. William Perry. A board of former Secretaries of State and Defense whose presence implied serious people had examined the technology. The persona of the visionary founder (black turtleneck, deliberate baritone, Stanford pedigree even in dropout form). Magazine covers. The Jobs comparison. None of these were the product. All of them were the argument that the product didn’t need to be proven because the frame already said it was. [SOURCE: trial record; widely documented]
THE JURY SPLIT — THE MORAL PUZZLE

WHAT TWO JURIES DECIDED

HOLMES jury
GUILTY on 3 counts wire fraud (investors) + 1 count conspiracy to defraud investors · ACQUITTED on all patient-related counts · Deadlocked on 3 counts
BALWANI jury
GUILTY on all 12 counts — including the patient-related fraud counts Holmes was acquitted on · Different jury, same facts, different conclusion on patient harm

The split is the case’s moral puzzle. The jury decided she defrauded the people who gave her money. It could not say, beyond a reasonable doubt, that she defrauded the people who got blood tests. Balwani’s jury reached the opposite conclusion on that question. The patients who received inaccurate tests from a technology that did not work as described — whether they suffered a wrong is a question neither verdict resolves. It sits in the gap between them. [SOURCE: trial records · NBC News verdict coverage]

THE INVESTORS — WHO BELIEVED, WHAT THEY LOST

KNOWN INVESTOR FIGURES — FROM UNSEALED COURT DOCUMENTS

Walton family (Walmart heirs)
$150M · SOURCE: WSJ / unsealed court documents
Rupert Murdoch
$125M invested (net loss ~$121M after $4M settlement) · SOURCE: court filings / Fierce Biotech
DeVos family
$100M · SOURCE: unsealed court documents / WSJ
Cox family
$100M · SOURCE: unsealed court documents
Partner Fund Management
$96M · SOURCE: Fortune (2018)
Total restitution ordered
$452M · SOURCE: Judge Davila restitution order (May 2023)
Total alleged investor exposure
~$945M (DOJ case estimate) · $550M (US Probation Office figure) · figures vary by accounting method [UNVERIFIED against single primary]
THE NINTH CIRCUIT — FEBRUARY 24 2025

CONVICTION AFFIRMED — APPEAL DENIED

“The promise of Theranos’s technology was a mirage.” — Ninth Circuit, No. 22-10312, February 24, 2025 [SOURCE: Bay City News / Fox4 citing panel opinion]
“Half-truths and outright lies.” — describing Holmes’s statements and Balwani’s [SOURCE: Ninth Circuit opinion, February 2025]

54-page opinion by Judge Jacqueline Nguyen for the unanimous three-judge panel. Two appeal grounds received most attention: improper fact-witness testimony by Dr. Kenneth Das (Theranos’s final lab director); and improper admission of a government regulatory report. Both were found harmless given the weight of other evidence. En banc rehearing denied May 8, 2025 — no judge requested a vote. Certiorari to the Supreme Court is the only remaining option (granted in fewer than 1% of criminal cases). [SOURCE: Bloomberg Law · Courthouse News · Fox4/KTVU]

CASE TIMELINE
3 Feb 1984
Born, Washington D.C.
SOURCE: case brief (sources listed in its SOURCES part)
2003
Founds Theranos, aged 19
drops out of Stanford
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Balwani joins as President/COO
they become partners
SOURCE: case brief (sources listed in its SOURCES part)
2013–2014
Theranos launches publicly
Holmes on magazine covers — "the next Steve Jobs"
SOURCE: case brief (sources listed in its SOURCES part)
2015
John Carreyrou, Wall Street Journal, publishes the first major exposé
SOURCE: case brief (sources listed in its SOURCES part)
2016
Regulators move
Theranos' lab operations cited
SOURCE: case brief (sources listed in its SOURCES part)
2018
Holmes and Balwani indicted
5:18-cr-00258-EJD
SOURCE: case brief (sources listed in its SOURCES part)
2018
Theranos dissolved
SOURCE: case brief (sources listed in its SOURCES part)
2021
Holmes' trial (severed from Balwani's)
SOURCE: case brief (sources listed in its SOURCES part)
3 Jan 2022
Convicted
4 counts (investor fraud); acquitted on patient counts
SOURCE: case brief (sources listed in its SOURCES part)
July 2022
Balwani convicted on all 12 counts
SOURCE: case brief (sources listed in its SOURCES part)
18 Nov 2022
Holmes sentenced
135 months
SOURCE: case brief (sources listed in its SOURCES part)
Dec 2022
Balwani sentenced
~13 years
SOURCE: case brief (sources listed in its SOURCES part)
May 2023
Holmes reports to prison
SOURCE: case brief (sources listed in its SOURCES part)
24 Feb 2025
Ninth Circuit opinion (appeals)
SOURCE: case brief (sources listed in its SOURCES part)

WHAT THIS CASE ESTABLISHED

She built a company on a story. The story was the product. The technology didn’t need to be proven if everything about the frame said it already was — board of statesmen, Stanford pedigree, Jobs comparison, magazine covers.
Silicon Valley’s founder-worship culture created the vulnerability. Doubting the technology felt like being the person who doubted the first Mac. Due diligence was reframed as a failure of imagination.
The exposé came not from regulators or board members but from a journalist who talked to people who were there. Carreyrou did what the board of Kissinger and Shultz had not done: he asked inside the building.
The jury split is the moral puzzle: convicted on investor fraud, acquitted on patient counts. Balwani’s jury reached the opposite conclusion on patients. The harm to people who received inaccurate blood tests is unresolved in the verdicts.
Series thesis, Case 007: the story was the product. In every preceding case something real was hidden — a stolen fund, a collapsed algorithm, a Ponzi, a hacked wallet. In this one, the story itself was what investors paid for.
THE FULL STORY — 10 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE MIRAGE (3,500 WORDS)
Sources: US v. Holmes, 5:18-cr-00258-EJD-1, N.D. Cal. San Jose · US v. Balwani, same case · Ninth Circuit No. 22-10312 (February 24, 2025 — affirmed; en banc rehearing denied May 8, 2025) · DOJ/US Attorney N.D. Cal. · Reuters · CNN Business · Fox4/KTVU · Bloomberg Law · Courthouse News · Bay City News. $9B = company valuation — paper value, not money stolen. Investor money figure labelled separately. Holmes: convicted 4 counts (investor fraud only — acquitted on patient counts). Balwani: convicted 12 counts including patient counts.
· PROLOGUE ·
The Mirage

The promise of Theranos was this: one drop of blood from a finger prick, placed on a small proprietary device called the Edison, could run hundreds of medical tests. Quickly, cheaply, accurately. Without a needle, without a lab, without the friction of traditional diagnostics.

The promise was beautiful in the way that the best Silicon Valley pitches are beautiful — it identified a real problem (blood draws are unpleasant and expensive), proposed an elegant solution (a device that did more with less), and positioned the person making it as the visionary who had seen what others had missed.

The promise was also, a federal jury in San Jose decided in January 2022, a fraud.

The Ninth Circuit Court of Appeals, affirming the conviction in February 2025, called the promise of Theranos's technology a 'mirage.' It described Elizabeth Holmes's statements and those of her partner Ramesh Balwani as 'half-truths and outright lies.' [SOURCE: Bay City News / Fox4, citing Ninth Circuit opinion, February 24, 2025]

She built a company on a story. The story was the product. And when the story was told to investors who wrote checks, she was convicted. When it was told to patients who got blood tests, the jury acquitted. That distinction — the jury's split — is the moral puzzle at the centre of Case 007, and it belongs at the beginning.

· PART ONE ·
Washington D.C., 1984 — The Making of a Founder

Elizabeth Anne Holmes was born on February 3, 1984, in Washington D.C.

Her family background was comfortable and connected — her father worked for government and later in business, her mother for Congress. She attended St. John's School in Houston, where by her own account she decided as a teenager that she would be a billionaire. [SOURCE: widely documented in press coverage] She told her father that she wanted to give him a birthday present he couldn't afford to buy himself, which he interpreted as affection and she may have meant literally.

She enrolled at Stanford University in 2002 to study chemical engineering. She was 18. By the following year, at 19, she had dropped out to found Theranos.

The Stanford credential — present even in its absence, perhaps especially in its absence — would carry forward in the Theranos story. She had been accepted to Stanford. She had studied there. She had left because she had something better to do. In Silicon Valley, dropping out to start a company is not failure. It is the specific sequence of actions that produced Gates, Dell, Zuckerberg. It is a credential of its own.

She was 19 years old when she founded Theranos. She was 37 when she was convicted.

· PART TWO ·
The Persona — Black Turtleneck, Baritone Voice, the Next Jobs

The black turtleneck was Steve Jobs's. It was his uniform — the same garment, worn every day, a statement that the mind had better things to occupy itself with than deciding what to wear. Elizabeth Holmes adopted it.

She also adopted — or developed, or cultivated — a voice. Her natural speaking voice, by those who knew her before Theranos became famous, was described as higher and more ordinary. The voice that appeared on magazine covers and TED stages and in board meetings with Henry Kissinger and George Shultz was deep, deliberate, and authoritative. Whether this was a performance or had become simply how she spoke is something that only she knows.

The Jobs comparison was not incidental. Magazines applied it. Interviewers applied it. The comparison served a function: it placed her in a lineage, attached her story to a known narrative of visionary founders who saw differently from everyone else and were proven right. If she was the next Jobs, then the people who doubted the technology were the equivalent of the people who doubted the first Mac. Doubt became a risk of being wrong rather than a form of due diligence.

She appeared on the cover of Fortune in 2014 under the headline 'This CEO Is Out For Blood.' She appeared in Forbes, Time, Inc. By 2015, at 31, she was on the Forbes 400 with an estimated net worth of $4.5 billion — all of it on paper, all of it contingent on the company's valuation being real. She was, the magazine said, the youngest self-made female billionaire in history.

The board of Theranos included Henry Kissinger, George Shultz, James Mattis, and William Perry. Not scientists. Not medical diagnostics professionals. Statesmen, generals, men of institutional authority whose presence on a board implied that the enterprise had been examined and found worthy. The board was, in its composition, a form of the argument: serious people are involved, serious people have looked at this.

The persona and the board were parts of the same machine. The story was being told in every dimension simultaneously — the appearance, the voice, the lineage, the backers, the magazine profiles. The technology didn't need to be proven if everything else about the frame said it already was.

· PART THREE ·
Sunny Balwani — The Partner, the President, the Co-Defendant

Ramesh Balwani, known as Sunny, was President and Chief Operating Officer of Theranos. He and Elizabeth Holmes were in a romantic relationship for years during the period the fraud occurred.

Balwani was 19 years older than Holmes. He had made money in software during the dot-com era and joined Theranos in 2009. At the company, he managed the laboratory operations and the customer-facing testing business — the part of the operation where patients actually received blood tests and results.

The court severed their cases — a procedural decision that meant they were tried separately, before different juries, at different times. [SOURCE: case record, 5:18-cr-00258-EJD] The consequence of severance was significant: their accounts could not be cross-examined against each other in the same proceeding. What Holmes said about Balwani's role, and what Balwani said about Holmes's, were not tested against each other in real time.

Holmes was tried first. She was convicted in January 2022 on four counts: three counts of wire fraud against investors and one count of conspiracy with Balwani to defraud investors. She was acquitted on the counts relating to patients.

Balwani was tried separately and convicted in July 2022 on all twelve counts he faced — including the patient-related counts that Holmes had been acquitted on. [SOURCE: DOJ / N.D. Cal.] The jury that evaluated his conduct regarding patients reached a different conclusion than the jury that evaluated Holmes's. He was sentenced in December 2022 to 13 years in federal prison. [SOURCE: Fox4/KTVU confirming 13 years]

· PART FOUR ·
What Theranos Said and What Was Happening

The Edison was the name of the Theranos device — a proprietary blood-testing machine that was supposed to do what the company claimed: run a comprehensive menu of tests from a single drop of blood obtained by finger prick.

What the company told investors, per the court record: the Edison could perform this analysis accurately and reliably across hundreds of tests. The technology was working. The results were trustworthy. The product was ready.

What was actually happening, per the evidence at trial: the Edison could not reliably run the full claimed menu of tests. Many tests were being run on commercial third-party laboratory machines — the kind made by Siemens and other established manufacturers — rather than on the proprietary Edison device. [SOURCE: trial record / DOJ] Theranos had publicly disparaged such machines as inferior to its own technology. It was using them instead.

Some patient test results were inaccurate. The lab's final director, Dr. Kenneth Das, ultimately ordered all tests run on the Edison machines to be voided — a decision that was later cited in the appeals proceedings. [SOURCE: Courthouse News / Bay City News, citing Ninth Circuit opinion]

Investors were shown demonstrations and financial projections that did not reflect the operational reality. The technology was described as finished and proven when, by the evidence presented at trial, it was neither.

The core lie, stated plainly as the court record allows: the product that investors were paying for did not work the way they were told it worked. The promise was what they were buying. The promise was the mirage.

· PART FIVE ·
The Expose — John Carreyrou and the Wall Street Journal

In October 2015, John Carreyrou of the Wall Street Journal published a story.

The headline: 'Hot Startup Theranos Has Struggled With Its Blood-Test Technology.' The story was based on interviews with former Theranos employees — people who had left the company and were willing, with some protection, to describe what they had seen inside.

What they described: that the Edison device was not performing as Theranos claimed. That many tests were being run on conventional laboratory equipment. That the results had accuracy problems. That the reality inside the company was considerably different from the story being told outside it.

Theranos and Holmes fought the story aggressively. Her lawyers sent cease-and-desist letters. The company held a press conference. Holmes went on television and called the reporting 'factually inaccurate' and 'misleading.' She told journalists that the story had been written by someone who did not understand the technology.

The story was accurate. Carreyrou continued reporting. He eventually published the book Bad Blood: Secrets and Lies in a Silicon Valley Startup, which became the definitive account of what had happened inside the company. The book came out in 2018 — the same year Holmes and Balwani were indicted.

The WSJ exposé is the origin point of the legal proceedings. Without Carreyrou's reporting, the fraud might have continued until it collapsed on its own. With it, the regulatory scrutiny that followed led to the evidence that led to the indictments. Journalism is in the chain of causation for this case in a way it usually is not.

· PART SIX ·
The Investors — Who Believed and What They Lost

The Theranos investor list was not a list of naive people who had been tricked by a slick presentation. It was a list of some of the wealthiest and most connected individuals and families in the United States.

Rupert Murdoch invested approximately $125 million in Theranos — later writing it down to zero. [SOURCE: widely reported; verify exact figure against primary before publication] The DeVos family, the Walton family, the Cox family — among the investors who collectively put in what the government characterised as approximately $945 million. [SOURCE: DOJ — verify against primary before final publication]

These were not people who failed to do due diligence because they lacked access to experts. They were people who had been told, by a founder with a Stanford pedigree and a board of statesmen, a compelling story about a transformative technology — and who chose to believe it. Some of them may not have asked the questions that would have revealed the problem, in part because the frame Holmes had constructed made asking those questions feel like missing the point.

This is a pattern visible across the series. Madoff's victims were sophisticated investors who could have investigated the returns and chose not to, partly because the returns looked like exactly what a Madoff investment should look like. 's backers were institutional funds that did due diligence and concluded the effective altruism framing made the risk worth taking. Holmes's investors had a board of Kissinger and Shultz and Mattis telling them, implicitly, that serious people had looked at this.

The company was valued at approximately $9 billion at its peak. That valuation — the figure that made Holmes a billionaire on paper — is not the amount investors lost. The lost figure is the actual capital invested, approximately $945 million per the government's case. The gap between those two numbers is the gap between valuation and reality, and it is the same gap that appears in every case in this series.

· PART SEVEN ·
The Trial — The Jury Split

Holmes's trial ran for four months in San Jose, California, before Judge Edward J. Davila. It was one of the most closely watched corporate fraud trials in recent memory.

The prosecution presented evidence that the Edison device could not reliably run the tests Theranos claimed it could, that many results had been generated on conventional laboratory equipment rather than the proprietary machine, that investor presentations had contained projections and representations that did not match the company's actual capabilities.

Holmes testified in her own defense over eight days. She told the jury that she had genuinely believed in the technology. She said she had been the victim of Balwani's abuse — domestic abuse claims that her legal team presented as part of the defense, arguing that his control over her limited her awareness of what was actually happening inside the company. [SOURCE: widely documented; trial record]

The jury deliberated and returned its verdict on January 3, 2022.

On three counts of wire fraud against investors and one count of conspiracy to defraud investors: GUILTY.

On the counts related to patients: NOT GUILTY.

The split is the most important legal fact in the case and the most important moral fact. The jury decided that she had defrauded the people who gave her money. It decided it could not say, beyond a reasonable doubt, that she had defrauded the people who got blood tests. Whether that distinction reflects the evidence, the difficulty of proving patient harm in a case this complex, or something else — that is a question the verdict leaves open.

Balwani's jury, evaluating his conduct separately eight months later, came to a different conclusion about the patient counts and convicted him on all twelve charges.

· PART EIGHT ·
11 Years and 3 Months — The Sentence

On November 18, 2022, Judge Edward J. Davila sentenced Elizabeth Holmes to 135 months in federal prison — 11 years and 3 months.

The sentence was below what prosecutors had sought and above what her lawyers had argued for. Davila acknowledged the genuine belief Holmes may have had in the technology, but found that the evidence of fraud was sufficient to warrant a substantial sentence. [SOURCE: Reuters / CNN Business, November 18, 2022]

Holmes was ordered to surrender to prison in April 2023. Her lawyers sought to delay while the appeal was pending. The Ninth Circuit denied the stay in May 2023, finding she had not raised a 'substantial question' that her conviction would be overturned. [SOURCE: UPI, May 2023] Judge Davila ruled she must report by May 30, 2023.

She reported to the Federal Prison Camp in Bryan, Texas — a minimum security facility. In a People Magazine interview, she described prison as 'hell and torture.' [SOURCE: Fox4 citing People Magazine] She is currently serving her sentence there.

Balwani was sentenced in December 2022 to 13 years — a longer sentence than Holmes, reflecting his additional convictions on the patient-related counts. [SOURCE: Fox4/KTVU confirming 13 years]

· PART NINE ·
The Appeals — The Mirage Confirmed

On February 24, 2025, a three-judge panel of the Ninth Circuit Court of Appeals unanimously affirmed Holmes's conviction and sentence.

The 54-page opinion, written by Judge Jacqueline Nguyen, rejected every argument Holmes's lawyers had raised. Two grounds of appeal had received the most attention: that the trial judge had improperly allowed Theranos's final lab director, Dr. Kenneth Das, to testify as a fact witness on matters that required him to be qualified as an expert; and that a government regulatory report had been improperly admitted and may have misled the jury. [SOURCE: Fox4/KTVU; Courthouse News; Bloomberg Law]

The Ninth Circuit found that even if the trial judge had committed procedural errors in these rulings, those errors were harmless — the other evidence against Holmes was so substantial that no different result would have been likely. [SOURCE: Bloomberg Law citing opinion, February 2025]

The court's characterisation of the fraud was the most significant element of the opinion for the series record: the promise of Theranos's technology was a 'mirage,' and Holmes's statements were 'half-truths and outright lies.' [SOURCE: Bay City News / Fox4, citing Ninth Circuit panel opinion]

Holmes requested a rehearing in April 2025, arguing that the harmless error analysis was wrong and that the panel had made factual mistakes in its opinion. On May 8, 2025, the Ninth Circuit denied the rehearing — both the panel rehearing and the en banc hearing request — unanimously. No judge of the court requested a vote on whether to rehear the matter. [SOURCE: Bloomberg Law, May 8, 2025; Courthouse News, May 2025]

The only remaining legal option is a petition to the United States Supreme Court for certiorari. The court grants fewer than 1% of such petitions in criminal cases. Holmes's conviction is, for all practical purposes, final.

· PART TEN ·
What It Means — She Built a Company on a Story

The series thesis for Case 007 is this: she built a company on a story, and the story was the product.

The other cases in this series document specific kinds of deception. deceived about the source of his money. deceived about his right to the Bitcoin he had stolen. deceived about what an algorithm had done. Madoff deceived about whether investments had occurred. deceived about the separation between his exchange and his trading firm.

Holmes deceived about what a machine could do. But more specifically, more relevantly: she deceived about whether the story she was telling about the machine was true. The story — revolutionary technology, democratised diagnostics, the next Jobs building the next Apple — was so compelling, so coherent, so well-constructed and so well-delivered that it substituted for the evidence that would have tested it.

Silicon Valley has a specific vulnerability to this kind of fraud. The culture privileges the founder's vision over conventional verification. Due diligence can feel like you are the person who told Jobs that a graphical interface was unnecessary. The board of statesmen was not assembled because they understood medical diagnostics. It was assembled because their presence implied that serious people had examined the claim and found it credible.

They had not. Or not sufficiently. Or the story was simply better than the questions it generated.

John Carreyrou did what the board had not done: he talked to people who had actually worked inside the company and reported what they said. The story he published in 2015 was not the product of technical expertise. It was the product of the journalist's oldest tool — talking to people who were there. The technology that could run hundreds of tests from a single drop of blood could not withstand that.

The jury decided she defrauded investors. It could not agree she defrauded patients. Balwani's jury convicted him on the patient counts. The moral question — did the patients who received inaccurate tests from a technology that did not work as described suffer a wrong? — is not resolved by either verdict. It sits in the gap between them, as it will continue to sit.

· TIMELINE ·
VERIFIED SOURCES
$9B = company valuation — not money stolen. Investor figure (~$945M) is from the government's case [DOJ — verify exact figure against primary before final publication]. Murdoch and DeVos figures are widely reported — verify exact amounts before quoting. Holmes: 4 counts convicted (investors only — acquitted on patient counts). Balwani: 12 counts, including patient counts — tried separately.
[1] US v. Holmes, 5:18-cr-00258-EJD-1, N.D. Cal. San Jose — conviction January 3, 2022; sentence November 18, 2022 (135 months)
[2] US v. Balwani, same case — convicted July 2022, all 12 counts; sentenced December 2022, 13 years
[3] Ninth Circuit No. 22-10312 — February 24, 2025: conviction affirmed unanimously. Judge Nguyen: 'mirage' / 'half-truths and outright lies.' En banc rehearing denied May 8, 2025. SOURCE: Fox4/KTVU; Bay City News; Bloomberg Law
[4] DOJ/US Attorney N.D. Cal. — conviction and sentencing press releases
[5] Reuters — 'Elizabeth Holmes sentenced to more than 11 years in prison for Theranos fraud,' November 18, 2022
[6] CNN Business — sentencing coverage, November 18, 2022
[7] UPI — bail/stay denial, May 2023 (prison report date set May 30, 2023)
[8] Bloomberg Law — en banc denial, May 8, 2025; initial appeal denial, February 24, 2025
[9] Courthouse News — Holmes/Balwani proceedings; May 2025 en banc denial
[10] John Carreyrou, Wall Street Journal — October 2015 exposé; Bad Blood (book, 2018)
[11] Fox4/KTVU — Balwani 13-year sentence confirmed; Ninth Circuit February 2025 reporting; Holmes in Bryan Texas; People Magazine 'hell and torture' quote
[12] TO VERIFY BEFORE PUBLICATION: exact investor total ($945M), Murdoch investment exact figure, DeVos family exact figure — all require confirmation against primary court record
END OF REPORT
#24 OF 45
Marcelo Odebrecht
SINGLE PERSON
CASE 042 · BRIBERYANNULLED
Odebrecht · 19y4m · annulled 2024
~$788M
WHAT WAS TAKEN
Bribes Odebrecht paid to officials in 12 countries to win public contracts (company's US plea).
HOW
Ran a company department whose job was paying bribes, with its own off-book accounts.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2009–2015As CEO, oversees the company whose Division of Structured Operations paid ~$788M in bribes across 12 countries.SOURCE: DOJ plea, 21 Dec 2016 (company admission)
19 June 2015Arrested in Operation Car Wash; sentenced in Curitiba to 19 years 4 months in March 2016.SOURCE: Federal court, Curitiba
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: World Economic Forum · CC BY-SA 2.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
MARCELO ODEBRECHT
THE DEPARTMENT · OPERATION CAR WASH · CASE 042 · BRIBERY · 19Y4M (2016) · ANNULLED 2024
BRIBES
~$788M in 12 countries (DOJ)
PENALTIES
$3.5B+ Odebrecht & Braskem
SENTENCE
19 years 4 months · 2016
ARRESTED
June 19, 2015
JAIL
~2.5 years, then house arrest
ANNULLED
May 21, 2024 · STF
WHAT $788M IS: bribes Odebrecht paid to officials to win contracts, as the company admitted in its 2016 US plea. Not a loss figure.
FULL PROFILE

IDENTITY

NAME
Marcelo Bahia Odebrecht
BORN
Oct 18, 1968 · Salvador, Bahia, Brazil
COMPANY
Odebrecht S.A. · CEO 2008–2015
THE UNIT
Division of Structured Operations — the bribery department

CASE RECORD

ARRESTED
June 19, 2015 · Car Wash
SENTENCED
Mar 8, 2016 · 19 years 4 months · Judge Sergio Moro
COOPERATION
Dec 2016 · admitted guilt, named officials
HOUSE ARREST
From Dec 2017
ANNULLED
May 21, 2024 · Justice Dias Toffoli; prosecutors appealed
KNOWN AS
Marcelo Odebrecht
STATUS
Convicted
CUSTODY
Released
COURT
13th Federal Court of Curitiba, Brazil; Supreme Federal Court (STF)
JUDGE
Sergio Moro
CHARGES
Corruption · Money laundering · Criminal association
PLEA
Cooperation (plea) agreement — December 2016
THE REACH
THE COMPANY$3.5B+
Odebrecht & Braskem
US plea Dec 2016
One of the largest corporate bribery settlements ever.
SOURCE: DOJ
PERUPRESIDENTS
Peru
Several ex-presidents investigated
Odebrecht payments reached Peru’s top politics.
SOURCE: Reuters
THE JUDGECURITIBA
Sergio Moro
Car Wash judge
Later a minister; his rulings were later criticised by the STF.
SOURCE: Agência Brasil
THE ANNULMENT2024
Dias Toffoli
Supreme Federal Court
Found due-process violations; the cooperation deal stands.
SOURCE: Agência Brasil
CASE TIMELINE
~2001
The department
Bribes paid across Latin America and Africa.
SOURCE: DOJ
June 19, 2015
Arrested
Car Wash.
SOURCE: Reuters
Mar 8, 2016
19y4m
Judge Moro.
SOURCE: Reuters
Dec 21, 2016
US plea
$788M in bribes admitted.
SOURCE: DOJ
Dec 2017
House arrest
Under his cooperation deal.
SOURCE: Agência Brasil
May 21, 2024
Annulled
STF Justice Toffoli.
SOURCE: Agência Brasil
HOW IT WORKED

HOW THE BRIBERY DEPARTMENT WORKED — DEFENSIVE LEVEL

01
The budget: A department with its own off-book accounts
02
The payments: Routed through offshore accounts to officials
03
The return: Public contracts for roads, dams and ports
04
The records: Kept meticulously — later the evidence
HOW A BRIBE BECAME A CONTRACT
Off-book fund
-->
Offshore payment
-->
Official
-->
Public contract

WHAT THIS CASE ESTABLISHED

Corruption can be run like a business process.
An annulled case is not the same as innocence; the admissions stand.
Series link: Method #44 Bribery.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE DEPARTMENT (1,100 WORDS)
Sources: US DOJ / Odebrecht-Braskem plea agreement (December 21, 2016) — the $788M bribery figure · Brazil's 13th Federal Court of Curitiba — conviction and sentencing · Brazil's Supreme Federal Court (STF) — annulment ruling, May 21, 2024, Justice Dias Toffoli · Reuters/Bloomberg/FT/fius.com.br (primary English-language coverage of the annulment). STATUS PRECISION: Convicted under Car Wash; sentenced 19y4m; leniency agreement reduced sentence to 7 years; proceedings annulled May 2024; leniency/cooperation agreement NOT covered by annulment — remains valid. PGR appealed the annulment (status: contested as of September 2026).
· PROLOGUE ·
The Department

Most companies have a legal department, a finance department, a human resources department. Odebrecht — Marcelo Odebrecht's construction conglomerate, the largest in Latin America — had one more: the Division of Structured Operations.

The Division of Structured Operations (Divisão de Operações Estruturadas) was, per the US DOJ's description in its 2016 charging documents, a bribery unit — a department with its own off-book accounting system, dedicated to routing payments to government officials across the region in exchange for public infrastructure contracts. It was staffed, budgeted, and audited. Its output was corruption, paid in cash and tracked in records.

The records are why the case is continental. When the Brazilian investigation Operation Car Wash (Lava Jato) reached Odebrecht's cooperation agreement in 2016, the Division's records provided evidence against officials in approximately 12 countries: Brazil, Peru, Ecuador, Mexico, Panama, Venezuela, Argentina, Colombia, the Dominican Republic, Guatemala, Mozambique, Angola, and others. Presidents, ministers, and party treasurers across the hemisphere were implicated by a single company's expense account.

Marcelo Odebrecht, born in 1968, was CEO of the company from 2008 to 2015. He was arrested in Brazil in 2015. He was convicted in 2016 and sentenced to 19 years and 4 months. He cooperated with investigators under a leniency agreement. And in May 2024, Brazil's Supreme Federal Court annulled the criminal proceedings — while leaving the cooperation agreement intact.

· PART ONE ·
The Mechanism — A Business Process

The bribe was the input. The contract was the output.

Odebrecht built its Latin American dominance through public infrastructure contracts — roads, dams, oil facilities, ports. The contracts were awarded by governments. The governments were controlled by officials. The officials could be paid.

The Division of Structured Operations managed those payments through a dedicated off-book accounting system — a shadow ledger that tracked bribes by official, by project, and by country. The amounts were substantial. The records were meticulous. The process was routine.

The DOJ's 2016 leniency agreement with Odebrecht and its petrochemical subsidiary Braskem documented approximately $788 million in bribes paid across the scheme's operational period — from approximately 2001 through 2016. This is the bribe total: the amount paid to officials to obtain contracts. It is not the contract value (which was far larger) and it is not a loss figure in the conventional sense. The bribes were an input cost, and the contracts were the return on investment.

The scale made Operation Car Wash, the Brazilian anti-corruption investigation that ultimately reached Odebrecht, one of the largest corruption investigations in history. The cooperation agreement Odebrecht signed with Brazilian, US, and Swiss authorities was, at the time, one of the largest corporate corruption settlements ever — with total penalties reported at approximately $3.5 billion across jurisdictions. [SOURCE: DOJ 2016; verify exact total]

· PART TWO ·
The Annulment — May 2024

On May 21, 2024, Justice Dias Toffoli of Brazil's Supreme Federal Court (Supremo Tribunal Federal — STF) issued a ruling annulling all procedural acts taken against Marcelo Odebrecht by the 13th Federal Court of Curitiba under Operation Car Wash. [SOURCE: STF; fius.com.br citing STF ruling; La Estrella de Panamá citing EFE]

The basis: Toffoli concluded that the prosecutors involved in Operation Car Wash and the former judge, Sergio Moro, had violated Odebrecht's right to a full defense and due process, making 'constant adjustments and arrangements' to prevent him from exercising his legal rights. Moro, who later became Minister of Justice in the Bolsonaro government, was the presiding judge who issued the Car Wash convictions.

The annulment is specific: it covers the proceedings by the 13th Federal Court. It does NOT cover Odebrecht's own leniency and cooperation agreement — the document in which he admitted guilt and provided evidence against co-conspirators. That agreement remains valid. His admissions of guilt in that agreement stand.

The practical effect: Odebrecht's criminal conviction under Car Wash was annulled. He had already served his time under the cooperation deal: about two and a half years in a Curitiba jail from his June 19, 2015 arrest, then house arrest from December 2017. [SOURCE: Reuters; Agência Brasil]

The Prosecutor General (PGR) appealed Toffoli's annulment ruling in June 2024. As of September 2026, the status of that appeal requires verification — the case may be pending before the full STF bench.

· PART THREE ·
What The Annulment Does and Does Not Mean

The annulment does not make the bribes un-happened. The cooperation agreement — the document in which Odebrecht admitted guilt, described the bribery system in detail, and named the officials who received payments — remains legally valid. His admissions are in the record. The evidence that implicated officials across the region was produced by that agreement and its status is separate from the criminal proceedings that were annulled.

The annulment reflects something about Car Wash itself. The investigation that began in Brazil in 2014 ultimately expanded to cover the political class of an entire continent, producing convictions and resignations at the highest levels of multiple governments. Whether those convictions were procedurally sound is a question that Brazil's courts are now resolving case by case. Several other Car Wash convictions — including that of former President Luiz Inácio Lula da Silva — were also annulled by the STF on procedural grounds, and Lula returned to win the 2022 presidential election.

This piece does not editorialize on Brazilian politics or on whether the annulment reflects the justice system or its corruption. It states the outcome: proceedings annulled; cooperation agreement intact; PGR appeal pending; verify final status before publication.

VERIFIED SOURCES AND STATUS WARNING
[1] US DOJ — Odebrecht-Braskem plea agreement, December 21, 2016. PRIMARY for: $788M bribery figure; Division of Structured Operations description; country list.
[2] Brazil's 13th Federal Court of Curitiba (Judge Sergio Moro) — conviction 2016; sentence 19 years 4 months; fines.
[3] Brazil's Supreme Federal Court (STF) — 2020 revision of leniency agreement (7-year reduction) · May 21, 2024 annulment ruling by Justice Dias Toffoli.
[4] fius.com.br (FIUS) — English-language summary of the May 2024 annulment ruling. SOURCE for: 'sentenced to 19 years and 4 months'; leniency agreement revision; annulment scope and grounds.
[5] La Estrella de Panamá / EFE — annulment coverage; due-process grounds; PGR appeal.
[6] Consultor Jurídico — PGR appeal of the annulment, June 4, 2024.
STATUS WARNING As of September 2026, the PGR appeal of the May 2024 annulment may or may not have been ruled on by the full STF bench. VERIFY BEFORE PUBLICATION whether the annulment stands, has been partially reversed, or is still pending.
SOURCES
[1] PRIMARY — US DOJ: Odebrecht and Braskem plead guilty (Dec 21, 2016)
[2] SECONDARY — Reuters / Agência Brasil: arrest, sentence, annulment
END OF REPORT
#25 OF 45
Anatoly Legkodymov
SINGLE PERSON
CASE 040 · CRYPTO LAUNDERINGCONVICTED
Bitzlato · time served · 2024
$700M+
WHAT WAS TAKEN
Nothing stolen: $700M+ in crypto traded with the Hydra darknet market through his exchange (DOJ).
HOW
Ran Bitzlato, a crypto exchange that asked customers for almost no identification.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2016–2023Lives in Shenzhen and runs Bitzlato, the exchange that the DOJ says moved ~$700M for darknet markets including Hydra.SOURCE: DOJ E.D.N.Y.
17 Jan 2023Arrested in Miami as Bitzlato is taken down.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
ANATOLY LEGKODYMOV
NO QUESTIONS ASKED · BITZLATO · CASE 040 · CRYPTO LAUNDERING · TIME SERVED 2024
WITH HYDRA
$700M+ exchanged (DOJ)
RANSOMWARE
~$15M received (DOJ)
ARRESTED
Miami · Jan 17, 2023
PLEA
Unlicensed money transmitting
SENTENCE
Time served (~18 months)
THE MIRROR
,
WHAT $700M IS: crypto Bitzlato users traded with the Hydra darknet market. It is not his profit and not theft.
FULL PROFILE

IDENTITY

NAME
Anatoly Legkodymov
FROM
Russia · lived in China
EXCHANGE
Bitzlato (co-founder, majority owner)
THE PITCH
Little or no customer identification

CASE RECORD

ARRESTED
Jan 17, 2023 · Miami
COURT
Eastern District of New York (Brooklyn)
PLEA
Dec 6, 2023 · unlicensed money-transmitting business
SENTENCED
July 18, 2024 · time served · Judge Eric Vitaliano
BORN
~1982
STATUS
Convicted
CUSTODY
Released
JUDGE
Eric Vitaliano
CHARGES
Operating an unlicensed money-transmitting business
THE PIPELINE
THE MARKET
Hydra
Its biggest counterparty
Hydra users moved $700M+ through Bitzlato.
SOURCE: DOJ
THE TAKEDOWNJAN 2023
France & Europol
With the US
Bitzlato’s servers seized the same day as the arrest.
SOURCE: DOJ
FINCENJAN 2023
US Treasury
Order
Named Bitzlato a primary money-laundering concern.
SOURCE: FinCEN
CASE TIMELINE
~2016
Bitzlato
Founded.
SOURCE: DOJ
Jan 17, 2023
Arrested
Miami; exchange taken down.
SOURCE: DOJ
Dec 6, 2023
Guilty
Unlicensed money transmitting.
SOURCE: DOJ
July 18, 2024
Time served
Released.
SOURCE: Cointelegraph
HOW IT WORKED

HOW BITZLATO WORKED — DEFENSIVE LEVEL

01
The pitch: Trade crypto without proving who you are
02
The users: Darknet markets and ransomware crews, per the DOJ
03
The result: Criminal crypto turned into spendable money
04
The rule: Money transmitters must know their customers
THE PIPELINE
Darknet sale (Hydra)
-->
Bitzlato, no ID
-->
Cash out
-->
Crime funded

WHAT THIS CASE ESTABLISHED

An exchange that never asks is a laundering service.
Series link: () and (Hydra).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — NO QUESTIONS ASKED (800 WORDS)
Sources: DOJ press release January 18, 2023 (charging); guilty plea December 2023; sentencing / release July 2024 · US Treasury/FinCEN Bitzlato action · Reuters/Bloomberg/The Record coverage. DISCIPLINE: >$700M = illicit funds moved through the exchange (DOJ figure) — not theft, not his take. Bitzlato did not collapse or steal deposits; it laundered. The Hydra () connection: DOJ identifies Hydra as a principal recipient of Bitzlato funds. MIRROR OF (015): Binance inadequate controls; Bitzlato deliberately absent controls.
· PROLOGUE ·
The Door With No Lock

Know Your Customer is not an optional framework. It is a legal requirement for any entity that transmits money — an exchange, a bank, a payment processor. The requirement exists because money-transmitting businesses are a chokepoint in the financial system, and the only way illegal money moves into the legitimate economy is through that chokepoint.

's Binance () failed to build adequate KYC/AML controls. The DOJ found the controls inadequate; the $4.3 billion company penalty reflected the scale of the failure; served four months for a BSA compliance charge.

Bitzlato was different. Bitzlato, founded around 2016 and co-founded by Anatoly Legkodymov, a Russian national, marketed itself explicitly as a 'No Questions Asked' exchange — an exchange whose users were not required to identify themselves, verify their identity, or provide information about the source of their funds. The absence of KYC was the product. The value proposition to a criminal was that no record of their identity would be attached to their transaction.

The result, per the DOJ: Bitzlato's users exchanged more than $700 million in cryptocurrency with Hydra Market alone, and the exchange also took in about $15 million in ransomware proceeds. Among the sources of those funds: proceeds from ransomware operations and funds from the Hydra Market darknet marketplace — the subject of . [SOURCE: DOJ January 18, 2023]

Legkodymov was arrested in Miami on January 17, 2023, pleaded guilty on December 6, 2023 to operating an unlicensed money-transmitting business, and on July 18, 2024 Judge Eric Vitaliano in Brooklyn sentenced him to time served — about 18 months in custody. [SOURCE: DOJ; Cointelegraph, July 2024]

· PART ONE ·
The Business Model — Absence as Feature

A conventional crypto exchange requires users to submit identity documents, verify their residency, and link verified payment methods. The process is slow and leaves records. For users moving funds they do not want associated with their names — ransomware proceeds, narcotics sales revenue, money from sanctioned jurisdictions — this is a liability.

Bitzlato offered the alternative. Users could operate without KYC verification. Transactions were processed without identity records being attached. The exchange accepted business from jurisdictions and users that a regulated exchange would have screened out. It did not file suspicious-activity reports. It did not build the monitoring infrastructure that the Bank Secrecy Act requires of US-linked money-transmitters.

The Hydra Market connection is documented by the DOJ: Hydra — the Russian-language darknet marketplace that processed over $5.2 billion in cryptocurrency before its April 2022 takedown — used Bitzlato as part of its financial infrastructure. Hydra funds moved through Bitzlato, the exchange that would not ask. [SOURCE: DOJ January 18, 2023; cross-reference ]

Ransomware operators — groups that encrypt victim organisations' data and demand cryptocurrency payments for decryption keys — also used Bitzlato to convert and launder their proceeds. The exchange was, in this framing, a service provider to the ransomware economy.

· PART TWO ·
The Series Pipeline — Cases That Connect

The series now has a documented pipeline: a darknet marketplace ( — Hydra) generated illegal cryptocurrency revenue; an exchange (Case 040 — Bitzlato) moved those funds without asking; and a state actor ( — Group Profile) generates revenue at the top of the chain through direct theft.

The Bitzlato case completes the AML spectrum the series has been building. /Binance () sits at the inadequate-controls end — a large, legitimate exchange that failed to build adequate controls at scale. Legkodymov/Bitzlato (Case 040) sits at the deliberate-absence end — an exchange whose entire model was built on the absence of those controls. Between them, the spectrum covers every variety of compliance failure from negligence to service.

The sentence contrast is notable and should be stated without editorial comment: received four months in prison after a $4.3 billion company penalty, then was pardoned. Legkodymov received time served — approximately 18 months in custody — for running an exchange whose absence of controls was by design and that moved $700 million in illicit funds. The accountability spectrum across these two cases is real and its shape is the record's to explain.

VERIFIED SOURCES
[1] DOJ press release, January 18, 2023 — Bitzlato charging announcement. $700M illicit funds figure. Hydra as 'principal recipient.' Legkodymov identified as co-founder and major shareholder.
[2] US Treasury/FinCEN — January 18, 2023 action against Bitzlato simultaneous with DOJ.
[3] Reuters/Bloomberg — plea (December 2023) and release (July 2024) coverage.
[4] Chainalysis — Bitzlato and Hydra fund-flow analysis supporting the illicit-funds attribution.
TO VERIFY Exact plea date · Exact sentencing date · Exact release date (July 2024 per brief) · Legkodymov's total custody period · Co-founder outcomes · Whether the total transaction volume (~$4B cited in some sources) is confirmed · Any US Treasury designation beyond the FinCEN action
SOURCES
[1] PRIMARY — US DOJ: Bitzlato founder charged (Jan 18, 2023)
[2] SECONDARY — Cointelegraph: time served (July 2024)
END OF REPORT
#26 OF 45
Trevor Milton
SINGLE PERSON
CASE 041 · CORPORATE FRAUDPARDONED
Nikola · 4 years · pardoned 2025
~$680M
WHAT WAS TAKEN
Restitution prosecutors sought for investors (never ordered). Nikola peaked at ~$30B in value.
HOW
Sold investors a hydrogen-truck story, including a video of a truck rolling downhill.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2014–2020Founds Nikola in Utah, moves it to Phoenix; the 'in motion' video of a truck rolling downhill is filmed in 2016.SOURCE: SDNY verdict; case brief
Sept 2020Hindenburg report; resigns as executive chairman.SOURCE: case brief
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: Miljøstiftelsen ZERO · CC BY 2.0 · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
TREVOR MILTON
THE DEMONSTRATION · NIKOLA CORPORATION · CASE 041 · CORPORATE FRAUD · 4 YEARS · PARDONED 2025
PEAK VALUE
~$30B (June 2020) — not theft
SENTENCE
4 years · Dec 18, 2023
FINE
$1M + Utah property
RESTITUTION
~$680M sought, never ordered
PRISON
None · free pending appeal
PARDON
March 2025
WHAT THE NUMBERS ARE: $30B was Nikola’s market value; ~$680M is restitution prosecutors asked for but never got ordered.
FULL PROFILE

IDENTITY

NAME
Trevor Milton
FROM
Utah, United States
COMPANY
Nikola Corporation, founded 2014 (Utah; later Phoenix, Arizona)
THE VIDEO
“Nikola One in Motion” (2016): the truck was rolling downhill

CASE RECORD

RESIGNED
Sept 20, 2020 · after the Hindenburg report
CHARGED
July 29, 2021 · SDNY
CONVICTED
Oct 14, 2022 · 1 securities fraud, 2 wire fraud
SENTENCED
Dec 18, 2023 · 4 years · Judge Edgardo Ramos
PARDONED
March 2025 · President Trump
BORN
1982
STATUS
Pardoned
CUSTODY
Released
COURT
US District Court, Southern District of New York
JUDGE
Edgardo Ramos
CHARGES
Securities fraud · Wire fraud (3 counts)
PLEA
Not guilty — convicted by a jury, 14 October 2022
THE PEOPLE AROUND IT
THE SHORT SELLERSEPT 2020
Hindenburg Research
Nate Anderson
“How to Parlay an Ocean of Lies” set off the collapse.
SOURCE: Hindenburg
THE PARTNERPULLED OUT
General Motors
11% stake, ~$2B
The planned partnership was cut back after the report.
SOURCE: Reuters
THE COMPANYBANKRUPT 2025
Nikola
Chapter 11, Feb 2025
Milton was reported to be bidding for its assets.
SOURCE: TechCrunch
CASE TIMELINE
2014
Nikola
Founded in Utah.
SOURCE: Wikipedia
2016
The video
Truck rolling downhill.
SOURCE: DOJ
June 2020
$30B
Peak market value.
SOURCE: Reuters
Sept 10, 2020
Hindenburg
Short-seller report.
SOURCE: Hindenburg
Sept 20, 2020
Resigns
Executive chairman.
SOURCE: Reuters
Oct 14, 2022
Guilty
Three counts.
SOURCE: DOJ
Dec 18, 2023
4 years
Free pending appeal.
SOURCE: DOJ
Mar 2025
Pardoned
President Trump.
SOURCE: AP
HOW IT WORKED

HOW THE STORY WAS SOLD — DEFENSIVE LEVEL

01
The claim: A working zero-emission truck
02
The video: A truck rolled downhill, filmed to look like it drove
03
The reach: Social media and interviews straight to retail investors
04
The warning sign: Demos you can’t check independently
HOW A VIDEO BECAME A VALUATION
Staged demo
-->
Hype online
-->
Retail buying
-->
$30B peak

WHAT THIS CASE ESTABLISHED

A demonstration can be the fraud.
A pardon is not innocence.
Series link: (Holmes), (Milken), ().
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE DEMONSTRATION (900 WORDS)
Sources: DOJ/SDNY indictment July 2021 · Conviction October 2022 · Sentencing December 2023 (4 years) · Pardon March 28, 2025 (White House confirmed) · Fox 2/Fox 5/Fortune/AP coverage. CORRECTIONS TO BRIEF: Brief said 'sentenced 2025' — the actual sentencing was December 2023; the pardon was March 28, 2025. METRIC DISCIPLINE: ~$680M was SOUGHT in restitution but NOT ordered. The pardon may wipe out any restitution that was ordered. ~$30B = peak Nikola market valuation (not theft). State the pardon as documented fact without editorial comment.
· PROLOGUE ·
The Demonstration Was the Fraud

Holmes () built a machine that could not do the test. Milton built a demonstration that was not happening.

In 2016, Nikola Corporation published a video of the Nikola One — its hydrogen-electric semi-truck prototype — appearing to be in motion. The video was titled 'Nikola One Electric Semi Truck in Motion.' The government alleged, and established at trial, that the truck in the video was not driving under its own power. It was rolling downhill. The camera angle and editing implied a functioning vehicle. [SOURCE: DOJ indictment / trial record]

Nikola Corporation was founded by Trevor Milton in 2014, in a basement in Utah. By 2020, amid the electric vehicle investment boom, it was worth approximately $30 billion at its peak market valuation — a figure that reflected investor belief in the technology story Milton was telling. That story, per the DOJ and per the conviction, contained material misrepresentations about the company's technology and progress.

Milton was convicted on October 14, 2022, on one count of securities fraud and two of wire fraud. He was sentenced on December 18, 2023, to 4 years in federal prison and a $1 million fine, and ordered to forfeit a property in Utah. He appealed. He was not incarcerated while the appeal was pending. He was pardoned by President Trump on March 28, 2025. [SOURCE: DOJ; Fox News/AP pardon reporting]

· PART ONE ·
The Short-Seller Break — The Sequence Matters

In September 2020, Hindenburg Research — a short-seller research firm — published a detailed report titled 'Nikola: How to Parlay an Ocean of Lies Into a Partnership With the Largest Auto OEM in America.' The report alleged that Milton had made a series of material misrepresentations about Nikola's technology, including the truck-rolling-downhill allegation.

