admin

Zhen Yang founded ICAR with a singular mission: to give fraud victims access to the same calibre of investigative expertise previously available only to corporations and governments. As Chief Recovery Officer, he personally oversees all case strategy, coordinates recovery efforts across legal and law enforcement channels, and serves as the primary advocate for every client ICAR represents. Areas of Expertise Fraud Recovery Strategy Cross-Border Asset Recovery Financial Dispute Resolution Case Management & Client Advocacy Anti-Money Laundering Investigation

The Wrong Number Text Scam: Why Even a Polite Reply Is a Mistake

A message arrives from a number you do not recognize. Hi Jessica, sorry I’m running late, see you at 7. You are not Jessica. The obvious move is to reply, wrong number, and move on. According to the Federal Trade Commission, that single exchange is often the opening move of a scam that, across all text based fraud, cost Americans $470 million in 2024, five times what was reported just four years earlier. This article explains why these messages are essentially never actual mistakes, what happens after someone replies, and why even a brief polite correction carries more risk than most people realize. It Is Never Actually the Wrong Number These messages are mass sent to enormous batches of numbers, either scraped from data breaches or generated in sequence, with no real Jessica and no real dinner plan behind any of them. The personal detail, a name, a time, a plausible reason for the mix up, exists purely to make the message feel human rather than automated, since a fully generic message is easier to ignore. Research from McAfee found that roughly one in four Americans have received a message matching this exact pattern, which gives a sense of just how widely these campaigns are run. The Federal Communications Commission specifically flagged this category in a 2022 consumer warning after RoboKiller estimated Americans were receiving billions of robotexts in a single month. What has changed since then is not the tactic itself but its role as a deliberate entry point into a much longer and more damaging scheme. The template itself has become remarkably consistent across campaigns, which is worth understanding because recognizing the pattern is often the fastest way to identify one. A first name that is common but not overly generic. A brief, mundane excuse, running late, wrong group chat, confused about an address. Just enough specificity to feel like a real mistake, and just enough vagueness that the message works equally well sent to a thousand different numbers at once. Genuine wrong numbers, by contrast, tend to be shorter, more confused sounding, and usually stop the moment the sender realizes their error rather than continuing to test for a response. Why Replying Feels So Natural, and Why That Matters Part of what makes this tactic effective has nothing to do with technology and everything to do with ordinary social habits. Most people are conditioned to respond politely when someone appears to have made an honest mistake reaching out to them. Ignoring a seemingly confused stranger can feel rude in a way that ignoring an obvious advertisement does not. Scam operators are relying specifically on that social reflex, because it reliably produces a higher reply rate than a message that reads as an obvious solicitation. This is worth naming explicitly because understanding why a tactic works is often more protective than simply being told not to fall for it. The urge to type wrong number, no worries is not a character flaw or a sign of gullibility. It is a normal social instinct being deliberately exploited at scale. Path One: The Slow Build Toward Pig Butchering If a target replies at all, even just to correct the sender, the scammer treats that reply as a signal worth pursuing. What typically follows is not an immediate pitch but a long, patient conversation, days and sometimes weeks of ordinary seeming friendliness, before any mention of money or investment appears. This pattern is documented at length in our companion Hub article on pig butchering scams, and the wrong number text is simply the most common single doorway into it. The scale of what this leads to is significant. The FBI’s 2025 Internet Crime Report found that cryptocurrency investment fraud, the category that captures the large majority of pig butchering losses, was the single largest source of financial harm to Americans that year at more than 8.6 billion dollars. The wrong number text is rarely the expensive part of the scam. It is the low cost, high volume filter that identifies which numbers are worth the weeks of relationship building that follows. What makes this filtering approach so efficient from the scammer’s perspective is the enormous mismatch in cost. Sending a text message costs essentially nothing at scale, while building a convincing weeks long relationship with a genuinely receptive target requires real time and effort. The wrong number opener exists specifically to sort a huge pool of random numbers down to the small subset of people willing to engage at all, before any real investment of the scammer’s own time begins. Path Two: The Reply Itself Has Resale Value This is the part most warnings skip entirely, and it matters even for someone who never falls for the relationship angle at all. Fraud researchers at TransUnion have noted that a scammer’s real objective is not always a large financial payday. Even a short reply confirms that a phone number is active, monitored, and attached to a real person willing to engage with an unknown sender. That confirmation alone has resale value on data marketplaces, since a verified active number is worth meaningfully more to other fraud operations than an unconfirmed one pulled from a leaked list. In some documented cases, a scammer who extracts enough information from a seemingly harmless exchange has gone on to locate a target’s social media accounts and lock them out entirely, then demand a smaller payment to restore access. None of this requires the elaborate multi week pig butchering build. It only requires a single reply confirming the number is live. It is worth understanding roughly how this secondary market functions, without treating it as anything mysterious. A confirmed active number, tied to a real, responsive person, becomes a data point that gets bundled with thousands of others and sold as a verified contact list. Other fraud operations then purchase these lists specifically because they carry a meaningfully higher success rate than cold, unverified numbers. A single reply, in effect, moves a phone number from a

The Wrong Number Text Scam: Why Even a Polite Reply Is a Mistake Read More »

