DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
Social Engineering Examples·6 sources
On August 27, 2025, the U.S. Attorney's Office for the Southern District of California and IRS Criminal Investigation announced that 28 alleged members of a Chinese organized-crime ring had been charged in four unsealed federal grand jury indictments (25-cr-1097-TWR, 25-cr-1762-TWR, 25-cr-1765-TWR, 25-cr-2208-TW) for their roles in a $65 million fraud and money-laundering scheme.
The network, rooted in Southern California and operating since at least 2019, served as the U.S.-based money-laundering and cash-collection arm for India-based scam call centers running "mistaken refund" (overpayment) scams against thousands of American seniors. A coordinated, weeklong nationwide takedown resulted in 25 of the 28 defendants being arrested across California, New York, Texas, and Michigan, more than $4.2 million seized from financial accounts, and several luxury vehicles seized as suspected fraud proceeds.
Independent YouTube "scambaiter" channels, Pierogi of Scammer Payback and Trilogy Media, played a documented role in the investigation: their 2020-2021 sting videos, in which they posed as victims, baited scammers, and confronted a money-mule collector (Zhiyi Zhang, alias "Cream Pablo") on camera, were passed to law enforcement and directly helped identify three defendants (Zhiyi Zhang, Dudu Chen, Huajian Chen) named in the indictments.
Victims (predominantly elderly) received unsolicited phone calls, emails, or pop-up ads instructing them to call a phone number for supposed customer support, a bank, or a government agency. That number actually connected them to scam call centers based in India. Callers posing as tech-support agents, bank employees, or government officials used scripted lies and psychological manipulation to build trust, and frequently convinced the victim to install remote-desktop software and grant remote access to their computer.
Once inside, the scammer staged a fake "mistaken" or excess refund appearing in the victim's bank/investment account (often via a doctored screen the victim could see through the remote session) and then pressured or threatened the victim to "return" the erroneous overpayment immediately, framing it as an urgent compliance obligation. Victims were told to send the money back via wire transfer, cash, or gift cards.
Cash-paying victims were directed to package currency and ship it via overnight/express courier addressed to fake names tied to false IDs, at short-term rental addresses in the U.S. that conspirators used and rotated frequently to collect proceeds and evade detection. U.S.-based members of the Chinese organized-crime network (many in the country illegally) served as the money-laundering/collection arm for the India-based call centers, being paid per package collected.
Lure: an unsolicited call, email, or computer pop-up warning of a supposed billing/refund error and providing a number to call "to fix it," exploiting fear of financial loss/liability and trust in apparent bank, tech-support, or government authority. The "mistaken refund" hook (you were overpaid, you must return the difference or face consequences) creates urgency and a false sense of legal/moral obligation, while remote-desktop access lets the scammer fabricate visual "proof" of the erroneous deposit on the victim's own screen.
Tell-tale signs missed by victims: legitimate banks/agencies never ask you to call a number from a pop-up or unsolicited message; refunds are never returned via wire, cash courier, or gift cards; remote-access software requested by an unsolicited caller is a hard stop; pressure/threats to act immediately on a "refund error" is a scripted urgency tactic, not standard institutional process.
On August 27, 2025, DOJ (USAO-SDCA) and IRS-CI announced a nationwide, weeklong takedown: 25 of 28 charged defendants were arrested across California, New York, Texas, and Michigan; all were charged with conspiracy to commit mail and wire fraud (18 U.S.C. § 1349) and conspiracy to launder monetary instruments (18 U.S.C. § 1956(h)), with forfeiture allegations in at least one indictment (25-cr-1765-TWR) under 18 U.S.C. §§ 981(a)(1)(C), 982(a)(1), 982(a)(2)(A), 2328(a) and 28 U.S.C. § 2461(c).
More than $4.2 million and several luxury vehicles were seized. Defendant Zhiyi Zhang ("Cream Pablo") was arrested August 19, 2025 at LAX. The case proceeded into 2026 with guilty pleas: Ziyue Zhao pleaded guilty (reported April 2, 2026, admitting to roughly 1,269 victim cash packages averaging ~$14,000 each between Feb. 2020-Mar. 2021); by around July 2026, Hua Wang and ten other defendants had also pleaded guilty, with Wang admitting responsibility for over 2,000 cash packages and $64 million in victim losses.
Sentencing hearings for multiple defendants were scheduled for July-September 2026. As of the case's most recent confirmed reporting, the matter remains ongoing (not fully resolved for all 28 defendants).
This case is a useful boundary example for a smishing/messaging-scam education track because the entry vector (unsolicited call/email/pop-up directing the victim to call a number) sits directly adjacent to smishing and vishing techniques, while the core exploit is pure social engineering rather than any technical hack: no malware payload was needed, only a scripted trust-building phone conversation, remote-desktop access, and a fabricated sense of urgent legal obligation.
It illustrates how transnational fraud is now industrialized and specialized: an India-based call center handles the psychological manipulation while a separate US-based organized-crime network handles laundering physical cash through couriers, false identities, and short-term rentals, showing students that "the scammer on the phone" and "the person who launders the money" are often entirely different organizations in different countries.
It's also a rare, well-documented case of civilian scambaiters directly contributing verifiable evidence (unblurred video, rental records, on-camera confessions) that helped identify high-level defendants, underscoring that private citizen research/documentation efforts can materially aid federal law enforcement in elder-fraud investigations.