The report was published just weeks after Nikola and General Motors had announced a major partnership in which GM would take an 11% stake in Nikola, worth about $2 billion, and supply fuel cells and other components. The short-seller report challenged the basis of that partnership. GM eventually withdrew. Milton resigned as Executive Chairman on September 20, 2020, shortly after the report's publication.

The government's investigation ran in parallel with the public controversy. Milton was charged on July 29, 2021, more than a year after his resignation and the Hindenburg report. The sequence — public short-seller challenge, then government action — is relevant because it shows the fraud was publicly contested before it was prosecuted. [SOURCE: Reuters/WSJ; DOJ indictment]

· PART TWO ·
The Pardon — March 28, 2025

The pardon is a documented act of executive clemency. It does not reverse the conviction factually or constitute a finding of innocence.

President Trump confirmed the pardon on March 28, 2025. Milton responded: 'I am incredibly grateful to President Trump for his courage in standing up for what is right and for granting me this sacred pardon of innocence.' [SOURCE: Fox News / AP / Fortune]

The background the record establishes: Milton and his wife donated more than $1.8 million to a Trump re-election campaign fund less than a month before the November 2024 election. When asked about the pardon, Trump said: 'They say it was very unfair, and they say the thing that he did wrong was he was one of the first people that supported a gentleman named Donald Trump for president.' [SOURCE: Fox News / AP]

Per AP and Fortune reporting, the pardon may cancel the restitution for defrauded investors that prosecutors had sought — the same investors who watched Nikola's stock fall after Milton's claims were publicly challenged and then convicted. The precise effect of the pardon on pending civil and financial claims is not fully established in public records as of this writing.

Nikola Corporation filed for Chapter 11 bankruptcy in February 2025. Milton was reportedly attempting to purchase Nikola's assets from the bankruptcy estate. [SOURCE: Electrive citing Techcrunch/court documents]

The series documents the pardon and its stated context as fact. It does not editorialize on it. It belongs in the same category as the Milken pardon (2020) and the pardon (2025) and the Ulbricht pardon (January 2025): a documented pattern in the accountability spectrum, with its own record.

VERIFIED SOURCES
[1] DOJ/SDNY — indictment July 29, 2021; conviction October 14, 2022, 3 counts; sentencing December 2023, 4 years.
[2] White House / AP / Fox News — pardon confirmed March 28, 2025. Trump's stated reason for the pardon. Milton's public statement.
[3] Fortune / AP — pardon may cancel restitution for investors; Nikola bankruptcy (February 2025); Milton attempting to purchase Nikola assets.
[4] Hindenburg Research — 'Nikola: How to Parlay an Ocean of Lies' report, September 2020. The short-seller exposure that preceded the government case.
[5] Reuters/WSJ — GM partnership announcement, Hindenburg report publication, Milton resignation September 20, 2020, all 2020.
SENTENCING NOTE Brief said 'sentenced 2025.' Actual sentencing: December 18, 2023. Pardon: March 28, 2025. He was not incarcerated between sentencing and pardon.
TO VERIFY Exact sentencing date · Exact restitution order (if any) and whether pardon cancels it · Whether the Nevada/other SEC settlement interacts with the pardon · Nikola bankruptcy asset sale outcome
SOURCES
[1] PRIMARY — US Attorney SDNY: conviction (2022) and sentence (2023)
[2] SECONDARY — AP / Fox News: pardon (March 2025)
[3] SECONDARY — Hindenburg Research report (Sept 2020)
END OF REPORT
#27 OF 45
Michael Milken
SINGLE PERSON
CASE 034 · STOCK FRAUDPARDONED
Drexel Burnham Lambert · 6 counts · pardoned 2020
~$600M
WHAT WAS TAKEN
Nothing proven stolen. ~$600M is what he paid under his 1990 plea: fines plus a fund for investors' claims.
HOW
Hid who really owned stock ('parking') and helped file false papers, inside the junk-bond market he built.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1978–1989Runs Drexel Burnham Lambert's high-yield bond desk from Wilshire Boulevard; the securities violations he admitted happened here.SOURCE: US v. Milken, SDNY plea 1990
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: US Government · Public domain · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
MICHAEL MILKEN
THE LEGEND AND THE RECORD · DREXEL BURNHAM LAMBERT · CASE 034 · STOCK FRAUD · 98 COUNTS CHARGED, 6 PLEADED · PARDONED 2020
PAID
~$600M under his plea — a penalty, not a theft
COUNTS
98 indicted → 6 pleaded
SENTENCE
10 years → cut to 2 · served ~22 months
DREXEL
$650M firm penalty; bankrupt Feb 1990
PAY
Over $550M in 1987 alone
PARDON
Feb 18, 2020 · not a finding of innocence
WHAT THE $600M IS: ~$200M in fines plus ~$400M into a fund for claims under his 1990 plea. It is what he paid, not a measure of money stolen.
FULL PROFILE

IDENTITY

NAME
Michael Robert Milken
BORN
July 4, 1946 · Encino, California
KNOWN AS
The Junk Bond King
FIRM
Drexel Burnham Lambert · high-yield bond department, Beverly Hills
AFTER
Prostate cancer diagnosis (1993); Milken Institute and medical-research philanthropy

CASE RECORD

INDICTED
March 1989 · 98 counts incl. RICO (SDNY)
PLEA
April 24, 1990 · 6 counts; RICO dropped
THE SIX
Conspiracy · securities fraud · mail fraud · stock parking (false SEC filing) · false tax return · reporting violation
SENTENCED
Nov 21, 1990 · 10 years · Judge Kimba Wood
CUT
Aug 1992 · to 2 years for cooperation · released Jan 3, 1993
PARDONED
Feb 18, 2020 · President Trump
THE PEOPLE AND THE FIRM
THE KEY WITNESSPLEADED GUILTY 1986
Ivan Boesky
Arbitrageur
Paid $100M, cooperated, and led prosecutors to Drexel and Milken.
SOURCE: Court record · Den of Thieves
THE FIRM$650M
Drexel Burnham Lambert
Pleaded guilty Dec 1988
Then the largest securities settlement; the firm went bankrupt in February 1990.
SOURCE: NYT / WSJ
THE PROSECUTORSDNY
Rudolph Giuliani
US Attorney
His office brought the RICO indictment in 1989.
SOURCE: NYT
THE JUDGE10 YEARS
Kimba Wood
SDNY
Sentenced him in 1990 and cut the term to two years in 1992.
SOURCE: NYT
THE MARKETSTILL HERE
High-yield bonds
Junk bonds
The market he built was real and still finances companies today.
SOURCE: Series
THE PARDON2020
Presidential clemency
Not innocence
The conviction stands in the record; the pardon forgives the punishment.
SOURCE: White House
THE LEGEND VS THE RECORD
LEGEND
“He looted America and stole $600M”
RECORD
Pleaded to 6 specific counts and paid ~$600M in penalties
LEGEND
A racketeer
RECORD
RICO was charged and dropped; never proven
CASE TIMELINE
1970s–80s
Junk bonds
Builds the high-yield market at Drexel.
SOURCE: Bruck
1987
$550M+
Reported pay in a single year.
SOURCE: Den of Thieves
Nov 1986
Boesky
Pleads guilty and cooperates.
SOURCE: court record
Dec 1988
Drexel pleads
$650M.
SOURCE: NYT
Mar 1989
98 counts
RICO indictment.
SOURCE: DOJ
Feb 1990
Drexel bankrupt
The firm collapses.
SOURCE: NYT
Apr 24, 1990
Guilty
Six counts; ~$600M.
SOURCE: DOJ
Nov 21, 1990
10 years
Judge Kimba Wood.
SOURCE: NYT
Jan 3, 1993
Released
After ~22 months.
SOURCE: NYT
Feb 18, 2020
Pardoned
President Trump.
SOURCE: White House
HOW IT WORKED

WHAT HE ADMITTED — DEFENSIVE LEVEL

01
Parking: Holding stock for someone else so the real owner stays hidden
02
False filings: Helping others file false disclosures with the SEC
03
The tax count: Helping file a false tax return
04
The lesson: Hidden ownership is a warning sign regulators look for
HOW STOCK PARKING HIDES OWNERSHIP
Real buyer
-->
Friendly firm holds the shares
-->
Filings show the wrong owner
-->
Market misled

WHAT THIS CASE ESTABLISHED

A 98-count indictment can end in a 6-count plea.
A penalty is not a theft figure.
A pardon forgives; it does not erase the record.
Series link: (Belfort) and (, also pardoned).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEGEND AND THE RECORD (1,300 WORDS)
Sources: DOJ/SDNY indictment (March 1989) · Plea agreement (April 24, 1990) · Judge Kimba Wood sentencing (November 21, 1990) · Presidential pardon record (February 18, 2020) · SEC civil actions · Drexel Burnham Lambert bankruptcy (February 1990) · James B. Stewart — Den of Thieves (1991) · Connie Bruck — The Predators' Ball (1988) · NYT/WSJ contemporaneous. METRIC DISCIPLINE: ~$600M is the plea/penalty figure, not a theft or victim-loss figure. Indictment counts (98) ≠ plea counts (6). Never write 'stole $600M.' Write: agreed to pay approximately $600M in fines and payments under his plea agreement.
· PROLOGUE ·
The Gap

Michael Milken was indicted on 98 counts in March 1989. He pleaded guilty to 6 counts in April 1990. The difference between those two numbers — 92 counts, including the RICO charges that would have defined him as a racketeering organisation — is the gap between the legend and the record, and the gap is the case.

The public story of Michael Milken is of the Junk Bond King as the face of 1980s financial excess — indicted under RICO, fined $600 million, and sent to prison. Most of that is correct in outline. The details are more specific.

He was indeed indicted under RICO. He did not plead guilty under RICO. The RICO charges were resolved as part of the plea agreement — which means the 6 counts he admitted were narrower: conspiracy, securities fraud, mail fraud, parking securities for others (holding stocks on their behalf to conceal who really owned them), assisting a false tax return, and a broker-dealer reporting violation. [SOURCE: DOJ plea record; Den of Thieves, James B. Stewart, 1991]

He agreed to pay approximately $600 million in fines and payments — the number the legend remembers wrongly. That is not what the number measures. It is the penalty figure in the plea agreement. No victim is on record receiving $600 million. The amount represents the price he paid to resolve the government's case, not money taken from an identified victim.

He was sentenced to 10 years by Judge Kimba Wood on November 21, 1990. He served approximately 22 months — released January 3, 1993. He was pardoned by President Trump on February 18, 2020. The pardon is executive clemency; it does not reverse the conviction or constitute a finding of innocence.

· PART ONE ·
What He Built — The Real Market

Drexel Burnham Lambert's high-yield department, operating out of Beverly Hills under Milken's leadership, financed the high-yield bond market into existence. The market was real. It is not gone.

High-yield debt — junk bonds — are bonds issued by companies that cannot access the investment-grade credit market. Before Milken's market, these companies had limited access to large-scale financing. Milken argued, and demonstrated, that properly priced high-yield bonds produced better risk-adjusted returns than the conventional wisdom assumed — because the premium for accepting default risk was set higher than the actual default rate.

The companies financed through Drexel's junk bond department include entities that employed tens of thousands of people and generated real economic activity. The leveraged buyout wave of the 1980s — which Drexel's bonds financed — restructured major corporations. The consequences of that restructuring were disputed and remain disputed; what is not disputed is that the financial instrument and the market were genuine.

Milken's department at Drexel was the dominant force in this market by the mid-1980s. His personal compensation was extraordinary — reportedly over $550 million in a single year (1987). The scale attracted scrutiny. The scrutiny was warranted not because the market was fraudulent, but because within that real market, specific conduct violated specific laws.

· PART TWO ·
The Investigation — Boesky and the Pivot

Ivan Boesky was one of the most prominent arbitrageurs of the 1980s — a trader who bet on corporate mergers and acquisitions using inside information. He pleaded guilty in November 1986 to one count of securities fraud, agreed to pay $100 million in penalties, and cooperated with federal prosecutors. His cooperation was the key that opened the wider investigation. [SOURCE: court record; Stewart, Den of Thieves]

Boesky's cooperation pointed investigators toward Drexel and Milken. The government's investigation alleged a web of reciprocal arrangements — parking securities, manipulating stock prices, sharing inside information about pending deals — that benefited both the Boesky operation and Drexel's clients. The 98-count indictment filed in March 1989 charged Milken with racketeering (RICO), securities fraud, market manipulation, and related offences.

Drexel Burnham Lambert, the firm, was separately charged. It pleaded guilty in December 1988 to six counts and paid $650 million in fines — at the time the largest securities settlement in history. It filed for bankruptcy in February 1990. The firm did not survive the investigation. Milken's departure from the firm had occurred before the bankruptcy.

· PART THREE ·
The Plea — What He Admitted

On April 24, 1990, Milken pleaded guilty to 6 counts of securities violations in the Southern District of New York. The RICO counts — the charges that would have characterised him as a racketeering organisation — were dropped as part of the plea agreement.

The specific counts: conspiracy, securities fraud, mail fraud, aiding and abetting a false SEC filing through 'parking' (holding securities on behalf of others to conceal who owned them), assisting the filing of a false tax return, and a broker-dealer reporting violation. These are specific, documented violations of specific securities law provisions — neither trivial nor the sweeping fraud the indictment suggested.

He agreed to pay approximately $200 million in fines directly and approximately $400 million into a fund for claims — the combined ~$600 million figure. [SOURCE: DOJ / plea record; NYT, April 1990]

Sentenced November 21, 1990: 10 years. Served approximately 22 months before release on January 3, 1993. In August 1992 Judge Wood reduced the 10-year sentence to two years, citing his cooperation with further investigations.

· PART FOUR ·
The Mythology Problem — Why This Case Exists

The series enforces a rule: every figure labelled by what it measures. The Milken case exists in the series to apply that rule to a person.

Milken became a symbol — of 1980s excess, of the captured financial system, of the proposition that the rules did not apply to people rich enough to hire lawyers smart enough. That symbol served a cultural function: it gave a complicated decade a face. The problem is that symbols are not evidence, and the record underneath the symbol is specific and narrow in ways the symbol is not.

He is 80 years old. After his release in 1993, he funded prostate cancer research — he was diagnosed with the disease in 1993, shortly after his release — and created foundations for education and medical initiatives. These are documented activities. They do not reverse the conviction and they are not its mitigation; they are what the record shows he did afterwards.

The pardon in 2020 sits in the same position as 's pardon (): a documented fact about the legal system's response to a convicted individual, executed by a specific president for reasons that were not a finding of innocence. The pardon is stated; it is not editoralised.

The brief for this case asks: write the second version of the story — the record, not the legend — and explain why the gap between them exists. The gap exists because the legal system produced a specific outcome through a specific plea process, and the cultural record produced a far larger story. Both are real. Only one is evidence.

VERIFIED SOURCES
[1] DOJ/SDNY — indictment March 1989, 98 counts. Plea agreement April 24, 1990, 6 counts. Sentencing November 21, 1990, 10 years by Judge Kimba Wood.
[2] White House pardon record — February 18, 2020. Full pardon by President Trump.
[3] SEC — civil actions against Milken and Drexel. The civil record complements the criminal.
[4] Drexel Burnham Lambert — December 1988 guilty plea ($650M); February 1990 bankruptcy filing.
[5] James B. Stewart — Den of Thieves (1991). The definitive journalistic account. Self-reported sourcing; treat as secondary journalism not primary legal record.
[6] Connie Bruck — The Predators' Ball (1988). The rise of Drexel and the junk bond market.
[7] NYT/WSJ — contemporaneous coverage of the investigation, trial, sentencing, and pardon.
TO VERIFY Exact split of the ~$600M (direct fine vs. settlement fund) · The specific 6 counts and their precise legal characterisation · Boesky cooperation timeline and its exact role in triggering the Drexel investigation · Milken's cooperation credit and how it reduced the sentence · Current legal status (post-pardon)
SOURCES
[1] PRIMARY — US Attorney SDNY: indictment (1989), plea (Apr 24, 1990), sentence (Nov 21, 1990)
[2] PRIMARY — White House: pardon (Feb 18, 2020)
[3] SECONDARY — NYT / WSJ: Drexel, sentence cut, release
[4] SECONDARY — James B. Stewart, Den of Thieves (1991); Connie Bruck, The Predators’ Ball (1988)
END OF REPORT
#28 OF 45
Jorge Perez
SINGLE PERSON
CASE 043 · HEALTHCARE FRAUDCONVICTED
EmpowerHMS · 100 months · 2023
~$400M
WHAT WAS TAKEN
What insurers paid out on ~$1.4B of lab-test bills sent through rural hospitals.
HOW
Billed insurers at hospital rates for lab tests done by outside labs, many unnecessary.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2015–2018From EmpowerHMS in Miami, bills ~$1.4B for lab tests through four rural hospitals in Florida, Georgia and Missouri; ~$400M paid.SOURCE: DOJ M.D. Fla.
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
JORGE PEREZ
THE BILLING LICENCE · RURAL HOSPITALS · CASE 043 · HEALTHCARE FRAUD · 100 MONTHS 2023
BILLED
~$1.4B to insurers
RECEIVED
~$400M (indictment)
SENTENCE
100 months · Dec 15, 2023
BROTHER
Ricardo Perez: 6y3m
THE TESTS
Mostly urine drug tests
THE PAYERS
Mostly private insurers
BILLED VS RECEIVED: ~$1.4B is what was billed; about $400M was received. Never write that he stole $1.4B.
FULL PROFILE

IDENTITY

NAME
Jorge Perez
FROM
Miami, Florida
COMPANY
EmpowerHMS — managed rural hospitals — four in the scheme, in Florida, Georgia and Missouri (DOJ)

CASE RECORD

CHARGED
June 2020 · with nine others
CONVICTED
June 27, 2022 · jury
SENTENCED
Dec 15, 2023 · 100 months
STATUS
Convicted
CUSTODY
In custody
COURT
US District Court, Middle District of Florida
CHARGES
Conspiracy to commit health care fraud and wire fraud · Money-laundering conspiracy
PLEA
Not guilty — convicted by a jury, 27 June 2022
THE HEALTHCARE TRIO
THE BROTHER6Y3M
Ricardo Perez
Co-defendant
Convicted with him.
SOURCE: DOJ
CASE TIMELINE
~2015
Billing begins
Through rural hospitals.
SOURCE: DOJ
June 2020
Charged
$1.4B scheme.
SOURCE: DOJ
June 27, 2022
Guilty
Jury.
SOURCE: KCUR
Dec 15, 2023
100 months
Sentenced.
SOURCE: DOJ
HOW IT WORKED

HOW PASS-THROUGH BILLING WORKS — DEFENSIVE LEVEL

01
The licence: Take over a hospital and its insurance contracts
02
The tests: Outside labs run the tests
03
The claim: Bill as if the hospital did them, at hospital rates
04
The warning sign: A tiny hospital suddenly billing huge lab volumes
HOW THE BILLING FLOWED
Outside lab test
-->
Billed under the hospital
-->
Insurer pays hospital rate
-->
Scheme collects

WHAT THIS CASE ESTABLISHED

The institution can be the instrument.
Billed is not the same as paid.
Series link: Cases 044 and 045.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE BILLING LICENCE (700 WORDS)
Sources: DOJ · US court records · HHS-OIG. DISCIPLINE: ~$1.4B = CLAIMS SUBMITTED, not money paid or stolen. The amount actually paid by insurers is smaller — verify to primary before stating a paid figure.
· PROLOGUE ·
The Billing Licence

The hospital was real. The building was real. The billing codes were real.

When Jorge Perez acquired struggling rural hospitals — small facilities in states with limited medical infrastructure — he acquired with them something far more valuable than the buildings: Medicare provider numbers and insurance contracts. These are the licences that allow a healthcare facility to bill government programmes and private insurers for services.

Per the DOJ, the operation submitted approximately $1.4 billion in claims to health insurers — mostly private insurers — for laboratory testing, largely urine drug tests and blood tests, billed as if the small rural hospitals had done them when most were done by outside laboratories, and many were not medically necessary. The operation received about $400 million. The patients listed on the claims were, in many cases, patients who never received those tests, never visited those facilities, or could not plausibly have needed those specific tests. The volume was the tell: a small rural hospital billing hundreds of millions in specialty lab work that its physical capacity could not have produced. [SOURCE: DOJ — verify specific hospital count and states]

He was convicted by a jury on June 27, 2022 and sentenced on December 15, 2023 to 100 months — 8 years and 4 months. His brother Ricardo Perez got 6 years and 3 months. The billed figure of $1.4 billion represents claims submitted; the amount actually paid by insurers was substantially lower. [SOURCE: DOJ — verify paid amount before publication]

· PART ONE ·
The Mechanism — Own the Licence, Own the Claims

Medicare billing is structured around provider numbers — identifiers that authorise a facility to bill the programme. A provider number, once obtained, is a financial asset: it allows the holder to submit claims for services at Medicare's established rates. For a scheme designed to fabricate claims, obtaining a real provider number through a real facility is the enabling step. The scheme does not require a fake hospital. It requires a real one with a cooperative or captured billing department.

This is the modern healthcare fraud insight: the institution is the instrument. Perez's rural hospitals were not the fraud — they were the vehicle. The billing department was the fraud. The provider number was the asset. Once those were in place, the volume of claims was limited only by how many patient records could be associated with the facility.

The harm is diffuse and it is enormous. Medicare is funded by taxpayers. Private insurance premiums are paid by employers and individuals. When claims are submitted for services that were not provided, the cost is absorbed into the system and ultimately paid by every participant in it. There is no single identifiable victim in the way that Madoff's investors or FTX's customers are identifiable. The harm is real — it is just spread across everyone who pays for healthcare.

· PART TWO ·
The Healthcare Category — Opening Note

This is the first of three healthcare cases in this series. Taken together, they document the full anatomy of healthcare fraud: fabricated claims (Perez), manufactured demand (Patel — ), and a purchased referral pipeline (Esformes — ).

The category is the largest source of fraud losses in the United States by DOJ measure — exceeding financial fraud, card fraud, and cryptocurrency fraud in annual recovered dollars. The cases exist not because healthcare fraud is new but because the mechanism is under-documented in financial fraud catalogues that tend to focus on markets and technology.

The hospital is a recurring vehicle. The provider number is the licence. The billing department is the engine. This is the shape the next two cases will repeat in different forms.

VERIFIED SOURCES
BILLED ≠ PAID. Verify paid amount before asserting. Living person. Do not generalize about rural hospitals.
[1] DOJ — press releases and charging documents for Jorge Perez / rural hospital billing scheme. [Verify specific case name, charge date, conviction date 2022, sentencing date 2023]
[2] HHS-OIG — healthcare fraud enforcement context.
TO VERIFY Exact hospital count and states · Charge date (2019 per brief) · Exact conviction counts · Sentencing date and exact term · Amount actually paid by insurers (vs. $1.4B billed) · Any sentence reduction · Co-defendant outcomes including Dr. Ricardo Perez
SOURCES
[1] PRIMARY — US DOJ: two men sentenced (Dec 15, 2023)
[2] SECONDARY — KCUR: convicted (June 2022)
END OF REPORT
#29 OF 45
Vladimir Drinkman
SINGLE PERSON
CASE 036 · CARD FRAUDCONVICTED
Hacker 1 · Heartland · 12 years · released 2022
$300M+
WHAT WAS TAKEN
Losses at three of the 17 victim companies alone; the crew stole ~160M card numbers.
HOW
Broke into payment and retail networks like Heartland and planted tools that captured card data.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2005–2012'Hacker 1': breaks into Heartland, NASDAQ, 7-Eleven and others from Russia; 160M cards across the crew.SOURCE: DOJ D.N.J.
28 June 2012Arrested in the Netherlands; fights extradition for nearly three years.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
VLADIMIR DRINKMAN
HACKER 1 · THE HEARTLAND BREACH · CASE 036 · CARD FRAUD · 12 YEARS 2018 · RELEASED 2022
CARDS
~160M card numbers crew-wide — a count
HEARTLAND
~130M from one payment processor
LOSSES
$300M+ at three victims alone (DOJ)
VICTIMS
17 companies
SENTENCE
12 years · Feb 2018
RELEASED
Oct 28, 2022
CARD NUMBERS ARE NOT DOLLARS: 160M = cards stolen by the whole crew · 130M = Heartland alone · $300M+ = losses at three victims. Crew-wide, not his alone.
FULL PROFILE

IDENTITY

NAME
Vladimir Drinkman
FROM
Syktyvkar and Moscow, Russia
HANDLE
Grig · “Hacker 1” in the 2009 case
ROLE
Broke into the victims’ networks

CASE RECORD

ARRESTED
June 28, 2012 · Netherlands
EXTRADITED
Feb 17, 2015
PLEA
Sept 2015 · computer-access conspiracy + wire-fraud conspiracy
SENTENCED
Feb 2018 · 12 years · Judge Jerome B. Simandle (D.N.J.)
RELEASED
Oct 28, 2022 · after 10 years 4 months in custody
ALIASES
Hacker 1 · Grig
BORN
~1980
STATUS
Convicted
COURT
US District Court, District of New Jersey (Camden)
JUDGE
Jerome B. Simandle
CHARGES
Conspiracy to gain unauthorised access to protected computers · Conspiracy to commit wire fraud
CREW
(), Dmitriy Smilianets, Aleksandr Kalinin, Roman Kotov, Mikhail Rytikov
THE CREW
THE BROKER51 MONTHS
Dmitriy Smilianets
Moscow
Sold the stolen data and paid the crew; pleaded guilty Sept 2015.
SOURCE: DOJ
HACKER 2CHARGED
Aleksandr Kalinin
Russia
Charged with breaking into networks alongside Drinkman; never tried in the US.
SOURCE: DOJ
THE MINERAT LARGE
Roman Kotov
Russia
Charged with pulling data out of the networks; never arrested.
SOURCE: DOJ
THE HOSTAT LARGE
Mikhail Rytikov
Ukraine
Charged with providing anonymous hosting; never arrested.
SOURCE: DOJ
THE CARD-FRAUD TRILOGY
ACCESS
Drinkman (036): broke in
COORDINATION
Gonzalez (011): ran the crew
SALES
Seleznev (029): sold the numbers
RESULT
Every link prosecuted; the trade kept running
CASE TIMELINE
~2005
Intrusions begin
The crew starts breaking in.
SOURCE: DOJ
2007–2008
Heartland
~130M cards harvested.
SOURCE: Heartland
Jan 20, 2009
Disclosed
Largest US breach at the time.
SOURCE: Heartland
2009
Hacker 1
Unnamed in the Gonzalez case.
SOURCE: DOJ
June 28, 2012
Arrested
Netherlands.
SOURCE: DOJ
Feb 17, 2015
Extradited
To New Jersey.
SOURCE: DOJ
Sept 2015
Guilty
Two conspiracies.
SOURCE: DOJ
Feb 2018
12 years
Judge Simandle.
SOURCE: DOJ
Oct 28, 2022
Released
From a Pennsylvania facility.
SOURCE: RFE/RL
HOW IT WORKED

HOW THE CREW WORKED — DEFENSIVE LEVEL

01
Get in: Break into payment and retail networks (SQL injection, per the DOJ)
02
Stay in: Plant tools that capture card data as it moves
03
Get it out: Extract the card numbers to servers abroad
04
Sell it: A broker sells the numbers to carders
05
The defence: Encrypt card data end to end and watch networks for unknown tools
THE CARD-DATA SUPPLY CHAIN
Break in
-->
Capture card data
-->
Broker sells it
-->
Carders use it

WHAT THIS CASE ESTABLISHED

Card fraud is a supply chain; no single arrest ends it.
Card counts and dollar losses are different numbers.
Series link: (Gonzalez) and (Seleznev).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — HACKER 1 (900 WORDS)
Sources: DOJ/US Attorney D.N.J. — Drinkman plea (September 2015) · Sentencing February 2018 (144 months, Judge Jerome B. Simandle, D.N.J.) · RFE/RL — released October 28, 2022, Pennsylvania facility · Heartland Payment Systems — breach disclosure January 2009 · DOJ/US Attorney D.N.J. — Smilianets sentencing, crew indictment. METRIC DISCIPLINE: 130M = Heartland cards specifically. 160M = crew-wide total. $300M+ = losses attributed to the whole conspiracy. These are three different numbers measuring different things.
· PROLOGUE ·
Hacker 1

When the FBI charged and co-conspirators in 2009 with the Heartland Payment Systems breach — then the largest data breach ever reported — it described two unnamed Russian hackers in the indictment as 'Hacker 1' and 'Hacker 2.' These were the individuals who had actually penetrated the payment processor's network and installed the tools to harvest card data as it moved through the system.

Hacker 1 was Vladimir Drinkman.

He was arrested in the Netherlands on June 28, 2012. He fought extradition for nearly three years before arriving in the United States on February 17, 2015. He pleaded guilty in September 2015 to two counts: conspiracy to commit unauthorized computer access and conspiracy to commit wire fraud. He was sentenced to 144 months — 12 years — in February 2018 by Judge Jerome B. Simandle in the District of New Jersey. He served 10 years and 4 months — 86 percent of the sentence — before being released from a federal facility in Pennsylvania on October 28, 2022. [SOURCE: DOJ D.N.J.; RFE/RL]

His case completes the card-fraud section of this series. Gonzalez () was the coordinator. Seleznev () was the data operator and seller. Drinkman was the intruder — the one who got inside the targets.

· PART ONE ·
The Crew — Division of Labour

The indictment named five individuals and described their specific functions within the operation. Understanding the crew's structure is the purpose of this case file — the Heartland breach was not a lone-actor event.

· PART TWO ·
The Heartland Breach — What Was Taken

Heartland Payment Systems was a major US payment processor — a company that sat between merchants and banks, routing credit and debit card transactions for thousands of businesses. In 2007 and 2008, Drinkman and his associates penetrated Heartland's network and installed tools that harvested payment card data as it moved through the processing system.

The data harvested from Heartland alone: approximately 130 million payment card numbers. At the time of disclosure — January 20, 2009 — it was described as the largest data breach in US history. [SOURCE: Heartland SEC filing; Krebs on Security]

The crew's targets extended beyond Heartland: 7-Eleven, Hannaford Brothers, NASDAQ, JC Penney, Carrefour (France), JetBlue Airways, Dow Jones, Wet Seal, Euronet, Dexia, Global Payments, Diners Club Singapore, Visa Jordan, Ingenicard and others — 17 corporate victims in all, per the DOJ. The crew-wide card number count across all targets: approximately 160 million. [SOURCE: DOJ D.N.J. indictment; Dark Reading]

The losses: three of the corporate victims alone reported more than $300 million, according to the DOJ — borne by financial institutions, merchants, and cardholders who faced the fraud that followed. It is a crew-wide figure, not attributable to Drinkman alone.

· PART THREE ·
The Supply Chain — What the Trilogy Means

The card-fraud series has now told the same story three times, from three different positions in the supply chain. The point of telling it three times is the point that a single arrest cannot make:

Card fraud is not one person with a laptop. It is a production chain. The intrusion specialists (Drinkman, Kalinin) obtained access to the networks. The mining specialists (Kotov) extracted the data. The infrastructure specialists (Rytikov) kept the operations hidden. The coordinator (Gonzalez) managed relationships across the chain. The broker (Smilianets) sold the output and paid the participants.

The stolen data then entered a secondary market — the carding forums where Seleznev () operated, selling POS-harvested card numbers to buyers who used them to produce fraudulent transactions. The card numbers are the input to account takeover, synthetic identity fraud, and retail fraud operations that run across other categories in this series.

Of the five crew members charged, Smilianets and Drinkman were convicted and have served their sentences. Gonzalez was convicted separately and has been released. Kotov and Rytikov remain at large. Two links in the chain were convicted; two links were never reached; the category continued running through the period of all five prosecutions.

VERIFIED SOURCES
[1] DOJ / US Attorney D.N.J. — crew indictment (2013); Drinkman plea September 2015 (2 counts: conspiracy to commit unauthorized access + conspiracy to commit wire fraud); sentencing February 2018, 144 months, Judge Jerome B. Simandle.
[2] RFE/RL — 'Russian Hacker Behind Massive Data Breach Released From U.S. Prison.' Released October 28, 2022 from Pennsylvania facility. Served 10 years 4 months (86%). Smilianets now US-based cyberthreat intelligence analyst.
[3] Dark Reading — 'Russian Hackers Sentenced in Heartland Payment Systems Breach Case.' February 2018 sentencing details. Full crew breakdown and roles.
[4] DOJ D.N.J. press release, September 2015 — guilty plea announcement. 'Hacker 1' designation; crew roles described.
[5] Heartland Payment Systems — SEC breach disclosure, January 20, 2009. ~130M cards. 'Largest data breach in US history' at the time.
[6] Krebs on Security — definitive reporting on the Heartland breach and the Gonzalez crew. Cross-reference all crew details here.
TO VERIFY Kalinin's separate prosecution outcome · Kotov and Rytikov current status · The exact $300M loss attribution basis · Whether any card-number count was revised in the sentencing record
SOURCES
[1] PRIMARY — US Attorney D.N.J. / DOJ: two Russian nationals sentenced (Feb 15, 2018)
[2] PRIMARY — DOJ: Drinkman guilty plea (Sept 2015)
[3] SECONDARY — RFE/RL: released from US prison (Oct 2022)
[4] SECONDARY — Krebs on Security / Dark Reading: Heartland and the crew
END OF REPORT
#30 OF 45
Emmanuel Nwude
SINGLE PERSON
CASE 021 · ADVANCE-FEE / BANK FRAUDCONVICTED
The fake airport · 25 years · Lagos 2005
$242M
WHAT WAS TAKEN
A Brazilian bank's money: ~$191M in cash plus interest, from Banco Noroeste, 1995–1998.
HOW
Posed as Nigeria's central bank governor and sold a bank director a share in an airport that was never going to be built.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1995–1998Poses as the central bank governor to sell Nelson Sakaguchi a non-existent airport; $242M paid to Nigerian accounts.SOURCE: EFCC; Lagos High Court
2003–2005Arrested by the EFCC in June 2003; pleads guilty in Lagos in Nov 2005.SOURCE: EFCC
Mar 1995The London meeting where the fake 'governor' is introduced to Sakaguchi.SOURCE: case brief
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
EMMANUEL NWUDE
THE AIRPORT · CASE 021 · ADVANCE-FEE / BANK FRAUD · CONVICTED LAGOS 2005 · CONVICTED AGAIN 2026
TAKEN
$242M · the bank’s total loss
CASH SENT
~$191M · 1995–1998
HIS SHARE
~$90M (estimate)
SENTENCE
5 years × 5 counts, concurrent · 25 on paper
IN CUSTODY
June 2003 – 2006 · about 3 years
ORDERED TO RETURN
$110M to the bank + $11.5M to the government
RECOVERED
~$138M by 2008
2026
Convicted again: forgery of forfeited-property papers
TWO NUMBERS: $242M = what the bank lost including interest · ~$191M = the cash actually sent. The 25-year sentence ran as five five-year terms at the same time.
FULL PROFILE

IDENTITY

NAME
Emmanuel Nwude Odinigwe
BACKGROUND
Former director, Union Bank of Nigeria
POSED AS
Paul Ogwuma, governor of the Central Bank of Nigeria (1993–1999)
TITLE
Owelle Abagana (chieftaincy title)
THE TARGET
Nelson Sakaguchi, head of Banco Noroeste’s international operation, São Paulo
THE BAIT
A share in a new international airport in Abuja, and a commission reported as $10M

CASE RECORD

ARRESTED
June 4, 2003 · by the EFCC · guns, 17 company seals and luxury cars found at his Ikoyi house
CHARGED
86 counts in Abuja (Feb 2004) → 91 in Lagos (July 2004) → 12 at the plea
PLEA
Guilty · November 18, 2005
SENTENCE
5 years on each of 5 counts, concurrent · Justice Joseph Oyewole, Lagos High Court, Ikeja
FORFEITED
14 properties, 6 cars, 100M+ shares · $110M to the bank, $11.5M to the government
RELEASED
2006
2016
Charged in Anambra after a land clash (murder, arson) — bailed; allegations, no verdict found
2026
Convicted March 11 on 13 counts of forgery and dealing in forfeited property; 1 year each (Justice Mojisola Dada)
THE SCHEME, YEAR BY YEAR
1994THE INTRODUCTION
A business trip
Enugu
Sakaguchi is introduced to the group on a trip to Nigeria by an Enugu businessman.
SOURCE: ThisDay, 2005
1995THE HOOK
The fax & the London suite
March 1995
A fax offers a stake in a new Abuja airport. In a London hotel suite a man hands Sakaguchi a card: “Paul Ogwuma — Central Bank of Nigeria.” Sakaguchi pays $35,000.
SOURCE: Glenny · ICC
1995THE FIRST MONEY
Instalments
$4.65M in seven payments
The first transfers go out in mid-1995 to accounts the group controls. Christian Anajemba poses as a CBN deputy governor.
SOURCE: ICC · ThisDay
1996THE ESCALATION
The forged letter
Fake CBN letterhead
A “contract review panel” values his deal at $200M and demands $6.73M in “fluctuational charges” by October 18, 1996. More demands follow.
SOURCE: ThisDay, 2004
1997THE MACHINE
Under the radar
94 transfers
Payments kept under $6M to avoid higher sign-off, routed through the UK, Switzerland, Hong Kong and the US. A launderer, Naresh Asnani, moves ~$120M.
SOURCE: Glenny · ICC
1998THE END
Discovered
January 1998
With Santander buying the bank, the hole surfaces while Sakaguchi is on holiday. Last payment: January 20, 1998. He is suspended in February.
SOURCE: ThisDay · ICC
KNOWN NETWORK & THE VICTIM
THE VICTIMDECEIVED
Nelson Sakaguchi
Banco Noroeste, São Paulo
Sent ~$191M over three years. Arrested at JFK in 2002 on a Swiss warrant; jailed in Switzerland; sentenced in Brazil in 2014 to 6 years for fraudulent management.
SOURCE: ThisDay · Exame
CO-LEADERKILLED 1998
Christian Anajemba
Posed as a CBN deputy governor
Shared the proceeds with Nwude. Killed in October 1998; accounts of how differ.
SOURCE: ThisDay · The Register
ACCOMPLICEPLEADED GUILTY
Amaka Anajemba
His widow
Pleaded guilty July 2005; 2.5 years; forfeited assets and returned tens of millions of dollars.
SOURCE: ThisDay · Reuters
ACCOMPLICEPLEADED GUILTY
Nzeribe Okoli
Sent the first faxes
Took ~$4M before being cut out. Pleaded guilty November 2005; 4 years per count, concurrent.
SOURCE: ICC · ThisDay
THE REAL GOVERNORNOT INVOLVED
Paul Ogwuma
CBN governor, 1993–1999
The man whose identity was used. He had no part in the scheme.
SOURCE: Wikipedia
THE PROSECUTOREFCC
Nuhu Ribadu
First EFCC chairman
Bribe attempts to free the suspects were recorded; two lawyers, Emmanuel Ofulue and Obum Osakwe, were charged separately with trying to bribe him.
SOURCE: ICC · Guardian NG
THE BANK
BANCO NOROESTE
Founded 1923 · controlled by the Simonsen and Cochrane families
THE SALE
Sold to Santander for ~$480M; absorbed into Santander Brasil in 1999 — the owners bore the loss
THE CHASE
Recovery lawyers worked in Nigeria, Switzerland, London, Hong Kong and the US; ~$138M recovered by 2008
THE RANKING
Often called the third-largest bank fraud in history at the time — no original source; Brazilian press call it Brazil’s largest
THE SENTENCE AND THE OUTCOME
SENTENCE
25 years on paper — five concurrent five-year terms
SERVED
About three years in custody (June 2003 – 2006)
THEN
Reclaimed about $52M of seized assets through lawsuits by 2008 (Financial Times)
IN COURT, 2021
“I’m not responsible for the 242 million dollars… I don’t know anything about it.”
2026
Convicted of forging documents over property he was ordered to forfeit
CASE TIMELINE
1994
Introduced
Sakaguchi meets the group on a Nigeria trip.
SOURCE: ThisDay
March 1995
The first fax
The airport offer; the London meeting.
SOURCE: ICC · Glenny
1995
Payments begin
$4.65M in the first instalments.
SOURCE: ICC
October 1996
The forged letter
Demands $6.73M in “charges.”
SOURCE: ThisDay
1997
94 transfers
Money moves through four countries.
SOURCE: ICC
January 1998
Discovered
Last payment January 20; Sakaguchi suspended in February.
SOURCE: ICC
October 1998
Anajemba killed
SOURCE: ThisDay
1999
The bank absorbed
Banco Noroeste folded into Santander Brasil.
SOURCE: Wikipedia (pt)
June 4, 2003
Arrested
By the EFCC.
SOURCE: ThisDay
February 2004
86 counts
Arraigned in Abuja; moved to Lagos.
SOURCE: ThisDay
November 18, 2005
Guilty
25 years on paper; $110M + $11.5M ordered.
SOURCE: ThisDay
2006
Released
SOURCE: Financial Times
August 2016
New charges
Anambra land clash; bailed December 2016 (allegations).
SOURCE: Vanguard
March 11, 2026
Convicted again
13 counts of forgery; 1 year each.
SOURCE: PM News
HOW IT WORKED

ADVANCE-FEE FRAUD AT BANK SCALE

01
The identity: Pose as the governor of a central bank
02
The project: Offer a share in something big and believable: a new national airport
03
The commission: Promise the insider a large personal reward
04
The escalation: Forged letters demand more “charges” to keep the deal alive
05
The layering: Keep each transfer small, spread it across countries, launder it into naira
THE MONEY FLOW
Banco Noroeste funds
-->
Transfers approved by one director
-->
17 recipients in four countries
-->
Nigeria · property · companies

WHAT THIS CASE ESTABLISHED

The “419” advance-fee scam, usually aimed at individuals, worked on a bank for three years.
One insider with authority and a promised commission was enough.
It gave Nigeria’s EFCC its first landmark conviction — and much of the money was recovered.
The sentence and the time served are different numbers: 25 years on paper, about 3 in custody.
Series link: the same weakness as () and () — a trusted identity and convincing paperwork.
THE FULL STORY — 6 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE AIRPORT (2,700 WORDS)
Sources: EFCC (Economic and Financial Crimes Commission, Nigeria) · Nigerian courts — Ikeja High Court, Justice Joseph Oyewole, 2005 · NAN (News Agency of Nigeria) · Premium Times / The Cable (Nigerian press) · Guardian Nigeria · Wikipedia — Emmanuel Nwude (aggregator; verify to primary). CORRECTIONS TO BRIEF: Nwude's employer was Union Bank of Nigeria — he IMPERSONATED Paul Ogwuma, CBN Governor. The airport was a fictitious new airport in Abuja — NOT Murtala Muhammed International Airport. Sentenced 2005 to five concurrent five-year terms (25 years on paper); released 2006 — about three years in custody from his June 2003 arrest.
· PROLOGUE ·
The Letterhead Was the Product

In 1995, Emmanuel Nwude told a Brazilian banker named Nelson Sakaguchi that he was Paul Ogwuma — the Governor of the Central Bank of Nigeria.

He was not Paul Ogwuma. He was a director at Union Bank of Nigeria, a different institution. But he had the confidence of a man in authority, the paperwork of a man in authority, and the detailed knowledge of Nigerian banking protocols that a man in authority would have. [SOURCE: DMARGE citing sources; NAN]

He told Sakaguchi that the Nigerian government was preparing to build a major new international airport in Abuja, the federal capital. The project was large. The contract was valuable. The commission on offer — $10 million — was extraordinary. And the man making the offer was, according to the documents in front of Sakaguchi, the Governor of the Central Bank of Nigeria.

Sakaguchi paid. Between 1995 and 1998, he paid $191 million in cash and the remainder in the form of outstanding interest — $242 million total — into accounts controlled by Nwude and his co-conspirators. [SOURCE: EFCC; NAN; Guardian Nigeria]

There was no airport. There was no contract. There was no Paul Ogwuma on the other side of the transaction. There was a letterhead and a man who had studied the architecture of authority well enough to reproduce its surface.

The fraud was discovered not by an investigator but by an accountant. In late 1997, Banco Santander attempted to acquire Banco Noroeste. In a joint board meeting, a Santander official asked why two-fifths of Noroeste's total value — half its liquid capital — was sitting dormant in the Cayman Islands. [SOURCE: NAN; Wikipedia citing sources]

That question ended the scheme.

He sold a banker an airport that did not exist. The letterhead said it was real, and for three years, for a quarter of a billion dollars, it was. Every advance-fee fraud since is a cheaper print of the same page — authority asserted, paperwork attached, a mark who wants to believe.

· PART ONE ·
Who He Was and What He Knew

Nwude's career at Union Bank of Nigeria is the foundation the fraud was built on. He was not a random impersonator. He was a banking professional who understood exactly how correspondent banking relationships worked, how Nigerian state procurement processes were structured, and how a foreign banker would expect a major government contract to be presented.

The fraud required specific knowledge: how central bank letterheads were formatted, what language official Nigerian government contracts used, which payment routes were appropriate for a transaction of this scale, and how to maintain the impersonation of a specific individual — Paul Ogwuma, who served as CBN Governor from October 1993 to May 1999 — across a three-year transaction. [SOURCE: NAN — Ogwuma's tenure dates]

He had accomplices. Christian Ikechukwu Anajemba (killed in 1998), his wife Amaka Anajemba and Nzeribe Okoli all played roles in the operation. (Two lawyers, Emmanuel Ofulue and Obum Osakwe, were charged separately with trying to bribe the EFCC chairman — not with the fraud.) [SOURCE: Wikipedia citing multiple sources] The scale of a $242 million, multi-year deception required multiple people maintaining consistent stories across multiple jurisdictions.

Sakaguchi, for his part, appears to have been motivated by a genuinely extraordinary proposition — a $10 million commission on a transaction with the Nigerian government, mediated by the central bank governor. The commission alone was the kind of number that made due diligence feel like an insult to the relationship. The mark's psychology matters here not because Sakaguchi shares the blame — he does not — but because the fraud was engineered specifically to exploit the place where greed and institutional authority intersect. [SOURCE: brief; series principles]

The brief for this piece states the rule clearly: explain the mechanism, do not blame the victim. Sakaguchi was defrauded. The explanation for why a sophisticated banker paid $242 million to fraudsters is the same explanation for why Google and Facebook paid $122 million to a man with a fake invoice. The institution's verification process trusted the surface. The surface was carefully produced.

· PART TWO ·
$242 Million — How It Moved

Sakaguchi paid in stages across three years. The total was $191 million in direct cash transfers and the remainder — approximately $51 million — in the form of accrued interest on the original principal between 1995 and 1998. [SOURCE: NAN; EFCC reporting]

The payments moved through accounts structured to receive them — a multi-layered operation that routed money through multiple jurisdictions. By the time the fraud was discovered in late 1997 through the Santander acquisition process, a substantial portion of the funds had been dispersed. The Cayman Islands account that triggered the discovery held the dormant remainder that Noroeste's balance sheet had obscured from routine review.

The collapse of Banco Noroeste was the human consequence. After the fraud was uncovered, the Simonsen and Cochrane families — the owners of Banco Noroeste — paid the $242 million liability themselves to facilitate the Santander acquisition. The bank was absorbed into Santander Brasil in 1999. [SOURCE: Wikipedia citing sources; NAN]

The fraud triggered criminal investigations in Brazil, Britain, Nigeria, Switzerland, and the United States. Sakaguchi himself was later arrested at New York's JFK airport and dispatched to Switzerland to face charges relating to the bank accounts he had used as part of the transaction — in effect, a victim who also faced legal consequences in multiple jurisdictions for his role in creating the banking infrastructure through which the fraud moved. [SOURCE: Wikipedia citing sources]

FIGURE

WHAT IT MEASURES

$242 million

Total extracted from Sakaguchi — $191M cash + ~$51M accrued interest. [SOURCE: EFCC / NAN]

$191 million

Cash portion paid by Sakaguchi, 1995–1998. [SOURCE: NAN / EFCC]

25 years

Sentence imposed by Justice Joseph Oyewole, Ikeja High Court, 2005. [SOURCE: NAN; Guardian Nigeria]

~3 years in custody

Arrested June 2003; sentenced November 2005 to five concurrent five-year terms; released 2006. VERIFY the release date against the primary record.

3rd largest

Widely repeated description — 'third-largest bank fraud in history' at the time, after Barings and the Iraqi Central Bank. No original source found; treat as a description, not a finding.

· PART THREE ·
The Method — 419 at Origin Scale

The fraud is called 419 after Section 419 of the Nigerian Criminal Code, which makes advance-fee fraud a criminal offence. The designation is a legal fact about where the law was codified. It is not a characterisation of a country.

