Files
DB-cleanup/merge-output/sources/383_Undisclosed.txt
T
StellarCrowandClaude Fable 5.1 439e83a4cb feat(sources): Wayback pass, automatic trimming, detention rule, ten cases re-sourced
Second and third rounds on the dossier pipeline, reviewed locally before commit.

Retrieval
- wayback_pass.py: retries every BLOCKED/DEAD/THIN/ERROR linked source through
  the Wayback Machine; blocks carry the snapshot date, archive URL and the live
  verdict. 143 slots retried: 93 fetched, 37 no snapshot, 12 script shells, 1 PDF.
- fetch_sources.py: fetch_wayback() helper.
- add_extra_sources.py: files staged extra_* finds (web search, not on the DB
  record) into the store with a provenance note.
- Cases re-sourced by web search: 248 (Oslo: Document.no, Avisa Oslo, NRK; the
  linked Le Parisien piece is case 242 and is marked OFF-CASE), 258 Kharkiv,
  260 Singapore, 358 Bangkok, 365 Las Vegas, 388 Verneuil-sur-Seine, 390 Zoersel,
  430 Homestead. 341 of 364 cases now hold a fetched article; 11, 66 and 399
  have no public text source (podcast, police video, direct victim report).

Trimming
- auto_trim.py: case-anchored furniture cut for UNTRIMMED blocks. Finds the body
  run that mentions the case, merges across subheadings and short furniture
  gaps, drops teasers, share bars, date/URL/caption lines and subscription
  pitches; refuses pages with no record term or almost no body. 302 blocks
  trimmed; 16 left on auto-trim-review.md (7 OFF-CASE suspects). Every cut is
  labelled AUTO-TRIMMED, UNREVIEWED in the dossier; the full extract stays in
  staging/. Decisions with anchors in trim-decisions-auto.json.
- build_cases.py / verify_all.py: banners for auto-trimmed and archived blocks,
  staged-file check extended to Wayback blocks, flag legend under the record.

Detention rule
- README "Definitions": the DB field `kidnappings` is the DETENTION violence
  type (victim, guard, staff or relative held to force submission or execute
  the theft), distinct from the Kidnapping scenario (taken away and held).
- detention-flag-review.md / detention-flag-corrections.json: 40 records
  reviewed with evidence; 30 set-to-1 proposals accepted by the owner on
  2026-09-06 (listed in corrections-approved.md), 10 still open.
- apply_detention_wording.py: "Violence Used" in the 70 reviewed summaries now
  names detention explicitly (62 of 70 labelled), supported by the summary's
  own text; idempotent; supersedes the batch scripts' wording.

Worklist and docs
- sofia-worklist.md: 248 decisions, detention rule item replacing the old
  "no abduction" item, fresh-search section for the textless cases.
- README-START-HERE.md: progress notes, run commands, next steps.
- Bug fixed in passing: Wayback blocks stored in-memory text with carriage
  returns; now stored as read back from disk.

verify_all.py PASSES (2321 checks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GZZENdTLzNGsbNy4DyF1yt
2026-09-06 19:36:45 +02:00

