📈 Get daily crypto insights that make you smarter about your money

Classiscam Operation Siphons .5 Million From Victims Across 79 Countries

The cybersecurity landscape in 2023 faces an increasingly sophisticated threat as the Classiscam operation, a scam-as-a-service platform, continues to expand its reach across 79 countries, amassing $64.5 million in illicit earnings since its emergence in 2019. With Bitcoin trading at $25,868 and Ethereum at $1,637 as of early September, the crypto ecosystem remains a prime target for organized fraud operations that blend social engineering with automated phishing infrastructure.

The Exploit Mechanics

Classiscam operates through a highly organized pyramid structure managed via 1,366 distinct Telegram groups. The operation relies on automated Telegram bots that generate phishing pages on demand, allowing even low-skilled criminals to participate. When a scammer identifies a target on a classified marketplace, the bot creates a convincing fake payment page within seconds. The victim receives a link — often shared through WhatsApp or Telegram — that mirrors a legitimate banking or payment portal.

What sets Classiscam apart from traditional phishing campaigns is its industrialization. The platform provides templates for 251 different brands, including major banks, e-commerce platforms, and cryptocurrency exchanges. Workers — the lowest tier in the criminal hierarchy — interface directly with victims, while “bombers” redirect them to spoofed pages. Supporters maintain the technical infrastructure, and administrators oversee recruitment and day-to-day operations.

A particularly insidious recent evolution involves a balance-check feature on phishing pages. Before charging the victim, the scam page asks users to verify their account, allowing criminals to assess how much money is available and tailor their theft accordingly. Some groups have also begun deploying stealer malware alongside their phishing campaigns, harvesting stored credentials and cryptocurrency wallet keys from infected devices.

Affected Systems

The geographic spread is staggering. European nations account for 62.2% of all fraudulent transactions, with Germany, Poland, Spain, Italy, and Romania experiencing the highest volumes. The Middle East and Africa represent 18.2% of victims, while the Asia-Pacific region accounts for 13%. The operation initially targeted Russia before expanding worldwide during the COVID-19 pandemic, capitalizing on the surge in online shopping and remote transactions.

Cryptocurrency users face heightened risk as Classiscam groups increasingly incorporate crypto-specific scams, including fake exchange login pages and fraudulent wallet verification portals. The connection to the broader cybercrime ecosystem is confirmed by Group-IB, which identifies Classiscam as the same operation tracked by ESET under the name Telekopye — a phishing kit that powers much of this criminal activity.

The Mitigation Strategy

Defending against Classiscam requires a multi-layered approach. First, never follow payment links shared through messaging apps, even if the sender appears legitimate. Always navigate directly to the official website or app. Second, enable two-factor authentication on all financial and cryptocurrency accounts using a hardware security key rather than SMS-based verification, which can be intercepted through SIM-swapping attacks.

For cryptocurrency holders specifically, hardware wallets remain the gold standard for asset protection. The recent wave of private key compromises — including the Stake.com breach that drained $41.3 million across multiple chains — demonstrates that even large platforms can fall victim to key theft. Storing private keys in cold storage, disconnected from internet-facing systems, eliminates the primary attack vector used by these criminal operations.

Organizations should implement domain monitoring to detect phishing sites impersonating their brand, and individuals should verify URLs carefully before entering any credentials. The automated nature of Classiscam means these phishing pages can be generated and discarded rapidly, making traditional blocklist approaches less effective than behavioral detection and user education.

Lessons Learned

The Classiscam operation illustrates the professionalization of cybercrime. With $64.5 million in cumulative theft, 1,366 active groups, and operations spanning 79 countries, this is not opportunistic fraud — it is an industry. The scam-as-a-service model lowers the barrier to entry for would-be criminals while generating recurring revenue for operators at the top of the pyramid.

The cryptocurrency community must recognize that threats extend beyond smart contract exploits and exchange hacks. Social engineering attacks targeting individual users through marketplace fraud represent a significant and growing vector. As Bitcoin hovers around $26,000 and the total crypto market cap exceeds $1 trillion, the financial incentives for these operations will only intensify.

User Action Required

If you have recently conducted transactions on classified marketplaces and followed links sent through messaging platforms, immediately check your financial accounts for unauthorized transactions. Change passwords for any accounts where credentials may have been entered on suspicious pages. For cryptocurrency users, transfer assets to a hardware wallet and generate new receiving addresses. Report any confirmed fraud to local law enforcement and relevant platforms. The fight against operations like Classiscam depends on both individual vigilance and coordinated international enforcement.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with qualified professionals before making security decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Classiscam Operation Siphons .5 Million From Victims Across 79 Countries”

  1. 1,366 Telegram groups, 251 brand templates, $64.5M stolen. Classiscam is basically a franchise operation for scammers. the barrier to entry is basically zero.

