A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.
Social Engineering Examples·5 sources
On April 29, 2026, the U.S. Attorney's Office for the Southern District of California and the FBI announced a coordinated international law-enforcement action against transnational pig-butchering (romance/friendship-based cryptocurrency investment fraud) scam compounds. The operation, described as "unprecedented cooperation" between the FBI, Dubai Police Department (under the UAE Ministry of Interior), and the Chinese Ministry of Public Security, with assistance from Thailand's Royal Thai Police, resulted in at least 276 arrests (275 by Dubai Police, 1 by Royal Thai Police) and the dismantlement of at least 9 scam centers.
FBI San Diego had opened a Homeland Security Task Force investigation in 2025 after identifying individuals and "companies" running scam compounds that defrauded Americans; the investigation identified three such organizations: "Ko Thet Company," "Sanduo Group," and "Giant Company." On the day of the announcement, prosecutors unsealed a March 2026 SDCA grand jury indictment against alleged Ko Thet Company manager/recruiter Thet Min Nyi ("Pixy") and a fugitive co-defendant (wire fraud conspiracy, money laundering conspiracy, criminal forfeiture), plus two April 2026 SDCA criminal complaints charging Wiliang Awang, Andreas Chandra, a second fugitive, and Lisa Mariam with wire fraud conspiracy tied to the Sanduo Group and Giant Company operations.
Meta Platforms (parent of Facebook and Instagram) provided information that supported the investigation.
Per the DOJ's plain-language description (echoed identically by the FBI and IRS Criminal Investigation mirrors of the release), the six SDCA defendants allegedly managed, worked for, or recruited others into three "companies" (Ko Thet Company, Sanduo Group, and Giant Company) that ran scam call-center-style compounds carrying out "pig-butchering" fraud.
Operators cultivated a victim's trust over time through feigned friendship or romance, then introduced the idea of cryptocurrency investing, helped the victim set up accounts, and directed them to transfer crypto to investment platforms that were, unbeknownst to the victim, fake. Operators touted their own fabricated investment successes to encourage victims to invest larger sums, including urging victims to borrow from friends/family or take out loans.
Once victims transferred funds to the recommended platforms, they lost control of the crypto, which the scam network then laundered through additional cryptocurrency accounts, including the operators' own. FBI agents identified victims nationally through IC3 complaints, victim interviews, and financial/crypto-ledger analysis.
The lure was the classic pig-butchering script described in the DOJ release: an unsolicited online contact who develops what appears to be a genuine friendship or romantic relationship with the victim over an extended period, then pivots the relationship toward cryptocurrency "investment opportunities," offers to help the victim open accounts, and boasts of the operator's own trading profits to build credibility and urgency.
The tell-tale signs consistent with this pattern: contact that originated online/through messaging with no prior real-world relationship; conversation migrating to a private messaging channel; introduction of a too-good investment opportunity tied to the new "friend"/romantic interest; coaching to deposit increasing sums, including by borrowing money or taking loans; and, ultimately, an inability to withdraw invested funds from the platform because the platform itself was fraudulent and controlled by the scam operators.
On April 29, 2026, DOJ/FBI unsealed in San Diego: (1) a March 2026 SDCA grand jury indictment (Case No. 26CR762-RSH) against Thet Min Nyi (27, Burmese national, aka "Ko Thet"/"Ko"/"Pixy") and a fugitive co-defendant, charging wire fraud conspiracy, money laundering conspiracy, and criminal forfeiture allegations (statutory max: 20 years plus fines up to $250,000-$500,000 or twice the gain/loss); and (2) two April 2026 SDCA criminal complaints: Case No. 26MJ2335-AHG against Wiliang Awang (23, Indonesia, arrested in Thailand by Royal Thai Police) and Andreas Chandra (29, Indonesia, arrested by Dubai Police) plus a fugitive co-defendant, and Case No. 26MJ2437-AHG against Lisa Mariam (29, Indonesia, arrested by Dubai Police), all charging wire fraud conspiracy tied to the Sanduo Group and Giant Company operations.
Internationally, Dubai Police (UAE Ministry of Interior) made 275 arrests and the Royal Thai Police made 1, for a total of at least 276 arrests and at least 9 dismantled scam centers. The case is prosecuted by AUSA Peter Horn (SDCA) and DOJ Criminal Division Trial Attorneys Stefanie Schwartz and William Gullotta, with DOJ's Office of International Affairs assisting extradition matters.
As of the sources reviewed, the SDCA charges remain unresolved allegations: the defendants are presumed innocent, and no plea, conviction, or sentencing has been publicly reported.
The case is a rare instance of U.S. federal prosecutors naming and charging specific managers/recruiters of Southeast Asian pig-butchering scam-compound "companies" (rather than only prosecuting low-level money mules or publishing anonymous advisories), and it shows real multi-country law-enforcement coordination (FBI-Dubai-China-Thailand) against an industry that has historically operated with near-impunity from jurisdictions that are hard for U.S. authorities to reach.
It also illustrates how these operations are structured as organized businesses ("companies" with managers and recruiters) running multiple scam centers rather than lone-wolf scammers, and how a single platform's cooperation (Meta) and a proactive victim-identification program (FBI's Operation Level Up) can materially aid disruption and victim notification at scale.
For consumer education, it reconfirms the enduring pig-butchering playbook, unsolicited online relationship-building leading to fraudulent crypto investment and fund-transfer coercion, as a persistent, industrialized threat rather than an isolated scam pattern.
