HomeTypologyIQ
Fraud

Romance & Investment Scams

Romance and investment scams, including pig-butchering, where victims are manipulated over time into sending payments to scam-controlled bank accounts or crypto wallets. Payments are often escalating, made to fake investment platforms, and rapidly layered or converted to crypto by the receiving network.

Firm typesBank / Credit InstitutionE-Money Institution (EMI)Payment Institution (PI)Neobank / Digital BankCrypto Asset Service Provider
ProductsDomestic PaymentsCross-Border PaymentsFX TransfersCrypto ExchangeE-Money Accounts
CustomersIndividualsHigh Net Worth IndividualsSMEsAgents & Intermediaries
Key terms:

What it is

Romance and investment scams, including pig-butchering, where victims are manipulated over time into sending payments to scam-controlled bank accounts or crypto wallets. Payments are often escalating, made to fake investment platforms, and rapidly layered or converted to crypto by the receiving network.

Control objective

Identify customers being defrauded through romance and fake-investment scams and disrupt payments to scam-controlled accounts and crypto platforms, while detecting the receiving accounts used to collect and launder victim funds.

Data required

  • Customer payment history and deviation from normal behaviour
  • Beneficiary type (new payee, crypto exchange, overseas account)
  • Escalating payment sequence and frequency to the same beneficiary
  • Customer-stated payment purpose and intervention responses
  • Receiving account or wallet age, profile, and reuse across victims
  • Crypto on-ramp activity and rapid conversion patterns
  • Customer vulnerability and demographic risk indicators
  • Device, channel, and remote-access or coaching indicators

Related typologies (Fraud)

Unusual Business Activity vs Declared Profile

Transaction activity that is materially inconsistent with the customer's declared business profile, sector, or expected turnover, potentially indicating front company activity, invoice fraud, or undisclosed business changes.

Authorised Push Payment (APP) Fraud

Social engineering schemes where victims are manipulated into authorising real-time payments to accounts controlled by fraudsters. Includes impersonation of banks, HMRC, solicitors, and romance scams, with losses often irrecoverable once funds are moved through mule networks.

Insurance & Claims Fraud

Fraudulent insurance claims including staged or fabricated losses, inflated or exaggerated claim values, duplicate claims across insurers, and organised claims rings operating across multiple policyholders. Proceeds are extracted as claim settlements and may be laundered through linked bank accounts.

Business Email Compromise & Invoice Redirection

Business email compromise and mandate or invoice redirection fraud. Attackers impersonate suppliers, executives, or counterparties to redirect legitimate payments to fraudster-controlled accounts using altered bank details, often followed by rapid layering through mule accounts to extract funds.

Account Takeover Fraud

A fraudster gains control of a genuine customer's account through credential theft, phishing, or SIM-swap, then changes device, contact, or beneficiary details before rapidly draining funds to mule accounts. Speed and post-compromise profile changes distinguish takeover from normal customer behaviour.