A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
Social Engineering Examples·5 sources
On January 4, 2024, a federal grand jury in the District of New Jersey returned a 19-count indictment (unsealed April 29, 2024, in United States v. Juan Rafael Parra Arias, et al., No. 2:24-cr-00006) charging 11 Dominican nationals with mail fraud, wire fraud, mail/wire fraud conspiracy, money-laundering conspiracy, and money laundering for operating a long-running "grandparent" or "family-in-need-of-bail" scam out of call centers in Santiago de los Caballeros, Dominican Republic.
Five additional US-based defendants were charged by complaint with wire fraud conspiracy as couriers who physically collected cash from victims. DOJ announced the 16 total charges on April 30, 2024, describing the scheme as defrauding hundreds of elderly Americans across New Jersey, New York, Pennsylvania, and Massachusetts out of millions of dollars.
A related, separately charged US-based courier, Victor Anthony Valdez, a former Social Security Administration claims specialist, was indicted in June 2024 and pleaded guilty to wire fraud conspiracy in December 2024, illustrating the same courier role used in the broader scheme.
The fraud used a layered, role-divided pretexting structure run like a call-center operation. "Openers" placed the first calls impersonating the elderly victim's grandchild (or another close relative), claiming to have been arrested, often after a car accident, sometimes adding a detail such as a pregnant companion having miscarried, to maximize panic and urgency.
Once the victim was emotionally hooked, "closers" took over the call posing as defense attorneys, police officers, or court personnel, instructing the victim that cash was needed immediately for bail, fines, or legal fees, and telling victims to keep the matter secret from other family members to avoid the grandchild getting into "more trouble." Dispatchers in the Dominican Republic then directed US-based couriers, via messaging apps and phone/text, to specific victims' homes, giving them the victim's name, address, the amount to collect, and even the false names to use when impersonating attorneys or court staff in person.
Couriers picked up cash at victims' doorsteps (sometimes issuing fake receipts) or received cash mailed via USPS or private carriers to drop addresses, then moved the money back into the network, generating the wire/mail fraud and money-laundering counts in the indictment.
The lure combined a plausible family emergency (arrest, car accident, needing bail) with escalating authority figures (grandchild, then "attorney," then "police"/"court personnel") and an explicit secrecy instruction that isolated the victim from anyone who could break the spell by contacting the real grandchild. The tell, in retrospect, was structural: legitimate bail and court processes never move through unsolicited phone calls demanding cash handed to an unannounced courier at the victim's home, never ask for secrecy from family, and never route payment through private couriers or mailed cash rather than official court/bail channels.
Sixteen defendants were charged (11 by indictment, 5 by complaint). Two Dominican nationals, Rafael Ambiorix Rodriguez Guzman ("Max Morgan") and Felix Samuel Reynoso Ventura ("Fili"/"Filly The Kid"), were extradited from the Dominican Republic and made their initial appearance in Newark federal court on July 22, 2024, and were detained pending trial.
Three more, alleged ringleader Juan Rafael Parra Arias, Miguel Angel Vasquez, and Jose Ismael Dilone Rodriguez, were extradited and appeared in Newark on August 5, 2024, also detained pending trial. Extraditions were secured with assistance from DOJ's Office of International Affairs, the US Marshals Service, HSI, SSA-OIG, NYPD, the FBI, and cooperation from the Dominican government under the US-DR extradition treaty.
In a related case, US-based courier Victor Anthony Valdez pleaded guilty to wire fraud conspiracy on December 5, 2024, before Judge Claire C. Cecchi in Newark, with sentencing scheduled for April 9, 2025; he faced a statutory maximum of 20 years and a $250,000 fine. As of the public record reviewed, the case against the main indicted defendants remains in pretrial proceedings, with charges (not final convictions) carrying up to 20 years per count and fines up to $250,000 (fraud counts) or $500,000 (money-laundering counts) if convicted; defendants are presumed innocent unless and until proven guilty.
This case is a rare, fully documented, DOJ-charged example of the classic "grandparent scam" escalated into an industrialized, role-specialized transnational operation, with distinct opener, closer, dispatcher, and courier functions spanning a foreign call-center hub and a US-based logistics network, rather than a single opportunistic caller. It shows how pretexting chains multiple impersonated authority figures (family member, then attorney, then police/court) to keep an elderly victim compliant long enough to physically hand cash to a stranger, and how extradition treaties and multi-agency cooperation (DOJ OIA, US Marshals, HSI, SSA-OIG, FBI, NYPD) can eventually reach offshore organizers.