Do Not Reply Wrong Number Text Icar 2 1

Real Wallet Drainer Scam Examples and How They Were Caught | ICAR

A wallet drainer is malicious code, usually delivered through a phishing website or a fake token claim, that tricks a victim into signing a transaction that hands control of their crypto assets to an attacker. This isn’t a hypothetical threat. It’s an active criminal industry with named operations, known operators, and a documented history of takedowns that never quite stops the underlying activity. This guide walks through five real cases, how each was actually discovered and disrupted, and what the pattern across all of them means for anyone holding crypto today. 83% Drop Wallet drainer losses fell from $494 million in 2024 to $83.85 million in 2025, according to Scam Sniffer data. Real progress, but still tens of millions stolen every year Source: Scam Sniffer, Group-IB, and SlowMist annual reporting Case 1: Inferno Drainer, the $80 Million Operation Caught by Researchers, Not Police Inferno Drainer ran from November 2022 to November 2023 as a scam as a service operation, meaning the people who built the drainer software rented it out to affiliates who kept 80 percent of what they stole while the operators took a 20 percent cut. It’s estimated to have stolen more than $80 million from roughly 137,000 victims, using more than 16,000 phishing domains that impersonated over a hundred real crypto brands and projects. Here’s the part worth understanding about how this got caught. It wasn’t a law enforcement raid. It was Group-IB’s High-Tech Crime Investigation unit, a private cybersecurity research team, publishing a detailed technical exposure of the operation’s infrastructure in January 2024, two months after the operators had already announced their own shutdown. The public research made it dramatically harder for the same operators to relaunch under the same identity, but it didn’t end the underlying threat. Inferno Drainer’s code and reputation resurfaced in 2025, and in just six months it struck more than 30,000 wallets and stole over $9 million more. Case 2: Monkey Drainer, Shut Down by a Single Independent Investigator Monkey Drainer was one of the earliest scaled drainer operations, and it shut down voluntarily in March 2023 after independent on chain investigator ZachXBT published a public investigation identifying the operator. This case is worth including specifically because it shows that formal law enforcement isn’t the only force that disrupts these operations. A single researcher, working publicly and sharing findings openly, applied enough pressure and public exposure that the operator chose to announce a shutdown via Telegram rather than continue operating under scrutiny. Case 3: Pink Drainer, $85 Million and 21,000 Victims Before a Quiet Retirement Pink Drainer is linked to more than $85 million stolen from over 21,000 victims before announcing its own wind down in 2024. Like Inferno, it operated as a service, meaning the technical skill barrier for running a drainer campaign was almost nonexistent for affiliates, who mainly needed to drive traffic to phishing pages through hacked social media accounts, paid ads, or spam. The retirement of both Pink and Inferno within roughly the same period didn’t reduce the total number of active drainer campaigns much, since the affiliate pool simply migrated to whichever kit was still available. Case 4: Angel Drainer and the Ledger Connect Kit Supply Chain Attack Angel Drainer’s most notable moment wasn’t a phishing site at all. On December 14, 2023, attackers compromised Ledger’s Connect Kit, a piece of legitimate, widely used code that many real crypto applications rely on to let wallets connect to them. Because the compromised code was distributed through official channels, a large number of genuine, reputable applications briefly served malicious code to their own users without either the applications or the users doing anything wrong on the surface. This is a meaningfully different attack pattern than a fake website, since it demonstrates that even careful users interacting only with applications they already trusted could still have been exposed, at least for the narrow window before the compromise was identified and reverted. Case 5: The September 2025 Case That Shows Even Experienced Users Get Caught In September 2025, a long time DeFi trader with a wallet tied to years of activity on respected protocols lost $6.5 million in a single incident. The attack began through a phishing link shared in a community channel, and the actual theft happened through a single malicious permit approval, a type of signature that grants a smart contract ongoing permission to move specific tokens on a wallet’s behalf. That one approval looked routine at the moment it was signed. The attackers then chained that permission across multiple contracts, moving funds in quick bursts before the victim could intervene. This case matters because the victim wasn’t a beginner. Long standing wallet history and familiarity with major protocols didn’t prevent the loss, because the vulnerability wasn’t a lack of crypto experience. It was a single signature, requested in a moment that felt ordinary, that granted more access than the victim understood they were granting. The Pattern Across Every Case None of these five cases involved a stolen private key or password in the traditional sense. Every one of them worked by getting the victim to actively sign something, a wallet connection, a token approval, a permit signature, that handed the attacker legitimate on chain permission to move funds. This is why so much wallet security advice now focuses on what you’re approving, not just what you’re clicking. A phishing site doesn’t need to steal your credentials if it can convince you to sign a transaction that does the same job with your own authorization attached to it. How These Operations Actually Get Disrupted Independent researchers publishing public investigations, as with ZachXBT and Monkey Drainer, which can pressure an operator into shutting down even without a formal arrest Cybersecurity firms exposing infrastructure through detailed technical reports, as Group-IB did with Inferno Drainer, which damages an operation’s ability to relaunch under the same identity Real time threat detection platforms that flag malicious addresses within hours of new activity, as Hypernative did within a day of Inferno Drainer’s 2025

Real Wallet Drainer Scam Examples and How They Were Caught | ICAR Read More »

