A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
Social Engineering Examples·6 sources
Between at least May and August 2022, an organized cryptocurrency fraud operation contacted five US-based victims through dating apps, social media, and unsolicited "wrong number" text messages, then spent weeks building personal or romantic rapport before pitching a cryptocurrency investment opportunity. Victims were directed to install investment apps and deposit crypto through seven websites built to impersonate the Singapore International Monetary Exchange (SIMEX), a real historical exchange that merged into the Singapore Exchange (SGX) in 1999 and, per SGX's own public statement, has never operated any such crypto trading platform.
Victims collectively transferred more than $10 million into scammer-controlled deposit addresses; one victim alone sent roughly $9.6 million in USDC after starting with a token $400 deposit. Funds were immediately routed through numerous private wallets and cryptocurrency swap services to obscure their origin. On November 21, 2022, the US Attorney's Office for the Eastern District of Virginia announced that a federal court had authorized seizure of the seven domains (simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, simexwim.com), reported as the first US federal action specifically targeting pig-butchering scam infrastructure.
The case was later cited by FinCEN as a named case study in its September 2023 pig-butchering alert (FIN-2023-Alert005).
Beginning at least May 2022, scammers first made contact with victims through dating apps, social media, or unsolicited text messages (including the classic "wrong number" opener), then spent time building a personal relationship or friendship before introducing a supposedly lucrative cryptocurrency investment opportunity. Contact and relationship-building for at least one victim continued over LINE and WeChat.
Once trust was established, victims were directed to one of seven domains built to impersonate the Singapore International Monetary Exchange (SIMEX/SGX): simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, and simexwim.com, where they were induced to install a fake trading app and deposit funds (in one case starting with as little as $400).
Believing they were investing through a legitimate, regulated exchange, victims sent cryptocurrency (USDC and others) to deposit addresses supplied by the scammers. As soon as funds landed in scammer-controlled addresses, the money was immediately layered through numerous private wallets and cryptocurrency "swapping" (mixing/exchange) services specifically to break the on-chain trail and frustrate tracing.
Lure: an online "friend," romantic interest, or accidental contact who, after weeks of relationship-building, reveals access to a lucrative crypto trading opportunity through what looks like a real, internationally recognized exchange (borrowing the credibility of the historic Singapore International Monetary Exchange / SGX brand). Tell: the platform was a domain no legitimate exchange operates (SGX confirmed post-merger it never ran any such crypto platform and does not accept investor funds directly); victims who tried to withdraw large sums were blocked or asked for further payments, while small "trust-building" withdrawals were permitted, a classic pig-butchering pattern flagged in DFPI's parallel California consumer alert on the same SIMEX impersonation.
On November 21, 2022, the US Attorney's Office for the Eastern District of Virginia announced that a federal court had authorized the civil in rem seizure of the seven spoofed SIMEX domains, taking the infrastructure offline/under government control. This was reported as the first US federal law-enforcement action specifically targeting pig-butchering scam infrastructure.
No individual defendants were publicly named or indicted in this action; it proceeded as a domain/asset forfeiture matter against the property (the domains) rather than a criminal prosecution of identified perpetrators, consistent with how many pig-butchering operations run out of reach of US jurisdiction (organized crime networks then understood to be largely Southeast-Asia based).
DOJ's press release solicited additional victims to come forward with website URLs, phone numbers, email accounts, social media profiles, and cryptocurrency transaction details. The case was subsequently cited by FinCEN as a named case study in its September 8, 2023 alert (FIN-2023-Alert005) on pig-butchering scams.
This is a benchmark case in the US government's public response to pig-butchering fraud: the first federal domain-seizure action specifically aimed at this scam type, occurring roughly a year before FinCEN issued formal nationwide guidance and years before major DOJ/Treasury actions against Southeast Asian scam-compound networks (e.g., Prince Group, Huione).
It illustrates how the scam brand-jacks a real, historically legitimate financial institution (SIMEX/SGX) to lend false authority, how romance/friendship grooming over ordinary consumer messaging apps (not sophisticated technical exploits) is the actual attack vector, and how quickly stolen crypto is laundered through wallet-hopping before any recovery is possible, which is why FinCEN's alert emphasizes financial-institution SAR reporting as an early-warning mechanism.
FinCEN's alert (and consistent DOJ/FBI guidance) recommends: verify any investment platform against the real regulated entity it claims to be (SGX Group publicly stated it never merged into or operated any crypto platform under the "SIMEX" name and does not accept investor funds directly); treat unsolicited relationship-building from strangers met via dating apps/social media/wrong-number texts that pivots to a crypto "opportunity" as a red flag; be suspicious of platforms that allow small test withdrawals but block large ones, or that demand extra "tax"/"fee" payments to unlock a withdrawal; avoid installing investment apps/configuration profiles pushed by an online contact outside official app stores; financial institutions should watch for the specific red flags enumerated in FinCEN's alert and file SARs referencing key term "FIN-2023-PIGBUTCHERING." Domain-seizure actions like this one also depend on victims reporting website URLs, phone numbers, social media handles, and transaction hashes to law enforcement (DOJ solicited such reports via a dedicated email in the press release).
