Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors into a fake.
Social Engineering Examples·6 sources
Between approximately September/October 2023 and June 2024, scheme participants used at least seven WhatsApp groups to impersonate financial-industry professionals and cultivate trust with U.S. retail investors before steering them into "NanoBit," a purported cryptocurrency trading platform that in reality executed no real trades and falsely claimed an SEC-registered brokerage affiliate ("NanobitUS Securities").
The SEC's complaint alleges at least 18 investors lost a combined ~$967,835 in crypto and fiat, with more than $2 million ultimately wired by the scheme's shell-company conduits to bank accounts in Hong Kong. The case, SEC v. NanoBit Limited et al. (E.D.N.Y., No. 2:24-cv-06517), was among the SEC's first enforcement actions explicitly targeting this "relationship investment"/pig-butchering fraud model, and culminated in a June 16, 2026 default judgment of $5,518,902 against six of the seven defendants.
Scheme participants added or drew targets into at least seven WhatsApp groups (examples named in the complaint: "VIP8012," "VIP34") where they posed as financial-industry professionals, including personas the complaint calls "Pseudo-Director A" and "Pseudo-Director B," each impersonating a real senior investment professional, and supported by fake assistants and other planted group members who reinforced the illusion of a thriving trading community.
Over time this built rapport and credibility (the classic "fattening" phase of pig butchering) before participants steered members toward a purported crypto trading platform, NanoBit (previously hosted at NanoBitUS.com). To allay safety concerns, NanoBit falsely claimed its affiliate "NanobitUS Securities" was an SEC-registered broker-dealer, and the in-group "professionals" touted fake initial coin offerings, including "Cosmic Energy" and "VTrade," complete with counterfeit downloadable whitepapers, promising outsized returns.
In reality no trades were ever executed on the platform: the trading interface was fabricated. When victims tried to withdraw funds, they were stalled with undisclosed "miner's fees" (one investor was told he owed $10,692 in "Ghana miners fees" before his withdrawal could be processed), told other members had successfully cashed out only after paying such fees, or simply removed from the WhatsApp group when they pushed back (the complaint cites one investor removed from "VIP8012" on March 11, 2024 after calling the scheme a fraud).
Investor money was funneled through entity defendants: Radiant Horizons Limited allegedly wired over $2 million to Hong Kong bank accounts (e.g., $145,690 on Jan. 17, 2024 and $127,638 on Jan. 18, 2024), while crypto contributions went to unhosted wallet addresses, and Sweet Karma Fashion Inc. and Zhao Tropical Deli Inc. (unrelated-sounding small-business entities) served as fiat "mule" conduits.
The lure: strangers added victims to (or drew them into) WhatsApp "VIP" investment groups populated by seemingly successful traders and a warm, patient "senior director" figure who built a personal rapport before ever mentioning money, then vouched for a slick-looking crypto trading platform and a supposedly SEC-registered brokerage affiliate. The tell: legitimate SEC-registered brokers and investment professionals do not recruit clients through unsolicited WhatsApp group additions, group chats are not a substitute for verifying registration on Investor.gov/EDGAR, and any platform that invents new "fees" (like undisclosed miner's fees) specifically at the moment of withdrawal, or that removes a member from the group for asking hard questions, is exhibiting the textbook signature of pig-butchering fraud rather than a functioning trading venue.
The SEC filed its civil enforcement complaint on September 17, 2024 in EDNY (SEC v. NanoBit Limited et al., No. 2:24-cv-06517), charging four entities (NanoBit Limited, Radiant Horizons Limited, Sweet Karma Fashion Inc., Zhao Tropical Deli Inc.) and three individuals (Jiajie Liu, Fei Liao, Hua Zhao) with violating the antifraud provisions of the Securities Act and Exchange Act (Section 17(a), Section 10(b)/Rule 10b-5).
On June 16, 2026, the EDNY court entered a final default judgment against six of the seven defendants (all except Fei Liao, who was named in the original complaint but was not part of the default judgment), permanently enjoining them from further securities-law violations and ordering a combined $5,518,902 in disgorgement, prejudgment interest, and civil penalties.
Liu and Zhao were further restricted to trading only in their own personal accounts. The SEC announced the judgment via Litigation Release No. 26576 on June 29, 2026.
This is one of the SEC's first enforcement actions explicitly built around the "pig-butchering" / relationship-investment fraud model, showing that U.S. securities regulators now treat WhatsApp-group crypto scams as a distinct, prosecutable pattern rather than ordinary fraud. It illustrates how the technique blends classic long-con social engineering (patient trust-building via impersonated authority figures and a fabricated peer community) with securities-fraud tactics (a fake registered-broker claim, fake ICOs) to bypass the skepticism investors typically reserve for cold outreach.
It also highlights the enforcement gap in this crime type: even a full $5.5 million default judgment is a paper win when the underlying funds have already been wired to Hong Kong and the responsible individuals may be judgment-proof or unreachable, meaning victim restitution is far from guaranteed. Finally, it validates that seemingly "boring" WhatsApp group chats revolving around finance/investing content are an active, regulator-recognized attack surface for retail investors.