DOJ/FBI framed the response as international law-enforcement coordination (FBI Homeland Security Task Force San Diego opened 2025; joint action with Dubai Police/UAE Ministry of Interior, Chinese Ministry of Public Security, Royal Thai Police) plus platform cooperation (Meta Platforms supplied information used in the investigation) and victim self-reporting via the FBI's IC3.gov portal.
For consumer-level defense, the case illustrates standard pig-butchering red flags worth teaching: unsolicited contact from a stranger who quickly builds a friendship/romance; steering the conversation to a private messaging app; unsolicited crypto-investment tips paired with claims of the "friend's" own trading success; pressure to deposit escalating amounts, including borrowing from family or taking loans; and inability to withdraw funds from the investment platform.
Financial institutions and crypto exchanges are encouraged to flag transfers tied to newly formed online-only relationships, and the public is directed to report suspected pig-butchering schemes to the FBI's Internet Crime Complaint Center (IC3.gov).
Social Engineering Examples. “San Diego Coordinated Takedown of Pig-Butchering Scam Compounds: Ko Thet Company, Sanduo Group, Giant Company (2026)”. Accessed 19 September 2026. https://socialengineeringexamples.com/san-diego-scam-compound-takedown-ko-thet-sanduo-giant-2026
Pig-butchering operators typically source large volumes of potential contacts through mass outreach on social platforms and dating-style apps, and commonly work from scripted personas (often with stolen or stock photos) and playbooks distributed inside the compound, consistent with the DOJ's description of these operations as organized 'companies' with managers and recruiters rather than lone scammers.
Mass social-platform outreach and persona-building is very hard to prevent at the source; the realistic control sits downstream, at platform-level detection of fake/scripted accounts and coordinated inauthentic behavior (the kind of signal Meta reportedly supplied to this investigation) rather than stopping profile creation itself.
Reporting on this category of Southeast Asian scam center (referenced in the DOJ release's mention of the related Tai Chang enterprise in Burma's Karen State) indicates operators frequently staff call-center-style compounds with trafficked or coerced workers alongside willing recruits, which is likely how the recruiter-level defendants in this case (Awang, Chandra, Mariam) built out scam-center headcount for Sanduo Group and Giant Company.
Disrupting forced labor inside overseas scam compounds is primarily a law-enforcement and diplomatic problem, addressed here through the FBI's Homeland Security Task Force investigation and coordinated action with Dubai Police, Chinese Ministry of Public Security, and Royal Thai Police rather than a consumer-side or platform-side control.
Per the DOJ release, operators approached victims online (case materials point to Meta's Facebook and Instagram, since Meta supplied information to the investigation) and, over an extended period, cultivated what appeared to be a genuine friendship or romance, tailoring the persona and pacing to keep the target engaged without raising suspicion.
Platform-level friction on unsolicited contact (message requests from strangers, romance-scam warning prompts, account-age/behavior signals) and public education on pig-butchering's 'stranger becomes friend or romantic interest fast' pattern are the nearest realistic controls at this stage.
Consistent with standard pig-butchering pattern, the conversation was steered from the public platform to a private messaging channel, isolating the interaction from platform-level moderation or a victim's social circle and giving the operator more control over the narrative.
User education to be suspicious when a new online contact quickly pushes the conversation off-platform, plus platform nudges that flag or slow attempts to move a new connection to another messaging app, directly target this migration point.
Once trust was established, operators introduced a cryptocurrency 'investment opportunity,' walked the victim through opening accounts, and directed transfers to fraudulent investment platforms built and controlled by the scam network, per the DOJ's charging narrative.
Crypto exchanges and wallet providers screening deposit/investment platforms against known-fraud domain and address lists, plus consumer education that unsolicited investment tips from an online romantic or friendship contact are a hallmark of pig-butchering, are the direct countermeasure here.
Operators touted their own fabricated trading successes to build credibility and pushed victims to invest larger sums, including encouraging them to borrow from friends and family or take out loans, per the DOJ release.
Financial institutions and crypto exchanges flagging escalating transfers tied to a newly formed online-only relationship, and loan/credit providers screening for the 'borrowing to invest' pattern the DOJ release calls out, counter this stage before losses compound.
Once victims transferred crypto to the platforms, they lost control of it; the scam network then laundered the funds through additional cryptocurrency accounts, including accounts controlled by the operators themselves, per the DOJ release and the wire fraud/money laundering conspiracy charges.
Blockchain analytics and exchange-level transaction monitoring to trace and freeze funds moving into scam-linked wallets, plus victim self-reporting via the FBI's IC3.gov portal, are the tools DOJ credits with identifying victims and building the money-laundering case; asset forfeiture is the direct countermeasure at this stage.
Laundered proceeds funded the scam-compound business (recruiters, compound operations, and further victim acquisition), consistent with DOJ's framing of Ko Thet Company, Sanduo Group, and Giant Company as ongoing criminal enterprises rather than one-off scams, until disrupted by the FBI-Dubai-China-Thailand law-enforcement action.
This is where the case's actual disruption happened: an FBI Homeland Security Task Force investigation combined with coordinated international arrests (Dubai Police, Royal Thai Police) and Chinese Ministry of Public Security cooperation, plus platform cooperation from Meta and DOJ's Office of International Affairs on extradition, dismantled the enterprise and its compounds rather than relying on any single upstream control.
Browse by what this case has in common with others in the library.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes…
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
A Singaporean finance professional in her 50s lost S$1.2 million.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
Posing as NatWest bank security, vishing criminals convinced Surrey solicitor Karen Mackie to wire £734,000 of client money to fraudulent…
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.