LIVE NEWSROOM · --:-- · May 15, 2026
A LIBRARY FOR SECURITY RESEARCHERS

276 Arrested, 9 Crypto Scam Compounds Shut, $701M Seized in FBI-Dubai-China Operation

Post on X LinkedIn
276 Arrested, 9 Crypto Scam Compounds Shut, $701M Seized in FBI-Dubai-China Operation

A coordinated international law enforcement operation has arrested at least 276 individuals, dismantled nine scam centers, and seized approximately $701 million linked to cryptocurrency investment fraud targeting Americans. The operation was led by Dubai Police under the UAE Ministry of Interior, in partnership with the U.S. Federal Bureau of Investigation and China’s Ministry of Public Security, with support from Thai authorities.

// 01 What We Know So Far

The scam centers operated what the FBI terms “pig-butchering” schemes — a social engineering fraud pattern in which scammers invest weeks or months building fake romantic or friendship relationships with victims before steering them toward fraudulent cryptocurrency investment platforms.

The mechanics follow a predictable pattern: initial contact via social media or messaging apps, relationship building to establish trust, introduction of a “successful” investment tip, encouragement to deposit and grow funds on a platform the victim believes is legitimate, and ultimately the complete loss of all deposited assets when the victim attempts to withdraw. Platforms appeared to show growing investment balances and simulated trading activity, but the funds were under scammer control from the first deposit.

Victims were pressured to open cryptocurrency accounts, transfer existing assets, take out personal loans, and borrow money to increase their positions — all under the pretense of a time-limited opportunity. Once targets had committed maximum funds, the scammers went silent and withdrew everything.

Among those charged with federal fraud and money laundering crimes in San Diego are Thet Min Nyi (27), Wiliang Awang (23), Andreas Chandra (29), and Lisa Mariam (29), individuals from Burma and Indonesia apprehended through cooperation between Dubai and Thai authorities. Two co-conspirators remain fugitives.

// 02 The Scale of the Fraud and How FBI Operation Level Up Changed It

The FBI’s Operation Level Up, a proactive victim-identification initiative launched in 2024 as a San Diego and Phoenix joint effort, fundamentally changed the US response to crypto fraud. Rather than waiting for victims to report losses, Operation Level Up identifies potential victims before they have lost everything and notifies them directly.

As of April 2026, Operation Level Up has:

  • Proactively notified approximately 9,000 victims
  • Prevented an estimated $562 million in losses by alerting victims mid-scam before they transferred maximum funds
  • Supported the prosecution cases that ultimately led to this operation’s arrests

The combination of proactive victim identification with international law enforcement coordination represents a significant shift in how authorities approach fraud at this scale.

// 03 Who Is Affected

Pig-butchering schemes specifically target individuals who are reachable via social media, dating applications, and messaging platforms and who have disposable income or access to credit. Common contact vectors include LinkedIn (fake professional connections), dating apps, WhatsApp wrong-number introductions, and Instagram.

Victims are disproportionately concentrated in the US, Western Europe, and Australia. The scam compounds that were dismantled in this operation primarily operated out of Southeast Asia, particularly Burma, Cambodia, and the Philippines, where criminal organizations have exploited political instability and porous borders to establish large-scale fraud infrastructure. Many workers in these compounds are themselves trafficking victims coerced into running scam operations.

The $701 million figure reflects assets seized or frozen directly linked to these nine compounds. Total losses across the broader pig-butchering ecosystem globally run into the tens of billions annually.

// 04 What You Should Do Right Now

  • Recognize the pattern. Pig-butchering scams always follow the same arc: unexpected contact, relationship building, investment opportunity, pressure to increase deposits. Any unsolicited message that eventually leads to a cryptocurrency investment suggestion should be treated as high-probability fraud.
  • Do not deposit money on platforms you cannot independently verify. Any cryptocurrency exchange or investment platform should be independently searchable with a traceable regulatory registration. Unregistered platforms with high promised returns are the operating model of every pig-butchering operation.
  • Report suspected fraud to the FBI IC3. File a complaint at IC3.gov if you believe you have been targeted. Operation Level Up uses these reports; early reporting has prevented millions in losses for other victims.
  • Warn your organization’s staff. Business executives, HR professionals, and finance personnel are frequently targeted via LinkedIn with business relationship pretexts that eventually pivot to investment fraud.

// 05 Conclusion

This operation demonstrates that international coordination between the US, UAE, and China can produce meaningful enforcement outcomes against crypto fraud at scale. The 276 arrests and $701 million seized are significant, but Operation Level Up’s proactive $562 million in prevented losses may ultimately be the more replicable model for future enforcement strategy.

For any query contact us at contact@cipherssecurity.com

    TE
    Team Ciphers Security

    The Ciphers Security editorial team — practitioners covering daily threat intel, CVE deep-dives, and hands-on cybersecurity research. About us →

    Previous Microsoft April 2026 Update Intentionally Blocks psmounterex.sys — Backup Apps Break Next CVE-2024-57727: SimpleHelp RMM Path Traversal Fuels Ransomware Double-Extortion

    Latest News

    YARA-X 1.16.0: Faster Scans, Panic Fixes, and Neovim LSP Support YARA-X 1.16.0 ships with performance improvements across 10 PRs, constant folding for bitwise ops, configurable mat… Instructure Removed from ShinyHunters' Leak Site as Canvas Breach Deadline Passes Instructure was quietly removed from ShinyHunters' extortion site after the May 12, 2026 deadline — no data dump, n… Costa Rica Joins Have I Been Pwned as the 42nd Government Costa Rica's CSIRT gains free access to Have I Been Pwned's government domain monitoring service, becoming the 42nd… LummaC2 Infostealer Targets US Critical Infrastructure: CISA-FBI Advisory AA25-141B and DOJ Domain Seizures CISA and FBI advisory AA25-141B details LummaC2 MaaS infostealer TTPs targeting critical infrastructure. DOJ seized… MacSync Stealer: Hackers Abuse Google Ads and Claude.ai Chats to Push Mac Malware Russian-speaking attackers combine Google Ads and Claude.ai shared chats in a ClickFix campaign deploying MacSync S… JDownloader Site Hacked, Installers Swapped with Python RAT Malware JDownloader's website was hacked May 6–7, 2026, replacing Windows and Linux installers with a Python-based RAT. Use… Operation HookedWing: 4-Year Phishing Campaign Hits 500+ Organizations Across Aviation, Energy, and Logistics Operation HookedWing has stolen credentials from 500+ organizations in aviation, energy, logistics, and critical in… Twelve Critical vm2 Node.js Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution A dozen CVEs in the vm2 Node.js sandbox library — including CVSS 10.0 flaws — allow sandbox escape and RCE. Update …
    Scroll to Top