Source: INTERPOL
Original report:
Review published:
Jurisdiction: Singapore / Timor-Leste
Reported legal status: Seven arrests reported; convictions not established by this source

A payment-change request from a lookalike address

On 6 August 2024, INTERPOL reported an email impersonation scam targeting a Singapore commodity firm. On 15 July, the firm received a purported supplier email asking that a pending payment go to a new account in Timor-Leste. INTERPOL said the fraudulent email address was spelled slightly differently from the supplier’s official address.

The firm transferred $42.3 million on 19 July and discovered the problem four days later when the real supplier said it had not received payment. The report does not publish the address or specify whether the difference was in the local part, domain, or both. It therefore does not justify naming a particular fraudulent domain.

Cross-border intervention and reported arrests

After a police report on 23 July, Singapore authorities sought assistance through INTERPOL’s Global Rapid Intervention of Payments mechanism, I-GRIP. The release states that $39 million was detected and withheld from the destination account, and that follow-up investigations led to the recovery of more than $2 million.

INTERPOL reported seven arrests and said steps were being taken to return the stolen funds. Interception and recovery are not the same as completed reimbursement. Arrests are not convictions; this article reflects only the status described in the cited report.

Editorial analysis — not additional case facts

Forensic lessons: a small address difference can matter

Verify bank-detail changes through previously known supplier contact details. Compare the actual email address, not only the display name. Keep the message, invoice, original headers and payment records together so that the authorization and destination changes can be examined.

DNS and registration data may help when a lookalike domain is actually identified. Here, no domain indicators were disclosed. The lesson is a verification workflow and careful evidence preservation—not a claim that the public report proved typosquatting or exposed the attacker’s infrastructure.

Primary source

Read the official INTERPOL report

This review summarizes the cited public report. The original source date is shown separately from this review’s publication date. Subsequent proceedings or recoveries have not been verified here.

This is an independent review of a publicly reported case, not a Digitpol client case or a claim of involvement. No undisclosed domain indicators or private victim evidence are included.