Wallet Drainer

How to Vet an Asset Recovery Firm Before Hiring | ICAR

Vetting an asset recovery firm before hiring one comes down to six checks: confirming what information they actually need from you, verifying their licensing and credentials independently, confirming the business itself is real and registered, understanding how they structure payment, asking what a realistic outcome looks like, and considering how they first made contact with you. This guide applies whether you’re evaluating a firm you found yourself or one that reached out to you and it’s worth applying the same standard to any firm, including ours. 66% Success rate of the FBI’s Recovery Asset Team in freezing funds on documented cases in 2024, processing over 3,000 requests and freezing $561 million — proof that legitimate recovery channels exist and work Source: FBI Recovery Asset Team, 2024 program statistics Check 1: What Information Do They Actually Ask For? A legitimate investigator working a fraud or crypto loss case needs specific documentation: transaction records or hashes, the wallet addresses or account numbers involved, a timeline of what happened, and any communication you had with the original scammer. What they should never ask for is your seed phrase, private keys, exchange account passwords, or remote access to your device or accounts. Any request for credentials that would give someone else control over assets you still have (as opposed to assets you’ve already lost) is a serious red flag regardless of how it’s justified. Check 2: Verify Licensing and Credentials Independently If a firm employs licensed private investigators, most jurisdictions maintain a public license database — in the US, this is typically run at the state level; New York’s Department of State license search is one example, and most other states maintain equivalent public tools. A real licensed investigator will provide license information upfront and won’t hesitate if you ask to verify it yourself. If a firm is affiliated with an attorney, every licensed attorney in the US is registered with a state bar association, and that registration is independently searchable. Beyond formal licensing, professional certifications relevant to fraud investigation and asset recovery  (Certified Fraud Examiner (CFE), Certified Anti-Money Laundering Specialist (CAMS), and similar credentials) are independently verifiable through the issuing body’s own certification lookup, not just a claim on a firm’s website. Ask for specific names and check them, the same way you’d verify a doctor’s board certification before a serious procedure. Check 3: Confirm the Business Itself Is Real Search for the firm’s actual business registration, not just its website. A legitimate firm has a real registered business entity, a genuine physical address (not just a virtual mailbox), and named team members whose professional backgrounds can be independently checked: a LinkedIn profile with a verifiable work history and industry connections is a reasonable, if not foolproof, signal, while a firm that lists no identifiable people at all is a meaningfully weaker prospect. Independent reviews on multiple platforms, not just testimonials curated on the firm’s own site, are also worth checking, keeping in mind that both glowing and harshly negative reviews can occasionally be fabricated in either direction. Check 4: Understand How Payment Actually Works Legitimate firms use standard business contracts and accept payment through conventional channels like wire transfer, credit card, check, or a retainer processed through a proper trust or business account. They do not ask for payment in cryptocurrency, gift cards, or other difficult-to-trace methods, regardless of how the request is framed,  a “blockchain activation cost,” a “tax clearance fee,” or a “processing fee” paid before any work begins are all versions of the same warning sign covered in our Recovery Scams Hub article. A large upfront payment demanded before any investigative work has started, particularly one paired with a guaranteed outcome, is one of the most reliable indicators of a fraudulent recovery operation. Legitimate firms may charge a retainer or work on a fee structure tied to actual investigative hours or milestones, but the structure should be transparent and explained clearly before you’re asked to commit. Check 5: Ask What a Realistic Outcome Looks Like No honest investigator, attorney, or firm can guarantee the recovery of stolen funds,  the outcome depends on where the money went, how quickly you’re acting, and whether the assets remain traceable at all. Anyone promising a specific percentage or guaranteed dollar amount back is telling you something false, full stop; this is one of the single most reliable tells across every version of this fraud. A legitimate firm will instead walk you through realistic probabilities, explain the actual forensic methodology involved (the tools and techniques used to trace fund movement) and be candid that outcomes vary considerably by case. It’s also worth understanding that recovery isn’t limited to a private firm’s own efforts. The DOJ’s Scam Center Strike Force, announced in November 2025, has seized and forfeited over $400 million in stolen cryptocurrency through coordinated federal action, and the FBI’s own Recovery Asset Team processed more than 3,000 requests in 2024 with a 66% success rate freezing funds on well-documented cases. A good private investigation often runs in parallel with these official channels, helping ensure your case reaches the right agencies with strong documentation rather than working as a total replacement for them. Check 6: How Did You Actually Make Contact? This is worth its own check because it’s such a reliable early filter. Legitimate investigators and firms generally don’t cold-call, cold-email, or send unsolicited direct messages specifically targeting people who’ve posted about a recent loss on social media or appear in a leaked victim list. If a firm reached out to you first, out of nowhere, referencing your specific situation, treat that as a reason for more scrutiny, not less, regardless of how professional the approach seems, and regardless of whether they reference a real, well-known agency or program by name. A Quick Vetting Checklist They ask only for documentation (transaction records, timelines, communications)  never seed phrases, passwords, or remote device access Licensing and professional certifications are independently verifiable, and they’re not defensive when you check The business has a real registered

How to Vet an Asset Recovery Firm Before Hiring | ICAR Read More »

Asset Recovery2

The Full List of Clone Firm Warning Signs | ICAR

A clone firm is a scam that uses a real, regulated company’s actual name, firm reference number, and branding to convince investors they’re dealing with a legitimate business and the UK’s FCA has reported over £78 million in losses tied to this specific tactic. This guide brings together every warning sign worth checking, organized by category, plus the single verification habit that catches nearly all of them. (This is a companion piece to our Hub article, Fake Trading Platforms & Forex/CFD Scams, and our Pillar guide, Investment Scams — The Complete Guide.) £78M+ Reported losses to clone firm investment scams in the UK, with reports continuing to rise year over year Source: UK Financial Conduct Authority / National Economic Crime Centre Website and Domain Warning Signs A domain that’s a near-identical variation of a genuine firm’s real URL: an extra letter, a hyphen, a different top-level domain (.net instead of .com) A domain registered very recently, despite the firm claiming years of operating history A URL that gets truncated on mobile, making a subtly altered domain harder to spot, always expand the address bar and read the full domain before entering any credentials Website content, testimonials, or “as featured in” logos copied directly from the genuine firm’s real site Contact Information Warning Signs A phone number, email domain, or postal address that doesn’t match what’s listed on the regulator’s own register, even if everything else looks identical An email address using a free provider (Gmail, Outlook) rather than the firm’s own domain, despite claiming to be a large regulated institution Contact details that work initially but become unreachable once you’ve invested, numbers that go straight to voicemail or ring out entirely Sales Conversation Warning Signs Unsolicited contact: a cold call or message you didn’t initiate, even if it references a genuine, well-known firm’s name Pressure to act quickly, framed around a limited-time rate, bonus, or exclusive opportunity A caller who directs you to a specific “verification” link rather than encouraging you to search independently Reluctance or evasiveness when asked direct questions about regulatory status, fees, or what happens in a losing month Documentation Warning Signs A firm reference number (FRN) that matches a real firm, but a service or product being offered that firm doesn’t actually provide Account statements or trading confirmations with formatting inconsistencies compared to the genuine firm’s known documentation style An offer to send scanned “proof” of authorisation rather than directing you to check independently on the regulator’s public register Payment Warning Signs A request to pay into an account under a different name than the firm you believe you’re dealing with Pressure to use cryptocurrency or an unconventional payment method rather than a standard bank transfer or card payment Any request for an additional payment (a “tax,” “compliance fee,” or “unlock fee”) before a withdrawal can be processed The One Habit That Catches Nearly All of These The FCA’s own guidance is consistent and specific on this point: always use the contact details shown on its Financial Services Register and Firm Checker tool, never the ones a firm or caller gives you directly. Navigate to the regulator’s site by typing the address yourself, search the firm’s name, and compare every detail (phone number, email domain, physical address) against what’s officially listed. A single mismatch on any of these points is enough reason to stop and independently verify before proceeding, regardless of how convincing everything else appears. This habit alone addresses the large majority of warning signs above, because nearly every category ultimately traces back to the same underlying gap: a detail that looks right on the surface but doesn’t match the regulator’s own record. Making independent verification (not verification through a link or number the firm supplies) a non-negotiable step before any deposit closes off most of this list at once. A Real Case: What This Actually Looks Like The FCA has publicly shared the account of a victim it identified as Janet, a finance officer from Chester who lost £40,000 to a clone investment firm. By her own account, she considered herself financially savvy and confident she could spot a scam, three-quarters of investors in the FCA’s own research say the same about themselves. After searching online for high-return bonds, she received a call the next day about a student accommodation investment. She found what appeared to be legitimate details about the company online, and everything seemed genuine, so she invested and invested again over the following months. It was only when she couldn’t reach the numbers she’d been given, which had gone dead, that she realized what had happened. What makes this case worth including isn’t anything unusual about it, it’s how ordinary the process was. Nothing about the initial contact or the company details looked obviously fraudulent, which is exactly the point of a well-executed clone firm operation, and exactly why independent verification against the regulator’s own register matters more than trusting how convincing an approach feels in the moment. The 2026 Evolution: AI Platforms and Phishing-as-a-Service The FCA’s most recent Warning List updates continue to flag two accelerating trends worth knowing about specifically. First, clone operations increasingly pair a stolen identity with AI-generated “trading platforms”, realistic dashboards, profit displays, and fabricated trading histories generated to look indistinguishable from genuine account activity, sometimes even allowing a small initial withdrawal to build trust before larger deposits are requested. Second, security researchers have documented the rise of “Phishing-as-a-Service” toolkits — pre-built clone-website packages that let operators with minimal technical skill quickly stand up a convincing fake broker site, which helps explain why the volume of clone firm reports keeps climbing rather than leveling off. What To Do If You Suspect a Clone Firm Stop all further contact and do not send any additional funds. Independently verify the firm through the regulator’s own Register or Firm Checker tool, navigated to directly rather than via any link provided to you. If you already sent funds by card, contact your card issuer about a chargeback as soon

