Case Library / Vishing (Voice Phishing) / DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams that stole $65 million from thousands of US seniors, cracking the case partly with help from YouTube scambaiters who filmed and identified key money mules.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On August 27, 2025, the U.S. Attorney's Office for the Southern District of California and IRS Criminal Investigation announced that 28 alleged members of a Chinese organized-crime ring had been charged in four unsealed federal grand jury indictments (25-cr-1097-TWR, 25-cr-1762-TWR, 25-cr-1765-TWR, 25-cr-2208-TW) for their roles in a $65 million fraud and money-laundering scheme. The network, rooted in Southern California and operating since at least 2019, served as the U.S.-based money-laundering and cash-collection arm for India-based scam call centers running "mistaken refund" (overpayment) scams against thousands of American seniors. A coordinated, weeklong nationwide takedown resulted in 25 of the 28 defendants being arrested across California, New York, Texas, and Michigan, more than $4.2 million seized from financial accounts, and several luxury vehicles seized as suspected fraud proceeds. Independent YouTube "scambaiter" channels, Pierogi of Scammer Payback and Trilogy Media, played a documented role in the investigation: their 2020-2021 sting videos, in which they posed as victims, baited scammers, and confronted a money-mule collector (Zhiyi Zhang, alias "Cream Pablo") on camera, were passed to law enforcement and directly helped identify three defendants (Zhiyi Zhang, Dudu Chen, Huajian Chen) named in the indictments.

How the Attack Worked

Victims (predominantly elderly) received unsolicited phone calls, emails, or pop-up ads instructing them to call a phone number for supposed customer support, a bank, or a government agency. That number actually connected them to scam call centers based in India. Callers posing as tech-support agents, bank employees, or government officials used scripted lies and psychological manipulation to build trust, and frequently convinced the victim to install remote-desktop software and grant remote access to their computer. Once inside, the scammer staged a fake "mistaken" or excess refund appearing in the victim's bank/investment account (often via a doctored screen the victim could see through the remote session) and then pressured or threatened the victim to "return" the erroneous overpayment immediately, framing it as an urgent compliance obligation. Victims were told to send the money back via wire transfer, cash, or gift cards. Cash-paying victims were directed to package currency and ship it via overnight/express courier addressed to fake names tied to false IDs, at short-term rental addresses in the U.S. that conspirators used and rotated frequently to collect proceeds and evade detection. U.S.-based members of the Chinese organized-crime network (many in the country illegally) served as the money-laundering/collection arm for the India-based call centers, being paid per package collected.

The Lure & the Tell

Lure: an unsolicited call, email, or computer pop-up warning of a supposed billing/refund error and providing a number to call "to fix it," exploiting fear of financial loss/liability and trust in apparent bank, tech-support, or government authority. The "mistaken refund" hook (you were overpaid, you must return the difference or face consequences) creates urgency and a false sense of legal/moral obligation, while remote-desktop access lets the scammer fabricate visual "proof" of the erroneous deposit on the victim's own screen. Tell-tale signs missed by victims: legitimate banks/agencies never ask you to call a number from a pop-up or unsolicited message; refunds are never returned via wire, cash courier, or gift cards; remote-access software requested by an unsolicited caller is a hard stop; pressure/threats to act immediately on a "refund error" is a scripted urgency tactic, not standard institutional process.

Outcome

On August 27, 2025, DOJ (USAO-SDCA) and IRS-CI announced a nationwide, weeklong takedown: 25 of 28 charged defendants were arrested across California, New York, Texas, and Michigan; all were charged with conspiracy to commit mail and wire fraud (18 U.S.C. § 1349) and conspiracy to launder monetary instruments (18 U.S.C. § 1956(h)), with forfeiture allegations in at least one indictment (25-cr-1765-TWR) under 18 U.S.C. §§ 981(a)(1)(C), 982(a)(1), 982(a)(2)(A), 2328(a) and 28 U.S.C. § 2461(c). More than $4.2 million and several luxury vehicles were seized. Defendant Zhiyi Zhang ("Cream Pablo") was arrested August 19, 2025 at LAX. The case proceeded into 2026 with guilty pleas: Ziyue Zhao pleaded guilty (reported April 2, 2026, admitting to roughly 1,269 victim cash packages averaging ~$14,000 each between Feb. 2020-Mar. 2021); by around July 2026, Hua Wang and ten other defendants had also pleaded guilty, with Wang admitting responsibility for over 2,000 cash packages and $64 million in victim losses. Sentencing hearings for multiple defendants were scheduled for July-September 2026. As of the case's most recent confirmed reporting, the matter remains ongoing (not fully resolved for all 28 defendants).

