The people who lost money are the easiest audience in this business, because their names and their amounts are already written down. The recovery offer is what gets sold to that list.
The call that comes after the loss
A reader in Ireland described the sequence on r/CryptoScams in August 2026. Someone rang him from a British landline, used his name, and said he was an officer of the Financial Conduct Authority. The caller said the stolen funds had been arrested and that more than 70,000 euro was coming back.
Then he sent his credentials. The reader looked them up online and the details matched. Over the following period he bought cryptocurrency and sent 10,333 euro to the caller, on top of what the first fraud had already taken. His own accounting puts the second loss at 12,293 euro.
"He was so convincing sending official emails etc. I'm so devastated." - the original poster, r/CryptoScams, August 2026
The replies did not treat this as unusual. One moderator noted that the pattern appears in the automated comment attached to every post in that subreddit. Another reader wrote that he had personally been approached by "at least 30 of these fake lawyers and recovery scammers". A third described it as the last step of the original scheme, which is closer to the truth than calling it a separate crime.
Why the person who already lost is the easiest target
Because everything a salesman normally has to guess is already written down. The first scheme collected the name, the messaging handle, the amount sent, the date it moved and the platform it moved to. That file has commercial value and it does not stay with one operator.
The FTC states the mechanism directly in its guidance on refund and recovery scams: operators buy lists of people who have already been scammed, on the expectation that they can be scammed again. The FBI's August 2025 alert on fictitious law firms lists the same tell from the victim's side. It describes contacts who have "knowledge of the exact amounts and dates of previous wire transfers and the third-party company where the victim previously sent scammed funds".
Read that as a warning and it inverts an instinct. A stranger who already knows your loss feels like someone who has been briefed by an investigation. In the documented cases, knowing your loss is the cheapest part of the approach, and it is the part that buys your attention.
There is a second reason the targeting works, and it is uncomfortable to write down. A person who has just lost money has a strong motive to believe the next message. The FBI's alert says as much, listing the exploitation of "victims' emotional state and financial need to recover funds from a previous scam" among the tactics. Nobody talks themselves out of hope while it is the only thing on offer.
Sounding official is a product, not a signal
Professional presentation is the cheapest input in the whole operation. Letterhead, a case reference, a call from a landline, a signature block, a PDF with an agency crest: none of these cost anything meaningful to produce, and all of them are produced by people who do this full time.
The FBI's alert describes what the finished article looks like: impersonation of real lawyers and real firms, plus "the production of fictitious documents with a legitimate law firm insignia or letterhead". Impersonating a firm that exists is the whole point, because it survives the one check most people run, which is typing the name into a search engine.
That is the trap in the Irish case. The credentials checked out because they belonged to somebody real. What could not be verified was the link between that real person and the voice on the phone, and that link is exactly the thing a search result never establishes.
The check that does work is boring and takes longer. Look up the organisation independently, through a search you started yourself, and contact it on the number published on its own site. Do not use a number, address or link that arrived in the message. Any genuine body will still be there when you call it back.
What the regulators say about themselves
Regulators are consistent on this and have been for years, because they are impersonated constantly. The CFTC's advisory on recovery frauds puts the boundary in one line: government agencies that prosecute financial fraud will never ask you for money, and they would only use ".gov" email addresses.
The FBI's version is the same rule from the law-enforcement side. If an unknown person contacts you claiming they can recover stolen cryptocurrency, do not send money and do not hand over financial or identifying information. Investigating a crime is not a service you are billed for.
The Irish case had a further problem that a caller counted on nobody checking. The FCA is a British regulator, it publishes a warning about fake FCA communications, and it has no jurisdiction in the Republic of Ireland at all. A body with no authority where you live cannot arrest anything on your behalf.
The shape of the scheme, in the words of the people who prosecute it
The CFTC classifies this as advance-fee fraud and defines it plainly: you are asked to pay upfront for the chance of getting a much bigger sum later. That definition is worth carrying around, because it does not depend on the story attached to it.
The story varies and the structure does not. The money you are told to pay is called a retainer, a tax, a bank verification fee, a customs charge, a compliance deposit or a gas fee. The FBI's alert notes payment demanded in cryptocurrency or prepaid gift cards, and claims that "payment of bank fees is required to verify identity and ownership to withdraw funds". The escalation is standard too: one fee is paid, and a second appears before the money can move.