The Full List of Clone Firm Warning Signs | ICAR Read More »

Clone Firms1

How the Receivership Claims Process Works | ICAR

The receivership claims process is the court-supervised system that distributes whatever assets remain after a Ponzi scheme collapses, and it typically unfolds in five stages: receiver appointment, asset freeze and investigation, a formal claims notice with a hard filing deadline called a bar date, claims review (including any clawback determinations), and finally court-approved distribution. This guide walks through each stage in the order it actually happens, using a real 2025 case to make the process concrete, plus a tax detail many victims never learn about until it’s too late to use. (This is a companion piece to our Hub article, Ponzi Schemes & High-Yield Investment Fraud Explained, and our Pillar guide, Investment Scams — The Complete Guide.) 2 Deadlines Real receiverships often set separate bar dates for individual claimants and government claimants — missing either one can mean forfeiting your claim entirely Source: SEC v. Legend Venture Partners receivership claims procedures, 2025 Stage 1: The Receiver Is Appointed When the SEC or another regulator files an enforcement action against a suspected Ponzi scheme, the court overseeing the case typically appoints a receiver (usually an experienced attorney or forensic accountant) to take immediate control of the entity’s assets, records, and operations. This appointment happens quickly, often within days of the initial complaint, specifically to prevent further dissipation of remaining funds while the case proceeds. From this point forward, the receiver, not the original operators, controls what happens to any remaining money. Stage 2: Asset Freeze and Investigation The receiver’s first job is to locate everything that can be recovered: bank accounts, real estate, vehicles, cryptocurrency, and any other assets connected to the scheme, sometimes across multiple states or countries. This stage can take months on its own, particularly when funds were moved through shell companies, offshore accounts, or crypto wallets designed specifically to obscure their trail. The receiver typically also investigates the full scope of the fraud (how many investors, how much was raised, and how funds actually moved) to build the factual record the rest of the process depends on. Stage 3: The Claims Notice and Bar Date Once the receiver has enough of a picture to proceed, the court approves a formal claims process, and notice goes out to known investors and other creditors. This notice sets a bar date, a hard deadline by which every claimant must submit a proof of claim form with documentation of their investment. Missing this deadline can mean forfeiting your entire share of whatever gets distributed, even if you’re a completely legitimate victim, which makes it one of the single most consequential dates in the entire process. A real 2025 case illustrates how this actually works in practice. In the SEC’s case against Legend Venture Partners, the court-appointed receiver’s approved claims procedures set two separate bar dates: one for non-governmental claimants and a later one for government claimants, each with a specific deadline time on a specific date. The notice also specified precisely who qualified as a “claimant” under the process, including anyone owed money for goods or services, loans, taxes, or other legal claims, while clarifying that investors holding an ownership interest in the entity itself would have their positions handled through separate investor statements rather than a proof-of-claim filing. This distinction between different claimant categories is common and worth reading carefully in the specific notice you receive, since the correct filing path differs depending on which category you fall into. Stage 4: Claims Review and Net Winner/Net Loser Determination Once the bar date passes, the receiver reviews every submitted claim against the entity’s own records  (bank statements, account records, and transaction histories) to verify the amounts claimed. This is also the stage where the receiver determines each investor’s status as either a “net loser” (someone who deposited more than they ever withdrew) or a “net winner” (someone who withdrew more than they deposited, meaning some of what they received was actually other victims’ money paid out as fake profit). Net winners can face a clawback claim requiring them to return some or all of their withdrawn “profit” back into the common pool for fair distribution among all victims, a mechanic we cover in more depth in our Ponzi/HYIP Hub article. This determination process can itself take considerable time, particularly in larger schemes with thousands of claimants and years of transaction history to reconstruct. Stage 5: Court Approval and Distribution Once claims are reviewed and any disputes resolved, the receiver proposes a distribution plan to the court, typically calculating each net-loser claimant’s share on a pro-rata basis, meaning proportional to their net loss relative to the total pool of recoverable assets and total net losses across all claimants. The court must approve this plan before any funds are actually distributed, and objections from claimants are typically heard during this stage. Distribution itself often happens in more than one round, as additional assets are recovered or litigation against third parties concludes over time. How Long Does This Actually Take? There’s no fixed timeline, and it varies enormously based on the scheme’s size, how many jurisdictions and asset types are involved, and whether litigation against third parties (banks, accountants, or others who may have facilitated the fraud) is part of the recovery effort. Smaller, more contained schemes can sometimes reach a first distribution within a year or two of the receiver’s appointment. Larger, more complex ones, particularly those involving international assets or extensive litigation, can take considerably longer, sometimes many years, before victims see any distribution at all. The Tax Detail Most Victims Never Learn About This is worth its own section because so few victims learn about it in time to use it well. Losses from a Ponzi scheme can often be deducted as a theft loss under IRC §165, which — unlike an ordinary investment capital loss — isn’t capped at the usual $3,000 annual limit that applies to capital losses. The IRS created a specific safe harbor under Revenue Procedure 2009-20 that simplifies this significantly for qualifying victims, generally allowing

How the Receivership Claims Process Works | ICAR Read More »

