How theScamWorks
Fake trading app · How it works

The Shop Window and the Till

Published 14 min read
Video: The Shop Window and the Till — 14:51. Watch on YouTube.

A fake investment site and the app it tells you to install usually have unrelated names. That is deliberate: the app can be killed without touching the website that recruits. In one FBI affidavit, 132 people reported the imitated broker's name, and none of them reported the website itself.

Key facts

1,969 mobile devices
Mobile devices recovered by the Royal Thai Police from the Shunda compound in Min Let Pan, Burma, and provided to the FBI, together with 68 desktop computers. The compound was taken by an armed group on 21 November 2025, and hundreds of workers fled into Thailand.
FBI affidavit, criminal complaint 1:26-mj-00017-MAU, U.S. District Court for the District of Columbia, filed 23 April 2026
$329,235.39
Sent in USDC on 7 March 2025 by one person in New York, who had been told a further deposit was needed to release a withdrawal. A line item in a spreadsheet recovered from the compound records the same person depositing approximately $329,062 on 8 March 2025. The FBI's affidavit reads the difference as fees taken in the middle.
FBI affidavit, criminal complaint 1:26-mj-00017-MAU, D.D.C., paragraphs 48-50
132 victims
Reports in the FBI's own complaint database referencing the name of the imitated broker, found when agents queried IC3 data. The affidavit adds that none of those reports specifically referenced the website that actually took the money.
FBI affidavit in support of a domain seizure warrant, case 26-sz-27, D.D.C., paragraph 70
one licence number, zero records
The licence number displayed at the bottom of the fake trading site, presented as proof of American regulation. Agents searched the regulator's own database for that number and confirmed no records existed for it.
FBI affidavit, domain seizure warrant, case 26-sz-27, D.D.C., paragraph 59
up to $10 million
Offered by the U.S. Department of State under the Transnational Organized Crime Rewards Program for information leading to the seizure or recovery of funds involved in money laundering related to the Tai Chang scam centres in Burma. The notice states that all identities are kept strictly confidential.
U.S. Department of State, Office of the Spokesperson, 23 April 2026
up to $4 million
Offered by the State Department on the same day as the $10 million notice, for information leading to the arrest of a money launderer who had already been convicted and sentenced in the Central District of California and remained a fugitive. Two notices, one day: a larger price on the money than on the man.
U.S. Department of State, Office of the Spokesperson, 23 April 2026
at least $10 billion
Lost by Americans in 2024 to scam operations based in Southeast Asia, according to a U.S. government estimate quoted by the Treasury when it sanctioned an armed group that hosts compounds. The same estimate records a 66 percent increase over the prior year.
U.S. Department of the Treasury, Office of Foreign Assets Control, 12 November 2025
five aliases, one location
The State Department's own fact sheet for the reward lists the target the way a wanted poster lists a person, except that the wanted is a place: a name, five aliases, and a location in Karen State, Burma. The same page records that Americans lost over $7.2 billion in 2025 to Southeast Asia-based scam operations.
U.S. Department of State, Bureau of International Narcotics and Law Enforcement Affairs, April 2026

The case

In March of 2025, someone in New York sent $329,235.39 to what they believed was an investment platform. They had been putting money into it since October of the previous year — roughly $2.1 million in all — and when they tried to take some out, they were told a further deposit was needed to complete the withdrawal. They sent it. Eleven days later they were asked for approximately $44,010 more, again to release funds that were already, on the screen, theirs. They sent that too.

Nine months later an FBI agent opened a spreadsheet that had come out of a building in Burma. One line on it recorded the same person depositing approximately $329,062 on 8 March 2025. A second line recorded approximately $43,990 on 19 March.

Close. Not the same. Both pairs are off by a small fraction — about $173 on the first, about $20 on the second — and the affidavit filed in the District of Columbia gives the agent’s reading of the gap in plain language: the difference in value “likely reflects fees paid to an intermediate money launderer,” and the difference in date reflects the FBI’s tracing being recorded in UTC while the compound’s records were kept in local time.

Somebody in the middle took a cut before the money reached the books of the people who stole it.