111 lines
12 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
================================================================================================
CASE 383 | Undisclosed | July 8, 2024 | USA
================================================================================================
DATABASE RECORD
id 383
date July 8, 2024
original_date July 8, 2024
year 2024
month 7
quarter 2024-Q3
victim Undisclosed
location New Mexico
country USA
scenario Home Invasion
description Criminal enterprise that operated from about October 2023 through March 2025 broke into a victims home to steal a hardware wallet.
kidnappings 0
violence_torture (null)
drugs_alcohol (null)
weapons (null)
theft 1
life_taken 0
money_wanted Crypto
coin_type A hardware wallet containing crypto
reports TRM Labs
notes The burglary was coordinated in real time by remotely monitoring the victims physical location by accessing the victims iCloud account.
has_processed_date 0
created_at 2025-12-23 21:03:26
(flag legend: 'kidnappings' is the DETENTION flag — 1 when the victim was held against
their will at any point, tied, locked in, held at gunpoint or taken away; it is NOT the
same as the 'Kidnapping' scenario, which means taken away and held. See README, Definitions.)
AI SUMMARY [generated at bulk import, NOT verified against sources]
**Victim:** Undisclosed victim in New Mexico
**Attackers:** Marlon Ferro (traveled to New Mexico for burglary), Danny Lam (remotely monitored victim)
**Attack Method:** Home invasion/burglary on July 8, 2024. Lam accessed victim's Apple iCloud account to monitor real-time location. Ferro set up telephone with video camera across from victim's home to livestream during break-in, alerting accomplices if victim returned. Social engineering fraud scheme executed prior to gain access to victim data.
**Violence Used:** Unlawful home entry while victim was away. No physical confrontation reported.
**Crypto Stolen:** Hardware virtual currency wallet stolen from residence during break-in.
**Status:** Part of broader criminal enterprise scheme tracking and surveilling individuals with significant crypto assets for physical theft. Investigation ongoing, charges filed against Ferro and Lam.
LINKED SOURCES
[url] https://www.trmlabs.com/resources/blog/doj-uses-organized-crime-statute-in-263-million-cryptocurrency-theft-money-laundering-and-home-invasion-conspiracy
[url_2] https://www.binance.com/en/square/post/24316542322970
[url_3] https://www.justice.gov/usao-dc/media/1400531/dl
OTHER LINKED SOURCES
[THIN] url_2 None — extractor recovered very little; needs the WebFetch path or a site-specific rule
https://www.binance.com/en/square/post/24316542322970
[NOT AN ARTICLE] url_3 justice.gov — Retrieval returned the raw PDF binary (%PDF, FlateDecode streams), not extractable text. The DOJ document link is preserved in the DB. Case 383 also has a trmlabs source. Extract the PDF text manually only if this document's content is needed.
https://www.justice.gov/usao-dc/media/1400531/dl
------------------------------------------------------------------------------------------------
FETCHED ARTICLE 1
Source trmlabs.com
URL https://www.trmlabs.com/resources/blog/doj-uses-organized-crime-statute-in-263-million-cryptocurrency-theft-money-laundering-and-home-invasion-conspiracy
Field url
Retrieved 2026-08-06T13:45:20+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
Language unknown
Kept paragraphs headline [0] + 3-18 of 46
Length 7,564 chars
Integrity sha256 e8f425df0dc8510c899802b3cd3fe426098bd1776e2dd00557df5e764f76055e
Trimmed trimmed on read-through
Caveat retrieved from a live page on the date above. Unlike text copied
from the spreadsheet, there is no second copy to hash it against.
------------------------------------------------------------------------------------------------
ORIGINAL (unknown, verbatim as retrieved)
DOJ Uses Organized Crime Statute in $263 Million Cryptocurrency Theft, Money Laundering and Home Invasion Conspiracy | TRM Labs
Yesterday, the Department of Justice and the U.S. Attorneys Office for the District of Columbia unsealed a sweeping four-count superseding indictment charging 12 additional individuals—both American citizens and foreign nationals—in connection with a racketeering conspiracy involving over $263 million in stolen cryptocurrency. The charges include racketeering conspiracy—the RICO statute (more on that below)-conspiracy to commit wire fraud, money laundering, and obstruction of justice. Several defendants were arrested this week in California; two remain at large and are believed to be in Dubai.
The indictment builds on charges initially brought against Malone Lam on September 19, 2024, and outlines a criminal enterprise that operated from about October 2023 through March 2025. The organization grew out of connections made on online gaming platforms and evolved into a coordinated scheme that combined cyber intrusions, social engineering, on-chain laundering, and real-world violence.
Members of the enterprise held defined roles. Database hackers obtained cryptocurrency-related user data by breaching websites and servers or purchasing information on the dark web. Organizers and target identifiers analyzed the data to locate high-net-worth individuals. Callers contacted victims directly by phone, falsely claiming to be cybersecurity professionals responding to a breach, and convinced them to disclose sensitive credentials or authorize fraudulent transactions. Money launderers converted stolen virtual assets into U.S. dollars through wire transfers and bulk cash deliveries. Residential burglars executed physical break-ins to steal hardware wallets containing digital assets.
