Case Library / Smishing (SMS Phishing) / EDVA Court-Authorized Seizure of Seven Spoofed SIMEX/SGX Domains Used in Pig-Butchering Scheme

EDVA Court-Authorized Seizure of Seven Spoofed SIMEX/SGX Domains Used in Pig-Butchering Scheme

A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used to defraud five US victims of over $10 million after grooming them via dating apps, social media, and messaging platforms.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between at least May and August 2022, an organized cryptocurrency fraud operation contacted five US-based victims through dating apps, social media, and unsolicited "wrong number" text messages, then spent weeks building personal or romantic rapport before pitching a cryptocurrency investment opportunity. Victims were directed to install investment apps and deposit crypto through seven websites built to impersonate the Singapore International Monetary Exchange (SIMEX), a real historical exchange that merged into the Singapore Exchange (SGX) in 1999 and, per SGX's own public statement, has never operated any such crypto trading platform. Victims collectively transferred more than $10 million into scammer-controlled deposit addresses; one victim alone sent roughly $9.6 million in USDC after starting with a token $400 deposit. Funds were immediately routed through numerous private wallets and cryptocurrency swap services to obscure their origin. On November 21, 2022, the US Attorney's Office for the Eastern District of Virginia announced that a federal court had authorized seizure of the seven domains (simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, simexwim.com), reported as the first US federal action specifically targeting pig-butchering scam infrastructure. The case was later cited by FinCEN as a named case study in its September 2023 pig-butchering alert (FIN-2023-Alert005).

How the Attack Worked

Beginning at least May 2022, scammers first made contact with victims through dating apps, social media, or unsolicited text messages (including the classic "wrong number" opener), then spent time building a personal relationship or friendship before introducing a supposedly lucrative cryptocurrency investment opportunity. Contact and relationship-building for at least one victim continued over LINE and WeChat. Once trust was established, victims were directed to one of seven domains built to impersonate the Singapore International Monetary Exchange (SIMEX/SGX): simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, and simexwim.com, where they were induced to install a fake trading app and deposit funds (in one case starting with as little as $400). Believing they were investing through a legitimate, regulated exchange, victims sent cryptocurrency (USDC and others) to deposit addresses supplied by the scammers. As soon as funds landed in scammer-controlled addresses, the money was immediately layered through numerous private wallets and cryptocurrency "swapping" (mixing/exchange) services specifically to break the on-chain trail and frustrate tracing.

The Lure & the Tell

Lure: an online "friend," romantic interest, or accidental contact who, after weeks of relationship-building, reveals access to a lucrative crypto trading opportunity through what looks like a real, internationally recognized exchange (borrowing the credibility of the historic Singapore International Monetary Exchange / SGX brand). Tell: the platform was a domain no legitimate exchange operates (SGX confirmed post-merger it never ran any such crypto platform and does not accept investor funds directly); victims who tried to withdraw large sums were blocked or asked for further payments, while small "trust-building" withdrawals were permitted, a classic pig-butchering pattern flagged in DFPI's parallel California consumer alert on the same SIMEX impersonation.

Outcome

On November 21, 2022, the US Attorney's Office for the Eastern District of Virginia announced that a federal court had authorized the civil in rem seizure of the seven spoofed SIMEX domains, taking the infrastructure offline/under government control. This was reported as the first US federal law-enforcement action specifically targeting pig-butchering scam infrastructure. No individual defendants were publicly named or indicted in this action; it proceeded as a domain/asset forfeiture matter against the property (the domains) rather than a criminal prosecution of identified perpetrators, consistent with how many pig-butchering operations run out of reach of US jurisdiction (organized crime networks then understood to be largely Southeast-Asia based). DOJ's press release solicited additional victims to come forward with website URLs, phone numbers, email accounts, social media profiles, and cryptocurrency transaction details. The case was subsequently cited by FinCEN as a named case study in its September 8, 2023 alert (FIN-2023-Alert005) on pig-butchering scams.

Why It Matters

This is a benchmark case in the US government's public response to pig-butchering fraud: the first federal domain-seizure action specifically aimed at this scam type, occurring roughly a year before FinCEN issued formal nationwide guidance and years before major DOJ/Treasury actions against Southeast Asian scam-compound networks (e.g., Prince Group, Huione). It illustrates how the scam brand-jacks a real, historically legitimate financial institution (SIMEX/SGX) to lend false authority, how romance/friendship grooming over ordinary consumer messaging apps (not sophisticated technical exploits) is the actual attack vector, and how quickly stolen crypto is laundered through wallet-hopping before any recovery is possible, which is why FinCEN's alert emphasizes financial-institution SAR reporting as an early-warning mechanism.