The 419 template — in its foundational form — has three elements: an authority figure, an extraordinary opportunity, and documentation that reproduces the surface of legitimacy. Nwude's operation ran all three at maximum scale.

The authority figure: the Governor of the Central Bank of Nigeria. Not a mid-level official. Not a fictional title. The highest-ranking monetary authority in Africa's most populous country, whose name and office were known to any serious financial institution operating in the region.

The extraordinary opportunity: a major infrastructure contract with a $10 million commission. The scale was designed to ensure that Sakaguchi would manage the relationship personally — at a level where due diligence was delegated downward and institutional checks were bypassed by the principals involved.

The documentation: forged correspondence on what purported to be Central Bank of Nigeria letterhead, supported by a contract for a facility that had been announced at the right institutional level to be plausible. [SOURCE: NAN; EFCC reporting] The airport in Abuja was not a random invention — Abuja was then Nigeria's new federal capital, and infrastructure development there was a credible government priority.

What the fraud did not require: hacking, malware, technical sophistication, or any computer capability beyond word processing. The entire $242 million extraction was accomplished with paper, a credible impersonation, and a mark who had every incentive to believe the deal was real.

() sent a spoofed email. () sent a fake invoice. Nwude sent a forged letter on official letterhead. The technique is identical across three decades and two continents. Only the medium changed. The exploit — authority asserted, paperwork attached, verification trusting the surface — has not been updated since 1995.

· PART FOUR ·
The Conviction — First Major EFCC Case

Emmanuel Nwude was convicted by the Ikeja High Court in 2005. The presiding judge was Justice Joseph Oyewole. The sentence was 25 years imprisonment. [SOURCE: NAN; Guardian Nigeria; The Cable]

The conviction was the first major prosecution for the Economic and Financial Crimes Commission — the EFCC, established by the Nigerian Parliament in 2002 at the request of President Olusegun Obasanjo specifically in response to the scale of advance-fee fraud emanating from Nigeria. [SOURCE: NAN] Nwude's case was not merely a landmark for its size; it was the founding conviction of Nigeria's primary anti-financial-crime institution.

He was arrested by the EFCC on June 4, 2003, and arraigned in February 2004. He pleaded guilty on November 18, 2005, and was sentenced to five years on each of five counts, to run concurrently — 25 years on paper, five in effect. He was released in 2006: about three years in custody. [SOURCE: ThisDay, November 2005; Financial Times, October 2008 — verify the release date against the primary record]

The plea came with a settlement: $110 million to be refunded to the bank and $11.5 million paid to the Federal Government from his companies, which were to be wound up, along with fourteen properties, six cars and more than 100 million shares. By 2008 the bank's lawyers reported about $138 million recovered across Nigeria, Switzerland, the US and the UK. [SOURCE: ThisDay, November 2005; ICC Commercial Crime Services]

After release, Nwude subsequently faced a 15-count charge for allegedly forging documents related to a property that Justice Oyewole had ordered him to forfeit to his victims — in effect, charged with fraud in the aftermath of a fraud conviction, relating to assets that were supposed to go to restitution. [SOURCE: NAN; The Cable] On March 11, 2026, a Lagos court convicted him on 13 of those 15 counts and sentenced him to one year on each. [SOURCE: PM News; Channels TV, March 2026] He was also reportedly arrested in 2016 on murder charges related to an attack on a town in Nigeria. [SOURCE: Wikipedia — verify primary]

· PART FIVE ·
The Sentence and the Outcome

The sentence was 25 years on paper — five five-year terms running at the same time. The outcome was about three years in custody.

This gap is the honest final note the brief asks for, and it is the same accountability question that runs through (, $4.3B company penalty, 4 months served, then pardoned) and (, $122M BEC, 5 years sentenced, released after sentence). In the Nwude case the gap is more extreme: a quarter-century sentence became a fraction of that, with the money substantially unrecovered.

Banco Noroeste did not survive as an independent bank. The families who owned it paid the $242 million liability out of their own assets to facilitate the Santander sale. The bank was absorbed into Santander Brasil in 1999. The restitution — whatever was returned through the plea arrangement — did not repair that outcome.

The series does not editorialize on this gap. It records it. The sentence and the time served are two different numbers. The loss and the recovery are two different numbers. Recording both is the minimum the victims of any fraud are owed by any account of what happened.

He is a living private individual. This piece reports the court record and the public record of his conviction. It does not speculate about his current circumstances beyond what the documented record establishes.

· PART SIX ·
What It Means — The Origin Document

Case 021 is where the BEC/advance-fee category begins. Not historically — the technique is older than Nigeria, older than banking — but in the documented series record that runs from (001) through (017) to this case, Nwude is the origin.

He is the proof that the exploit is not technical. It is psychological. Authority, once asserted convincingly, is treated as real by institutions built to verify authority. The check on authority is usually the letterhead, the title, the established relationship. When those can be reproduced, the check fails.

Every spam filter, every email authentication protocol (SPF, DKIM, DMARC), every vendor verification process that Google and Facebook implemented after the fraud — all of it is a response to the same problem Nwude ran in 1995 with a typewriter and a telephone. The digital defenses grew around a human vulnerability. The vulnerability has not changed.

The Nigerian Criminal Code's Section 419 gave the fraud its name not because Nigeria invented it but because Nigeria was where it was codified into law as a specific offense — a recognition that the technique had become organised at industrial scale. The EFCC, which Nwude's conviction inaugurated as a serious institution, exists for the same reason. The prosecution record is documented; the generalisation is not this piece's business.

He sold a banker an airport that did not exist. The letterhead said it was real, and for three years, for a quarter of a billion dollars, it was. Every scam email since is a cheaper print of the same page — authority asserted, paperwork attached, and a mark who wants to believe. The airport was never for sale. It never had to be.

VERIFIED SOURCES AND CORRECTIONS RECORD

EXTENSIVE VERIFICATION REQUIRED — this case has significant folklore in circulation. Brief contained two factual errors corrected above. State both the 25-year sentence AND the time actually spent in custody (about three years). No national stereotyping — the 419 reference is a legal fact, not a characterisation.

[1] NAN (News Agency of Nigeria) — court coverage, 2021: 'I didn't know how $242m got into my account.' Confirmed: Ikeja High Court, Justice Joseph Oyewole, 2005 conviction. Sentence: 25 years. $191M cash + remainder interest = $242M total. Sakaguchi as director of Banco Noroeste. Nwude's impersonation of Paul Ogwuma (CBN Governor, October 1993–May 1999).

[2] Guardian Nigeria — '$242m airport scam: I'm unaware of source of funds, Nwude tells court.' Same facts. EFCC described as: Nwude 'convinced a director of the bank, Nelson Sakaguchi, to buy a yet-to-be-built airport in Abuja for $242 million.' Third-largest bank fraud in history at time.

[3] The Cable — '$242m airport scam: I don't know anything about the money, says Nwude.' Reports the 15-count post-conviction charge for forging forfeited property documents. First major EFCC conviction confirmed.

[4] DMARGE — detailed reconstructed account: Santander acquisition December 1997 trigger; Cayman Islands dormant funds; the $10M commission; co-conspirators named; the end of Banco Noroeste (absorbed by Santander, 1999).

[5] Wikipedia — Emmanuel Nwude. Confirmed: 'Date apprehended: February 2004; released in 2006.' Title: Director of Union Bank of Nigeria (not CBN). Also: Sakaguchi arrested at JFK and dispatched to Switzerland. Nwude arrested on murder charges 2016. [Aggregator — verify all to primary]

CORRECTIONS TO BRIEF (1) EMPLOYER: Union Bank of Nigeria, not CBN. He impersonated Paul Ogwuma, CBN Governor. (2) AIRPORT: fictitious new airport in Abuja, not Murtala Muhammed International Airport. (3) TIME SERVED: about three years in custody (arrested June 2003, released 2006); the 25 years ran as five concurrent five-year terms.

TO VERIFY BEFORE PUBLICATION Exact birth date · Union Bank of Nigeria employment dates and title · Precise US court involvement (if any — this appears primarily to be a Nigerian prosecution) · Exact plea arrangement terms and amounts returned · Primary EFCC sentencing documents · The 2016 murder charge outcome · Co-defendant outcomes (Christian Anajemba reportedly assassinated — verify) · $110M offered to return (brief figure — not found in available sources)

SOURCES
[1] PRIMARY — EFCC / Lagos High Court conviction, November 18, 2005 (as reported)
[2] SECONDARY — ICC Commercial Crime Services: The Banco Noroeste Fraud
[3] SECONDARY — Misha Glenny, “The Banker and the Chief”, NZZ Folio (2009)
[4] SECONDARY — ThisDay, Vanguard, Guardian NG, Punch (2004–2006, via 419 Coalition archive)
[5] SECONDARY — Financial Times, October 31, 2008
[6] SECONDARY — PM News, March 12, 2026
[7] AGGREGATOR — Wikipedia: Emmanuel Nwude
END OF REPORT
#31 OF 45
Malone Lam
SINGLE PERSON
CASE 002 · CRYPTO / SOCIAL ENGINEERINGPLEADED GUILTY
Anne Hathaway · King Greavys · Awaiting sentence · status hearing Dec 8 2026
$230M
WHAT WAS TAKEN
4,100 bitcoin from one man's crypto wallet.
HOW
Callers posed as tech support and tricked the victim into giving up his wallet.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
Oct 2023Arrives in the US on the visa-waiver programme and moves between Miami, Los Angeles and the Hamptons.SOURCE: DOJ D.D.C.; case brief
2023–2024Runs the social-engineering crew with roommates in Texas; the group grows to 14 members.SOURCE: superseding indictment, May 2025
Aug 2024The 4,100 BTC heist from a single investor, live-streamed; the money goes into cars, watches, a Miami mansion and nightclubs within weeks.SOURCE: DOJ; case brief
18 Sept 2024Arrested by the FBI in Miami; his phone is thrown into Biscayne Bay.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
MALONE LAM YU XUAN
AKA ANNE HATHAWAY · KING GREAVYS · $$$ · CASE 002 · PLEADED GUILTY SEPTEMBER 2026
PRIMARY HEIST
$230M+ (4,100+ BTC)
TOTAL CONSPIRACY
$245M+
STATUS
Pleaded guilty
SENTENCING
Not yet scheduled · status hearing Dec 8, 2026
MAX EXPOSURE
20 years
AGE AT ARREST
20 years old
BORN
19 July 2004 · Singapore
HISTORIC FIRST
First Bitcoin RICO case ever
FULL PROFILE

IDENTITY

LEGAL NAME
Malone Lam Yu Xuan
BORN
19 July 2004 · Singapore
NATIONALITY
Singaporean citizen
EDUCATION
Eighth-grade dropout · Unity Secondary School, Choa Chu Kang (entered 2017)
BASE AT ARREST
Miami, Florida (multiple rented mansions) · also Los Angeles
ALIASES
Anne Hathaway · King Greavys / Greavy · $$$ · 7 · Kg
NETWORK ORIGIN
Online gaming platforms · network of young men in late teens and early 20s

CASE RECORD

PRIMARY HEIST
August 18, 2024 · Washington DC victim
CONSPIRACY RAN
October 2023 – May 2025
ARRESTED
September 18, 2024 · Miami, Florida
CO-ARRESTED
Jeandiel Serrano · same day · LAX
JURISDICTION
US District Court · District of Columbia
JUDGE
Hon. Colleen Kollar-Kotelly
CHARGE
RICO conspiracy · 18 U.S.C. §1962 · first Bitcoin RICO in US history
PLEA
Guilty · September 2026
SENTENCING
Not yet scheduled · status hearing December 8, 2026
TOTAL DEFENDANTS
18 charged · 11 pleaded guilty · 7 still pending
CASE TIMELINE
October 2023
The Network Forms
Malone Lam, a Singaporean teenager who had dropped out of school after the eighth grade, begins organizing a network of young men connected through online gaming platforms. Most are in their late teens and early twenties. The network divides labour: hackers obtain victim data from websites and the dark web; callers execute social engineering attacks impersonating customer service representatives; money movers launder proceeds through crypto mixers, exchanges, pass-through wallets, and VPNs. Lam is the organizer, identifying victims and coordinating conspirators.
SOURCE: DOJ superseding indictment May 2025 · US Attorney DC press release September 2026
August 18, 2024 — the heist
One Phone Call. 4,100 Bitcoin. $230 Million.
A Washington DC resident — identified in court filings as "Victim 7," a wealthy longtime cryptocurrency investor and Genesis creditor — receives a phone call from someone identifying themselves as a Google support representative. A second caller, claiming to be from Gemini exchange, warns of a malware attack on the victim's crypto wallet. The callers — Lam, Jeandiel Serrano, and Veer Chetal — manipulate the victim into granting Google Drive access, revealing security codes, and using screen-sharing software that exposes private keys. More than 4,100 Bitcoin — valued at over $230 million — is siphoned from the victim's wallet. A private recording captures the moment Lam and his friends realize the scale of what they just stole. They live-streamed the heist to friends online. The entire operation was a phone call.
SOURCE: DOJ criminal complaint September 2024 · Boston Globe September 2026 · ZachXBT blockchain investigation
August 18 – September 18, 2024
Thirty Days. Thirty-One Cars.
In the thirty days between the theft and his arrest, Lam spends hundreds of thousands of dollars per night at nightclubs in Los Angeles and Miami. He purchases 31 luxury vehicles — custom Lamborghinis, Ferraris, and Porsches — including a Pagani Huayra for $3.8 million and a Lamborghini Revuelto for over $1 million. He buys a watch for $2 million. He rents multiple high-end homes in Miami — one mansion costs $68,000 per month. He gives out Hermès bags to models and influencers at clubs. He flies between cities on private jets. He runs up tabs of $500,000 in a single night. Co-conspirator Jeandiel Serrano, identified by the time he vacations in the Maldives, rents an Encino, California home for $47,500 per month and is arrested at LAX wearing a $500,000 watch. As of October 2024: 22 of Lam's 31 vehicles remain unaccounted for. Over $100 million of the stolen Bitcoin remains unrecovered.
SOURCE: CNBC October 2024 · NBC News · Malay Mail · DOJ court filings
September 18, 2024
Arrested — Miami. Phone Into Biscayne Bay.
FBI agents move to arrest Lam at his Miami mansion. Before they arrive, Lam is warned of his impending arrest by an off-duty law enforcement officer. He throws his mobile phone into Biscayne Bay. He is apprehended the same day. On the same day across the country, Serrano is taken into custody at Los Angeles International Airport, where agents find him wearing a watch worth approximately $500,000. The following day, the US Attorney's Office for the District of Columbia unseals indictments against both men. The DOJ describes the case as one of the largest cryptocurrency thefts from a private individual in US history.
SOURCE: DOJ press release September 2024 · NBC News · Wikipedia
May 2025
Superseding Indictment — RICO — 12 More Defendants
Federal prosecutors expand the case into a full RICO conspiracy indictment, charging 12 additional defendants and documenting more than $263 million in cryptocurrency stolen and laundered across the enterprise. The network continued operating until May 2025, months after Lam's arrest. Total defendants: 18. The RICO charge is the first Bitcoin-related Racketeer Influenced and Corrupt Organizations Act prosecution in US history.
SOURCE: DOJ superseding indictment May 2025 · CoinTelegraph
September 2026
Guilty Plea — RICO Conspiracy
Malone Lam pleads guilty in US District Court, Washington DC, to participating in a RICO conspiracy that stole and laundered more than $245 million in cryptocurrency. He is the 11th of 18 defendants to plead guilty. US Attorney Jeanine Ferris Pirro: "If you build a cybercrime empire, we will find you, dismantle your operation, and hold you accountable." Lam faces a maximum of 20 years. Sentencing guidelines suggested at least 14 years. A status hearing was set for December 8, 2026; no sentencing date has been scheduled.
SOURCE: DOJ press release September 2026 · NBC News · Forbes
HOW THE FRAUD WORKED

SOCIAL ENGINEERING METHODOLOGY — THREE ROLES

01
Reconnaissance: Hackers within the network obtain victim data from websites and the dark web. Targets are identified as wealthy, longtime cryptocurrency holders with significant holdings in accessible wallets. Victim 7 was a Genesis creditor — publicly known to hold substantial crypto assets.
02
First call — Google impersonation: A caller posing as a Google support representative contacts the victim, claiming to have detected unauthorized attempts to breach the victim's account. The call establishes urgency and positions the callers as helpers, not attackers. Trust is established before the attack begins.
03
Second call — Gemini impersonation: A second caller, posing as Gemini exchange security, warns the victim of a malware attack threatening the victim's crypto wallet. The victim is instructed to reset two-factor authentication and use screen-sharing software to "verify" the threat. The screen-share exposes private keys.
04
Extraction: Private keys and security codes obtained through the calls allow Lam and co-conspirators to drain the wallet. More than 4,100 Bitcoin — $230M+ at time of theft — is transferred within the call. No hacking of systems. No malware. Pure manipulation of human verification processes.
05
Laundering: Stolen Bitcoin is moved through crypto mixers, peer-to-peer exchanges, pass-through wallets, and VPNs to obscure the trail. Proceeds are converted to fiat and luxury assets. Over $100M remains unrecovered as of late 2024. Serrano was caught when he failed to conceal his IP address on an exchange holding $30M in stolen funds.
ATTACK CHAIN — VICTIM 7
Victim identified
(Genesis creditor)
→
Google spoof call
(trust established)
→
Gemini spoof call
(screen share)
→
Private keys exposed
4,100 BTC drained
→
Mixers / exchanges
laundered
KNOWN NETWORK & CO-CONSPIRATORS
PRIMARY CO-CONSPIRATOR · CALLER / LAUNDERERCHARGES PENDING
Jeandiel Serrano
VersaceGod · @SkidStar · Age 21 at arrest · Los Angeles
Arrested September 18, 2024 at LAX wearing a $500,000 watch. Rented Encino CA home for $47,500/month. Was vacationing in the Maldives when first identified by investigators. Had approximately $20M of victim's stolen Bitcoin on his phone at arrest. Failed to conceal IP address while creating exchange account holding ~$30M in stolen funds — this traced the operation. Charges remain pending as of September 2026.
SOURCE: CNBC Oct 2024 · DOJ filings
CO-CONSPIRATOR · HEIST CALLERPLEADED GUILTY
Veer Chetal
On the call during the August 18 heist
Participated in the social engineering calls on the day of the primary heist. Pleaded guilty to conspiracy charges November 2024. Awaiting sentencing as of September 2026.
SOURCE: Boston Globe Sep 2026 · DOJ
CO-CONSPIRATOR · MONEY LAUNDERERSENTENCED
Evan Tangeman
Money laundering role within the enterprise
Sentenced to 70 months (approximately 6 years) in April 2026 for money laundering in connection with the conspiracy. One of the first co-defendants sentenced in the case.
SOURCE: KuCoin / Phemex news reports · DOJ
CO-CONSPIRATOR · EVIDENCE DESTRUCTIONSENTENCED
Tucker Desmond
Destroyed evidence of co-conspirators' crimes
Pleaded guilty to destroying evidence connected to the conspiracy. Sentenced to probation. At sentencing: "I got obsessed with the image of success rather than actually becoming a hard-working individual myself."
SOURCE: Boston Globe Sep 2026 · DOJ sentencing records
CO-DEFENDANTS · NAMED IN DOJ FILINGSCHARGES PENDING
Hamza Doost & Kunal Mehta
Named in DOJ court filings alongside photograph of Malone Lam
Named defendants in the wider RICO conspiracy. Status of charges pending as of September 2026. Seven defendants in the overall case of 18 still face unresolved charges.
SOURCE: AP / Fox News court filing photographs Sep 2026
DOCUMENTED SPENDING — 30 DAYS AFTER THE HEIST

ASSET RECORD — SOURCED FROM DOJ COURT FILINGS

VEHICLES
31 luxury cars purchased (22 still unaccounted for as of Oct 2024) · custom Lamborghinis, Ferraris, Porsches · SOURCE: DOJ / Malay Mail
PAGANI HUAYRA
$3,800,000 · not located as of court filings · SOURCE: CNBC Oct 2024
LAMBORGHINI REVUELTO
$1,000,000+ · SOURCE: DOJ court filing
WATCH
$2,000,000 · SOURCE: DOJ / Boston Globe
MIAMI MANSION
$68,000/month rental · multiple Miami properties · SOURCE: CNBC Oct 2024
NIGHTCLUB SPEND
Hundreds of thousands of dollars per night in LA and Miami · $500,000 single-night tabs · SOURCE: Malay Mail / CNBC
HERMÈS BAGS
Distributed to models and influencers at clubs · SOURCE: Malay Mail Mar 2025
SERRANO WATCH
~$500,000 · worn at time of arrest at LAX · SOURCE: CNBC Oct 2024
RECOVERED / FROZEN
~$70M as of October 2024 · SOURCE: Malay Mail
STILL UNACCOUNTED
$100M+ as of October 2024 · SOURCE: CNBC / DOJ filings

WHAT THIS CASE ESTABLISHED

The largest known single-victim cryptocurrency heist in US history — one phone call, one victim, $230M. SOURCE: DOJ
The first Bitcoin-related RICO prosecution in US history. The conspiracy model now applies to organised cryptocurrency theft. SOURCE: Wikipedia / DOJ
Social engineering requires zero technical skill from the caller — impersonation and manipulation of legitimate security procedures is the entire attack surface.
The spending spree — 31 luxury cars, $3.8M Pagani, $2M watch, $68,000/month mansions — began within hours of the theft and generated its own forensic evidence trail.
Blockchain forensics (ZachXBT) publicly identified the victim category before law enforcement confirmed it — on-chain analysis is now an independent investigative layer.
The network was built on gaming platforms among teenagers and twenty-year-olds — organised crime with a Discord energy and RICO consequences.
THE FULL STORY — 12 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE (3,700 WORDS)
Sources: DOJ/US Attorney DC press releases (Sept 2024, Nov 2025, Sept 2026) · IRS Criminal Investigation · FBI arrest · NBC News · CNBC · NYT · BBC · Straits Times · Malay Mail · ZachXBT/@zachxbt · Courthouse News · Case: 24-CR-417 (CKK), D.D.C. Every figure traces to a named source. Dollar amounts labelled by what they measure. This is an active case — Lam has pleaded guilty but has not yet been sentenced as of this writing.
· PROLOGUE ·
$569,528.39

That is a real number. It is not a monthly rent, a car price, or an investment. It is a receipt from a single night at a nightclub in Los Angeles.

One night. One club. $569,528.39 spent — documented in a court filing, sourced to the club's management, submitted as evidence by federal prosecutors. [SOURCE: NBC News / DOJ filing]

The man who ran up that tab was twenty years old. He had arrived in the United States fourteen months earlier on a tourist visa from Singapore. He had no job, no degree, and no source of income that could be explained to a tax authority.

He had, however, recently stolen 4,100 Bitcoin from a single investor in Washington D.C. — a theft that authorities would describe as the largest known single-victim cryptocurrency heist in history. The Bitcoin was worth approximately $230 million at the time of the theft. [SOURCE: NYT, Sept 2024; DOJ]

He spent it as fast as he could. He was arrested within a month.

· PART ONE ·
Choa Chu Kang — The Boy From the HDB Block

The neighbourhood of Choa Chu Kang sits in the western reaches of Singapore, a planned residential town of Housing Development Board flats, hawker centres, and the particular density of a city that fits six million people into seven hundred square kilometres.

Malone Lam Yu Xuan was born there on July 19, 2004. He attended Unity Secondary School in the same neighbourhood, part of the ordinary infrastructure of Singaporean education — a system that routes its students through standardised examinations toward university or polytechnic, toward careers in finance, engineering, or the professions.

He dropped out in his teens.

What he did instead was go online. The platforms were Minecraft and Discord — the spaces where a generation of young men with internet connections and time on their hands built their first social worlds, learned to read communities, and discovered that the online economy ran on different rules than the one outside.

He was good at reading those rules. By the time he was a teenager he was trading cryptocurrency — not as a hobby but as a primary activity, with the focus of someone who had decided that this was the path and everything else could wait.

By the time he was nineteen, he had decided that earning it was slower than taking it.

In October 2023, Malone Lam boarded a flight to the United States. He entered on the Visa Waiver Program — no interview, no sponsor, no questions that mattered. He arrived in Miami, moved through Los Angeles, touched the Hamptons. He started with two roommates in Texas. He had a plan.

· PART TWO ·
The Operation — How You Steal $230M Without Touching a Blockchain

The blockchain was not broken. It never is, in cases like this. What Malone Lam and his associates broke was something far older and more reliable than cryptography: human trust.

Social engineering is the technical term for what the group did. The plain English version: they called people and convinced them to hand over their money by pretending to be people they were not.

The target in August 2024 was a wealthy early Bitcoin investor in Washington D.C. — a Genesis creditor whose holdings had been accumulating since the early days of the network, some of the Bitcoin reportedly dormant since 2012. [SOURCE: ZachXBT/@zachxbt; DOJ] The kind of investor whose wallet, if you could access it, represented a number most people would not see in a lifetime.

In August 2024, the scheme reached its peak. More than 4,100 Bitcoin transferred from a single investor. Worth approximately $230 million at the time. The largest known single-victim cryptocurrency theft in history. [SOURCE: Courthouse News, Oct 2024; DOJ]

Lam and his co-conspirator Jeandiel Serrano celebrated. They did not do this quietly.

They live-streamed it. On a Discord voice chat, to friends, they watched the Bitcoin arrive. 'Oh my god! 243 million dollars! Yes!' [SOURCE: ZachXBT; reported by NYT, NBC News] During the stream, one participant's screen inadvertently displayed his real Windows username. A separate recording showed another participant being referred to by his first name. These were the threads that would unravel everything.

· PART THREE ·
The Spending — $569,528.39 in One Night

He did not hide the money. He displayed it. With the same instinct that drove to post every watch, every car, every front row — Malone Lam converted 4,100 Bitcoin into the most visible lifestyle money could buy, as fast as it was physically possible to spend it.

Within weeks of the theft, he was in Los Angeles. The clubs in LA told investigators that Lam had been trying to pay his tabs in cryptocurrency and was spending approximately $400,000 to $500,000 per night. [SOURCE: NBC News / DOJ filing] One receipt entered into evidence showed a single night's tab of $569,528.39. [SOURCE: NBC News / court filing]

He bought 31 luxury vehicles. [SOURCE: DOJ — prosecutors' own figures] Among them:

The prosecution noted that 'many of Lam's vehicles have not been located as of yet, such as his Pagani Huayra that he purchased for $3,800,000.' [SOURCE: NBC News quoting DOJ filing] Twenty-two of the thirty-one cars remained unrecovered. The money had physically disappeared into metal and carbon fibre and been driven away.

· PART FOUR ·
The Birkins, the Lamborghini, and the Woman Who Said No

The Hermès Birkin is a handbag that starts at approximately $10,000 for the most basic configuration and climbs from there — to $20,000, to $50,000, to prices that require an invitation from the house to spend. It is an object that carries its price in its scarcity, its waitlist, its deliberate exclusivity.

Malone Lam gave them away at nightclubs.

Five Hermès Birkin bags, worth approximately $20,000 each, handed to women he met at clubs. [SOURCE: The Droid Guy reporting on DOJ filing] Not as gifts in the romantic sense — as favours, as calling cards, as the currency of a man who had decided that money was the language and he was fluent.

One woman reportedly received a Birkin after chatting with him for ten minutes. Another found one on her nightstand. The bags were sourced, paid for, and distributed as casually as most twenty-year-olds buy rounds of drinks.

Then there was the Lamborghini.

A pink Lamborghini Urus. Gifted — or attempted to be gifted — to a woman on Instagram as a means of winning her back or winning her over, the record is not precise on which. Her response, documented in reporting: 'I am taken once again.' [SOURCE: The Droid Guy] The car, reportedly, was still sent. She still declined. The Lamborghini sat somewhere, ungifted, as a monument to the specific failure of money to solve problems that money did not create.

And then there were the Birkins sent to his girlfriend after he was arrested.

This is documented in the IRS Criminal Investigation press release and the DOJ superseding indictment. Following his arrest in September 2024, while in pretrial detention, Lam allegedly continued working with members of the enterprise — directing them to buy luxury Hermès Birkin bags and hand-deliver them to his girlfriend in Miami, Florida. [SOURCE: IRS/DOJ Nov 2025 press release; DOJ superseding indictment]

He was in a detention cell. He was still ordering Birkins. From prison. For delivery. To Miami.

· PART FIVE ·
The Mansion — $68,000 a Month and a View of Biscayne Bay

On September 10, 2024, Malone Lam boarded a private jet from Los Angeles to Miami. He had spent weeks in LA accumulating receipts, cars, and attention. Now he moved the operation to Florida.

In Miami, he rented multiple homes. One was on Hibiscus Island — a private island in Biscayne Bay accessible only by a guarded causeway, where the houses sit behind gates and the water is visible from every window. Another was near the water. A third was a luxury mansion with ten bedrooms and ten bathrooms — the kind of property typically used, the reporting notes, by actors, businessmen, and politicians. [SOURCE: The Droid Guy / NBC News]

The monthly rent on one of the Miami properties: $68,000. [SOURCE: NBC News / DOJ filing — Malay Mail]

He was twenty years old. He had been in the United States for less than a year. His visa had expired.

The enterprise was not just renting property in his own name. Co-conspirators obtained luxury rental homes for members of the enterprise using fake identity documents. [SOURCE: IRS/DOJ superseding indictment] They booked private jet travel with stolen cryptocurrency. They concealed ownership of exotic cars by registering them in shell company names. They shipped bulk cash through US mail to members of the enterprise — hidden inside Squishmallows stuffed animals. [SOURCE: DOJ superseding indictment, Nov 2025]

The Squishmallows detail is in the federal indictment. Bulk cash, mailed across the country, packed into stuffed animals.

· PART SIX ·
The Network — 14 People, Six States, One Enterprise

It started with two roommates in Texas.

By the time the superseding indictment was filed in November 2025, the network had grown to Lam plus twelve others — fourteen people in total, operating across California, Connecticut, New York, Florida, and overseas. [SOURCE: DOJ superseding indictment Nov 2025; IRS Criminal Investigation]

The enterprise had specialised roles. Some members ran the unlicensed crypto-to-cash conversion services that turned stolen Bitcoin into spendable dollars. Others obtained the rental properties using fake identities. Others booked the private jets. Others — this is in the indictment — hid the cash in the stuffed animals and mailed it.

The operation had gone from two roommates to a structured criminal enterprise with a supply chain, a logistics function, and a money laundering operation that the DOJ would ultimately charge under RICO — the Racketeer Influenced and Corrupt Organizations Act. The first Bitcoin-related RICO case in American legal history. [SOURCE: DOJ Sept 2026 press release; BBC]

In July 2024, the group expanded into physical crime. Marlon Ferro traveled to New Mexico and broke into a victim's home to steal their hardware cryptocurrency wallet while Lam monitored the victim's location by logging into their iCloud account remotely. [SOURCE: DOJ indictment] They had gone from calling people to burglary. The network was arming itself.

· PART SEVEN ·
ZachXBT — The Man Who Watched the Blockchain

While Malone Lam was spending $569,528 in a single night at an LA club, a pseudonymous blockchain investigator who goes by ZachXBT was watching the Bitcoin move.

ZachXBT is a former crypto scam survivor who became, by reputation, the most effective private blockchain forensics investigator in the industry. He operates under a pseudonym, has never revealed his real name, and maintains a following of hundreds of thousands of people who track his work exposing fraud in the cryptocurrency space. He is, in the context of this case, the person the story turns on.

On the day of the August 2024 theft, ZachXBT was in transit when he saw the blockchain movement. He began tracking. The stolen funds split into three main flows — he identified three suspects. He posted publicly on X (formerly Twitter) that a theft was occurring. He received a tip from an informant with leads on the hacker's identity. For the following week he worked through the night, sleeping four to five hours a day, sharing his findings directly with law enforcement. [SOURCE: ZachXBT reporting compiled by Chaincatcher/Bitget; ZachXBT @zachxbt on X]

Then he found the video.

A 90-minute recording of the Discord session during the heist — the voice chat in which Lam, Serrano, and others had celebrated as the Bitcoin arrived. During the stream, one participant's Windows screen had briefly displayed his real username. People on the call referred to others by their first names. 'Oh my god! 243 million dollars! Yes!' [SOURCE: ZachXBT; reported by multiple outlets including TradingView News, NYT]

ZachXBT posted the recording. He identified three suspects. He shared everything with law enforcement.

The mechanism of exposure was the same mechanism that had made vulnerable: the compulsion to share the moment. To have an audience for the win. To let people see. Lam and Serrano had streamed themselves committing the largest single-victim cryptocurrency theft in history, and that stream had been obtained, posted publicly, and delivered to the FBI by a man on a plane watching the blockchain move in real time.

· PART EIGHT ·
The Phone in the Bay

On September 18, 2024, an off-duty police officer tipped off Malone Lam that the FBI was coming.

What he did with this information: he threw his mobile phone into Biscayne Bay. [SOURCE: Wikipedia citing primary reporting; DOJ record] Not into a bin, not wiped and handed to a friend, not left in a hotel room. Into the water. Biscayne Bay, which is a body of water, into which he threw the device that contained whatever he believed the FBI most needed to find.

The FBI arrived at the mansion on Hibiscus Island anyway. Lam was there. He was arrested. The phone was in the bay.

Jeandiel Serrano was arrested the same day at Los Angeles International Airport — returning from a holiday in the Maldives with his girlfriend. [SOURCE: Malay Mail / DOJ]

The network continued operating without them. Through the autumn of 2024, through the winter, through the spring of 2025. The superseding indictment in May 2025 named Lam plus twelve others. By May 2026, nine of the thirteen defendants had pleaded guilty. Some agreed to testify against Lam. [SOURCE: DOJ press release May 2026]

And Lam, in pretrial detention, allegedly continued directing the enterprise from inside. The Birkins sent to his girlfriend in Miami were not an act of romance. They were evidence, documented in a federal indictment, that he was still running the operation from a detention cell. [SOURCE: IRS/DOJ Nov 2025]

· PART NINE ·
The Numbers — Seven Figures for One Case

This is the case that explains why the METRIC row exists on every TraceChain card.

The lesson: 4,100 Bitcoin from one victim is the only figure that does not change depending on when you measure it. Every dollar figure in this case is a dollar figure measured at a specific moment on a specific exchange. Lead with the BTC. Label the dollars.

· PART TEN ·
The Plea — First Bitcoin RICO in History

On September 8, 2026, Malone Lam Yu Xuan pleaded guilty in the US District Court for the District of Columbia to RICO conspiracy.

The charge — the Racketeer Influenced and Corrupt Organizations Act — was not designed for cryptocurrency. It was designed for organised crime. For the Mafia. For enterprises that operate as ongoing criminal organisations across multiple states, with structured roles and coordinated operations. The DOJ determined that what Lam had built, in less than two years from two roommates in Texas, qualified. [SOURCE: DOJ Sept 2026 press release; BBC]

It was the first Bitcoin-related RICO prosecution in American legal history.

The DOJ press release was headlined: 'Singaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty.' [SOURCE: DOJ/US Attorney DC, Sept 8, 2026]

Lam appeared in court in a green prison jumpsuit. A status hearing was scheduled for December 2026. He has not yet been sentenced as of this writing. He faces up to 20 years. [SOURCE: DOJ; Malay Mail]

· PART ELEVEN ·
Singapore's Reaction — The Kid Who Left and Didn't Come Back

Singapore is a country with a specific relationship to crime and consequence. The legal system is strict, the consequences are public, and the national mythology around meritocracy and order runs deep enough that a twenty-year-old from a Choa Chu Kang HDB block committing the largest single-victim cryptocurrency theft in history and spending it in Hollywood nightclubs was not a story the country could process quietly.

The Straits Times — Singapore's newspaper of record — covered the case extensively, running multiple stories at different dollar figures as the investigation developed. The Business Times reported on the plea. The coverage was not congratulatory. It was, in its own way, a reckoning with what it meant that one of their own had left, had reached, and had been caught.

He was, by most measures, a dropout from a respectable neighbourhood who had found a way to make the system irrelevant to him. The school he had left — Unity Secondary — is not a school that produces criminals. It produces engineers, managers, the ordinary working population of a city-state built on competence and order.

He found a different order. It lasted fourteen months in the United States before the blockchain gave him up.

· PART TWELVE ·
What It Means — The Second Chapter of the Same Story

was about the flex as evidence. posted his way into a federal case file. He turned his Instagram into the prosecution's exhibit list.

Case 002 is the same story told in a different register. Malone Lam did not build an Instagram persona over nine years. He was twenty years old. He had no patience for nine years of careful brand-building. He had 4,100 Bitcoin and a phone and the specific generational instinct to share the moment — to stream it, to show it, to let the people in the Discord chat see.

The live-stream of the heist. The Discord where people referred to each other by name. The Instagram posts that let ZachXBT track his location through his girlfriend's location tags. The $569,528 receipt that is now a court exhibit. The Squishmallows stuffed with cash. The pink Lamborghini.

Every element of the story is evidence. Every element of the evidence was content.

In , the persona was built over years and then dismantled by the prosecution. In Case 002, the persona lasted months — barely long enough to buy all the cars. The speed compressed the arc but did not change its shape. The instinct was identical: to take the money and make it visible, to have an audience for the arrival, to let the world see what you had reached.

sat in the front rows of Paris fashion weeks and built a brand that 2.5 million people believed in for nine years before the FBI arrived.

Malone Lam threw a phone into Biscayne Bay and was arrested within a month.

· EPILOGUE ·
The Receipt

$569,528.39.

One night. One club. One receipt that is now a line in a federal court filing in the District of Columbia. [SOURCE: NBC News / DOJ]

The Pagani Huayra is somewhere. Twenty-two of the thirty-one cars have not been located. The phone is in Biscayne Bay. The Birkins were delivered to a woman in Miami by people following instructions from a detention cell. The Bitcoin is partly recovered — approximately $70 million frozen or recovered as of October 2024 — and the rest is still in the trail. [SOURCE: Malay Mail / DOJ]

He was twenty years old when he stole it. He will not be free for most of his twenties.

The blockchain detective who caught him was on a plane when the Bitcoin started moving. He posted his findings publicly. He worked through the night. He found the video of two men celebrating in a Discord call. He delivered the evidence to the FBI.

Twenty-two cars still missing. One phone in the bay. A girl who said no to the Lamborghini. Nine co-defendants who said yes to the prosecutors.

VERIFIED SOURCES

All figures labelled by what they measure. Dollar amounts vary by source — see Part 9. The stable anchor throughout is 4,100 BTC from one victim. Lam has pleaded guilty; sentencing has not yet occurred as of this writing.

[1] DOJ — RICO PLEA US Attorney DC press release, Sept 8, 2026: 'Singaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty.' Case: 24-CR-417 (CKK), D.D.C.
[2] DOJ — SUPERSEDING INDICTMENT US Attorney DC press release, Nov 2025: '$263 Million' RICO conspiracy; 13 defendants named.
[3] IRS CRIMINAL INVESTIGATION Press release, Nov 28, 2025: '$263 million' figure; Birkin bags delivered to girlfriend in Miami confirmed in this filing.
[4] FBI Arrest of Malone Lam, Sept 18, 2024, Miami. Phone thrown into Biscayne Bay; off-duty officer tip confirmed in reporting.
[5] NEW YORK TIMES '2 Stole $230 Million in Cryptocurrency…' (Sept 20, 2024); 'They Stole a Quarter-Billion in Crypto and Got Caught Within a Month' (Apr 25, 2025).
[6] NBC NEWS 'Historic bitcoin theft tied to Connecticut kidnapping, luxury cars, $500K bar bills.' Contains the $569,528.39 single-night club receipt from DOJ filing. Pagani Huayra price, 22 unrecovered vehicles, $68K/month mansion rent.
[7] CNBC 'Bitcoin RICO: Feds say $265 million crypto theft ring blew $13M on exotic cars, nightclubs' (May 15, 2025).
[8] BBC 'Singaporean man pleads guilty in US to massive crypto heist' — RICO precedent confirmed.
[9] STRAITS TIMES Mar 10, 2025 ($306M); Mar 16, 2025 ($320M). $665,000/night figure; 30+ cars.
[10] MALAY MAIL Full breakdown of spending; $68K/month rent; Serrano arrested at LAX returning from Maldives; $70M recovered figure.
[11] ZACHXBT / @zachxbt Discovery of Discord live-stream; blockchain tracing; identification of three suspects; 'Oh my god! 243 million dollars!' quote from the stream. Reported by NYT, NBC, TradingView News, multiple outlets.
[12] COURTHOUSE NEWS 'One of largest single victim thefts in history' — Oct 22, 2024.
[13] THE DROID GUY Birkin bags ($20K each) given at clubs; pink Lamborghini Urus for woman on Instagram; 'I am taken once again' response; 10-bedroom mansion description.
[14] BLOOMBERG 'Accused Crypto Hacker Becomes an Overnight TikTok Celebrity' (Oct 2, 2024).
END OF REPORT
#32 OF 45
Albert Gonzalez
SINGLE PERSON
CASE 011 · CARD / BANK FRAUDRELEASED 2023
segvec · soupnazi · j4guar17 · 20 years · released 2023
~$200M+
WHAT WAS TAKEN
170 million credit and debit card numbers. The TJX breach alone cost stores and insurers ~$200M.
HOW
Hacked store networks and sold the stolen card numbers.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2003Arrested for hacking and turned into a Secret Service informant.SOURCE: DOJ; case brief
2005–2007From Miami, runs the intrusions into TJX, Heartland, Hannaford and 7-Eleven while still informing for the government.SOURCE: indictments, D. Mass. and D.N.J.
2000–2003Moves to New York, then Kearny; leads the ShadowCrew carding forum under the name CumbaJohnny.SOURCE: case brief
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
ALBERT GONZALEZ
segvec · soupnazi · CASE 011 · CARD / BANK FRAUD · RELEASED 2023
CARDS STOLEN
170 million
METRIC
Card & debit numbers stolen — NOT a dollar figure
LARGEST BREACH
Heartland Payment Systems — 130M cards
SENTENCE
20 years · March 25, 2010
SERVED
~13 years · released 2023
STATUS
RELEASED 2023
BORN
1981 · Cuba · raised Miami
ROLE BEFORE
US Secret Service cooperating informant
METRIC: 170 million is a count of card and debit numbers stolen — NOT a dollar figure. Each number represents a person’s financial identity. Dollar losses from downstream fraud are not quantified in the court record in a single figure. This is a card count case, not a dollar loss case.
FULL PROFILE

IDENTITY

NAME
Albert Gonzalez
HANDLES
segvec · soupnazi · j4guar17 · CumbaJohnny · kingchilli · stanozlolz
BORN
1981 · Cuba · raised Miami, Florida
SCHOOL
South Miami High School — led the “computer nerds”
FIRST HACK
NASA — age 14
COMMUNITY
ShadowCrew — online carding marketplace — 1.5M card numbers
INFORMANT ROLE
US Secret Service cooperating source from 2003

CASE RECORD

INDICTMENTS
3 separate: New York (Dave & Buster’s, May 2008) · Massachusetts (TJX, May 2008) · New Jersey (Heartland, Aug 2009)
TJX
TJ Maxx / Marshalls / HomeGoods — 45.6M cards over 18 months
HEARTLAND
130M cards — single largest breach in the set
HANNAFORD
4.6M cards
METHOD
SQL injection → network foothold → packet sniffing → ARP spoofing → card data intercepted in transit
PLEA
Guilty · September 11, 2009
SENTENCED
20 years · March 25, 2010 [SOURCE: NYT/Reuters]
RELEASED
2023 · served ~13 years
THE DOUBLE LIFE

BRIEFING THE AGENTS WHO WERE HUNTING HIM

“Government informant is called kingpin of largest U.S. data breaches.”
Computerworld, August 2009 — when the third indictment dropped

The Secret Service recruited Gonzalez as a cooperating source after his 2003 arrest. He briefed agents on the carding ecosystem — the forums, the methods, the markets. He was useful. He was real. He was providing genuine operational intelligence that led to arrests of other people in the ecosystem. And then he went home and ran the largest version of the operation he had just described. Every briefing was an autobiography with the identifying details edited out.

He is the only person in this series who was inside the investigation while it was looking for him. Not separate from it — inside it. The photograph the Secret Service used for the target was taken before 2009, when he was on file as an asset.

CASE TIMELINE
1981
Born, Cuba
raised Miami
SOURCE: case brief (sources listed in its SOURCES part)
~1993
First computer, aged 12
SOURCE: case brief (sources listed in its SOURCES part)
~1995
Hacks NASA at 14
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
South Miami High School
"troubled" leader of the computer nerds
SOURCE: case brief (sources listed in its SOURCES part)
2000
Moves to New York City (3 months), then Kearny, New Jersey
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
ShadowCrew
accused mastermind (screen name "CumbaJohnny"); trafficked 1.5M card/ATM numbers
SOURCE: case brief (sources listed in its SOURCES part)
2003
Busted for hacking → becomes a cooperating informant
SOURCE: case brief (sources listed in its SOURCES part)
2005–2007
The theft spree
TJX, Heartland, Hannaford, Dave & Busters, 7-Eleven ATMs
SOURCE: case brief (sources listed in its SOURCES part)
May 2008
Indictment #1
NY, Dave & Busters case
SOURCE: case brief (sources listed in its SOURCES part)
May 2008
Indictment #2
Massachusetts, TJX/TJ Maxx case
SOURCE: case brief (sources listed in its SOURCES part)
Aug 2009
Indictment #3
New Jersey, Heartland Payment case
SOURCE: case brief (sources listed in its SOURCES part)
Sept 2009
Pleads guilty (Secret Service "TJX" case)
SOURCE: case brief (sources listed in its SOURCES part)
25 Mar 2010
Sentenced to 20 years federal prison
SOURCE: case brief (sources listed in its SOURCES part)
2023
Released
SOURCE: case brief (sources listed in its SOURCES part)
HOW THE FRAUD WORKED

HOW IT WORKED — FROM THE CASE BRIEF

01
SQL injection: against corporate web-facing systems → gained a foothold
02
Deployed backdoors to keep access
03
Moved laterally into internal corporate networks
04
Ran packet sniffing / ARP spoofing to capture card data in transit
05
Exfiltrated and resold the numbers
06
Why it matters defensively: every step above has a standard control. That's the lesson — not the method.
DEFENSIVE LEVEL ONLY · THE SHAPE OF THE SCHEME, NOT A PLAYBOOK
KNOWN NETWORK & CONNECTED CASES

WHAT THIS CASE ESTABLISHED

170 million card numbers — the largest card data theft prosecution in US history at the time. Card count, not a dollar figure. The metric matters.
The entry point for every major breach was SQL injection — a well-understood vulnerability with well-understood defences, deployed against companies that had not taken the basic precautions.
A cooperating informant simultaneously operated at the highest level of the crime they were helping investigate. The federal system’s oversight mechanisms failed to detect it across multiple years and multiple breaches.
Three simultaneous federal prosecutions across three jurisdictions — New York, Massachusetts, New Jersey — for crimes committed by the same person during the same period while cooperating with federal law enforcement.
His case accelerated adoption of EMV chip cards, point-to-point encryption, and stronger PCI DSS enforcement. The payment security auditor’s standard example for why controls matter.
Series thesis, Case 011: The Informant. He taught the investigators how it worked. He was the best at it. They were the same thing at the same time.
BACKGROUND & BIOGRAPHY

EARLY LIFE & CAREER

FULL NAME
Albert Gonzalez
BORN
1981 · Miami, Florida
BACKGROUND
Cuban-American · grew up Miami · self-taught hacker from teenage years
EARLY HACKING
Became leader of ShadowCrew — major carding and identity theft forum
THE PIVOT
Arrested 2003 · flipped by Secret Service · became cooperating informant code-named 'Cumber'
DOUBLE LIFE
While working AS a Secret Service informant, continued hacking major US retailers
THE TECHNIQUE
SQL injection attacks · wardriving (driving near stores to intercept wireless POS traffic) · packet sniffers
NETWORK
Ran international team including Russian hackers — notably Maksym Yastremskiy and Aleksandr Suvorov

THE BREACHES

TJX COMPANIES
2006–2007 · 45.6 million card numbers stolen · Marshalls, T.J. Maxx · largest at the time [DOJ]
HEARTLAND PAYMENT
2008 · 130 million cards · single largest card breach in history at sentencing [DOJ]
7-ELEVEN
ATM network breach · card data intercepted · exact count classified
HANNAFORD BROS.
4.2 million cards stolen from New England grocery chain
DAVE & BUSTER'S
Multiple locations · card skimming operation integrated into larger scheme
TOTAL CARDS (CHARGED)
170 million+ card numbers across all breaches [DOJ indictment / sentencing]
TOTAL LOSSES
~$200 million estimated financial losses to financial institutions and card holders
TECHNIQUE
Planted packet sniffers on retail networks · exfiltrated data to servers in Latvia, Netherlands, Ukraine
THE DOUBLE AGENT — INFORMANT AND CRIMINAL SIMULTANEOUSLY

THE INFORMANT PERIOD

ARRESTED
2003 · ShadowCrew takedown by Secret Service
COOPERATION
Became informant 'Cumber' for Secret Service · helped bring down ShadowCrew in 2004
THE BETRAYAL
While informing on the carding world, ran the TJX and Heartland breaches simultaneously
HOW HE CONCEALED IT
Used separate infrastructure · compartmentalised his criminal operation from his handler relationships
SECRET SERVICE REACTION
Handler reported Gonzalez as 'one of the best' informants — had no knowledge of his continued hacking
DISCOVERY
His criminal activity discovered only when a co-conspirator was arrested overseas
SIGNIFICANCE
Largest case of someone committing crime while acting as government informant in cyber history
PARALLEL
Same dual-role structure as Belfort (wore wire) and Gonzalez (was the wire)

SENTENCING & RECORD

ARRESTED (CRIMINAL)
May 2008 · Miami · by the same Secret Service he had worked for
INDICTMENTS
Three separate federal indictments — District of Massachusetts, New Jersey, New York
PLEA
Guilty to multiple counts of wire fraud, computer fraud, identity theft, conspiracy
SENTENCED
March 2010 · 20 years federal prison — two 20-year terms concurrent
SENTENCE DISTINCTION
Longest sentence ever imposed for hacking crimes in US history at time of sentencing
CO-DEFENDANTS
Maksym 'Maksik' Yastremskiy (Ukraine) · Aleksandr 'Grig' Suvorov (Estonia) · Christopher Scott (Miami)
LIFESTYLE
Used stolen card proceeds to fund lifestyle including $75,000 birthday party for himself
CURRENT STATUS
Serving federal prison sentence · projected release 2025 [verify current BOP record]

WHAT THIS CASE ESTABLISHED

The largest card theft prosecution in US history at the time of sentencing. 170 million card numbers. The victims were not just the card holders — they were every financial institution that had to reissue and cover fraudulent charges.
He was hacking the most significant retail networks in America while simultaneously working as a Secret Service informant. His handler described him as exceptional. His criminal network was processing millions of stolen cards.
The case triggered foundational changes in how US retailers approach payment security — the TJX breach specifically was the catalyst for the industry-wide shift toward chip-and-PIN payment technology.
Gonzalez's technique — wardriving near retail stores, planting sniffers on wireless point-of-sale systems — was state of the art in 2006. The breach disclosures from TJX, Heartland, and Hannaford changed how the payment card industry thought about network security perimeter.
Series note: Case 011 documents the first BEC/card fraud at this scale, run by a man who was simultaneously cooperating with the government it was being stolen from.
THE FULL STORY — 11 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE INFORMANT (3,300 WORDS)
Sources: US v. Albert Gonzalez — District of New Jersey (Aug 2009); DOJ Office of Public Affairs; US Secret Service press releases; NYT (26 Mar 2010); Reuters (26 Mar 2010); Computerworld (Aug 2009); CNBC American Greed; Miami Herald. Every figure traces to a named source. Card counts are card counts — not dollar amounts. This case involves a living person released from federal custody in 2023.
· PROLOGUE ·
$340,000 and a Broken Machine

He complained about counting it by hand.

