Case Library / Pretexting & Impersonation / Dominican Republic "Grandparent Scam" - Attorney/Police Impersonation Ring (D.N.J. Indictment)

Dominican Republic "Grandparent Scam" - Attorney/Police Impersonation Ring (D.N.J. Indictment)

A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.

Share:

Social Engineering Examples·5 sources

What Happened

On January 4, 2024, a federal grand jury in the District of New Jersey returned a 19-count indictment (unsealed April 29, 2024, in United States v. Juan Rafael Parra Arias, et al., No. 2:24-cr-00006) charging 11 Dominican nationals with mail fraud, wire fraud, mail/wire fraud conspiracy, money-laundering conspiracy, and money laundering for operating a long-running "grandparent" or "family-in-need-of-bail" scam out of call centers in Santiago de los Caballeros, Dominican Republic.

Five additional US-based defendants were charged by complaint with wire fraud conspiracy as couriers who physically collected cash from victims. DOJ announced the 16 total charges on April 30, 2024, describing the scheme as defrauding hundreds of elderly Americans across New Jersey, New York, Pennsylvania, and Massachusetts out of millions of dollars.

A related, separately charged US-based courier, Victor Anthony Valdez, a former Social Security Administration claims specialist, was indicted in June 2024 and pleaded guilty to wire fraud conspiracy in December 2024, illustrating the same courier role used in the broader scheme.

How the Attack Worked

The fraud used a layered, role-divided pretexting structure run like a call-center operation. "Openers" placed the first calls impersonating the elderly victim's grandchild (or another close relative), claiming to have been arrested, often after a car accident, sometimes adding a detail such as a pregnant companion having miscarried, to maximize panic and urgency.

Once the victim was emotionally hooked, "closers" took over the call posing as defense attorneys, police officers, or court personnel, instructing the victim that cash was needed immediately for bail, fines, or legal fees, and telling victims to keep the matter secret from other family members to avoid the grandchild getting into "more trouble." Dispatchers in the Dominican Republic then directed US-based couriers, via messaging apps and phone/text, to specific victims' homes, giving them the victim's name, address, the amount to collect, and even the false names to use when impersonating attorneys or court staff in person.

Couriers picked up cash at victims' doorsteps (sometimes issuing fake receipts) or received cash mailed via USPS or private carriers to drop addresses, then moved the money back into the network, generating the wire/mail fraud and money-laundering counts in the indictment.

The Lure & the Tell

The lure combined a plausible family emergency (arrest, car accident, needing bail) with escalating authority figures (grandchild, then "attorney," then "police"/"court personnel") and an explicit secrecy instruction that isolated the victim from anyone who could break the spell by contacting the real grandchild. The tell, in retrospect, was structural: legitimate bail and court processes never move through unsolicited phone calls demanding cash handed to an unannounced courier at the victim's home, never ask for secrecy from family, and never route payment through private couriers or mailed cash rather than official court/bail channels.

Outcome

Sixteen defendants were charged (11 by indictment, 5 by complaint). Two Dominican nationals, Rafael Ambiorix Rodriguez Guzman ("Max Morgan") and Felix Samuel Reynoso Ventura ("Fili"/"Filly The Kid"), were extradited from the Dominican Republic and made their initial appearance in Newark federal court on July 22, 2024, and were detained pending trial.

Three more, alleged ringleader Juan Rafael Parra Arias, Miguel Angel Vasquez, and Jose Ismael Dilone Rodriguez, were extradited and appeared in Newark on August 5, 2024, also detained pending trial. Extraditions were secured with assistance from DOJ's Office of International Affairs, the US Marshals Service, HSI, SSA-OIG, NYPD, the FBI, and cooperation from the Dominican government under the US-DR extradition treaty.

In a related case, US-based courier Victor Anthony Valdez pleaded guilty to wire fraud conspiracy on December 5, 2024, before Judge Claire C. Cecchi in Newark, with sentencing scheduled for April 9, 2025; he faced a statutory maximum of 20 years and a $250,000 fine. As of the public record reviewed, the case against the main indicted defendants remains in pretrial proceedings, with charges (not final convictions) carrying up to 20 years per count and fines up to $250,000 (fraud counts) or $500,000 (money-laundering counts) if convicted; defendants are presumed innocent unless and until proven guilty.

