Advance Fee Fraud

Advance Fee Fraud (also commonly known as a 419 scam) involves perpetrators who solicit victims with promises of large future returns, prizes, or other benefits if the victims first pay a series of upfront fees. Criminals typically contact targets through mass-marketing channels—such as emails, phone calls, text messages, or social media—and inject a sense of urgency or secrecy to pressure payment. Once victims provide these fees, scammers often demand additional sums by claiming unexpected problems have arisen, continuing until the victims recognize the scam or run out of funds. Global losses from advance fee fraud are estimated in the tens of billions of dollars, underscoring its considerable profitability and cross-border scope. After collecting illicit proceeds, perpetrators rapidly launder the funds through structuring or layering, often across multiple jurisdictions or via money mule networks, to obscure their origin. Victims are frequently reluctant or slow to report these scams, which hinders investigations and recovery efforts. Sub-variations include “Lottery Scams,” in which victims pay purported taxes or handling charges on nonexistent prize winnings, and “Timeshare Scams,” where owners pay upfront for fraudulent resale or exit deals. All rely on falsely promised rewards, anonymity in digital communications, and rapid fund movements through multiple accounts to evade detection.

[
Code
T0144.002
]
[
Name
Advance Fee Fraud
]
[
Version
1.0
]
[
Parent Technique
]
[
Risk
Channel Risk, Jurisdictional Risk
]
[
Created
2025-03-12
]
[
Modified
2025-04-02
]

419 Scam

Nigerian Letter Scam

Spanish Lottery Scam

Tactics

Advance fee fraud scammers solicit victims under false pretenses of lucrative returns or prizes, requiring upfront payments that directly generate illicit proceeds from unsuspecting victims. This is the primary objective of the scheme.

Risks

RS0003
|
Channel Risk
|

Criminals heavily rely on remote, non-face-to-face channels such as email, phone calls, and social media for mass solicitations. These methods leverage anonymity, making it difficult for institutions to verify or trace perpetrators in real time. This is the primary vulnerability that enables large-scale victim targeting and payment collection without direct interaction.

RS0004
|
Jurisdictional Risk
|

Perpetrators rapidly launder fraudulent proceeds across multiple jurisdictions, exploiting varied AML controls and regulatory gaps to obscure the origin of funds and complicate investigation efforts.

Indicators

IND02364
|

Multiple inbound transfers from unrelated individuals referencing 'advance fee' or 'deposit' with no documented goods or services.

IND02365
|

Rapid onward movement of newly received funds—often in small, structured amounts—to multiple external accounts, potentially across different jurisdictions, shortly after receipt.

IND02366
|

Frequent changes in customer contact information (email, phone) shortly after receiving multiple 'advance fee' payments.

IND02367
|

Inconsistent or vague explanations provided by the account holder regarding the purpose of recurring 'advance fee' payments from multiple payers.

IND02368
|

Funds disbursed to multiple newly established or unverified entities lacking operational history soon after receipt of 'advance fees.'

IND02369
|

Account receiving large numbers of 'advance fee' deposits from individuals across different regions, inconsistent with the stated business profile.

IND02370
|

Multiple inbound payments referencing lottery winnings, inheritance claims, or timeshare fees from unconnected individuals, with no supporting official documentation or legitimate business evidence.

Data Sources

  • Aggregates publicly available data (websites, social media, official announcements) on purported lotteries, timeshares, or inheritance processes.
  • Assists in verifying whether advertised schemes are genuine or part of advance fee fraud by uncovering discrepancies or confirming there is no legitimate underlying entity.
  • Provides comprehensive records of financial transactions, including timestamps, senders, recipients, amounts, and references.
  • Enables detection of repeated 'advance fee' references, multiple small inbound transfers from unrelated parties, and rapid onward structuring of received funds—hallmarks of advance fee fraud.
  • Captures user authentication events, IP addresses, timestamps, and changes to account settings (e.g., email, phone).
  • Allows detection of unusual or repeated contact detail updates following large inbound 'fee' payments, a common indicator in advance fee fraud schemes.
DS0033
|
|

Contains information on known or suspected fraudulent activities (e.g., scam phone numbers, email addresses, and patterns) specifically associated with advance fee fraud schemes. Financial institutions can cross-reference suspicious incoming payments or customer profiles against documented scam indicators, thereby enhancing the detection and investigation of potential 419 or lottery scam transactions.

  • Stores verified customer identity details, addresses, and transactional risk profiles.
  • Facilitates the detection of suspicious account behavior tied to advance fee fraud, such as sudden changes in contact information or inconsistent explanations for frequent incoming 'advance fee' payments.
  • Contains details on cross-border transfers, including involved jurisdictions, currencies, and settlement processes.
  • Helps identify international layering or rapid fund displacement associated with advance fee fraud proceeds, particularly when scammers move victim payments offshore quickly to evade detection.
  • Provides origin and destination geolocation details for financial transactions.
  • Exposes irregular cross-regional inbound deposits labeled as ‘advance fees,’ helping to flag potential international or multi-regional scam activity.
  • Contains official incorporation and ownership details, allowing for the verification of newly formed or suspicious entities receiving funds.
  • Identifies shell or unverified companies frequently used to launder or redirect proceeds from advance fee scams, assisting in tracking ultimate beneficiaries.