The currency-counting machine had broken, and he had $340,000 in cash that needed to be tallied, and the inconvenience of doing it manually was, to him, a logistical problem worth mentioning. Not the fact of having $340,000 in cash in a room. Not the source. The counting. [SOURCE: Miami Herald / reporting]

This is the detail that opens the case because it tells you everything about the man in a single image: money so abundant it became a chore. Stacks high enough to require a machine. And when the machine failed, the complaint was not about the money or the risk or the exposure — it was about the tedium of touching every bill.

He also threw himself a birthday party that cost $75,000. [SOURCE: Reporting / Miami Herald]

His name was Albert Gonzalez. He stole more than 170 million credit and debit card numbers — the largest such theft in American history. And while he was doing it, he was a cooperating informant for the United States Secret Service.

· PART ONE ·
South Miami High — The Leader of the Computer Nerds

He was born in 1981, in Cuba, and raised in Miami.

The family settled in the kind of neighbourhood that produces the working class of a city built on tourism, trade, and the particular American ambition of people who arrived from somewhere else. Miami in the 1980s and 1990s was a city of reinvention — a place where origin was less important than what you did with the opportunity the city offered.

What Albert Gonzalez did with it was buy a computer. He was twelve years old. [SOURCE: Court record / reporting]

At South Miami High School, he was described as the leader of a group the reporting calls the computer nerds — but the word "troubled" appears alongside it. He was not the quiet kid in the back of the lab. He was the kid who ran the lab, who understood what the machines could do before the teachers did, and who had already decided that the boundary between learning how a system worked and breaking into that system was a distinction other people cared about more than he did.

At fourteen, he hacked NASA. [SOURCE: Reporting]

That sentence requires a pause. Not because hacking NASA at fourteen is unprecedented — the history of American computer crime is populated with teenagers who reached further than anyone expected and touched systems that should have been unreachable. But because it establishes, very early, the specific quality that made Gonzalez different from the other carders and hackers of his era: he did not operate at the edges of the system. He went to the centre. He touched the thing that mattered most. And he did it before he was old enough to drive.

· PART TWO ·
Kearny, New Jersey — The ShadowCrew

In 2000, Gonzalez moved to New York City. He lasted three months. Then he moved to Kearny, New Jersey — a working town across the Meadowlands from Manhattan, the kind of place where rent was cheap and nobody asked what you did for a living as long as you paid on time.

In Kearny, he found his community. Or built it.

ShadowCrew was an online forum — a marketplace where stolen credit card numbers, ATM PINs, and the tools to use them were bought, sold, and traded by a community of carders who operated in the open, behind screen names, with the confidence of people who believed the internet was a jurisdiction unto itself. [SOURCE: DOJ / court record]

Gonzalez's handle was CumbaJohnny. He was accused of being a mastermind of the operation. The numbers associated with ShadowCrew: 1.5 million stolen card and ATM numbers trafficked through the forum. [SOURCE: Court record]

1.5 million is a large number. It would not remain the largest number associated with his name for long.

· PART THREE ·
2003 — The Arrest That Changed Everything

In 2003, he was caught. Busted for hacking. The details of the arrest are straightforward — he was identified, detained, and faced the full weight of federal charges that could have sent him to prison for years.

What happened next is what makes this case different from every other case in this series.

He became an informant. A cooperating source for the United States Secret Service. [SOURCE: DOJ / Secret Service / Computerworld]

The Secret Service — which handles financial crimes alongside its protective duties — recruited him. The logic was sound from their perspective: here was a young man who understood the carding ecosystem from the inside, who spoke the language, who knew the players. A man like that, cooperating, could map the networks that agents spent years trying to penetrate from the outside.

He cooperated. He provided intelligence. He helped agents understand how carding operations worked — the acquisition of numbers, the encoding onto blank cards, the cash-out at ATMs, the resale on forums. He was useful. He was knowledgeable. He was, by the assessment of the agents who worked with him, an asset.

He was also, per the record that would later emerge, still hacking. Still stealing. Still running operations that made the work he'd been caught for look like a practice round.

The headline that would eventually describe this arrangement, from Computerworld in August 2009: "Government informant is called kingpin of largest U.S. data breaches."

The man briefing federal agents on how carding worked was the largest carder alive. Every explanation he gave them was a description of his own operation, with the identifying details edited out.

· PART FOUR ·
The Method — How You Steal 170 Million Numbers

The number requires context before it can be understood.

170 million. That is the combined count of credit card and debit card numbers that Albert Gonzalez and his associates stole between 2005 and 2007. [SOURCE: DOJ indictment] It is not a dollar figure — it is a count of card numbers. Each number represents a person's financial identity: the card number, the expiration date, and in many cases the associated data needed to create a functioning clone.

The victims were not individuals. They were the companies that held those individuals' data:

TJX Companies — the parent of TJ Maxx, Marshalls, and HomeGoods. 45.6 million card and debit numbers stolen over an eighteen-month period ending in 2007. [SOURCE: Court record]

Heartland Payment Systems — a payment processor that handled transactions for hundreds of thousands of merchants. 130 million card numbers. The single largest breach in the set. [SOURCE: Court record]

Hannaford Brothers — a supermarket chain. 4.6 million numbers. [SOURCE: Indictment]

Also named in the indictments or associated with the scheme: Dave & Buster's, 7-Eleven ATMs, and others.

The method, as the court record describes it, operated in layers. The first layer was finding a way in — and the way in was almost always the same: SQL injection against a company's web-facing systems. A technique that, even in 2005, was well-understood and well-defended against by companies that took the basic precautions. The companies that Gonzalez targeted had not taken those precautions, or had not taken them thoroughly enough.

Once inside, he deployed tools that maintained access — backdoors that allowed his team to return without being detected. From that foothold, they moved laterally through internal networks. And then the part that made the operation extraordinary: they intercepted card data in transit. Packet sniffing. ARP spoofing. The technical terms describe a man sitting inside a company's own network, watching card numbers flow past like water through a pipe, and capturing them.

The data was exfiltrated and sold.

Every step of that chain has a standard defence. That is the lesson the case teaches — not the method, which belongs in a textbook, but the fact that 170 million people's card numbers were exposed because the companies holding those numbers had not deployed the controls that already existed.

· PART FIVE ·
Three Indictments, Three Cities

The scale of what Gonzalez did was so large that no single federal district could contain it.

May 2008: the first indictment, in New York, for the Dave & Buster's case. [SOURCE: DOJ]

May 2008 — the same month: the second indictment, in Massachusetts, for the TJX case. The one that put 45.6 million card numbers into the public record. [SOURCE: DOJ]

August 2009: the third indictment, in New Jersey, for Heartland Payment Systems. 130 million numbers. The biggest single breach, filed as a separate case because it involved different victims, different infrastructure, different evidence. [SOURCE: DOJ / District of New Jersey]

Three federal indictments. Three jurisdictions. Three sets of prosecutors, three courtrooms, three evidence chains — all converging on the same man, who had been cooperating with the Secret Service while committing the crimes that generated each of those filings.

The Computerworld headline ran in August 2009, when the third indictment dropped and the scale became visible to the public for the first time. The informant was the kingpin. The briefings had been autobiographies.

· PART SIX ·
The Double Life — Inside the Investigation of Himself

This is the part that distinguishes Gonzalez from every other fraudster in this series.

built a persona. built a spending spree. built a company. Madoff built duration. Holmes built a story. Each of them operated in a space that was, fundamentally, separate from the people who would eventually investigate them. There was the fraud, and there was the investigation, and the two met at the point of arrest.

Gonzalez was inside the investigation.

He sat with the agents. He explained how the systems worked. He provided intelligence — real intelligence, useful intelligence, intelligence that led to arrests of other people in the carding ecosystem. The Secret Service valued him. He was not pretending to cooperate while providing nothing. He was providing genuine operational detail about the world he dominated.

And then he went home and ran the operation.

The photograph the Secret Service used in connection with the case was taken before 2009 — because they had him on file. As an asset. As someone who worked for them. The photograph of their informant became the photograph of their target. [SOURCE: Secret Service / reporting]

The duality is not something the record resolves into a clean narrative. It would be easy to write that he was cynically manipulating the government from inside, or that the government was negligently failing to supervise its own asset. The truth is probably less dramatic and more human: he was a man who understood two systems — the federal law enforcement system and the criminal carding system — and who lived comfortably inside both of them simultaneously, giving each one exactly enough to sustain the relationship, until the scale of the operation made the duality impossible to maintain.

He was, in the end, too good at both jobs. The informant provided real value. The carder stole 170 million numbers. Both of those things were true at the same time, and neither cancelled the other out.

· PART SEVEN ·
The Lifestyle — Modest Homes and Expensive Parties

The money was enormous. The life was strange.

Gonzalez stayed in lavish hotels. He threw the $75,000 birthday party. He had the $340,000 that needed counting by hand. The lifestyle trappings were present — the visible, performative spending that appears in every fraud case in this series.

But his actual homes were described as modest. [SOURCE: Reporting / Miami Herald]

That detail matters because it reveals something different from the model or the model. Those men spent to be seen spending. The money was fuel for the image. The lifestyle was the product.

Gonzalez spent for the theatre of it — but not for the permanence. He did not build a brand. He did not post the party. He lived in an era before Instagram made every purchase a content opportunity, and his instinct was not toward documentation but toward experience. The $75,000 party was for the people in the room. The $340,000 was for counting, not for photographing.

The money was not the point. The access was the point. The knowledge that he was operating at a level that no one around him fully understood — that the agents he briefed did not know they were being briefed by the man they were hunting, that the companies whose networks he had penetrated did not know they had been penetrated, that the card numbers flowing through global payment systems carried his fingerprints and nobody had yet matched the prints.

That was the high. Not the party. The knowing.

· PART EIGHT ·
The Sentence — 20 Years

On September 11, 2009, Gonzalez pleaded guilty in the Secret Service's TJX case. [SOURCE: Secret Service press release, 11 Sept 2009]

On March 25, 2010, he was sentenced to twenty years in federal prison. [SOURCE: NYT, 26 Mar 2010; Reuters, 26 Mar 2010; DOJ]

The sentence reflected the scale. The judge considered the informant cooperation — and sentenced him to twenty years anyway. The cooperation had been real, but the crime committed during the cooperation was too large for the cooperation to substantially mitigate.

DOJ's own language: "Leader of Hacking Ring Sentenced for Massive Identity Thefts from Payment Processor and U.S. Retail Networks." [SOURCE: DOJ Office of Public Affairs]

Twenty years. The same sentence the federal system would later give Sebastian Greenwood for OneCoin. The same range that applies to armed bank robbery. For a man who never touched a weapon, never met his victims, never entered a bank. He sat at a keyboard, found the holes in systems that should not have had holes, and took 170 million numbers that were not his to take.

· PART NINE ·
The Handles — segvec, soupnazi, j4guar17

A note on the names, because they tell you something about the culture.

segvec — a segmentation violation, a specific kind of software crash. A technical handle that signals competence to other technical people.

soupnazi — a Seinfeld reference. The character who withheld soup from customers who did not follow his arbitrary rules. The handle of a man who controlled access and enjoyed the power of it.

j4guar17 — the animal and a number. Speed and youth.

cumbajohny, kingchilli, stanozlolz — the others, less serious, more playful, the kind of handles a man generates when he needs a new identity for a new forum and does not think anyone will ever read them in a court filing.

They read them in three court filings. In three jurisdictions. The handles that were supposed to be walls between his identity and his activity became exhibits. The anonymity of the internet, which he had relied on as an article of faith, failed at the exact moment that the Secret Service realised their informant and their target shared the same operational knowledge because they were the same person.

· PART TEN ·
2023 — Release

Albert Gonzalez was released from federal custody in 2023. [SOURCE: Federal Bureau of Prisons records / reporting]

He served approximately thirteen years of a twenty-year sentence. He is now in his early forties. He lives, as far as the public record indicates, as a private citizen. He has not spoken publicly about the case in any substantial way since his sentencing.

The companies he breached have rebuilt. Heartland Payment Systems was acquired by Global Payments. TJX Companies continues to operate TJ Maxx, Marshalls, and HomeGoods across thousands of locations. The 170 million card numbers were replaced, reissued, and forgotten by most of the people whose wallets held them.

The payment industry changed. EMV chip cards — which Gonzalez's method could not have intercepted in the same way — became the global standard. Point-to-point encryption became a baseline requirement. PCI DSS compliance, which was already a standard during his spree but unevenly enforced, became the cost of doing business for any company that touched card data.

He did not cause these changes alone. But his name is in the room every time the payment security industry explains why the controls matter. He is the example. He is the reason the auditor can point at a company and say: this is what happens when you do not encrypt card data in transit.

· PART ELEVEN ·
What This Case Established

170 million card numbers — the largest card data theft prosecution in US history at the time of indictment. [SOURCE: DOJ]

The first major case to demonstrate that a cooperating informant could simultaneously operate at the highest level of the crime they were helping investigate — and that the federal system's own oversight mechanisms could fail to detect it.

SQL injection, a well-understood vulnerability with well-understood defences, was the entry point for every major breach in the case. The lesson is not technical sophistication — it is the cost of leaving known doors unlocked.

Three simultaneous federal prosecutions across three jurisdictions — New York, Massachusetts, New Jersey — for crimes committed by the same person during the same period while cooperating with federal law enforcement.

The case accelerated the adoption of chip-based card technology (EMV), point-to-point encryption, and stronger PCI DSS enforcement across the US payment industry.

· EPILOGUE ·
The Briefing

He taught the investigators how carding worked.

He sat across the table from Secret Service agents and explained the ecosystem — the forums, the methods, the markets, the way stolen card data moved from breach to buyer to blank card to ATM withdrawal. He gave them real intelligence. Real names. Real operations. He helped them make arrests.

And when the briefing was over, he went home and executed the largest version of the operation he had just described.

170 million card numbers. Three federal indictments. A $75,000 birthday party. A broken counting machine and $340,000 in cash. A man who hacked NASA at fourteen, became a federal informant at twenty-two, and was sentenced to twenty years at twenty-nine.

Every other case in this series is about a person who built something — a persona, a company, a Ponzi, a product — and then watched the investigation close in from outside. Gonzalez is the only one who was inside the investigation while it was looking for him.

He taught them how it worked. He was the best at it. They were the same thing.

· VERIFIED SOURCES ·

All figures labelled by what they measure. Card counts are card counts — not dollar amounts. This involves a living person released from federal custody in 2023.

[1] US v. ALBERT GONZALEZ — District of New Jersey indictment, August 2009. a/k/a segvec, soupnazi, j4guar17. 18 U.S.C. §§ 371, 1349.
[2] DOJ OFFICE OF PUBLIC AFFAIRS — "Leader of Hacking Ring Sentenced for Massive Identity Thefts from Payment Processor and U.S. Retail Networks."
[3] US SECRET SERVICE — "Key Defendant Pleads Guilty in Secret Service's 'TJX' Case" (11 September 2009).
[4] FEDERAL INDICTMENTS — NY (Dave & Buster's, May 2008); Massachusetts (TJX, May 2008); NJ (Heartland, August 2009).
[5] NEW YORK TIMES — "Computer Hacker Gets 20 Years in Theft of Card Numbers" (26 March 2010).
[6] REUTERS — "Gonzalez sentenced for multimillion-dollar credit card scam" (26 March 2010).
[7] COMPUTERWORLD — "Government informant is called kingpin of largest U.S. data breaches" (August 2009).
[8] MIAMI HERALD — Lifestyle reporting: $75,000 birthday party, $340,000 cash counting, modest homes.
[9] CNBC AMERICAN GREED — "Hackers: Operation Get Rich or Die Tryin'" (Season 5).
*TraceChain Forensics · Fraud Exposed Series · Case 011*
*Every claim sourced. Estimates labelled. Card counts are not dollar amounts.*

*What would prove it wrong?*

END OF REPORT
#33 OF 45
Jordan Belfort
SINGLE PERSON
CASE 012 · SECURITIES FRAUDRELEASED — STILL TALKING
Wolf of Wall Street · Stratton Oakmont · 22 months · 1,513 victims
$200M
WHAT WAS TAKEN
His clients' investment money. A court ordered $110M paid back.
HOW
Pump and dump: hyped cheap stocks to clients, then sold his own shares at the top.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1989–1996Runs Stratton Oakmont, a boiler room pumping and dumping penny stocks on 1,513 clients; expelled by the NASD in Dec 1996.SOURCE: SIPC v. Stratton Oakmont; DOJ E.D.N.Y.
1999Pleads guilty, wears a wire against his partners; 22 months.SOURCE: US v. Belfort, E.D.N.Y.
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
JORDAN ROSS BELFORT
WOLF OF WALL STREET · STRATTON OAKMONT · CASE 012 · SECURITIES FRAUD · RELEASED 2006
INVESTOR LOSSES
~$200M
RESTITUTION ORDERED
$110.4M (50% of income)
VICTIMS
1,513 clients [SOURCE: SIPC filing]
SENTENCE
22 months · pleaded guilty 1999
NASD EXPULSION
Stratton Oakmont — December 1996
BORN
July 9, 1962 · Bronx, New York
THE FILM
The Wolf of Wall Street (Scorsese, 2013) · $390M+ gross
STATUS
RELEASED · motivational speaker
TWO FIGURES — TWO THINGS: $200M = investor losses (SIPC filing). $110.4M = restitution ordered (50% of income structure). Different numbers, different things. The film is not the record. The memoir is self-serving. Court documents are the authority.
FULL PROFILE

IDENTITY

NAME
Jordan Ross Belfort
BORN
July 9, 1962 · Bronx, New York · raised Bayside, Queens
EDUCATION
American University · BA · briefly dental school
FIRM
Stratton Oakmont — Long Island — up to ~1,000 brokers at peak
SCHEME
Pump-and-dump · penny stocks · boiler room sales tactics
COOPERATION
FBI informant · wore recording device · testified against partners

CASE RECORD

CASE
US v. Belfort, 1:00-cr-00126, E.D.N.Y.
NASD EXPULSION
December 1996 — Stratton Oakmont expelled
GUILTY PLEA
1999
SENTENCE
22 months federal
RESTITUTION
$110.4M ordered · 50% of income structure
VICTIMS
1,513 clients · ~$200M losses [SOURCE: SIPC v. Stratton Oakmont, 234 B.R. 293]
POST-RELEASE
Memoir (2007) · Film rights · Scorsese film (2013) · Motivational speaking
THE WOLF OF WALL STREET — FILM VS RECORD

THE GAP BETWEEN THE IMAGE AND THE RECORD

The film grossed over $390M worldwide. Five Academy Award nominations. DiCaprio plays Belfort. It is based on a memoir written by a man with strong financial incentives to make his life sound as entertaining as possible. The court record tells a more specific story: 1,513 clients, $200M in losses, 22 months, a wire worn on his own partners.

RECORD
1,513 clients defrauded · ~$200M losses · pump-and-dump penny stocks · 22 months prison · $110.4M restitution
FILM
$390M+ gross · 5 Oscar nominations · DiCaprio · global cultural icon · motivational speaking career
THE GAP
The retelling outlasted, outscaled, and outperformed the original. $200M put him at the bottom of this series by scale. The film put him at the top by recognition.
CASE TIMELINE
9 Jul 1962
Born, Bronx, NYC
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Raised Bayside, Queens
parents both accountants
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
American University, BS
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Founds Stratton Oakmont (franchise → buyout of Stratton Securities)
SOURCE: case brief (sources listed in its SOURCES part)
1989 onward
Under NASD scrutiny
SOURCE: case brief (sources listed in its SOURCES part)
Dec 1996
NASD expels Stratton Oakmont
firm closed
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Indicted for securities fraud
SOURCE: case brief (sources listed in its SOURCES part)
1999
Pleads guilty
fraud and related crimes
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Cooperates
FBI informant, wire, testifies against partners
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Sentenced to 22 months
SOURCE: case brief (sources listed in its SOURCES part)
2007
Publishes The Wolf of Wall Street
SOURCE: case brief (sources listed in its SOURCES part)
2013
Scorsese film released
DiCaprio plays him
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Ordered to pay $110.4M restitution
50% of income until 2009
SOURCE: case brief (sources listed in its SOURCES part)
HOW THE FRAUD WORKED

HOW IT WORKED — FROM THE CASE BRIEF

01
The model — a boiler room running a pump-and-dump: The firm controlled the supply of a thinly-traded penny stock (often via IPO allocations it managed)
02
Brokers — trained to sell hard — pushed the stock to clients, "pumping" the price
03
The firm sold its own position into the demand it had created — the "dump"
04
Clients were left holding stock the firm had already abandoned
05
Why it worked: the firm was the market maker for those securities. It could set the price its own sales force was telling clients to buy at. The house was both the seller and the scoreboard.
DEFENSIVE LEVEL ONLY · THE SHAPE OF THE SCHEME, NOT A PLAYBOOK
KNOWN NETWORK & CONNECTED CASES

WHAT THIS CASE ESTABLISHED

22 months for the leadership of an operation that cost 1,513 clients $200M. The cooperation credit is the explanation: he wore a wire on his own partners and testified against them. Structurally identical to Ellison in — different fraud, same mechanism.
The film is not the record. The memoir is self-serving. The standard for this case is: court documents are the authority.
The retelling built the legend. He became more famous after the crime than during it — not because of anything he built while operating, but because Scorsese filmed it. The crime ended. Then the legend was built from it.
He is the one a stranger can name. By scale he is near the bottom of this series. By recognition he is at the top. The gap between those two facts is the whole case.
Series thesis, Case 012: The Legend. The retelling can outlast, outscale, and outperform the original. $200M in losses. $390M in box office. The crime produced losses. The retelling produced revenue. Both true about the same events.
BACKGROUND & BIOGRAPHY

EARLY LIFE & EDUCATION

FULL NAME
Jordan Ross Belfort
BORN
9 July 1962 · Bronx, New York City
RAISED
Bayside, Queens · middle class · parents both accountants
EDUCATION
American University, Washington D.C. · BS degree
EARLY CAREER
Brief dental school enrollment before pivoting to finance · became licensed stockbroker
FIRST JOB IN FINANCE
Small brokerage · developed an exceptional talent for sales and persuasion
PERSONALITY
Charismatic · high-energy · driven · gifted communicator · the room adjusted to him
STRATTON OAKMONT NAME
Deliberately chosen to evoke Ivy League establishment · the name was the first fiction

STRATTON OAKMONT — THE OPERATION

FOUNDED
Early 1990s · Great Neck, Long Island, New York
PEAK SIZE
~1,000 brokers at peak · one of the largest broker-dealers on Long Island
PRODUCT
Penny stocks — low-priced securities in small, thinly-traded companies
THE SCHEME
Pump-and-dump: controlled supply → brokers pushed stock → firm sold into created demand
THE POWER
Stratton was market maker for its own stocks — set the price its own brokers told clients to buy at
CLIENT COUNT
1,513 clients defrauded [SIPC v. Stratton Oakmont, 234 B.R. 293]
NASD SCRUTINY
Under regulatory scrutiny from 1989 — operated for years before shutdown
SHUTDOWN
December 1996 — NASD expelled Stratton Oakmont
THE AFTERMATH — WIRE, PRISON, AND THE BOOK

THE COOPERATION

INDICTED
After NASD expulsion and subsequent federal investigation
PLEA
Guilty — 1999 · fraud and related crimes
KEY MOVE
Became FBI informant — wore recording device against his own partners and subordinates
TESTIFIED
Against former brokers and co-conspirators who built the scheme alongside him
SENTENCING IMPACT
22-month sentence reflects full cooperation credit — drastically below guideline range
CELLMATE (REPORTED)
Shared cell with Tommy Chong of Cheech & Chong [widely reported — verify to primary]
RESTITUTION
$110.4 million ordered · 50% of income toward payment until 2009
PARALLEL
Same structure as Ellison () — cooperated against those closest to him

THE LEGEND — HOW IT OUTRAN THE FRAUD

MEMOIR
The Wolf of Wall Street · 2007 · self-serving · written for commercial effect
FILM
Martin Scorsese · The Wolf of Wall Street · 2013 · DiCaprio plays Belfort
FILM GROSS
$390M+ worldwide · 5 Academy Award nominations
FILM FUNDING (ALLEGED)
Red Granite Pictures — DOJ alleged company funded with 1MDB money [ / connection]
POST-PRISON CAREER
Motivational speaker · sales consultant · charges substantial fees · Wolf brand continues
THE IRONY
The restitution structure (50% of income) meant speaking fees went toward victims — the career served the debt
SCALE IN SERIES
$200M in losses puts him near the bottom of this series by scale. He is the top by name recognition.
SERIES THESIS
The legend. He is famous because of how it was retold, not because of what he did.

THE GAP — FRAUD VS. FILM

Film: three-hour spectacle. Quaalude scenes. Yacht. DiCaprio screaming. An American excess fable. Record: 1,513 clients. $200 million. 22 months. $110.4 million in restitution. A man who wore a wire on his own people.
Every other case in this series was famous because of what they did. Belfort is famous because of how it was retold. The crime got 22 months. The legend got Oscar nominations and $390 million at the box office.
The film was allegedly funded by money stolen from Malaysia. The movie that made Belfort immortal was produced by a company the US government alleged was financed by 1MDB. The fraud that made is the funding source for the film about Case 012.
Victims: 1,513 people who were told by trained salespeople using designed techniques to buy stock those salespeople already knew was going to collapse. They did not get the memoir or the film deal.
THE FULL STORY — 7 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEGEND (2,500 WORDS)
Sources: US v. Belfort, 1:00-cr-00126, E.D.N.Y. · NASD expulsion of Stratton Oakmont, December 1996 · SEC actions against Stratton Oakmont / Belfort · SIPC v. Stratton Oakmont, Inc., 234 B.R. 293 (Bankr. S.D.N.Y. 1999) · NYT 'Stratton Oakmont Executives Admit Stock Manipulation' (24 Sept 1999) · Belfort memoir The Wolf of Wall Street (2007) — self-serving, used with care · Scorsese film (2013) — dramatised; cited as adaptation, not record. $200M = investor losses; $110.4M = restitution ordered — different figures, different things.
· PROLOGUE ·
The Party

The movie opens with Leonardo DiCaprio screaming.

He is on a yacht. He is high. He is rich in a way that seems to exist on a different plane from ordinary richness — not the quiet, managed, invested richness of people with advisors and portfolios, but the velocity-of-cash richness of a man who has more money coming in than he can spend fast enough to keep up. The film runs three hours. For most of those three hours, someone is screaming, or taking drugs, or throwing things, or spending money on something obscene.

Martin Scorsese directed it. Leonardo DiCaprio plays Jordan Belfort. The film received five Academy Award nominations. It grossed over $390 million worldwide. It is one of the most profitable biopics ever made.

Jordan Belfort watched it from the other side of the screen as a famous man. He had already written the memoir. He had sold the film rights. He was being played by the biggest movie star on earth.

The record — the court record, the NASD record, the SEC record, the bankruptcy filing — tells a different story. Not a less interesting one. A more specific one. 1,513 clients. Approximately $200 million in investor losses. Twenty-two months in federal prison. $110.4 million in restitution ordered.

He is, by the numbers in this series, a relatively small operator. His losses are a fraction of Madoff's. His victims are numbered in the thousands, not the millions. His sentence was shorter than anyone else in this collection.

He is also the one a stranger can name.

· PART ONE ·
The Bronx. Queens. Two Accountant Parents.

Jordan Ross Belfort was born on July 9, 1962, in the Bronx, New York City. His parents were both accountants. He grew up in Bayside, Queens — a middle-class neighbourhood in the northeastern corner of the borough, the kind of place that produces people who know how close they are to Manhattan and who measure their lives against that distance.

He attended American University in Washington D.C. and graduated with a bachelor's degree. He then, by his own account, briefly enrolled in a dental school programme before deciding that dentistry was not where the money was and pivoting toward finance.

He started as a broker. The conventional path. A licensed broker placing trades for clients, earning commissions, learning the mechanics. He was good at it, or specifically good at the part of it that involved persuading people to buy things — which, in the brokerage world, is the primary skill.

He co-founded Stratton Oakmont, named to evoke the Ivy League establishment — the kind of patrician, old-money credibility that a firm operating from Long Island had no actual claim to. The name was the first fiction. What followed was the operation.

· PART TWO ·
Stratton Oakmont — What It Was

Stratton Oakmont was a boiler room. Not in the metaphorical sense that it was aggressive or high-pressure. In the specific, regulatory sense: a firm that used manipulative sales tactics and broker misconduct to push clients into investments that served the firm's interests rather than the clients'.

The product was penny stocks — low-priced securities in small companies, trading on markets with lower listing requirements, with thin trading volume that meant even modest buying pressure could move the price significantly. These are not inherently fraudulent instruments. But they are instruments that are relatively easy to manipulate when a firm controls the supply and the sales force simultaneously.

Stratton Oakmont's model was a pump-and-dump. The firm would obtain a large position in a penny stock — often through an IPO that it managed, giving it allocations of shares at prices before the public offering. Its brokers, trained in high-pressure selling techniques, would then call clients and push the stock hard: rising fast, limited time, get in now. The calls created buying demand. The demand pushed the price. When the price was high enough, the firm sold its own position into the market the sales force had just created. The clients who had been told to buy were left holding stock the firm had already sold at a profit. [SOURCE: NASD / SEC; case record]

At peak, Stratton Oakmont had approximately a thousand brokers. It was one of the largest broker-dealers on Long Island. It processed enormous volumes of transactions. It made a great deal of money for the firm. It lost approximately $200 million for approximately 1,513 clients. [SOURCE: US v. Belfort, E.D.N.Y.; SIPC filing]

· PART THREE ·
The Film vs. The Floor

This is where the case requires the sharpest separation in the series.

The film is not a fraud. It is a movie. It is based on a memoir written by a man with strong financial incentives to make his life sound as entertaining as possible. Scorsese made a great film about a real event and in doing so produced something that most people have seen — which means most people's mental model of Jordan Belfort is a three-hour dramatisation of a self-serving memoir, not a court document.

This matters because the gap between the image and the record is the specific lesson of Case 012. It is not that Belfort was worse than the film shows. It is that the film made him aspirational in a way that the record does not.

· PART FOUR ·
The Fall — NASD, FBI, and the Wire

The National Association of Securities Dealers had been examining Stratton Oakmont since 1989. The firm operated under regulatory scrutiny for years — which is itself a data point. The boiler room ran, expensively and loudly and visibly, for the better part of a decade before it was shut down.

In December 1996, the NASD expelled Stratton Oakmont. The firm was finished. The expulsion was the end of the operation as a regulated entity. [SOURCE: NASD action, December 1996]

The federal case built more slowly. Belfort was indicted for securities fraud. He did not fight it. He pleaded guilty in 1999. He then did something that the film handles but does not dwell on: he cooperated. Fully and specifically.

He became an FBI informant. He wore a recording device. He gathered evidence against his former partners and subordinates — the people who had worked for him, run the operation with him, profited alongside him. He testified against them. [SOURCE: US v. Belfort, E.D.N.Y.; case brief]

This cooperation is the reason his sentence was 22 months. The cooperation credit is substantial. He received a 22-month sentence for the leadership of an operation that cost clients $200 million because he gave the government his own people.

In this he is the operational counterpart to in . Different context, different fraud, different relationship to the person he was cooperating against. But the structure is the same: he wore a wire on the people closest to him, and the sentence reflects it.

· PART FIVE ·
The Numbers That Matter

The series applies the same discipline to every case: figure, label, source. Case 012 has four numbers that must not be blurred.

The restoration rate — $110.4 million ordered against approximately $200 million in losses — is roughly 55 cents per dollar lost. This is not unusual in financial fraud cases. Asset recovery is partial, restitution orders are not always collected in full, and the gap between what a court orders and what victims actually receive is often significant. In Belfort's case, the restitution structure tied payment to his income — 50% of earnings — which created the specific incentive for the post-prison career.

· PART SIX ·
The Memoir, the Film, the Motivational Speaking Career

He was released from prison and became a motivational speaker.

The logic is not as cynical as it sounds, or rather it is exactly as cynical as it sounds but with a legal structure attached. Fifty percent of his income went toward the $110.4 million restitution order. The more he earned, the more went to victims. The career that let him earn the most — the book, the film rights, the speaking fees — was structurally connected to the restitution obligation.

The memoir, The Wolf of Wall Street, was published in 2007. It is written in the register of a man who wants you to enjoy the ride before you get to the part where everything collapses. It is entertaining. It is self-serving. It is careful in the way that people who have lawyers and reputations to manage are careful. It is the document that Scorsese optioned.

The film, released in 2013, grossed over $390 million worldwide. It received five Academy Award nominations. It turned Jordan Belfort into a global cultural figure. The man who had defrauded 1,513 clients and worn a wire on his partners became one of the most recognisable names in finance — not despite having committed fraud, but specifically because of a three-hour cinematic rendering of that fraud.

He consults. He speaks. He charges substantial fees to speak about sales and motivation and the lessons of his experience. His image — the one the film created — is part of the commercial product. The Wolf of Wall Street is not a cautionary tale in the way he deploys it. It is a brand.

· PART SEVEN ·
The Series Argument — The Legend

Every case in this series has a thesis. A single thing it documents about how fraud at scale works.

Case 012's thesis is different from every other case, because it is not primarily about how the fraud worked. It is about what happened to the fraud after it ended.

Madoff's fraud ran for 48 years. destroyed $40 billion in market value. Ignatova took $4 billion from 3.5 million victims and disappeared. deceived the most credentialed investors in the country. Stanford defrauded 20,000 people across 100 countries.

Jordan Belfort defrauded 1,513 people and approximately $200 million.

He is the one a stranger can name.

The film did something that none of the fraud itself could do: it made the experience of the fraud cinematic. It gave it a soundtrack, a runtime, a DiCaprio performance, and a three-hour arc that ends with Belfort being led away in handcuffs and then — inevitably, because this is the shape the story has — beginning again. The film closes on a motivational seminar. The room is full. He is telling the story again.

This is where the series contrast is sharpest. built a brand on Instagram. spent faster than he could count. told the world the algorithm was working. Madoff fabricated 48 years of returns. All of them built their own legend as part of the fraud.

Belfort built his legend after. After the guilty plea, after the wire, after the 22 months, after the release — the film came out and turned a convicted fraudster who cooperated against his partners into a cultural icon. He did not build the legend as the fraud. The fraud ended. Then the legend was built.

That is the specific lesson of Case 012: the retelling can outlast, outscale, and outperform the original. $200 million in losses put him at the bottom of this series by scale. The film put him at the top by recognition. The gap between those two things — between what he did and what he is known for — is the whole case.

· EPILOGUE ·
Still Talking

Jordan Belfort is 64 years old. He consults on sales. He speaks at conferences. He charges fees. His face appears on the cover of his book. Leonardo DiCaprio played him. He is, by several measures, the most famous person in this series who is still actively trading on the fame.

He is also the only person in this series who turned his fraud into a performance career before anyone was convicted. The memoir preceded the conviction. The film came a decade after the plea. The speaking career runs alongside both. The entire arc — from fraud to prison to book to film to keynote — is a single coherent commercial operation, and it is built on a crime that cost 1,513 people approximately $200 million.

The victims are part of the record too. They are 1,513 people who were told by trained brokers, using specifically designed sales techniques, to buy stock that those brokers already knew was going to be sold out from under them. They did not get to write the memoir. They did not get the film. They got the loss.

This does not make Jordan Belfort uniquely bad. Every fraudster in this series left victims behind. The victims of Madoff are still waiting on the Picard trustee. The victims of Stanford got partial recovery after a decade of litigation. The victims of Ignatova may never see the money.

What makes Case 012 distinct is the specific way the story was retold — not by investigators or prosecutors but by the man himself, in a memoir and a film rights deal, and then amplified by one of the greatest directors alive. The fraud produced losses. The retelling produced revenue. Both of those things are true about the same set of events.

The party was the movie. And the movie was not the crime.

FULL TIMELINE
VERIFIED SOURCES

Film is not record. Memoir is self-serving. Court documents are the authority. Figures: $200M investor loss vs $110.4M restitution — different things, both labelled. Living person — accurate sourced language throughout.

[1] US v. Belfort, 1:00-cr-00126, E.D.N.Y. — guilty plea 1999; 22-month sentence; $110.4M restitution ordered; 50% of income structure.
[2] NASD expulsion of Stratton Oakmont, December 1996 — firm closure; regulatory authority.
[3] SIPC v. Stratton Oakmont, Inc., 234 B.R. 293 (Bankr. S.D.N.Y. 1999) — 1,513 clients defrauded; ~$200M investor losses. Primary legal source for victim count and loss figure.
[4] SEC actions against Stratton Oakmont and Belfort — civil enforcement record.
[5] NYT — 'Stratton Oakmont Executives Admit Stock Manipulation,' September 24, 1999 — contemporaneous coverage of the guilty plea.
[6] Jordan Belfort — The Wolf of Wall Street (memoir, 2007). Self-serving. Used with care. Not treated as court record.
[7] Scorsese/DiCaprio — The Wolf of Wall Street (film, 2013). Dramatised adaptation. Cited as adaptation throughout, not as fact.

VERIFY BEFORE PUBLICATION Tommy Chong cellmate detail (widely reported, secondary sources only) · Current restitution repayment total · Exact restitution schedule post-2009 · Film gross figure verification

END OF REPORT
#34 OF 45
Minal Patel
SINGLE PERSON
CASE 044 · HEALTHCARE FRAUDCONVICTED
LabSolutions · 27 years · 2023
~$187M
WHAT WAS TAKEN
What Medicare paid on $463M of genetic-test bills; he personally took $21M+.
HOW
Paid kickbacks to call centres and telemedicine doctors to order tests seniors didn't need.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2016–2019LabSolutions bills Medicare ~$463M for genetic tests ordered through kickbacks to call centres and telemedicine doctors; ~$187M paid.SOURCE: DOJ S.D. Ga.
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
MINAL PATEL
THE KICKBACK ENGINE · LABSOLUTIONS · CASE 044 · HEALTHCARE FRAUD · 27 YEARS 2023
BILLED
~$463M to Medicare
PAID
~$187M
HIS TAKE
$21M+
SENTENCE
27 years · Aug 2023
YEARS
2016–2019
TARGET
Elderly Medicare patients
BILLED VS PAID: $463M billed, $187M paid, $21M+ to him personally. Three different numbers.
FULL PROFILE

IDENTITY

NAME
Minal Patel
FROM
Atlanta, Georgia
LAB
LabSolutions LLC — genetic and other lab tests

CASE RECORD

CONVICTED
Dec 2022 · jury
SENTENCED
Aug 2023 · 27 years
FORFEITURE
$187M ordered (Becker’s)
BORN
~1979
STATUS
Convicted
CUSTODY
In custody
COURT
US District Court, Southern District of Georgia
CHARGES
Health care fraud · Kickback conspiracy · Money-laundering conspiracy
PLEA
Not guilty — convicted by a jury, December 2022
COMPANY
LabSolutions LLC, Atlanta, Georgia
HOW THE PATIENTS WERE FOUND
THE CALLERSTELEMARKETING
Call centres
Paid per test
Told seniors Medicare covered cancer genetic tests.
SOURCE: DOJ
THE DOCTORSTELEMEDICINE
Signing doctors
Never saw the patients
Signed orders for tests patients didn’t need.
SOURCE: DOJ
CASE TIMELINE
July 2016
Begins
Kickback-driven orders.
SOURCE: DOJ
Aug 2019
Ends
Scheme stops.
SOURCE: DOJ
Dec 2022
Guilty
Jury.
SOURCE: DOJ
Aug 2023
27 years
Sentenced.
SOURCE: DOJ
HOW IT WORKED

HOW THE KICKBACK ENGINE WORKED — DEFENSIVE LEVEL

01
The call: “Medicare covers a free genetic test”
02
The swab: A kit mailed to the senior
03
The signature: A telemedicine doctor signs the order
04
The warning sign: Unsolicited calls offering free medical tests
HOW A PHONE CALL BECAME A CLAIM
Cold call
-->
Test kit
-->
Doctor signs
-->
Medicare billed

WHAT THIS CASE ESTABLISHED

A real test can still be fraud if nobody needed it.
Series link: Cases 043 and 045.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE KICKBACK ENGINE (700 WORDS)
Sources: DOJ · US court records · HHS-OIG. DISCIPLINE: ~$463M billed ≠ ~$187M paid. These are different numbers. Never combine or substitute. 27 years = one of the longest healthcare fraud sentences in US history.
· PROLOGUE ·
The Kickback Was the Engine

The test was real. The need for it was not.

Minal Patel, owner of a genetic testing laboratory called LabSolutions LLC in Atlanta, Georgia, built a business model around manufactured demand. The genetic tests his laboratory performed were legitimate medical procedures. The question they were intended to answer — does this patient have a genetic predisposition to a condition, and does this affect their medication options — is a real clinical question. But the patients who received those tests under Patel's scheme, per the DOJ, were not patients whose doctors had determined they needed genetic testing. They were people whose details had been obtained by marketers who were paid for every test they brought in.

The kickback structure: Patel's laboratory paid marketers a fee per test — not a per-referral fee that a physician might receive, but a per-unit payment to salespeople whose job was to generate test orders from elderly and vulnerable people, often by using their Medicare or insurance information without the patients' full understanding. Some patients did not know a test had been ordered in their name. Some were told they were receiving a service they had not requested. [SOURCE: DOJ]

~$463 million was billed to Medicare and private insurers. ~$187 million was paid. The difference is the portion that was refused, reversed, or detected. Patel was convicted by a jury in December 2022 and sentenced in August 2023 to 27 years in federal prison — one of the longest sentences in the history of healthcare fraud prosecutions. He personally received more than $21 million. [SOURCE: DOJ, August 2023]

· PART ONE ·
Manufactured Demand — The Kickback as Sales Funnel

The conventional healthcare fraud case involves a false claim — a service that was not provided, billed as if it were. Patel's case is the complement: a service that was provided, but should not have been, because the patient had no genuine need for it and the need was invented by a payment structure.

Genetic testing is expensive and covered by Medicare when medically indicated — when a physician, based on clinical judgment, determines that the test result would affect the patient's treatment. The kickback network Patel operated bypassed that clinical judgment entirely. Marketers recruited elderly patients — mostly through telemarketing calls that falsely said Medicare covered the tests, with telemedicine doctors signing the orders, and senior communities — and generated test orders associated with their identities, sometimes without the patients' knowledge or meaningful consent.

This is manufactured demand: the creation of apparent need through financial incentives paid to people whose interest is the kickback, not the patient's clinical outcome. The test results, once generated, provided cover for the billing claim. The patient exists; the test was performed; the claim is technically defensible. The fraud is in the kickback that generated the order in the first place.

The victims include people who were tested without genuine need and whose insurance details were used without full consent. They were targeted because they were elderly and because Medicare coverage made the billing easy. [SOURCE: DOJ]

· PART TWO ·
The Healthcare Trio — Position 2 of 3

Three healthcare cases in this series; Patel is the second. Perez (043) used a billing licence to fabricate claims. Patel used a kickback network to manufacture demand. Esformes (045) used kickbacks to purchase patient referrals into a nursing-home network.

The 27-year sentence distinguishes Patel's case from the others in the healthcare category. It reflects the specific harm documented — the targeting of vulnerable patients, the sustained operation of the kickback network, and the scale of the billing. It is one of the longest sentences in US healthcare fraud history as of its imposition in 2023. State it factually; do not editorialize about proportionality.

