Press Releases


  • Exposing the Play Field of Catfish Dating

    Dating scams have long been a highly profitable “business,” fueled by a vast market and the frequent underreporting of fraud to authorities due to the sensitive nature of the activity. Qurium’s investigation uncovers the full ecosystem of actors involved in these scams and reveals how dating fraud, disinformation campaigns, and financial crime are interconnected — all operating through the same infrastructure and often orchestrated by the same individuals.

  • Qurium uncovers global takedown attempts targeting its Bifrost mirroring service

    Qurium Media Foundation has uncovered multiple takedown requests submitted to Google targeting its Bifrost mirror service, an initiative designed to keep independent journalism accessible in countries with heavy Internet censorship.Qurium’s investigation reveals coordinated international efforts to suppress journalism and erase investigative reporting through legal mechanisms. The takedown demands came from state-linked institutions and reputation management firms operating in Azerbaijan, Pakistan, Russia, and Venezuela.

  • Proxy provider Biterika connected to state sanctioned research center linked to attack against investigative media

    On June 19, Russian independent media outlets IStories and Verstka published a joint investigation detailing how a sprawling network for selling sex with minors was built in Russia and how some of its high-profile clients — such as Russian oligarch and billionaire Oleg Deripaska — had escaped justice. Within hours of publication, both organizations suffered […]

  • Denial-of-Service Attacks on Investigative Media Traced to yet another Proxy Provider

    On May 21, the Peruvian investigative outlet IDL Reporteros was targeted by a Layer 7 DDoS attack involving over 10,000 unique IP addresses. Four days later, Armando.info, a Venezuelan investigative media platform, faced a 48-hour long series of denial-of-service attacks.

  • VoIP Providers serving the Scam Empire

    The call centers operating under the #ScamEmpire make millions of phone calls each year to lure new victims into the trap and pressure existing ones into “investing” their life savings. The vast majority of these calls are routed through five VoIP providers that are actively supporting the scammers and making a big cut themselves.

  • Disinformation, Malware and Drugs: Aeza’s cyber crime portfolio

    Qurium has previously reported that the Russian disinformation campaign Doppelganger operates its infrastructure from European data centers, not from Russian soil. Data centers in Germany hosted large part of the malicious content. Qurium also revealed that the ecosystem of Doppelganger had its hub in Aeza (International), a Russian provider with European presence. Aeza was a […]

  • Affiliate Marketing – a central player in the scam industry

    Leaked documents from the ScamEmpire shows that affiliates were rewarded in just one year with no less than 11 million USD from the scam call centers in Israel, Bulgaria, Cyprus and Ukraine for bringing victims to the scammers. The affiliates call it “traffic generation” – a legit marketing service. Without the affiliates black marketing strategies […]

  • #Scam Empire – inside the call centers

    Today, we are following up with a second report on the #ScamEmpire investigation and invite you to explore scam call centers from inside and learn how they are organized. Meet the junior sales team responsible for onboarding, and the senior, ruthless retention team that ensures victims are drained of every last dollar—leaving them with empty savings, high-interest loans, and debts to friends and family.

  • #Scam Empire – Victims of profit

    During the past four years, scam call centers operating from Tel Aviv (Israel), Sofia (Bulgaria), Limassol (Cyprus), Tbilisi (Georgia) and Barcelona (Spain) have stolen no less than $275 million dollars from 33,000 individuals in 33 countries. Today it is time to reveal their true identities.

  • When Kehr meets VexTrio

    Qurium can reveal that Doppelganger is using a hidden Cloaking service, making it possible for everything from Russian disinformation to Bitcoin scams to bypass both automatic and manual moderation of content in Facebook. The service, known as “Redirect.pro” is provided by Kehr.io, an actor known for providing a variety of online scam and fraudulent services. The investigation also links Doppelganger with VexTrio, a sophisticated cyber criminal operation that has been operating for years.