    1. scam-as-a-service is such a 2023 thing. you dont even need to be technically skilled, the telegram bot does everything for you. horrifying scale.

    2. 251 brand templates means they cloned every major payment app in existence. the fact this ran for 4 years before getting serious attention tells you everything about enforcement priorities

      1. Kofi Asante 251 brand templates means they cloned every payment app that matters. 4 years of operation tells you law enforcement was clueless the entire time

    3. onchain_sleuth_

      fatima 1366 telegram groups and zero technical skill needed. the franchise model scales infinitely because each scammer runs their own operation

  2. 79 countries and most victims never recover their money. these phishing pages look identical to the real banking portals. always check the URL, not just the page design.

    1. Marco F. checking the URL works on desktop but these scams are designed for mobile where the address bar is hidden after 2 seconds of scrolling

    2. marco is right about checking the URL but most victims are on mobile where the address bar is hidden. these scams are designed for small screens

      1. nigerian_prince_

        rui makes a great point about mobile. these scams work because the url bar is basically invisible on phone browsers

      2. Rui Santos mobile URL bars being basically invisible is the exploit. these phishing pages are designed for thumb scrolling not careful inspection

  3. 251 brand templates means the bot can clone literally any payment app. you think youre paying through your bank portal and its a perfect copy on your phone

  4. vishing_victim_ and 1366 telegram groups running the whole thing. scam-as-a-service is basically a franchise at this point. $64.5M since 2019 is probably understated

    1. Aleksandra W.

      Linnea F. exactly. the franchise model means the operator barely matters, the bot does 90% of the work. cutting off one telegram channel is pointless

  5. 64.5M over 4 years across 79 countries. the per-country average is small enough that no single jurisdiction prioritized taking it down. thats the exploit

  6. phish_sherlock

    251 brand templates means the bot can clone basically any bank or payment app. the scale of this operation is industrial

    1. grifter_archive_

      phish_sherlock 251 templates is just the ones they found. these operations rotate new brands faster than takedown requests get processed

  7. $64.5M since 2019 across 79 countries and most victims never recover a cent. 251 fake payment portal templates means they cloned every major banking app

  8. $64.5M since 2019 across 79 countries and most victims never recover a cent. 251 fake payment portal templates means they cloned every major banking app

  9. classifieds_rat_

    1366 telegram groups coordinating 251 fake payment portals is wild. the franchise model means taking down one just spawns three more

    1. phish_hunter_

      classifieds_rat_ 1366 telegram groups generating fake payment pages on demand. the franchise model means taking down one admin just spawns three new ones

    2. phish_hunter_

      classifieds_rat_ 1366 telegram groups generating fake payment pages on demand. the franchise model means taking down one admin just spawns three new ones

    3. classifieds_rat_ exactly. you shut down a telegram group and the bot just regenerates with a new invite link. the infrastructure is designed to survive takedowns

      1. Saanvi R. exactly. shut down one telegram group and the bot generates a new invite link in seconds. the infrastructure was built to survive takedowns from day one

      2. Saanvi R. exactly. shut down one telegram group and the bot generates a new invite link in seconds. the infrastructure was built to survive takedowns from day one

  10. wire_fraud_rat

    64.5M since 2019 and still running. classifieds platforms need to be legally responsible for not flagging these patterns earlier

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,401.00+0.2%ETH$2,509.53-0.4%SOL$101.17-0.2%BNB$722.40-0.2%XRP$1.38+0.9%ADA$0.2080+0.1%DOGE$0.0841-0.7%DOT$1.02+0.2%AVAX$7.40-0.6%LINK$11.39-1.0%UNI$6.27-1.7%ATOM$1.59-1.0%LTC$54.12-0.3%ARB$0.1357-3.7%NEAR$2.42+3.8%FIL$0.9932+22.0%SUI$0.7230+0.0%BTC$77,401.00+0.2%ETH$2,509.53-0.4%SOL$101.17-0.2%BNB$722.40-0.2%XRP$1.38+0.9%ADA$0.2080+0.1%DOGE$0.0841-0.7%DOT$1.02+0.2%AVAX$7.40-0.6%LINK$11.39-1.0%UNI$6.27-1.7%ATOM$1.59-1.0%LTC$54.12-0.3%ARB$0.1357-3.7%NEAR$2.42+3.8%FIL$0.9932+22.0%SUI$0.7230+0.0%
Scroll to Top