Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes prizes.
Social Engineering Examples·4 sources
Roger Roger led a fraudulent telemarketing scheme run out of a call center in Costa Rica that, over a period of years (indictment unsealed October 2, 2018), defrauded hundreds of victims across the United States, most of them elderly, out of more than $4 million. Co-conspirators impersonated U.S. government officials over the phone, falsely telling victims they had won a substantial sweepstakes prize, then demanded a series of up-front payments (framed as taxes, customs duties, and fees) before victims could supposedly collect.
Calls were routed through VOIP technology to spoof caller ID so they appeared to originate from Washington, D.C. and other U.S. locations, concealing the Costa Rica origin. Roger was arrested and extradited from Costa Rica in February 2023. A federal jury in the Western District of North Carolina convicted him on September 20, 2024 on fraud and international money-laundering conspiracy charges.
He was sentenced on July 15, 2025 to more than 15 years in prison, with more than $3.3 million in restitution and more than $4.2 million in forfeiture ordered.
Roger Roger operated a telemarketing fraud call center in Costa Rica. Co-conspirators falsely posed as U.S. government officials and called victims in the U.S. to tell them they had won a substantial "sweepstakes" prize. To conceal their true identities and location, the conspirators used Voice over Internet Protocol (VOIP) technology to spoof caller ID so calls appeared to originate from Washington, D.C. and other U.S. locations rather than Costa Rica.
Roger personally called victims using fake names and fabricated documents to reinforce the sweepstakes-winner pretext. After convincing victims, many of them elderly, that they stood to receive a large financial reward, the callers told victims they first had to make a series of up-front payments, characterized as taxes, customs duties, insurance, and other fees, before the "prize" could be released.
Once a victim paid, conspirators (acting as "loaders") would re-contact them claiming a problem had arisen or the prize was even larger, prompting additional rounds of payment. Payments were extracted via wire transfers, Western Union/MoneyGram transfers, and blank money orders shipped by courier; some victims who refused to send funds directly overseas were directed to send money to U.S.-based co-conspirators who then forwarded it to Costa Rica.
Roger recruited and trained other co-conspirators to run this script and to move victim payments from the U.S. to Costa Rica. No prize ever existed.
Lure: an unsolicited phone call from someone claiming to be a U.S. government official informing the victim they had won a substantial cash "sweepstakes" prize, using a spoofed VOIP caller ID displaying a Washington, D.C. (or other U.S.) number, plus fake names and fabricated official-looking documents, to make the claim of government authority credible.
Tell (fraud escalation): after an initial upfront payment (framed as taxes, customs duties, fees, or insurance) was sent, "loaders" would call back saying a mistake occurred or the prize was actually larger, demanding further payments, a repeating cycle designed to keep victims paying rather than realizing no prize existed.
Roger Roger, 40, of Costa Rica, was convicted by a federal jury on September 20, 2024 of one count of conspiracy to commit mail and wire fraud, four counts of wire fraud, one count of conspiracy to commit international money laundering, and two counts of international money laundering. Because the jury found the telemarketing scheme victimized at least 10 people over age 55, he faced enhanced maximum penalties (25 years per fraud/conspiracy-to-fraud count, 20 years per money laundering count).
On July 15, 2025, Roger, then 41, was sentenced to more than 15 years in prison and ordered to pay more than $3.3 million in restitution and forfeit more than $4.2 million. He had been arrested and extradited from Costa Rica in February 2023 with assistance from DOJ's Office of International Affairs and Costa Rican law enforcement. Six other individuals (Paul Andy Stiep, Manuel Mauro Chavez, David Michael Nigh, Mark Raymond Oman, Cole Anthony Parks, and Nicholas Richer) were named as co-defendants in the underlying indictment for roles including U.S.-based fund collection/forwarding ("runners") and phone solicitation ("openers"/"loaders").
This case is a documented, DOJ-prosecuted example of how caller-ID spoofing via commodity VOIP technology can manufacture the appearance of government authority (a Washington D.C. area code) to lend false legitimacy to an advance-fee fraud at scale: hundreds of victims, over $4 million stolen, across a years-long operation before law enforcement made an arrest.
It illustrates that (1) caller ID is not a trust signal once VOIP spoofing is in play, (2) legitimate government agencies and legitimate sweepstakes never require upfront payment to release winnings, and (3) elderly victims were deliberately targeted and re-victimized through repeated "loader" calls demanding additional fees, a pattern DOJ's elder-fraud enforcement and hotline infrastructure now explicitly targets.
It's a clean pretexting case study distinct from BEC/vendor-fraud incidents: pure voice-channel authority impersonation with no email or corporate-network component.