VERIFIED SOURCES
~$463M billed ≠ ~$187M paid. State both. 27 years — do not editorialize. Living person. Victims are vulnerable/elderly — state with care.
[1] DOJ — press releases on Minal Patel / LabSolutions LLC case. [Verify exact charge date 2019, conviction date 2022, sentencing date/term 2023]
[2] HHS-OIG — healthcare fraud enforcement.
TO VERIFY Lab's exact corporate name (LabSolutions LLC) · Charge date · Conviction counts · Sentencing exact date and term · $463M billed / $187M paid split — verify both to DOJ primary documents · Patient counts and states · Co-defendant (marketer) outcomes
SOURCES
[1] PRIMARY — US DOJ: lab owner sentenced for $463M genetic testing scheme (Aug 2023)
[2] SECONDARY — Becker’s Hospital Review: forfeiture
END OF REPORT
#35 OF 45
Roman Seleznev
SINGLE PERSON
CASE 029 · CARD FRAUDCONVICTED
Track2 · 27 years · freed in 2024 prisoner swap
~$169M
WHAT WAS TAKEN
Losses to ~3,700 banks and card holders from 2.9 million stolen card numbers.
HOW
Put malware on US restaurant card terminals and sold the numbers on carding forums.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2009–2013Hacks point-of-sale systems and sells card data on his own forums from Vladivostok; 2.9M cards.SOURCE: W.D. Wash. trial record
5 July 2014Detained at Malé airport by US agents and flown to Guam.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
ROMAN SELEZNEV
THE SENATOR’S SON · “TRACK2” · CASE 029 · CARD FRAUD · SENTENCED 27 YEARS 2017 · FREED IN PRISONER SWAP 2024
LOSSES
~$169M · ~3,700 banks and card holders
CARDS
2.9M+ card numbers — a count, not dollars
SENTENCE
27 years · Seattle · April 2017
ARRESTED
Malé, Maldives · July 5, 2014
FREED
August 1, 2024 · US–Russia prisoner exchange
FATHER
Valery Seleznev · member of the Russian Duma
CARD NUMBERS ARE NOT DOLLARS: 2.9 million = how many card numbers were stolen · ~$169M = the losses that followed. Never mix them.
FULL PROFILE

IDENTITY

NAME
Roman Valerevich Seleznev
HANDLES
Track2 · Bulba · nCuX
NATIONALITY
Russian
FATHER
Valery Seleznev, member of the State Duma
THE BUSINESS
Point-of-sale malware on US restaurant and small-business card terminals; stolen numbers sold on carding forums
THE NAME
“Track 2” is the magnetic-stripe data on the back of a card

CASE RECORD

ARRESTED
July 5, 2014 · Malé airport, Maldives · flown to Guam, then the US
COURT
US District Court, Western District of Washington (Seattle)
CONVICTED
August 2016 · jury · 38 counts (wire fraud, damaging protected computers, identity theft)
SENTENCED
April 21, 2017 · 27 years — then the longest US hacking sentence
ALSO
2017 guilty pleas in Nevada (the Carder.su case) and Georgia; reported 14 years, concurrent
FREED
August 1, 2024 · the 26-person US–Russia exchange in Ankara
KNOWN NETWORK & THE POLITICS
THE FATHERDUMA MEMBER
Valery Seleznev
Russian parliament
Called his son’s arrest a “kidnapping”. Russia’s Foreign Ministry objected too. The US called it a lawful arrest.
SOURCE: BBC · Reuters
THE ARRESTJULY 2014
The Maldives
Malé International Airport
US agents, working with the Maldives, detained him on holiday and flew him to Guam — US territory.
SOURCE: DOJ · Wikipedia
THE FORUMGUILTY PLEA
Carder.su
Nevada case
A carding network prosecuted in Nevada; he pleaded guilty in 2017 in that case and in a Georgia bank-hacking case.
SOURCE: Krebs on Security
THE VICTIMS~3,700 INSTITUTIONS
Restaurants & card holders
Across the US
Payment terminals at restaurants and small businesses; the losses fell on banks and card holders.
SOURCE: DOJ
THE EXCHANGEAUG 1, 2024
The Ankara swap
26 people
Freed with other Russians held in the West, in the exchange that released Evan Gershkovich and others held in Russia.
SOURCE: CNN · Krebs on Security
GONZALEZ (CASE 011) VS SELEZNEV (CASE 029)
WHO
Gonzalez: US citizen, Secret Service informant · Seleznev: Russian, operated from Russia
HOW
Gonzalez: broke into retailer and processor networks · Seleznev: malware on card terminals + forum sales
SCALE
Gonzalez: 170M+ card numbers · Seleznev: 2.9M card numbers, ~$169M losses
SENTENCE
Gonzalez: 20 years · Seleznev: 27 years
HOW IT ENDED
Gonzalez: released 2023 · Seleznev: traded home in 2024
CASE TIMELINE
~2009
The business starts
Point-of-sale hacking and card sales.
SOURCE: DOJ
2009–2013
Track2
Millions of card numbers harvested and sold.
SOURCE: DOJ · Krebs
July 5, 2014
The Maldives
Detained at Malé airport; flown to Guam.
SOURCE: Reuters
July 2014
“Kidnapping”
His father protests in Moscow.
SOURCE: BBC
August 2016
Convicted
Seattle jury, 38 counts.
SOURCE: DOJ
April 21, 2017
27 years
Longest US hacking sentence at the time.
SOURCE: DOJ
2017
More pleas
Nevada (Carder.su) and Georgia.
SOURCE: Krebs on Security
August 1, 2024
Traded home
Released in the US–Russia prisoner exchange.
SOURCE: CNN
HOW IT WORKED

HOW THE CARD BUSINESS WORKED — DEFENSIVE LEVEL

01
The target: Payment terminals at US restaurants and small businesses
02
The malware: Software on the terminals captured card data as customers paid
03
The storefront: Numbers sold in bulk on carding forums, priced by card type and freshness
04
The fraud: Buyers used the numbers for purchases; banks and card holders took the losses
05
The catch: US agents tracked him for years and waited until he travelled
HOW STOLEN CARD DATA MOVED
Restaurant card terminals
-->
Malware collects card data
-->
Servers abroad
-->
Carding forums & buyers

WHAT THIS CASE ESTABLISHED

Card fraud runs like an industry: steal at the terminal, sell on a forum, cash out through buyers.
Card counts and dollar losses are different numbers.
A court can hand down 27 years; politics can end it. He served about ten.
Series link: (Gonzalez) — the insider; Seleznev — the outsider.
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE SENATOR’S SON (1,700 WORDS)
Sources: US DOJ press releases · W.D. Washington (Seattle) court records, 2016 · Nevada conviction, 2017 · Reuters / AP · Krebs on Security (carding operation coverage) · Wikipedia — Roman Seleznev (aggregator; verify to primary). METRIC DISCIPLINE: 2.9 million = COUNT of card numbers (not a dollar figure). ~$170M = reported fraud losses (not 'value of the cards'). Never convert card numbers into dollars. Both figures labelled every time.
· PROLOGUE ·
One Seat in Parliament. One Cell in Washington.

In July 2014, Roman Valerevich Seleznev was arrested in the Maldives. US authorities apprehended him at Malé International Airport and transferred him to Guam, then to the United States. He was subsequently tried in the Western District of Washington — Seattle — on charges relating to one of the largest carding operations the DOJ had prosecuted.

His father, Valery Seleznev, is a member of the Russian State Duma. When news of the arrest reached Moscow, Valery Seleznev publicly characterised it as a 'kidnapping.' The statement was made from the floor of the Duma. It was reported internationally. [SOURCE: BBC; Reuters]

The US position: the arrest was a lawful apprehension of a fugitive. The Maldivian authorities cooperated. The legal process then ran in US federal courts. [SOURCE: DOJ]

In August 2016, after a trial in Seattle, Roman Seleznev was convicted on 38 counts. In April 2017 he was sentenced to 27 years in federal prison — the longest sentence for a hacking crime in US history at the time of sentencing. [SOURCE: DOJ sentencing press release, April 2017] Later in 2017 he pleaded guilty in separate cases in Nevada and Georgia.

He spent a decade in US custody. On August 1, 2024, he was freed in the US–Russia prisoner exchange and flown home. His father sits in the Russian parliament. The piece is the space between the courtroom and the exchange.

He sold card numbers from a server in Russia. America asked the Maldives to arrest him, and the Maldives said yes. His father called it a kidnapping from the floor of the Duma. In 2024 the politics brought him home: he was traded back to Russia in a prisoner exchange. The keyboards stopped. The politics never did.

· PART ONE ·
What He Did — The Carding Operation

The carding economy runs on two things: stolen card data and the infrastructure to sell it. Seleznev supplied both.

He operated under the handle 'Track2' — a reference to the magnetic stripe data on the back of a credit card, which contains the information needed to clone the card or process transactions. The handle is a precise technical description of what he was selling. [SOURCE: DOJ; Krebs on Security]

His operation, per the DOJ indictment and trial record, involved obtaining stolen credit card numbers through point-of-sale malware — software that, when installed on retail payment terminals, harvested card data as customers swiped their cards. The data was then sold in bulk through carding forums: underground marketplaces where stolen card data is priced by type, country, freshness, and associated cardholder information.

The scale: approximately 2.9 million credit card numbers obtained and sold. The attributed fraud losses: approximately $170 million — the losses suffered by card holders and financial institutions as a result of the fraudulent transactions that followed the data theft. [SOURCE: DOJ — verify exact figures to primary charging documents]

The distinction matters: the card count and the fraud loss are different measurements of a different quantity. The card count is how many records were in the database. The loss figure is the dollar harm that resulted from those records being used. They are connected but not interchangeable.

His operation targeted point-of-sale systems at restaurants and small businesses across the United States. The victims were ordinary consumers whose card data moved from their local restaurant's payment terminal to a server controlled by Seleznev, and then to buyers on carding forums who used the data to make fraudulent purchases. The harm was distributed across thousands of individual victims and the financial institutions that bore the chargeback costs.

· PART TWO ·
The Card Fraud Category — The Insider and the Outsider

() and Case 029 (Seleznev) complete the card fraud section of this series. The brief frames them accurately: the insider and the outsider, the American and the Russian, the informant and the exile-turned-prisoner.

GONZALEZ () vs SELEZNEV (Case 029)

Background

Gonzalez: US citizen, Miami, became Secret Service informant while hacking. Seleznev: Russian national, operated from Russia.

Method

Gonzalez: SQL injection attacks on major US retailers (TJX, Heartland). Seleznev: point-of-sale malware + carding forum sales.

Scale

Gonzalez: 170M+ card numbers. Seleznev: 2.9M card numbers, $170M fraud losses.

Sentence

Gonzalez: 20 years (longest hacking sentence at the time). Seleznev: 27 years (then overtook it as the longest).

Political dimension

Gonzalez: none — US citizen, tried domestically. Seleznev: his arrest became a US-Russia diplomatic incident; his father is a Duma member.

The comparison is not to suggest equivalence of conduct — the cases are different in mechanism, scale, and context. It is to make the series argument: card fraud operates at industrial scale, perpetrated by distinct actors with distinct methods, and the US sentencing response has escalated in kind. Gonzalez's 20 years was, in 2010, the longest hacking sentence in US history. Seleznev's 27 years, in 2016, set a new record. The numbers move in one direction.

· PART THREE ·
The Arrest — The Maldives, July 2014

The Maldives is an island nation in the Indian Ocean with which Russia does not have an extradition treaty. It is a place where a Russian national might reasonably feel less exposed to US law enforcement than in a country where cooperation was more established.

In July 2014, Seleznev was at Malé International Airport in the Maldives when US authorities, working with Maldivian officials, apprehended him. He was transferred to Guam — US territory — and from there to the continental United States to face charges. [SOURCE: DOJ; Reuters]

The Russian government's response was immediate and sharp. Valery Seleznev, his father and a member of the State Duma, characterised the arrest as a 'kidnapping' — an illegal seizure of a Russian citizen on foreign soil, orchestrated by the US government. The Russian Foreign Ministry made similar objections through official channels. [SOURCE: BBC; Reuters]

The US did not acknowledge the characterisation. The DOJ described the arrest as a lawful apprehension facilitated by cooperation with Maldivian authorities. The legal proceedings ran in US federal courts. Both positions — the DOJ's account and Valery Seleznev's account — are part of the record. This piece states both, attributed. The legal determination was made by the US courts: he was convicted.

The political dimension of the arrest is context for how the case was received, not the subject of the case. The subject is 2.9 million card numbers and $170 million in fraud losses and 27 years in federal prison.

· PART FOUR ·
38 Counts — The Conviction

The trial in Seattle took place in the Western District of Washington. In August 2016, after a jury trial, Roman Seleznev was convicted on 38 counts — wire fraud, intentional damage to a protected computer, and related charges. [SOURCE: DOJ press release, 2016]

In April 2017 he was sentenced to 27 years in federal prison. At the time of sentencing, it was the longest sentence ever imposed in the United States for a hacking crime. The DOJ described the sentence as appropriate given the scale of the operation and the harm caused to victims. [SOURCE: DOJ sentencing press release, April 2017]

In 2017 he also pleaded guilty in separate cases in Nevada and Georgia, related to different victims and a parallel conspiracy; the resulting sentence was reported as 14 years, running concurrently. [SOURCE: DOJ — verify counts and how the Nevada sentence interacted with the Seattle sentence in terms of total time]

He served about ten years in US custody. On August 1, 2024, he was released in the US–Russia prisoner exchange in Ankara and returned to Russia. [SOURCE: CNN; Krebs on Security, August 2024]

His father, Valery Seleznev, has continued in his role in the Russian Duma. He has spoken publicly about his son's case. His son was released in the August 2024 prisoner exchange, not through the courts. The 27-year sentence was the court's answer; the exchange was the politics'. Both are part of the record.

He sold card numbers from a laptop in Russia. America asked the Maldives to arrest him, and the Maldives said yes. He got twenty-seven years — the longest hacking sentence the country had ever handed down. His father called it a kidnapping from the floor of the Duma. In 2024 the politics brought him home: he was traded back to Russia in a prisoner exchange. The keyboards stopped. The politics never did.

VERIFIED SOURCES
Card numbers ≠ dollars. 2.9M = count. ~$170M = fraud losses. Label both. The father's 'kidnapping' claim is attributed context — not a legal finding. No national generalization. Living persons: Seleznev released to Russia in the August 2024 prisoner exchange, his father a public figure (Duma status: verify current).
[1] US DOJ press release — W.D. Washington conviction, August 2016. 38 counts. [Verify exact counts and charges from primary press release]
[2] US DOJ press release — W.D. Washington sentencing, 2016. 27 years — 'longest sentence for a hacking crime in the US.' [Verify exact sentencing date]
[3] US DOJ — Nevada conviction, 2017. [Verify counts and how the sentence interacted with the Seattle sentence]
[4] Reuters — Maldives arrest, July 2014. Transfer to Guam and US. DOJ and Russian government reactions.
[5] BBC — Valery Seleznev 'kidnapping' characterisation; Russian Foreign Ministry statement.
[6] Krebs on Security — Track2 carding forum and point-of-sale malware operation reporting. Technical context.
[7] Wikipedia — Roman Seleznev. Aggregator. [Verify all key facts to primary sources before publication]
TO VERIFY Birth date · which handles are confirmed as his (Track2 vs Bulba/bandys) · exact DOJ wording on loss figure · exact sentencing dates for both cases · how Nevada sentence combined with Seattle sentence · father's current Duma status · any appeal outcomes
SOURCES
[1] PRIMARY — DOJ: Russian cyber-criminal sentenced to 27 years for hacking and credit card fraud (April 2017)
[2] SECONDARY — Krebs on Security: Track2 coverage; U.S. Trades Cybercriminals to Russia in Prisoner Swap (Aug 2024)
[3] SECONDARY — CNN: Who was freed in the prisoner swap (Aug 1, 2024)
[4] SECONDARY — BBC / Reuters: the arrest and the “kidnapping” claim (July 2014)
[5] AGGREGATOR — Wikipedia: Roman Seleznev
END OF REPORT
#36 OF 45
Dennis Kozlowski
SINGLE PERSON
CASE 038 · CORPORATE FRAUDCONVICTED
Tyco · 8y4m–25 years · paroled 2014
~$134M
WHAT WAS TAKEN
Restitution the court ordered for pay and loans Tyco's board never approved (prosecutors put the total at ~$600M).
HOW
Paid himself bonuses and forgiven loans, then made the records show approvals that never happened.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1975–2002Joins Tyco in 1975, CEO from 1992; the unauthorised pay, loans and the $6,000 shower curtain apartment on Fifth Avenue.SOURCE: Manhattan DA; NY Supreme Court
2002–2005Indicted in Manhattan; mistrial in 2004; convicted at retrial in June 2005.SOURCE: NY Supreme Court
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
DENNIS KOZLOWSKI
HE WROTE THE APPROVAL · TYCO INTERNATIONAL · CASE 038 · CORPORATE FRAUD · MISTRIAL, THEN CONVICTED · PAROLED 2014
RESTITUTION
~$134M ordered (with CFO Swartz)
PROSECUTION TOTAL
~$600M: $150M taken + share sales
FINE
$70M
SENTENCE
8y4m to 25 years · Sept 2005
TRIALS
Mistrial 2004 → guilty 2005
PAROLED
January 2014
THREE NUMBERS: ~$134M = restitution the court ordered · ~$600M = the prosecution’s total (unauthorised pay and loans plus inflated share sales) · $70M = his fine.
FULL PROFILE

IDENTITY

NAME
L. Dennis Kozlowski
BORN
Nov 16, 1946 · Newark, New Jersey
COMPANY
Tyco International · CEO 1992–2002
THE EXHIBITS
A $6,000 shower curtain; a ~$2M birthday party in Sardinia, half billed to Tyco

CASE RECORD

COURT
New York State Supreme Court, Manhattan (state case)
MISTRIAL
April 2004
CONVICTED
June 17, 2005 · grand larceny, securities fraud, falsified records
SENTENCED
Sept 19, 2005 · 8 years 4 months to 25 years
PAROLED
Jan 17, 2014
KNOWN AS
Dennis Kozlowski
STATUS
Convicted
CUSTODY
Released
JUDGE
Michael Obus
CHARGES
Grand larceny · Securities fraud · Falsifying business records · Conspiracy (22 counts)
PLEA
Not guilty — first trial ended in a mistrial (April 2004); convicted at retrial, 17 June 2005
THE PEOPLE AROUND IT
THE CFOSAME SENTENCE
Mark Swartz
Tyco CFO
Convicted with him; paroled 2014.
SOURCE: NYT
THE PROSECUTORMANHATTAN DA
Robert Morgenthau
District Attorney
Brought the case under New York state law.
SOURCE: NYT
THE PARTY~$2M
Sardinia, 2001
His wife’s 40th birthday
Half billed to Tyco; shown to the jury.
SOURCE: Trial record
CASE TIMELINE
1975
Tyco
Joins the company.
SOURCE: Wikipedia
1992
CEO
Leads a buying spree.
SOURCE: Wikipedia
June 2002
Resigns
Then indicted over art sales tax.
SOURCE: NYT
Sept 2002
Indicted
Manhattan DA, with Swartz.
SOURCE: DA
Apr 2004
Mistrial
Juror pressure ends the first trial.
SOURCE: NBC
June 17, 2005
Guilty
At retrial.
SOURCE: DA
Sept 19, 2005
Sentenced
8y4m to 25 years.
SOURCE: DA
Jan 17, 2014
Paroled
After ~8.5 years.
SOURCE: NBC
HOW IT WORKED

HOW THE MONEY LEFT TYCO — DEFENSIVE LEVEL

01
Pay: Bonuses the board never approved
02
Loans: Company loans later forgiven without approval
03
The papers: Records made to show approvals that never happened
04
The shares: Stock sold while the company’s condition was misrepresented
HOW A FORGED APPROVAL WORKS
CEO wants money
-->
Writes the approval
-->
Records look normal
-->
Board never asked

WHAT THIS CASE ESTABLISHED

A control is only as good as who writes it.
Series link: (Ebbers) and (Rigas).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — HE WROTE THE APPROVAL (800 WORDS)
Sources: Manhattan District Attorney / New York State Supreme Court — first trial (2004 mistrial); retrial conviction June 17, 2005; sentencing September 19, 2005 · SEC civil actions · Reuters/NYT/Fortune coverage · CNBC conviction reporting. CRITICAL DISCIPLINE: ~$134M = restitution ordered by the court. $600M is the prosecution's total (unauthorised pay and loans plus inflated share sales), not the restitution order — label it. The $6,000 shower curtain and $2M birthday party are in the trial record as evidence. Do not treat them as mere colour.
· PROLOGUE ·
He Wrote the Receipt

The fraud was not exotic. A public company paid for a CEO's apartment, his wife's birthday party in Sardinia, and a shower curtain that cost $6,000. The company's board approved these payments — or appeared to, because the documentation said so. The documentation was false because Kozlowski had written it.

L. Dennis Kozlowski joined Tyco International in 1975 and rose to CEO. By the late 1990s he had built Tyco into one of the largest conglomerates in the world — diversified manufacturing, fire protection, electronics. The company was real. Its earnings were substantial. The fraud was not in the earnings; it was in what the CEO took out of the company for himself.

The prosecution established two categories of conduct. First: unauthorized compensation — bonuses, loans that were never repaid, and expense reimbursements that the board had not approved and that were structured to look as if it had. Second: falsified records — documentation created or altered to make unauthorized payments appear to have proper board authorization. The first category is self-dealing; the second is fraud.

The first trial, in 2004, ended in a mistrial after a juror received a letter about the case. The retrial produced a conviction on June 17, 2005. Kozlowski and CFO Mark Swartz were each sentenced to 8 years 4 months to 25 years on September 19, 2005, in New York State Supreme Court in Manhattan; Kozlowski was also fined $70 million. The case was brought by the Manhattan District Attorney under state law — grand larceny, securities fraud and falsifying business records. Kozlowski was paroled in January 2014 after serving approximately 8.5 years. [SOURCE: DOJ; CNBC; Wikipedia]

· PART ONE ·
The Details as Evidence

The famous details of this case — the $6,000 shower curtain, the $2 million birthday party for his wife staged in Sardinia and billed in part to Tyco, the Fifth Avenue apartment — were presented at trial as evidence, not as tabloid colour. They served a purpose: to demonstrate the scale of the self-dealing and to show the jury what the unauthorized payments were for.

The shower curtain was part of an apartment that Tyco paid for in New York City. The birthday party — a week-long event in Sardinia for Karen Kozlowski's 40th birthday, attended by business contacts alongside family and friends — was billed partially as a corporate function. Both are in the trial record because both were presented as examples of the kind of expenditure that was being run through the company under falsified authorizations.

The point the prosecution made: these expenditures are what the money was for. Not sophisticated financial manipulation — actual spending, on real things, that a CEO decided a public company owed him without his shareholders or his board having approved it.

· PART TWO ·
The Governance Lesson

The mechanism by which Kozlowski concealed the unauthorized compensation was the falsification of internal records — specifically, the creation of documentation purporting to show board approval for loans and compensation that the board had not approved.

This is the same governance theme the series returns to in Leeson (022), in Kerviel (030), and in the machine-gate framework: a control can be forged. If the person committing the fraud is also the person generating the authorization, the control does not check the conduct. It certifies it.

The board's independent oversight function — the audit committee, the compensation committee, the governance structure that was supposed to prevent exactly this — was bypassed not by breaking it, but by producing false documentation that it appeared to have operated normally. The records said the board approved it. The board had not approved it.

Sarbanes-Oxley (produced by the Ebbers/WorldCom case in 2002) was already law by the time Kozlowski was convicted in 2005. Its personal-certification requirements — CEOs and CFOs signing off on financial statements under criminal penalty — are a response to precisely the conduct Kozlowski engaged in.

VERIFIED SOURCES
[1] Manhattan District Attorney / NY State Supreme Court — first trial (2004 mistrial); retrial conviction June 17, 2005; sentencing September 2005, 8 years 4 months to 25 years.
[2] SEC — civil actions against Kozlowski and Tyco.
[3] CNBC/Reuters — conviction, sentencing, and parole (January 2014) coverage.
[4] NYT/Fortune — the trial record details including the shower curtain and birthday party as trial exhibits.
$600M NOTE The $600M figure is the prosecution's alleged total (~$150M in unauthorised pay and loans plus ~$430M from share sales at inflated prices). The court ordered ~$134M in restitution. Label which number is which.
TO VERIFY Exact conviction and sentencing dates · Exact restitution figure and its split with Swartz · Parole date · Co-defendant Swartz's separate sentencing and current status
SOURCES
[1] PRIMARY — Manhattan District Attorney: conviction and sentence (2005)
[2] SECONDARY — NYT / NBC News: trial, mistrial and parole
END OF REPORT
#37 OF 45
Evaldas Rimašauskas
SINGLE PERSON
CASE 017 · BEC / INVOICE FRAUDCONVICTED
Fake “Quanta” · 5 years · SDNY Dec 2019
~$122M
WHAT WAS TAKEN
Company money: ~$99M from Facebook and ~$23M from Google (named in reporting).
HOW
Posed as a real supplier, Quanta, and sent fake invoices. Staff paid them.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2013–2015Registers a company with the same name as Quanta Computer and sends fake invoices to Facebook and Google; ~$122M paid into his accounts.SOURCE: DOJ SDNY
Mar 2017Arrested by Lithuanian police; extradited to the US in Aug 2017.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
EVALDAS RIMAŠAUSKAS
THE INVOICE · CASE 017 · BEC / FAKE VENDOR · PLEADED GUILTY MAR 2019 · SENTENCED 5 YEARS DEC 2019
STOLEN
~$122M
FROM
Facebook ~$99M · Google ~$23M
SENTENCE
5 years + 2 supervised
FORFEITURE
$49.7M ordered
RESTITUTION
$26.5M ordered
RECOVERED
Google: all · Facebook: most
JUDGE
George B. Daniels · SDNY
STATUS
CONVICTED · deportation expected after sentence
THREE FIGURES — THREE THINGS: ~$122M = money wired to him by the two companies · $49.7M = forfeiture ordered · $26.5M = restitution ordered. The DOJ described the total as “more than $100 million.”
FULL PROFILE

IDENTITY

NAME
Evaldas Rimašauskas (often written Rimasauskas)
NATIONALITY
Lithuanian
AGE
About 50 at his March 2019 plea · 51 at sentencing [CyberScoop] · exact birth date not public
THE DISGUISE
Quanta Computer — a real Taiwanese hardware maker that built servers for both victims
THE FRONT
A company registered in Latvia under the name Quanta Computer [DOJ; Reuters]
METHOD
Look-alike email addresses · fake invoices, purchase orders, contracts, corporate stamps and letters

CASE RECORD

COURT
US District Court, Southern District of New York
INDICTED
December 2016
ARRESTED
March 2017 · by Lithuanian police
EXTRADITED
August 2017 · to the United States
PLEA
Guilty · March 20, 2019 · one count of wire fraud · agreed to forfeit $49.7M
SENTENCED
December 2019 · 5 years + 2 years supervised release · $26.5M restitution
JUDGE
Hon. George B. Daniels
THE VICTIMS & WHAT CAME BACK
VICTIM · SOCIAL MEDIAMOST RECOVERED
Facebook
~$99 million wired · 2013–2015
Paid fake Quanta invoices for about two years. Said afterwards it had recovered the bulk of the money.
SOURCE: Sophos · SecurityWeek · Facebook statement
VICTIM · SEARCH / CLOUDFULLY RECOVERED
Google
~$23 million wired
“We detected this fraud against our vendor management team and promptly alerted the authorities. We recouped the funds.”
SOURCE: Google statement · Sophos
THE TOTALCOURT RECORD
~$122 million
Two companies · two years
The sentencing coverage puts the total above $122 million; the DOJ described it as “more than $100 million.” Neither company was named by the DOJ — Reuters identified them from Lithuanian court records in April 2017.
SOURCE: Sophos · DOJ · Reuters
CASE TIMELINE
2013 – 2015
The Invoices
Fake Quanta invoices go to Facebook and Google. Both pay. About $122 million leaves the two companies over two years.
SOURCE: DOJ · Sophos
April 2017
The Victims Named
Reuters identifies Google and Facebook from Lithuanian court records. Both companies confirm.
SOURCE: Reuters
December 2016 – March 2017
Indicted, Then Arrested
Indicted in Manhattan in December 2016. Arrested by Lithuanian police in March 2017.
SOURCE: The Register · DOJ
August 2017
Extradited
Sent to the United States to face charges in the Southern District of New York.
SOURCE: SecurityWeek · Bloomberg
March 20, 2019
Guilty Plea
Pleads guilty to one count of wire fraud before Judge George Daniels. Agrees to forfeit $49.7 million.
SOURCE: DOJ · Bloomberg
December 2019
Five Years
Sentenced to 5 years in federal prison plus 2 years of supervised release; ordered to pay $26.5 million in restitution.
SOURCE: SecurityWeek · Sophos · The Register
HOW THE FRAUD WORKED

FAKE-VENDOR INVOICE FRAUD — FIVE STEPS

01
Pick a real supplier: Quanta Computer really did build hardware for Google and Facebook, and was paid tens of millions routinely.
02
Become it on paper: Register a company with the same name in Latvia; set up email addresses that look like Quanta’s.
03
Send the paperwork: Invoices, purchase orders, contracts, stamps and letters matching what accounts-payable staff expected.
04
Let the process pay: Employees approve and wire payment for hardware they believe was delivered. No system is hacked.
05
Move the money: Funds land in Latvia and Cyprus, then move on to accounts in Slovakia, Lithuania, Hungary and Hong Kong [DOJ; SecurityWeek].
DOCUMENTED MONEY FLOW
Fake Quanta invoice
-->
Google / Facebook accounts payable
-->
Latvia & Cyprus accounts
-->
Slovakia · Lithuania · Hungary · Hong Kong
IN THEIR WORDS
US ATTORNEY GEOFFREY BERMAN
“He devised a blatant scheme to fleece US companies out of $100 million, and then siphoned those funds to bank accounts around the globe… the arms of American justice are long.” [DOJ, March 20, 2019]
GOOGLE
“We detected this fraud against our vendor management team and promptly alerted the authorities. We recouped the funds.”

WHAT THIS CASE ESTABLISHED

The weak point was a payment process, not a computer. No system was hacked: the attack was on trust in a known supplier.
The same trick as () — business email compromise — worked on two of the most security-conscious companies on earth, for two years.
Big companies can claw money back. Google recovered all of it and Facebook most of it; the victims of Madoff () could not.
$122M is what was taken. The $49.7M forfeiture and $26.5M restitution are court orders, not the loss.
Series thesis, Case 017: the invoice. You cannot patch a process that trusts a PDF.
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE INVOICE (1,600 WORDS)
Sources: DOJ/SDNY plea press release March 2019 · sentencing December 2019 · Judge George Daniels, SDNY · Bloomberg · Reuters · SecurityWeek · Sophos. Facebook ~$99M / Google ~$23M. DOJ characterised total as 'more than $100 million' — multiple sources cite $122M+. $49.7M = forfeiture ordered. $26M+ = restitution ordered. These are three different numbers measuring different things.
METRIC NOTE — READ FIRST: $122M+ = total fraudulent wire transfers from Google and Facebook combined. Google: ~$23M. Facebook: ~$99M.
$49.7M = forfeiture ordered at plea — NOT the same as the loss.
$26M+ = restitution ordered at sentencing — a third, separate figure.
Google fully recovered its money. Facebook recovered most of its money.
Convicted: guilty plea March 2019. Sentenced: 5 years federal prison, December 2019.
· PROLOGUE ·
You Cannot Patch a Process That Trusts a PDF

Between 2013 and 2015, a Lithuanian national named Evaldas Rimasauskas sent emails to employees of Google and Facebook.

The emails looked like they came from Quanta Computer — a Taiwanese hardware manufacturer that both companies legitimately did business with, routinely, for tens of millions of dollars. The emails asked Google and Facebook to wire money to bank accounts for hardware the companies believed they had received. The purchase orders looked correct. The invoices looked correct. The corporate letterhead, the stamps, the signatures — all of it looked correct.

Google wired approximately $23 million. Facebook wired approximately $99 million. [SOURCE: SecurityWeek / Sophos citing sentencing record] The total: more than $122 million sent to accounts he controlled, then moved through banks in Latvia, Cyprus, Slovakia, Lithuania, Hungary, and Hong Kong.

He did not hack Google. He did not breach Facebook's systems. He did not plant malware or exploit a zero-day. He sent emails and invoices. The payment processes trusted the paperwork and paid.

He was approximately 50 years old when he pleaded guilty in March 2019 before US District Judge George Daniels in the Southern District of New York. He was sentenced to five years in federal prison in December 2019, ordered to forfeit $49.7 million, and ordered to pay over $26 million in restitution. [SOURCE: SecurityWeek; DOJ sentencing]

The two companies that built the modern internet — whose entire business is organising and verifying information — were defrauded for two years by invoices that were not real. You cannot patch a process that trusts a PDF.

· PART ONE ·
The Mechanism — What Actually Happened

Quanta Computer is a Taiwanese electronics manufacturer. It builds servers, laptops, and hardware for some of the largest technology companies in the world. Google and Facebook were legitimate, ongoing Quanta customers — the kind of relationship that produces routine multimillion-dollar transactions on established invoice schedules.

Rimasauskas registered a company in Latvia with the name Quanta Computer. [SOURCE: DOJ; Reuters] He created email addresses that appeared to come from the same company. He generated invoices, purchase orders, contracts, corporate stamps, and letters — a complete documentation package designed to match what Google and Facebook expected to receive from their real hardware supplier.

He and his co-conspirators then sent those emails and invoices to employees at both companies, requesting payment for hardware those employees believed they had received. The accounts payable processes at both companies processed the payments.

The money went to bank accounts in Cyprus and Latvia, then moved to additional accounts across multiple jurisdictions. [SOURCE: DOJ plea agreement; SecurityWeek] The scheme ran from 2013 to 2015 — two years, more than $122 million in fraudulent wire transfers, before it was detected.

Lithuanian authorities arrested him in March 2017. He was extradited to the United States in August 2017. [SOURCE: SecurityWeek; Bloomberg citing extradition date]

VICTIM

AMOUNT / OUTCOME

Facebook

~$99 million wired to accounts controlled by Rimasauskas · Facebook: recovered bulk of the funds [Facebook statement]

Google

~$23 million wired · fully recovered: 'We detected this fraud against our vendor management team and promptly alerted the authorities. We recouped the funds.' [Google statement]

Total

More than $122M transferred [Sophos/DOJ sentencing] · DOJ charged 'more than $100 million' in the indictment

· PART TWO ·
Why These Victims — The Inversion

The reason Case 017 exists in this series is not the dollar amount. It is who the victims are.

() defrauded a law firm, a Qatari businessman, wealthy individuals. The mechanism was identical: business email compromise, fake payment instructions, misdirected wires. The dollar amounts were significant.

Rimasauskas defrauded Google and Facebook.

Google is Alphabet — one of the most valuable technology companies in history, whose core product is the organisation and verification of information. Its security apparatus is among the most sophisticated and expensive in the world.

Facebook — now Meta — built the social graph of the internet. It operates at a technical depth that places it in a category with perhaps a dozen other organisations on earth.

Both companies paid fake invoices. Not because their security systems failed technically — those systems were never the attack surface. Because their accounts payable process trusted a PDF with the right name on it.

The FBI's annual IC3 reports rank BEC among the costliest categories of cybercrime loss year after year. This case is one of the most expensive documented proofs of why: the attack surface is human verification, not software. The best security engineers in the world were in the next building. The payment process that processed the fake invoices did not ask them.

One of the most expensive BEC cases on record targeted two of the most sophisticated technology companies on earth. The fraud was a paperwork attack. No malware. No breach. Just invoices that looked correct — and a process that trusted them.

· PART THREE ·
The Plea and the Sentence

On March 20, 2019, Evaldas Rimasauskas pleaded guilty to one count of wire fraud before US District Judge George Daniels in Manhattan. He agreed to forfeit $49.7 million.

US Attorney Geoffrey Berman at the time of the plea: 'As Evaldas Rimasauskas admitted today, he devised a blatant scheme to fleece US companies out of $100 million, and then siphoned those funds to bank accounts around the globe. Rimasauskas thought he could hide behind a computer screen halfway across the world while he conducted his fraudulent scheme, but as he has learned, the arms of American justice are long.' [SOURCE: DOJ press release, March 2019]

At sentencing in December 2019, Judge Daniels sentenced him to five years in federal prison plus two years of supervised release, and ordered him to pay over $26 million in restitution in addition to the $49.7 million forfeiture. [SOURCE: SecurityWeek; DOJ]

The sentence contrast is part of the record. Five years for $122 million in losses that were largely recovered from corporate balance sheets. Madoff received 150 years for a fraud more than a hundred times larger, in which the victims were pensioners and charities with no means of recovery. The difference — victim identity, restitution potential, and cooperation — is how federal sentencing works. It is stated here as observation, not as a claim about proportionality.

He faces almost certain deportation following his sentence. He was convicted and sentenced. The record is closed.

· PART FOUR ·
What This Case Means

Every BEC case in this series — and the FBI's annual IC3 report — makes the same argument: the vulnerability is the human, not the machine. The phishing email works not because it defeats technical controls but because the person receiving it believes it came from somewhere legitimate.

Rimasauskas took that principle to its logical conclusion. He did not target individuals. He targeted a corporate payment process. He registered a company with the same name as a real vendor. He created documents that matched what the accounts payable department expected. He sent them. The process ran.

Google and Facebook subsequently improved their vendor verification processes. Both companies acknowledged the fraud after Reuters obtained Lithuanian court records in 2017 that identified them. Google confirmed full recovery. Facebook confirmed partial recovery. The money moved quickly enough through multiple jurisdictions that recovery was not complete.

The series thesis for Case 017: the invoice. He did not build a persona like . He did not build a brand like Ignatova. He did not build a company like Petters. He built a piece of paper with the right name on it, and the process that was supposed to verify it did not.

It is one of the most expensive business-email-compromise cases on record. The victim companies build software to detect fraud. The fraud was two years of invoices that looked correct. You cannot patch a process that trusts a PDF.

VERIFIED SOURCES
Birth year: reports say approximately 50 at 2019 plea — born c.1969, NOT 1988 as original brief stated. Exact date not in public record — omitted. Scheme: 2013–2015. Arrested Lithuania March 2017. Extradited August 2017. Pleaded guilty March 20, 2019. Sentenced December 2019: 5 years + 2 supervised + $49.7M forfeiture + $26M+ restitution.
[1] DOJ/SDNY — plea press release, March 20, 2019. US Attorney Berman quote. '$49.7M forfeiture.' 'More than $100 million' loss characterisation.
[2] SecurityWeek — sentencing coverage December 2019. Five years + 2 years supervised. $26M+ restitution. Facebook ~$99M / Google ~$23M split. Extradition dates.
[3] Bloomberg — 'Man Pleads Guilty in $100 Million Scam of Facebook and Google,' March 20, 2019. $49.7M forfeiture. Judge George Daniels.
[4] Sophos — 'Man jailed for $122 million scam that fooled Google and Facebook.' Source for total $122M figure; Google full recovery statement; Facebook 'bulk' recovery.
[5] Reuters — initial identification of Google and Facebook as victims via Lithuanian court order, April 2017.
TO VERIFY Exact sentencing date December 2019; whether aggravated identity theft remained in final plea (Bloomberg March 2019 plea indicates one count wire fraud); exact restitution figure.
END OF REPORT
#38 OF 45
Rui-Siang Lin
SINGLE PERSON
CASE 039 · DARK WEBCONVICTED
“Pharaoh” · Incognito Market · 30 years
$105M+
WHAT WAS TAKEN
Drugs sold on his darknet market; he took ~$6M, then kept $1M+ of users' deposits.
HOW
Ran Incognito Market with a 5% cut, then shut it down, kept the deposits and extorted users.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2020–2024Runs Incognito Market from Saint Lucia, according to the DOJ and press; the market moves ~$100M in narcotics.SOURCE: DOJ SDNY
Mar 2024Exit scam: keeps users' deposits and threatens to publish their data.SOURCE: DOJ SDNY
18 May 2024Arrested at JFK Airport.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
RUI-SIANG LIN
THE SEVERANCE PACKAGE · "PHARAOH" · INCOGNITO MARKET · CASE 039 · DARK WEB · 30 YEARS 2026
SALES
$105M+ of drugs sold on the site
HIS TAKE
~$6M in commissions
EXIT
$1M+ of users’ deposits kept
SENTENCE
30 years · Feb 4, 2026
BUYERS
400,000+ · 1,800 vendors
DEATH
At least one, per the DOJ
SALES VS TAKE: $105M is what sold through the market; his own cut was about $6M. The forfeiture was set at $105M.
FULL PROFILE

IDENTITY

NAME
Rui-Siang Lin (林睿庠)
ALIAS
Pharaoh
FROM
Taiwan · ~24 at sentencing
BASED
St. Lucia, per the DOJ and press

CASE RECORD

ARRESTED
May 18, 2024 · JFK Airport
PLEA
Dec 16, 2024 · narcotics conspiracy, laundering, misbranded medicine
SENTENCED
Feb 4, 2026 · 30 years · Judge Colleen McMahon
FORFEIT
$105,045,109.67
BORN
~2001
STATUS
Convicted
CUSTODY
In custody
COURT
US District Court, Southern District of New York
JUDGE
Colleen McMahon
CHARGES
Narcotics conspiracy · Money laundering · Conspiracy to sell adulterated and misbranded medication
PLATFORM
Incognito Market (Oct 2020 – Mar 2024)
THE DARKNET TRILOGY
THE JUDGE30 YEARS
Colleen McMahon
SDNY
“The most serious drug crime I have ever been confronted with.”
SOURCE: Bitdefender citing court
THE EXITMARCH 2024
“YES, THIS IS AN EXTORTION”
His message to users
Kept deposits and demanded payment not to publish users’ records.
SOURCE: DOJ
CASE TIMELINE
Oct 2020
Opens
Incognito Market launches.
SOURCE: DOJ
Jan 2022
Opiates allowed
Fake prescription pills follow.
SOURCE: DOJ
Mar 2024
Exit
Deposits kept; users threatened.
SOURCE: DOJ
May 18, 2024
Arrested
JFK Airport.
SOURCE: DOJ
Dec 16, 2024
Guilty
Three counts.
SOURCE: DOJ
Feb 4, 2026
30 years
Judge McMahon.
SOURCE: DOJ
HOW IT WORKED

HOW INCOGNITO WORKED — DEFENSIVE LEVEL

01
The shop: Vendors listed drugs; buyers paid in crypto
02
The bank: An in-site wallet held everyone’s money
03
The cut: 5% commission on each sale
04
The exit: The operator kept the deposits and threatened users
HOW MONEY MOVED
Buyer’s crypto
-->
In-site “bank”
-->
Vendor paid, 5% kept
-->
Deposits taken at exit

WHAT THIS CASE ESTABLISHED

A darknet market’s own users are the easiest people to rob.
Blockchain tracing and one domain record were enough to find him.
Series link: (Silk Road) and (Hydra).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE SEVERANCE PACKAGE (800 WORDS)
Sources: DOJ/SDNY press release February 4, 2026 (primary) · Guilty plea December 16, 2024 before Judge Colleen McMahon · Arrest May 18, 2024, JFK Airport · Bitdefender / SecurityAffairs / Decrypt citing DOJ. METRIC DISCIPLINE: >$105M = platform sales volume. Lin's actual profit = >$6M (5% commission). These are different numbers. Forfeiture order: $105,045,109.67. Judge McMahon: 'the most serious drug crime I have ever been confronted with in 27.5 years.' One confirmed death: 27-year-old Arkansas man, fentanyl-laced pills from the platform.
· PROLOGUE ·
A Business

Incognito Market was not an ideology. It was a business.

Rui-Siang Lin, 24 years old at the time of sentencing, a Taiwanese national, built Incognito Market and operated it from October 2020 to March 2024 under the alias 'Pharaoh' — from locations including St. Lucia, where he had concurrently established himself as a resource for local law enforcement on cybercrime and cryptocurrency. He provided training to Caribbean police on blockchain and cyber investigations while operating a major narcotics darknet marketplace. [SOURCE: DOJ press release; SecurityAffairs]

The platform: over 400,000 buyers, 1,800+ vendors, 640,000+ completed transactions. $105 million in narcotics sales — cocaine, methamphetamine, heroin, MDMA, counterfeit prescription drugs including fentanyl-laced pills sold as oxycodone. [SOURCE: DOJ February 4, 2026]

Vendors paid a 5 percent commission on each sale. Lin also operated an internal cryptocurrency 'bank' through which he collected payments and held escrowed funds. His total operating profit: approximately $6 million. The $105 million in sales is the platform volume, not his take. [SOURCE: Decrypt citing DOJ]

In January 2022, Lin explicitly allowed the sale of opiates on the platform. This led to counterfeit prescription drug listings. In September 2022, a 27-year-old man in Arkansas died after taking pills he had purchased on Incognito Market that contained fentanyl disguised as oxycodone. The DOJ described Lin as responsible for at least one death. [SOURCE: DOJ press release]

· PART ONE ·
The Exit — Stealing From His Own Customers

In March 2024, Lin abruptly shut down Incognito Market without warning. He stole at least $1 million in user deposits from the platform's internal escrow bank — funds that vendors and buyers had deposited with the expectation they would be returned or applied to transactions.

He then posted a message on the site. The message threatened to publish the transaction histories and cryptocurrency addresses of users unless they paid. It stated, in his own words: 'YES, THIS IS AN EXTORTION!!!' [SOURCE: Bitdefender citing DOJ; SecurityAffairs]

The users he was extorting were criminals — vendors who had sold narcotics on the platform and buyers who had purchased them. They could not file a police report about the theft of their escrow funds or the threat to expose their darknet market activity. They had no recourse. Lin's leverage was precisely their own criminality.

This is the moral inversion unique to this case in the series: every other case involves a fraudster and a victim outside the scheme. Incognito's victims, in the exit scam, were the scheme's own participants. The piece states this factually. It does not frame them as sympathetic; it does not excuse Lin.

· PART TWO ·
Arrest, Plea, and Sentence

Lin was arrested on May 18, 2024 when he flew into New York's JFK Airport en route from the Caribbean to Singapore. He was taken into custody by US authorities. [SOURCE: DOJ; Cyberinsider]

He pleaded guilty on December 16, 2024 before US District Judge Colleen McMahon in the Southern District of New York, to conspiracy to distribute narcotics, money laundering, and conspiring to sell adulterated and misbranded medication.

He was sentenced on February 4, 2026 to 30 years in federal prison. Judge McMahon described Incognito Market as 'a business that made [Lin] a drug kingpin' and called it 'the most serious drug crime I have ever been confronted with in 27.5 years.' [SOURCE: Bitdefender citing DOJ] He was also ordered to forfeit $105,045,109.67 — the platform's total sales volume. He received five years of supervised release to follow his prison term.

