Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake Cross-Border Remittance Company WhatsApp Business Scam: Impersonating Brand Customer Service to Induce "Unfreezing Fee" Payments

The victims are primarily cross-border e-commerce sellers, foreign trade salespersons, overseas study remitters, and ordinary users who frequently use cross-border remittances. Scammers exploit victims' blind trust in WhatsApp business verification badges and the anxiety triggered by "fund freezes." Victims generally exhibit a cognitive inertia of "believing the problem can be solved as long as they follow customer service instructions," lacking the steps to verify identities through official channels. When the other party sends forged business licenses and remittance voucher screenshots, many people assume that "the other party has shown credentials" and lower their guard, eventually transferring the "unfreezing fee" into a so-called "safe account" under pressure. After being scammed in the first step, some victims—e-ager to recover their losses—are subsequently induced to download remote control software, leading to bank card verification code leaks and having all funds in their accounts transferred out.

SCAM

Key Fields

FIELD STAMPS
IndustryE-commerce / Retail
RegionMulti-region(中国/东南亚)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The victims are primarily cross-border e-commerce sellers, foreign trade salespersons, overseas study remitters, and ordinary users who frequently use cross-border remittances. Scammers exploit victims' blind trust in WhatsApp business verification badges and the anxiety triggered by "fund freezes." Victims generally exhibit a cognitive inertia of "believing the problem can be solved as long as they follow customer service instructions," lacking the steps to verify identities through official channels. When the other party sends forged business licenses and remittance voucher screenshots, many people assume that "the other party has shown credentials" and lower their guard, eventually transferring the "unfreezing fee" into a so-called "safe account" under pressure. After being scammed in the first step, some victims—e-ager to recover their losses—are subsequently induced to download remote control software, leading to bank card verification code leaks and having all funds in their accounts transferred out.

骗局怎么运作

  • Step 1: Impersonating the Brand Identity. Scammers register business accounts on WhatsApp using the exact same profile pictures, names, and bios as target remittance companies, or purchase WhatsApp business verified "green check" badges through gray channels, or pose as "official customer service" via forged official website certificate screenshots. Subsequently, through LinkedIn, Facebook ads, Google keyword ad placements, etc., they publish "customer service WhatsApp numbers" or "exchange rate discount policies," attracting victims to proactively add them.
  • Step 2: Fabricating "Remittance Anomaly" Scripts. After a victim submits a remittance application on a legitimate remittance platform, scammers impersonate customer service to initiate private chats, claiming that "due to incorrect recipient information filled in by you, the funds have been frozen by regulatory agencies, and you need to add the operations specialist on WhatsApp for verification." During the conversation, they also send VBS documents containing macro code or malicious attachments disguised as "declaration forms," requesting victims to click to "activate the unfreezing process," laying the groundwork for subsequently implanting remote control tools.
  • Step 3: Inducing "Deposit" Transfers. The so-called "operations specialist" presents forged remittance company business licenses, legal representative ID cards, and "unfreezing notices" with official watermarks, demanding that victims transfer the "deposit" or "differential tariffs" in advance to designated personal bank accounts, repeatedly promising that "funds will be returned via the original route within 24 hours, otherwise the account will be permanently frozen." The scripts usually carry intense time pressure, forcing victims to complete the operation in a short time.
  • Step 4: Secondary Harvesting and Money Laundering. Once the victim transfers money to a personal account, scammers immediately disperse and transfer the funds quickly, or complete money laundering by purchasing gold, cryptocurrencies, or using "runners" for cash withdrawals. In some regions, scammers also induce victims to download remote control software such as AnyDesk or TeamViewer under the guise of "assisting with operations," tricking them out of bank SMS verification codes to directly log into the victims' online banking and plunder all remaining funds.
  • Step 5: Disappearance and Rebranding. After obtaining the stolen money, scammers quickly block the victim, deactivate the WhatsApp number, and delete all chat records. They then change the brand name and a batch of receiving accounts, set up "customer service" accounts in overseas disaster areas again, and continue to use the same script to find the next victim. Due to the special nature of cross-border virtual numbers and encrypted communications, victims often do not discover they have been scammed until weeks later through official channel verification, by which time the funds are already untraceable.

红旗信号(看到这些快跑)

  • 🚩 Any demand claiming that "remittance is frozen again, and you must pay an unfreezing fee/deposit" to release funds is a scam—legitimate cross-border remittance companies will never ask customers to transfer money to personal accounts.
  • 🚩 Customer service proactively adds you on WhatsApp and sends ".vbs", ".docm", or ".apk" attachments, or asks you to install remote control software such as AnyDesk or TeamViewer, which are classic phishing intrusion signals.
  • 🚩 The domain name of the sent link is extremely similar to the official domain but has extra characters or uses non-mainstream suffixes, such as "worldremit-secure.xyz" or "panda-remit.net", which will prompt you to enter your bank card number, payment password, or verification code upon clicking.
  • 🚩 The conversation features official-sounding scripts such as "due to your timeout operation, funds have been frozen by the Banking Regulatory Commission," combined with pressure urging you to "complete the transfer within 10 minutes, otherwise face permanent ban," creating a sense of urgency.
  • 🚩 The electronic business license or remittance voucher screenshots sent by "customer service" are blurry, and the recipient is an account under a personal name rather than a corporate public account, which does not match the publicly disclosed receiving information of the remittance company.

