This cluster centers on 1630 connected domains tagged as BABADEDA, pw-2026, wsh. The domains include storage.googleapis.com, cdn.discordapp.com, implementing-theft-metal-justin.trycloudflare.com, staying-heavily-meaning-blowing.trycloudflare.com, creations-venture-traditional-stainless.trycloudflare.com, arilprivate.storexyz.web.id, 206.123.145.26, 103.125.219.204, 45.87.43.154, 10cricofficial.com, justwatch.life, 195.16.44.75, advise-visual-playstation-closer.trycloudflare.com, 91.92.241.197, 61.160.213.179, 113.116.149.250, 114.252.224.245, 183.30.204.216, bursaelektriktamir.com, 147.124.212.141 and 1610 more. 112 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus.
Flagged domains in this cluster, storage.googleapis.com, cdn.discordapp.com, implementing-theft-metal-justin.trycloudflare.com, staying-heavily-meaning-blowing.trycloudflare.com, creations-venture-traditional-stainless.trycloudflare.com, arilprivate.storexyz.web.id, 206.123.145.26, 103.125.219.204, 45.87.43.154, 10cricofficial.com, justwatch.life, 195.16.44.75, advise-visual-playstation-closer.trycloudflare.com, 91.92.241.197, 61.160.213.179, 113.116.149.250, 114.252.224.245, 183.30.204.216, bursaelektriktamir.com, 147.124.212.141 and 92 more.
The connected infrastructure includes 705 phone numbers (5086371451, 2012011305, 3096844401) with 291 FTC complaints; 181 email addresses (online.motors@consultant.com, online-motors@consultant.com, ceo@cmhomewarranty.com).
Across all linked entities, consumers have filed 593 complaints with federal agencies.
Geographically, consumer complaints associated with this campaign are concentrated in Seattle, WA, Austin, TX, Santa Fe, NM, Huntington Beach, CA, Colorado Springs, CO. This regional pattern may indicate targeted operations or reflect where the scam has been most actively reported.
If you receive a call or text from any of these numbers, do not engage. Hang up immediately and do not call back. Never provide personal information or make payments to unknown callers. Do not click links to any of the flagged domains. If you have visited one, check your accounts for unauthorized activity and consider changing your passwords. Do not reply to suspicious emails or click any links or attachments they contain. Check the sender's domain carefully for misspellings or unusual variations. You can report suspicious contacts to the FTC at reportfraud.ftc.gov or to the FCC at consumercomplaints.fcc.gov.
This campaign was identified through automated analysis of FTC/FCC complaint databases, threat intelligence feeds, email threat intelligence and entity relationship mapping.