Defenses

FinCEN's alert (and consistent DOJ/FBI guidance) recommends: verify any investment platform against the real regulated entity it claims to be (SGX Group publicly stated it never merged into or operated any crypto platform under the "SIMEX" name and does not accept investor funds directly); treat unsolicited relationship-building from strangers met via dating apps/social media/wrong-number texts that pivots to a crypto "opportunity" as a red flag; be suspicious of platforms that allow small test withdrawals but block large ones, or that demand extra "tax"/"fee" payments to unlock a withdrawal; avoid installing investment apps/configuration profiles pushed by an online contact outside official app stores; financial institutions should watch for the specific red flags enumerated in FinCEN's alert and file SARs referencing key term "FIN-2023-PIGBUTCHERING." Domain-seizure actions like this one also depend on victims reporting website URLs, phone numbers, social media handles, and transaction hashes to law enforcement (DOJ solicited such reports via a dedicated email in the press release).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Infrastructure setup: The fraud network is documented (per DOJ and DFPI) as having registered a batch of look-alike domains (simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, simexwim.com, plus at least four more named in DFPI's parallel alert) spoofing the historic Singapore International Monetary Exchange brand, and building a fake trading app/site layer capable of showing fabricated deposit balances and 'trading profit' notifications after each deposit.
Countering Stage 1: Brand-monitoring and domain-watch services that scan new registrations for look-alike variants of a known financial brand (as SIMEX/SGX's actual name was here) can flag spoof domains for takedown before they see victim traffic; this is also the stage law enforcement itself targets, since seizing the domains was this case's actual remedy.
2
Victim sourcing and initial contact: Operators are documented as reaching a broad pool of prospective victims through dating apps, social media, and unsolicited 'wrong number' SMS texts, a mass-outreach approach typical of pig-butchering rings that then filters for individuals who engage.
Countering Stage 2: Unsolicited contact via dating apps, social platforms, and 'wrong number' texts is very hard to block at the platform level without curbing legitimate use; the realistic control is consumer-facing education treating any unsolicited relationship overture from a stranger as inherently unverified, and platform reporting tools for suspected scam accounts.
3
Trust-building (grooming): Per DOJ and BleepingComputer, scammers spent weeks cultivating a personal or romantic relationship before any financial pitch, in at least one case moving the conversation to LINE and WeChat, consistent with the broader pattern of using intimate messaging apps to deepen rapport away from the platform where contact began.
Countering Stage 3: Grooming conversations happen in private messaging and are largely invisible to any outside control; the nearest practical lever is dating/social platforms flagging rapid migration of a new contact to an external messaging app (LINE, WeChat) as a known scam behavior pattern, paired with consumer education on the romance-to-investment pivot as a textbook red flag.
4
Pitch and platform introduction: Once trust was established, the scammer introduced a supposedly lucrative cryptocurrency investment opportunity and directed the victim to one of the spoofed SIMEX/SGX domains, borrowing the credibility of a real, internationally recognized exchange brand to lower the victim's guard.
Countering Stage 4: Independently verify any investment platform against the real regulated entity it claims to be, exactly as SGX Group did on the record (confirming it operates no such crypto platform and never accepts investor funds directly), rather than trusting a brand name supplied by an online contact.
5
Graduated trust-building via small deposits and fabricated returns: Victims made an initial modest deposit (as little as $400 in one documented case) and were shown fabricated account growth and trading-profit alerts in the fake app; DFPI's parallel alert documents scammers permitting small test withdrawals ($100 to $2,500) specifically to reinforce the illusion of a legitimate, liquid platform.
Countering Stage 5: Treat platforms that permit only small test withdrawals as a specific red flag rather than reassurance, and avoid installing investment apps or configuration profiles pushed by an online contact outside official app stores, per FinCEN and FBI guidance.
6
Escalation and fund extraction: Believing the platform was real and profitable, victims were persuaded to transfer increasingly large sums, in one case up to roughly $9.6 million in USDC, to deposit addresses supplied by the scammers; DFPI's alert separately documents a victim pressured to deposit retirement (401(k)) savings.
Countering Stage 6: Financial institutions and exchanges can apply transaction monitoring for accelerating outbound crypto transfers to a single previously-unseen address following an initial small deposit, and impose friction (warnings, cooling-off periods) on large transfers consistent with FinCEN's enumerated red flags.
7
Withdrawal blocking and advance-fee extraction: When victims attempted to withdraw substantial sums, the scammers blocked the request or demanded further 'tax,' 'fee,' or 'security deposit' payments framed as necessary to unlock the funds, a classic advance-fee pattern documented by both DOJ and DFPI.
Countering Stage 7: Any demand for an upfront 'tax,' 'fee,' or 'security deposit' to release a withdrawal is a definitive scam indicator per FinCEN and FBI guidance; consumers and institutions should treat this as a hard stop rather than a legitimate platform requirement.
8
Laundering and payout: Per the DOJ affidavit, funds landing in scammer-controlled addresses were immediately moved through numerous private wallets and cryptocurrency swapping/mixing services to break the on-chain trail, completing the theft before recovery was realistically possible.
Countering Stage 8: Wallet-hopping and swap-service laundering happens within minutes, making real-time interdiction largely impractical; the realistic control is rapid victim and financial-institution reporting (SARs citing 'FIN-2023-PIGBUTCHERING,' IC3 complaints, and the URL/wallet-hash tips DOJ solicited) that feeds the kind of after-the-fact domain-seizure and asset-tracing action seen in this case.
Quick Facts
Victim
5 individual US-based victims (unnamed in the DOJ release)
Location
Victims located in the United States; case filed/adjudicated in the Eastern District of Virginia; impersonated entity (SIMEX) was historically based in Singapore (SIMEX merged into the Singapore Exchange, SGX, in 1999; SGX publicly stated it operates no such crypto platform and never authorized these sites).
Date
2022-05 through 2022-08 (fraud period); announced/seized 2022-11-21
Impact
Over $10 million combined losses across 5 US victims (reported regionally as roughly S$13.8 million). Documented detail on one victim: after being tricked in May 2022 into installing a fake investment app with an initial deposit of just $400, that victim went on to transfer approximately $9.6 million in USD Coin (USDC) to a scammer-controlled deposit address.
Status
Confirmed
Case Type
Real-World Incident
Sector
Cryptocurrency & Digital Assets
Threat Actor
Organized Crime
Related

Related Cases

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group…

Incident 2022Read →

Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)

A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam, then embezzled $47.1…

Incident 2022Read →

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…

Incident 2023Read →