The spreadsheet exists because the building fell. On or about 21 November 2025, an armed group seized and took control of a compound called Shunda, in Min Let Pan, Burma. Hundreds of workers fled across the border, where Thai immigration authorities detained them. The Royal Thai Police recovered approximately 1,969 mobile devices and 68 desktop computers from the compound and provided them to the FBI, which interviewed approximately 18 former workers between 8 and 10 December 2025.

One of those desktops held a spreadsheet with a title in Chinese that translates as “Miracle Client Account Recharge.” In it, victims were listed by name, by description, by phone number, and by amount stolen. Approximately three of them were in the United States.

This article is not about the raid. It is about the question that the same set of filings answers and that almost nobody asks out loud: why the website that sold the investment and the app that held the money had nothing to do with each other.

How it works, step by step

1. The shop window copies a broker that exists

The site in this case imitated a real, regulated broker. We are not naming that company, and neither does the filing — it is a third party whose name was taken, and repeating it does the taking again. What matters is the shape: the fake name is a near-miss of a real one, close enough that a search for the real firm returns reassuring results and a person checks nothing further.

The borrowed brand is doing one job. It converts a stranger’s pitch into a company you can look up.

2. The licence number at the bottom of the page is a decoration

Near the foot of the site, in the place where regulated firms put their registration, was a licence number attributed to an American regulator. In November 2025, agents searched that regulator’s own database for the number and confirmed that no records existed for it.

The number was not wrong in a way you could see. It was simply a string of digits printed on a page, and the page was the only place it existed. This is why the check that works is never “does the site show a licence” — it is “does the regulator show the licence.”

3. The till is a different company

Here is the part that the regulators’ advice pages skip. The site did not take deposits itself. It offered apps for download — four of them, according to the seizure affidavit — and not one carried the site’s name or the imitated broker’s. They were unrelated words. A person who installed one of them was, from that moment, holding an app whose name had no connection to anything they could look up.

That is not sloppiness. It is the architecture.

An app can be reported and pulled from a store in days. A domain can be seized by warrant. Neither action touches the other, and when the names are unrelated, neither action even points at the other. Killing the till leaves the shop window open for the next person. Seizing the shop window leaves the till holding everybody’s balance.

4. And it works — here is the number that proves it

When agents queried the FBI’s own complaint database at IC3, they found approximately 132 victims reporting scams associated with websites and apps referencing the imitated broker’s name. The affidavit then records the detail that makes the whole design visible: none of those reports specifically referenced the site that had actually taken the money.

A hundred and thirty-two people told the federal government what had happened to them, and a hundred and thirty-two people named the wrong thing — because they named the thing they had been shown. The site’s own name, the string that would have connected their reports to each other, was never the thing they remembered dealing with.

Working the other way round — starting from the money rather than from the complaints — agents identified 21 potential victims of that site, and seven of them specifically mentioned it as the platform they had used. Seven out of twenty-one is what recall looks like when the shop window and the till carry different names. Eight of the identified victims had sent roughly $126,000 in bitcoin and ether to just two addresses.

Read the two figures together and the asymmetry is the whole point. Searching the database for the brand returns 132 reports that cannot be joined to a site. Searching the money returns 21 people, a third of whom can name the site. The design does not stop investigators. It stops the reports from finding each other, which is slower and cheaper and works on far more people.

5. The first withdrawal works

One victim described in the filings withdrew the $1,000 they had initially deposited. Over the following period they deposited approximately $70,000, and have been unable to withdraw since.

The small successful withdrawal is the most efficient sales tool in the whole operation, because it is the only moment at which the platform behaves exactly like a real one. It is also the cheapest: giving back a thousand dollars to secure seventy is a marketing cost.

6. Then the release fee, and then another

Once the balance is large enough, the withdrawal stops working and a reason appears. In the New York case the reason was an additional deposit of $329,235 required to complete the withdrawal. After that was paid, a second was required — approximately $44,010, described as securing the release of the funds.

There is no arithmetic under this. The number is chosen to be payable by someone who believes they are about to recover far more.

7. Nobody knows yet

The most uncomfortable line in the filings is not about money. Agents contacting people they had identified from the money trail recorded that every victim contacted regarding the site was not yet aware it was a scam. One of them had sent approximately $30,000 just two days before the FBI called.

