AIWAS
ServicesPricingKnowledge BaseBlogGet Started
Email Us At
Get Started
Home » Alerts & Business  »  $52.8 million seized from a Telegram marketplace that sold scammers their tools
The US seized $52.8 million from a Telegram marketplace where scammers bought money laundering services, stolen personal data and deepfake tools. Fraud has a supply chain, and that changes how you verify a payment.

$52.8 million seized from a Telegram marketplace that sold scammers their tools

On September 9, 2026, the US Treasury Department and the Justice Department took action against a store. Not a storefront you would stumble across, and not a dark corner of the internet that requires special software to reach — a marketplace that ran on Telegram, the ordinary messaging app, and sold the things scammers need in order to run scams.

According to The Record's report on the takedown, the Justice Department seized $52.8 million from 52 cryptocurrency wallets tied to the platform, which went by the name Xinbi Guarantee. What its vendors sold, in The Record's own words, was "everything from money laundering services to stolen personal data to deepfake technology."

That is the part worth sitting with, and it has nothing to do with cryptocurrency. The people trying to defraud your business are mostly not lone opportunists who happen to be good at lying. They are customers. They have suppliers. They place orders.

What happened

Every detail below comes from The Record, reporting on September 9, 2026, on the joint Treasury and Justice Department action.

  • The platform ran on Telegram and had been operating since 2022. Vendors advertised in channels, and buyers found them the way you would find any other seller in a group chat.
  • The Treasury Department sanctioned it. The same action also named Anwen Technology, a Cambodia-based company behind an app called XinbiPay, and SafeW Technology Co., which makes an encrypted messaging application. A sanction means US individuals and companies are barred from doing business with them.
  • The Justice Department seized $52.8 million from 52 wallets under a court-authorized warrant. Roughly $12 million of that was sitting in two wallets holding vendor payments, and was seized with the cooperation of Tether — the company behind USDT, the dollar-pegged cryptocurrency all payments on the platform were made in.
  • The Telegram channels themselves were seized. Jeanine Pirro, the US Attorney for the District of Columbia, said: "Yesterday, my office issued a signed warrant to seize the Telegram channels where these vendors conduct their business and hawk their service to scammers."
  • The United Kingdom had already sanctioned the platform in March 2026.

One note on numbers. Several outlets covering this action also published a figure for the marketplace's total lifetime transaction volume, and those figures differ from each other by billions of dollars with no explanation offered, so we are not repeating any of them. The $52.8 million seized is the figure the government acted on, and it is the only headline number here.

Fraud has a supply chain

Most business owners picture fraud as a person: someone clever, working alone, who picked your company. The more useful picture is a purchase order. Think about what a scam actually requires, and notice that each requirement was a line item on this marketplace:

  • Someone to target. Names, phone numbers, email addresses, job titles, sometimes account details. That is "stolen personal data," and a scammer does not have to steal it himself. He buys a list.
  • A way to sound and look real. A voice on a phone call, a face on a video call, a document that passes a glance. That is what "deepfake technology" means when it is sold as a product: software that produces a convincing imitation of a specific real person from samples of their voice or face.
  • A way to keep the money. Stolen funds are useless if they can be traced back and clawed back. "Money laundering services" is the step that moves the money through enough hands that it stops looking like yours.

The Record also reports the platform facilitated "pig butchering" scams. That is the industry's blunt term for a long con: a stranger strikes up a friendship or a romance over weeks or months, builds real trust, then steers the victim into an investment platform that does not exist. The relationship is the setup. The fake investment is the payoff. Victims are frequently business owners and retirees with money to move.

Security people have a name for this arrangement — crime as a service. It means the skills have been split up and sold separately, so that running a scam no longer requires being good at any of the individual parts. You need money and a Telegram account.

Why this matters to a business like yours

You are probably not important enough for anyone to build a custom attack against. That was always the quiet comfort of being a small or mid-sized company, and it is the part that has stopped being true — not because you got more interesting, but because the attack no longer has to be built. It is assembled from parts that are already for sale.

Four practical consequences for an owner:

  • Your data has resale value even if your company is small. Your customer list, your employee records, your vendor contacts — that is inventory for somebody's next campaign, and it does not have to be worth much individually to be worth stealing in bulk.
  • A familiar voice is no longer evidence. The call from "the owner" approving a wire transfer, the voice note from "the bookkeeper," the video call where your supplier's face appears — those can now be manufactured, and the tools to manufacture them are a retail product.
  • The badly written scam email is a thing of the past. Fluent, correctly formatted, context-aware messages are cheap to produce. Spotting typos was never a real defense, and now it is not even a weak one.
  • Speed is the whole game. Once a payment leaves, it enters a laundering pipeline built specifically to outrun recovery. Your window to stop a fraudulent wire is measured in hours, not days.

What to do about it

None of this requires new software or a security department. It requires a small number of rules that everyone who touches money follows without exception.

  1. Verify money on a number you already have. Any request to send funds or change bank details gets confirmed by calling the person back — on the number in your own records, never a number, link, or email address supplied in the message itself. This single rule defeats most of what is being sold on marketplaces like this one.
  2. Treat a change of bank details as the highest-risk event in your business. An email from a real supplier saying "we've changed banks, please update our details" is the most profitable fraud aimed at ordinary companies. It should always trigger a callback, and always to the old number.
  3. Stop treating voice and video as identity. Say it plainly to your team: hearing the boss's voice is not authorization. Agree on something a fake cannot supply — a callback, a second approver, or a shared detail that was never written down in an email.
  4. Require a second pair of eyes above a dollar threshold. Pick a number that fits your business. Every payment above it needs two people. Fraud that has to convince two separate people at once mostly does not happen.
  5. Know what personal data you hold and who can export it. Customer lists, payroll files, vendor records. If you cannot say who in your company is able to download all of it at once, that is the first afternoon's work.
  6. Turn on multi-factor authentication for email and banking. Most of these frauds start with someone reading a real mailbox and waiting for a real invoice to imitate. A second login step is the cheapest thing standing between them and that mailbox.
  7. Make urgency the warning sign, not the reason to hurry. "Today, quietly, before the deadline" is the pressure that carries the whole scheme. Any message that discourages you from checking with someone else is the message to check hardest.

If the money has already gone

Act the same hour, not the next morning.

  • Call your bank and use the word "fraud." Ask them to attempt a recall of the payment. Recovery odds fall sharply with every hour.
  • Report it. In the United States, the FBI takes reports of business email compromise and wire fraud at ic3.gov. File as soon as you know, not after you have finished investigating internally.
  • Keep everything. The original emails with their full technical headers, the invoices, the call records. That is the material investigators actually work from.
  • Tell your team the same day. The same fake supplier usually tries more than one person in the same company.

The rule worth keeping

A $52.8 million seizure is a good week for law enforcement, and it is not a fix. Marketplaces like this one are businesses, and businesses get rebuilt. The lasting lesson is not that one Telegram channel went dark — it is what the inventory list tells you about the person on the other end of your next suspicious email.

They did not have to be skilled. They bought the skills. So the message will be well written, the voice will sound right, the timing will be plausible, and none of that will mean a thing — because the only defense that keeps working is the slow, boring rule about calling a number you already had.

Source: The Record, "US disrupts Xinbi Guarantee marketplace used by cybercriminals," September 9, 2026.

More plain-language explanations of how AI and business systems help and hurt are in the AIWAS knowledge base, and short briefings are on X at @AIWASai.

Leave a Reply

Your email address will not be published. Required fields are marked *