DOJ/USPIS/IRS-CI/FBI cross-border investigation with Costa Rican law enforcement and DOJ's Office of International Affairs secured Roger's February 2023 extradition; case built via years-long evidence gathering culminating in jury trial (not caught pre-loss; this is a law-enforcement takedown, not a technical control). For consumers/families: the case underpins DOJ's standing guidance: government agencies never demand upfront "taxes," "customs duties," or "fees" via wire transfer/money order/gift cards to release a prize; caller-ID showing a Washington D.C. or U.S. number is not proof of legitimacy since VOIP lets callers spoof any number; unsolicited sweepstakes/lottery notifications by phone are categorically fraudulent since legitimate sweepstakes do not require advance payment.
DOJ's National Elder Fraud Hotline (1-833-FRAUD-11) is cited in both releases as the reporting/support channel for victims aged 60+.
Social Engineering Examples. “Roger Roger's Costa Rica Sweepstakes Call Center: VOIP-Spoofed Government Impersonation Bilks Hundreds of Elderly Victims of $4M+”. Accessed 19 September 2026. https://socialengineeringexamples.com/roger-roger-costa-rica-sweepstakes-scheme-2024
Advance-fee sweepstakes rings of this kind typically work from lead lists of older U.S. consumers, likely compiled from prior sweepstakes/lottery mailing lists, cold-call databases, or lists that circulate among fraud crews, giving the callers a pool of plausible targets skewed toward elderly victims before any call was placed.
Which specific consumers end up on a sweepstakes-fraud lead list is largely outside any single victim's or company's control; the realistic control sits downstream, at the point of contact, rather than at list formation.
Per the indictment's "manner and means" section, Roger and his co-conspirators set up Voice over Internet Protocol (VOIP) calling capability using numbers with area codes tied to Washington, D.C. and other U.S. cities, so outbound calls from Costa Rica displayed as domestic U.S. numbers.
Carrier-level STIR/SHAKEN caller-ID authentication and robocall/spoofed-number filtering are the direct technical countermeasure to VOIP caller-ID spoofing, though cross-border VOIP routing can still evade some of this filtering.
The conspirators adopted aliases and fabricated documents, and scripted a false claim of being agents or representatives of a U.S. government agency, including the IRS, to lend the sweepstakes claim official-sounding legitimacy, per the indictment.
Standing DOJ/FTC consumer guidance that legitimate government agencies never call to announce a prize or demand payment to release one is the countermeasure; treating any such call as fraudulent by default removes the pretext's power regardless of how convincing the script or documents are.
An "opener" called the victim, falsely claimed they had won a large sweepstakes prize (the indictment cites a stated $450,000 prize), and told them a fee, tax, or duty had to be paid before the prize could be released.
Consumer and caregiver education, of the kind DOJ's National Elder Fraud Hotline provides, that no legitimate sweepstakes ever requires an up-front fee, plus encouraging elderly consumers to consult a trusted family member before acting on any unsolicited prize call.
Victims who tried to verify the call were given a callback number that also rang into the same Costa Rica call center over VOIP, so the conspirators could supply false confirmation and defeat a victim's own skepticism check.
Advise verifying any such claim only through an independently looked-up official number, never a callback number supplied by the caller, since a self-provided verification channel proves nothing.
Victims were directed to send funds via Western Union or MoneyGram, by mailing blank money orders (including Postal Money Orders) via FedEx or UPS, or by wiring money directly to accounts the conspirators controlled; victims wary of sending funds abroad were routed to U.S.-based co-conspirators who collected the money domestically and forwarded it to Costa Rica.
This is the strongest real-world chokepoint. Money Service Businesses like Western Union and MoneyGram, along with the U.S. Postal Service, can flag and delay money-order and wire transactions matching known sweepstakes-fraud indicators, and bank or retail staff trained to question elderly customers making large money-order or wire purchases can interrupt the payment before it leaves the country.
After an initial payment, a "loader" called the same victim back claiming a clerical error or a larger prize (the indictment cites claims of $4,500,000 or more), demanding further fee payments, and repeating this cycle until the victim ran out of money or realized the fraud.
The same money-transfer chokepoint controls as Stage 6 apply, reinforced by repeat-transaction monitoring, since multiple sweepstakes-related transfers from the same sender in a short window is a known red-flag pattern for MSBs and fraud investigators.
Domestic collectors retained a cut and forwarded the remainder to Costa Rica, where it funded call-center operations and was split among Roger and his co-conspirators, completing the objective of ongoing, repeat extraction from the same victims.
Once funds reach Costa Rica this becomes a law-enforcement and international-cooperation problem rather than a consumer or corporate control; DOJ's Office of International Affairs working with Costa Rican authorities to investigate, extradite, and prosecute (as happened here) is the applicable response at this stage.
Browse by what this case has in common with others in the library.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.
An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a…
A Singaporean finance professional in her 50s lost S$1.2 million.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona…
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a…
After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP…
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.