Sri Lanka Scam Network Alert: How Fraud Factories Relocated and What Victims Can Do (2026)

Chinese-run scam networks displaced from Southeast Asia have relocated to Sri Lanka, targeting victims worldwide with fake investments, crypto fraud, and romance scams.

By DefendMe Editorial, Intelligence Team · · Hot News

You sent money to what looked like a legitimate investment platform, a romantic partner who encouraged you to invest in crypto, or a company with professional documentation and a US registration certificate displayed on the wall. Now withdrawals are blocked, the contact has gone silent, and the platform has disappeared. What you encountered almost certainly originated inside one of the transnational scam operations that have relocated from Southeast Asia to Sri Lanka.

Sri Lankan police spokesperson Fredrick Wootler publicly described the situation as an alarming increase of cybercrimes, carried out by people who enter the country on tourist visas and set up industrial-scale fraud operations targeting victims across the world, including in the United States, Europe, and Asia. Your loss was not the result of bad luck or a bad investment decision. It was the product of a sophisticated, well-funded criminal enterprise.

How It Works

The networks that have set up in Sri Lanka follow the same operational playbook refined over a decade in Cambodia and Myanmar. Operators enter Sri Lanka on tourist visas or the country's newer digital nomad visas. They rent out entire floors of apartment buildings or rotate through hotels and offices in small cells of approximately five people, moving locations every three months to evade police detection. A single operation raided by Sri Lankan authorities in Colombo in June 2026 had rented eight floors of one apartment building.

Inside these operations, workers run multiple simultaneous fraud schemes. The most common formats identified in raids and victim reports include romance scams, where operators build weeks-long emotional relationships before steering victims toward fake investment platforms; crypto investment fraud, where victims are shown fabricated profit dashboards and encouraged to deposit more before a withdrawal fee trap is triggered; and fake company investment pitches, where professionally forged documents including falsified US Treasury certifications, counterfeit company registrations, and framed US business certificates create an illusion of legitimacy. One raided Colombo site contained 62 passports, dozens of forged documents, laptops, phones, and document-forging equipment.

The money flow is deliberately complex. Deposits are routed through cryptocurrency wallets, third-party payment processors, or wire transfers to accounts controlled by the networks. Blockchain records reviewed in similar Southeast Asian cases consistently show rapid layering across multiple wallets within hours of deposit, making straightforward bank recalls extremely difficult without specialist tracing. Victims who attempt to withdraw are told to pay additional taxes, compliance fees, or insurance deposits. These are not real fees. They are a secondary extraction mechanism. No payment of such fees has ever resulted in a verified withdrawal from operations of this type.

Sri Lanka became attractive to these networks for specific structural reasons: tourist and digital nomad visas are easy to obtain, SIM card and internet connection regulation is limited, office and hotel space is cheap and plentiful, and the existing Chinese business presence in the country means Chinese nationals do not attract immediate suspicion. Cybercrime researcher Mark Bo, author of Scam: Inside Southeast Asia's Cybercrime Compounds, documented the shift toward Sri Lanka approximately two years ago, noting recruitment posts on Telegram channels explicitly referencing the country as a new base of operations after the crackdown in Cambodia intensified.

Red Flags. What Victims Reported

Investigation Findings

DefendMe analysts reviewed the publicly available reporting from The Guardian's June 2026 investigation, Sri Lankan police statements, and open-source records of the broader Southeast Asian scam industry. The findings are consistent with a deliberate, coordinated geographic relocation of criminal infrastructure rather than isolated incidents. Sri Lankan authorities have conducted more than a dozen raids since the start of 2026, resulting in the arrest and deportation of approximately 700 foreign nationals. Nationalities confirmed in arrests include Chinese, Vietnamese, Indian, Indonesian, Laotian, Filipino, Malaysian, and Burmese citizens, all of whom entered on tourist visas.

The June 2026 Colombo raid, the most recent at time of publication, detained 18 Chinese nationals and one Laotian national. Physical evidence recovered at the site included 62 passports (predominantly Chinese), phones, laptops, portable storage devices, computer components, a document-forging stamp, and multiple forged certificates including a fake US Treasury document and a framed fake US company registration claiming a company valuation of $10 billion. Sri Lankan Superintendent of Police Kamal Ariyawansa confirmed the operation was run by a Chinese crime syndicate and was designed to defraud American victims specifically.