Why It Matters

This case is a useful boundary example for a smishing/messaging-scam education track because the entry vector (unsolicited call/email/pop-up directing the victim to call a number) sits directly adjacent to smishing and vishing techniques, while the core exploit is pure social engineering rather than any technical hack: no malware payload was needed, only a scripted trust-building phone conversation, remote-desktop access, and a fabricated sense of urgent legal obligation. It illustrates how transnational fraud is now industrialized and specialized: an India-based call center handles the psychological manipulation while a separate US-based organized-crime network handles laundering physical cash through couriers, false identities, and short-term rentals, showing students that "the scammer on the phone" and "the person who launders the money" are often entirely different organizations in different countries. It's also a rare, well-documented case of civilian scambaiters directly contributing verifiable evidence (unblurred video, rental records, on-camera confessions) that helped identify high-level defendants, underscoring that private citizen research/documentation efforts can materially aid federal law enforcement in elder-fraud investigations.

Defenses

DOJ/IRS-CI attribute the breakthrough substantially to independent YouTube "scambaiters" (Pierogi of Scammer Payback, and the Trilogy Media channel) who ran sting operations posing as victims, physically confronted money-mule collectors on camera, and passed unblurred footage, rental records, and identifying details to law enforcement; footage from 2020-2021 videos directly helped identify defendants Zhiyi Zhang, Dudu Chen, and Huajian Chen. Practical defenses for the public per DOJ/IRS guidance embedded in the release: never call back numbers from unsolicited pop-ups/emails claiming a refund error; never grant remote desktop/screen-sharing access to an unsolicited caller; a legitimate refund is never "returned" via wire, cash courier, or gift card; verify any refund/billing claim by calling the institution back using a number independently looked up (not one provided by the caller); be suspicious of pressure to send cash to a third-party name via overnight courier to a residential/short-term-rental address; family/community education for elderly relatives on this exact "mistaken overpayment" script is a key defense given the demographic targeting.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and infrastructure setup: Per DOJ/IRS-CI's account, the India-based call centers behind the underlying tech-support, bank-impersonation, government-impersonation, and refund scripts likely relied on mass-market contact infrastructure, purchased or scraped calling and email lists, spoofed caller-ID services, and malicious pop-up ad placements, to generate a high volume of initial contacts, consistent with mass-targeted elder fraud rather than named-victim OSINT research.
Countering Stage 1: Mass-market contact infrastructure, spoofed caller ID, scraped calling lists, and bulk pop-up/email networks, sits largely outside an individual victim's control and outside US jurisdiction when run through India-based call centers; the realistic controls are carrier-level caller-ID authentication, ad-network and pop-up filtering, and cross-border law-enforcement cooperation rather than anything a victim can do at this stage.
2
Initial contact and lure: Victims received an unsolicited phone call, email, or computer pop-up warning of a fabricated billing or refund error and directing them to call a phone number; per the indictment, that number actually routed to an India-based scam call center rather than any real bank, government agency, or tech company.
Countering Stage 2: Treat any unsolicited call, email, or pop-up instructing you to call a number as inherently suspicious, and never call the number it provides; look up the institution's number independently, from a bank statement or the official website, and call that instead.
3
Pretext and rapport-building: Per the indictment's description of conspirators using "social engineering techniques to build trust," callers posed as tech-support agents, bank employees, or government officials and used scripted lies to establish credibility and keep the victim engaged.
Countering Stage 3: No legitimate bank, government agency, or tech-support provider initiates unsolicited contact and pressures a decision within the same call; awareness education for the targeted demographic on this specific fast-trust-building pattern is the practical control, since the call itself cannot be intercepted before it happens.
4
Remote-access facilitation: The caller convinced the victim to install commercial remote-desktop software and grant control of their computer, a step DOJ's account describes as central to the scheme and that gave the scammer a persistent channel to control what the victim saw on their own screen.
