Skip to content
All Case Studies
AdvancedOSINTFinancial FraudLink Analysis

The Shell Network: Unmasking a Financial Fraud Ring Through OSINT Link Analysis

A pattern of near-identical 'investment opportunity' pitches across social media led investigators to a network of 14 fake profiles, three shell domains, and a single reused image asset that broke the case open.

Background

Multiple victims filed complaints describing a nearly identical scheme: a social media profile presenting as a successful trader would build rapport over weeks before directing victims to a fraudulent trading platform. Because the perpetrators used only social media and self-hosted websites — no direct device seizure was initially possible — the investigation began entirely with open-source intelligence.

Evidence Seized

  • Screenshots and profile URLs submitted by seven victims
  • URLs of three trading-platform websites referenced in victim communications
  • Cryptocurrency wallet addresses used for victim deposits

Tools Used

  • Maltego (entity link analysis)
  • Reverse image search (Google Images, TinEye, PimEyes)
  • WHOIS history / DomainTools
  • Sherlock (username enumeration)
  • Wayback Machine (historical site snapshots)

Methodology

  • Catalogued each victim-reported profile's display name, handle, profile photo, and bio text into a structured spreadsheet as the seed dataset.
  • Ran reverse image searches on every profile photo; several resolved to stock photography or to unrelated real people whose images had been stolen — confirming the profiles were fabricated personas, not real individuals.
  • Used Sherlock to check whether the same handles appeared on other platforms, uncovering two additional profiles per persona that hadn't been reported by victims, each pushing the same script at different times.
  • Pulled WHOIS history for the three trading-platform domains; despite WHOIS privacy protection, historical records from before privacy was enabled showed a shared registrant email across all three.
  • Used the Wayback Machine to retrieve archived snapshots of the sites, revealing they had cloned page templates from a legitimate broker, with only the payment wallet addresses changed between iterations.
  • Built a Maltego graph linking personas → shared registrant email → domains → wallet addresses → deposit transaction clusters, visually surfacing that all three 'independent' platforms funneled to the same wallet cluster.
  • Documented every finding with source URL, access timestamp, and archived snapshot to preserve a defensible, citable evidence trail before the content could be taken down.

Key Artifacts Found

  • A single stock-photography image reused across four supposedly unrelated 'trader' personas
  • One registrant email address common to all three fraud-platform domains, recovered from pre-privacy-protection WHOIS history
  • A cluster of victim deposit transactions converging on two related wallet addresses within days of each victim's onboarding call

Challenges

  • Profiles and websites were taken down mid-investigation once the operators noticed victim complaints; having already archived pages via Wayback Machine and personal screenshots with hashes prevented total evidence loss.
  • WHOIS privacy protection initially masked the registrant; only historical (pre-privacy) records recovered from a third-party WHOIS history service closed that gap.
  • Maintaining OPSEC — investigators used a dedicated non-attributable research browser profile and sock-puppet accounts with no connection to their real identities to avoid tipping off the operators during reconnaissance.

Outcome

The consolidated OSINT report, including archived evidence and the wallet-transaction cluster, was handed to a financial crimes unit and used to support a cross-border asset freeze request against the linked wallet addresses.

Lessons Learned

Reused media assets (photos, page templates) are often the weakest link in an otherwise well-compartmentalized fraud operation. Archiving evidence the moment it's found is not optional — takedowns can happen within hours of a scheme being reported.

This case has been anonymized and fictionalized for confidentiality. Names, identifiers, and specific circumstances have been altered or composited; any resemblance to a real investigation is coincidental.