US Attorney Jay Clayton stated: 'Rui-Siang Lin was one of the world's most prolific drug traffickers, using the internet to sell more than $105 million of illegal drugs throughout this country and across the globe. While Lin made millions, his offenses had devastating consequences. He is responsible for at least one tragic death.' [SOURCE: DOJ press release February 4, 2026]

VERIFIED SOURCES
[1] DOJ/SDNY press release, February 4, 2026 — full sentencing details, forfeiture order, US Attorney Clayton statement, platform statistics. PRIMARY SOURCE for all figures.
[2] DOJ — guilty plea December 16, 2024, before Judge Colleen McMahon.
[3] Bitdefender citing DOJ — Judge McMahon's quotes; the 'YES, THIS IS AN EXTORTION!!!' message text; the St. Lucia/Caribbean cybercrime training detail.
[4] SecurityAffairs / Decrypt — arrest at JFK May 18, 2024; platform operation details; $6M operator profit figure (5% commission).
TO VERIFY Birth date (approximate 2001-2002) · Exact arrest date (May 18, 2024 widely reported) · Whether the extortion attempt produced any payments · Co-founder status (Lin co-founded with another individual per some reports — verify)
SOURCES
[1] PRIMARY — US Attorney SDNY: sentenced to 30 years (Feb 4, 2026)
[2] SECONDARY — Decrypt / Bitdefender / SecurityAffairs
END OF REPORT
#39 OF 45
Daren Li
SINGLE PERSON
CASE 026 · PIG-BUTCHERING LAUNDERINGFUGITIVE
Fugitive · 20 years in absentia · up to $4M reward
$73.6M
WHAT WAS TAKEN
Money Americans lost to fake romance and investment scams run from Cambodia. He moved it; the scammers took it.
HOW
Set up US shell-company bank accounts to catch victims' wires, then sent the money through a Bahamas bank into crypto.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2021–2024Lives in Cambodia and launders proceeds of the 'pig-butchering' scam centres there through shell companies and US bank accounts; ~$73M.SOURCE: DOJ C.D. Cal. plea
2021–2024Also lives in the UAE, according to the DOJ, while directing the laundering network.SOURCE: DOJ
before 2021Chinese national; lived in China before moving to Cambodia and the UAE, according to the DOJ.SOURCE: DOJ
12 Apr 2024Arrested at Hartsfield-Jackson airport; flees in Dec 2025 after cutting off his ankle monitor.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
DAREN LI
THE PIPELINE · PIG-BUTCHERING LAUNDERER · CASE 026 · PLEADED GUILTY 2024 · FLED 2025 · 20 YEARS IN ABSENTIA 2026
LAUNDERED
At least $73.6M in victim money
VIA US SHELLS
$59.8M through US shell-company accounts
SENTENCE
20 years, in absentia · Feb 2026
STATUS
FUGITIVE since Dec 2025
REWARD
Up to $4M · US State Dept
CITIZENSHIP
China · St Kitts and Nevis (Cambodia also listed)
MONEY MOVED, NOT MONEY STOLEN BY HIM: $73.6M is victim money Li admitted laundering for scam centres in Cambodia. The scammers who talked to victims are separate people.
FULL PROFILE

IDENTITY

NAME
Daren Li
ALIASES
Devon · KG · RF · KG-Perfect · Xuan Li
BORN
November 8, 1982 (US Secret Service) · birthplace not published
CITIZENSHIP
China and St Kitts and Nevis (DOJ); Cambodia also listed by the Secret Service
LIVED IN
China, Cambodia, United Arab Emirates

CASE RECORD

ARRESTED
April 12, 2024 · Atlanta airport
COURT
US District Court, Central District of California (Los Angeles)
PLEA
Guilty, Nov 12, 2024 · money-laundering conspiracy
FLED
December 2025 · cut off his ankle monitor
SENTENCED
February 2026 (DOJ release dated Feb 9) · 20 years, in absentia
WANTED
US Secret Service Most Wanted · reward up to $4M (April 24, 2026)
STATUS
Fugitive
CUSTODY
At large
JUDGE
R. Gary Klausner (reported)
CHARGES
Conspiracy to commit money laundering
NOT CHARGED WITH
Running the romance or investment chats — DOJ says the scammers were unindicted co-conspirators
THE NETWORK
CO-DEFENDANTPLEADED GUILTY
Yicheng Zhang
Temple City, California
Arrested May 16, 2024 in Los Angeles; later pleaded guilty to money-laundering conspiracy.
SOURCE: The Record
SAME NETWORK51 MONTHS
Shengsheng He
La Puente, California
Ran ~$36.9M through a Bahamas company; sentenced Sept 8, 2025, with $26.9M restitution.
SOURCE: DOJ
THE BANKBAHAMAS
Deltec Bank
Nassau
More than $35M of victim money went to accounts there before becoming Tether (TRM Labs).
SOURCE: TRM Labs
THE SHELLS~74 COMPANIES
US shell companies
Opened by associates
Bank accounts that existed to receive victims’ wires and pass them on.
SOURCE: DOJ · TRM Labs
THE VICTIMSACROSS THE US
Americans
Romance and “investment” scams
People who trusted someone they believed cared about them. Not naive — targeted.
SOURCE: DOJ
EIGHT PLEASCONVICTED
Co-conspirators
Same case
Eight co-conspirators have pleaded guilty; Li was the first sentenced who received victim funds.
SOURCE: DOJ, Feb 2026
CASE TIMELINE
~2021–2024
The pipeline
Shell-company accounts receive victims’ wires.
SOURCE: DOJ
April 12, 2024
Arrested
Atlanta airport; flown to Los Angeles.
SOURCE: Secret Service
May 17, 2024
Charges announced
With co-defendant Yicheng Zhang.
SOURCE: Secret Service
Nov 12, 2024
Guilty plea
Admits laundering at least $73.6M.
SOURCE: DOJ
Dec 2025
Gone
Cuts off his ankle monitor and flees.
SOURCE: DOJ
Feb 2026
20 years
Sentenced in absentia in Los Angeles.
SOURCE: DOJ
April 24, 2026
Reward
Up to $4M for information.
SOURCE: US Embassy Cambodia
HOW IT WORKED

HOW THE PIPELINE WORKED — DEFENSIVE LEVEL

01
The scam: Scam centres in Cambodia build fake romances and friendships, then push fake crypto-trading sites
02
The deposit: Victims wire money to US bank accounts of shell companies
03
The layering: Money moves through more accounts and a Bahamas bank
04
The conversion: Converted into Tether (USDT) and sent on to the scam bosses
05
The warning sign: Anyone you have never met who steers you to an investment app is the scam
HOW VICTIM MONEY REACHED CAMBODIA
US victim’s bank
-->
US shell-company account
-->
Bahamas bank
-->
Tether → scam bosses

WHAT THIS CASE ESTABLISHED

Scam compounds are out of reach; the bank accounts they need are not.
Pleading guilty does not end a case: he fled before sentencing.
Series link: () — also a St Kitts and Nevis passport.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PIPELINE (1,000 WORDS)
Sources: US DOJ press releases on Daren Li · US court records (plea and in-absentia sentencing) · FinCEN / Treasury pig-butchering advisories · UNODC SE Asia scam-compound reports. DISCIPLINE: $73M = money LAUNDERED through his pipeline (not stolen by him). He is the movement arm. Never write 'Li stole $73M.' Status: FUGITIVE — pleaded guilty, fled, sentenced in absentia February 2026. Verify all dates to primary before publication.
· PROLOGUE ·
The Money Had to Move

Pig-butchering is the English translation of sha zhu pan — a Chinese term for an investment fraud built on a romance. The victim is cultivated over weeks or months, introduced to a fake investment platform, encouraged to deposit increasing sums, and then the platform disappears and the money is gone.

The operations run these schemes from compounds in Southeast Asia — Myanmar, Cambodia, Laos — where workers generate the messages and maintain the fake relationships. The compounds are largely beyond US law enforcement reach. The operators may be effectively untouchable.

But the money cannot teleport. It exits a US victim's bank account in US dollars and needs to arrive at a compound in Cambodia as something usable. Between those two points, it passes through a banking system — and banking systems have US correspondents, US regulatory requirements, and US paper trails.

Daren Li's role, per the DOJ, was the passage. He held dual citizenship in China and St. Kitts and Nevis. He controlled US-registered shell companies and US bank accounts. At least $73.6 million in victim funds moved through his pipeline, $59.8 million of it through US shell companies. [SOURCE: DOJ, 9 February 2026] He was arrested at Atlanta airport in April 2024 and pleaded guilty in November 2024. In December 2025 he cut off his ankle monitor and fled. In February 2026 he was sentenced in absentia to 20 years. He is a fugitive.

· PART ONE ·
The Pig-Butchering Machine — Context

This piece does not describe how pig-butchering fraud is operated. The series' Category 04 page explains the pattern at the required defensive level. What this case requires is the money-movement context.

The victims of pig-butchering fraud are people who were cultivated in a fake relationship, trusted the person on the other end of the phone, and were convinced to deposit money into what appeared to be a legitimate investment platform. Returns were fabricated. The platform was fake.

The losses are often catastrophic — life savings, retirement accounts, emergency funds. The fraud is designed to maximise extraction by building trust slowly, showing early fake profits, and encouraging reinvestment before the exit. The victims are not naive in any unusual sense. They are people who trusted someone they believed cared about them. This piece does not blame them. The series rule is clear: explain the machine, do not mock the people caught in it.

The UNODC estimates that pig-butchering operations in Southeast Asia generated tens of billions of dollars in the years spanning the pandemic period. The infrastructure is industrial — relationship workers, platform maintainers, and financial pipeline operators. That last piece is where the US has legal reach.

· PART TWO ·
The Pipeline — What He Did

Per the DOJ, Daren Li directed and controlled US-registered shell companies and US bank accounts that existed primarily to receive and launder fraud proceeds. Victim funds — money stolen from Americans through romance-investment fraud — was wired to these accounts. [SOURCE: DOJ — verify charging document and figures before publication]

The money was then layered through additional accounts to obscure its origin and transmitted onward to Cambodia. The passage through the US banking system was a feature: it made the international transfer appear to originate from a legitimate US business.

At least $73.6 million moved through the pipeline. [SOURCE: DOJ] This is money taken from real people in fraudulent schemes. Li did not commit the romance fraud. He laundered its proceeds — moving money from where victims paid it to where operators could use it.

This case exists in US federal court because the pipeline is the soft spot. The scam operators in Cambodia may be beyond reach. The shell company addresses in the United States are not. The bank accounts are not. The laundering arm is where US law enforcement can act. Chokepoints get charged.

· PART THREE ·
Guilty Plea, Fugitive, Sentenced in Absentia

Daren Li was arrested on 12 April 2024 and charged in Los Angeles. On 12 November 2024 he pleaded guilty to money-laundering conspiracy — an admission before a federal judge that he conspired to launder fraud proceeds through US accounts. [SOURCE: DOJ — verify plea date and court venue]

He did not appear for sentencing.

The sequence matters: he was not a fugitive who was never caught. He came into a courtroom, admitted his conduct, and then failed to appear for the consequence. He fled after pleading guilty: in December 2025 he cut off his ankle monitor and disappeared. That detail is part of the record.

In February 2026 (the DOJ release is dated 9 February), a US federal judge in Los Angeles sentenced Daren Li in absentia to 20 years in federal prison. He holds dual citizenship in China and St. Kitts and Nevis — the St. Kitts citizenship, like 's (), provides travel options when avoiding a specific jurisdiction.

He is currently a fugitive. Whether the sentence is ever served depends on whether he is found and whether the country where he is found cooperates with extradition.

VERIFIED SOURCES — EXTENSIVE VERIFICATION REQUIRED
[1] US DOJ — press release(s) on Daren Li. The ~$73M figure. [VERIFY exact figure, charge date, venue before publication]
[2] US court records — plea agreement and in-absentia sentencing (February 2026). [VERIFY exact sentencing date]
[3] FinCEN / Treasury — pig-butchering typology advisories. Money-movement context.
[4] UNODC — SE Asia scam-compound reports. Scale and operational context.
TO VERIFY Charge date and exact venue · plea date · whether $73M is charged amount or total flow · flight date · in-absentia sentencing exact date · co-defendant outcomes · whether 20 years is total or per-count sentence · current DOJ wanted record status
SOURCES
[1] PRIMARY — DOJ: Daren Li sentenced in absentia to 20 years (Feb 9, 2026)
[2] PRIMARY — US Secret Service: arrest release (May 2024) and Most Wanted page
[3] SECONDARY — South China Morning Post / US Embassy Cambodia: reward of up to $4M (April 24, 2026)
[4] SECONDARY — The Record: plea (Nov 2024) and sentencing (Feb 2026)
[5] SECONDARY — TRM Labs: the Li laundering network (Feb 2026)
END OF REPORT
#40 OF 45
Heather Morgan
SINGLE PERSON
CASE 020 · CRYPTO LAUNDERINGCONVICTED
Razzlekhan · 18 months · D.C. 2024
$71M
WHAT WAS TAKEN
Bitcoin from her husband's 2016 Bitfinex hack: ~$71M then, ~$3.6B when seized. She helped launder part of it (~25,000 BTC).
HOW
Moved it through accounts in other names, mixers and foreign banks.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
2016–2022With Ilya Lichtenstein, launders bitcoin stolen from Bitfinex through fake identities, darknet markets and gold; performs as Razzlekhan.SOURCE: DOJ D.D.C.; plea, Aug 2023
Feb 2022Arrested in New York; the government seizes most of the coins.SOURCE: DOJ
2019Spends about a month in Ukraine, which the government says was used to move funds.SOURCE: sentencing filings
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
HEATHER MORGAN
THE ALIBI · “RAZZLEKHAN” · CASE 020 · CRYPTO LAUNDERING · SENTENCED 18 MONTHS NOV 2024 · RELEASED DEC 2025
WHAT SHE DID
Helped launder bitcoin from her husband’s 2016 Bitfinex hack
THE HACK
119,754 BTC · his, not hers
SEIZED
94,643 BTC · ~$3.6B · Feb 8, 2022
SENTENCE
18 months + 3 years supervised
JUDGE
Colleen Kollar-Kotelly · D.D.C.
RELEASED
Dec 28, 2025 · First Step Act credits, no clemency
RESTITUTION
$0 — court ruled Bitfinex not a “victim” under the law
ON NETFLIX
Biggest Heist Ever · Dec 2024
THE SAME COINS, THREE PRICES: 119,754 BTC was worth ~$71M when taken in 2016; the 94,643 BTC seized were worth ~$3.6B in February 2022; more than $10B later. She did not carry out the hack.
FULL PROFILE

IDENTITY

NAME
Heather Rhiannon Morgan
KNOWN AS
Razzlekhan — her rapper persona
FROM
Raised in Tehama, California (population ~400)
EDUCATION
Economics, UC Davis · graduate work at the American University in Cairo
WORK
Research assistant at UC Davis (2011) · Hong Kong · Cairo · founded SalesFolk, a B2B cold-email firm (~2013–14)
WRITING
Inc. columnist (from 2016) · Forbes contributor until September 2021
MARRIED
Ilya “Dutch” Lichtenstein, November 2021

CASE RECORD

COURT
US District Court, District of Columbia · No. 1:23-cr-00239 (CKK)
ARRESTED
February 8, 2022 · Manhattan · age 31
BAIL
Home detention with GPS from February 14, 2022
PLEA
Guilty · August 3, 2023 · money-laundering conspiracy + conspiracy to defraud the US
SENTENCED
November 18, 2024 · 18 months
PRISON
FCI Victorville (women’s camp) from ~February 2025; home confinement ~October 2025
RELEASED
December 28, 2025
TWO PEOPLE — TWO CHARGES — TWO SENTENCES
ILYA LICHTENSTEIN
Carried out the 2016 Bitfinex hack — his own admission. 60 months, November 14, 2024; released early under the First Step Act, January 2026.
HEATHER MORGAN
Did not carry out the hack. Pleaded guilty to laundering and defrauding the US. 18 months, November 18, 2024.
WHEN SHE KNEW
Prosecutors: he told her in early 2020. She had suspected an illicit source, “such as drugs or tax evasion.”
HER ROLE
“Thrust into the middle of a serious criminal scheme without her initial consent” — but she “used her own skillset to aid and enhance his criminal endeavors” (prosecutors, Oct 2024).
RAZZLEKHAN — THE PUBLIC PERSONA
YOUTUBE & MUSICRAPPER
The videos
From ~2018
“Versace Bedouin”, “SaaSholes” (2020), “Menace to Society” (shot in Ho Chi Minh City), “Turkish Martha Stewart” (performed at her wedding). Prosecutors later quoted a lyric: “Spear phish your password / All your funds transferred.”
SOURCE: Rolling Stone · NYMag
THE CHARACTERSELF-DESCRIBED
“Crocodile of Wall Street”
“Like Genghis Khan, but with more pizzazz”
Her website pitched Razzlekhan as “more fearless and more shameless than ever before.” On TikTok she called herself a “$pace Pimp.”
SOURCE: Rolling Stone · NBC News
THE COLUMNSFORBES · INC.
Social engineering expert
“Persuasion, social engineering and game theory”
Wrote on protecting businesses from cybercriminals (“Experts Share Tips To Protect Your Business From Cybercriminals”, June 2020). Forbes dropped her in September 2021.
SOURCE: Forbes · NBC News
THE TALK · 2019ON STAGE
“How to Social Engineer Your Way Into Anything”
New York
“I do believe that the ends justify the means sometimes… My end goals aren’t bad or evil.”
SOURCE: Forbes, Feb 9, 2022
THE COMPANYFOUNDER
SalesFolk
B2B cold-email copywriting
Inc. described her journey from “sleeping on couches to creating a bootstrapped seven-figure business.” Lichtenstein was listed as an adviser in 2014.
SOURCE: Forbes
AFTER THE CASESTILL RECORDING
New songs & Netflix
2024–2025
Netflix’s Biggest Heist Ever (dir. Chris Smith, Dec 6, 2024). Songs “Razzlekhan vs. The United States” (Jan 2025) and “Turki$h Martha” (Nov 2025).
SOURCE: TIME · CoinDesk · Decrypt
KNOWN NETWORK
THE HACKERRELEASED 2026
Ilya “Dutch” Lichtenstein
Her husband
Russian-born US citizen; co-founded MixRank (Y Combinator 2011), later Endpass. Admitted the hack; testified in the Bitcoin Fog trial; 60 months.
SOURCE: DOJ · CoinDesk
THE VICTIM$0 RESTITUTION
Bitfinex
Crypto exchange
Lost 119,754 BTC in August 2016. In April 2025 the court ruled it is not a “victim” for restitution; the seized coins went to a separate forfeiture proceeding.
SOURCE: US v. Morgan, Apr 4, 2025
THE INVESTIGATORSTRACED IT
IRS-CI
Special Agent Chris Janczewski
With FBI Chicago and HSI New York. Decrypted Lichtenstein’s files on January 31, 2022; a week later, the seizure.
SOURCE: DOJ · Forbes
THE COURTSENTENCED BOTH
Judge Colleen Kollar-Kotelly
D.C. federal court
“You were true partners in this laundering scheme.” “You did not stop voluntarily.”
SOURCE: CoinDesk
WHAT INVESTIGATORS FOUND
THE APARTMENT
75 Wall Street, searched January 5, 2022: ~$40,000 cash, a bag labelled “burner phone”, 50+ devices, two hollowed-out books
THE CLOUD FILES
~2,000 bitcoin addresses with private keys; folders named “personas” and “passport_ideas”; a wallet file named “dirty_wallet.dat”
THE SMALL THINGS
A $500 Walmart gift card redeemed in her name helped justify the warrants
THE GOLD
Gold coins “which Morgan then concealed by burying them” in California (DOJ) — dug up by investigators
AFTER THE RAID
Threw a computer down a garbage chute and deleted data (prosecutors)
IN THEIR WORDS
PROSECUTORS
“She made a conscious decision to engage in specific criminal activity, helping her husband launder millions in stolen funds for their personal gain.”
MORGAN AT SENTENCING
“I am extremely sorry and deeply regret the choices I made… The harm I’ve caused will haunt me for the rest of my life.”
WHITE HOUSE, OCT 2025
The president “had nothing to do with a commutation of her sentence” — responding to her “Papa Trump” video.
CASE TIMELINE
2011
UC Davis
Economics degree; research assistant.
SOURCE: Forbes
~2013–14
SalesFolk
Launches her company; meets Lichtenstein.
SOURCE: Forbes · NYMag
August 2016
The hack
Lichtenstein takes 119,754 BTC from Bitfinex (~$71M then).
SOURCE: DOJ
2018
New York & Razzlekhan
Moves to 75 Wall Street; starts rapping.
SOURCE: NYMag
August 2019
Ukraine; the talk
A month in Ukraine; “How to Social Engineer Your Way Into Anything.”
SOURCE: Forbes
Early 2020
She is told
Lichtenstein tells her he did the hack.
SOURCE: The Record
November 2021
Married
SOURCE: NYMag
January 5, 2022
The search
$40K cash, burner phones, hollowed-out books.
SOURCE: Forbes
February 8, 2022
Arrested; $3.6B seized
94,643 BTC — the DOJ’s largest financial seizure then.
SOURCE: DOJ
August 3, 2023
Guilty pleas
Both plead guilty.
SOURCE: DOJ
November 2024
Sentences
Him: 5 years (Nov 14). Her: 18 months (Nov 18).
SOURCE: USAO · CoinDesk
December 6, 2024
Netflix
Biggest Heist Ever.
SOURCE: TIME
February 2025
Prison
Reports to FCI Victorville.
SOURCE: Victor Valley News
April 4, 2025
$0 restitution
Court ruling on Bitfinex.
SOURCE: CourtListener
December 28, 2025
Released
Full release after home confinement.
SOURCE: Bitcoin.com · Decrypt
HOW IT WORKED

LAUNDERING STOLEN CRYPTO — AS THE DOJ DESCRIBED IT

01
Fake identities: Accounts at exchanges opened with fictitious identities
02
Darknet markets: Coins moved through AlphaBay from early 2017, later Hydra
03
Mixers & privacy coins: Bitcoin Fog, Helix and ChipMixer; chain-hopping into Monero
04
Cash-out: US business accounts, Russian and Ukrainian middlemen, gold coins (buried), gift cards, NFTs
05
The trail: IRS-CI followed the blockchain; files decrypted January 31, 2022; seizure February 8
WHERE THE MONEY WENT
Bitfinex hack wallet
-->
Mixers & darknet markets
-->
Fake-name exchange accounts
-->
Gold, gift cards & foreign banks

WHAT THIS CASE ESTABLISHED

The crime after the crime: stolen crypto is useless until it is laundered, and laundering is where most thieves get caught.
The blockchain does not forget. Coins moved in 2016 were traced and seized in 2022.
She did not hack Bitfinex. Her conviction is for laundering and defrauding the United States.
Her early release came from prison credits, not clemency — despite her public thanks to the president.
Series link: () built a brand to show off the money; Razzlekhan’s persona made people stop asking.
THE FULL STORY — 6 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE ALIBI (2,500 WORDS)
Sources: DOJ / US District Court, District of Columbia plea records · Morgan plea August 3, 2023 · Sentencing November 18, 2024 · Lichtenstein sentencing November 14, 2024 · DOJ seizure announcement February 8, 2022 · Bloomberg · Reuters · CoinDesk · The Block · Decrypt. METRIC DISCIPLINE: 119,754 BTC stolen August 2016 (~$71M at that date) · 94,643 BTC seized February 2022 (~$3.6B at that date). SAME COINS, DIFFERENT DATES. Date every figure.
· PROLOGUE ·
The Alibi

The music videos are the point.

Not because they are amusing, or strange, or because the internet found them funny in February 2022 when the DOJ unsealed its case. They are the point because a person who launders money needs a public identity that makes them look harmless — and nothing makes a person look more harmless than being a joke.

Heather Rhiannon Morgan, known online as Razzlekhan, had a rap persona. Self-described: 'the most dangerous woman in tech.' She wrote columns about cybersecurity, small business, and social engineering for Forbes and Inc. She performed at cryptocurrency events. Her music videos — produced, uploaded, and distributed under her own name — circulated widely in the crypto community.

The DOJ's case, as it emerged in February 2022, was about something underneath all of it. Her husband, Ilya 'Dutch' Lichtenstein, had hacked the Bitfinex cryptocurrency exchange in August 2016, stealing 119,754 Bitcoin worth approximately $71 million at the time. [SOURCE: DOJ] The coins sat largely dormant. Then, from 2016 to 2022, a laundering operation moved them through a layered architecture of fictitious identities, account hops, and asset conversions designed to break the chain back to Bitfinex.

She pleaded guilty to money laundering conspiracy on August 3, 2023. She was convicted. She was sentenced to 18 months in federal prison on November 18, 2024 in Washington D.C. She served her sentence at FCI Victorville, California.

The music videos were not the crime. They were the air. While the press treated Razzlekhan as a novelty — the eccentric rapper whose husband had stolen Bitcoin — the laundering was a different operation running underneath the same name.

built a brand to display the money. Razzlekhan built a persona to explain away the money. Both were performances. One bragged. One sang off-key. The off-key one nearly worked.

· PART ONE ·
The Hack — What Lichtenstein Did

This part is Lichtenstein's. It is context for her case. It is not her charge.

In August 2016, Bitfinex — a major cryptocurrency exchange — was hacked. 119,754 Bitcoin were stolen from the exchange's multisignature wallet infrastructure. The attack, at the time valued at approximately $71 million, was one of the largest crypto hacks on record and sent Bitcoin's price down nearly 20% on the day the breach was announced. [SOURCE: DOJ; Bloomberg]

The stolen coins were held in wallets controlled by the hacker. For years, the coins moved in small amounts — exploratory transactions, washing through intermediary addresses — but the bulk of the hoard remained dormant. The blockchain preserved every movement, but the connection back to Bitfinex was obscured by layering.

In August 2023, Ilya Lichtenstein pleaded guilty and admitted he had carried out the hack. He was sentenced to five years in federal prison on November 14, 2024. [SOURCE: Bloomberg sentencing coverage]

This is where his story ends in this case file. The hack is context. The laundering is the case.

LICHTENSTEIN'S ROLE — FOR THE RECORD: He carried out the Bitfinex hack — his own admission in his guilty plea.

Sentence: 5 years · sentenced November 14, 2024, Washington D.C. federal court. [SOURCE: Bloomberg]

She was 'initially unaware' of how he obtained the BTC — prosecutors stated she became aware in early 2020 when he told her he was behind the hack. Her charged involvement began from that point.

His sentence, his hack, his figure: 5 years. Her sentence: 18 months. These are different people.

· PART TWO ·
The Laundering — What She Pleaded Guilty To

Money laundering conspiracy. That is the charge. That is what she admitted.

The DOJ's description of the laundering operation: the stolen funds were moved through a layered structure designed to sever the trail back to the Bitfinex hack. The mechanism included moving funds between accounts, converting Bitcoin to other assets, using fictitious identities and fake names, and withdrawing through chains of intermediary steps. [SOURCE: DOJ plea agreement / DOJ press release]

Prosecutors described Morgan as a 'lower-level participant' relative to Lichtenstein. She played a smaller role in the conspiracy, became involved after being told about the hack in early 2020, and the government noted she had spent only 'a small fraction' of what the pair had stolen. [SOURCE: DOJ sentencing filing, October 2024]

Her lawyers argued her involvement stemmed from loyalty to her husband rather than personal intent — that she became aware of the source of the funds and, rather than reporting it, chose to assist him. Prosecutors did not dispute the outline, but were clear: 'She made a conscious decision to engage in specific criminal activity, helping her husband launder millions in stolen funds for their personal gain. It was not a momentary lapse or impulsive decision.' [SOURCE: DOJ sentencing filing quoted in CoinMarketCap/Reuters coverage]

She cooperated with the government. The cooperation credit is documented in the sentencing recommendation — prosecutors cited her 'substantial assistance' as the basis for recommending 18 months rather than a longer term. [SOURCE: DOJ filing; CoinMarketCap coverage]

FIGURE

WHAT IT MEASURES — DATE LABELLED

119,754 BTC

Total stolen from Bitfinex, August 2016. Value at hack: ~$71 million. [SOURCE: DOJ / Bloomberg]

94,643 BTC

Amount seized by DOJ, February 8, 2022. These are the same coins — the remainder had been laundered or moved. [SOURCE: DOJ forfeiture filing]

~$3.6 billion

Value of 94,643 BTC at time of February 2022 seizure. NOT the value in 2016. Same coins, different date. [SOURCE: DOJ announcement]

~$71 million

Approximate value of 119,754 BTC at the time of the August 2016 hack. [SOURCE: Bloomberg / DOJ]

18 months

Morgan's sentence — her personal sentence only. Imposed November 18, 2024. FCI Victorville, California. [SOURCE: Bloomberg; Decrypt]

5 years

Lichtenstein's sentence — his. Imposed November 14, 2024. Different person, different number. [SOURCE: Bloomberg]

· PART THREE ·
Razzlekhan — The Persona as Operational Security

The brief for this piece opens with an instruction: do not write the comedy version.

The Razzlekhan persona is easy to mock. The music videos are objectively strange. The self-description — 'the most dangerous woman in tech,' 'Crocodile of Wall Street,' 'a surrealist rapper and economist' — reads as performance art. The internet treated her as a novelty when her arrest was announced. That reaction is the whole point.

Consider the operational logic. A person who assists in laundering billions in stolen cryptocurrency needs a public identity. The identity needs to explain the lifestyle — the appearances at conferences, the international travel, the proximity to crypto money — without triggering the question of where the money actually comes from. It needs to be conspicuous enough to register but strange enough that nobody takes it seriously as the cover story of a money laundering operation.

The eccentric rapper persona — in this framing — performed exactly that function. It put Heather Morgan in front of cameras at cryptocurrency events. It gave her a reason to be publicly connected to the crypto world. It created a character so bizarre that scrutiny slid off it. Nobody investigates the comedian. Nobody runs due diligence on the joke.

The brief states this clearly, and it is worth stating here: this is not a claim that the persona was consciously constructed as operational cover from the start. It is an observation about function. Whatever its origin, the Razzlekhan brand served as a layer of public identity that made questions feel unnecessary. In the world of money laundering, that function has a name.

Before her arrest, she wrote columns for Forbes and Inc. about protecting businesses from cybercriminals and about social engineering — 'your way into anything,' as one column put it. She wrote about how criminals exploit trust. She was, on her published record, an expert in how people get deceived.

Holmes wore a black turtleneck. Madoff chaired NASDAQ. Morgan rapped. Each disguise was calibrated to the environment it needed to work in. The most effective cover is the one that makes a reasonable person stop asking questions. Strange people do not launder money. Strange people are just strange.

· PART FOUR ·
The Seizure — February 2022

On February 8, 2022, the United States Department of Justice announced the seizure of approximately 94,643 Bitcoin with a value of approximately $3.6 billion — the largest financial seizure in DOJ history at that point. [SOURCE: DOJ press release, February 8, 2022]

The same day, Heather Morgan and Ilya Lichtenstein were arrested in New York.

The seizure figure — 94,643 BTC — is not the full hack total. 119,754 BTC were stolen from Bitfinex in August 2016. The difference — approximately 25,111 BTC — had been laundered and dispersed through the operation. Investigators recovered the bulk, not all.

At the February 2022 seizure date, Bitcoin was trading at approximately $38,000. The seized 94,643 BTC was valued at approximately $3.6 billion. That is the seizure figure. That is the date it belongs to. The same coins were worth approximately $71 million in August 2016. The distance between those two numbers — $71 million to $3.6 billion — is six years of Bitcoin's price history, not the scale of the laundering operation itself.

The Decrypt coverage notes that by late 2025, the recovered Bitcoin had a value of more than $11 billion — same coins, later date, higher price. Every figure in this case must carry its date or the reader is misled.

· PART FIVE ·
The Conviction and Sentence

August 3, 2023. Heather Morgan pleaded guilty to money laundering conspiracy and conspiracy to defraud the United States before a federal court. Ilya Lichtenstein pleaded guilty the same day.

More than a year passed between the guilty pleas and the sentencing. During that period, Morgan remained free on bail, subject to strict pretrial conditions. She attended some cryptocurrency conferences. She continued to create content as Razzlekhan — releasing a song about the emotional experience of impending incarceration, and maintaining an active presence on Cameo, where she billed herself as 'crypto's favorite felon.' [SOURCE: Decrypt]

Lichtenstein was sentenced on November 14, 2024: five years. Morgan was sentenced on November 18, 2024: 18 months. Both sentencings took place in Washington D.C. federal court. Judge Colleen Kollar-Kotelly sentenced both: 'You were true partners in this laundering scheme.' [SOURCE: Bloomberg; The Block]

At sentencing, Morgan addressed the court: 'I am extremely sorry and deeply regret the choices I made… I used my time and energy to do harm instead of good, and I'm ashamed of that.' [SOURCE: CoinDesk sentencing coverage]

She was designated to FCI Victorville in California. By November 2025, she was posting from custody — indicating she remained incarcerated roughly a year into her 18-month sentence. In late October 2025, she posted on X: 'I wanna give a shout-out to papa Trump for making my 18-month sentence shorter' — though her early release came from First Step Act credits, not clemency. [SOURCE: Decrypt; San Antonio news coverage] A White House official said the president 'had nothing to do with a commutation of her sentence.' Her time was cut through First Step Act credits and home confinement; her full release date was December 28, 2025. [SOURCE: CoinDesk, October 2025; Bitcoin.com, November 2025]

· PART SIX ·
The Inversion — and Case 020

() built a brand around the money. The Rolls-Royces, the Gucci, the private jets, the 2.5 million Instagram followers watching the lifestyle in real time. He was the most visible BEC fraudster in the world because he chose to be visible. The brand attracted law enforcement. The Instagram account was evidence.

Razzlekhan built a brand that explained the money away. The persona was not an accident of personality — it was a functional layer. Strange people are eccentric. Eccentric people are not criminals. Eccentric people who rap about being dangerous in the crypto world are content creators, not launderers.

This is the inversion the brief identifies, and it is the right frame. Both and Morgan were performers. Both built public identities connected to the crypto world. The identities served opposite functions: one displayed the crime and got caught. One obscured the crime and nearly didn't.

The series thesis for Case 020 is not that she was a criminal mastermind. She was a lower-level participant, per the prosecutors who sentenced her. The theft was her husband's. The laundering was hers. The cooperation was significant. The sentence was 18 months.

The thesis is about the function of the persona. The most operationally significant thing Razzlekhan did was make herself impossible to take seriously. In money laundering, the best cover is the one that makes a reasonable person stop asking. The music videos worked, until they didn't.

She made music videos so strange that nobody looked at what she was actually doing. The performance was the alibi. The disguise worked so well that the world wrote her off as a joke — while the money moved. bragged and got caught. Razzlekhan sang off-key and nearly didn't.

VERIFIED SOURCES
Living persons — both convicted and sentenced. Report per the record only. No editorialising on the music or the persona's quality. The piece is about laundering. Date every BTC figure. Birth date not confirmed in primary sources — omitted.
[1] DOJ press release, February 8, 2022 — 'Two Arrested for Alleged Conspiracy to Launder $4.5 Billion in Stolen Cryptocurrency.' Seizure: 94,643 BTC at ~$3.6B. First mention of both defendants.
[2] DOJ / D.D.C. — Morgan guilty plea, August 3, 2023. Money laundering conspiracy + conspiracy to defraud US. [Verify exact docket / case number before publication]
[3] DOJ sentencing filing, October 2024 — prosecutors recommend 18 months. Morgan 'lower-level participant.' 'Substantial assistance.' She was 'initially unaware' — Lichtenstein told her in early 2020. [SOURCE: CoinMarketCap / Reuters citing filing]
[4] Bloomberg — Lichtenstein 5-year sentencing, November 14, 2024; Morgan 18-month sentencing, November 18, 2024, Washington D.C. federal court.
[5] The Block — 'Heather Razzlekhan Morgan sentenced to 18 months for role in Bitfinex heist,' November 18, 2024. Both sentencing dates confirmed.
[6] Decrypt — 'Bitfinex Bitcoin hack money launderer Razzlekhan release new music,' November 2025. FCI Victorville confirmed via Morgan's own posts. Early release post (late October 2025, X/Twitter).
[7] CoinDesk / Forklog — Morgan at-sentencing statement: 'I am extremely sorry and deeply regret the choices I made.'
[8] CoinMarketCap — Morgan asks for leniency, October 31 defense filing. Defense argument: loyalty, not intent. 'Deeply remorseful.' The 'Razzlekhan' persona described as a 'caricature' by her own lawyers.
[9] Reuters / Bloomberg — Bitfinex hack 2016 coverage; seizure 2022; ongoing laundering analysis.
VERIFY BEFORE PUBLICATION Exact sentence reduction mechanism (good-conduct credits, commutation, or other executive action — 'papa Trump' reference per her October 2025 X post is informal, not a DOJ confirmation); exact docket number; birth date if needed; BTC value at 2016 hack (~$71M — verify to DOJ filing); 94,643 BTC split verification.
SOURCES
[1] PRIMARY — DOJ: Two Arrested for Alleged Conspiracy to Launder $4.5 Billion in Stolen Cryptocurrency (Feb 8, 2022)
[2] PRIMARY — DOJ: Bitfinex Hacker and Wife Plead Guilty (Aug 3, 2023)
[3] PRIMARY — US v. Morgan, D.D.C. No. 1:23-cr-00239 (CKK); restitution opinion Apr 4, 2025
[4] SECONDARY — Forbes (Feb 9 & 10, 2022); NYMag (Feb 15, 2022); Rolling Stone (Feb 8, 2022); NBC News (Feb 9, 2022)
[5] SECONDARY — CoinDesk (2022–2026); The Record (Nov 18, 2024); TRM Labs
[6] SECONDARY — TIME (Dec 6, 2024) — Biggest Heist Ever
END OF REPORT
#41 OF 45
Raj Rajaratnam
SINGLE PERSON
CASE 033 · INSIDER TRADINGCONVICTED
Galleon Group · 11 years · SDNY 2011
~$63.8M
WHAT WAS TAKEN
Profits from trading on insiders' tips (prosecutors). The victim was the market.
HOW
Insiders at companies passed him news before it was public; the FBI recorded the calls.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1997Founds Galleon Group.SOURCE: case brief
2003–2009Trades on tips from insiders at Intel, IBM, McKinsey and Goldman; ~$63.8M in profits and avoided losses.SOURCE: SDNY verdict, 2011
16 Oct 2009Arrested by the FBI in New York.SOURCE: DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
RAJ RAJARATNAM
THE PHONE CALL · GALLEON GROUP · CASE 033 · INSIDER TRADING · 14 COUNTS · 11 YEARS
PROFITS
~$63.8M from tips (prosecutors)
SEC
~$92.8M civil penalty
FORFEIT + FINE
$53.8M + $10M
SENTENCE
11 years · Oct 13, 2011
THE TOOL
FBI wiretaps on a hedge fund
RELEASED
Home confinement July 2019
DIFFERENT NUMBERS: ~$63.8M = trading profits and losses avoided · $92.8M = SEC civil penalty · $53.8M = forfeiture. The victim is the market, not his own investors.
FULL PROFILE

IDENTITY

NAME
Raj Rajaratnam
BORN
June 15, 1957 · Colombo, Sri Lanka
FIRM
Galleon Group, New York (founded 1997)
SCHOOL
Wharton MBA

CASE RECORD

ARRESTED
Oct 16, 2009 · FBI
CONVICTED
May 11, 2011 · all 14 counts
SENTENCED
Oct 13, 2011 · 11 years · Judge Richard Holwell
APPEAL
Upheld June 24, 2013
RELEASED
July 23, 2019 · home confinement (First Step Act)
STATUS
Convicted
COURT
US District Court, Southern District of New York
JUDGE
Richard J. Holwell
CHARGES
Securities fraud · Conspiracy (14 counts)
PLEA
Not guilty — convicted by a jury on all 14 counts, 11 May 2011
THE NETWORK
THE TIPSTERCONVICTED 2012
Rajat Gupta
Goldman Sachs board member
Passed boardroom news to Rajaratnam; 2 years.
SOURCE: DOJ
THE PROSECUTORSDNY
Preet Bharara
US Attorney
His office used the Galleon wiretaps to build a wider crackdown.
SOURCE: DOJ
THE JUDGE11 YEARS
Richard Holwell
SDNY
Then the longest US insider-trading sentence.
SOURCE: PBS Frontline
THE SEC$92.8M
Civil penalty
Nov 2011
A separate civil case alongside the criminal one.
SOURCE: SEC
CASE TIMELINE
1997
Galleon
Founds the hedge fund.
SOURCE: Wikipedia
2003–2009
The tips
Insiders pass news before it’s public.
SOURCE: DOJ
Oct 16, 2009
Arrested
FBI arrest after wiretaps.
SOURCE: DOJ
May 11, 2011
Guilty
All 14 counts.
SOURCE: DOJ
Oct 13, 2011
11 years
Judge Holwell.
SOURCE: DOJ
June 24, 2013
Appeal lost
Second Circuit.
SOURCE: Reuters
July 23, 2019
Home
First Step Act.
SOURCE: Bloomberg
HOW IT WORKED

HOW INSIDER TRADING WORKS — DEFENSIVE LEVEL

01
The tip: An insider learns news before it’s public
02
The call: They pass it on
03
The trade: Buy or sell before the news
04
The proof: Wiretaps turned suspicion into recordings
HOW A TIP BECOMES PROFIT
Boardroom news
-->
Phone call
-->
Trade before the announcement
-->
Profit after

WHAT THIS CASE ESTABLISHED

Wiretaps, once used for the mob, now convict hedge-fund managers.
Insider trading harms everyone else in the market.
Series link: (Milken) and (Belfort).
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PHONE CALL (700 WORDS)
Sources: DOJ/SDNY indictment; conviction May 11, 2011; sentencing October 13, 2011; appeal denial 2013 · SEC civil action (~$92.8M penalty) · FBI wiretap authorization records · Reuters/Bloomberg/NYT trial coverage. METRIC DISCIPLINE: ~$63.8M = illegal trading gains and losses avoided (DOJ criminal figure). ~$92.8M = SEC civil penalty (different forum). These are different numbers. Neither is 'customer money' — the victim is market integrity, not his own investors.
· PROLOGUE ·
The Crime That Was Common Knowledge

Insider trading was one of Wall Street's worst-kept secrets. The pattern was visible: certain traders consistently bought ahead of earnings announcements, ahead of merger disclosures, ahead of FDA decisions. The timing was too consistent to be luck. The returns were too reliable to be skill. The inference was reasonable. The proof was not.

Raj Rajaratnam founded the Galleon Group in 1997. By the mid-2000s it was one of the largest hedge funds in the world, managing billions in assets. His returns were strong. His network was extensive. His phone was busy.

Between 2003 and 2009, Rajaratnam ran what the DOJ described as a network of insiders — corporate officers, board members, consultants, and others who passed him material non-public information about companies before that information was disclosed to the market. Galleon traded ahead of those disclosures. The fund made money. The network grew.

The FBI obtained wiretaps. The recordings captured him receiving tips directly — specific, clear calls in which specific people told him specific things that the market did not yet know. The suspicion became evidence. The evidence became 14 counts. The counts became 11 years. [SOURCE: DOJ/SDNY; FBI wiretap records]

· PART ONE ·
The Network — Information as Supply Chain

The insider-trading network Rajaratnam built was not one tipster. It was multiple sources across multiple companies, providing information about earnings, M&A, and product decisions — a sustained information supply chain. Key figures in the network included Rajat Gupta, a former McKinsey managing director and Goldman Sachs board member, who was separately convicted in 2012 and sentenced to 2 years. [SOURCE: DOJ Gupta case]

The mechanism: an insider receives non-public information through their role — in a board meeting, in an earnings review, in an M&A process. They communicate that information to Rajaratnam before it is publicly disclosed. Galleon trades ahead of the disclosure. The position is closed after the public announcement moves the price. The profit is the difference between the insider's price and the market's price after disclosure.

The harm is not to Rajaratnam's own investors — Galleon's clients benefited from the returns. The harm is to every other participant in the market who traded without the same information. Market integrity depends on the assumption that prices reflect publicly available information. Insider trading corrupts that assumption without leaving a specific identifiable victim.

The DOJ attributed approximately $63.8 million in illegal profits and losses avoided to the scheme. The SEC's civil action produced a penalty of approximately $92.8 million — a separate civil figure in a separate forum. [SOURCE: DOJ criminal record; SEC civil action — verify exact SEC figure]

· PART TWO ·
The Conviction and the Crackdown

The trial lasted approximately two months. The jury convicted Rajaratnam on all 14 counts on May 11, 2011 — securities fraud and conspiracy. He was sentenced to 11 years on October 13, 2011 by Judge Richard Holwell in the Southern District of New York — at the time, the longest sentence ever imposed in the United States for insider trading. [SOURCE: DOJ/SDNY]

The Second Circuit upheld the conviction on June 24, 2013. On July 23, 2019 he was moved to home confinement under the First Step Act, which lets some inmates over 60 finish their sentences at home; he had served nearly eight years, mostly at FMC Devens. He was also ordered to forfeit $53.8 million and pay a $10 million fine.

The Galleon case opened a broader crackdown. US Attorney Preet Bharara's office used the wiretap precedent to investigate hedge fund information networks across the industry. Dozens of people were convicted in the broader sweep (some convictions were later overturned after a 2014 appeals ruling) — traders, analysts, corporate officers, consultants. [SOURCE: DOJ — verify exact count] The era of easy insider trading, if it had ever been easy, became definitively more dangerous.

VERIFIED SOURCES
[1] DOJ/SDNY — indictment; conviction May 11, 2011, 14 counts; sentencing October 13, 2011, 11 years, Judge Richard Holwell.
[2] SEC — civil action, ~$92.8M civil penalty. Separate from the criminal case. [Verify exact figure]
[3] DOJ — Rajat Gupta case (separate): former Goldman board member, convicted June 2012, sentenced to 2 years.
[4] Reuters/Bloomberg/NYT — trial, sentencing, and crackdown coverage throughout 2011-2013.
TO VERIFY Exact SEC penalty figure · Release date and legal basis (health grounds) · Exact count of broader crackdown convictions (80+ figure — verify to DOJ press releases) · Appeal exact date and court
SOURCES
[1] PRIMARY — US Attorney SDNY: conviction and sentence (2011)
[2] PRIMARY — SEC: $92.8M penalty (2011)
[3] SECONDARY — Reuters: appeal (2013); Bloomberg: release (2019)
END OF REPORT
#42 OF 45
Nicholas Truglia
SINGLE PERSON
CASE 025 · SIM SWAPCONVICTED
SIM swap · 18 months → 12 years
$23.8M
WHAT WAS TAKEN
Crypto stolen from one investor, Michael Terpin, after his phone number was hijacked.
HOW
Hackers took over the phone number and reset his accounts. Truglia turned the crypto into bitcoin, passed it on and kept a cut.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
Jan 2018Takes part in the SIM swap that drains ~$23.8M from Michael Terpin.SOURCE: DOJ SDNY plea
Nov 2018Arrested in Manhattan on California charges.SOURCE: case brief
2023Detained in Miami for moving money and luxury spending while owing $20.4M restitution; resentenced to 12 years in 2025.SOURCE: SDNY
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
NICHOLAS TRUGLIA
THE PHONE NUMBER · SIM SWAP · CASE 025 · 18 MONTHS (2022) → 12 YEARS (2025)
STOLEN
~$23.8M in crypto · one investor
HIS CUT
At least $673,000
RESTITUTION
$20,379,007 ordered · nothing paid
FIRST SENTENCE
18 months · Dec 1, 2022
RESENTENCED
12 years · July 10, 2025
VICTIM
Michael Terpin, crypto investor
HIS ROLE: Truglia converted the stolen crypto into bitcoin and passed it on, keeping a cut. He is not charged with doing the SIM swap itself.
FULL PROFILE

IDENTITY

NAME
Nicholas Truglia
FROM
Florida, US (DOJ: “Florida man”) · lived in Manhattan in 2018
BORN
~1997 (21 at his 2018 arrest)
HANDLE
@erupts
LIFESTYLE
Reported luxury watches, private jets, nightclubs (Krebs on Security)

CASE RECORD

ARRESTED
Nov 14, 2018 · Manhattan (California case, a separate ~$1M theft)
COURT
SDNY · 1:19-cr-00921 · Judge Alvin K. Hellerstein
PLEA
Guilty, Dec 2021 · conspiracy to commit wire fraud
SENTENCED
Dec 1, 2022 · 18 months + $20,379,007 restitution
DETAINED
May 2023, Miami · released Nov 2024
RESENTENCED
July 10, 2025 · 12 years (guidelines: 51–63 months)
ALIASES
@erupts
STATUS
Convicted
CUSTODY
In custody
CASE NUMBER
1:19-cr-00921
JUDGE
Alvin K. Hellerstein
CHARGES
Conspiracy to commit wire fraud
NOT CHARGED WITH
Carrying out the SIM swap itself — his role was converting and passing on the stolen crypto
VICTIM
Michael Terpin, crypto investor
THE PEOPLE AND THE LAWSUITS
THE VICTIM$23.8M
Michael Terpin
Crypto investor
His AT&T number was moved to a hacker’s SIM on Jan 7, 2018; his wallets were drained within hours.
SOURCE: DOJ · Terpin filings
ALLEGED RINGLEADER$22M SETTLEMENT
Ellis Pinsky
Aged 15 in 2018
Agreed in Oct 2022 to pay Terpin $22M; approved Nov 2022. Never criminally charged, as far as reported.
SOURCE: CoinDesk
THE CARRIER$224M SUIT
AT&T
Terpin v. AT&T
The fraud claims and $200M punitive request were dismissed in 2020; one claim was revived on appeal in 2024. Outcome not reported.
SOURCE: 9th Circuit, 2024
THE CIVIL CASE$75.8M
Terpin v. Truglia
California, May 2019
A default judgment for Terpin against Truglia: $24M plus punitive damages.
SOURCE: Krebs on Security
THE ASSETSOVER $50M
What he held
While paying nothing
Reported as $53M at sentencing; a July 2025 court order put them at $61.8M.
SOURCE: Decrypt · Cointelegraph
THE JUDGE12 YEARS
Alvin K. Hellerstein
SDNY
“If ten years are OK, I’ll sentence you to twelve.”
SOURCE: Inner City Press
CASE TIMELINE
Jan 7, 2018
The number moves
Terpin’s phone goes dead; ~$23.8M drained.
SOURCE: DOJ
Aug 15, 2018
Terpin sues AT&T
$224M claim.
SOURCE: court filings
Nov 14, 2018
Arrested
Manhattan, on California charges.
SOURCE: Krebs
May 2019
$75.8M judgment
Civil default judgment for Terpin.
SOURCE: Krebs
Dec 2021
Guilty plea
Wire-fraud conspiracy, SDNY.
SOURCE: DOJ
Dec 1, 2022
18 months
Plus $20.4M restitution.
SOURCE: DOJ
Dec 31, 2022
Deadline missed
$12.1M due; nothing paid.
SOURCE: DOJ
May 2023
Detained
Miami: moving money, buying luxury goods.
SOURCE: Decrypt
Nov 2024
Released
Judge hopes he will pay from outside.
SOURCE: crypto.news
July 10, 2025
12 years
Resentenced for wilful non-payment.
SOURCE: Decrypt
HOW IT WORKED

HOW A SIM SWAP WORKS — DEFENSIVE LEVEL

01
The target: A phone number that receives two-factor codes for crypto accounts
02
The swap: Someone convinces the carrier to move the number to a SIM card they control
03
The reset: Password-reset codes now arrive on the attacker’s phone
04
The drain: Wallets and exchange accounts are emptied
05
The cash-out: Truglia’s role: convert the tokens to bitcoin and pass them on, keeping a cut
06
The defence: Use an authenticator app or security key, not SMS; set a carrier PIN / port-out lock
HOW THE MONEY MOVED
Terpin’s number hijacked
-->
Accounts reset & drained
-->
Tokens converted to bitcoin
-->
Passed to the group

WHAT THIS CASE ESTABLISHED

A phone number is not a secret: it is a customer-service decision.
Courts can add years when stolen money is never returned.
Series link: the first case in the SIM Swap category.
THE FULL STORY — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE PHONE NUMBER (900 WORDS)
CORRECTIONS TO BRIEF: Initial sentence was 18 months (December 2022, SDNY federal), NOT 10 years (2019 NY state). The fraud claims and $200M punitive-damages request in Terpin's AT&T lawsuit were dismissed in 2020; one claim was revived on appeal in 2024. The $22M was a settlement with alleged ringleader Ellis Pinsky, not AT&T. Resentencing to 12 years confirmed July 2025. Sources: SDNY records · Decrypt / Cointelegraph (resentencing, July 2025) · The Record / SecurityWeek (2022 sentencing) · Terpin public statements.
· PROLOGUE ·
The Phone Number Was the Key

In January 2018, Michael Terpin's phone stopped working.