In one of the largest alleged cryptocurrency thefts in US history, the indictment charges that on August 18, 2024, Malone Lam and others contacted a victim in Washington, DC, and fraudulently obtained over 4,100 Bitcoin—worth approximately USD 230 million at the time. In another incident in July 2024, Lam and associates allegedly stole over USD 14 million in cryptocurrency from a second victim.
In July 2024, Marlon Ferro, a member of the criminal enterprise, allegedly traveled to New Mexico to break into a victims home in order to steal a hardware virtual currency wallet. The burglary was coordinated in real time with Lam, who is accused of remotely monitoring the victims physical location by accessing the victims iCloud account. Ferro unlawfully entered the residence and stole the device containing cryptocurrency. This incident was part of a broader scheme in which members of the enterprise tracked and surveilled individuals identified as holding significant crypto assets, then targeted them for physical theft.
The allegations come in the wake of a number of high profile violent crimes involving cryptocurrency including an attempted kidnapping in France on May 15, 2025 - the same day as the superseding indictment in this case was unsealed.
The stolen proceeds were spent on luxury goods and services, including USD 4 million at nightclubs, with individual outings costing up to USD 500,000. Members of the group are alleged to have purchased high-end handbags, watches, and clothing, and to have rented properties in Los Angeles, the Hamptons, and Miami. They allegedly chartered private jets, retained personal security teams, and purchased at least 28 exotic cars, some worth as much as USD 3.8 million, often registering the vehicles through shell companies to conceal ownership.
The laundering of proceeds involved the use of cryptocurrency mixers, peel chains, pass-through wallets, and virtual private networks designed to obscure transaction paths and participant identities. Kunal Mehta, Hamza Doost, Joel Cortez, and Evan Tangeman are accused of facilitating these efforts through unlicensed crypto-to-cash conversion services. According to the indictment, they also secured rental homes and jet travel using fake identity documents, managed vehicle ownership concealment, and shipped bulk cash hidden inside squishmallow stuffed animals through the U.S. mail.
Even while in pretrial detention following his September 2024 arrest, Malone Lam is alleged to have continued participating in the enterprise. The indictment states he directed co-conspirators to collect stolen cryptocurrency and deliver Hermès Birkin handbags to his girlfriend in Miami.
The case is being investigated by the FBIs Washington Field Office Criminal and Cyber Division, IRSCriminal Investigations Washington, DC Field Office, and the U.S. Attorneys Office for the District of Columbia, with support from the FBIs Los Angeles and Miami field offices.
This case reflects a growing trend in which on-chain financial crime converges with real-world threats. What begins with the compromise of digital credentials can escalate into physical surveillance, intimidation, and home invasion. Sophisticated laundering strategies—including the use of mixers, VPNs, and shell entities—are increasingly paired with coercive offline tactics to access and monetize digital assets.
But law enforcement is also using new tools and authorities. Investigators are not only deploying advanced blockchain intelligence to trace stolen cryptocurrency across mixers, cross-chain swaps, and high-risk exchanges—they are also reaching back to a powerful statute originally designed to dismantle traditional organized crime: the Racketeer Influenced and Corrupt Organizations Act, or RICO.
Enacted in 1970, RICO was crafted to go after mafia syndicates, drug cartels, and other structured criminal enterprises that engaged in repeated, coordinated illegal conduct. The statute allows prosecutors to charge all members of an enterprise if they have participated in a pattern of racketeering activity—defined to include crimes like wire fraud, money laundering, obstruction of justice, and even acts of violence—provided those acts were committed as part of the groups shared criminal objective. Importantly, RICO allows law enforcement to hold not just individual actors accountable, but to treat a sprawling web of participants as a single criminal organization.
The use of RICO in this case signals a shift in how federal prosecutors are approaching crypto-native criminal networks. What may look at first like a string of isolated hacks, wallet thefts, and laundering schemes is being treated as part of a coherent, ongoing criminal enterprise—complete with assigned roles, coordination across jurisdictions, shared proceeds, and infrastructure built for repeat targeting.
This approach is meaningful. It enables law enforcement to connect digital asset thefts with physical-world violence, to tie overseas laundering nodes to U.S.-based facilitators, and to apply enhanced sentencing guidelines and asset forfeiture tools designed for dismantling organizations—not just punishing individuals.
In short, the RICO charges in this case dont just reflect what happened. They reflect how it happened: with structure, coordination, and intent. And they provide DOJ with the legal architecture to pursue the full enterprise, from the iCloud-tracking home invader to the squishmallow-stuffed cash courier to the crypto-laundering broker in Dubai. At a time when blockchain-based crime is converging with traditional organized criminal behavior, we may see DOJ leverage RICO more often as it pursue cartels and other criminal enterprises.
================================================================================================
generated from attacks-export-Gart-website.json + reported_K&R | case 383
================================================================================================