This cluster centers on 3287 connected domains tagged as HijackLoader, RemcosRAT, screenconnect. 617 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1649 phone numbers (5408463620, 8552597377, 8007873903) with 7110 FTC complaints; 143 companies (Informative LLC, HomePlus Corporation, Doral Capital Corporation) with 8547081 CFPB complaints; 807 email addresses (kellymoore_64@yahoo.com, schantzsybg7@...
(530) 304-5825
Last reported Mar 20, 2026
- 1 community report from users
Campaign Intelligence
Details
Connected Entities
No known connections to other entities yet.
Community Reports
I received a text message from someone pretending to be my boss. They used my boss's real name and knew where I worked which made the message seem completely legitimate. The text said my boss was about to go into a presentation and urgently needed me to go to a nearby grocery store to buy celebration cards and gift certificate barcodes, promising to pay me back right away. Because the message appeared to come from my boss and they had specific details about my workplace I trusted it and went to the store right away. The scammer created a sense of urgency so that I would act fast without stopping to question or verify anything. I purchased a Microsoft Xbox gift card. After I bought it the scammer then instructed me to scratch off the back of the card and send them a photo of the card number and PIN. That is how they were able to immediately access and steal the funds. By the time my aunt recognized it as a scam and alerted me it was already too late and the funds had already been fully redeemed and used. The fraudulent text came from the number +1 (530) 304-5825 which appears to be a Northern California number. I contacted Microsoft however the scammer had already used all the funds by that point. I still have the physical card and my receipt as evidence. .css-1w6dufj{-webkit-box-flex:0;-webkit-flex-grow:0;-ms-flex-positive:0;flex-grow:0;-webkit-flex [BBB Scam Type: Business Email Compromise] [Business: Unknown] [Location: NY, USA- 10027]
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.
Proton VPN — Block malicious sites and encrypt your connection
Proton VPN routes your traffic through encrypted servers and blocks known malware domains. Free plan available.