The platform was still showing a balance. The balance was the product.

8. The person typing to you may not be free to stop

The same affidavit follows a man it calls Trafficking Victim 1. He answered a job offer in July 2023 and was taken to a compound called KK Park. In September 2025 he was moved to Shunda under armed escort. He is the reason there is a description of the inside of the building at all: he is the one who counted approximately four to five Starlink terminals on the roof.

This matters for a practical reason rather than a sentimental one. If the person at the other end of the chat is working under guard, then “catching him” solves nothing and removes nobody’s incentive — and the Treasury’s November 2025 sanctions notice, which designated the armed group hosting compounds in the area, records that soldiers have been filmed beating handcuffed scam workers. The people at the keyboards are replaceable, and are replaced. The brand, the domain, the app listing and the ledger are not.

That is the argument for going after the money rather than the man, and it is the argument the United States ended up making with a price tag attached.

Where does the money go after it leaves your wallet?

It is moved within minutes, and by the time anyone looks there is usually no balance left to freeze. The domain seizure affidavit records that in many instances the victim’s cryptocurrency was withdrawn and sent to new wallets within minutes — and that as of 9 April 2026 the addresses involved still did not hold any balance that could be frozen or seized.

So by the time a person realises, three things have already happened. The money has moved through intermediaries who took their fee on the way — that $173 gap is somebody’s wage. It has been recorded, line by line, in a ledger on a desktop computer. And it has become, on paper, the property of an operation sitting behind a wall in a territory where no American court order arrives.

That last fact is the one that reorganises everything else. Shunda sat behind a wall with a single gate, its connectivity supplied by satellite terminals on the roof rather than by any local carrier — investigators corroborated it with open-source Wi-Fi data from a Swedish app showing at least nine networks operating at the compound’s coordinates. There is no local registrar to serve, no ISP to subpoena, no landlord to compel. The building cannot be taken by law. It was taken, in this case, by an armed group in a war, and the United States got the computers afterwards because they crossed a border with the people carrying them.

What can be taken by law is the storefront and the records. The imitating domain was seized by the FBI on or about 2 December 2025 and still returns a seizure notice. A replacement domain, registered on 25 March 2026, was seized within a month of going up.

And then there is the price list. On 23 April 2026 the State Department published a reward of up to $10 million for information leading to the seizure or recovery of funds involved in money laundering related to the Tai Chang scam centres in Burma, with all identities kept strictly confidential. Not for an arrest. For the money.

On the same day it published a second notice: up to $4 million for information leading to the arrest of a launderer who had already been convicted and sentenced in California and remained a fugitive.

Ten million for the money. Four million for the man. The State Department’s own fact sheet for the first reward is laid out like a wanted poster whose wanted is a place — a name, five aliases, a location in Karen State — and it records that Americans lost over $7.2 billion in 2025 to Southeast Asia-based scam operations. The Treasury’s sanctions announcement from November 2025 puts the 2024 figure at at least $10 billion, a 66 percent increase over the year before.

Does raiding a scam compound shut the operation down?

No — it takes the building and the records, and the operation rebuilds somewhere else within weeks. This case ran that test.

After Shunda fell in November 2025, the managers left. Roughly eighty former Shunda workers moved together, then split into two groups. By the turn of the year the operation had been reassembled at Bokor Mountain in Cambodia, in a three-storey building organised exactly as the last one had been: the first floor for scamming operations, the second a dormitory for the workers, the third reserved for management. One of the men later charged was recorded arranging the purchase of approximately 160 phones for the new site, and noting that he had only about twenty workers and would need to hire more.

Six weeks. A different country, a different building, the same floor plan, and a shopping list.

The Royal Thai Police arrested two men on or about 21 January 2026. Approximately ninety phones were found at the safehouse. And the shop window had already been rebuilt too: the imitating domain seized in December was replaced by a fresh one registered on 25 March 2026, which the FBI seized within a month of it going live.