Two other details from the same alert are worth recognising in advance. Victims get placed into a WhatsApp or messenger group chat for supposed secrecy, which isolates them from anyone who would ask an obvious question. And the operators claim to be working with, or acting on information from, a government agency, which borrows an authority they can never be asked to demonstrate.
This is the same funnel logic described in where signal scams actually make their money, pointed at a smaller and more valuable audience.
Why the first payment feels like it worked
Sometimes it does work, in the sense that something happens. A small sum arrives back, a portal shows a recovered balance, a document confirms a partial release. Each of these is cheap to produce and each converts a doubter into a participant.
That mechanism has its own article, because it is the same one that runs inside fake trading platforms: being paid once proves only that the payment was allowed. A balance on a screen is a number the operator typed. A small transfer is a marketing cost against a larger ask.
Apply the test that would have settled the original loss. Ask what the evidence would look like if the person were lying to you, and notice how much of what you have been shown looks identical under both explanations.
What is actually free, and where it goes
Reporting costs nothing, and it is the only part of this that has a real address. It rarely returns money and it should not be sold to you as if it might.
- The police where you live. A crime report with a reference number is what banks, exchanges and regulators ask for later.
- The national reporting route. In the United States that is the FBI's Internet Crime Complaint Center and the FTC's ReportFraud. Elsewhere, the equivalent national body, found through your own search.
- The exchange. If funds moved through a named exchange, its compliance team can act on an address while the funds are still there. Speed matters more than completeness in this one.
- Your bank or card provider. Fiat legs sometimes sit inside a dispute window that expires quickly.
Blockchain analytics is a real field, and firms in it do trace stolen funds. They work for law enforcement, exchanges and institutions, generally through a case that already exists. They do not find individual victims in a direct message, and a genuine engagement is not funded by an urgent crypto transfer from the person who was robbed.
The full first-response sequence, including what evidence to save before it disappears, is in what to do first after a channel scams you.
The rule that covers every version
Anyone who asks for money before returning money is running the same scheme as the first one. That single sentence covers the lawyer, the forensic firm, the regulator, the exchange security officer and the sympathetic fellow victim who knows a guy.
It holds regardless of how the request is framed, because the framing is the variable part. It also holds when the contact appears helpful, patient and free at first, since the fee arrives later by design.
The corollary is just as short. Nobody who contacts you first, after a loss, is helping you. Recovery, in the rare cases where it happens, moves through a bank, a court, an exchange or a criminal case, and none of those introduce themselves in a private message.
What we do not do
We do not recover funds, mediate disputes, hold money or refer anyone to a recovery service. We have no list of people who can get crypto back, and we would not publish one.
What a public record does is narrower. It keeps a channel's published calls and their outcomes somewhere the operator cannot quietly edit them, which is useful before a payment and only marginally useful after one. If you want the loss to be worth something to the next reader, the durable version is a specific, checkable account: dates, amounts, exact claims, and a clear line between what you saw and what you concluded. That format is set out in how to write a review that holds up.
One last thing about the tone people use with victims of this. In the thread that opens this article, several replies told the poster what he should have known. He had already been targeted twice by an industry with full-time staff, purchased victim lists and impersonated regulators. Reading the pattern before it arrives is worth something. Being told it afterwards is worth nothing at all.
Sources
On the pattern. The FBI's public service announcement Fictitious Law Firms Targeting Cryptocurrency Scam Victims (alert I-081325-PSA, 13 August 2025), opened and quoted directly. It covers knowledge of exact previous transfer amounts and dates, fictitious documents on real firm letterhead, WhatsApp group chats, and payment demanded in crypto or gift cards. The CFTC's advisory Don't be Re-Victimized by Recovery Frauds, opened and quoted directly: recovery scams as advance-fee fraud, and the rule that prosecuting agencies never ask you for money.
On victim lists. The FTC's guidance on refund and recovery scams states that operators buy lists of people who have already been scammed. The FTC's consumer pages could not be opened from the machine this article was written on, so the point is attributed and not quoted.
On the impersonated regulator. The FCA publishes a page on fake FCA communications. It could not be opened here either, and is cited as a destination.
Where to report. The FBI's Internet Crime Complaint Center and the FTC's ReportFraud, both opened. These are destinations and nothing here is quoted from them.
The case and the comments. The thread on r/CryptoScams, read in August 2026. The figures of 70,000 euro promised, 10,333 euro sent and 12,293 euro lost are the poster's own account and have not been independently verified.
What this does not establish. We hold no data on how often stolen crypto is recovered and offer no estimate. Nothing here is legal advice, and nothing here is financial advice.