Impersonation Scam: Cross-Border Remittance Companies Used to Hijack Accounts and Steal Funds
The primary victims are cross-border e-commerce practitioners, independent site sellers, and small-to-medium-sized foreign trade business owners. They rely heavily on WhatsApp for international client communication and fund settlement, often lacking suspicion toward business accounts with official blue checkmarks. Scammers exploit their desire for large orders and trust in business document formats, sending phishing files or Trojan scripts disguised as remittance vouchers near year-end or during settlement periods. Once clicked on a mobile device, victims lose account control, leading to the alteration of payment accounts and the theft of funds.
Key Fields
FIELD STAMPSWho Gets Targeted
The primary victims are cross-border e-commerce practitioners, independent site sellers, and small-to-medium-sized foreign trade business owners. They rely heavily on WhatsApp for international client communication and fund settlement, often lacking suspicion toward business accounts with official blue checkmarks. Scammers exploit their desire for large orders and trust in business document formats, sending phishing files or Trojan scripts disguised as remittance vouchers near year-end or during settlement periods. Once clicked on a mobile device, victims lose account control, leading to the alteration of payment accounts and the theft of funds.
骗局怎么运作
- Scam syndicates typically operate from luxury apartments or homestays in Southeast Asia, using WhatsApp Business to register and package themselves as official customer service numbers for cross-border remittance firms or major overseas clients. They leverage WhatsApp Business profile features to display fake official websites, emails, and company descriptions, sometimes even obtaining verification badges through illicit channels to appear legitimate.
- Scammers obtain contact information for foreign trade practitioners and e-commerce sellers through illegally purchased IoT SIM cards or black-market channels. They initiate contact on WhatsApp under the guise of inquiries or large-scale remittance settlements, sending enticing purchase intentions or fund liquidation confirmations to quickly build business trust.
- After establishing initial contact, scammers send VBS documents containing malicious macros or phishing links disguised as remittance vouchers. They claim the files must be opened to verify account information. Once the victim downloads and runs the file on their mobile device, a Trojan program is silently installed, granting the scammers control over the local WhatsApp session.
- Once the victim's WhatsApp account is hijacked, scammers immediately enable two-step verification and change the linked phone number, permanently locking the victim out. They then use the account to mass-send phishing links or loan requests to the victim's business contacts, exploiting existing trust to spread the scam and expand the victim pool.
- After gaining control, scammers review the victim's transaction history and payment records. They then impersonate the seller to notify overseas clients of a change in payment accounts. Unsuspecting clients then wire subsequent payments directly into the scammers' offshore bank accounts or third-party payment platforms, completing the theft of funds.
红旗信号(看到这些快跑)
- 🚩 Receiving unexpected large procurement inquiries or remittance notifications from an unknown business number on WhatsApp, especially those requiring you to click a link or download an attachment to view details.
- 🚩 Business documents received with a .VBS or other executable script extension instead of standard PDF or Excel formats, often prompting the user to 'enable macros' upon opening.
- 🚩 The sender is overly urgent about verifying remittance account information or frequently mentions large orders without providing specific business details or past collaboration history.
- 🚩 Your WhatsApp account is suddenly logged out, and upon attempting to log back in, you find that the verification SMS is required and the linked phone number has been changed without your authorization.
- 🚩 When dealing with a new contact, the provided file link redirects to an unfamiliar website that requests your WhatsApp or bank account login credentials.
真实案例
- Between 2024 and 2025, a court in Xiaoshan District, Zhejiang, sentenced 20 defendants in a cross-border telecom fraud case, all extradited from Malaysia and other locations. The syndicate operated from Southeast Asia, using WhatsApp and fake business documents to hijack accounts and steal funds from Chinese e-commerce sellers. The case involved over 10 million RMB, with one victim losing over 600,000 RMB in order payments.
- In 2025, major cross-border seller Huakai Yibai issued an emergency statement reporting that several employees and partners had been targeted by WhatsApp business document phishing. Scammers posed as overseas remittance agents, sending fake vouchers that induced employees to install Trojans on their phones. This nearly led to the diversion of hundreds of thousands of dollars in payments, which were only recovered after timely freezing of the accounts.
- According to public reports, Malaysian police dismantled two major telecom fraud syndicates in Forest City and Gelang Patah, arresting 335 individuals, over 90% of whom were Chinese nationals. These syndicates targeted victims in China by using WhatsApp Business to pose as financial service firms, using VBS phishing documents to hijack accounts and steal funds, with total losses reaching hundreds of millions of RMB.
- In December 2023, public security authorities in Nanchong, Sichuan, broke a cross-border 'pig-butchering' (sha zhu pan) telecom fraud case. The syndicate targeted domestic residents through dating apps to lure them into fake investments. 842 people were arrested, 439 were prosecuted, and 129 have been convicted, with over 6 million RMB in illicit funds recovered. (Source: https://m.mp.oeeee.com/a/BAAFRD000020231208885019.html)
- In December 2023, police in Huangshan reported a case where a woman in Tunxi District was induced by an online acquaintance to deposit 1.79 million RMB into an investment platform, only realizing she was scammed after police intervened. Simultaneously, Lanzhou police issued warnings regarding a 'new type of pig-butchering scam' where victims were induced to download a gold trading app and transfer millions of RMB that could not be withdrawn. (Source: https://m.mp.oeeee.com/a/BAAFRD000020231208885019.html)
Official Stance
- In November 2025, Huakai Yibai issued an emergency security statement via official channels, warning foreign trade and e-commerce practitioners to be vigilant against WhatsApp phishing attacks involving fake remittance vouchers and to avoid clicking on suspicious business documents.
- On July 28, 2026, Malaysian police in Johor, in coordination with the Commercial Crime Investigation Department, dismantled two transnational fraud centers in Forest City and Gelang Patah, arresting 335 suspects and confirming the group specifically targeted Chinese nationals for WhatsApp phishing scams.
- On August 1, 2026, the Xiaoshan District Court in Zhejiang, China, publicly sentenced 20 defendants for cross-border telecom fraud involving the use of messaging apps to steal funds. Officials urged foreign trade companies to strengthen security audits for online remittance links.
How to Protect Yourself
- ✅ Do not trust business documents sent by unknown numbers in foreign trade communications, especially VBS script files or Office documents requiring macro activation. Do not download or open them until their safety is verified.
- ✅ Enable two-step verification for your WhatsApp account and set a strong, unique password. Never enter your WhatsApp verification code on third-party websites to prevent remote account hijacking.
- ✅ Establish a strict dual-verification mechanism for any changes to payment accounts within your company. Any request to modify bank details via messaging apps must be confirmed through a pre-verified, dedicated phone line or video call.
- ✅ Regularly install system patches and use reputable antivirus software on mobile phones and office computers. Avoid downloading third-party applications that have not been security-vetted to prevent the silent installation of Trojans.