Skip to content

About

A live alert feed, not a history archive

Online fraud is fast, disposable, and industrial. The record that prevents a loss has to be published while the operation is still running — and has to be findable by someone who is thirty seconds away from paying.

Every modern scam relies on the same asymmetry: the person being approached cannot check the other side in the moment that decides the outcome. A trading platform with a live price ticker, a storefront with a full catalogue, a recruiter with a company logo, a courier notice with a tracking number — all of it can be assembled in an afternoon and all of it looks exactly like the real thing on a phone screen.

What makes it work at scale is disposability. Infrastructure is designed to be abandoned. A domain gets registered, pushed through paid advertising for a few weeks, and dropped the moment complaints start surfacing, while the same scripts, the same wallets, the same bank beneficiaries, and the same operators reappear on a new name days later. The website is a costume, not a business.

That is why identifiers matter more than brands here. A wallet address, a messenger handle, a beneficiary name, or a phone number is expensive to replace and tends to be reused across rebuilds. A domain name is cheap and gets replaced constantly. Search a brand and you will find nothing about a site registered last Tuesday. Search the wallet it asked you to pay, and you will often find the operation's entire history.

So this is built as a feed rather than an archive. Newest first, graded by severity, with every alert carrying the checkable identifiers alongside the narrative. The aim is narrow and practical: make the disposable-infrastructure strategy expensive by ensuring that any identifier an operation reuses is already documented, indexed, and one search away.

How alerts are built

01

Indicators, not accusations

An alert records what can be independently checked: when the domain was registered, which registrar and host it sits behind, where the product photographs originally appeared, which wallet or beneficiary received the funds, and the dates money moved. Anything resting on a single unverified account is labelled as a single unverified account.

02

Speed is the whole product

Online fraud operates on a timetable measured in weeks. A domain is registered, advertised hard, and abandoned before the first police report is filed. An archive that publishes months later documents history; a feed that publishes within days interrupts the operation while it is still taking money.

03

Findable at the moment of payment

Almost nobody researches fraud as a topic. They search one domain, one wallet address, or one handle in the two minutes before they authorise a transfer. Every alert is structured so that search resolves to the record, because that search is usually the last point where the loss is still preventable.

04

Correctable on the record

Grading a legitimate business as fraudulent causes real harm. Operators can submit documentation, and records that turn out to be wrong are re-graded as cleared or withdrawn with a dated public note explaining what changed. Corrections are published, not quietly applied.

What this is not

Not a law enforcement body

We hold no power to freeze funds, compel disclosure, or prosecute. Report to your bank first and then to your national fraud body — IC3 in the US, Action Fraud in the UK, your national police cybercrime unit elsewhere.

Not a recovery service

We never charge anyone who was defrauded and never offer to trace or retrieve funds. Every organisation that contacts you offering that after a loss is running the second stage of the same scheme.

Not a clearance register

An absence from this feed means nothing has been reported yet. New operations are new precisely because nobody has documented them. Verify independently regardless of what this or any feed says.

Categories we track

Six recurring structures. The stories change constantly; the mechanics almost never do.