Receivership Claims1

Recovery Scams: When Fraudsters Target You Again | ICAR

A recovery scam is a secondary fraud that specifically targets people who have already lost money to an earlier scam, offering to recover the lost funds in exchange for an upfront fee that, once paid, simply disappears along with the “recovery agent.” The FBI’s 2025 Internet Crime Report recorded more than 10,500 recovery scam complaints totaling $1.4 billion in losses, including $540 million taken specifically from victims aged 60 and older, across 2,529 complaints. This is the fifth and final Hub article in our Investment Scams cluster, and in some ways it’s the most important one to read regardless of which type of scam you may have encountered, because recovery scams specifically target victims of every scam type covered in our other four Hub articles: cryptocurrency fraud, pig butchering, Ponzi/HYIP schemes, and fake trading platforms. (See also: our Pillar guide, Investment Scams: The Complete Guide, and our Hub articles on Cryptocurrency Investment Scams, Pig Butchering Scams, Ponzi Schemes & High-Yield Investment Fraud, and Fake Trading Platforms & Forex/CFD Scams.) $1.4B Reported losses to recovery scams in 2025 — fraudsters specifically targeting people who had already lost money once Source: FBI Internet Crime Complaint Center, 2025 Annual Report Why Recovery Scams Work So Well Recovery scams exploit a specific emotional and financial state that makes victims unusually receptive: someone who has just lost money is often desperate, ashamed, and actively searching for any way to undo what’s happened. A caller or message that arrives claiming to already know the details of the original scam, sometimes because the same criminal network sold that information, sometimes because the recovery scammer is affiliated with the original scam operation itself, feels credible precisely because it demonstrates specific knowledge a stranger shouldn’t have. The FTC has documented that scam operations frequently maintain what they internally call “sucker lists” (records of who has already paid, how much, and what pitch worked on them) which get sold, traded, or reused to run a second scam against the same victim, sometimes years after the original loss. This turns a single fraud into an ongoing cycle: the 2026 Identity Theft Resource Center Trends in Identity Report found that just over a quarter of identity crime victims were managing two or more incidents simultaneously. There’s also a psychological dimension worth naming directly. A person who has just been defrauded is frequently experiencing a specific kind of urgency that has nothing to do with the recovery pitch itself: the desire to fix the mistake before anyone finds out, before a spouse or adult child asks hard questions, before the financial hole becomes permanent. A recovery scam offer arrives at exactly the moment that urgency is highest, promising a way to make the whole thing disappear quietly and completely, which is precisely the emotional state that overrides the skepticism the same person might apply to almost any other unsolicited financial offer. How the Pitch Usually Works Recovery scammers typically make contact by phone, email, or text, identifying themselves as a law firm, a government agency, a financial regulator, or occasionally a cybersecurity or asset-recovery firm. The FBI has specifically warned that scammers produce documents on convincing law firm letterhead, claim affiliation with agencies like the Consumer Financial Protection Bureau, and reference real financial institutions by name to build credibility quickly. The pitch usually follows a consistent shape: they already know you lost money (sometimes with unsettling specificity about the amount or the platform involved), they claim to have identified where the funds went or secured a legal mechanism to recover them, and they need a retainer, processing fee, tax payment, or your banking details to “release” or “process” the recovered funds. Once paid, the retainer disappears along with the recovery agent, and the victim has now lost money twice to what may be the exact same criminal organization. The documentation these operations produce has grown notably more sophisticated. Fabricated case numbers, official-looking seals, and letterhead mimicking real government agencies or established law firms are now common enough that a document’s visual polish alone should never be treated as proof of legitimacy, genuine government correspondence rarely arrives as an unsolicited cold contact promising a specific dollar recovery in exchange for an upfront payment. How Recovery Scams Target Each Type of Original Fraud It’s worth being specific about how this plays out across the four scam categories covered elsewhere in this cluster, since the recovery pitch is often tailored to match the original fraud precisely. Following crypto investment fraud Victims of crypto scams are frequently approached by someone claiming to be a “blockchain recovery specialist” or “crypto forensics firm” who claims to have already traced the stolen funds and can recover them for a fee paid in cryptocurrency itself. Following pig butchering scams Victims of relationship-based scams are sometimes approached by someone posing as a victim advocate or a fellow victim who has “already recovered” their own funds and offers to connect the new victim with the same recovery contact, exploiting the same trust-building mechanism that made the original scam work. Following Ponzi/HYIP collapses Investors in a collapsed Ponzi scheme are frequently targeted by fraudsters posing as the court-appointed receiver or a law firm representing the receivership, requesting an upfront “processing fee” to release a claims-process distribution, a tactic that works precisely because a real receivership claims process does exist and does eventually distribute funds, making the fake version harder to distinguish from the legitimate one. Following fake trading platform losses Forex and CFD scam victims are often approached by someone claiming to specialize in regulatory complaints or chargebacks, offering to handle the entire dispute process for an upfront fee, even though (as covered in our Forex/CFD Hub) a legitimate chargeback dispute is something a victim can typically initiate directly with their own card issuer at no cost. The Particularly Cynical Twist: Impersonating Real Victim-Protection Programs One of the more troubling patterns the FBI has flagged is that fraudsters have begun impersonating the Bureau’s own legitimate victim-outreach initiative, Operation Level Up — the program that proactively identifies and contacts

Recovery Scams: When Fraudsters Target You Again | ICAR Read More »

