Case Library / Pretexting & Impersonation / San Diego Coordinated Takedown of Pig-Butchering Scam Compounds: Ko Thet Company, Sanduo Group, Giant Company (2026)

San Diego Coordinated Takedown of Pig-Butchering Scam Compounds: Ko Thet Company, Sanduo Group, Giant Company (2026)

A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad, while a San Diego federal grand jury indicted alleged Ko Thet Company manager/recruiter Thet Min Nyi ("Pixy") and criminal complaints charged three others tied to the Sanduo Group and Giant Company networks.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On April 29, 2026, the U.S. Attorney's Office for the Southern District of California and the FBI announced a coordinated international law-enforcement action against transnational pig-butchering (romance/friendship-based cryptocurrency investment fraud) scam compounds. The operation, described as "unprecedented cooperation" between the FBI, Dubai Police Department (under the UAE Ministry of Interior), and the Chinese Ministry of Public Security, with assistance from Thailand's Royal Thai Police, resulted in at least 276 arrests (275 by Dubai Police, 1 by Royal Thai Police) and the dismantlement of at least 9 scam centers. FBI San Diego had opened a Homeland Security Task Force investigation in 2025 after identifying individuals and "companies" running scam compounds that defrauded Americans; the investigation identified three such organizations: "Ko Thet Company," "Sanduo Group," and "Giant Company." On the day of the announcement, prosecutors unsealed a March 2026 SDCA grand jury indictment against alleged Ko Thet Company manager/recruiter Thet Min Nyi ("Pixy") and a fugitive co-defendant (wire fraud conspiracy, money laundering conspiracy, criminal forfeiture), plus two April 2026 SDCA criminal complaints charging Wiliang Awang, Andreas Chandra, a second fugitive, and Lisa Mariam with wire fraud conspiracy tied to the Sanduo Group and Giant Company operations. Meta Platforms (parent of Facebook and Instagram) provided information that supported the investigation.

How the Attack Worked

Per the DOJ's plain-language description (echoed identically by the FBI and IRS Criminal Investigation mirrors of the release), the six SDCA defendants allegedly managed, worked for, or recruited others into three "companies" (Ko Thet Company, Sanduo Group, and Giant Company) that ran scam call-center-style compounds carrying out "pig-butchering" fraud. Operators cultivated a victim's trust over time through feigned friendship or romance, then introduced the idea of cryptocurrency investing, helped the victim set up accounts, and directed them to transfer crypto to investment platforms that were, unbeknownst to the victim, fake. Operators touted their own fabricated investment successes to encourage victims to invest larger sums, including urging victims to borrow from friends/family or take out loans. Once victims transferred funds to the recommended platforms, they lost control of the crypto, which the scam network then laundered through additional cryptocurrency accounts, including the operators' own. FBI agents identified victims nationally through IC3 complaints, victim interviews, and financial/crypto-ledger analysis.

The Lure & the Tell

The lure was the classic pig-butchering script described in the DOJ release: an unsolicited online contact who develops what appears to be a genuine friendship or romantic relationship with the victim over an extended period, then pivots the relationship toward cryptocurrency "investment opportunities," offers to help the victim open accounts, and boasts of the operator's own trading profits to build credibility and urgency. The tell-tale signs consistent with this pattern: contact that originated online/through messaging with no prior real-world relationship; conversation migrating to a private messaging channel; introduction of a too-good investment opportunity tied to the new "friend"/romantic interest; coaching to deposit increasing sums, including by borrowing money or taking loans; and, ultimately, an inability to withdraw invested funds from the platform because the platform itself was fraudulent and controlled by the scam operators.

Outcome

On April 29, 2026, DOJ/FBI unsealed in San Diego: (1) a March 2026 SDCA grand jury indictment (Case No. 26CR762-RSH) against Thet Min Nyi (27, Burmese national, aka "Ko Thet"/"Ko"/"Pixy") and a fugitive co-defendant, charging wire fraud conspiracy, money laundering conspiracy, and criminal forfeiture allegations (statutory max: 20 years plus fines up to $250,000-$500,000 or twice the gain/loss); and (2) two April 2026 SDCA criminal complaints: Case No. 26MJ2335-AHG against Wiliang Awang (23, Indonesia, arrested in Thailand by Royal Thai Police) and Andreas Chandra (29, Indonesia, arrested by Dubai Police) plus a fugitive co-defendant, and Case No. 26MJ2437-AHG against Lisa Mariam (29, Indonesia, arrested by Dubai Police), all charging wire fraud conspiracy tied to the Sanduo Group and Giant Company operations. Internationally, Dubai Police (UAE Ministry of Interior) made 275 arrests and the Royal Thai Police made 1, for a total of at least 276 arrests and at least 9 dismantled scam centers. The case is prosecuted by AUSA Peter Horn (SDCA) and DOJ Criminal Division Trial Attorneys Stefanie Schwartz and William Gullotta, with DOJ's Office of International Affairs assisting extradition matters. As of the sources reviewed, the SDCA charges remain unresolved allegations: the defendants are presumed innocent, and no plea, conviction, or sentencing has been publicly reported.

