Investment fraud as a network: blocking individual payments is no longer enough
Analytics2026-09-01, 12:02
Group-IB published a study on how modern investment fraud schemes are evolving into large-scale infrastructure networks. The main challenge for banks and anti-fraud systems is that many transfers are technically legitimate: the victim authorizes the transaction themselves. As a result, detecting fraud only at the transaction stage is often too late.
The researchers examine two operations as examples:
GoldBull — manipulation of legitimate stocks. The attackers use deepfake-based advertising to redirect users to WhatsApp groups, where they persuade them to buy illiquid stocks. In one case, mass buying drove the price up by 12.4%, after which the fraudsters sold shares they had acquired in advance, and their value subsequently fell by approximately 42%. In each such campaign, victims collectively invested around $1.5–3 million.
CoinLure — a network of fake investment platforms. Users are attracted through search results, social media advertising, and romance scams, then redirected to fraudulent investment websites. When they try to withdraw their money, they face additional “taxes,” “insurance fees,” and other demands; after the funds are lost, victims may even be offered paid help recovering their money. An analysis of one such platform identified 208 domains linked by a shared infrastructure; the estimated combined revenue of the CoinLure cluster exceeds $187 million.
Both examples show that detecting fraud only when funds are transferred may be insufficient: by that point, the victim is already involved in the scheme and authorizes the transaction themselves. Group-IB therefore recommends considering indicators that can expose fraudulent activity earlier:
Infrastructure reuse. Shared hosting, domains, cryptocurrency wallets, recipient accounts, and contact details can link individual incidents into a single network and help identify new fraudulent resources.
Changes in payment app usage patterns. Unusual session times and other changes in a customer's normal behavior can serve as additional risk indicators, especially when they coincide with signs of an active fraud campaign.
Signal sharing across the financial sector. Data on suspicious recipients, devices, and infrastructure can be used to identify linked schemes and mule accounts before the main fraudulent transactions take place.
The research shows that effectively detecting modern investment fraud schemes requires analyzing the entire connected infrastructure, not just individual transactions. As a scheme grows, attackers increasingly reuse domains, accounts, wallets, and technical templates, leaving persistent links between different incidents. This makes it possible to detect a fraud campaign earlier — before funds are transferred.
Vendors
Products