The original scam was surprisingly simple.
A man living in the US saw an Instagram ad for a P2P currency exchange service. The exchange rate was around 2–3% better than the alternatives.
Nothing crazy. Just good enough to make the service look worth trying.
He clicked, started the exchange, and was asked to complete an AML check.
He connected his account, approved the transaction, and lost about $25,000.
A private cyber investigation team was then asked to find out what happened.
What followed was a useful lesson in how these scams actually work.
The slightly better price is deliberate
Most people imagine scammers making offers that are obviously too good to be true.
That isn’t always how it works.
In this case, the exchange rate was only slightly better. That made it look like someone had simply found a competitive service.
But if a company you’ve never heard of consistently beats every established competitor, there’s a reasonable question to ask:
What’s their business model?
“AML” can make a fake website look surprisingly real
The scam site didn’t just ask for money.
It asked for an AML check first.
That was clever because AML checks are something legitimate financial services actually do.
The problem was that the check was designed to lead the victim into authorizing a transaction.
The terminology was legitimate. The process wasn’t.
A genuine AML check is intended to establish where funds came from. It shouldn’t require you to send funds somewhere to prove they’re clean.
There wasn’t necessarily one person behind it
The investigation pointed toward a Drainer-as-a-Service operation.
That’s an important distinction.
Instead of a single scammer building everything himself, specialized groups can provide the infrastructure while affiliates handle promotion and victims.
The package can include fake websites, payment-draining tools, and management software.
The affiliate finds the victims and gets a cut.
Some publicly reported operations have paid affiliates as much as 80%.
That also means that tracing the Instagram advertisement isn’t necessarily enough. The advertiser may not be the person running the infrastructure, and the advertising account itself may have been paid for with a stolen card.
The investigation eventually found links to private communities and P2P traders who appeared to be involved in converting stolen money into cash.
Then came the interesting part: finding the ad
The investigators couldn’t simply open Instagram and search for the advertisement.
Instagram’s feed depends on who you are.
Country matters. Interests matter. Devices matter. Account history matters.
An investigator sitting outside the US might never receive an ad designed for a US user.
And scammers can make this even harder through cloaking, showing different pages to different visitors.
So the team essentially had to recreate the victim’s environment.
They created a fresh email address, maintained a consistent browser profile, used a US IP address, and needed a US phone number for Instagram.
A foreign number would have looked out of place. A physical US SIM would have been inconvenient to obtain abroad. VoIP numbers could be rejected, while public free numbers for SMS verification were unsuitable because anyone could see the codes.
A temporary US mobile number solved the signup problem.
After the account was created, the investigators behaved like normal users. They followed financial and investment pages similar to the ones associated with the victim.
Eventually, the P2P exchange ad showed up.
Finding the ad wasn’t enough
The team knew the advertisement might disappear at any moment.
So they preserved everything they could while it was still online: screenshots, IDs, URLs, timestamps, and hashes of the collected files.
Just as importantly, they avoided claiming things that the evidence couldn’t establish.
For example, two people using the same payment account aren’t automatically the same person. And someone who handled stolen money isn’t automatically guilty of the original theft.
That distinction matters if the evidence is eventually used by a lawyer, court, payment provider, or law enforcement agency.
The expensive tools weren’t the difficult part
Residential IPs, browser profiles, and even temporary US phone numbers were relatively easy.
The difficult part was making an investigative account look like a normal user for long enough to receive the right ad without getting banned.
There was no guarantee it would work.
And there is an awkward legal and practical detail: even a legitimate investigation can involve an account that violates a platform’s terms.
Finally, finding the scam doesn’t mean recovering the money.
A private investigation team can’t freeze someone’s bank account or issue a subpoena.
What it can do is collect evidence, report the scam, and give useful records to people who actually have the authority to take action.
For everyone else, the lesson is much easier.
If an unknown exchange offers a better rate than everyone else and then asks you to prove your money is legitimate by approving a transaction, don’t try to find out whether the deal is real.
Just leave.


