DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams that stole $65 million from thousands of US seniors, cracking the case partly with help from YouTube scambaiters who filmed and identified key money mules.
Reviewed by the Social Engineering Examples team.
On August 27, 2025, the U.S. Attorney's Office for the Southern District of California and IRS Criminal Investigation announced that 28 alleged members of a Chinese organized-crime ring had been charged in four unsealed federal grand jury indictments (25-cr-1097-TWR, 25-cr-1762-TWR, 25-cr-1765-TWR, 25-cr-2208-TW) for their roles in a $65 million fraud and money-laundering scheme. The network, rooted in Southern California and operating since at least 2019, served as the U.S.-based money-laundering and cash-collection arm for India-based scam call centers running "mistaken refund" (overpayment) scams against thousands of American seniors. A coordinated, weeklong nationwide takedown resulted in 25 of the 28 defendants being arrested across California, New York, Texas, and Michigan, more than $4.2 million seized from financial accounts, and several luxury vehicles seized as suspected fraud proceeds. Independent YouTube "scambaiter" channels, Pierogi of Scammer Payback and Trilogy Media, played a documented role in the investigation: their 2020-2021 sting videos, in which they posed as victims, baited scammers, and confronted a money-mule collector (Zhiyi Zhang, alias "Cream Pablo") on camera, were passed to law enforcement and directly helped identify three defendants (Zhiyi Zhang, Dudu Chen, Huajian Chen) named in the indictments.
Victims (predominantly elderly) received unsolicited phone calls, emails, or pop-up ads instructing them to call a phone number for supposed customer support, a bank, or a government agency. That number actually connected them to scam call centers based in India. Callers posing as tech-support agents, bank employees, or government officials used scripted lies and psychological manipulation to build trust, and frequently convinced the victim to install remote-desktop software and grant remote access to their computer. Once inside, the scammer staged a fake "mistaken" or excess refund appearing in the victim's bank/investment account (often via a doctored screen the victim could see through the remote session) and then pressured or threatened the victim to "return" the erroneous overpayment immediately, framing it as an urgent compliance obligation. Victims were told to send the money back via wire transfer, cash, or gift cards. Cash-paying victims were directed to package currency and ship it via overnight/express courier addressed to fake names tied to false IDs, at short-term rental addresses in the U.S. that conspirators used and rotated frequently to collect proceeds and evade detection. U.S.-based members of the Chinese organized-crime network (many in the country illegally) served as the money-laundering/collection arm for the India-based call centers, being paid per package collected.
Lure: an unsolicited call, email, or computer pop-up warning of a supposed billing/refund error and providing a number to call "to fix it," exploiting fear of financial loss/liability and trust in apparent bank, tech-support, or government authority. The "mistaken refund" hook (you were overpaid, you must return the difference or face consequences) creates urgency and a false sense of legal/moral obligation, while remote-desktop access lets the scammer fabricate visual "proof" of the erroneous deposit on the victim's own screen. Tell-tale signs missed by victims: legitimate banks/agencies never ask you to call a number from a pop-up or unsolicited message; refunds are never returned via wire, cash courier, or gift cards; remote-access software requested by an unsolicited caller is a hard stop; pressure/threats to act immediately on a "refund error" is a scripted urgency tactic, not standard institutional process.
On August 27, 2025, DOJ (USAO-SDCA) and IRS-CI announced a nationwide, weeklong takedown: 25 of 28 charged defendants were arrested across California, New York, Texas, and Michigan; all were charged with conspiracy to commit mail and wire fraud (18 U.S.C. § 1349) and conspiracy to launder monetary instruments (18 U.S.C. § 1956(h)), with forfeiture allegations in at least one indictment (25-cr-1765-TWR) under 18 U.S.C. §§ 981(a)(1)(C), 982(a)(1), 982(a)(2)(A), 2328(a) and 28 U.S.C. § 2461(c). More than $4.2 million and several luxury vehicles were seized. Defendant Zhiyi Zhang ("Cream Pablo") was arrested August 19, 2025 at LAX. The case proceeded into 2026 with guilty pleas: Ziyue Zhao pleaded guilty (reported April 2, 2026, admitting to roughly 1,269 victim cash packages averaging ~$14,000 each between Feb. 2020-Mar. 2021); by around July 2026, Hua Wang and ten other defendants had also pleaded guilty, with Wang admitting responsibility for over 2,000 cash packages and $64 million in victim losses. Sentencing hearings for multiple defendants were scheduled for July-September 2026. As of the case's most recent confirmed reporting, the matter remains ongoing (not fully resolved for all 28 defendants).
This case is a useful boundary example for a smishing/messaging-scam education track because the entry vector (unsolicited call/email/pop-up directing the victim to call a number) sits directly adjacent to smishing and vishing techniques, while the core exploit is pure social engineering rather than any technical hack: no malware payload was needed, only a scripted trust-building phone conversation, remote-desktop access, and a fabricated sense of urgent legal obligation. It illustrates how transnational fraud is now industrialized and specialized: an India-based call center handles the psychological manipulation while a separate US-based organized-crime network handles laundering physical cash through couriers, false identities, and short-term rentals, showing students that "the scammer on the phone" and "the person who launders the money" are often entirely different organizations in different countries. It's also a rare, well-documented case of civilian scambaiters directly contributing verifiable evidence (unblurred video, rental records, on-camera confessions) that helped identify high-level defendants, underscoring that private citizen research/documentation efforts can materially aid federal law enforcement in elder-fraud investigations.
DOJ/IRS-CI attribute the breakthrough substantially to independent YouTube "scambaiters" (Pierogi of Scammer Payback, and the Trilogy Media channel) who ran sting operations posing as victims, physically confronted money-mule collectors on camera, and passed unblurred footage, rental records, and identifying details to law enforcement; footage from 2020-2021 videos directly helped identify defendants Zhiyi Zhang, Dudu Chen, and Huajian Chen. Practical defenses for the public per DOJ/IRS guidance embedded in the release: never call back numbers from unsolicited pop-ups/emails claiming a refund error; never grant remote desktop/screen-sharing access to an unsolicited caller; a legitimate refund is never "returned" via wire, cash courier, or gift card; verify any refund/billing claim by calling the institution back using a number independently looked up (not one provided by the caller); be suspicious of pressure to send cash to a third-party name via overnight courier to a residential/short-term-rental address; family/community education for elderly relatives on this exact "mistaken overpayment" script is a key defense given the demographic targeting.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors…
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and…