He was a prominent cryptocurrency investor. What was happening on the other end of his number: Nicholas Truglia and co-conspirators had convinced AT&T to transfer Terpin's phone number to a SIM card they controlled. SIM swap is a customer-service transaction — if you call your carrier and provide sufficient identifying information, the carrier will move your number to a new device.

Once Terpin's number was on their SIM, they reset passwords on accounts protected by two-factor authentication sent to that number. They intercepted the verification codes. They drained his cryptocurrency accounts. Approximately $23.8 million in crypto was stolen. [SOURCE: SDNY indictment; The Record]

The crypto was never hacked. The keys were never touched. The exchange's security worked as designed. The recovery channel — the phone number — was the attack.

· PART ONE ·
How SIM Swap Works — The Principle

Two-factor authentication works by sending a code to a device you own as a second check beyond your password. The assumption is that even if an attacker has your password, they do not have your physical phone. The second factor is the thing only you possess.

SIM swap breaks this assumption by going to the source: not your device, but the carrier that controls your number. If the attacker can convince the carrier that they are you, the carrier transfers the number. Your phone goes dead. Their phone now receives every code sent to your number.

The attack surface is not cryptographic. It is human and institutional. The carrier's verification process — the questions it asks, the training of its representatives — is the control that either holds or fails. When it fails, a phone number is a customer-service decision someone else made.

This is the mechanism the series' SIM-swap category has listed as an empty slot. Case 025 fills it: the documented case where this was used to steal $23.8 million from a sophisticated investor who had done nothing technically wrong.

· PART TWO ·
The Theft and the Conspirators

Truglia's role, per SDNY prosecutors: he received the stolen cryptocurrency, converted it to Bitcoin, and distributed it to co-conspirators — keeping approximately $673,000 as his share. The total moved through his accounts: approximately $23.8 million. [SOURCE: SDNY; SecurityWeek]

The alleged mastermind was Ellis Pinsky — who was 15 years old at the time of the 2018 hack. In October 2022, Pinsky agreed to pay Terpin $22 million to settle his civil suit; the court approved it in November 2022. That settlement is with Pinsky, not AT&T.

Terpin also sued AT&T — the carrier whose verification process failed — for $224 million, including $200 million in punitive damages. In 2020 a federal court dismissed the fraud claims and the punitive-damages request; in 2024 an appeals court revived one claim, and the case went on. The brief for this case had these two civil outcomes confused. The correction is documented here and in the sources section.

Truglia's criminal case was in the Southern District of New York. He was sentenced in December 2022 to 18 months — with approximately 12 months already served — and ordered to pay $20,379,007 in restitution to Terpin. He was released shortly after sentencing. [SOURCE: The Record; SecurityWeek]

· PART THREE ·
The Second Act — He Didn't Pay

The restitution schedule required $12.1 million by December 31, 2022, and $8.28 million by January 30, 2023. Truglia paid neither — despite holding more than $50 million in assets.

In May 2023, he was detained in Miami for moving funds and purchasing luxury goods while owing unpaid restitution. Despite a contempt order, he was released in November 2024 — the judge determined he might repay from outside prison. He did not make any payments.

At the 2025 resentencing hearing, prosecutors presented a courtroom video of Truglia boasting about hiding stolen cryptocurrency. The judge found the non-payment wilful. Resentencing: 12 years in federal prison — more than double the federal guidelines recommendation. [SOURCE: Decrypt; Cointelegraph, July 2025]

The sentence grew not because the original crime became worse, but because the court's restitution obligation was treated with contempt.

VERIFIED SOURCES AND CORRECTIONS
[1] SDNY — conviction and sentencing, December 2022. 18 months. $20,379,007 restitution ordered. [Verify docket]
[2] The Record — 'SIM-swapper gets 18 months, must pay back $20 million.' December 2022.
[3] SecurityWeek — sentencing details. Confirmed SDNY venue.
[4] Decrypt — 'SIM Swapper … Resentenced to 12 Years in Prison.' July 2025. Confirmed: assets over $50M, Miami detention, November 2024 release, 12-year resentencing.
[5] Cointelegraph — 'Crypto scammer gets 12 years after reneging on restitution deal.' July 11, 2025.
[6] Malwarebytes — initial coverage; Ellis Pinsky settlement ($22M); AT&T punitive-damages claim dismissed 2020.
CORRECTIONS Brief had two errors: (1) initial sentence 18 months not 10 years; (2) only part of the AT&T lawsuit was dismissed — the $22M settlement was with Pinsky, not AT&T. Both corrected throughout.
TO VERIFY Exact resentencing date · exact SDNY docket · birth date · FTX-hack SIM-swap link is reporting only (attribute to reporting, not court record)
SOURCES
[1] PRIMARY — US Attorney SDNY: Florida man sentenced to 18 months for SIM-swap theft (Dec 1, 2022)
[2] PRIMARY — Terpin v. AT&T Mobility, 9th Cir. No. 23-55375 (Sept 30, 2024)
[3] SECONDARY — Decrypt / Cointelegraph: resentenced to 12 years (July 2025)
[4] SECONDARY — CoinDesk: Pinsky $22M settlement (Oct 14, 2022)
[5] SECONDARY — Krebs on Security: arrest, judgment and lifestyle (2018–2021)
END OF REPORT
#43 OF 45
Charles Ponzi
SINGLE PERSON
CASE 009 · HISTORIC · THE ORIGINALDECEASED 1949
Carlo Ponzi · Securities Exchange Company · Boston 1920
$20M
WHAT WAS TAKEN
Investors' cash in 1920, about $237M in today's money.
HOW
Promised 50% in 45 days on postal-coupon trades, and paid early investors with later deposits.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1903Arrives in Boston on the SS Vancouver, by his account with $2.50.SOURCE: his autobiography (self-serving)
1919–1920Runs the Securities Exchange Company on School Street, paying old investors with new deposits; up to ~$250,000 a day at the peak.SOURCE: In re Ponzi, 268 F. 997; Boston Post
Aug–Nov 1920Boston Post exposes him; bank run, bankruptcy, guilty plea to larceny in Suffolk County.SOURCE: Boston Post; court record
1907–1911Works at Banco Zarossi, which paid depositors out of new deposits; jailed three years for forging a cheque.SOURCE: case brief
1939–1949After deportation to Italy, works for an Italian airline in Rio; dies there in 1949 with about $75.SOURCE: case brief
METHODS USED
Tap a method to see where it came from and everyone who used it.
Photo: Unknown photographer (1920) · Public domain · Wikimedia Commons
TAP A SECTION TO OPEN IT
KEY FACTS
CHARLES PONZI
CARLO PONZI · SECURITIES EXCHANGE COMPANY · CASE 009 · CONVICTED 1920 · DIED 1949
INVESTOR LOSSES
~$20M [1920 dollars]
ADJUSTED (2024)
~$237M equivalent
SCHEME DURATION
~8 months (1919–1920)
INVESTORS
~10,000–40,000 [contested]
ARRIVED IN US
1903 · $2.50 in pocket
DIED
January 18, 1949 · Rio de Janeiro · ~$75
PROMISE
50% in 45 days · 100% in 90 days
STATUS
Deceased · Convicted 1920
METRIC NOTE: $20M in 1920 dollars ≈ $237M in 2024 purchasing power [ESTIMATE — inflation-adjusted]. Exact victim count is contested in the historical record: between 10,000 and 40,000. The legal and journalistic record is clear; exact figures from his autobiography are self-serving and used with care throughout.
FULL PROFILE

IDENTITY

BIRTH NAME
Carlo Pietro Giovanni Guglielmo Tebaldo Ponzi
BORN
March 3, 1882 · Lugo, Emilia-Romagna, Italy
DIED
January 18, 1949 · Hospital Umberto I, Rio de Janeiro · aged 66
ARRIVED IN US
November 15, 1903 · Boston · SS Vancouver
ARRIVED WITH
“$2.50 in cash and $1 million in hopes” — his own words [SOURCE: Ponzi’s autobiography — self-serving]
ESTATE AT DEATH
~$75
COMPANY
Securities Exchange Company · Boston · incorporated 1919
VEHICLE
International Reply Coupons (IRCs) — stated; never executed at scale

CASE RECORD

FEDERAL BANKRUPTCY
In re Ponzi, 268 F. 997 (D. Mass., November 12, 1920) [PRIMARY]
STATE CHARGES
Suffolk County · 22 counts larceny · guilty plea November 30, 1920 [ABA Journal]
FEDERAL SENTENCE
5 years · served ~3.5 years · released 1922
STATE SENTENCE
Convicted 1926 · ~7–9 years · served until 1934
DEPORTED
1934 · to Italy (never became US citizen)
ACTUAL IRCs HELD
$61 worth at time of audit [SOURCE: International Banker]
PRIOR CRIMES
Forgery · Canada 1908–1911 (3 yrs) · immigrant smuggling · Atlanta 1911 (2 yrs)
THE TWO PEOPLE WHO BROKE HIM
FINANCIAL JOURNALIST · THE ARITHMETICVINDICATED
Clarence Barron
Boston News Bureau · Boston Post · July–August 1920
Calculated mathematically that the volume of International Reply Coupons required to generate the promised returns did not exist in the world. Published findings in the Boston Post, August 2, 1920. The arithmetic was the exposure — not a leak, not a whistleblower, just a journalist who did the math.
SOURCE: Boston Post Aug 2, 1920 · International Banker
PONZI’S OWN PUBLICIST · THE INSIDE ACCOUNTVINDICATED
William McMasters
Ponzi’s hired publicist · exposed him from inside
Ponzi hired McMasters to manage positive press coverage. McMasters investigated from inside, concluded the scheme was fraudulent, and wrote a devastating insider account for the Boston Post in August 1920. The man hired to protect the brand destroyed it. The Boston Post investigation is widely cited as helping win the paper a Pulitzer Prize. [VERIFY Pulitzer attribution to primary before publication]
SOURCE: Boston Post Aug 1920 · Wikipedia / McMasters entry
THE SERIES ARGUMENT

HE NAMED THE THING THE THING IS STILL RUNNING

Charles Ponzi did not invent the Ponzi scheme. The structure — paying earlier investors with later investors’ money, maintaining a cover story about legitimate returns, collapsing when inflows can no longer fund redemptions — predates him. William W. Miller ran the “Franklin Syndicate” in Brooklyn in 1899, promising 520% annual returns. [SOURCE: Wikipedia / secondary — verify to primary before publication]

What Ponzi contributed was the version that stuck. He ran it in one summer in one city with one promise, and the Boston Post documented it in a way that gave the English language a permanent name for the pattern. Every fraud prosecutor in the world now uses the phrase he made necessary.

Madoff: 48 years · $64.8B fabricated · . Ponzi: 8 months · ~$20M · Case 009.
The template. The record-holder. The man the scheme is named after. The scheme that is named after him.
CASE TIMELINE
3 Mar 1882
Born, Lugo, Italy
SOURCE: case brief (sources listed in its SOURCES part)
15 Nov 1903
Arrives in Boston
by his account with $2.50
SOURCE: case brief (sources listed in its SOURCES part)
1907
Moves to Montreal
becomes involved in forgery
SOURCE: case brief (sources listed in its SOURCES part)
1908–1911
3 years in Canadian prison (forgery)
SOURCE: case brief (sources listed in its SOURCES part)
UNDATED
Returns to US
later involved in smuggling Italian immigrants across the border; 2 years in Atlanta Prison — became a translator for the warden
SOURCE: case brief (sources listed in its SOURCES part)
1918
Marries Rose Gnecco, a Boston stenographer
SOURCE: case brief (sources listed in its SOURCES part)
1919–1920
Launches the Securities Exchange Company
the scheme begins
SOURCE: case brief (sources listed in its SOURCES part)
24 Jul 1920
Boston Post prints a favourable article
investors pour in faster than ever. Ponzi was making ~$250,000 a day
SOURCE: case brief (sources listed in its SOURCES part)
26 Jul 1920
A bank run hits his company
he pays it off and it stops
SOURCE: case brief (sources listed in its SOURCES part)
2 Aug 1920
Boston Post turns
Clarence Barron's investigation (via McMasters, paid $5,000) declares Ponzi hopelessly insolvent: claimed $7M liquid, actually ≥ $2M in debt, up to $4.5M in the red
SOURCE: case brief (sources listed in its SOURCES part)
Aug 1920
Massachusetts AG J. Weston Allen moves
Hanover Trust ordered to stop paying his checks; involuntary bankruptcy filed by small investors
SOURCE: case brief (sources listed in its SOURCES part)
12 Nov 1920
In re Ponzi, 268 F. 997 (D. Mass.)
SOURCE: case brief (sources listed in its SOURCES part)
30 Nov 1920
Ponzi pleads guilty to larceny (Suffolk County
22 counts)
SOURCE: case brief (sources listed in its SOURCES part)
1920–1922
5 years US federal (mail fraud)
served ~3½ before facing the state charge
SOURCE: case brief (sources listed in its SOURCES part)
1927–1934
9 years state
SOURCE: case brief (sources listed in its SOURCES part)
1934
Deported
SOURCE: case brief (sources listed in its SOURCES part)
18 Jan 1949
Dies in Rio de Janeiro, aged 66
SOURCE: case brief (sources listed in its SOURCES part)
HOW THE FRAUD WORKED

THE SCHEME, STATED PRECISELY — FROM THE CASE BRIEF

01
The claimed arbitrage: International postal reply coupons could be bought cheaply in certain countries (notably Italy, where currencies were weak)
02
They could be redeemed in the US at face value
03
The spread was, in theory, profit
04
Why it wasn't the story: The actual volume of reply coupons in existence could never support the money Ponzi was taking in
05
He was not running the arbitrage at scale — he was paying old investors from new investors' deposits
06
The "mechanism" was the cover story, not the engine
07
The structure: returns paid from new capital → the scheme survives while inflows exceed redemptions → collapse when they don't. His name attached to it permanently.
DEFENSIVE LEVEL ONLY · THE SHAPE OF THE SCHEME, NOT A PLAYBOOK

WHAT THIS CASE ESTABLISHED

He named the crime. Not by inventing it — by running it so visibly and so completely that the newspapers found the words, the courts found the law, and the English language absorbed his name as the permanent label.
He arrived with $2.50 (his account). He died with $75. The scheme took in ~$20M between those two figures, paid some investors, left the rest with nothing.
His own publicist exposed him. Ponzi hired McMasters to manage the brand. McMasters looked at the books and wrote the story that brought the scheme down. The Carreyrou inversion — not a journalist from outside, but the hired hand who couldn’t stay quiet.
Every case in this series is a version of the same structure: pay old investors with new investors’ money while the cover story holds. He gave the pattern its name. The pattern preceded him and outlasted him.
Series thesis, Case 009: the man named it. The thing he named is still running. Somewhere, right now, someone is being told they have found the next wave. The mechanism is the same one Ponzi ran in Boston in 1920.
BIOGRAPHY — THE MAN BEFORE THE NAME

EARLY LIFE & IMMIGRATION

FULL NAME
Carlo Pietro Giovanni Guglielmo Tebaldo Ponzi
BORN
3 March 1882 · Lugo, Emilia-Romagna · Kingdom of Italy
EDUCATION
University of Rome — attended but did not complete · financial pressure
ARRIVED USA
15 November 1903 · Boston · S.S. Vancouver from Genoa
CLAIMED ASSETS
$2.50 in his pocket — his own account [autobiography — self-serving; treat as lore]
LANGUAGES
Italian, later English and others · multilingual ability used throughout career
EARLY JOBS
Waiter · clerk · odd jobs · developed skill reading people · no professional standing
WIFE
Rose Maria Gnecco · Boston stenographer · married 1918 · divorced 1937

THE THREE PRISONS

CANADA · 1908–1911
3 years · Saint-Vincent-de-Paul penitentiary, Quebec · forgery in connection with Banco Zarossi Montreal fraud
BANCO ZAROSSI LESSON
Zarossi ran a fraudulent bank paying old depositors with new depositors' money — Ponzi saw the mechanism firsthand
ATLANTA · c.1910–1911
Additional time for smuggling Italian immigrants across the US border · became prison translator for warden
TRANSLATOR DETAIL
His linguistic skill and social intelligence — used throughout — earned him the warden's trust even in prison
US FEDERAL · 1920–1924
5 years mail fraud · served ~3.5 years before facing state charge
MASSACHUSETTS STATE · 1927–1934
9 years larceny · continued running schemes even during appeal process
FLORIDA 1925
Land fraud scheme in Florida while Boston conviction under appeal — ran a second fraud while fighting the first
DEPORTATION
1934 · deported to Mussolini's Italy after completing Massachusetts sentence
THE SCHEME & THE NEWSPAPERS

THE SECURITIES EXCHANGE COMPANY

FOUNDED
Late 1919 · Boston
THE PROMISE
50% in 45 days · 100% in 90 days — paid in early stages to build credibility
COVER STORY
International Postal Reply Coupon arbitrage — buy cheap in Italy (weak currency), redeem at face value in US
WHY IT WAS A LIE
Total global supply of reply coupons could never support the volume Ponzi was taking in [Barron investigation]
PEAK INTAKE
~$250,000/day at peak [widely reported — verify to primary]
BOSTON POST ARTICLE
July 24, 1920 — favourable article · investor rush accelerated · Ponzi took in more in days than weeks before
THE BANK RUN
July 26, 1920 — clients tried to withdraw · Ponzi paid everyone · crowd cheered · run stopped · paid with new inflows
TOTAL LOSSES
~$20 million in 1920 dollars · ~$237M in 2024 adjusted [case brief sourcing]

THE JOURNALISTS WHO ENDED IT

CLARENCE BARRON
Boston News Bureau · identified the arithmetic impossibility · how many coupons would Ponzi need to exist?
WILLIAM MCMASTERS
Ponzi's own publicity agent · paid ~$5,000 by the Boston Post for his insider account [verify exact figure]
THE EXPOSÉ
August 2, 1920 · Boston Post publishes Barron's findings · Ponzi claimed $7M liquid · actually $2M–$4.5M in debt
CONSEQUENCE
Massachusetts AG J. Weston Allen moves · Hanover Trust ordered to stop his checks · involuntary bankruptcy
LEGAL RECORD
In re Ponzi, 268 F. 997 (D. Mass., 12 Nov 1920) · Suffolk County — 22 counts larceny · guilty plea Nov 30, 1920
PULITZER PRIZE
Boston Post won Pulitzer Prize for the investigation [verify primary attribution]
WILLIAM W. MILLER
Brooklyn 1899 — '520% Miller' — ran similar scheme, took ~$1M · Ponzi may have been inspired [secondary sources only — not confirmed]
PONZI DID NOT INVENT IT
The scheme existed before him. He made it famous enough to be named after him.

THE LEGACY — WHY THE NAME STUCK

He died on January 18, 1949, in a charity ward at Hospital Umberto I in Rio de Janeiro. He was 66 years old. He had approximately $75. He had arrived in America with $2.50 — by his own account. His wife had left him. Every country he had lived in had eventually imprisoned or deported him.
He had run his scheme for eight months. His name is now synonymous with a category of crime that existed for centuries before him and continues today. The name stuck not because he invented the scheme but because the scheme was documented in real time by good journalists, prosecuted by a functioning legal system, and explained clearly enough that English absorbed his name as the permanent label.
Every case in this series descends from the structure he made famous. Madoff ran it for 48 years. Ignatova ran it with a fake blockchain. ran it through a hedge fund. Stanford ran it through certified deposits. The mechanism is always the same: new investors fund old investors' returns, the story explains why that is legitimate, and it ends when the inflows stop.
The Boston Post article is one of the most consequential pieces of financial journalism in American history. The paper won a Pulitzer. The story it broke gave English a new word for a specific category of crime. And the man at the centre of it died in a charity ward having never stopped insisting the arbitrage was real.
THE FULL STORY — 9 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE NAME (3,800 WORDS)
Sources: In re Ponzi, 268 F. 997 (D. Mass., 12 Nov 1920) · Suffolk County indictment, 22 counts larceny; guilty plea 30 Nov 1920 · US federal mail fraud conviction, 1920 · Massachusetts AG J. Weston Allen · Boston Post (24 Jul 1920; 2 Aug 1920) · Clarence Barron / Boston News Bureau · ABA Journal · New England Historical Society · Wikipedia (aggregator; claims verified to primary where possible). $20M = investor losses in 1920 dollars. ~$237M = 2024 inflation-adjusted equivalent. Myth distinguished from documented record throughout. Ponzi's own autobiography used with care — self-serving.
· PROLOGUE ·
The Name

Every fraud in this series has a name. . . Madoff. Holmes. Ignatova.

One of them gave a name to the crime itself.

Not the crime he invented — the crime that carries his name was running before he arrived, and was running after he left. What he contributed was not the mechanism. The mechanism is older and simpler than any one person. What he contributed was the version that stuck: the execution, the scale, the public spectacle, and the fall that was so complete and so documented that the newspapers found the words for it, the courts found the law for it, and the English language absorbed his name as the permanent label.

Carlo Pietro Giovanni Guglielmo Tebaldo Ponzi. Born March 3, 1882, in Lugo, a town in the Emilia-Romagna region of what was then the Kingdom of Italy. Died January 18, 1949, in Rio de Janeiro, Brazil, aged 66, in a charity ward.

Between those two facts: three countries, three prisons, one wife, one deportation, a promise of 50% in 45 days, and approximately $20 million in 1920 dollars — roughly $237 million in 2024 purchasing power — taken from somewhere between ten thousand and forty thousand investors who believed him. [SOURCE: case brief citing primary sources; exact victim count is contested in the historical record]

He did not invent the Ponzi scheme. He made it his name.

· PART ONE ·
From Lugo to Boston — $2.50 in His Pocket

He arrived in Boston on November 15, 1903, aboard the S.S. Vancouver, sailing from Genoa. By his own account, he had $2.50 in his pocket. [SOURCE: Ponzi's autobiography, The Rise of Mr. Ponzi — use with care: self-serving. The $2.50 figure is widely repeated from his own telling.]

The Italian emigrant arriving in America with next to nothing and building something large is a specific narrative that Ponzi understood and deployed. He told the $2.50 story. He told it as an origin — the proof that he had started from the bottom, that the rise was self-made, that the money was the result of extraordinary individual capacity rather than inherited advantage. The story, whether strictly accurate or not, was part of the persona from the beginning.

He was well-educated by Italian provincial standards — he had attended the University of Rome for a time before family financial pressures ended his studies. He arrived in America speaking limited English, with facility in Italian and, eventually, several other languages. He was charming, social, and good at reading rooms. These were the tools he had.

His early years in America were characterised by a series of jobs — waiter, clerk, import-export agent — and a series of failures and marginal dealings that did not yet rise to the level of crime but established a pattern: he was drawn to schemes at the edges of the legitimate, to the gap between what was promised and what was delivered, to the specific opportunity created by the difference between what people believed and what was true.

In 1907, he moved to Montreal. There he became involved with a bank — Banco Zarossi — that was itself operating a fraud, paying interest on deposits from later depositors' money. He learned something from this, even if he did not design it. He was convicted of forgery in connection with these activities and served three years in a Canadian prison from 1908 to 1911. [SOURCE: case brief citing primary record]

He returned to the United States. He was later arrested in Atlanta in connection with smuggling Italian immigrants across the border and served time at the federal prison there, where he became a translator for the prison warden — a detail that speaks to both his linguistic ability and his social skill, two of the essential tools he would later use at scale.

In 1918, he married Rose Maria Gnecco, a Boston stenographer. He was 36 years old. He had a criminal record in two countries and, by most measures, no particular prospects. He was also, within two years, going to be the most famous man in Boston.

· PART TWO ·
The Coupon — The Mechanism That Was a Story

The mechanism Ponzi used was, in principle, real. International postal reply coupons existed. The price discrepancy he described was real — in some countries, particularly Italy, where the currency had weakened after the First World War, you could buy reply coupons cheaply in local currency and redeem them in the United States at a higher fixed face value. [SOURCE: Investopedia; widely documented from case record]

The arbitrage was legitimate in theory. Buy low in Italy. Redeem high in America. The spread is profit. Ponzi proposed to do this at scale, and to share the returns with investors: 50% profit in 45 days, or 100% profit in 90 days. Investors would give him money, he would run the arbitrage, and they would collect. The promise was almost irresistible.

The problem, identified quickly by investigators at the time and documented by Clarence Barron of the Boston News Bureau, was simple arithmetic. The volume of international postal reply coupons in actual existence across the world was nowhere near sufficient to generate the returns Ponzi was paying. If he had been genuinely doing the arbitrage at the scale his investor inflows required, he would have had to purchase essentially all the reply coupons in existence and then some. The mechanism was real. The mechanism at this scale was impossible. [SOURCE: Barron's investigation, documented in Boston Post exposé, August 2, 1920]

What he was actually doing: paying early investors with later investors' money. The returns were real, in the sense that people actually received them. But the returns were not generated by the arbitrage. They were funded by the deposits of the people who had invested after them. As long as new money was coming in faster than redemptions were going out, the scheme worked. When that balance reversed, it collapsed.

He knew this. The mechanism was the cover story, not the engine.

· PART THREE ·
He Did Not Invent It — William W. Miller

This must be stated directly because it is both true and important: Charles Ponzi did not invent the Ponzi scheme.

The structure he used — paying earlier investors with later investors' money, maintaining a cover story about legitimate returns, collapsing when inflows can no longer fund redemptions — was not his invention. It predates him. It had been used before him by multiple operators in multiple contexts.

The most directly relevant precedent is William W. Miller, a Brooklyn bookkeeper who in 1899 ran what newspapers called the 'Franklin Syndicate' — promising 520% annual returns and attracting approximately $1 million in deposits before the scheme collapsed. [SOURCE: case brief citing Wikipedia / WeTrust reference; flag: secondary sources — verify against primary before final publication] Miller became known in the press as '520% Miller.' He ran his scheme twenty years before Ponzi ran his.

Ponzi may have been inspired by Miller — the case brief flags this as 'may have been' rather than confirmed, and that is the correct framing. [SOURCE: case brief sourcing note] The connection is plausible given the timing and the press coverage Miller received, but the direct line of influence is not settled in the historical record.

Why does this matter to the series? Because the structure Ponzi made famous is the same structure that runs through every case in this collection. Madoff paid earlier investors with later investors' money. Ignatova sold coins that were numbers in a database funded by the deposits of people who came after the people being paid. Stanford paid CD returns from new investor capital. Holmes raised valuations built on investor money that was funding the lifestyle rather than the research. The mechanism is ancient. What changes is the wrapper.

Ponzi's name is on it not because he invented it but because he did it in one summer in one city with one promise, and the newspapers found it and documented it in a way that made it permanent. The Boston Post won its first Pulitzer Prize partly for this story. [SOURCE: case brief — verify Pulitzer attribution to primary before publication] The crime needed a name. He was there when the name was assigned.

· PART FOUR ·
The Rise — Boston 1919 to 1920

In late 1919, Ponzi founded the Securities Exchange Company in Boston. He began accepting investor money on his promise of 50% returns in 45 days, backed by the international postal reply coupon arbitrage story.

He was good at this. The immigrants who had come to Boston as he had — Italian, Jewish, Irish, working class people who knew what it was to arrive with nothing and build toward something — were exactly the audience for a man who told a story of found opportunity. He did not pitch them as marks. He pitched them as insiders. He was letting them in on something that the wealthy already understood and that ordinary people could now access if they were smart enough to see it.

The money came in slowly at first, then faster. He paid his early investors — they received their returns on time, told their friends, and the friends came. By mid-1920 he was one of the most famous men in Boston, celebrated in the press as the financial wizard who had discovered a way to turn paper coupons into extraordinary profits, the immigrant who had cracked the system and was now sharing the discovery with his community.

On July 24, 1920, the Boston Post ran a favourable article about Ponzi. Investors poured in faster than ever. By some accounts he was taking in approximately $250,000 a day at the peak — the equivalent of several million dollars in contemporary terms. [SOURCE: case brief citing historical record; flag: this figure has not been independently verified to primary — treat as illustrative of scale, not as precise]

Two days later, on July 26, a bank run hit his office. Investors tried to withdraw simultaneously. He paid them. All of them. He stood in front of the crowd and paid everyone who came, and by the end of the day the bank run had dissolved into cheering. The man had held. The man had paid. The man must be legitimate.

He was not. He had paid the bank run from new investor deposits that had come in during the same days. He was paying old money with new money. The run had tested the scheme and the scheme had survived — but only because new inflows had happened to exceed the redemptions at exactly the right moment.

One week later, the structure was exposed.

· PART FIVE ·
The Fall — The Boston Post August 1920

On August 2, 1920, the Boston Post turned.

Clarence Barron of the Boston News Bureau had been investigating Ponzi's operation. The investigation was, in part, funded by the Post — which paid Ponzi's former publicity agent, William McMasters, $5,000 for his insider account of what he had seen. [SOURCE: case brief — flag: verify exact McMasters payment figure to primary before publication]

The story the Post published was based on Barron's arithmetic and McMasters's testimony. It was direct. Ponzi claimed approximately $7 million in liquid assets. The actual figure, investigators determined, was a deficit — he was at least $2 million in debt and possibly up to $4.5 million in the red. [SOURCE: case brief citing Boston Post exposé, August 2, 1920; Boston News Bureau]

The Massachusetts Attorney General, J. Weston Allen, moved immediately. The Hanover Trust bank, which had been processing Ponzi's transactions, was ordered to stop honoring his checks. State auditors descended. Involuntary bankruptcy was filed by a group of small investors.

On November 12, 1920, the federal bankruptcy court issued its ruling: In re Ponzi, 268 F. 997 (D. Mass.). [SOURCE: primary legal citation] The scheme was documented, the losses tabulated, the legal framework established.

On November 30, 1920, Charles Ponzi pleaded guilty to 22 counts of larceny in Suffolk County, Massachusetts. [SOURCE: ABA Journal; case brief citing Suffolk County record]

The Boston Post's investigation is one of the most consequential pieces of financial journalism in American history. The paper received the Pulitzer Prize. The story it broke gave the English language a new word for a specific category of crime. The story was better documented and more consequential than most financial journalism produced before or since — because the crime it exposed was so clean, so structurally legible, and so scalable that every subsequent fraud of the same kind would eventually be measured against it.

· PART SIX ·
Three Prisons One Deportation One Death

The criminal record of Charles Ponzi is long and runs across three countries.

Canadian prison, 1908–1911: three years for forgery, connected to his involvement with Banco Zarossi in Montreal. [SOURCE: case brief citing primary record]

US federal prison, 1920–1922: sentenced to five years for mail fraud in connection with the Securities Exchange Company scheme; served approximately three and a half years before being released to face state charges. [SOURCE: case brief]

Massachusetts state prison, 1927–1934: nine years for larceny. The state charges had been contested across several years of legal proceedings — during which he ran a land fraud scheme in Florida in 1925, for which he was separately prosecuted. He was, while fighting the Boston conviction on appeal, running another fraud. The Florida scheme collapsed when he was convicted in Massachusetts. [SOURCE: widely documented; Florida land scheme is part of the public record]

He was deported in 1934, after serving the state sentence. He went to Italy — then under Mussolini's government — and worked in various capacities including for the state airline. He eventually moved to Brazil. He taught English. He gave private lessons. He had, by his own later accounts, very little.

On January 18, 1949, Charles Ponzi died in a charity ward at the Hospital Umberto I in Rio de Janeiro. He was 66 years old. He had been partially paralyzed by a stroke. He had, by some accounts, approximately $75 in cash at the time of his death. [SOURCE: widely reported — verify to primary before publication]

His wife Rose had divorced him in 1937 after years of separation. She died in 1963, having rebuilt a life separate from his name.

· PART SEVEN ·
The Myth vs the Record

Much of what people know about Charles Ponzi is repeated, not sourced.

The $2.50 figure comes from his own autobiography, The Rise of Mr. Ponzi, published in 1937. The book is self-serving and romanticising, and the specific details it contains should be treated as Ponzi's version of his own story rather than as verified historical record. He was, among other things, a man who understood the narrative value of an origin story. Whether he truly arrived with $2.50 or whether that number was chosen for its poetic quality is not definitively established.

The $250,000 per day figure — his peak intake — appears in historical accounts and is structurally plausible given the total documented losses and the time frame. It has not been independently verified to a primary financial document in the academic literature available at the time of this writing.

The William W. Miller connection — that Ponzi was inspired by or modelled on '520% Miller' — is plausible but not confirmed. The case brief correctly frames this as 'may have been.' It is included here because it is the most direct documented precedent and because the pattern similarity is exact: the promise, the mechanism-as-cover-story, the collapse. Whether Ponzi knew about Miller specifically or arrived at the same structure independently is a historical question that remains open.

What is not myth: the legal record. The federal bankruptcy ruling is a primary document. The guilty plea is a primary document. The Boston Post investigation was contemporaneous journalism that has been verified by subsequent historians. The charges, the convictions, the sentences — these are in the record.

Where this piece relies on secondary sources or contested figures, those are flagged. The appendix lists verification targets. Handle the myth carefully — the record is better than the legend.

· PART EIGHT ·
The Origin of the Series

Every case in this series descends from this one structure. Not from Charles Ponzi — from the structure he made famous.

: paid for his Instagram lifestyle with money from wire fraud. The lifestyle was the product. The money was a Ponzi, in the broad sense: the later victims funded what the earlier investment in his brand produced.

: 's operation was not a Ponzi in the classic sense — it was straightforward theft. But the spending spree that consumed $230 million in a month was funded in exactly the same way Ponzi's payments to early investors were funded: by taking real money and using it to demonstrate that the thing was working.

: 's algorithmic stablecoin was explicitly a Ponzi-adjacent structure. The yields paid through Anchor Protocol required continuous inflows to sustain. When the inflows stopped, the yields stopped. The mechanism that was supposed to be self-sustaining was funded by new capital.

: Madoff ran the cleanest Ponzi in this series — 48 years of fabricated statements, paying earlier investors from later investors' deposits. He is, of all the cases here, the direct descendant.

: 's FTX used customer deposits — new money — to cover Alameda's losses, which were in part the result of earlier speculative positions. The structure was a Ponzi on the assets of the exchange.

: Holmes's Theranos raised investor money to fund a lifestyle and a product development process that was not producing what investors were told. New money covered the gap between what existed and what was promised.

: Ignatova's OneCoin was Ponzi in structure and explicit in mechanism: new investor deposits paid earlier investors' 'returns' from a coin that had no underlying value.

Case 009 Stanford: certificates of deposit paying above-market returns, funded by later investor deposits rather than a legitimate investment portfolio.

Ponzi's scheme ran in Boston in 1920. He made it famous enough to name. Every case in this series is a version of the same thing, run with different wrappers, in different centuries, across different asset classes and geographies. The structure is the same. It survives while inflows exceed redemptions. It collapses when they don't.

· EPILOGUE ·
Rio de Janeiro, 1949

He died in a charity ward in Rio de Janeiro on January 18, 1949. He was 66 years old. He was partially paralyzed. He had, by most accounts, next to nothing.

He had arrived in Boston in 1903 with $2.50 in his pocket — by his own telling. He died in Brazil with approximately $75. Between those two numbers: Montreal, Atlanta, Boston, Miami, Italy, Brazil. Three prisons. One wife. One divorce. One deportation. One summer in which he was the most famous man in Boston, and the rest of his life in which he was the man the summer was named after.

He had run his scheme for a little over a year. He had taken in approximately $20 million in 1920 dollars — roughly $237 million in 2024 purchasing power — from somewhere between ten thousand and forty thousand people who believed him. [SOURCE: case brief; exact victim count is contested] He had paid the early ones. He had not paid the rest.

He maintained, to the end, that the arbitrage had been real. That the scheme had worked in principle. That the problem was not the design but the execution, the publicity, the regulators who moved too fast. He was, among other things, a man who had told stories so long that some of them had become his own beliefs.

The English language absorbed his name. The legal system codified the structure. Every financial fraud prosecutor in the world now uses the phrase he made necessary. Every journalist covering the cases in this series reaches for it. Every investor who has ever been told that returns are generated by arbitrage or algorithm or technology has, somewhere in the back of their mind, the awareness that this has a name.

The name is his.

· TIMELINE ·
VERIFIED SOURCES AND VERIFICATION TARGETS

Myth distinguished from record throughout. Ponzi's autobiography is self-serving and used with care. Figures flagged for primary verification are labelled below. The Boston Post investigation is contemporaneous journalism verified by subsequent historians.

[1] PRIMARY — FEDERAL In re Ponzi, 268 F. 997 (D. Mass., November 12, 1920) — federal bankruptcy ruling. Primary legal citation.
[2] PRIMARY — STATE Suffolk County indictment, 22 counts of larceny. Guilty plea November 30, 1920. SOURCE: ABA Journal ('Nov. 30, 1920: Charlie Ponzi pleads guilty to larceny'); case brief citing primary.
[3] PRIMARY — FEDERAL MAIL FRAUD US federal mail fraud conviction, 1920. Five-year sentence; served approximately 3.5 years.
[4] REGULATORY Massachusetts Attorney General J. Weston Allen — moved against Ponzi following the August 2, 1920 exposé. Ordered Hanover Trust to stop processing his checks.
[5] JOURNALISM — PRIMARY Boston Post — two key articles: (a) Favourable profile, July 24, 1920 — precipitated the peak inflow; (b) Barron exposé, August 2, 1920 — exposed the insolvency. The Post reportedly received Pulitzer recognition for this investigation [verify precise Pulitzer attribution before publication].
[6] JOURNALISM — INVESTIGATION Clarence Barron, Boston News Bureau — financial investigation that produced the key arithmetic demonstrating the scheme's insolvency.
[7] SECONDARY Wikipedia — Charles Ponzi (aggregator; used for timeline and William W. Miller reference — both require verification to primary sources before final publication).
[8] SECONDARY Investopedia — 'Who Was Charles Ponzi?' — overview of the postal reply coupon mechanism.
[9] SECONDARY New England Historical Society — 1920 Boston coverage and context.
[10] PRIMARY (WITH CARE) Charles Ponzi — The Rise of Mr. Ponzi (1937 autobiography). Self-serving. The $2.50 arrival figure and other personal narrative details come from this source and require independent verification where possible.

VERIFY BEFORE PUBLICATION McMasters exact payment (~$5,000) · Daily intake figure ($250,000/day at peak) · William W. Miller direct inspiration link · Pulitzer Prize attribution · Final assets at death (~$75)

END OF REPORT
#44 OF 45
Ramon Abbas
SINGLE PERSON
CASE 001 · BEC / LAUNDERINGCONVICTED
Hushpuppi · 11 years US Federal
$1.73M
WHAT WAS TAKEN
Company money wired to fake accounts: $1.73M proven in court. Prosecutors say he tried to launder $300M+.
HOW
Fake business emails tricked companies into wiring money, which he laundered.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1990sSells sneakers and clothes from his car boot in Bariga, Lagos; later opens boutiques.SOURCE: his letter to the court; BBC
2011Starts building the Hushpuppi Instagram persona from Lagos.SOURCE: BBC; Business Insider
2014Leaves Nigeria for Kuala Lumpur.SOURCE: BBC
2014–c.2017Lives in Kuala Lumpur while the persona takes off: designer goods, cars, the follower count climbing towards two million.SOURCE: BBC; Bloomberg
c.2017–2020Runs the business-email-compromise laundering network from a Palazzo Versace apartment; the FBI affidavit ties his phone and email to the accounts.SOURCE: FBI complaint, C.D. Cal. 2:20-cr-00322
Feb 2019Supplies bank accounts to receive ~$14.7M moved from a foreign bank (Forbes links it to Bank of Valletta, Malta).SOURCE: FBI affidavit; Forbes
June 2020Dubai Police raid the apartment in Operation Fox Hunt 2: ~$40M in cash, 13 cars, 21 laptops, 47 phones seized. Flown to the US on 3 July 2020.SOURCE: Dubai Police; DOJ
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
RAMON ABBAS
AKA HUSHPUPPI · BEC / LAUNDERING · CASE 001 · CONVICTED 2022
RESTITUTION ORDERED
$1,732,841 · two victims
STATUS
Convicted
SENTENCE
11 years (US)
ARREST
Dubai, June 2020
INSTAGRAM
~2.5M followers (BBC)
JURISDICTION
CD California
FULL PROFILE

IDENTITY

LEGAL NAME
Ramon Olorunwa Abbas
BORN
11 October 1982 · Lagos State, Nigeria
NATIONALITY
Nigerian
BASE OF OPS
Dubai, UAE (Palazzo Versace residence)
ALIASES
Ray Hushpuppi · Hushpuppi · Hush
ONLINE HANDLE
@hushpuppi (Instagram)
COVER STORY
Real estate developer / entrepreneur
ACTUAL ROLE
Money launderer · BEC fraud coordinator · network node for international cybercrime

CASE RECORD

ARRESTED
June 10, 2020 · Dubai, UAE
OPERATION
Operation Fox Hunt 2 · FBI + Dubai Police
EXTRADITED
July 2, 2020 · Chicago, Illinois
JURISDICTION
Central District of California · Los Angeles
CHARGE
18 U.S.C. 1956(h) · Conspiracy to engage in money laundering
PLEA
Guilty · April 2021
SENTENCED
November 7, 2022 · 135 months
JUDGE
Hon. Otis D. Wright II · CD California
RESTITUTION
$1,732,841 ordered to two fraud victims
EFCC STATUS
Also wanted by Nigeria Economic & Financial Crimes Commission
KNOWN NETWORK & CO-CONSPIRATORS
CO-CONSPIRATOR · BEC / LAUNDERINGCONVICTED
Olalekan Jacob Ponle
Mr Woodberry · Nigerian national · 8 years US federal
Arrested alongside Abbas in the Dubai operation June 2020. BEC fraud co-conspirator. Extradited to the US and sentenced to 8 years. Operated parallel BEC scheme under the same network infrastructure.
SOURCE: DOJ · FBI Dubai affidavit 2020
CO-CONSPIRATOR · NORTH KOREA LINK · MONEY LAUNDERINGPLEADED GUILTY
Ghaleb Alaumary
Big Boss · Canadian-American · Ontario, Canada
High-level money launderer who connected Abbas to North Korean state-sponsored hackers. Alaumary conspired with Abbas to launder funds from the February 2019 Bank of Valletta (Malta) cyber heist orchestrated by North Korea's / APT38. Alaumary pleaded guilty November 2020 in the CD California.
SOURCE: DOJ indictment Feb 2021 · FBI
LINKED INDIVIDUAL · ALLEGED / CHARGES DISPUTEDALLEGED ONLY
Abba Kyari
Former Nigerian Police Commander · Deputy Commissioner of Police
Named in US court documents as alleged co-conspirator in a scheme to frame and arrest a rival of Abbas. Kyari denied all allegations. Nigerian authorities subsequently investigated. This entry reflects allegations in court filings only -- Kyari has not been convicted in connection with Abbas. Published as allegation, not fact.
SOURCE: US court filings [ALLEGATION ONLY -- not a conviction]
ARRESTED WITH ABBAS · DUBAI OPERATIONRECORD UNCLEAR
Young Chainz / Logic / Ziko
Street names only · arrested Dubai June 2020
Named individuals arrested alongside Abbas and Ponle in Operation Fox Hunt 2. Exact legal names and subsequent prosecution records not publicly confirmed in available US court filings. Listed here as documented by Dubai Police press release. Status: [UNVERIFIED beyond arrest].
SOURCE: Dubai Police statement June 2020 [STATUS UNVERIFIED]
DOCUMENTED SCHEMES
SCHEME 01 · BEC · CONFIRMED IN PLEACONVICTED
New York Law Firm — $922,857
Real estate wire redirect · Central District of California
Loss$922,857
MetricConfirmed victim loss · plea agreement
A paralegal at a New York law firm received fraudulent wire instructions via a spoofed bank email address. The firm wired funds intended for a client's real estate refinancing to an account controlled by Abbas's network. Confirmed in guilty plea.
SOURCE: DOJ plea agreement 2021 · FBI affidavit
SCHEME 02 · BEC · CONFIRMED IN PLEACONVICTED
Qatari Businessman — $1.1M
School financing fraud · wire redirect
Loss$1.1M+
MetricConfirmed victim loss · plea agreement
Qatari businessperson attempting to secure financing for a school. Fraudsters intercepted communications, spoofed the legitimate lender, and redirected the wire to a controlled account. Confirmed in Abbas's guilty plea.
SOURCE: DOJ plea agreement 2021 · CNN Nov 2022
SCHEME 03 · BEC · ALLEGED IN AFFIDAVITALLEGED
Premier League Club — £100M Attempt
SWIFT transfer redirect · unnamed club · unsuccessful
Target~$124M attempted
MetricAttempted redirect [ALLEGED in affidavit]
FBI affidavit alleges Abbas conspired to steal £100M from an unnamed English Premier League club through a player transfer payment redirect. Described as ultimately unsuccessful. The club has not been publicly identified. Published as allegation from the FBI affidavit -- not included in the guilty plea.
SOURCE: FBI affidavit 2020 [ALLEGATION -- not in guilty plea]
SCHEME 04 · CYBER HEIST · ALLEGEDALLEGED
Bank of Valletta, Malta — SWIFT Heist
/ North Korea · Feb 2019 · via Ghaleb Alaumary
TargetEUR 13M attempted [largely reversed]
MetricAttempted theft [funds largely traced and reversed]
North Korea's hacked Bank of Valletta's SWIFT system February 2019. Abbas's role: laundering proceeds through his network via co-conspirator Ghaleb Alaumary. Malta PM addressed parliament over the incident. Funds were largely traced and reversed. Abbas's connection is through the Alaumary indictment -- not the guilty plea itself.
SOURCE: DOJ Feb 2021 · Bank of Valletta confirmed breach to Forbes · [ALLEGATION via Alaumary indictment]
ASSETS SEIZED — DUBAI ARREST JUNE 2020

OPERATION FOX HUNT 2 — SEIZURE RECORD

CASH
150 million dirhams (~$40M) · SOURCE: Dubai Police statement
VEHICLES
~13 luxury vehicles including Rolls-Royce Wraith, Bentley Bentayga · SOURCE: Dubai Police / DOJ
DEVICES
21 computers · 47 smartphones · SOURCE: DOJ press release July 2020
RESIDENCE
Palazzo Versace Dubai · exclusive residential tower
CO-ARRESTED
Olalekan Ponle + several others (Young Chainz, Logic, Ziko per Dubai Police)
RESTITUTION
$1,732,841 ordered at sentencing Nov 2022 · SOURCE: DOJ sentencing release
NOTE: Dubai Police initially reported "11 others" arrested in the wider operation. The exact total varies by source. Documented named individuals are Ponle, Young Chainz, Logic, and Ziko per Dubai Police press release.
CASE TIMELINE
2010 -- 2019
The Instagram Years
Ramon Abbas, a Nigerian national, builds a social media following under the name "Hushpuppi." His Instagram -- eventually approximately 2.5 million followers (BBC) -- documents private jets, designer goods, Dubai penthouses. He describes himself as a real estate developer. Federal investigators later establish he had no legitimate income at that scale. The lifestyle was the operation.
SOURCE: DOJ Complaint · FBI Affidavit (2020)
February 2019
The Qatari School Fraud -- $1.1M Wire Intercepted
Abbas and co-conspirators target a Qatari businessperson attempting to secure financing for a school. Fraudsters intercept communications, spoof the legitimate lender, and redirect a $1.1M wire to a controlled account. This single case -- one of many -- illustrates the core BEC model: no hacking, no malware. Email spoofing and social engineering only.
SOURCE: DOJ Indictment (2020) · FBI Case File
2019 -- 2020
Premier League Club -- Attempted Redirect of Transfer Payment
Abbas is implicated in an attempted fraud targeting a Premier League football club -- an effort to redirect a large player transfer payment. The attempt was ultimately unsuccessful. UK and UAE authorities were notified. The case demonstrated the ambition of the operation: moving from retail BEC to targeting institutional financial flows.
SOURCE: UK reports · cross-referenced DOJ filings
June 2020
Operation Fox Hunt 2 -- Dubai Police Arrest
Dubai Police, acting on FBI intelligence, raid Abbas's Dubai residence and arrest him alongside several co-conspirators including Olalekan Ponle (Mr Woodberry), Young Chainz, Logic, and Ziko. Seized from the apartment: approximately 13 luxury vehicles, 150 million dirhams (~$40M) in cash, 21 computers, and 47 smartphones. Abbas is extradited to the United States in July 2020.
SOURCE: Dubai Police statement · DOJ press release July 2020
July 2021
Guilty Plea -- US Federal Court, Los Angeles
Abbas pleads guilty in the Central District of California to conspiracy to engage in money laundering. The plea details his role coordinating fraudulent wire transfers, recruiting money mules, and moving funds through accounts across the US, Europe, and the UAE. He cooperates with investigators.
SOURCE: DOJ Plea Agreement (July 2021)
November 2022
Sentenced -- 135 Months Federal Prison
Judge Otis Wright II sentences Abbas to 135 months (11 years and 3 months) in federal prison. Wright cites the scale of harm, the deliberate display of criminal proceeds, and the effect on international financial trust. Abbas is ordered to pay restitution to victims.
SOURCE: DOJ Sentencing Release (November 2022) · Court Record
HOW THE FRAUD WORKED

BEC METHODOLOGY -- FIVE STEPS

01
Reconnaissance: Identify a target with a large pending financial transaction -- real estate closings, corporate acquisitions, wire payments. Monitor email communications to understand timing and parties involved.
02
Spoofing: Create a domain visually similar to the legitimate counterparty. Set up email accounts that appear identical to the real parties in the transaction.
03
Intercept: Insert into the email thread at the right moment -- typically when wire instructions are expected. Provide fraudulent banking details for a controlled account.
04
Transfer: Victim sends funds to the fraudulent account believing they are paying the legitimate recipient. Funds typically move within hours of receipt.
05
Layering: Funds dispersed across multiple accounts in multiple jurisdictions immediately to prevent tracing and freezing. Abbas coordinated this layer across the US, Europe, UAE, and West Africa.
DOCUMENTED MONEY FLOW -- QATAR CASE
Victim wire $1.1M
-->
US mule account
-->
UAE layering
-->
West Africa extraction
-->
Luxury assets Dubai

WHAT THIS CASE ESTABLISHED

BEC fraud is a scalable, multinational operation -- not opportunistic crime.
Social media lifestyle documentation became forensic evidence of unexplained wealth.
The FBI-Dubai Police cooperation model became a template for transnational BEC prosecution.
No malware, no hacking -- the attack surface is email trust and human verification failure.
Co-conspirator cooperation in plea agreements continues to generate additional indictments.
THE FULL STORY — 17 CHAPTERS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE (5,700 WORDS)
Sources: FBI criminal complaint 2:20-cr-00322 · DOJ/US Attorney CD Cal · Dubai Police · DOJ press releases on North Korea connection and Abba Kyari indictment · BBC · Business Insider · Bloomberg · Forbes · Times of Malta · TheCable.ng · Public Instagram record. Every claim traced. Estimates labelled. Allegations framed as allegations.
· PROLOGUE ·
The Birthday Cake

On the eleventh of October, 2017, a man in Dubai posted a photo of a birthday cake on Instagram.

