A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used to defraud five US victims of over $10 million after grooming them via dating apps, social media, and messaging platforms.
Reviewed by the Social Engineering Examples team.
Between at least May and August 2022, an organized cryptocurrency fraud operation contacted five US-based victims through dating apps, social media, and unsolicited "wrong number" text messages, then spent weeks building personal or romantic rapport before pitching a cryptocurrency investment opportunity. Victims were directed to install investment apps and deposit crypto through seven websites built to impersonate the Singapore International Monetary Exchange (SIMEX), a real historical exchange that merged into the Singapore Exchange (SGX) in 1999 and, per SGX's own public statement, has never operated any such crypto trading platform. Victims collectively transferred more than $10 million into scammer-controlled deposit addresses; one victim alone sent roughly $9.6 million in USDC after starting with a token $400 deposit. Funds were immediately routed through numerous private wallets and cryptocurrency swap services to obscure their origin. On November 21, 2022, the US Attorney's Office for the Eastern District of Virginia announced that a federal court had authorized seizure of the seven domains (simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, simexwim.com), reported as the first US federal action specifically targeting pig-butchering scam infrastructure. The case was later cited by FinCEN as a named case study in its September 2023 pig-butchering alert (FIN-2023-Alert005).
Beginning at least May 2022, scammers first made contact with victims through dating apps, social media, or unsolicited text messages (including the classic "wrong number" opener), then spent time building a personal relationship or friendship before introducing a supposedly lucrative cryptocurrency investment opportunity. Contact and relationship-building for at least one victim continued over LINE and WeChat. Once trust was established, victims were directed to one of seven domains built to impersonate the Singapore International Monetary Exchange (SIMEX/SGX): simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, and simexwim.com, where they were induced to install a fake trading app and deposit funds (in one case starting with as little as $400). Believing they were investing through a legitimate, regulated exchange, victims sent cryptocurrency (USDC and others) to deposit addresses supplied by the scammers. As soon as funds landed in scammer-controlled addresses, the money was immediately layered through numerous private wallets and cryptocurrency "swapping" (mixing/exchange) services specifically to break the on-chain trail and frustrate tracing.
Lure: an online "friend," romantic interest, or accidental contact who, after weeks of relationship-building, reveals access to a lucrative crypto trading opportunity through what looks like a real, internationally recognized exchange (borrowing the credibility of the historic Singapore International Monetary Exchange / SGX brand). Tell: the platform was a domain no legitimate exchange operates (SGX confirmed post-merger it never ran any such crypto platform and does not accept investor funds directly); victims who tried to withdraw large sums were blocked or asked for further payments, while small "trust-building" withdrawals were permitted, a classic pig-butchering pattern flagged in DFPI's parallel California consumer alert on the same SIMEX impersonation.
On November 21, 2022, the US Attorney's Office for the Eastern District of Virginia announced that a federal court had authorized the civil in rem seizure of the seven spoofed SIMEX domains, taking the infrastructure offline/under government control. This was reported as the first US federal law-enforcement action specifically targeting pig-butchering scam infrastructure. No individual defendants were publicly named or indicted in this action; it proceeded as a domain/asset forfeiture matter against the property (the domains) rather than a criminal prosecution of identified perpetrators, consistent with how many pig-butchering operations run out of reach of US jurisdiction (organized crime networks then understood to be largely Southeast-Asia based). DOJ's press release solicited additional victims to come forward with website URLs, phone numbers, email accounts, social media profiles, and cryptocurrency transaction details. The case was subsequently cited by FinCEN as a named case study in its September 8, 2023 alert (FIN-2023-Alert005) on pig-butchering scams.
This is a benchmark case in the US government's public response to pig-butchering fraud: the first federal domain-seizure action specifically aimed at this scam type, occurring roughly a year before FinCEN issued formal nationwide guidance and years before major DOJ/Treasury actions against Southeast Asian scam-compound networks (e.g., Prince Group, Huione). It illustrates how the scam brand-jacks a real, historically legitimate financial institution (SIMEX/SGX) to lend false authority, how romance/friendship grooming over ordinary consumer messaging apps (not sophisticated technical exploits) is the actual attack vector, and how quickly stolen crypto is laundered through wallet-hopping before any recovery is possible, which is why FinCEN's alert emphasizes financial-institution SAR reporting as an early-warning mechanism.
FinCEN's alert (and consistent DOJ/FBI guidance) recommends: verify any investment platform against the real regulated entity it claims to be (SGX Group publicly stated it never merged into or operated any crypto platform under the "SIMEX" name and does not accept investor funds directly); treat unsolicited relationship-building from strangers met via dating apps/social media/wrong-number texts that pivots to a crypto "opportunity" as a red flag; be suspicious of platforms that allow small test withdrawals but block large ones, or that demand extra "tax"/"fee" payments to unlock a withdrawal; avoid installing investment apps/configuration profiles pushed by an online contact outside official app stores; financial institutions should watch for the specific red flags enumerated in FinCEN's alert and file SARs referencing key term "FIN-2023-PIGBUTCHERING." Domain-seizure actions like this one also depend on victims reporting website URLs, phone numbers, social media handles, and transaction hashes to law enforcement (DOJ solicited such reports via a dedicated email in the press release).
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group…
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam, then embezzled $47.1…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…