13th March 2026
When one lead becomes a global investigation.
Sometimes a case starts small, an email, a message. Something easy to ignore. And sometimes, that single thread unravels an operation spanning continents, criminal networks, and thousands of victims.
That was the tone for our latest webinar, OSINT Proven: Part 2. It wasn’t just another session on tools or techniques. It was a real-world look at what happens when open-source intelligence meets persistence, curiosity, and a willingness to follow the data wherever it leads.
Let’s walk through what happened, who led the conversation, and where we’re heading next.
So, who was in the room?
This session brought together a mix of practitioners and specialists who live and breathe investigations:
Toby Langston (Altia) – Guiding the session and framing the discussion around real-world investigative workflows
Dave Samson (Altia) – Adding context from an OSINT practitioner’s perspective
Larry Cameron (Paradigm Intelligence) – The driving force behind the case study; a cyber investigator with deep experience in OSINT, digital forensics, and human trafficking investigations
Larry’s background alone set the tone. From training law enforcement and special forces to working on anti-trafficking operations, he didn’t just present theory, he walked us through lived investigations.
And that matters because this wasn’t hypothetical.
What did we cover?
The entire investigation stemmed from a single email and one report. Something that could’ve been dismissed.
Instead, it turned into a multi-year investigation into “pig butchering” scams, a form of fraud where victims are groomed over time, often through romance or investment schemes, before being financially drained.
These scams aren’t just financial crimes. They’re tied to human trafficking operations, where individuals are forced to run scams under threat and abuse.
That shift, from fraud to exploitation, is what hit many attendees the hardest.
The anatomy of a modern scam operation
Larry broke down the structure in a way that felt uncomfortably familiar to anyone in financial crime:
- Front office: fake personas, social media outreach, victim engagement
- Back office: IT infrastructure, crypto wallets, laundering networks
- Trafficked workers: running scripts, managing conversations, often under coercion
It’s organized, it’s efficient, and frankly, it’s run like a business.
OSINT in action
This is where the session really delivered for investigators.
We saw how different intelligence disciplines came together:
- Social media intelligence (SOCMINT): identifying scam patterns and recruitment posts
- Geospatial intelligence (GEOINT): mapping compounds like KK Park and tracking device movement across borders
- Network intelligence: analyzing IP traffic, VPN usage, and infrastructure dependencies
- Blockchain analysis: tracing crypto wallets, identifying laundering pathways, and flagging malicious tokens
One particularly striking method involved geofencing entire border regions to identify illegal telecom connections, revealing how infrastructure was being routed to support scam compounds.
The scale is hard to ignore
If there was one recurring reaction in the chat, it was this: “I didn’t realize it was this big.”
We’re talking about:
- Hundreds of thousands of trafficked individuals
- Massive SIM card farms (hundreds of thousands seized)
- Billions in illicit financial flows
- Entire compounds built for fraud operations
And perhaps most concerning, evidence suggesting state-level awareness or complicity in certain regions.
The questions that sparked real discussion
The audience didn’t hold back and that’s where some of the best insights came out.
Question: “Where are victims being targeted?”
Answer: everywhere.
From Facebook and Instagram to WhatsApp, LinkedIn, and even random SMS messages. No platform is immune.
Question: “How do you protect yourself as an investigator?”
Answer: operational security, layered precautions, and sometimes accepting the risk.
Because when you’re exposing networks tied to billions of dollars, you’re not exactly invisible.
Question: “Can’t authorities just shut these operations down?”
Answer: It’s not that simple. Even when:
- Power is cut
- Internet lines are disrupted
- Infrastructure is seized
…the operations often resume elsewhere.
Why? Redundancy. Backup systems. Distributed infrastructure.
In other words, they’ve planned for disruption.
Question: “Is destroying infrastructure enough?”
Answer: Not really. As discussed, unless you target the people and financial networks behind the operations, the system rebuilds.
What does this mean for investigators?
This session wasn’t just about one case. It was a reminder of how investigations are evolving.
A few takeaways that stuck:
- Follow the data even when it gets messy
- Combine intelligence disciplines; don’t work in silos
- Think infrastructure, not just individuals
- Understand the human element behind digital crime
And maybe most importantly, sometimes the case you almost ignore is the one that matters most.
So, what’s next?
We’re continuing the conversation with our upcoming session – Paper to Proof: Building Evidence in Contract and Payment Fraud with OSINT.
This next webinar shifts focus slightly, from large-scale global fraud networks to something investigators face every day:
- Contract fraud
- Payment diversion
- Evidence building using open-source data
If the last session showed the scale of modern fraud, this one will focus on the process of proving it, turning scattered data into something that holds up in court.
Webinar Review
There was a moment in the webinar where someone said they’d never connected a random scam message to human trafficking before.
It’s easy to treat these things as separate problems, fraud over here, exploitation over there. But they’re not separate anymore. They’re connected.
And OSINT, when used well, gives us a way to see that connection clearly and act on it.
Find the right solution for your organisation.
Email us on: info@altiaintel.com
The leading global provider of intelligence and investigation software.













