The Scam Center Strike Force seized 503 domains. The escrow file still needs a record.
DOJ's April action exposed the layers of scam-center fraud. For escrow, the work remains specific: record the source, open items and office decision.

On April 23, the Department of Justice announced an action against a set of scam-center operations that had reached into several layers of the same machine: recruitment, fraudulent investment sites, cryptocurrency money laundering and the people alleged to run parts of the operation.
The announcement included charges against two Chinese nationals, a seized Telegram recruiting channel, 503 fraudulent .com domains, coordinated Treasury sanctions and State Department rewards. DOJ said that the U.S. Attorney's Office for the District of Columbia, the Criminal Division and their partners had cumulatively restrained more than $700 million in cryptocurrency alleged to be connected to scam-center money laundering.
That is a meaningful enforcement record. It is not a new escrow rule, a payee-verification mandate or a reason to treat an instruction as settled because it looks familiar.
For the escrow office, the useful question is smaller: when an instruction changes, what did the office rely on before it acted?
What the April action actually reached
The DOJ release is worth reading for its shape, not just its numbers.
It describes a Telegram channel used to recruit people under false job promises into a Cambodian compound. It describes 503 .com domains presented as investment platforms. It describes the restraint, seizure and proposed forfeiture of cryptocurrency alleged to have moved through scam-center money laundering.
Those are different parts of one operating system. A person can be recruited into the work. A domain can make a false platform look ordinary. A wallet or account can receive the proceeds. The action was aimed at the infrastructure around all three.
The criminal charges are allegations. The restrained cryptocurrency is not the same as money returned to victims. The release says the Strike Force is pursuing forfeiture with the goal of returning funds where possible; it does not say the full restrained amount has been returned.
This article is limited to that April action. It does not assess the status of Executive Order 14390's internal deadlines or action plan.
The escrow parallel is not a shared platform
Escrow is not a cryptocurrency investment scam. A title company is not a scam compound. It would be careless to flatten those things into one story.
The parallel is narrower. A fraud operation often works by making an unfamiliar instruction look like it belongs inside a familiar process. A domain, a phone call, an account change or a copied signature can borrow the appearance of a real relationship.
At the desk, the officer is not deciding whether a foreign criminal organization exists. The officer is looking at one instruction, one source and one file.
The public enforcement action cannot answer whether the phone number used on that file came from a known source, whether the changed account instruction was compared with the prior record, or what remained unresolved when the office made its decision.
Those are not gaps that a press release fills after the fact. They are file-level questions before money moves.
A domain seizure is not a wire review
DOJ says the 503 seized domains were made to resemble legitimate investment platforms. Seizing those domains can remove infrastructure from a scheme and can make the public record more visible. It does not establish a federal callback procedure for escrow, define an acceptable source for payment instructions or impose a new private review standard.
The same limit applies to any broad enforcement announcement. It may be valuable context for an office's risk discussion. It is not evidence that an individual instruction was checked, and it is not an authorization to release a wire.
The FBI's business email compromise guidance makes the practical distinction well. It tells people to find a company's phone number independently rather than use a number supplied by a possible scammer, to examine email addresses and URLs, and to check changes in payment procedures directly.
That is guidance. It does not decide a file. An office still applies its own procedures, governing obligations and judgment.
What the file should carry instead
A changed instruction deserves a record proportionate to what changed. It does not need a dramatic narrative. It needs the work the office actually did.
- State the instruction that changed, including the prior version and the new one.
- Identify the source used for the follow-up. If the number came from the original file, record that. If it came from the message requesting the change, say that too.
- Record the contact attempt, the person reached and the date and time.
- Identify what remained open after the review.
- Name the reviewer and state the office action.
This record does not prove account ownership. It does not turn a federal enforcement campaign into a control standard. It gives the office and anyone reading the file later an honest account of what the office relied on.
That is the difference between knowing that a threat exists and being able to describe the work performed on a particular instruction.
Why the Strike Force's work still matters
The April release makes the scale of this problem harder to dismiss as a string of isolated messages. The operation described by DOJ involved recruitment, impersonation, web infrastructure, financial rails and coordination across agencies and private companies.
For an escrow office, that is context for taking a late change or a familiar-looking request seriously. It is not a reason to make a generic promise about fraud, or to imply that software decides what should happen to a wire.
The useful response remains concrete: identify the changed instruction, identify the source used to review it, record what remained open and record the office's decision.
Federal action can make the infrastructure of a scheme less available. The file has to show what the office did with the instruction in front of it.
— Sebastian Heyneman
Sources
- Scam Center Strike Force April 23 actions — Department of Justice
- Business email compromise guidance — Federal Bureau of Investigation
Boundaries
This is a dated reading of public sources, not legal advice. It does not say that a domain seizure establishes a wire-review standard, that restrained cryptocurrency has been returned to victims, or that the April action created a private escrow compliance duty. Veto records the office's review; it does not verify a payee, authorize a wire, clear fraud or decide what the office should do.
The office decides. Veto records the review.
See a sample Review Record.
One page showing what changed, what was checked, what stayed open, and who reviewed it.