Recovery Scam1

How to Reverse Image Search a Dating Profile Photo | ICAR

You can reverse image search a dating profile photo in under five minutes using free tools like Google Lens, TinEye, and Yandex, but in 2026, a clean result no longer tells you what it used to. AI image generators now produce photorealistic faces that have never been posted anywhere online, meaning there’s nothing for a reverse search to find, even when the profile is entirely fabricated. This guide covers the classic reverse-search process, the newer facial-recognition tools built specifically for this problem, and the video-call verification techniques that catch what image search alone can’t. (This is a companion piece to our Hub article, Pig Butchering Scams Explained, and our Pillar guide, Investment Scams — The Complete Guide.) 5% Report Rate Only an estimated 5% of romance scam victims report it, meaning the FTC’s yearly count likely represents a small fraction of actual cases Source: FTC romance scam reporting data, industry analysis 2026 Step 1: Screenshot the Photo Properly Save or screenshot every photo the person has sent or that appears on their profile, not just the main profile picture. Scammers often reuse a consistent set of images across multiple fake profiles, so checking two or three photos, not just one, meaningfully improves your odds of a match. Crop tightly to the face and upper body where possible; a clean, front-facing image returns better results than one that’s heavily filtered, cropped awkwardly, or taken from an angle. Step 2: Run a Standard Reverse Image Search Google Lens (upload the image directly at images.google.com or through the Lens app) is the most widely used starting point, and TinEye and Yandex’s image search are worth running as second and third sources, since each indexes a different slice of the web and can surface results the others miss, Yandex in particular has a reputation for stronger facial matching than Google Lens on certain image types. Upload the same photo to all three if the first search comes back empty; a miss on one tool doesn’t mean a miss everywhere. What you’re looking for: the same photo appearing under a different name, on a modeling or stock-photo site, attached to a news article, or flagged on a scam-reporting site. Any of these is close to definitive, a real person’s dating profile photo showing up as a professional stock image licensed for commercial use is not a coincidence. Step 3: Use a Dedicated Facial Recognition Search Standard reverse image search matches identical or near-identical files. Facial recognition tools like PimEyes and FaceCheck.ID go further, analyzing facial geometry (the distance between eyes, nose width, jawline shape) to find the same face even in a completely different photo, taken at a different angle or in different lighting. This matters because a scammer using a stolen identity often has access to multiple real photos of that person, not just the one they’ve reused, and a geometry-based search can surface those even when a standard reverse image search comes back empty. A note on using these tools responsibly: facial recognition search raises real privacy considerations, and reputable tools in this category position themselves specifically for personal-safety verification, confirming who you’re actually talking to, rather than surveillance of someone who hasn’t given you their photo directly. Use these tools only on photos sent to you directly as part of verifying an online relationship, not to search for or track someone who hasn’t shared their photo with you. The 2026 Problem: AI-Generated Faces Leave No Trail Here’s the wrinkle that’s changed this entire process over the past year or two: AI image generators can now produce a photorealistic human face that has never existed and has never been posted anywhere. A reverse image search, regardless of which tool you use, works by matching a file against an index of images that already exist online. A unique, never-before-posted AI-generated face simply has no origin to trace and no match to find. A completely clean result across every tool in this guide no longer proves the person is real. This means reverse image search needs to be paired with a second layer: recognizing the visual signature of an AI-generated photo directly. A few tells that still hold up reasonably well: AI-generated faces often show subtle asymmetry in details like earrings, glasses, or jewelry that don’t quite match between the two sides. Real people’s photo collections are messy: group shots, bad lighting, selfies from years ago, photos where they’re not looking directly at the camera, an AI-generated persona typically has only a small handful of flawless, professional-looking headshots and nothing else. And backgrounds in AI-generated images sometimes carry subtle distortions or textures that look slightly wrong on close inspection, even when the face itself looks convincing. Step 4: The Video Call Test If reverse image search comes back clean and something still feels off, the most reliable next step is requesting a live video call, but even this now requires a specific approach, since deepfake video filters have become sophisticated enough to convince a casual observer. During the call, ask the person to turn their head fully to the side, in profile; real-time deepfake filters frequently break down or glitch at extreme angles that the underlying model wasn’t trained to handle smoothly. Also ask them to wave a hand slowly in front of their own face, filter-based deepfakes often glitch or distort around fast-moving objects passing in front of the tracked face. Someone who refuses a video call entirely, or who always has a convincing reason it’s not possible right now  (a broken camera, a work restriction, being deployed overseas) is itself one of the clearest patterns covered in our : Pig Butchering Hub article, regardless of what any image search turns up. What a Clean Result Does and Doesn’t Mean A reused photo (found on a stock site, a different name’s profile, or a scam-report database) is close to definitive proof of a fake profile A completely clean result across every tool is reassuring but not proof because it’s consistent with both a real

How to Reverse Image Search a Dating Profile Photo | ICAR Read More »

Reverse Image Search

How to Check If a Crypto Wallet Is Linked to a Scam | ICAR

You can check whether a crypto wallet address is linked to a scam in about five minutes using free public tools, before you send funds, and sometimes even after, if you’re trying to understand where money you’ve already sent has gone. This guide walks through the exact steps: reading an address’s history on a blockchain explorer, cross-checking it against public scam-report databases, screening for sanctions exposure, and understanding what these checks can and can’t tell you. (This is a companion piece to our Hub article, Cryptocurrency Investment Scams — How They Work, and our Pillar guide, Investment Scams — The Complete Guide for Victims in 2026.) 3 Free Tools A blockchain explorer, a scam-report database, and a sanctions check — the three-step process covers most of what a pre-send screen can tell you Source: Chainabuse (TRM Labs), Etherscan, US Treasury OFAC Step 1: Read the Address’s History on a Blockchain Explorer Every cryptocurrency transaction is public, permanent, and viewable through a free blockchain explorer — Etherscan for Ethereum and ERC-20 tokens, Blockscout for several EVM-compatible chains, or Blockchain.com’s explorer for Bitcoin. Paste the wallet address into the search bar and you’ll see its full transaction history: how old the address is, how much has moved through it, and  critically, whether the explorer itself has applied a public label, such as “Phishing,” “Fake_Phishing,” or a scam-report tag contributed by the community. What to look for: an address created recently with a sudden spike in inbound transactions from many different sources is a common pattern for a scam collection wallet. A very old address with a long, steady, boring transaction history is generally a better sign, though not a guarantee on its own. Step 2: Cross-Check Against Public Scam-Report Databases Chainabuse, backed by blockchain intelligence firm TRM Labs, is a free public database where scam victims and researchers report wallet addresses, domains, and social handles tied to fraud. Search the address directly on chainabuse.com — if it’s already been reported, you’ll see the details other victims submitted, which can also help you recognize the broader scam pattern you may be dealing with. CryptoScamDB is a similar open-source database worth checking as a second source, and PhishTank is useful specifically if a website URL (rather than just a wallet address) is part of what you’re trying to verify. None of these databases has complete coverage  (a scam address that’s brand new may simply not have been reported yet) so a clean result on any one of them isn’t proof of safety on its own. Step 3: Check for Sanctions Exposure Separately from scam reporting, the US Treasury’s Office of Foreign Assets Control (OFAC) maintains a Specially Designated Nationals (SDN) list that includes specific cryptocurrency addresses tied to sanctioned individuals, entities, and state-linked hacking operations. Several blockchain explorers and screening tools automatically flag direct matches to this list. An address flagged here isn’t necessarily a scam targeting you personally, but it indicates a serious compliance and legal risk that should stop any transaction on its own. Step 4: Understand What ‘Proximity’ Means More advanced tools including visual tracing tools like MetaSleuth, or the professional-grade platforms investigators use, can show whether an address is a close number of “hops” away from a known hack, drainer kit, or stolen-funds cluster, even if the address itself has no direct report against it. This is a meaningfully deeper check than the free tools above provide, and it’s the kind of analysis that becomes necessary once real money is already at stake rather than during a quick pre-send screen. A practical way to think about hop distance: an address that received funds directly from a wallet already flagged for a hack is one hop away, and represents a serious red flag. An address that received funds from a wallet that itself received funds from a flagged wallet is two hops away — still worth caution, but meaningfully less certain, since legitimate funds and tainted funds do sometimes mix at exchanges and other high-volume destinations. Free tools generally show you zero hops (direct reports against the exact address) and one hop at most; multi-hop analysis is where professional tracing tools add real value beyond what a five-minute manual check can offer. A Worked Example Say you’re about to send funds to an address a new online contact has provided, claiming it’s their personal wallet for receiving a trading platform deposit. Paste it into Etherscan: the address was created eleven days ago and has received twenty-three separate incoming transactions from twenty-three different wallets, with almost nothing sent out. That pattern alone (a brand-new address rapidly collecting funds from many unrelated sources) is a strong behavioral signal on its own, independent of whether any explorer label or database report exists yet, since it resembles a collection wallet far more than a personal account. Search the same address on Chainabuse: no reports yet, because the operation may simply be too new. This is exactly the scenario where the address check alone isn’t sufficient — the transaction-pattern read from Step 1 is doing more work here than the database lookup in Step 2, which is why treating this as a single combined process, rather than a pass/fail on any one tool, matters. Watch for Address Poisoning One increasingly common scam tactic deserves specific mention: address poisoning, where an attacker sends a tiny, near-worthless transaction from a wallet address deliberately crafted to look nearly identical to one you’ve genuinely transacted with before, matching the first and last several characters, which is what most wallet apps display by default. The goal is that the next time you go to send funds, you copy the poisoned look-alike address from your transaction history by mistake, rather than typing or pasting the real one. Always verify the complete address, not just the first and last few characters, and consider using an address book or saved-contact feature in your wallet rather than copying from transaction history. This tactic has grown more common precisely because it doesn’t require tricking a