Social Engineering Examples. “EDVA Court-Authorized Seizure of Seven Spoofed SIMEX/SGX Domains Used in Pig-Butchering Scheme”. Accessed 19 September 2026. https://socialengineeringexamples.com/edva-simex-domain-seizure-pig-butchering-2022
The fraud network is documented (per DOJ and DFPI) as having registered a batch of look-alike domains (simexarts.com, simexbiz.com, simexcbr.com, simexlua.com, simexrue.com, simexvtn.com, simexwim.com, plus at least four more named in DFPI's parallel alert) spoofing the historic Singapore International Monetary Exchange brand, and building a fake trading app/site layer capable of showing fabricated deposit balances and 'trading profit' notifications after each deposit.
Brand-monitoring and domain-watch services that scan new registrations for look-alike variants of a known financial brand (as SIMEX/SGX's actual name was here) can flag spoof domains for takedown before they see victim traffic; this is also the stage law enforcement itself targets, since seizing the domains was this case's actual remedy.
Operators are documented as reaching a broad pool of prospective victims through dating apps, social media, and unsolicited 'wrong number' SMS texts, a mass-outreach approach typical of pig-butchering rings that then filters for individuals who engage.
Unsolicited contact via dating apps, social platforms, and 'wrong number' texts is very hard to block at the platform level without curbing legitimate use; the realistic control is consumer-facing education treating any unsolicited relationship overture from a stranger as inherently unverified, and platform reporting tools for suspected scam accounts.
Per DOJ and BleepingComputer, scammers spent weeks cultivating a personal or romantic relationship before any financial pitch, in at least one case moving the conversation to LINE and WeChat, consistent with the broader pattern of using intimate messaging apps to deepen rapport away from the platform where contact began.
Grooming conversations happen in private messaging and are largely invisible to any outside control; the nearest practical lever is dating/social platforms flagging rapid migration of a new contact to an external messaging app (LINE, WeChat) as a known scam behavior pattern, paired with consumer education on the romance-to-investment pivot as a textbook red flag.
Once trust was established, the scammer introduced a supposedly lucrative cryptocurrency investment opportunity and directed the victim to one of the spoofed SIMEX/SGX domains, borrowing the credibility of a real, internationally recognized exchange brand to lower the victim's guard.
Independently verify any investment platform against the real regulated entity it claims to be, exactly as SGX Group did on the record (confirming it operates no such crypto platform and never accepts investor funds directly), rather than trusting a brand name supplied by an online contact.
Victims made an initial modest deposit (as little as $400 in one documented case) and were shown fabricated account growth and trading-profit alerts in the fake app; DFPI's parallel alert documents scammers permitting small test withdrawals ($100 to $2,500) specifically to reinforce the illusion of a legitimate, liquid platform.
Treat platforms that permit only small test withdrawals as a specific red flag rather than reassurance, and avoid installing investment apps or configuration profiles pushed by an online contact outside official app stores, per FinCEN and FBI guidance.
Believing the platform was real and profitable, victims were persuaded to transfer increasingly large sums, in one case up to roughly $9.6 million in USDC, to deposit addresses supplied by the scammers; DFPI's alert separately documents a victim pressured to deposit retirement (401(k)) savings.
Financial institutions and exchanges can apply transaction monitoring for accelerating outbound crypto transfers to a single previously-unseen address following an initial small deposit, and impose friction (warnings, cooling-off periods) on large transfers consistent with FinCEN's enumerated red flags.
When victims attempted to withdraw substantial sums, the scammers blocked the request or demanded further 'tax,' 'fee,' or 'security deposit' payments framed as necessary to unlock the funds, a classic advance-fee pattern documented by both DOJ and DFPI.
Any demand for an upfront 'tax,' 'fee,' or 'security deposit' to release a withdrawal is a definitive scam indicator per FinCEN and FBI guidance; consumers and institutions should treat this as a hard stop rather than a legitimate platform requirement.
Per the DOJ affidavit, funds landing in scammer-controlled addresses were immediately moved through numerous private wallets and cryptocurrency swapping/mixing services to break the on-chain trail, completing the theft before recovery was realistically possible.
Wallet-hopping and swap-service laundering happens within minutes, making real-time interdiction largely impractical; the realistic control is rapid victim and financial-institution reporting (SARs citing 'FIN-2023-PIGBUTCHERING,' IC3 complaints, and the URL/wallet-hash tips DOJ solicited) that feeds the kind of after-the-fact domain-seizure and asset-tracing action seen in this case.
Browse by what this case has in common with others in the library.
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
Binance CCO Patrick Hillmann claimed scammers built an AI deepfake "hologram" of him from his TV interview footage and used…
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP…
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.