🚨 $64 Billion Scam Network Exposed Through OSINT
Those fake WhatsApp job offers aren't just stealing money, they're funding a $64 billion human trafficking operation.
A recent OSINT investigation using OSINT Industries exposed:
✅ 2 operators in Brazil identified
✅ 4 shell companies exposed
✅ Money laundering flows mapped through crypto
✅ Direct links to SE Asian torture compounds
📖 Read the full investigation: https://t.co/lRDup8LOhE
‼️ Meet the Chinese man who has sold over 6,500 counterfeit licenses to Americans and Canadians, making over $750k. He used more than 83 domains and multiple social media accounts to promote his services.
🚨 ForgeCraft: Unmasking a China-Linked Operation Selling Counterfeit IDs Across North America 🚨
A China-linked network selling counterfeit US and Canadian driver's license IDs and SSN cards via 83+ domains — generating $785K+ from 6,500+ fake licenses and 4,500+ unique buyers across North America — has been uncovered.
Controlled HUMINT traced the threat actor's exact geolocation and facial imagery to China. Backed by shell e-commerce fronts, social media ads, and covert shipping, the operation poses severe risks — potentially enabling fraud, trafficking, SIM swaps, and ultimately threatening U.S. national security — while offering actionable intelligence for disruption.
https://t.co/JJUbdwZFT6
https://t.co/jiWrtnIlgd
CloudSEK has uncovered a large-scale document forgery operation run by a threat actor based in China, selling fake driver's licenses and social security numbers (SSNs) to customers in the United States and Canada. The operation, called ForgeCraft, is based on more than 83 interconnected web domains and has generated an estimated $785,000 USD in revenue from the sale of more than 6,500 fake documents.
The fake documents are high quality, scannable, and equipped with security features such as holograms and UV markings to appear authentic. To evade detection, they are shipped via couriers such as FedEx and USPS in covert packaging that hides the documents inside boxes or other items.
The investigation identified a vulnerability that allowed the exfiltration of a database containing the personal information of over 4,500 buyers, including names, addresses, and payment details. The threat actor was located in Xiamen, Fujian, China, and their identity was confirmed through geolocation and a facial image obtained through an intelligence operation. A case study revealed that one buyer used 42 fake driver's licenses for transportation and logistics operations, highlighting how the documents are used for large-scale crimes that threaten national security.
https://t.co/o5NyB54GNl
#FakeIDs #CounterfeitIDs #Cybercrime #Fraud #IdentityTheft #ThreatIntelligence #DigitalRisk #NationalSecurity #ChinaLinked #ForgeCraft #UnderageAccess #SIMSwap #FinancialCrime
Credit CloudSEK
The 40 page long report attributes the individual behind the operation, exposes the infrastructure that enabled it, breaks down stealth packaging and delivery methods, analyzes the customer base, and provides evidence of real-world misuse of these DLs impacting national security.
At CloudSEK, we just dropped our latest research uncovering a large-scale operation run by a China-based threat actor producing and shipping counterfeit U.S. and Canadian driver’s licenses to buyers across North America.
Full Report - https://t.co/WwJBao1IxD
@FBI@NSAGov@CBP
The private Telegram group currently has around 80 members.
It’s maintained primarily by 5 key individuals:
• 1aCry (owner)
• Peter (manager)
• Max (admin)
̐• Melik (admin)
• Daniel (admin)
@soursecc @skocherhan@MichalKoczwara@malwrhunterteam@1ZRR4H On dropthefile[.]xyz from screenshot --> BODY_SHA1-HOST=8c51d0c0e8978f1c87918c4e5c9e958422c13715 has returned me a pretty good list of related|similar domains, so I placed all of them to "neutral "#fakeapp detection: https://t.co/KrkS5lu8Z3
@skocherhan@500mk500@skocherhan I found a few more infras similar to this. doesn’t look like APT36 infra - it's a different scam altogether where anyone can register on these portals and pay to generate fake Indian ID documents.
/dc.crsorgi.gov.in.verifycertificate.php.viewcarde[.]in
@500mk500