How to Check If a Crypto Wallet Is Linked to a Scam | ICAR Read More »

Crypto Wallet Scam

Fake Trading Platforms & Forex/CFD Scams Explained | ICAR

A fake trading platform scam involves a website or app that presents itself as a legitimate forex, CFD, or binary options broker while never executing real trades on a client’s behalf, or manipulating the trading software to guarantee client losses. The global forex market turns over more than $7 trillion a day, and that scale makes it an enormous target: the UK’s FCA maintains a daily-updated Warning List specifically because so many unauthorised brokers now operate, and the US CFTC runs dedicated advisories on binary options fraud because complaints have risen steadily as offshore platforms multiply. This article covers exactly how these platforms work technically, the specific tactic known as a “clone firm,” a 2026 case that shows even a real, verifiable licence number isn’t a full guarantee of safety, and what to do if you’ve been targeted. $7 Trillion The forex market’s estimated daily trading volume — the scale that makes it such an attractive hunting ground for fraudulent brokers Source: UK Financial Conduct Authority; industry volume aggregates, 2025–2026 How Fake Trading Platforms Actually Work The defining feature of this scam category is a dashboard that looks and behaves like a real trading platform without any of it reflecting genuine market activity. In the most basic version, deposits simply disappear — the “platform” was never connected to any market at all, and withdrawal requests are stalled indefinitely or denied outright, sometimes with a sudden “tax” or “compliance fee” demanded first. In more sophisticated versions, particularly with binary options, the fraud is built directly into the payout mathematics. The CFTC has documented platforms where the expected value of every trade is structured to be negative for the client regardless of outcome, the payout for a winning trade is deliberately smaller than the loss on a losing one, so that even a coin-flip-accurate trader loses money on average over time. Some platforms go further and manipulate the software itself to generate losing trades outright, or alter displayed prices so that a position that should have closed in profit is shown closing at a loss instead. A third variant sits in between these two: the platform does route some trades to real markets, often small, early ones, to build trust and produce genuine-looking statements, while quietly widening spreads, adding hidden fees, or requiring “liquidity provider” approval on larger withdrawals that never actually arrives. This hybrid version is harder to spot precisely because a portion of the early experience is real, which is exactly the point. How These Scams Have Evolved: From Cold Calls to Social Ads The underlying fraud hasn’t changed much in decades, but the distribution has. Where forex and CFD scams once relied heavily on cold-calling from offshore boiler rooms, most operations today build their initial contact through paid social media advertising, sponsored posts featuring convincing testimonials, or influencer partnerships promoting a platform’s “proprietary trading algorithm.” A prospective victim often discovers the platform through an ad that looks indistinguishable from a legitimate fintech company’s marketing, professional video production, a polished landing page, and social proof in the form of comments and testimonials that may themselves be fabricated or purchased. Once initial contact is made, whether through an ad click or a cold call, the sales process itself has become more structured. Account managers are frequently given scripts specifically designed to overcome common objections: concerns about the guaranteed-return language, hesitation around a large deposit, or a request to “think about it” and are measured internally on deposit conversion rates the same way a legitimate sales organization would track any other KPI. Recognizing that you’re being worked through a script, rather than having an organic conversation with someone who has your interests at heart, is itself one of the more reliable defenses available. Clone Firms: Wearing a Real Company’s Identity One of the most effective tactics in this category is what the FCA calls a “clone firm” — a fraudulent operation that uses the actual name, firm registration number, and address of a real, FCA-authorised firm to appear legitimate to anyone who does a basic search. A victim who checks the firm registration number will often find it matches a real, regulated company, because it does; the fraudsters have simply borrowed that identity wholesale, typically operating through a lookalike website or a slightly altered domain name. This is precisely why the FCA has built a dedicated verification tool that checks not just whether a firm registration number exists, but whether it’s actually connected to the entity you’re dealing with and the specific service being offered, because a clone firm will pass a naive “is this number real” check every time. The practical implication is that you should never navigate to a regulator’s verification page through a link the firm itself provided; always type the regulator’s URL directly or search for it independently, since a clone operation’s own website may link to a fabricated “verification” page designed to confirm whatever you’re hoping to see. A 2026 Case That Complicates the Standard Advice Most fraud-prevention guidance, including our own Ponzi/HYIP Hub article, centers on checking whether a firm or adviser is registered with the relevant regulator. That remains essential, but a 2026 enforcement action out of South Africa illustrates an important nuance: registration alone isn’t a complete safeguard. South Africa’s Financial Sector Conduct Authority provisionally withdrew the licence of a CFD broker operating under a real, verifiable FSP number, citing aggressive and manipulative high-pressure sales tactics, unauthorised advice, guaranteed-return promises, and inadequate risk disclosure. A second, related firm had been under investigation for months over similar conduct before its licence was pulled, despite trading under a number that would have passed a basic register check throughout that entire period. The lesson isn’t that regulatory verification is pointless, it remains the single highest-leverage check available, and the vast majority of fraudulent brokers fail it outright. The lesson is that a passing registration check should be the start of your due diligence, not the end of it. High-pressure sales tactics, guaranteed-return promises, and pushback against