DOJ, FBI, and elder-fraud advocates recommend: never act on an unsolicited call claiming a relative is arrested or hospitalized without independently calling that relative or another family member back on a known number; treat any demand for secrecy as a red flag rather than a reason to comply; know that legitimate bail, court, or attorney processes do not collect cash via unannounced in-person couriers, wired retail gift cards, or mailed cash to third-party addresses; establish a family safe word/code phrase in advance for genuine emergencies; and financial institutions/postal and shipping carriers should train staff to flag elderly customers withdrawing large cash sums or mailing cash-filled packages under pressure, since those chokepoints intersected with this scheme's mail and wire fraud counts.
Social Engineering Examples. “Dominican Republic "Grandparent Scam" - Attorney/Police Impersonation Ring (D.N.J. Indictment)”. Accessed 19 September 2026. https://socialengineeringexamples.com/dominican-republic-grandparent-scam-attorney-police-impersonation-2024
The indictment does not detail how victims were first identified, but a call-center operation dialing hundreds of specific elderly Americans by name and address is consistent with typical grandparent-scam tradecraft of buying bulk lead lists from data brokers, prior breach/leak dumps, or robocall-harvested number pools, rather than random dialing.
Which specific elderly individuals end up on a scam call list is largely outside any single defender's control given the breadth of data-broker and breach-derived contact lists in circulation; the realistic control sits downstream, at the moment the phone actually rings, rather than at list-sourcing.
Per the indictment, defendant Nelson Rafael Gonzalez Acevedo and others procured voice-over-internet-protocol telephone services specifically to mask that calls originated in the Dominican Republic and to spoof caller-ID data so calls appeared to come from within the United States, a low-cost, commercially available technique rather than custom-built tooling.
Telecom carriers and regulators can enforce STIR/SHAKEN caller-ID authentication standards and flag or block inbound VOIP traffic that falsely presents foreign calls as originating domestically, making the spoofing step harder to pull off convincingly.
'Openers' at the call centers phoned elderly victims and impersonated a grandchild or other close relative, typically claiming to have been arrested after a car accident, sometimes adding a detail such as a pregnant companion having miscarried, to maximize panic before any request for money was made.
Families should adopt a habit, ideally agreed in advance, of hanging up on any unsolicited call claiming a relative is arrested or hospitalized and independently calling that relative or another family member back on a known number before reacting.
Once the victim was emotionally hooked, 'closers' took over the call posing as defense attorneys, police officers, or court personnel, demanded cash for bail or fees, and instructed the victim to keep the matter secret from other family members, isolating the victim from anyone who could break the pretext.
Teach that legitimate attorneys, police, and courts never demand cash for bail or fees over the phone from a third party and never instruct secrecy from family; both are definitional tells that should end the call immediately.
Conspirators in the Dominican Republic relayed the victim's name, address, and the amount to collect to US-based couriers over encrypted messaging services, using voice calls, text messages, and audio notes, and told couriers what false names and fake receipts to use when appearing in person.
Encrypted messaging traffic between dispatchers and couriers is hard to intercept at the technical layer, so the more practical control is stopping the fraud earlier at the call itself (Stage 3 or 4) or later at the physical cash handoff (Stage 6), rather than monitoring courier-dispatch communications.
Couriers collected cash directly from victims' homes, sometimes issuing fake receipts, or victims mailed cash via USPS or private carriers to addresses the couriers controlled, completing the physical handoff of funds.
Train postal and parcel-carrier staff, and encourage banks, to flag elderly customers withdrawing large cash sums or mailing cash-filled packages under apparent pressure, and encourage the public to simply refuse in-person cash handoffs to unverified couriers.
Per the indictment's money-laundering conspiracy count, couriers delivered the cash to US-based money collectors, who then moved the funds toward the Dominican Republic via wire transfers and bulk cash transfers, obscuring the source and letting the organizers profit, completing the scheme's financial objective.
Financial institutions can apply anti-money-laundering monitoring for rapid bulk cash consolidation and outbound wire patterns consistent with fraud proceeds, and law enforcement can pursue extradition treaties and multi-agency cooperation, as DOJ's Office of International Affairs, the US Marshals Service, HSI, SSA-OIG, the FBI, and NYPD did here, to reach organizers once proceeds are traced.
Browse by what this case has in common with others in the library.
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.
A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a…
Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
A retired 60-year-old Malaysian bank manager in Johor Baru lost RM936,000 (life savings) after a Macau-scam vishing syndicate posing successively.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.