DOJ Disrupts SocksEscort Network Linked to Crypto Fraud

A court-authorized international law enforcement operation led by the U.S. Department of Justice has disrupted SocksEscort, a large residential proxy network that allegedly exploited thousands of internet routers worldwide to facilitate cybercrime and financial fraud.

Authorities said the U.S. government executed seizure warrants against dozens of internet domains registered in the United States that were allegedly connected to the criminal infrastructure. The announcement was made by U.S. Attorney Eric Grant.

According to court documents, the SocksEscort network infected home and small business routers with malware, allowing operators to redirect internet traffic through compromised devices

The network then sold access to these infected routers as proxy services to customers seeking to hide their true locations online.

Investigators said the service had been operating since at least the summer of 2020 and offered access to roughly 369,000 IP addresses at various points

As of February 2026, the SocksEscort platform listed about 8,000 infected routers available for purchase, including around 2,500 located in the United States.

Cybercriminals allegedly used the proxy network to conceal their identities while carrying out a range of fraudulent activities. These included account takeovers targeting U.S. bank accounts and cryptocurrency platforms, as well as schemes involving fraudulent unemployment insurance claims.

Authorities said the crimes caused millions of dollars in losses to victims. Among the cases cited by investigators was a New York resident who lost approximately $1 million in cryptocurrency from an exchange account

In another case, a manufacturing company in Pennsylvania lost $700,000, while current and former U.S. service members using Military Star credit cards were defrauded of about $100,000.

The operation involved coordinated action by international partners, with law enforcement agencies in Austria, France, and the Netherlands helping dismantle key SocksEscort servers.

The investigation is being led by the Federal Bureau of Investigation Sacramento Field Office, along with the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service and IRS Criminal Investigation.

Authorities said the operation highlights the growing importance of international cooperation in combating cybercrime networks that exploit global digital infrastructure.

Your web3 identity + services + payments in one single link. Get your pay3.so link today.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Gemini Faces Class-Action Suit Over Prediction Market Pivot, Plummeting Stock Price

Gemini faces a class action lawsuit from shareholders alleging that the company misled investors about its business viability and concealed its shift to prediction markets, contributing to a significant decline in stock value.

Decrypt4h ago

CLARITY Act’s Stablecoin Yield Deal Near as SEC Redefines Tokens

Lawmakers and regulators are making progress on crypto policy, with a stablecoin yield proposal anticipated soon. The SEC and CFTC classified most crypto assets as non-securities, designating several as digital commodities.

CryptoFrontNews6h ago

80-Year-Old Scam Victim Lost $285,000 to Telecom Fraud, Files Lawsuit Against Charles Schwab After Funds Converted to Cryptocurrency

80-year-old investor George Chryssanthou fell victim to a telecom scam in January 2025, losing approximately $285,000. The scammers impersonated Microsoft technical support and induced him to transfer funds to a CEX account, which were subsequently converted to Bitcoin. He has filed a complaint with FINRA against Charles Schwab for failing to prevent the suspicious transfer.

GateNews8h ago

IPO Dreams Shattered! Gemini Hit with Class Action Lawsuit for "Misleading Investors," Stock Price Plummets 80% with 25% Layoffs and Exit from Multiple Countries

Gemini cryptocurrency exchange is facing its biggest crisis since its IPO, as it has been accused of providing false information in its listing documents, causing its stock price to plummet 80% and significant losses. The company has announced a 25% workforce reduction and withdrawal from multiple international markets, sparking serious market concerns about its operations. This incident may also impact the listing process of future crypto enterprises.

動區BlockTempo9h ago

Guizhou Police Crack Down on Virtual Currency Trading Fraud Case, Scammer Uses "Read-Only Wallet" to Steal 7118 USDT

Police in Wanshan District, Tongren City, Guizhou Province, China have cracked a virtual currency trading fraud case. The victim was defrauded of 7118 USDT, equivalent to over 50,000 yuan. The scammers used read-only wallets and cash displays to gain trust before quickly transferring assets. Police remind the public that virtual currency trading carries high risks and requires careful verification of wallet address authenticity.

GateNews9h ago

UK Shuts Down Zedxion Over False Registration Claims

Companies House has shut down crypto firm Zedxion for submitting misleading information during its incorporation. This action highlights increasing regulatory scrutiny in the digital asset sector and emphasizes the need for compliance and transparency in company registrations.

TodayqNews10h ago
Comment
0/400
No comments