Why It Matters

This case is a rare, fully documented, DOJ-charged example of the classic "grandparent scam" escalated into an industrialized, role-specialized transnational operation, with distinct opener, closer, dispatcher, and courier functions spanning a foreign call-center hub and a US-based logistics network, rather than a single opportunistic caller. It shows how pretexting chains multiple impersonated authority figures (family member, then attorney, then police/court) to keep an elderly victim compliant long enough to physically hand cash to a stranger, and how extradition treaties and multi-agency cooperation (DOJ OIA, US Marshals, HSI, SSA-OIG, FBI, NYPD) can eventually reach offshore organizers.

Defenses

DOJ, FBI, and elder-fraud advocates recommend: never act on an unsolicited call claiming a relative is arrested or hospitalized without independently calling that relative or another family member back on a known number; treat any demand for secrecy as a red flag rather than a reason to comply; know that legitimate bail, court, or attorney processes do not collect cash via unannounced in-person couriers, wired retail gift cards, or mailed cash to third-party addresses; establish a family safe word/code phrase in advance for genuine emergencies; and financial institutions/postal and shipping carriers should train staff to flag elderly customers withdrawing large cash sums or mailing cash-filled packages under pressure, since those chokepoints intersected with this scheme's mail and wire fraud counts.

Sources
  • Sixteen Defendants Charged in Connection with Transnational "Grandparent Scam" Operated from Dominican Republic. U.S. Department of Justice (Office of Public Affairs) Primary. Original April 30, 2024 announcement of the 16-defendant, 19-count indictment/complaint; lists all defendants, roles, charges, and states hundreds of victims / millions of dollars. Verified by fetch: content matches exactly, including all 11 named defendants and aliases.
  • Arias et al. Indictment, Crim. No. 24-cr-6 (D.N.J.). U.S. Department of Justice / U.S. District Court, District of New Jersey Primary. The 19-count unsealed indictment itself; Count One and Count Seventeen both charge the conspiracy period as January 2019 through December 2023; Count Seventeen's Section 1957(a) object clause is the source of the >$10,000 criminally-derived-property language, distinct from the substantive Section 1956(a)(1)(B)(i) Counts Eighteen and Nineteen. Verified by direct fetch of the primary PDF plus a secondary search snippet quoting the Count 18/19 table (Victim 5/Williamstown NJ, Victim 9/Paterson NJ) that the primary fetch's extraction truncated before reaching.
  • Two Dominican Nationals Extradited in Connection with Grandparent Scam. U.S. Department of Justice (Office of Public Affairs) Primary. July 23, 2024 release confirming extradition and July 22 initial appearance of Rodriguez Guzman and Reynoso Ventura, and describing extradition-treaty cooperation with the Dominican government. Verified by fetch: content matches exactly.
  • Three Additional Dominican Nationals Extradited to Face "Grandparent Scam" Charges in New Jersey. U.S. Attorney's Office, District of New Jersey Primary. August 5, 2024 release confirming extradition of Parra Arias, Vasquez, and Dilone Rodriguez, naming investigating agencies (HSI, SSA-OIG, NYPD, FBI) and describing call-center leadership structure. Verified by fetch: content matches exactly.
  • Former Social Security Administration Employee Admits to Role in Transnational "Grandparent Scam" Operated from Dominican Republic. Social Security Administration Office of the Inspector General Primary. December 6, 2024 release on courier Victor Anthony Valdez's guilty plea (Aug 2020-Aug 2021 courier conduct window, distinct from the main scheme's Jan 2019-Dec 2023 charged conspiracy period), corroborating the opener/attorney-police-impersonation/courier mechanics and sentencing date. Verified by fetch: content matches exactly, including the April 9, 2025 sentencing date and $250,000/20-year statutory maximum.
Cite this case

Social Engineering Examples. “Dominican Republic "Grandparent Scam" - Attorney/Police Impersonation Ring (D.N.J. Indictment)”. Accessed 19 September 2026. https://socialengineeringexamples.com/dominican-republic-grandparent-scam-attorney-police-impersonation-2024

Attack Chain & Defense
1Target and lead sourcing
What happened

The indictment does not detail how victims were first identified, but a call-center operation dialing hundreds of specific elderly Americans by name and address is consistent with typical grandparent-scam tradecraft of buying bulk lead lists from data brokers, prior breach/leak dumps, or robocall-harvested number pools, rather than random dialing.