Fake Trading Platforms & Forex/CFD Scams Explained | ICAR Read More »

Forex Scam1

Ponzi Schemes & High-Yield Investment Fraud Explained | ICAR

A Ponzi scheme is a fraud that pays returns to earlier investors using the deposits of later investors, rather than from any genuine profit, a structure that always collapses once new money slows down. In its fiscal year 2025 enforcement results, published April 2026, the US Securities and Exchange Commission reported pursuing multiple large-scale Ponzi and high-yield investment schemes, including one that raised over $770 million from roughly 2,700 investors and caused $400 million in losses, and another that took more than $140 million from around 300 investors. This article breaks down how Ponzi schemes and their modern cousin, the high-yield investment program (HYIP), actually work: the math that should raise a flag before you ever invest, how affinity fraud turns community trust into a weapon, and what happens legally once a scheme collapses. $17.9B Total monetary relief the SEC ordered in FY2025 across its enforcement actions — a record year, driven substantially by Ponzi and offering-fraud cases Source: US Securities and Exchange Commission, FY2025 Enforcement Results, April 2026 The Anatomy of a Ponzi Scheme Named after Charles Ponzi’s 1920s postal-coupon scheme and made infamous at scale by Bernie Madoff, the structure hasn’t changed in a century: money from new investors pays the “returns” promised to earlier ones, with little or no legitimate underlying business generating real profit. The scheme can run for months or years, Madoff’s ran for decades, as long as enough new money keeps entering. It collapses the moment withdrawals outpace new deposits, redemptions are frozen, or a regulator intervenes. What makes a Ponzi scheme durable, sometimes for years at a time, is that it doesn’t need every investor to believe in it forever, it only needs enough new deposits each month to cover that month’s redemption requests. Madoff’s scheme survived for an estimated two decades partly because it deliberately avoided the explosive, too-good-to-be-true returns of a typical HYIP, instead paying steady, unspectacular, believable numbers that never triggered obvious suspicion. That’s an important lesson on its own: a scheme doesn’t have to look flashy to be fraudulent. Slow, steady, and just slightly better than the market is sometimes the more dangerous version, precisely because it’s designed to avoid scrutiny. A high-yield investment program, or HYIP, is functionally the same fraud dressed in more modern language, typically an online platform promising fixed daily, weekly, or monthly returns from a vague strategy like forex trading, arbitrage, or “AI-powered” trading algorithms. HYIPs are especially common in crypto-adjacent spaces because cross-border crypto payments make both collecting deposits and disappearing with them faster. Both structures depend entirely on a mismatch investors rarely think to check: the promised return has no connection to any actual, verifiable trading activity. In a legitimate fund, you can typically request audited financials, a custodian statement from an independent bank or brokerage holding the actual assets, and a registered adviser’s Form ADV filing. In a Ponzi or HYIP scheme, at least one of those pieces is always missing, vague, or unverifiable; the fund administrator, the custodian, and the auditor are frequently one and the same entity, or don’t exist as independently checkable parties at all. Case Study Walkthrough: How the Heller/Prestige Scheme Actually Ran The SEC’s largest FY2025 Ponzi action is worth walking through in detail because the pattern is instructive well beyond this one case. According to the SEC’s complaint, Daryl Heller and his companies Prestige Investment Group and Paramount Management Group raised more than $770 million from approximately 2,700 investors between January 2017 and June 2024, telling investors their money would fund a network of ATMs that Paramount operated, with returns paid from ATM transaction fees. The pitch had surface-level plausibility that made it harder for investors to dismiss: ATMs are a real, understandable business, and a modest return from transaction fees sounds far more believable than a vague crypto trading algorithm. That plausibility is exactly what made it effective for seven years. What investors couldn’t easily verify was whether the actual number of ATMs, and their actual transaction volume, could ever have generated anything close to the returns being paid and, per the SEC’s complaint, it could not. The company allegedly used new investor funds to pay earlier investors’ returns, the defining Ponzi mechanic, for years before the scheme was charged. The takeaway for evaluating any investment pitch: a plausible-sounding underlying business is not the same as a verified one. If an opportunity is built around a real-world business: ATMs, real estate, a restaurant chain, equipment leasing, ask specifically how many units/properties/assets currently exist, request independently verifiable documentation (public records, satellite imagery, an on-site visit), and compare the stated revenue per unit against public industry benchmarks. A gap between the story and the checkable numbers is the same red flag whether the vehicle is crypto or vending machines. Warning Signs in the Marketing Materials Themselves Beyond the return itself, the way an opportunity is marketed often contains its own tells. Legitimate investment offerings are required to disclose specific risks, fees, and conflicts of interest in writing, disclosures that are often dense and unglamorous precisely because they’re legally mandated, not optional marketing copy. Fraudulent offerings tend to read the opposite way: heavy on lifestyle imagery and testimonials, light on risk disclosure, and vague about exactly which regulator, if any, oversees the offering. Marketing that emphasizes exclusivity or scarcity (“only accepting 50 more investors”) to discourage careful due diligence Testimonials and “as seen in” media logos that can’t be verified through the original source A registered agent or business address that resolves to a virtual office or mail-forwarding service An offering that isn’t registered with the SEC or your national regulator, or that claims an exemption without explaining which one A principal who deflects specific due-diligence questions with reassurance (“trust me, I’ve never had an unhappy investor”) rather than documentation Verifying an Adviser or Offering Before You Invest Every US-registered investment adviser has a Form ADV on file with the SEC, searchable free through the Investment Adviser Public Disclosure database: it discloses disciplinary history, fee structure,

Ponzi Schemes & High-Yield Investment Fraud Explained | ICAR Read More »

Sfcfy2025 1