Phish of the Week: Fake Fund Recovery Scam Targeting Investment Fraud Victims
This Phish of the Week features a scam that targets people who have already lost money to investment fraud, offering a fake recovery service to harvest their personal and financial details for a follow-up scam.
How the attack works:
The recipient receives an email made to look like it's from a fund-recovery organization called 'Recoup,' sent from a real bulk-email platform's domain. The email states that time is limited for victims to recover their funds and includes a "Claim money" button.
Clicking the button leads to a polished landing page. The page opens with a headline promising to recover money taken by a "scam broker," alongside reassurances of no upfront fees, senior investigators, and bank-grade encryption.
The recipient is asked to fill out a form with their contact details, an estimated loss amount, and free-text details about the broker involved, how they were contacted, and when the loss occurred.
After the recipient submits the form, the page displays a confirmation message thanking them for their submission and promising that a "recovery specialist" will contact them within 24 hours, setting up direct contact with the scammer.
Why the attack works:
The core of this attack's effectiveness is emotional rather than technical: it targets people who have already experienced a financial loss and are hoping to reverse it. That state of mind narrows a person's usual caution considerably, since the offer directly addresses a need they already have rather than creating a new one.
Because the email is sent through a legitimate third-party email marketing platform rather than a spoofed or freshly registered domain, it can pass authentication checks that would normally flag a fraudulent sender, and it inherits some of the sending reputation of the platform itself.
The landing page compensates for the lack of a real track record by borrowing credibility from names the recipient already trusts. Referencing actual financial regulators next to logos of real, well-known platforms creates the impression of regulatory backing and an established case history, when neither actually applies to this operation.
Finally, the attack doesn't try to extract money immediately. By ending in a promised callback rather than an urgent payment request, it lowers the perceived risk of filling out the form and sets up a second, more personal stage of the scam where a "specialist" can build further trust over a phone call.
How to spot similar attacks:
- An unsolicited email offering to help recover money from a previous scam or investment loss
- A claim that the recipient is receiving the email because they "subscribed to a newsletter" they don't remember signing up for
- Urgency language suggesting only a limited window remains to reclaim funds
- A sender domain belonging to a bulk email or marketing platform rather than the organization's own domain
Anyone contacted about recovering money from a past scam should navigate to the relevant regulator, their bank, or law enforcement independently rather than following a link or phone number provided in the message.
What is Phish of the Week?
Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.