The control that would have stopped it

Which specific elderly individuals end up on a scam call list is largely outside any single defender's control given the breadth of data-broker and breach-derived contact lists in circulation; the realistic control sits downstream, at the moment the phone actually rings, rather than at list-sourcing.

2Telecom infrastructure setup
What happened

Per the indictment, defendant Nelson Rafael Gonzalez Acevedo and others procured voice-over-internet-protocol telephone services specifically to mask that calls originated in the Dominican Republic and to spoof caller-ID data so calls appeared to come from within the United States, a low-cost, commercially available technique rather than custom-built tooling.

The control that would have stopped it

Telecom carriers and regulators can enforce STIR/SHAKEN caller-ID authentication standards and flag or block inbound VOIP traffic that falsely presents foreign calls as originating domestically, making the spoofing step harder to pull off convincingly.

3Opener call and pretext initiation
What happened

'Openers' at the call centers phoned elderly victims and impersonated a grandchild or other close relative, typically claiming to have been arrested after a car accident, sometimes adding a detail such as a pregnant companion having miscarried, to maximize panic before any request for money was made.

The control that would have stopped it

Families should adopt a habit, ideally agreed in advance, of hanging up on any unsolicited call claiming a relative is arrested or hospitalized and independently calling that relative or another family member back on a known number before reacting.

4Closer escalation to authority impersonation
What happened

Once the victim was emotionally hooked, 'closers' took over the call posing as defense attorneys, police officers, or court personnel, demanded cash for bail or fees, and instructed the victim to keep the matter secret from other family members, isolating the victim from anyone who could break the pretext.

The control that would have stopped it

Teach that legitimate attorneys, police, and courts never demand cash for bail or fees over the phone from a third party and never instruct secrecy from family; both are definitional tells that should end the call immediately.

5Dispatch to US-based couriers
What happened

Conspirators in the Dominican Republic relayed the victim's name, address, and the amount to collect to US-based couriers over encrypted messaging services, using voice calls, text messages, and audio notes, and told couriers what false names and fake receipts to use when appearing in person.

The control that would have stopped it

Encrypted messaging traffic between dispatchers and couriers is hard to intercept at the technical layer, so the more practical control is stopping the fraud earlier at the call itself (Stage 3 or 4) or later at the physical cash handoff (Stage 6), rather than monitoring courier-dispatch communications.

6Cash extraction at the victim
What happened

Couriers collected cash directly from victims' homes, sometimes issuing fake receipts, or victims mailed cash via USPS or private carriers to addresses the couriers controlled, completing the physical handoff of funds.

The control that would have stopped it

Train postal and parcel-carrier staff, and encourage banks, to flag elderly customers withdrawing large cash sums or mailing cash-filled packages under apparent pressure, and encourage the public to simply refuse in-person cash handoffs to unverified couriers.

7Layering and repatriation of proceeds
What happened

Per the indictment's money-laundering conspiracy count, couriers delivered the cash to US-based money collectors, who then moved the funds toward the Dominican Republic via wire transfers and bulk cash transfers, obscuring the source and letting the organizers profit, completing the scheme's financial objective.

The control that would have stopped it

Financial institutions can apply anti-money-laundering monitoring for rapid bulk cash consolidation and outbound wire patterns consistent with fraud proceeds, and law enforcement can pursue extradition treaties and multi-agency cooperation, as DOJ's Office of International Affairs, the US Marshals Service, HSI, SSA-OIG, the FBI, and NYPD did here, to reach organizers once proceeds are traced.