Mitigations

Implement targeted monitoring rules to flag repeated inbound transactions referencing 'advance fees,' 'lottery winnings,' 'inheritance claims,' or 'timeshare fees' from multiple individuals or geographies, followed by rapid onward transfers. These specific rules highlight potential advance fee fraud activity and prompt timely investigation of accounts receiving or moving scam proceeds.

Provide targeted alerts, educational materials, and proactive outreach to warn customers about common advance fee scam tactics, such as unsolicited promises of large returns if fees are paid upfront. Encourage customers to verify requests and notify the institution when approached with such schemes to reduce unwitting participation in 419 fraud channels.

Use external data sources, public records, and media reporting to identify known advance fee fraud rings, flagged contact information, or suspicious domains. Cross-check inbound or outbound transactions referencing these details to confirm authenticity and disrupt potential scam networks.

Restrict or freeze accounts identified as repeatedly facilitating advance fee scams by imposing transaction limits or blocking outgoing transfers until the suspicious activity is validated. This prevents continued victimization and disrupts the flow of illicitly obtained funds from 419-type frauds.

Regularly reassess accounts that are receiving or sending recurring 'advance fees.' Verify any changes in contact details or unusual transaction narratives that deviate from the stated account purposes. Escalate anomalies for deeper review to minimize continued exposure to elaborate 419 schemes.

Instruments

  • Fraudsters instruct victims to deposit or wire 'advance fees' into accounts controlled by scammers or money mules.
  • Once the funds arrive, criminals immediately move them across multiple accounts or jurisdictions, creating layers that obscure the original source of the payments.
  • Perpetrators set up fake merchant websites or payment portals where victims are prompted to pay 'advance fees' using their cards.
  • Once cleared, the funds are rapidly withdrawn or transferred to additional accounts, complicating transaction tracing and concealing the fraud’s source.
IN0040
|
|
  • Scammers direct victims to purchase money orders for the required 'fees' under urgent or fabricated reasons.
  • Criminals then cash or deposit these money orders into multiple accounts, quickly dispersing the funds to mask their origin.
  • Fraudsters ask victims to load prepaid cards or digital wallets with so-called 'advance fees.'
  • These balances are then redeemed or transferred by the criminals, often split across multiple accounts, impeding efforts to trace or recover the stolen funds.

Service & Products

  • Fraudsters exploit P2P platforms by guiding victims to transfer fees under superficial references (e.g., 'deposit' or 'administrative cost').
  • Criminals take advantage of the quick, informal nature of these transfers to layer funds further, often sending them to accomplices or other accounts to avoid scrutiny.
  • Fraudsters may set up fake merchant accounts or websites to appear legitimate, directing victims to submit 'advance fees' through these channels.
  • The service infrastructure enables seamless acceptance of credit/debit payments, which are then swiftly rerouted or cashed out, hindering detection of fraudulent fund flows.
  • Fraudsters instruct victims to send initial 'advance fees' through common remittance providers, often under the pretext of urgent or unexpected fees.
  • Once received, perpetrators rapidly withdraw or transfer the funds to additional accounts—potentially across multiple jurisdictions—to obscure the trail.
  • Scammers request victims to wire upfront payments, citing contrived emergencies or time-sensitive opportunities.
  • After funds arrive, perpetrators immediately layer them via successive wire transfers to isolate them from the original victim payment, complicating investigative tracing.
  • Advance Fee Fraud operators instruct victims to submit fees using popular online payment portals, citing convenience and speed to coax rapid compliance.
  • After receipt, criminals transfer funds to various linked accounts or digital wallets, exploiting platform features that mask origin and beneficiary details.

Actors

Illicit operators engage in advance fee fraud by contacting victims with false promises of significant returns or benefits in exchange for upfront fees. They knowingly acquire illicit proceeds from these payments and then quickly layer or structure the funds—often using multiple accounts across various jurisdictions—to conceal their origin. Their reliance on anonymity and frequent cross-border transfers hinders financial institutions' efforts to accurately trace funds or identify ultimate beneficiaries.

AT0076
|
|

Money mules transfer or receive funds on behalf of illicit operators, facilitating the layering of victim payments. They may be fully aware or unwittingly recruited under false pretenses. By swiftly moving the money through multiple accounts, often across borders, they complicate financial institutions' ability to detect or trace the fraudulent proceeds, obscuring the link between the source and beneficiary.

References

  1. APG (Asia/Pacific Group on Money Laundering). (2011). Typologies report: Money laundering associated with large-scale transnational frauds. Asia/Pacific Group on Money Laundering (APG). https://apgml.org/documents/default.aspx

  2. Caribbean Financial Action Task Force (CFATF). (2016). Illegal Lotteries Typology Project Report. CFATF. https://cfatf-gafic.org/index.php/documents/typologies/6949-illegal-lotteries-typology-project-report

  3. AUSTRAC (Australian Transaction Reports and Analysis Centre). (2011). AUSTRAC typologies and case studies report 2011. AUSTRAC. https://www.austrac.gov.au/sites/default/files/2019-07/typ_rpt11_full.pdf