This is the whole reason the name-splitting matters. An operation whose identity lives in a building can be ended by taking the building. An operation whose identity lives in a rotating set of unrelated names — one for the shop window, another for the till, a third for the next shop window — survives the building by design. What it cannot easily survive is the record: the spreadsheet on the desktop that ties a specific deposit to a specific person on a specific day, which is the one artefact that does not regenerate when the operation moves.

That is also why the reward is priced the way it is. Arrests remove workers who were, in several documented cases, not free to leave. Seizures remove the thing the operation cannot rebuild from memory.

How do you spot a fake trading platform?

By checking two names and one number somewhere other than the page asking you to trust it. Each check below takes under a minute, and each has a counter-test you run somewhere other than the page you are suspicious of.

The app’s name has nothing to do with the site’s name. Counter-test: open your app store and read the listing title, then read the name on the site that sent you there. If they are unrelated words, that is the design described above, and it is the single strongest signal on this list.

A licence or registration number printed on the page. Counter-test: type the number into the regulator’s own database — Investor.gov and FINRA BrokerCheck for securities, the National Futures Association’s BASIC system for futures and forex, or your state securities regulator. Never the logo, never a PDF the site hosts, never a screenshot.

The store listing is new, thin, or absent. Counter-test: check the listing’s history and the developer name. A real broker’s app names the regulated entity somewhere on the store page.

A first withdrawal that worked. Counter-test: none needed — just know what it is. A small withdrawal that clears tells you about that withdrawal and nothing about the balance behind it.

A deposit required to release a withdrawal. Counter-test: stop. There is no regulated arrangement anywhere in which you must send money to receive money that is already yours.

The person who introduced you is unusually patient. Counter-test: count the weeks. Cultivation over a long period, with no pressure early, is the documented pattern of this category — it is the subject of our piece on how the relationship is built.

What to do if it already happened

Stop sending, including the release fee. Especially the release fee. It is the payment with the highest expected loss in the whole sequence, because it is the one made by someone who has already decided the money is recoverable.

Report it to ic3.gov, and report the strings, not the brand. The IC3 is the FBI’s intake, and reports there are the database agents actually query — in this case, a query of IC3 data is literally how investigators found the 132 reports. So give it the exact web address of the site, the exact name of the app, the wallet addresses you sent to, and the exact amounts and dates. The brand you believe you dealt with is the one detail that has already been shown not to connect anything.

Write down the ledger before you lose access. Amounts to the cent, dates, the wallet addresses, the app name, the name the person used with you. In this case the match between the victim’s records and the compound’s records was made on figures that differed by $173 — precision is what made the identification possible.

Assume the name you were given was not a person. The filings are explicit that the identity used with the New York victim was invented. Chasing it wastes the days that matter.

Never pay anyone who contacts you offering to get the money back. Recovery offers arriving after a loss are the second layer of the same trade. No legitimate party asks for a payment up front to recover funds.

If you have information about where the money went, there is a formal channel and it pays. The State Department reward described above is explicitly for information leading to the seizure or recovery of funds, and the notice states that all identities are kept strictly confidential.

How to not be next

The defence is not vigilance. It is two lookups, done somewhere other than where you were sent.

Look the licence up in the regulator’s database, not on the page that shows it. The page that shows it is the page you are checking, and in this case it printed a number that existed nowhere else in the world.

Compare the name of the app that holds your money with the name of the site that sold it to you. If they are unrelated, that is not a branding quirk. It is the seam the operation is built on — the one that lets the till survive the shop window and the shop window survive the till, and that made a hundred and thirty-two people describe the same crime to the FBI without any of their descriptions meeting.

Everything above comes from published federal court filings and government notices. Charges in a complaint are allegations, and every defendant is presumed innocent until proven guilty. No defendant is named here, and neither is the broker whose name was taken.

Questions people ask

Why does the investment app have a different name from the website?

Because the two are built to be separated. The website is the shop window: it carries the borrowed brand, the fake licence number and the sales pitch, and it is what a person remembers dealing with. The app is the till: it holds the balance and it is what takes the deposits. Giving them unrelated names means a takedown of one leaves the other standing, and it means that when victims report what happened, they report two different things that nobody joins up. An FBI affidavit put a number on how well that works: 132 reports named the imitated broker, and none of them named the site.