Why It Matters

The case is a rare instance of U.S. federal prosecutors naming and charging specific managers/recruiters of Southeast Asian pig-butchering scam-compound "companies" (rather than only prosecuting low-level money mules or publishing anonymous advisories), and it shows real multi-country law-enforcement coordination (FBI-Dubai-China-Thailand) against an industry that has historically operated with near-impunity from jurisdictions that are hard for U.S. authorities to reach. It also illustrates how these operations are structured as organized businesses ("companies" with managers and recruiters) running multiple scam centers rather than lone-wolf scammers, and how a single platform's cooperation (Meta) and a proactive victim-identification program (FBI's Operation Level Up) can materially aid disruption and victim notification at scale. For consumer education, it reconfirms the enduring pig-butchering playbook, unsolicited online relationship-building leading to fraudulent crypto investment and fund-transfer coercion, as a persistent, industrialized threat rather than an isolated scam pattern.

Defenses

DOJ/FBI framed the response as international law-enforcement coordination (FBI Homeland Security Task Force San Diego opened 2025; joint action with Dubai Police/UAE Ministry of Interior, Chinese Ministry of Public Security, Royal Thai Police) plus platform cooperation (Meta Platforms supplied information used in the investigation) and victim self-reporting via the FBI's IC3.gov portal. For consumer-level defense, the case illustrates standard pig-butchering red flags worth teaching: unsolicited contact from a stranger who quickly builds a friendship/romance; steering the conversation to a private messaging app; unsolicited crypto-investment tips paired with claims of the "friend's" own trading success; pressure to deposit escalating amounts, including borrowing from family or taking loans; and inability to withdraw funds from the investment platform. Financial institutions and crypto exchanges are encouraged to flag transfers tied to newly formed online-only relationships, and the public is directed to report suspected pig-butchering schemes to the FBI's Internet Crime Complaint Center (IC3.gov).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Victim sourcing and profile-building: Pig-butchering operators typically source large volumes of potential contacts through mass outreach on social platforms and dating-style apps, and commonly work from scripted personas (often with stolen or stock photos) and playbooks distributed inside the compound, consistent with the DOJ's description of these operations as organized 'companies' with managers and recruiters rather than lone scammers.
Countering Stage 1: Mass social-platform outreach and persona-building is very hard to prevent at the source; the realistic control sits downstream, at platform-level detection of fake/scripted accounts and coordinated inauthentic behavior (the kind of signal Meta reportedly supplied to this investigation) rather than stopping profile creation itself.
2
Forced or coerced staffing of the compound: Reporting on this category of Southeast Asian scam center (referenced in the DOJ release's mention of the related Tai Chang enterprise in Burma's Karen State) indicates operators frequently staff call-center-style compounds with trafficked or coerced workers alongside willing recruits, which is likely how the recruiter-level defendants in this case (Awang, Chandra, Mariam) built out scam-center headcount for Sanduo Group and Giant Company.
Countering Stage 2: Disrupting forced labor inside overseas scam compounds is primarily a law-enforcement and diplomatic problem, addressed here through the FBI's Homeland Security Task Force investigation and coordinated action with Dubai Police, Chinese Ministry of Public Security, and Royal Thai Police rather than a consumer-side or platform-side control.
3
Initial contact and relationship-building: Per the DOJ release, operators approached victims online (case materials point to Meta's Facebook and Instagram, since Meta supplied information to the investigation) and, over an extended period, cultivated what appeared to be a genuine friendship or romance, tailoring the persona and pacing to keep the target engaged without raising suspicion.
Countering Stage 3: Platform-level friction on unsolicited contact (message requests from strangers, romance-scam warning prompts, account-age/behavior signals) and public education on pig-butchering's 'stranger becomes friend or romantic interest fast' pattern are the nearest realistic controls at this stage.
4
Channel migration: Consistent with standard pig-butchering pattern, the conversation was steered from the public platform to a private messaging channel, isolating the interaction from platform-level moderation or a victim's social circle and giving the operator more control over the narrative.
Countering Stage 4: User education to be suspicious when a new online contact quickly pushes the conversation off-platform, plus platform nudges that flag or slow attempts to move a new connection to another messaging app, directly target this migration point.
