The US Department of Justice has issued seizure warrants targeting Starlink satellite internet terminals allegedly used by scam compounds in Myanmar, which are implicated in large-scale crypto fraud and money laundering operations targeting US citizens. According to affidavits from FBI investigators, Starlink devices played a substantial role in enabling these scam operations by providing reliable internet connectivity to compounds in the Three Pagodas Pass area, with dozens of terminals observed on the roofs of scam centers controlled by criminal organizations. The warrants direct SpaceX to disable service to the identified devices and accounts, aiming to disrupt the technical infrastructure supporting these transnational criminal activities.
These actions are part of a broader law enforcement initiative to combat "pig butchering" scams and other crypto-related frauds emanating from Southeast Asia, which have resulted in billions of dollars in losses and affected thousands of victims worldwide. The scale and sophistication of these scam compounds, as well as the use of advanced technology like Starlink for operational resilience, highlight the challenges faced by authorities in dismantling such networks. The DOJ's move to seize internet infrastructure marks a significant escalation in efforts to disrupt the technical enablers of organized cybercrime targeting US and global victims.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Supporting affidavits described how the alleged scam brand 'Wealthob' used a 'wrong number' social-engineering approach, moving victims to WhatsApp or Telegram before promoting fraudulent crypto investments. Investigators said records from SpaceX and Meta/WhatsApp linked the operation's activity to specific Starlink service used at the scam compounds.
US law enforcement obtained two seizure warrants and supporting affidavits targeting Starlink satellite internet terminals and associated accounts allegedly used at scam compounds near Three Pagodas Pass/Payathonzu and the Tai Chang compound. The warrants argued that identified terminals should be disabled or disconnected because they were allegedly facilitating wire fraud and money laundering against US victims.
SpaceX said it proactively disabled more than 2,500 Starlink devices in the vicinity of scam compounds in Myanmar. The company also reported that Starlink usage in Myanmar had declined afterward.
The US Justice Department established the District of Columbia Scam Center Strike Force to target industrialized cryptocurrency scam operations in Southeast Asia. According to the report, the initiative was already operational and had seized roughly $400 million in cryptocurrency tied to scams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.