This cluster centers on 3287 connected domains tagged as HijackLoader, RemcosRAT, screenconnect. 617 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1649 phone numbers (5408463620, 8552597377, 8007873903) with 7110 FTC complaints; 143 companies (Informative LLC, HomePlus Corporation, Doral Capital Corporation) with 8547081 CFPB complaints; 807 email addresses (kellymoore_64@yahoo.com, schantzsybg7@...
(888) 389-8100
Last reported Mar 20, 2026
- 1 community report from users
Campaign Intelligence
Details
Connected Entities
No known connections to other entities yet.
Community Reports
This operation relies on a "ghost hub" located at 85 Dunstall Hill, Wolverhampton, WV6 0SR. While this address is a small, two-story residential property, it is currently the registered headquarters for nearly 900 active UK Limited companies. This "mailbox factory" allows international criminal syndicates (primarily operating from Nigeria and Spain) to project a facade of UK-based legitimacy. ?How the Scam Operates ?The syndicate uses a network of companies registered at this address to perform different roles in a coordinated theft cycle: ?The "Payment Bridge" (e.g., Net Fusion Tech Services Ltd): This company (Company No. 16397389) acts as a financial gateway. The scammers hijack or create professional-looking webshops (often using hijacked German .de domains like richter-uhren.de). When a victim makes a purchase, the money is processed through this UK entity, making it difficult for European banks to claw back the funds. ?Logistics Manipulation (The FedEx Weight-Hack): The most dangerous aspect is the manipulation of shipping data. In a documented case involving an order for 1,000 kg (1 Tonne) of firewood/fuel, the syndicate used a logistics front to generate a FedEx label (Tracking: 888389810094). ?The Hack: The physical package sent weighed only 300g (containing conifer waste). ?The Deception: By injecting a fraudulent "Proof of Delivery" photo into the FedEx and PayPal systems, the scammers "prove" delivery to the victim's address. This defeats automated buyer protection, as the system sees a "successful delivery" for a 1-tonne order that was physically impossible. ?Diversified Fraud Portfolio: The same address at 85 Dunstall Hill hosts a variety of other suspicious entities that target different victims: ?Ghost Retailers: Companies like Grab N Go E-Commerce Ltd facilitate rapid-fire shop scams. ?Rigged Auctions: Bid &a [BBB Scam Type: Online Purchase] [Business: Netfusiontechservices.com Date Re
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.
Proton Pass — Unique passwords for every account
After a breach, reused passwords let attackers into your other accounts. Proton Pass generates and stores a unique password for each one.