SEC's own investor alert (issued with this case, in collaboration with CFTC, FINRA, and NASAA) advises: never rely solely on information from group chats to make investment decisions; independently verify any broker-dealer's registration status via Investor.gov/SEC EDGAR rather than trusting an in-group claim of being "SEC-registered"; be suspicious of unsolicited additions to investment-themed WhatsApp/Telegram groups by strangers; treat any request for extra fees (e.g., "miner's fees") to unlock a withdrawal as a hard stop, not a hurdle to pay; and note that being removed from a group chat after questioning returns or fees is itself a fraud indicator.
Financial institutions and messaging platforms are encouraged to flag patterns of newly-added contacts steering users toward off-platform "trading" links.
Social Engineering Examples. “SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals”. Accessed 19 September 2026. https://socialengineeringexamples.com/whatsapp-pig-butchering-nanobit-sec-2024
Scheme participants likely registered shell companies (e.g. Sweet Karma Fashion Inc., Zhao Tropical Deli Inc.) to serve as fiat mule accounts, stood up the fake NanoBit trading platform and dashboard, prepared counterfeit ICO whitepapers, and sourced WhatsApp numbers, consistent with the infrastructure named in the SEC complaint.
Shell-company formation and fake trading-platform builds are hard to intercept pre-launch; the realistic control sits with banks screening newly formed small-business accounts for mule-like deposit/withdrawal patterns once money starts moving, addressed at Stage 7.
Per the SEC complaint, at least one persona ('Pseudo-Director A') borrowed the name and title of a real managing director at a legitimate global investment firm, indicating some OSINT on real financial-industry professionals to make the impersonation credible.
Public professional profiles used for persona-borrowing are difficult to lock down at scale; the more effective control is verifying any individual's registration and firm affiliation directly on Investor.gov/SEC EDGAR rather than trusting the name and title as presented in a chat.
Scheme participants added or drew targets into private WhatsApp 'VIP' investment groups, with the SEC noting some investors were first solicited via other social media apps before being funneled into the groups.
Treat unsolicited additions to investment-themed WhatsApp/Telegram groups by strangers as a default red flag, and decline to engage rather than waiting to see where the group leads.
Impersonated senior professionals, backed by planted fake assistants and other fabricated group members, gave real-sounding investment commentary over an extended period to build rapport and the appearance of a thriving trading community before ever discussing money.
Recognize patient, no-pitch rapport-building in an investment-themed group chat as a known pig-butchering pattern in itself, per the SEC's investor alert, and avoid making investment decisions based on group-chat relationships regardless of how genuine they feel.
The group steered members toward the NanoBit platform, falsely claiming its affiliate 'NanobitUS Securities' was an SEC-registered broker-dealer tied to reputable firms, to defeat the skepticism a cold pitch would normally trigger.
Independently verify any broker-dealer's registration status on Investor.gov/SEC EDGAR before funding an account; this single check would have exposed NanobitUS Securities as unregistered.
In-group 'professionals' touted fake initial coin offerings (named in reporting as 'Cosmic Energy' and 'VTrade'), backed by counterfeit whitepapers, to induce larger investments beyond the initial deposit.
Apply the same registration/legitimacy check to any touted ICO or token before investing further, and treat a slick whitepaper alone as no substitute for verifiable registration or an independently confirmed trading history.
Victims wired fiat and transferred crypto into the scheme; funds were routed through the shell 'mule' entities to bank accounts in Hong Kong and into unhosted crypto wallets rather than any real trading activity.
Banks and crypto platforms can flag newly opened small-business accounts receiving many unrelated incoming wires followed quickly by large outbound transfers to overseas accounts, a recognizable mule-account signature.
When victims tried to cash out, they were charged undisclosed fees invented on the spot (e.g. one investor was told he owed $10,692 in 'Ghana miners fees') and told other members had only succeeded after paying similar fees.
Treat any new or undisclosed fee demanded to unlock a withdrawal as a hard stop rather than a cost of doing business, per SEC/CFTC/FINRA/NASAA guidance issued alongside this case.
Investors who pushed back or called the platform fraudulent were removed from the WhatsApp group, cutting off further contact while the already-diverted funds remained with scheme participants overseas, completing the theft.
Being removed from a group chat for questioning legitimacy is itself a fraud indicator that should trigger an immediate report to the SEC, FINRA, or state regulators; once funds reach overseas banks or unhosted wallets, recovery depends on cross-border law-enforcement asset tracing, which this case shows is slow and only partially effective given the still-uncollected judgment.
Browse by what this case has in common with others in the library.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a…
Criminals impersonated a trusted vendor over email and redirected two building-fund payments totaling $4.92M from a North Dakota school district.
California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
FIN7 (Carbanak) mailed USPS packages disguised as Best Buy gift-card rewards containing BadUSB hardware implants to HR, IT.
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.