The cake was from Gucci. Iced in the house's signature green and red, the interlocking double-G logo rendered in fondant on the top tier. The caption: Happy Birthday Ramon.

Followers sent their birthday wishes. The FBI noticed something else.

Agents cross-referenced the name against a US visa application linked to a phone number connected to a co-conspirator in an active money laundering investigation. Date of birth: October 11, 1982. Name: Ramon Olorunwa Abbas. A public Instagram birthday post verified the identity of a man the bureau had been building a case around for months. The flex was the fingerprint.

This is that story. All seventeen chapters of it.

· PART ONE ·
Bariga — Where the Hunger Starts

To understand what Ramon Abbas became, you have to understand the place that made him.

Bariga sits on the Lagos mainland — pressed between the lagoon and the grinding density of one of Africa's most chaotic and alive cities. Not the Lagos of Banana Island penthouses and gated Lekki estates. Bariga is the city that built those gates. Where the taxi drivers live. Where the market traders sleep. Where the generators run all night because the power grid is a suggestion rather than a service.

Ramon Olorunwa Abbas was born there on October 11, 1982. His father drove a taxi. His mother sold goods at the market. He would later repeat these facts himself — in interviews, in Instagram captions, in a handwritten letter to a federal judge — with the pride of a man who believed his origin story made everything that followed both understandable and, in some way, forgivable.

Lagos in the late 1980s and 1990s, when Abbas was coming of age, was a city of strangled potential. The oil revenue that should have built infrastructure and employment had been captured by successive governments. The young men of Bariga were educated enough to understand what the world offered. They were constrained enough to understand how little of it had their names on it.

The internet arrived through cafes in the late 1990s — small shops lined with terminals, paid by the hour, where you could reach anywhere on earth through a screen. For the young men of Bariga, this was not a convenience. It was a revelation. Through a screen, geography dissolved. The visa barriers and capital requirements that kept the world closed became, theoretically, irrelevant.

· PART TWO ·
The First Hustle — Sneakers, Boutiques, the Education of an Eye

Before the fraud. Before Instagram. Before the Richard Mille and the Rolls and the Palazzo Versace — there was a car boot full of sneakers.

Abbas sourced premium branded clothing and shoes and sold them from the trunk of a car, moving through Lagos to wherever the buyers were. This requires genuine commercial intelligence: reading demand before it articulates itself, understanding the relationship between price and aspiration, knowing when a customer is considering and how to tip the scale. He expanded. The car boot became boutiques — physical retail locations where people moving up in Lagos could acquire the objects that announced arrival.

What the fashion business taught him — and this is the thing that would define everything that followed — is that people do not buy products. They buy the version of themselves they become when they own them.

Abbas understood this before he had ever seen a fashion week, before he had ever sat in a front row. He understood it the way some people understand mathematics — not as a learned skill but as intuition so natural it does not feel like understanding at all.

· PART THREE ·
Building Hushpuppi — The Instagram Rises

In 2011, Instagram launched. Abbas created an account. He called it Hushpuppi.

The name suggested quiet money — the dog that does not bark, the wealth that does not need to announce itself while announcing itself constantly. The irony was presumably intentional.

The early posts were modest. Fashion content. His own outfits assembled with real skill — the Lagos boutique owner applying genuine knowledge of what looks right, what signals correctly, what tells the right story. He was not yet posting borrowed luxury. He was posting what he had and presenting it well.

The account grew. The audience that found him were young Africans — in Nigeria, Ghana, Kenya, in the diaspora communities of London, Houston, Toronto — hungry for exactly what he was offering. Someone who looked like them, who came from where they came from, standing in rooms that were supposed to be closed to people like them.

He studied what worked. He refined constantly. The content became more expensive, more aspirational, more detailed in its documentation of a life at the absolute top. Every detail mattered — the angle of the watch, the way the bag sat against the car seat, the specific restaurant, the specific suite. He was not posting life. He was producing it.

In 2014, he left Nigeria. His destination: Kuala Lumpur, Malaysia.

· PART FOUR ·
Kuala Lumpur — Where the Operation Matured

The choice of Malaysia was strategic on multiple levels.

Kuala Lumpur in 2014 was modern, connected, and positioned as a hub between the financial systems of Southeast Asia, the Gulf, and the West. The international community was large enough that a Nigerian man living conspicuously well would not draw unusual scrutiny. The cost of luxury was lower than Dubai or London. And from KL, the banking networks that mattered for what the operation was becoming were accessible.

Abbas arrived and built. The Instagram accelerated dramatically. Daily posts, sometimes multiple per day, each one a production — composition, lighting, clothing, accessories arranged in the frame to tell a story of wealth so comprehensive it admitted no doubt. Malaysia was where the following broke past a million, then two million. Where the character became more real than the man.

And Malaysia was where, the court record shows, the criminal operation scaled from informal fraud into something organised, networked, and capable of moving tens of millions of dollars across continents.

Business Email Compromise requires infrastructure: knowledge of corporate payment processes, connections to money mule networks across multiple jurisdictions, the ability to coordinate across legal systems. Abbas had become the infrastructure. Not necessarily the man at the keyboard — what the FBI alleged, and what the record establishes, is that he operated as a coordinator. Providing accounts. Connecting operations. Moving money through the nodes of a transnational fraud network.

His Instagram was not separate from this business. It was part of it. The luxury displayed on his feed attracted two audiences simultaneously: the millions of followers who saw aspiration, and the operators in the fraud economy who saw proof of legitimacy. A man who lives that way has standing. He can be trusted with a large transaction.

· PART FIVE ·
The Gucci Master — A Brand Built in Detail

He called himself the Gucci Master. It was not a casual title.

Abbas had studied the house — its heritage, its aesthetic codes, its position in the European luxury hierarchy. He wore Gucci the way a scholar wears citations: with authority, with reference, with the implication he understood something others did not. He wore the Disney x Gucci collaboration T-shirt — $650 — as casually as other men wore plain cotton. He stacked Gucci accessories, shoes, belts, bags. But he did not wear logos. He wore a language. The distinction matters: logos say I can afford this. Language says I belong here.

Gucci was the anchor. The portfolio diversified: Louis Vuitton, Fendi, Chanel, Dior, Balenciaga, Hermès. Each house has a specific cultural position in the luxury hierarchy and he positioned himself in relation to all of them simultaneously. He understood the grammar of these brands — which piece meant what, which collaboration carried weight, which bag signalled what level of spending to what kind of observer.

On his wrist: the Richard Mille RM11-03. Approximately $230,000. A watch so technically complex — its movement visible through the case back, its architecture borrowing from motorsport engineering — that it announced serious money even to people who did not know watches. The FBI's criminal affidavit noted specifically that this watch was purchased with money scammed from a Qatari businessman. On Instagram, it was just Tuesday.

· PART SIX ·
Paris — Louis Vuitton and the Front Row

The fashion weeks were the crowning content of the Hushpuppi brand. Paris most of all.

Paris Fashion Week is the apex of the global luxury calendar — the city and the season where Louis Vuitton, Dior, Givenchy, Chanel present the work that defines what the world aspires to. The shows happen in the Grand Palais, the Louvre, purpose-built architectural spaces that treat fashion as an event for the experience of something that exceeds the functional.

Abbas attended. He documented everything.

The Louis Vuitton shows were particular reference points. To be at LV in Paris was to be present at a cultural event with a guest list as curated as any in the world. The brands saw: ~2.5 million followers (BBC), product worn correctly, photographs beautifully composed. That was the currency of the front row. Abbas had it. The brands gave him the seat. He gave them the content.

The Paris posts were his most powerful. Hotel suites at the kind of addresses that charge per night what most Bariga households earn in a year. The private car to the venue. The front-row or near-front-row positioning. The photographs with other attendees who had their own visibility. The post-show dinner at the restaurant where the after-party and the real business happened simultaneously.

He captioned these posts with the authority of a man who belonged — not the excited fan, not the tourist who had somehow secured a seat, but the man for whom this was simply the routine of his life. The Gucci Master on his natural ground.

· PART SEVEN ·
The Jets — Manufacturing a Life

The private jet content is the most revealing window into how precisely the machine was calculated.

Private jets are the ultimate social media luxury signal. Not the car — too many people lease cars they cannot afford. Not the watch — high-quality fakes circulate convincingly on camera. But the interior of a private jet — the cream leather, the burled wood panels, the oval window view of clouds from a cabin that seats twelve — communicates a specific and very large quantity of money that is difficult to convincingly fake, and that an audience recognises as categorically different.

Abbas chartered jets. Private aviation companies in Dubai and Malaysia service a market of people who need aircraft for specific purposes without owning them. They are businesses; they take bookings. Abbas would charter, spend time aboard, and produce content systematically: boarding the aircraft, seated in the cabin, the window view at altitude, the food service on the fold-down table, the shoes off and feet on the cream leather footrest.

He posted these with the energy of a man for whom this was simply how travel worked. Not look at this extraordinary thing I have done — but here I am, on my way, as one does.

The calculation was precise. Per dollar spent on charter, private jet content generated higher returns in follower growth and brand consolidation than any other category. He was not taking these flights to get somewhere. He was taking them to be seen taking them. The destination was the content. The content was the credential.

· PART EIGHT ·
Dubai — The Palazzo Versace Years

When Abbas established himself in Dubai, both the persona and the operation were at their peak.

Dubai is a city built on the proposition that money from anywhere, earned by any means, can purchase any lifestyle if it arrives in sufficient quantity. The towers, hotels, malls, restaurants — designed to convert wealth into experience with maximum efficiency and minimum questioning.

He took an apartment at the Palazzo Versace Dubai. Not a hotel room. An apartment. A residence. Home.

The Palazzo Versace is a building that exists as a fashion statement made permanent — built in collaboration with the Versace house, the fabrics on the chairs matching runway patterns, the pool tiles printed with the Medusa head, the corridors designed to feel like walking through a collection. Everything in the building says this is not ordinary accommodation. This is a lifestyle sustained in architectural form.

Abbas lived there and documented all of it. The apartment interior. The views of the Dubai skyline and the Gulf beyond. The cars in the building's valet. The pool where the Medusa heads shimmered under the water. The lobby where staff knew him by name.

Every room. Every morning. Every evening. The Instagram grid became a catalogue of a life at a level most people had only seen in magazines — magazines always populated by Western celebrities, European heirs, people born into access. Here was a man from Bariga, from a taxi driver's household, in those rooms.

· PART NINE ·
The Frauds — What Actually Happened

The law firm lost approximately $40 million.

One redirected wire. One fraudulent payment instruction that appeared to come from a trusted source, directing funds to accounts that emptied within hours. A single BEC operation producing tens of millions of dollars that moved through the banking system before anyone understood what had happened.

The foreign financial institution — Malta's Bank of Valletta, as Forbes's reporting linked the February 2019 operation — lost approximately $14.7 million. The FBI's affidavit traces Abbas to this specifically: he supplied two European bank accounts anticipating approximately $5.6 million each. The money moved through those accounts and onward through the US, UK, Czech Republic, and Hong Kong — a chain of jurisdictions designed to put maximum distance between crime and trace.

The English Premier League club was targeted for approximately £100 million. A player transfer fee — the specific mechanism whereby enormous sums move between football clubs through agents, solicitors, and banking instructions that travel by email. The amount was large enough to justify the operational risk. The attempt was intercepted.

800,000 emails of potential victims were found on Abbas's seized devices. Not his correspondence — the contact details and assessed vulnerabilities of people and organisations that had not yet been defrauded. Future targets, stored in categories on a hard drive next to the Gucci receipts.

· PART TEN ·
The North Korean Connection

This is where the story moves into territory that most Instagram influencers — even fraudulent ones — never approach.

US authorities alleged that Abbas was involved in laundering funds connected to North Korean state-sponsored hackers.

The — the cyberattack unit operating on behalf of the North Korean state, the organisation linked to the Sony Pictures hack, the Bangladesh Bank heist, the WannaCry ransomware attack, and the theft of hundreds of millions from cryptocurrency exchanges — needed to move money. Cryptocurrency stolen in sophisticated cyberattacks does not spend itself. It needs to be converted, cleaned, moved through a system that will accept it at the end without asking where it originated.

According to US Department of Justice allegations, Abbas was connected to a scheme involving laundering proceeds of North Korean cyber theft. A network built on Business Email Compromise was now allegedly operating as infrastructure for the financial operations of a sanctioned state's hacking program.

What the allegation suggests, if accurate: the man with the Richard Mille and the Gucci birthday cake was a node in a network that connected Lagos street-level fraud infrastructure to the cyber operations of the North Korean state. The front row at Louis Vuitton and the hacking for Pyongyang — connected through the same man's accounts.

· PART ELEVEN ·
Abba Kyari — When the Police Chief Falls Too

If the North Korea connection is the most extraordinary dimension of the story, the Abba Kyari connection is the most revealing about what money and social access can construct.

Abba Kyari was not a minor figure. He was the Deputy Commissioner of Police, head of Nigeria's Intelligence Response Team, decorated for operations against kidnappers and armed groups, personally commended by the President. His arrest operations were covered by Nigerian newspapers as national news. He was, by public reputation, one of the most effective law enforcement commanders in the country.

He was also, according to the US Department of Justice, a friend of Ramon Abbas.

The DOJ charged Kyari in 2022 with conspiracy to commit wire fraud and money laundering in connection with a BEC scheme. Federal prosecutors alleged that Kyari had received bribes from Abbas in exchange for arresting individuals Abbas wanted targeted — using his position in Nigerian law enforcement to have people who were threatening or inconveniencing Abbas's operation detained.

On social media, Abbas had publicly celebrated Kyari. He had posted photographs with the police commander. He had spoken of him warmly. The decorated officer and the Instagram influencer, photographed together, both presenting as successful men at the top of their respective worlds.

The allegation, if proved, describes a specific and extraordinary arrangement: a senior police commander on the payroll of one of the most wanted money launderers in the world, using the power of Nigerian law enforcement as a private security service for a criminal enterprise. The case is unresolved. Kyari denied all charges.

· PART TWELVE ·
The Co-Conspirators — The Network by Name

Abbas did not operate alone. The court record names others.

Ridwan Abdulaziz Aliyu — known as Lade — was charged as a co-conspirator. Identified in the record as a participant in the network through which the fraud operated, involved in the management and movement of proceeds.

Kelly Chibuzor Vincent and Boye Emmanuel Oluwaseun were named in connection with the scheme to defraud the English Premier League club — the attempted £100 million transfer fee fraud. The record documents their roles in the attempted interception and redirection of the football club's payment.

Abdulrahman Juma appeared in the record in connection with the network's Gulf operations.

And there was a co-conspirator — unnamed in some filings — whose October 2019 arrest in an unrelated case was the moment the thread became visible. Their devices were opened. Their communications were examined. The chain of connections led, eventually, to Palazzo Versace Dubai and the man living in the apartment there.

The network was large enough to be operational across continents. It was also large enough that when one node was compromised, the connections running through it became legible to investigators who knew what they were reading.

· PART THIRTEEN ·
The St Kitts Passport — A Second Identity

Among the details in the case record: Abbas held a passport from St Kitts and Nevis.

St Kitts and Nevis offers citizenship by investment — a legal program through which foreign nationals obtain citizenship in exchange for qualifying investments. It is a program used by many people legitimately seeking a second passport. It is also, for certain purposes, strategically valuable.

Abbas's St Kitts passport was not obtained legitimately. According to the record, it was obtained through a sham marriage — a fraudulent arrangement designed to create the appearance of qualifying for citizenship that did not reflect a genuine relationship.

A second passport from a Caribbean nation, held by a Nigerian man operating across Dubai and Malaysia: the practical utility in the context of what the record describes requires no further elaboration. It represents another layer of constructed identity — the same impulse that built the Hushpuppi Instagram brand, applied to documentation.

· PART FOURTEEN ·
Telli Person — The Prophecy

In 2017, Timaya released a track. Featuring Olamide and Phyno.

These are not small names. Olamide is one of the most commercially successful and culturally respected artists in Nigerian music history. Phyno built his reputation on credibility and craft. Timaya had sustained a career across multiple eras of the industry. When these three made a record together, people listened carefully.

Telli Person was directed at Abbas. The accusations came in music's coded language — barely veiled to anyone paying attention. You are not what you claim. This will end. The warning was explicit enough to be unmistakeable.

Abbas heard it. He responded as he always responded to threats to the brand — loudly, publicly, with the fury of a man whose image is his most valuable asset. He contested the narrative. He doubled down. He posted more. He bought more. He wore more. When you cannot answer the accusation, you outspend it.

The feud ran for years. Nigerian social media divided — between those who read the Timaya record as truth and those who read it as jealousy. Between those who understood how the Yahoo boy economy worked at its highest levels and those who had decided that the front rows and the Richard Mille were proof enough of legitimacy.

The song was streaming in 2022 when Abbas was led into a federal courtroom in Los Angeles. The prophecy had found its fulfilment — not in music but in law. The music industry had said: this man is not what he claims. The court said: he is a money launderer. The gap between those two statements was narrower than five years of Instagram posts had made it appear.

· PART FIFTEEN ·
Operation Fox Hunt 2 — The Night It Ended

In October 2019, a co-conspirator was arrested in a separate case. Their devices were opened. Their communications were examined.

Somewhere in the chain of messages and transactions, the thread led to Ramon Abbas.

Federal cases build quietly. Not the dramatic raids of television but the slow accumulation of subpoenas, financial records from banks in multiple countries, international cooperation across legal systems that do not always speak the same language. The Dubai Police were engaged. Interpol involvement was secured. The operation was named Fox Hunt 2.

On a night in June 2020, the team arrived at the Palazzo Versace. They came with the full apparatus of an international law enforcement operation that had been building for months.

Abbas was home.

Dubai Police produced a video. They took his own Instagram content — the cars, the watches, the fashion week photographs, the jet interiors, the birthday cake — and edited it against footage of the raid. Police entering the apartment. Evidence being catalogued. Cybercrime graphics overlaid on images he had chosen to define his public identity. The aesthetic tools he had spent nine years developing were turned against him by a police media department that understood exactly what it was doing.

The video went viral. Of course it did. He had built one of the most viral Instagram accounts in African history. The system he created for his own mythology was repurposed for his destruction.

He arrived in the United States on July 3, 2020. The country he had defrauded was waiting.

· PART SIXTEEN ·
The Reckoning — What the Court Said

The federal case in the Central District of California proceeded over two years.

Abbas pleaded guilty to conspiracy to engage in money laundering. The government's case was comprehensive: financial records, digital evidence from 47 smartphones and 21 laptops, blockchain analysis, international banking records, the communications with co-conspirators across multiple jurisdictions, and the Instagram account itself — which functioned not only as lifestyle evidence but as a chronological record of movements, associations, purchases, and the specific timeline of an operation.

His attorney argued for leniency. The origin story was presented — Bariga, the taxi driver father, the market trader mother. Character letters were submitted. And Abbas himself wrote to the judge.

A handwritten letter, dated September 9, 2022, addressed to Judge Otis D. Wright II.

In the letter, he described the beginning. The car trunk. The sneakers. The boutiques. The boy from Bariga who had wanted something the world had decided was not available to him, who had found a way — the wrong way — to reach for it. He expressed remorse. He described himself as a businessman who had made catastrophically wrong choices.

The man who sat in the front rows of Paris fashion weeks, who drove Rolls-Royces through Dubai, who posted ~2.5 million followers (BBC) through the rooms of a life built on wire fraud and money laundering — he will be in his mid-fifties before he walks free. He is also wanted in Nigeria.

· PART SEVENTEEN ·
What It Meant — Nigeria, the Yahoo Boys, the Prophecy Fulfilled

The uncomfortable truth at the centre of the Hushpuppi story is not simply that a criminal became famous.

It is that the fame was real. The access was real. He genuinely sat in those front rows. He genuinely wore those watches. The Palazzo Versace apartment was genuinely his home. The jets were genuinely in the air.

He got there. From Bariga, from a taxi driver's household, from the car-boot sneaker business — he got to the rooms that were supposed to be permanently closed to people from where he came from.

The cost was paid by the law firm that lost $40 million. By the Maltese bank. By the English football club targeted for £100 million. By the victims whose 800,000 emails were found in storage on his devices, waiting to be next.

That is the arithmetic of the story. The glamour was purchased on credit taken from people who never agreed to extend it.

The reaction in Nigeria was complicated in the way these things are always complicated in Nigeria.

There was condemnation. There was the told-you-so from those who had always questioned the source. There was the religious establishment's long-standing critique of the Yahoo boy culture's corruption of a generation. There was Telli Person finally, definitively, proven right.

And there was something else. A grief that was not for the fraudster but for the proposition he had represented. The idea that someone from Bariga could actually be in those rooms. Could actually belong in those rooms. Could sit where princes sat and be treated as an equal.

His life had appeared to prove it was possible. The conviction proved the version that existed was built on stolen money. The rooms were real. The key was stolen.

Prof. Adedeji Oyenuga of Lagos State University spent six years embedded among Yahoo boys for his doctoral research. Prof. Daniel Smith of Brown University has written on the structural drivers: unemployment, thwarted opportunity, a generation educated enough to understand what it was missing and constrained enough to understand how little of it could be reached through legitimate paths.

Abbas was not the cause of this system. He was its most famous product. And his fall was the system demonstrating, with the full weight of US federal law, that the shortcut he took had a price that was coming no matter how long you managed to avoid it.

· EPILOGUE ·
The Cake

The birthday cake was from Gucci. It sat on a table in a room in Dubai, lit beautifully, the double-G logo in fondant. The caption: Happy Birthday Ramon.

Two million people saw the fire emojis pile up. The praise. The tags. The messages from young men who looked at that cake and saw everything they wanted their own lives to become.

And somewhere, an FBI agent looked at the same post, matched the name to a file, confirmed the date of birth, and added it to a case.

He told the world who he was. Post by post by post. For nine years. The watch and the car and the jet and the Paris front row and the Palazzo Versace apartment. The Louis Vuitton shows and the private charters and the Gucci birthday cake. He told them everything.

He just did not tell them where the money came from.

When the court told that part of the story, it took eleven years to tell it back.

VERIFIED RECORD — COMPLETE

Every claim in this piece traces to a named source below. Allegations are framed as allegations. Estimates labelled.

END OF REPORT
#45 OF 45
Frank Abagnale
SINGLE PERSON
CASE 019 · CHECK FRAUD / IMPOSTORCONVICTED
Catch Me If You Can · paroled 1974
$1,448.60
WHAT WAS TAKEN
Ten forged Pan Am payroll checks: the documented federal case. He claims $2.5M; records don't support it.
HOW
Cashed bad checks and posed as a pilot for about three months. Most of his famous story is disputed.
OPERATED FROM
Where they were physically based or worked. Tap a country for its page.
1964–1965Passes bad cheques in New York; enters Great Meadow prison in July 1965.SOURCE: court and prison records cited in the brief
Feb 1969Arrested in Baton Rouge; convicted of theft and forgery.SOURCE: case brief
Nov 1970Arrested in Georgia over forged Pan Am cheques; federal sentence, paroled 1974.SOURCE: case brief
Sept 1969Arrested in Montpellier and jailed in France.SOURCE: case brief
1969–1970Serves time in Malmö before deportation to the US.SOURCE: case brief
METHODS USED
Tap a method to see where it came from and everyone who used it.
TAP A SECTION TO OPEN IT
KEY FACTS
FRANK ABAGNALE
THE LEGEND · CASE 019 · CHECK FRAUD / IMPOSTOR · CONVICTED · PAROLED 1974
DOCUMENTED
$1,448.60 in forged Pan Am checks · the federal case
HE CLAIMS
$2.5 million in 26 countries — his memoir
PRISON
About 5 years: New York, France, Sweden, US federal
PAROLED
February 8, 1974
THE FILM
$352M worldwide · Spielberg, 2002
LATER
Fraud-prevention consultant since 1976
THE STORY VS THE RECORD: his famous claims (pilot, doctor, lawyer, professor, $2.5M) are disputed. Prison records show he was in a New York prison from July 1965 to December 1968.
FULL PROFILE

IDENTITY

NAME
Frank William Abagnale Jr.
BORN
April 27, 1948 · the Bronx, New York · French mother, Italian-American father
FAMILY
Parents separated when he was about 12; lived with his father in Mount Vernon, NY
NAVY
Enlisted December 1964 at 16; discharged February 18, 1965
ALIASES
Frank Williams · Robert Conrad
TODAY
Living, 78 · married, three sons · Charleston, South Carolina

CASE RECORD

1965
Arrests in Mount Vernon, California and Tuckahoe, NY → Great Meadow Correctional Facility, July 1965 – December 1968 (inmate #25367)
1969
Baton Rouge: arrested posing as a TWA pilot, with checks stolen from a flight attendant’s family
1969–70
France (~3 months, Perpignan) and Sweden (~2 months, Malmö); deported to the US
1970
University of Arizona: posed as a pilot and physician to students
1970–71
Federal case: ten forged Pan Am payroll checks, $1,448.60; 10 years + 2 for escape
1974
Paroled February 8; arrested in August in Friendswood, Texas, for stealing cameras
THE DOCUMENTED CRIMES
NEW YORK · 1965–68PRISON
Great Meadow
Inmate #25367
After arrests for petty larceny, car theft and check theft, he was held from July 26, 1965 to December 24, 1968 — the years he later said he was a Pan Am pilot.
SOURCE: Logan (2020) · prison records
LOUISIANA · 1969ARRESTED
Baton Rouge
Posing as a TWA pilot
Arrested February 14, 1969. He had written about $1,200 in bad checks on checks stolen from the family of flight attendant Paula Parks.
SOURCE: WHYY · Logan (2020)
FRANCE & SWEDEN · 1969–70JAILED
Perpignan & Malmö
Swedish Interpol warrant
Arrested in Montpellier in September 1969; about three months in Perpignan, then about two months in Malmö; deported to the US.
SOURCE: Britannica · Wikipedia
ARIZONA · 1970DOCUMENTED
The “physicals”
University of Arizona
Posed as a pilot and physician and gave “physical exams” to 12 female students who thought they were applying to be flight attendants. Confirmed by university officials.
SOURCE: Wikipedia
FEDERAL · 1970–74CONVICTED
The Pan Am checks
$1,448.60
Arrested in Cobb County, Georgia, on November 2, 1970 over ten forged Pan Am payroll checks. Sentenced to 10 years + 2 for a jail escape; about 2 years at FCI Petersburg; paroled 1974.
SOURCE: Britannica · Wikipedia
TEXAS · 1974ARRESTED
Camp Manison
Friendswood
While on parole and posing as a pilot at a summer camp, he stole cameras from counselors. Arrested; outcome unverified.
SOURCE: The News (Friendswood), Sept 5, 1974
THE MOVIE & THE LEGEND
BOOK · 1980HIS ACCOUNT
Catch Me If You Can
With Stan Redding
The memoir that made him famous: pilot, doctor, lawyer, $2.5M in bad checks. Film rights sold the same year to Norman Lear and Bud Yorkin.
SOURCE: Wikipedia
FILM · 2002$352M WORLDWIDE
Steven Spielberg’s film
Budget $52M · released Dec 25, 2002
Leonardo DiCaprio as Abagnale, Tom Hanks as FBI agent Carl Hanratty, Christopher Walken as his father, with Amy Adams and Martin Sheen. Abagnale cameos as the French officer who arrests DiCaprio.
SOURCE: Wikipedia
THE REAL AGENTCOMPOSITE
Carl Hanratty
Loosely based on Joseph G. Shea
The Hanks character is loosely based on FBI Special Agent Joseph Shea, who asked not to be named. The real FBI pursuit lasted about three months, not years.
SOURCE: Wikipedia · Logan (2020)
AWARDS2 OSCAR NOMINATIONS
Walken & Williams
BAFTA and SAG for Walken
Christopher Walken (Supporting Actor) and John Williams (Score) were Oscar-nominated; DiCaprio got a Golden Globe nomination.
SOURCE: Wikipedia · goldenglobes.com
BROADWAY · 2011TONY WINNER
The musical
Neil Simon Theatre
Ran April 10 – September 4, 2011. Four Tony nominations; Norbert Leo Butz won Best Actor in a Musical — playing the FBI agent.
SOURCE: Wikipedia
THE BUSINESSSPEAKER
Fraud expert
AARP · books · talks
Abagnale & Associates (1976); books including The Art of the Steal (2001) and Scam Me If You Can (2019); AARP Fraud Watch ambassador (2015) and podcast co-host (2018); fees reported at $20,000–$30,000 a talk.
SOURCE: Wikipedia · AARP
THE DEBUNKERS
1978FIRST EXPOSÉ
San Francisco Chronicle
Stephen S. Hall
“Johnny is conned. A convict who makes up crimes.” — published two years before the memoir.
SOURCE: SF Chronicle, Oct 6, 1978
1978–81REFUTED
Louisiana
State Bar & Attorney General’s office
The bar found he “never took the exam under his name or any alias.” A senior AG official: “The man is not an imposter, he is a liar.”
SOURCE: Wikipedia · The Advocate, 1981
2020THE BOOK
Alan C. Logan
The Greatest Hoax on Earth
Court, prison and newspaper records: in prison 1965–68; a Pan Am uniform for about three months; checks under $1,500; many arrests, not one.
SOURCE: WHYY · The Irish World
THE FLIGHT ATTENDANTWITNESS
Paula Parks
Wrote the foreword to Logan’s book
Says he followed her along the East Coast and stole her family’s checks in Baton Rouge.
SOURCE: WHYY · Louisiana Voice
2022PODCAST
Javier Leiva
PRETEND: “The Real Catch Me If You Can”
Checked the claims against the records and confronted Abagnale at a Las Vegas conference on June 23, 2022.
SOURCE: thisispretend.com
2022DISCLAIMER
Google
Talks at Google (2017)
Disabled comments and added a note that it does not endorse the content or “lay claim to the validity of the actions described.”
SOURCE: Wikipedia
THE RECORD VS HIS ACCOUNT
DOCUMENTED
Check forgery and convictions (US, France, Sweden) · about 5 years in prison · a Pan Am uniform for about 3 months in 1970 · an FBI pursuit of about 3 months
DISPUTED
Years as a pilot, doctor, lawyer or professor · prison escapes as described · a years-long FBI chase
HIS CLAIM
$2.5 million in checks in 26 countries — not confirmed by any court record
IN HIS WORDS
USA TODAY, 2002
“I impersonated a doctor for a few days, I was a lawyer for a few days. In the book, it’s like I am doing this for a year.”
ON LOGAN’S BOOK, 2021
“I have not read the book, nor do I think it is worthy of a comment.”
XAVIER UNIVERSITY, 2022
Denied lying; said he had no responsibility for the content of his autobiography, the film or the musical.
CASE TIMELINE
April 27, 1948
Born
The Bronx, New York.
SOURCE: Britannica
July 1965 – Dec 1968
Great Meadow
Held in a New York prison — the years of his most famous claimed exploits.
SOURCE: Logan (2020)
Feb 1969
Baton Rouge
Arrested posing as a TWA pilot.
SOURCE: Logan (2020)
Sept 1969
France, then Sweden
Arrested in Montpellier; jailed in Perpignan and Malmö.
SOURCE: Britannica
Nov 1970
The Pan Am checks
Arrested in Georgia over $1,448.60 in forged payroll checks; 10 years + 2.
SOURCE: Britannica
Feb 1974
Paroled
Leaves FCI Petersburg, Virginia.
SOURCE: Wikipedia
1976
Abagnale & Associates
Starts a fraud-prevention consulting business.
SOURCE: Wikipedia
Oct 1978
First exposé
San Francisco Chronicle: “A convict who makes up crimes.”
SOURCE: SF Chronicle
1980
The memoir
Catch Me If You Can; film rights sold.
SOURCE: Wikipedia
Dec 2002
The movie
Spielberg’s film opens; $352M worldwide.
SOURCE: Wikipedia
April 2011
Broadway
The musical opens; one Tony win.
SOURCE: Wikipedia
Dec 2020
The Greatest Hoax
Alan Logan’s records-based book.
SOURCE: WHYY
2022
Confronted
Leiva’s podcast; Google’s disclaimer.
SOURCE: Wikipedia
HOW IT WORKED

WHAT HE ACTUALLY DID — AND WHAT HE SAID

01
Checks: Forged and cashed bad checks, including Pan Am payroll checks — documented
02
Impersonation: Posed as a pilot for about three months and as a physician to students in Arizona — documented
03
The claims: Years as a pilot, a hospital doctor, a Louisiana lawyer, a professor — disputed
04
The legend: A memoir, talk-show fame, a Spielberg film, a Broadway musical
05
The business: Decades of paid talks on fraud prevention, built on the story
HOW THE STORY GREW
Small check frauds
-->
A memoir
-->
A movie
-->
Speaking fees
KNOWN NETWORK & CONNECTED CASES

WHAT THIS CASE ESTABLISHED

The con that lasted was the story, not the checks.
Documented: convictions in three countries and a federal check case of $1,448.60. Claimed: $2.5M and years of impossible careers.
His claims were publicly questioned from 1978 on — and the legend still outsold the record for four decades.
Series link: (Belfort) — famous for the retelling, not the record.
THE FULL STORY — 4 PARTS — SOURCES VERIFIED
TAP TO READ FULL NARRATIVE — THE LEGEND (2,200 WORDS)
Sources: US federal court records · French court records, 1969 · Alan C. Logan — The Greatest Hoax on Earth (2020) · The Irish World interview with Logan · Attrition.org documentation of exposés · San Francisco Chronicle, October 6, 1978 ('Johnny is conned. A convict who makes up crimes.') · Abagnale's memoir Catch Me If You Can (1980, with Stan Redding) — self-reported, treated as claim not source. DISCIPLINE: Self-reported figures attributed as such throughout. The biography dispute must appear. Court record is the authority.
· PROLOGUE ·
The Ancestor

() sent a spoofed email and a wire moved. () sent a fake invoice and Google and Facebook paid $122 million. Neither of them broke into a building, cracked a safe, or wrote a line of code. Both of them exploited the same vulnerability: institutions verify surfaces, not substance.

Frank Abagnale Jr. is in this series because he documented that vulnerability four decades before email existed. In the 1960s, without a computer, he forged cheques and — by his account — impersonated people the system already trusted: an airline pilot, a physician, a lawyer. The surface was a uniform, a badge, a printed credential, a confident voice. The institution saw the surface and verified him by sight.

That is the same failure mode. The mechanism is identical. The medium changed — from a face in a uniform to a spoofed domain — but the exploit is the same one: trust built on appearance rather than verification.

Case 019 is the field guide entry, not the hagiography. The story Abagnale told — and sold — has been substantially contradicted by investigative research. A journalist named Alan C. Logan published a book in 2020 called The Greatest Hoax on Earth documenting those contradictions from court records, prison documents, and contemporary newspaper archives. [SOURCE: Logan, 2020; The Irish World interview with Logan]

The documented crime is real: check forgery, conviction, prison. The famous version — the years-long FBI chase, the serial impersonations at scale, the multiple prison escapes — is not supported by the primary record. What Abagnale did after prison was turn that distinction into a 40-year career. He is a living private individual and this piece reports the record, both the documented parts and the disputed parts.

The man whose fraud was impersonation ended up impersonating his own history. The biggest con he ever pulled was convincing the world his story was true — and then selling that conviction as fraud expertise for four decades.

· PART ONE ·
What the Record Shows

Frank William Abagnale Jr. was born on April 27, 1948, in the Bronx, New York City. He grew up in Bronxville, then Mount Vernon, New York. His parents separated when he was 12 and divorced when he was 15.

Between approximately 1965 and 1974, Abagnale was in and out of prison and involved in check fraud. What the documentary record shows: he was a convicted check forger with multiple arrests. Prison records placed him at institutions during periods when, by his own account, he was flying as a Pan Am pilot or practicing medicine in Georgia. [SOURCE: Alan C. Logan, The Greatest Hoax on Earth, 2020 — citing court records and prison documents]

What Logan's research found, and what he documented from primary sources: between ages 17 and 20, Abagnale was incarcerated — not impersonating pilots. The FBI task force he described did not exist as described in his memoir. The prison escapes did not occur as described; he was never at Atlanta Federal Penitentiary and never escaped from it. He was arrested multiple times, not once as he claimed at a 2017 Google talk. [SOURCE: Logan, 2020; attrition.org documentation]

What is documented and not in serious dispute: a brief period in 1970 when Abagnale wore a Pan Am pilot uniform — approximately three months. The FBI pursuit was real but brief — approximately three months, not the years-long chase of the memoir and film. He was arrested in France in 1969. He served time in French and US prisons. He was released on condition that he assist federal authorities. He did some consulting work. [SOURCE: Logan, 2020; San Francisco Chronicle, October 6, 1978]

The San Francisco Chronicle article from October 6, 1978 — published two years before his memoir — was titled 'Johnny is conned. A convict who makes up crimes.' It was the first major exposé questioning his claims. It was cited in subsequent reporting. His claims were questioned for over 40 years by at least a dozen journalists before Logan's comprehensive 2020 book. [SOURCE: attrition.org compilation; Chronicle citation]

· PART TWO ·
The Story He Sold

In 1980, Frank Abagnale Jr. published a memoir co-written with Stan Redding. The book was called Catch Me If You Can.

The book claimed: from approximately ages 16 to 21, Abagnale impersonated a Pan American World Airways pilot, logging over two million air miles. He practiced law in Louisiana without a degree. He worked as a supervising resident at a Georgia hospital. He cashed over $2.5 million in fraudulent cheques across 26 countries. He escaped from prison twice. He was chased by the FBI for years.

Each of these claims has been substantially disputed or refuted by Logan's primary-source research. Pan Am records do not support the pilot impersonation at the claimed scale. No Louisiana bar records support the attorney claim. Georgia hospital records do not support the physician claim. Prison records do not support the escape claims from the institutions he named. The FBI pursuit was approximately three months, not years. [SOURCE: Logan, The Greatest Hoax on Earth, 2020]

The memoir is self-reported. It is a claim, not a source. It is used here as a cultural document, not as evidence.

In 2002, Steven Spielberg made the book into a film. Leonardo DiCaprio played Abagnale. Tom Hanks played the FBI agent pursuing him. The film grossed over $350 million. It received two Academy Award nominations. It entered the cultural record as a true story of a charming genius-level con man.

That cultural entry is real even if the details are not. The film taught a generation what social engineering looks like. It gave the term 'con artist' a face. It made check fraud glamorous. The myth became the lesson whether the myth was accurate or not.

In 2002, Abagnale acknowledged on his website that some facts had been 'over-dramatized or exaggerated' without being specific about which ones. [SOURCE: Wikipedia citing archived website statement] This is not a full retraction. It is a partial acknowledgement. The disputed details continue to be repeated in speaking engagements and media appearances.

· PART THREE ·
The Consulting Career — Fraud as a Product

After his release, Frank Abagnale built a career as a fraud-prevention consultant. He founded Abagnale and Associates in 1976. He lectured at the FBI Academy. He consulted for banks, corporations, and government agencies on check fraud, forgery, and social engineering. [SOURCE: public record; Abagnale Inc. materials — self-reported]

The product he sold was his story. Banks hired him because he claimed to have defeated their systems. The FBI brought him in because he claimed to have evaded them for years. The consulting engagement required the legend — a watered-down resume would not have commanded the same fees or the same platform.

This is the mechanism that Logan documents: the fabricated criminal biography was not just a memoir, it was a commercial product. The grander and more spectacular the crimes, the more valuable the expert who had supposedly committed them. The fraud and the fraud prevention were the same business.

In 2020, when Logan's book was published, Abagnale continued to maintain his account in speaking appearances. He told a 2017 Google audience he had been arrested only once. Prison records cited by Logan document otherwise. [SOURCE: Logan, 2020; attrition.org]

He remains a living private individual. He is now 78 years old. This piece does not speculate about his current circumstances beyond the documented public record of his career.

DOCUMENTED RECORD vs ABAGNALE'S ACCOUNT

Check forgery / conviction

DOCUMENTED — court record confirms. This is real. [SOURCE: court record]

~5 years total prison time

DOCUMENTED — prison records confirm incarceration periods. [SOURCE: Logan, 2020]

Brief Pan Am uniform use (1970)

DOCUMENTED — approximately 3 months confirmed. [SOURCE: Logan, 2020]

FBI pursuit of ~3 months

DOCUMENTED — the FBI pursuit was real. The duration is confirmed as approximately 3 months. [SOURCE: Logan]

Years as pilot / doctor / lawyer

DISPUTED — no primary records support the claimed scale. Abagnale account; contradicted by Logan's primary-source research. [SOURCE: Logan, 2020]

Prison escapes

DISPUTED — records show he was not at Atlanta Federal Penitentiary; escapes as described not supported by prison documents. [SOURCE: Logan, 2020]

Years-long FBI chase

DISPUTED — FBI task force as described did not exist in the form claimed. Pursuit approximately 3 months. [SOURCE: Logan, 2020]

$2.5M in cheques, 26 countries

SELF-REPORTED — from memoir and speaking engagements. Not independently confirmed from court record. Attribute as his account. [SOURCE: Abagnale memoir, 1980]

· PART FOUR ·
The Principle That Holds

The disputed details do not cancel the lesson. They sharpen it.

When verification is built on appearances, the fraud only needs to reproduce the appearance. That principle predates Abagnale, is documented through him, and runs through every non-technical case in this series.

() sent a spoofed email. The payment process saw the right domain and paid. () registered a company with the same name as a legitimate vendor, generated matching paperwork, and Google and Facebook paid $122 million. Morgan () built a public persona eccentric enough that law enforcement did not look at what was underneath it.

Every one of these cases exploits the same vulnerability: the institution verifies the surface. The email domain. The invoice format. The uniform. The confident voice. The artist brand. Not the underlying reality.

Abagnale's contribution to this catalogue — whatever the accurate scope of his crimes — is that he documented the principle clearly enough that it became a cultural reference. The film made it famous. The consulting career made it curriculum. Banks and corporations hired him to teach them how the surface exploit works because understanding the exploit is the beginning of defending against it.

That teaching function is real even if the biography is inflated. The modern KYC (know your customer) framework, enhanced vendor verification processes, and corporate anti-social-engineering training all address the same vulnerability Abagnale described. The defenses were built, at least in part, because the story made the vulnerability visible.

The fraudulent biography does not undermine the lesson — it doubles it. A man whose documented crime was impersonating people the system trusted went on to impersonate a more impressive version of himself and was trusted for four decades. That is not a contradiction of the principle. It is a demonstration of it.

He was never the greatest forger. He was the greatest salesman of the idea that trust is a surface. The cheques are long gone. The lesson is still being taught — by every scam email that says it's from someone you already trust.

VERIFIED SOURCES AND DISPUTE RECORD

Living private individual — report the record only. Self-reported figures attributed throughout. The dispute is presented from both sides as sourced. Do not present either the legend or the debunking as settled fact beyond what the primary sources confirm.

[1] US federal court records — conviction and supervised release. The court record establishes: check forgery, conviction, prison time. [VERIFY exact case numbers and docket before publication]

[2] French court records — 1969 arrest, Montpellier. [VERIFY exact sentence term and prison locations from primary French records before publication]

[3] Alan C. Logan — The Greatest Hoax on Earth (2020). The primary debunking source. Drawing on court records, prison documents, and newspaper archives. SOURCE for: incarceration between ages 17-20; no escapes from Atlanta FP (was never there); FBI pursuit ~3 months; multiple arrests contradicting his '1 arrest' claim. THIS SOURCE MUST BE NAMED AND ATTRIBUTED — do not present Logan's findings as established fact without attribution; present as his documented research.

[4] San Francisco Chronicle, October 6, 1978 — 'Johnny is conned. A convict who makes up crimes.' Written by Stephen S. Hall. The first major published exposé, predating the memoir. Cited in attrition.org documentation and by Logan.

[5] Attrition.org — 'He has been debunked before' — compilation of 12+ articles questioning Abagnale from 1978 to 2020. Establishes the pattern of repeated debunking across four decades.

[6] The Irish World — interview with Alan C. Logan. Key finding stated: 'between the ages of 17 and 20, Abagnale was incarcerated' — not flying internationally. 'The real FBI chase was just three months long.'

[7] Frank Abagnale with Stan Redding — Catch Me If You Can (memoir, 1980). SELF-REPORTED. Treated throughout as a claim, not a source of fact. The figures ($2.5M, 26 countries) come substantially from this document.

[8] Abagnale Inc. / Abagnale and Associates — his own consultancy materials. Self-reported. Founded 1976 per public record.

[9] Wikipedia — Frank Abagnale (aggregator). Source for 2002 website statement acknowledging 'over-dramatized or exaggerated' facts — verify this to the archived website before publication.

TO VERIFY Exact loss figure and its source (court record vs memoir); precise prison timeline and institutions; whether any impersonations are court-documented vs entirely self-reported; exact nature of the federal consulting arrangement post-release; birth date (April 27, 1948 — widely cited, verify to primary)

SOURCES
[1] PRIMARY — Great Meadow record #25367 and federal parole record, as published by Alan C. Logan (2020)
[2] SECONDARY — Alan C. Logan, The Greatest Hoax on Earth (2020)
[3] SECONDARY — San Francisco Chronicle, Oct 6, 1978
[4] SECONDARY — WHYY (2021); The Irish World (2021); Louisiana Voice (2021)
[5] SECONDARY — Britannica: Frank Abagnale Jr.
[6] AGGREGATOR — Wikipedia: Frank Abagnale; Catch Me If You Can (film, musical)
[7] SELF-SERVING — Catch Me If You Can (memoir, 1980)
END OF REPORT