5
Investment pitch and platform onboarding: Once trust was established, operators introduced a cryptocurrency 'investment opportunity,' walked the victim through opening accounts, and directed transfers to fraudulent investment platforms built and controlled by the scam network, per the DOJ's charging narrative.
Countering Stage 5: Crypto exchanges and wallet providers screening deposit/investment platforms against known-fraud domain and address lists, plus consumer education that unsolicited investment tips from an online romantic or friendship contact are a hallmark of pig-butchering, are the direct countermeasure here.
6
Social proof and escalation: Operators touted their own fabricated trading successes to build credibility and pushed victims to invest larger sums, including encouraging them to borrow from friends and family or take out loans, per the DOJ release.
Countering Stage 6: Financial institutions and crypto exchanges flagging escalating transfers tied to a newly formed online-only relationship, and loan/credit providers screening for the 'borrowing to invest' pattern the DOJ release calls out, counter this stage before losses compound.
7
Fund capture and layered laundering: Once victims transferred crypto to the platforms, they lost control of it; the scam network then laundered the funds through additional cryptocurrency accounts, including accounts controlled by the operators themselves, per the DOJ release and the wire fraud/money laundering conspiracy charges.
Countering Stage 7: Blockchain analytics and exchange-level transaction monitoring to trace and freeze funds moving into scam-linked wallets, plus victim self-reporting via the FBI's IC3.gov portal, are the tools DOJ credits with identifying victims and building the money-laundering case; asset forfeiture is the direct countermeasure at this stage.
8
Objective completion, payout and reinvestment in the enterprise: Laundered proceeds funded the scam-compound business (recruiters, compound operations, and further victim acquisition), consistent with DOJ's framing of Ko Thet Company, Sanduo Group, and Giant Company as ongoing criminal enterprises rather than one-off scams, until disrupted by the FBI-Dubai-China-Thailand law-enforcement action.
Countering Stage 8: This is where the case's actual disruption happened: an FBI Homeland Security Task Force investigation combined with coordinated international arrests (Dubai Police, Royal Thai Police) and Chinese Ministry of Public Security cooperation, plus platform cooperation from Meta and DOJ's Office of International Affairs on extradition, dismantled the enterprise and its compounds rather than relying on any single upstream control.
Quick Facts
Victim
US citizens and international individuals (other countries also affected per DOJ) targeted for cryptocurrency investment fraud through pig-butchering; victims were identified nationally through complaints filed with the FBI's Internet Crime Complaint Center (IC3), supplemented by victim interviews and financial/cryptocurrency-ledger analysis. No victims are individually named in the public record reviewed.
Location
Scam compounds operated in Southeast Asia; the coordinated arrest operation was executed by Dubai Police (UAE Ministry of Interior, 275 arrests) and Thailand's Royal Thai Police (1 arrest), with Chinese Ministry of Public Security cooperation; the federal criminal case (indictment + two complaints) was filed in the Southern District of California, San Diego
Date
2026-04-29 (DOJ/FBI public announcement); Thet Min Nyi indictment returned by SDCA grand jury March 2026; two criminal complaints (Awang/Chandra/fugitive; Mariam) filed SDCA April 2026; Dubai-led arrests conducted the week prior to the announcement (on/around 2026-04-20 to 2026-04-24)
Impact
DOJ's press release states the scam centers "targeted Americans who have suffered millions of dollars in losses" but does not itemize a case-specific total loss figure or name individual victims. Separately (and not specific to these three named companies), the release notes that the FBI's broader "Operation Level Up" initiative, a proactive victim-identification program running since 2024, had by April 2026 notified almost 9,000 victims and saved an estimated $562 million; that figure should not be read as the loss total for Ko Thet Company/Sanduo Group/Giant Company specifically. One lower-tier secondary source (thefinancialstandard.com) cites larger aggregate figures ($701M restrained, 20,000+ victims across 30 countries) and a conflicting Nyi arrest date of May 7, 2026 that contradicts the primary release's own timeline ("last week" of arrests before the April 29 announcement); those unconfirmed figures/dates are not relied upon in this record and are flagged as discrepant.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Cryptocurrency & Digital Assets
Threat Actor
Organized Crime
Related

Related Cases

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…

Incident 2026Read →

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…

Incident 2025Read →

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and…

Incident 2025Read →