Is a trading app with a name unrelated to the broker always a scam?

No, and the check is quick rather than absolute. Large brokers do ship apps under a product name rather than the company name, and a few white-label platforms are sold to several firms at once. What separates them is verifiability: a real broker’s app listing names the regulated entity somewhere in the store page, and the regulator’s own database lists that entity. If the app name appears nowhere in the broker’s public filings and the licence number returns nothing in the regulator’s database, the mismatch has stopped being a branding decision.

How do I check a broker's licence number?

Look the number up in the regulator’s own database, not on the page that shows it. The page showing it is the page being checked, and in this case it was a forgery: agents searched the American regulator’s database for the number printed at the bottom of the site and confirmed no records existed for it. In the United States the databases to use are the SEC’s Investor.gov and FINRA BrokerCheck for securities, the National Futures Association’s BASIC system for futures and forex, and your state securities regulator. Type the number and the firm name in yourself.

My first withdrawal worked. Does that mean the platform is real?

No. The small successful withdrawal is a sales tool, and it is one of the most reliable signs that something is being sold to you rather than held for you. One victim described in the filings withdrew the $1,000 initially deposited, then put in approximately $70,000 over time and has been unable to withdraw since. Treat a first withdrawal that works as zero information about the second.

Should I pay a fee to release my withdrawal?

No. No regulated broker requires a new deposit before it will pay out what is already in your account, and the request is the point at which a loss turns into a larger loss. In the case described here, one person was told to deposit $329,235 to complete a withdrawal, sent it, and was then asked for approximately $44,010 more. Neither payment released anything. The money went into a ledger inside a building.

What happens to the money after it leaves my wallet?

It moves almost immediately, and it is usually gone before anyone looks. The affidavit for the domain seizure records that in many instances the cryptocurrency was withdrawn and sent to new wallets within minutes, and that as of April 2026 the addresses involved still held no balance that could be frozen or seized. Freezing money is a separate story with a separate mechanism, and it is covered in our piece on how stolen crypto gets frozen.

Do victims get their money back when a compound is raided?

Sometimes, slowly, and through a process that has nothing to do with the raid. Taking a building recovers records, not balances. Getting money to a person requires a court to forfeit it and an official to decide who receives it, which is a different pipeline with its own deadlines and its own paperwork. What a raid does produce is evidence that a specific person was robbed, and that has value of its own.

Where do I report a fake trading platform?

In the United States, the FBI’s Internet Crime Complaint Center at ic3.gov. Report the exact web address of the site and the exact name of the app, not only the brand you believe you were dealing with. That distinction is the whole lesson of this case: agents searching their own database for the imitated broker’s name found 132 reports, and none of them contained the string that would have led to the site taking the money.

  • Case

    The Line for the Money

    When the government seizes billions from a fraud, the victims are not the only ones in line. A live federal docket shows who else filed, and who goes first.

  • Government or police impersonation

    Four Callers, One Script

    The caller who tells you that you are a suspect is reading a script someone else wrote. A federal affidavit lays out all four of its phases, in order.

Sources

  1. FBI affidavit, criminal complaint 1:26-mj-00017-MAU, U.S. District Court for the District of Columbia (filed 23 April 2026) — the Shunda compound, the devices, the spreadsheet and the two deposits
  2. FBI affidavit in support of a domain seizure warrant, case 26-sz-27, D.D.C. — the storefront, the forged licence number, the four apps and the 132 reports
  3. U.S. Department of State, Office of the Spokesperson — reward of up to $10 million for information leading to the seizure or recovery of funds (23 April 2026)
  4. U.S. Department of State, Office of the Spokesperson — reward of up to $4 million for information leading to an arrest, published the same day (23 April 2026)
  5. U.S. Department of State, Bureau of International Narcotics and Law Enforcement Affairs — the reward fact sheet, laid out like a wanted poster for a place (April 2026)
  6. U.S. Department of the Treasury, Office of Foreign Assets Control — sanctions on the armed group hosting compounds, with the $10 billion 2024 estimate (12 November 2025)
  7. U.S. Department of Justice, Office of Public Affairs — the 23 April 2026 umbrella announcement of the Scam Center Strike Force actions