From Deepfakes to WhatsApp: inside a $187 million investment fraud network
- Evelyn Carter

- 1 day ago
- 5 min read
Group-IB has analyzed two investment fraud models, GoldBull and CoinLure, that use deepfakes, social media advertising, WhatsApp, and fake investment platforms to manipulate victims. Infrastructure associated with CoinLure was linked to 208 domains, with Group-IB estimating the network’s revenue at more than $187 million. The activity is not associated with a specific CVE.
A transaction can be properly authenticated, executed from a legitimate account, and approved by the account owner - yet still be the result of a fraud scheme that began days or weeks earlier.
That is one of the most important findings in Group-IB’s research into GoldBull and CoinLure. Instead of relying on direct compromise of brokerage accounts or exploiting WhatsApp vulnerabilities, the operators build a chain of trust manipulation: deepfakes establish credibility, social media attracts targets, WhatsApp sustains engagement, and legitimate stocks or fake investment platforms are ultimately used to extract money.

How are GoldBull and CoinLure deceiving investors?
GoldBull manipulates victims into buying real shares through WhatsApp investment groups, while CoinLure directs victims to fraudulent cryptocurrency investment platforms. Both models exploit trust rather than relying primarily on direct system compromise.
Once inside the group, victims are contacted by someone posing as an “analyst” who instructs them to buy a small-cap stock listed on a legitimate exchange. Victims may even be asked to send screenshots proving that they completed the purchase.
At that point, the platform introduces additional requirements such as minimum balances, taxes, insurance charges, account upgrades, or compliance checks. Some victims are later targeted again by fake “asset recovery” services demanding advance payments.
What does the $187 million figure actually mean?
The $187 million figure represents Group-IB’s estimate of revenue generated by the broader fraudulent platform network associated with CoinLure. It is not a law-enforcement-confirmed victim loss figure.
That distinction is important when assessing the scale of the operation.
Using this information, Group-IB extrapolated the potential revenue generated across the broader cluster of 208 platforms and estimated the total at approximately $187 million. The figure should therefore be understood as a research estimate based on infrastructure analysis and on-chain activity, rather than a fully verified total of victim losses.
The share price later reached $27.87, representing a 12.4% increase, before falling to $14.27 — approximately 42.4% below the instructed purchase price. Group-IB assessed that coordinated capital of roughly $1.5 million to $3 million could potentially create meaningful price movement in a low-liquidity stock.
Indicator | GoldBull | CoinLure |
Initial contact | Deepfake ads, social media | SEO, advertising, relationship-building |
Main engagement channel | Fake investment websites and messaging | |
Trust mechanism | Fake experts, fabricated group members | Professional-looking websites, fake KYC and returns |
Financial mechanism | Purchases of real stocks | Cryptocurrency transfers |
Monetization | Generate buying pressure, then exit existing positions | Collect deposits and block withdrawals |
Notable scale | $1.5M–$3M of coordinated capital in the analyzed scenario | 208 domains, estimated network revenue above $187M |
Why do deepfakes and WhatsApp make these scams harder to detect?
Deepfakes are not the entire attack. Their primary role is to establish credibility during the earliest stage of the fraud before victims are moved into channels where attackers can maintain longer-term psychological pressure.
👉 For organizations assessing the broader security implications, IPSIP has also examined how AI can increase the realism and scalability of social engineering in its analysis of AI risks and social engineering in modern cybersecurity.
The FBI reported that complaints mentioning ramp-and-dump fraud increased by at least 300% in 2025 compared with 2024. These schemes commonly begin with advertisements or invitations to join an investment club before victims are moved onto secure messaging applications.
Meta also reported that WhatsApp detected and banned more than 6.8 million accounts linked to scam centers during the first half of 2025. This figure reflects scam activity on WhatsApp more broadly and should not be interpreted as meaning that all of those accounts were associated with GoldBull or CoinLure.
Where could Vietnamese businesses be exposed?
The risk extends beyond individual retail investors. Finance teams, accounting staff, treasury personnel, executives, and employees with authority to approve payments can all be targeted using similar impersonation techniques.
The challenge is that a fraudulent request can increasingly arrive with multiple signals that appear convincing: the correct face, a familiar voice, the expected sender name, and a plausible business context.
Organizations may also become the impersonated brand. Logos, executive identities, employee profiles, and corporate websites can be copied and reused to give fraudulent campaigns additional legitimacy.
👉 IPSIP Vietnam has previously examined this problem in its analysis of brand impersonation used for fraud and financial theft. CoinLure is particularly relevant to this risk because fraudulent website infrastructure can be duplicated and reused under multiple identities.
What should businesses do immediately?
The first priority is to stop treating a familiar image, voice, or messaging account as sufficient proof of identity. Requests involving money, sensitive information, or payment details should be verified through an independent channel.
Verify unusual payment, investment, or beneficiary-change requests through a separate communication channel.
Call back using a phone number that was independently verified beforehand, rather than one supplied in the suspicious message.
Require dual approval for high-value or unusual financial transactions.
Do not treat video, voice, or a live call as the sole authentication factor for sensitive requests.
Train employees to recognize deepfakes, social engineering, and unverified investment groups.
Restrict the ability of unknown users to automatically add employees to WhatsApp groups where operationally feasible.
Independently verify financial advisers, investment firms, and trading platforms before sharing information or transferring funds.
Preserve phone numbers, domains, wallet addresses, advertisements, and chat logs when fraud is suspected.
Contact the relevant bank, broker, or exchange immediately if a suspicious transaction has already occurred.
For organizations, security awareness programs should evolve beyond basic phishing education. IPSIP’s Cybersecurity Awareness Training covers phishing, social engineering, account protection, data security, and incident response scenarios that can help organizations build stronger verification habits.
What does IPSIP Vietnam’s cybersecurity perspective suggest?
Organizations may face direct financial loss, exposure of identity information, brand abuse, investigation costs, and reputational damage. Financial institutions also face the challenge of distinguishing genuine customer activity from transactions voluntarily approved after sustained manipulation.
Fraud detection should shift from asking only, “Is this transaction legitimate?” to asking, “Was the journey leading to this transaction abnormal?” Signals involving domains, devices, behavioral patterns, beneficiary accounts, cryptocurrency wallets, and threat intelligence become more useful when correlated.
👉 GoldBull and CoinLure highlight an important shift in fraud prevention: the final transaction can appear completely legitimate from a technical perspective even when the entire journey leading to it has been manipulated through social engineering.
For Vietnamese organizations, the priority should not be trying to visually identify every fake video or synthetic voice. Security programs should instead ensure that sensitive requests cannot succeed based on a single identity signal, require independent verification for high-risk actions, and train employees to respond appropriately when urgency and authority are being used against them. When fraud operates as a network, defense must look beyond a single message or transaction.
References
Group-IB - The Architecture of Deception: How a $187 Million Fraud Ecosystem Exploits Trust Across Australia and the United States, 6/5/2026.Group-IB — The Architecture of Deception
FBI Internet Crime Complaint Center - Fraudsters Target US Stock Investors through Investment Clubs Accessed on Social Media and Messaging Applications, 3/7/2025.FBI IC3 — Fraudsters Target US Stock Investors
FINRA - Investor Alert: Social Media ‘Investment Group’ Imposter Scams Continue to Rise, 9/12/2025.FINRA — Investment Group Imposter Scams
ASIC - ASIC ramps-up action to protect consumers from AI-powered online investment scams, 2026.ASIC — AI-powered online investment scams










Comments