Quick Facts
Victim
Hundreds of elderly US residents, concentrated in New Jersey, New York, Pennsylvania, and Massachusetts; nine victims specifically identified in the indictment
(Victims 1-9, mostly New Jersey, one Pennsylvania)
Location
Call centers in Santiago de los Caballeros, Dominican Republic
; victims and courier pickups in New Jersey, New York, Pennsylvania, and Massachusetts, USA
Date
Conspiracy charged (Count One, Mail and Wire Fraud Conspiracy) as operating from at least January 2019 through December 2023, per the indictment's own charging language; the money-laundering conspiracy (Count Seventeen) is charged over the same January 2019-December 2023 window.
Specific overt acts underlying the wire/mail fraud counts (Counts 2-16) that were reviewed run from May 2021 through June 2022, a narrower slice within the charged conspiracy period. 19-count indictment filed in D.N.J. 2024-01-04, unsealed 2024-04-29; DOJ announced charges 2024-04-30; ongoing prosecution through 2024-2025 with extraditions and a guilty plea. Note: the separately charged courier case against Victor Valdez covers roughly August 2020-August 2021, and that window belongs to Valdez's individual courier conduct only and should not be read as the main scheme's charged period.
Impact
DOJ states the scheme defrauded "hundreds" of elderly Americans of "millions of dollars" in aggregate.
But no exact total-loss figure or victim-by-victim damages table is disclosed in the public charging documents reviewed. In a related but distinct case, courier Victor Valdez is alleged to have collected cash from victims over roughly August 2020-August 2021, with individual pickups described in the tens of thousands of dollars in some instances; that figure and window belong to Valdez's case, not an audited total for the main 11-defendant scheme. On the money-laundering counts specifically: Count Seventeen (money-laundering conspiracy, 18 U.S.C. § 1956(h)) alleges, as one of three alternative theories of the conspiracy, that conspirators engaged in monetary transactions in criminally derived property valued at more than $10,000, in violation of 18 U.S.C. § 1957(a), but that $10,000 threshold attaches to Count Seventeen's Section 1957(a) object clause, not to the substantive money-laundering Counts Eighteen and Nineteen, which are charged under 18 U.S.C. § 1956(a)(1)(B)(i) and do not carry a stated dollar threshold in the charging language. Count Eighteen concerns cash taken from Victim 5 (Williamstown, NJ) and Count Nineteen concerns cash taken from Victim 9 (Paterson, NJ), per the indictment, though the specific dollar amounts of those individual transactions are not stated in the portions of the charging documents reviewed. Figures beyond "hundreds of victims" / "millions of dollars" should be treated as DOJ's characterization, not an audited total.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public
Threat Actor
Organized Crime
Explore more

Related Cases

Browse by what this case has in common with others in the library.

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…

Incident 2024Read →

Fake AnyDesk Installer to MetaStealer: FileFix/search-ms Variant of ClickFix

A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.

Incident 2025Read →

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…

Incident 2026Read →

P&G's 'Bad Hair Day': Dumpster-Diving Corporate Espionage on Unilever's Hair-Care Business

P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.

Incident 2000Read →

OpenAI's "ScopeCreep": Russian-Speaking Actor Used Disposable ChatGPT Accounts to Build C2-Enabled Windows Malware Distributed via a Trojanized "Crosshair-X" Gaming Tool

A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.

Incident 2025Read →

Fake ChatGPT Download Site (openew[.]app): SEO Poisoning, Malvertising, and an AI-Generated chatgpt.com Redirect Deliver Cross-Platform Infostealers with Wallet-Swap Payload

A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a…

Incident 2026Read →

ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain

Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.

Incident 2025Read →

Caesars Entertainment Vendor Social Engineering Breach (2023)

The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…

Incident 2023Read →

KnowBe4 Unknowingly Hires a North Korean Fake IT Worker Using an AI-Enhanced Photo and Stolen Identity

KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…

Incident 2024Read →

Southern California Edison Utility Disconnection Threat Scam (2025)

Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…

Incident 2024Read →

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.

Incident 2013Read →

EDVA Court-Authorized Seizure of Seven Spoofed SIMEX/SGX Domains Used in Pig-Butchering Scheme

A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.

Incident 2022Read →