The hardest fraud to stop is the one the customer wants to make. In 2025, investment scams were the largest fraud loss category in both Australia and the United States, roughly $8.7 billion combined, with Australian losses of $837.7 million across more than 481,000 reports, US losses of $7.9 billion, average individual losses above $10,000, and the over-65s carrying more than a quarter of Australia’s total. In almost every case, the victim authorised the payment, often over their bank’s warnings. At the transaction, there was nothing to refuse.
Behind aggregate numbers like these sit specific, organised operations, and Group-IB’s investigation of the ecosystem profiled two that show how the business works.
The first, tracked as GoldBull, runs pump-and-dump on real stocks. Deepfake advertisements impersonate financial professionals; deliberately short ad lifespans manufacture urgency; geo-targeted redirects route victims into WhatsApp groups run by a ‘head analyst’ persona who names a small-cap stock, a limit price, and a target.
Victims buy through legitimate brokerages with proof of purchase required. In one documented case, victims were instructed on 6 November 2025 to buy a NASDAQ-listed stock at $24.79 against a $29.00 target. The price peaked at $27.87, up 12.4% on 9 December, at which point the operators dumped their pre-positioned shares; the target was never reached.
By February the stock traded at $14.27, down 42% from entry, the victims holding the losses. The arithmetic scales frighteningly well: two or three WhatsApp groups of a thousand members generate enough coordinated buying to move a small-cap, and $1.5–3 million of victim capital per campaign.
The second, CoinLure, industrialised the fake investment platform. Victims arrive through SEO-optimised content, social advertising, or romance-scam grooming; they pass through fake registration, fake KYC, and trial-fund traps into tiered ‘investment plans.’
Withdrawals are then obstructed by script: minimum-balance requirements, ‘tax’ and ‘insurance’ fees of 10–30% of the balance, forced account upgrades, indefinite technical issues, and finally a compliance freeze. When the victim gives up, the same operators return offering fund recovery, for an upfront fee. Infrastructure analysis linked one confirmed platform to 208 domains across 23 shared templates with same hosting, same contact details and an estimated network revenue of $187 million.
Now the insight. Neither operation can be defeated at the payment, because the payment is the operation’s most defensible point: authorised, customer-insistent, often routed through legitimate brokerages and exchanges. But both operations are extraordinarily vulnerable one level up, because everything that makes them industrial also makes them networked. Shared hosting. Shared templates. Reused contact details. Reused wallets and beneficiary accounts. Repeating WhatsApp number patterns. Fraud at this scale cannot afford to be artisanal, and its economies of scale are its signature. Detect one node, run graph analysis, and the network surfaces: one confirmed CoinLure platform exposed the other two hundred and seven.
One impersonating advertisement exposed the full web of fraudulent ads, redirect URLs, and analyst personas. Automated takedowns then cut victim exposure from hours to minutes, merchant-blocking procedures follow with evidence attached, and, because cash-out ultimately passes through KYC’d exchanges, the transfer pattern hands law enforcement a direct path from stolen funds to identifiable persons. The scam economy’s greatest strength, scale, is a defender’s map.
There is a quieter signal too. Analysis of victim behaviour shows that customers being groomed by fake platforms measurably change how they use their real banking apps before the large transfers begin: unusual session time, changed patterns. Inside one bank, that is noise. Corroborated with intelligence that a specific scam network is active against that customer segment, it is a warning that arrives before the money moves.
Which raises the question every chief risk officer asks, and it is the right question: a scam network operates across dozens of institutions: can we see what our peers have flagged without breaking privacy law? For years, especially in North America, legal caution made the honest answer ‘no,’ and the result was paralysis: forty banks each seeing one-fortieth of the same operation.
What has changed is the architecture. A cyber-fraud intelligence exchange built on irreversible tokenisation, independently validated by Bureau Veritas as GDPR-compliant lets institutions share risk signals (is this beneficiary suspicious; has this device appeared in confirmed fraud) without customer data ever leaving the bank. Each institution decides what it shares. A peer’s flag arrives as corroborating input, weighted your way, not as an imposed verdict.
With more than 75 participants globally, the network already demonstrates the property that defines it: mule accounts being warmed up across several banks, invisible as anomalies inside any one of them, become visible as a pattern, and the receiving account of a scam payment is scored against the sector’s experience before funds settle. Its prediction window is the longest of any layer (weeks to months) because criminal infrastructure is detected during its warm-up phase, before the first transaction is ever attempted.

Fusion’s end-state architecture: capabilities on one data model inside the institution, extended across institutions by a privacy-preserving network layer.
Do this week. Put the network question on the agenda of your next fraud-vendor or consortium review, phrased exactly as the CRO asks it: how do we see what peer institutions have flagged: beneficiaries, devices, campaigns, without customer data leaving the bank? Any architecture that cannot answer with a concrete privacy mechanism, and any answer that requires you to accept another institution’s verdict rather than weigh its signal, has not solved the problem.
One Adversary is a five-part series on Cyber-Fraud Fusion. Each article stands alone; the full 90-day playbook is in part 5.