Countering Stage 4: Remote-desktop or screen-sharing software requested by an unsolicited caller is a hard stop; family and community education campaigns for elderly relatives are the main lever here, since once access is granted the scammer controls what the victim sees next.
5
Fabricated "mistaken refund": Using the remote session, the scammer staged a doctored on-screen balance or transaction showing an erroneous overpayment or refund in the victim's bank or investment account, manufacturing visual "proof" the victim had no independent way to check.
Countering Stage 5: Because the scammer controls the victim's screen at this point, no on-screen "proof" can be trusted; the effective countermeasure is upstream, refusing remote access in the first place (Stage 4), or independently verifying any account balance via a separate device or a callback to the institution using an independently sourced number.
6
Urgency and compliance pressure: The caller pressured or threatened the victim to "return" the fabricated overpayment immediately, framing it as a legal or moral obligation, per DOJ's account, to short-circuit any pause to verify independently.
Countering Stage 6: Recognizing manufactured urgency, being told to act now or face legal consequences, as a scripted manipulation tactic rather than standard institutional process, and building in a mandatory pause to call a trusted family member or the institution back, breaks the pressure loop.
7
Cash/wire/gift-card extraction and courier routing: Victims were instructed to send funds by wire transfer or gift card, or, per the indictments and Ziyue Zhao's plea agreement, to withdraw bulk cash and ship it via overnight/express courier to fictitious names tied to false IDs at short-term rental addresses controlled by the US-based collection network.
Countering Stage 7: A legitimate refund or bank correction is never returned via wire transfer, cash courier, or gift card; financial institutions and retailers can flag and delay large cash withdrawals or bulk gift-card purchases by elderly customers, and courier carriers can flag high-volume cash-package patterns addressed to short-term-rental addresses.
8
Money-mule collection and laundering (objective completion): US-based network members, paid per package, collected the courier shipments at rotating short-term rentals under a documented "hub-and-spoke" booking pattern (per Zhao's plea agreement) to launder the physical cash and evade detection, completing the transfer of stolen funds from victim to the India-based call centers' US collection arm.
Countering Stage 8: By this stage the realistic countermeasures are law-enforcement-side, financial-account and courier-record subpoenas, short-term-rental monitoring for rotating hub-and-spoke booking patterns, and cross-border cooperation targeting the call centers directly, since cash already in a mule network's hands is typically unrecoverable for the victim; this case's own resolution leaned heavily on citizen-documented evidence (unblurred video, rental records) supplementing law enforcement, underscoring that victim-side defense has to happen at the earlier stages.
Quick Facts
Victim
Thousands of US senior citizens, including a named 97-year-old San Diego widow of a Holocaust survivor who lost her entire life savings
Location
San Diego / Southern District of California (case venue); arrests executed in California, New York, Texas, and Michigan; fraudulent calls originated from India-based call centers; victims located across the United States
Date
2025-08-27 (nationwide takedown/indictments unsealed); scheme operated since at least 2019; guilty pleas continuing into 2026 (Ziyue Zhao plea reported Apr. 2, 2026; Hua Wang and 10 others by ~July 2026)
Impact
$65 million in alleged total fraud/laundering proceeds cited in the indictments; more than $4.2 million seized in cash/financial accounts during the August 2025 takedown, plus luxury vehicles (a 2022 Mercedes-Benz G63, 2024 Porsche Panamera, and 2025 GMC Yukon Denali) seized as suspected proceeds. Subset admissions from later guilty pleas: defendant Ziyue Zhao admitted the organization received roughly 1,269 victim cash packages averaging about $14,000 each (~$17.8M) during Feb. 2020-Mar. 2021 alone; defendant Hua Wang later admitted responsibility for over 2,000 cash packages and $64 million in victim losses tied to his portion of the scheme (per follow-up DOJ/IRS reporting in 2026). Defendant Zhiyi Zhang alone was linked to at least $1.8 million in losses per the government's detention memo. One named victim, a 97-year-old San Diego widow of a Holocaust survivor, lost her entire life savings.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Financial Services & Insurance, Government & Public Sector
Threat Actor
Organized Crime
Related

Related Cases

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…

Incident 2025Read →

Quebec AI-Assisted "Grandparent Scam" Ring: Teodor/Condurache Sentenced After Targeting Saskatchewan Seniors

Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors…

Incident 2025Read →

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and…

Incident 2025Read →