DOJ/IRS-CI attribute the breakthrough substantially to independent YouTube "scambaiters" (Pierogi of Scammer Payback, and the Trilogy Media channel) who ran sting operations posing as victims, physically confronted money-mule collectors on camera, and passed unblurred footage, rental records, and identifying details to law enforcement; footage from 2020-2021 videos directly helped identify defendants Zhiyi Zhang, Dudu Chen, and Huajian Chen.
Practical defenses for the public per DOJ/IRS guidance embedded in the release: never call back numbers from unsolicited pop-ups/emails claiming a refund error; never grant remote desktop/screen-sharing access to an unsolicited caller; a legitimate refund is never "returned" via wire, cash courier, or gift card; verify any refund/billing claim by calling the institution back using a number independently looked up (not one provided by the caller); be suspicious of pressure to send cash to a third-party name via overnight courier to a residential/short-term-rental address; family/community education for elderly relatives on this exact "mistaken overpayment" script is a key defense given the demographic targeting.
Social Engineering Examples. “DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring”. Accessed 19 September 2026. https://socialengineeringexamples.com/chinese-organized-crime-mistaken-refund-elder-fraud-2025
Per DOJ/IRS-CI's account, the India-based call centers behind the underlying tech-support, bank-impersonation, government-impersonation, and refund scripts likely relied on mass-market contact infrastructure, purchased or scraped calling and email lists, spoofed caller-ID services, and malicious pop-up ad placements, to generate a high volume of initial contacts, consistent with mass-targeted elder fraud rather than named-victim OSINT research.
Mass-market contact infrastructure, spoofed caller ID, scraped calling lists, and bulk pop-up/email networks, sits largely outside an individual victim's control and outside US jurisdiction when run through India-based call centers; the realistic controls are carrier-level caller-ID authentication, ad-network and pop-up filtering, and cross-border law-enforcement cooperation rather than anything a victim can do at this stage.
Victims received an unsolicited phone call, email, or computer pop-up warning of a fabricated billing or refund error and directing them to call a phone number; per the indictment, that number actually routed to an India-based scam call center rather than any real bank, government agency, or tech company.
Treat any unsolicited call, email, or pop-up instructing you to call a number as inherently suspicious, and never call the number it provides; look up the institution's number independently, from a bank statement or the official website, and call that instead.
Per the indictment's description of conspirators using "social engineering techniques to build trust," callers posed as tech-support agents, bank employees, or government officials and used scripted lies to establish credibility and keep the victim engaged.
No legitimate bank, government agency, or tech-support provider initiates unsolicited contact and pressures a decision within the same call; awareness education for the targeted demographic on this specific fast-trust-building pattern is the practical control, since the call itself cannot be intercepted before it happens.
The caller convinced the victim to install commercial remote-desktop software and grant control of their computer, a step DOJ's account describes as central to the scheme and that gave the scammer a persistent channel to control what the victim saw on their own screen.
Remote-desktop or screen-sharing software requested by an unsolicited caller is a hard stop; family and community education campaigns for elderly relatives are the main lever here, since once access is granted the scammer controls what the victim sees next.
Using the remote session, the scammer staged a doctored on-screen balance or transaction showing an erroneous overpayment or refund in the victim's bank or investment account, manufacturing visual "proof" the victim had no independent way to check.
Because the scammer controls the victim's screen at this point, no on-screen "proof" can be trusted; the effective countermeasure is upstream, refusing remote access in the first place (Stage 4), or independently verifying any account balance via a separate device or a callback to the institution using an independently sourced number.
The caller pressured or threatened the victim to "return" the fabricated overpayment immediately, framing it as a legal or moral obligation, per DOJ's account, to short-circuit any pause to verify independently.
Recognizing manufactured urgency, being told to act now or face legal consequences, as a scripted manipulation tactic rather than standard institutional process, and building in a mandatory pause to call a trusted family member or the institution back, breaks the pressure loop.
Victims were instructed to send funds by wire transfer or gift card, or, per the indictments and Ziyue Zhao's plea agreement, to withdraw bulk cash and ship it via overnight/express courier to fictitious names tied to false IDs at short-term rental addresses controlled by the US-based collection network.
A legitimate refund or bank correction is never returned via wire transfer, cash courier, or gift card; financial institutions and retailers can flag and delay large cash withdrawals or bulk gift-card purchases by elderly customers, and courier carriers can flag high-volume cash-package patterns addressed to short-term-rental addresses.
US-based network members, paid per package, collected the courier shipments at rotating short-term rentals under a documented "hub-and-spoke" booking pattern (per Zhao's plea agreement) to launder the physical cash and evade detection, completing the transfer of stolen funds from victim to the India-based call centers' US collection arm.
By this stage the realistic countermeasures are law-enforcement-side, financial-account and courier-record subpoenas, short-term-rental monitoring for rotating hub-and-spoke booking patterns, and cross-border cooperation targeting the call centers directly, since cash already in a mule network's hands is typically unrecoverable for the victim; this case's own resolution leaned heavily on citizen-documented evidence (unblurred video, rental records) supplementing law enforcement, underscoring that victim-side defense has to happen at the earlier stages.
Browse by what this case has in common with others in the library.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing all ~11,000 staff W-2s to…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.