The Chinese Embassy in Colombo has publicly acknowledged that Chinese citizens involved in telephone fraud gangs have relocated to Sri Lanka following the Southeast Asia crackdown, and stated it provides full support to Sri Lankan law enforcement. The United States government has estimated that Americans lost $10 billion to Southeast Asian scam centres in 2024 alone, a figure that predates the confirmed expansion into Sri Lanka. Open-source recruitment activity on Telegram, documented by researcher Mark Bo, shows operators actively advertising for workers in Sri Lanka as early as approximately 2024. Office rental prices in Colombo have reportedly more than doubled in some complexes due to demand from these operations, according to local businesspeople cited by The Guardian.

Criminal Context and Enforcement Landscape

The transnational scam industry centred in Southeast Asia is consistently described by law enforcement and researchers as one of the largest organised crime enterprises in the world. Operating originally from fortified compounds in Myanmar and Cambodia, these networks run romance scams, fake crypto investment platforms, online gambling fraud, and large-scale money laundering simultaneously. The United Nations Office on Drugs and Crime has previously documented the coercive labour conditions inside these compounds, where many workers are trafficked or deceived into participation. US authorities have attributed $10 billion in American losses in 2024 alone to these operations.

The relocation to Sri Lanka follows a documented pattern. When host governments in Southeast Asia, under international pressure, began conducting raids and extraditing operators, the networks adapted by fragmenting into smaller mobile cells and moving to countries with weaker cybercrime enforcement infrastructure. Sri Lanka's current approach, primarily deportation rather than prosecution of arrested individuals, means the operational cost of being caught remains low for syndicate leadership. DefendMe analysts assess that victims targeted by Sri Lanka-based operations are unlikely to see prosecutions of the individuals who defrauded them in the near term, making financial tracing and civil recovery pathways the more viable immediate options.

International enforcement cooperation is developing but uneven. Interpol's financial crime and cybercrime divisions have been active in the broader Southeast Asia scam compound context. Victims in the United States should report to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov and the Federal Trade Commission (FTC) at reportfraud.ftc.gov. Victims in the United Kingdom should report to Action Fraud. Victims in Australia should contact the Australian Federal Police via ReportCyber. Preserving all transaction records, chat logs, platform screenshots, and wallet addresses before reporting will significantly strengthen any complaint filed.

What Victims Should Do Now

  1. Stop all deposits immediately. Do not send additional funds under any circumstances, including to pay withdrawal fees, taxes, or compliance charges. These are fraudulent secondary extractions.
  2. Do not contact the platform or the individual who introduced you to it. Further contact can expose you to re-victimisation, identity theft, or a recovery scam where a second fraudster poses as a recovery service.
  3. Preserve all evidence before it disappears. Take screenshots of the platform, all chat conversations, transaction confirmations, wallet addresses, email correspondence, and any documents the operator sent you. Store copies in a secure location.
  4. Record every financial transaction. Note the exact amounts, dates, payment methods, receiving wallet addresses or bank account numbers, and any reference numbers. This documentation is essential for tracing.
  5. Report to the relevant authorities in your country. US victims should file with the FBI IC3 at ic3.gov and the FTC at reportfraud.ftc.gov. UK victims should contact Action Fraud. Australian victims should use ReportCyber. Sri Lankan authorities are actively investigating and coordinating with international agencies.
  6. Do not pay any company that cold-contacts you offering to recover your money. Recovery scams routinely target people who have already lost funds to investment fraud. Legitimate platforms do not solicit you after a loss.
  7. Request a specialist assessment to determine whether your funds are traceable on-chain. Cryptocurrency transactions leave a permanent record on public blockchains, and early tracing action improves the prospect of identifying where funds were moved.

Source: https://www.theguardian.com/world/2026/jun/16/sri-lanka-alarming-rise-cybercrime-scam-networks-south-east-asia-cambodia-myanmar-china?utm_source=chatgpt.com

Were you affected by this scam?