The Lisbon Crypto Recovery Ring
A network of "asset recovery" firms in Lisbon, Dublin, and Dubai that targets previous crypto-scam victims — charging upfront fees of 8-15% to "unlock" funds that never existed. 312 victims confirmed, $4.7M extracted.
An independent forensic investigation desk tracking scams, shell companies, and predatory schemes across borders. We open the files that institutions leave closed.
Each file represents months of document work, victim interviews, and cross-jurisdictional verification. We publish only what we can stand behind in court.
A network of "asset recovery" firms in Lisbon, Dublin, and Dubai that targets previous crypto-scam victims — charging upfront fees of 8-15% to "unlock" funds that never existed. 312 victims confirmed, $4.7M extracted.
Mass-mailed fraudulent inheritance notices across Germany, Austria, and Switzerland demanding "transfer fees" from elderly recipients. Forged seals, spoofed notary IDs, and a Bulgarian PO box network traced to Sofia.
14 LLCs registered in Delaware in 18 months, all sharing a Wilmington registered agent and three different signatories. Layered through Cyprus, then the BVI, then to accounts in Miami. $6.1M frozen by court order in August.
An active SMS campaign is impersonating HSBC fraud teams, directing UK customers to a cloned verification page hosted on hsbc-secure-verify.co (not affiliated). We have flagged the domain and shared indicators of compromise with the National Fraud Intelligence Bureau.
Read the full alert and IOC listDu Deceptions operates a distributed investigation model. We work alongside consumer-protection lawyers, forensic accountants, and academic researchers on six core tracks.
Deep-dive reconstruction of individual cases: tracing wire transfers, recovering correspondence, identifying mule accounts, and building evidentiary packets that prosecutors can actually use.
See casesWe crawl corporate registries in 19 jurisdictions and visualize beneficial-ownership chains to expose fraud infrastructure — the holding companies, nominees, and agents that keep scams solvent.
Read methodologyOur intake desk processes hundreds of new reports weekly. Threat patterns are deduplicated, classified, and escalated — the same intel that feeds our alerts page is shared with Europol and FTC liaisons.
View active alertsWe prepare evidence packages for public prosecutors, regulatory counsel, and class-action firms — translating messy financial trails into admissible exhibits, with chain-of-custody logs attached.
Meet the teamPlain-language explainers on common scam patterns, red-flag checklists, and recovery guides — written by investigators, not content marketers. Updated when new typologies emerge.
Browse the libraryA secure, encrypted channel for industry insiders — compliance officers, AML analysts, customer-service staff — to disclose fraud infrastructure without career exposure. PGP-encrypted, source-protected.
Secure submissionWe don't publish on tips alone. Every case file passes through a documented verification pipeline before it goes public.
A report enters our encrypted queue, is deduplicated against existing patterns, and assigned a priority score based on loss severity and pattern novelty.
We gather bank records, domain history, corporate filings, and victim correspondence. Interviews are conducted in writing first, then by secure call when warranted.
Each claim is corroborated by at least two independent sources — corporate registries, court records, victim interviews, or financial-trace data. Single-source findings stay internal.
The case file is published with a full evidence index, and the evidence packet is simultaneously referred to the appropriate public prosecutor or regulator.
Most fraud platforms either sell consulting hours or recycle press releases. We sit closer to the courtroom than the newsroom — and that shapes everything.
No affiliate links. No referral fees. Our operating budget comes from individual supporters and a handful of foundation grants — disclosed in the annual transparency report.
Weeks, sometimes months, between intake and publication. The alternative — racing to publish before evidence is solid — is how fraud narratives get weaponized against victims.
Every published case includes a numbered evidence index with copies of underlying documents, hashes where appropriate, and a chain-of-custody note. Replicable by any journalist.
Default setting is no attribution. Victims and whistleblowers choose how, when, or whether their name appears — and we do not publish identifiers that could re-identify them.
Identities are abbreviated or changed at the request of contributors. The substance is theirs.
I had given up on ever seeing a paper trail. The Du Deceptions team rebuilt the entire chain from one screenshot and a date. That packet is what my lawyer used to file.
We work with many self-styled fraud reporters. Du Deceptions is the only one that has ever sent us a verifiable evidence index alongside a press release. We treat their referrals as presumptively reliable.
What I appreciated most: they did not promise me anything. They told me the realistic recovery window, the realistic enforcement odds, and the realistic risks. Then they delivered on the realistic part.