Fraud Ring Targets Crypto Users via Phone + Phish

About DFIR · High sophistication
Last updated August 18, 2026

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands, making the outreach feel legitimate by referencing real-looking case numbers and verification codes.

Key findings

  • The operation used an exposed Asterisk phone system to validate large volumes of phone numbers against cryptocurrency exchange accounts before targeting victims.
  • Confirmed crypto users were then approached with phishing emails, vishing calls, and fake wallet apps.
  • Attackers impersonated well-known wallet brands (Ledger, Trezor, Exodus) to increase trust.
  • Records were enriched so attackers could cite case numbers and verification codes to make calls sound legitimate.
  • The infrastructure spanned multiple countries; researchers notified hosting providers and Apple while parts were still active.

Who’s being targeted

  • Commonly targeted roles: All employees (general awareness), Finance, Executives, Anyone who holds/manages cryptocurrency, IT/Helpdesk (handling user-reported scam checks).
  • Affected industries: Cryptocurrency exchanges, Financial services, Consumers (crypto investors/users).
  • Attack channels: email, vishing.
  • Impersonated: Ledger / Trezor / Exodus (crypto wallet provider), Crypto exchange support or wallet provider support.

Awareness takeaways

  • Treat unexpected crypto ‘security’ emails and calls as high-risk, even if the sender/caller knows your phone number.
  • Be suspicious when someone references case numbers or verification codes to build trust, verify through official channels you initiate.
  • Do not install ‘security’ or ‘recovery’ apps from links in messages; only use official app stores and verified publishers.

Red flags to watch for

  • Unsolicited security outreach tied to crypto accounts
  • Pressure to install an app to resolve an alleged problem
  • Brand impersonation (Ledger/Trezor/Exodus) used to build trust
  • Caller uses ‘case numbers’/‘verification codes’ to create urgency and credibility
  • Unexpected call about crypto account access
  • Request to complete verification outside of the official app/site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

If you’ve got crypto, assume your number’s on a list. Researchers found a fraud ring using an exposed Asterisk phone system to test hundreds of thousands of numbers, then hit confirmed crypto owners with phishing emails, vishing calls, and fake wallet apps posing as Ledger, Trezor, and Exodus. Here’s the trick: you get a ‘Ledger’ or ‘Trezor’ security email, then a call that sounds legit because they drop a case number and a verification code, and push you to install a “recovery” app or follow a link to fix an urgent wallet issue. If you get any crypto ‘security’ email or call out of the blue, don’t tap links, don’t install apps, hang up and open your wallet or exchange app yourself to check for alerts.

Similar attacks

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026