真实案例

  • In August 2026, a woman in Hangzhou received messages on WhatsApp impersonating cross-border remittance customer service. The scammer used her "abnormal remittance account" as an excuse to induce her to transfer money to designated accounts in multiple batches, resulting in a cumulative loss of approximately HKD 6 million. Hangzhou police cooperated with Shenzhen police to intercept 5.9 kilograms of gold purchased by the suspect at a Shenzhen gold shop and arrested the involved personnel on the spot (according to HK01 reports, personnel information has been desensitized). (Source: [https://www.hk01.com/%E5%A4%A7%E5%9C%8B%E5%B0%8F%E4%BA%8B/60320419/%E6%9D%AD%E5%B7%9E%E5%A5%B3%E5%A2%AEwhatsapp%E9%A8%99%E5%B1%80%E5%A4%B1600%E8%90%AC-%E8%AD%A6%E6%96%B9%E6%B7%B1%E5%9C%B3%E9%87%91%E8%88%96%E6%94%94%E6%88%AA5-9%E5%85%AC%E6%96%A4%E9%BB%83%E9%87%91%E6%8B%89%E4%BA%BA](https://www.hk01.com/%E5%A4%A7%E5%9C%8B%E5%B0%8F%E4%BA%8B/60320419/%E6%9D%AD%E5%B7%9E%E5%A5%B3%E5%A2%AEwhatsapp%E9%A8%99%E5%B1%80%E5%A4%B1600%E8%90%AC-%E8%AD%A6%E6%96%B9%E6%B7%B1%E5%9C%B3%E9%87%91%E8%88%96%E6%94%94%E6%88%AA5-9%E5%85%AC%E6%96%A4%E9%BB%83%E9%87%91%E6%8B%89%E4%BA%BA))
  • In July 2026, Taiwan police and Thai police joined forces to smash a telecom fraud call center in Cambodia controlled by Bamboo Union members. The gang impersonated multiple foreign exchange companies, defrauding victims using "cross-border investment returns + remittance freeze" scripts involving over NTD 200 million, leading to 20 arrests. Reports indicated that gang members specifically used WhatsApp to bulk-send "receiving account abnormal" phishing links, with victims spread across China and Southeast Asia (according to public reports by Taiwan media).
  • In July 2026, Malaysian police launched operations in Forest City and Gelang Patah, dismantling telecommunications fraud syndicate hideouts and arresting 335 people, including 309 Chinese nationals. Police reported that the syndicate targeted "specifically defrauding Chinese citizens," sending fake "cross-border remittance bills" and malicious links through instant messaging software like WhatsApp to induce domestic Chinese victims to transfer funds. A large number of operational mobile phones and bank ledgers were seized (according to reports by Malaysia's Oriental Daily and NetEase). (Source: [https://www.163.com/dy/article/L397F85L0556NLUM.html](https://www.163.com/dy/article/L397F85L0556NLUM.html))
  • In August 2026, Taiwan and Thai police joined forces in Cambodia to smash a telecom fraud call center controlled by Bamboo Union members. The gang impersonated multiple foreign exchange companies, committing fraud under the guise of cross-border investment returns combined with remittance freeze tactics, involving over NTD 200 million and resulting in 20 arrests. Gang members specifically used WhatsApp to bulk-send receiving account anomaly phishing links, with victims spread across China and Southeast Asia. (Source: [https://news.ltn.com.tw/news/society/paper/1739008](https://news.ltn.com.tw/news/society/paper/1739008))

Official Stance

  • The Embassy of China in Pakistan issued a statement on August 17, 2026, stating that Pakistani law enforcement agencies arrested 111 Chinese suspects in operations combating telecom fraud. The Chinese side explicitly expressed support for Pakistani law enforcement in accordance with the law, with zero tolerance for shielding criminals, while reminding overseas Chinese citizens not to participate in any form of telecom fraud activities (reprinted by Toutiao).
  • The Royal Malaysia Police disclosed on July 28, 2026, that during "Op Cyber Scam" operations carried out in Forest City and Gelang Patah, 335 individuals involved in fraud were arrested, including 309 Chinese nationals. Police specially reminded the public at the briefing not to easily trust messages demanding money transfers under the guise of "account freezing" or "customs detention" on instant messaging software like WhatsApp (reported by Malaysia's Oriental Daily).
  • Hong Kong police, in a joint operation with mainland police on August 16, 2026, targeted a WhatsApp fraud syndicate impersonating customer service of cross-border remittance companies, arresting a total of 17 people, including a Malaysian "runner," and seizing HKD 3.67 million in cash. Police reminded citizens at a press conference not to click links in unfamiliar WhatsApp messages, emphasizing that any demands for "unfreezing fees" are scams (reported by on.cc).

How to Protect Yourself

  • ✅ When receiving any private message from "customer service," do not reply immediately. Open the remittance company's official website or official app, use the in-site customer service window or official telephone callback to verify, and never use the numbers and links provided by the other party.
  • ✅ As long as a conversation includes demands to "transfer money to a personal account to unfreeze," immediately stop communication and report the number to WhatsApp. At the same time, take screenshots to save chat logs, transfer vouchers, and the other party's account information.
  • ✅ Never download or open any attachments sent by the other party (especially .vbs, .docm, and .apk formats), do not install remote control software such as AnyDesk or TeamViewer, and do not input URLs sent by the other party through your browser.
  • ✅ Enable "Two-Step Verification" in WhatsApp, periodically check "Linked Devices" to clear suspicious logins; once you discover your account has been compromised, immediately log out through official channels, contact your bank to freeze your accounts, and report the bank cards as lost.