Fraud & Financial Crime Intelligence
IntermediateFraud investigation and crypto tracing: follow scam money from pig butchering sites and money mules to stablecoin freezes, then stop the next payment. Everything rests on real cases in court filings and government releases, and five missions put you on a fictional UK bank's fraud intelligence desk. Business email compromise, APP fraud, card and identity fraud and professional laundering are covered too, across 40 lessons with a verifiable certificate at the end.

Curriculum
9 more steps behind a free account
Free account
Ready to start Fraud & Financial Crime Intelligence?
Create a free account to open the remaining 9 steps, track every one you finish and earn your certificate.
- Free to start
- Progress saved on every step
- Certificate on completion
Already have an account? Sign in
About this path
Most fraud reaches an intelligence team as a payment that has already left. By then the scam site has been live for weeks, the mule account has passed the money on and the crypto is two chains away. This path follows the money in order, from the scam compound and the fake trading platform to the mule account, the exchange deposit address and the stablecoin freeze, and shows where an analyst can still act at each step.
The first section covers fraud as an industry: how a scam runs from first contact to cash-out as a chain of separate businesses, which payment rails can still be recalled or frozen and for how long, and how to read fraud statistics without fooling yourself. It then sets up the discipline itself, with one vocabulary for fraud and cyber teams through scam typologies and MITRE's Fight Fraud Framework, the rules for linking accounts, devices and payees without false merges, and the signals that cross over from cyber into fraud.
The second section is the scam industry. You take apart relationship and investment scams, often called pig butchering, along with task scams, fake jobs and the phantom hacker and crypto kiosk scams aimed at older adults, and you learn the red flags a bank or an exchange sees in a victim's payments. You study the scam compounds that run these operations as businesses, what disruption has and has not achieved, how to read a fake trading storefront, and how to tell a shared hosting supplier from the operator behind a scam cluster.
The third section follows the money. It covers business email compromise and the recall window, what a receiving bank sees of an authorised push payment (APP) scam, money mules and the herders behind them, account takeover, SIM swaps and deepfake payment fraud, then card fraud, phishing kits built for bank fraud and synthetic identities. A six-lesson module teaches crypto tracing, from reading a transaction and clustering addresses to stablecoin freezes, chain hopping and mixers, and the section closes on the professional launderers, OTC brokers and guarantee marketplaces that move scam proceeds at scale.
The fourth section turns the work into a programme and its products: requirements that look left of the loss, what a CTI analyst contributes to suspicious activity reports and 314(b) sharing, metrics that keep their denominator, and then typology alerts, detection rules, scam campaign reports, takedown referrals and freeze-ready referrals to law enforcement, platforms and peer banks.
Every lesson rests on real cases from court filings, sanctions actions and published research, and the missions put you on the fraud intelligence desk of a fictional UK bank. Nothing asks you to register on, deposit to or chat with a live scam. Each mission ends in something a bank, an exchange or a platform can act on.
What you will learn
- Follow a fraud from first contact to cash-out. Name the hand-offs between the lure, the platform, the payment, the mule and the cash-out, and which of them leave a trace you can reach.
- Know which payments can still be stopped. Read the payment rail and its reversibility, and know who can recall, freeze or block the money and for how long.
- Describe fraud in one vocabulary. Classify scams consistently and map an incident to MITRE's Fight Fraud Framework so fraud, cyber and AML teams read it the same way.
- Link accounts without false merges. Tell a shared device or payee that points to one controller from a shared network address or a big exchange that proves nothing.
- Read a fake storefront. Spot a clone firm, link scam sites through their payment identifiers, and know when shared hosting only proves a shared supplier.
- Find the mule behind the payment. Recognise pass-through accounts and the herder behind them, follow the second hop, and recall money while it is still there.
- Trace crypto with stated confidence. Read a transaction, cluster addresses with their limits, find the exchange deposit address, and say how sure you are of each link.
- Act inside the freeze window. Know who can freeze a stablecoin, how long the window stays open, and how much of a frozen balance belongs to one victim.
- Recognise professional laundering. Read guarantee marketplaces, OTC brokers and launderers for hire, and check direct and indirect sanctions exposure.
- Write products that stop the next payment. Produce typology alerts, detection rules, takedown reports and freeze-ready referrals that the receiver can act on the same day.
Who this path is for
- CTI analysts moving into fraud, scam or financial crime intelligence at banks, fintechs, payment firms, exchanges and platforms.
- Fraud and AML investigators who want the cyber and crypto side of the cases they already work.
- Trust and safety and scam-disruption teams that cluster scam infrastructure and refer it for takedown.
- Learners who finished the Cyber Threat Intelligence path and want a specialisation employers hire for.
Guides for this path
- Bulletproof Hosting and the Money Mule Ecosystem, ExplainedOne bulletproof hosting provider sanctioned in late 2025 had been serving attackers since 2015, outlasting nearly every ransomware gang that rented from it. This guide breaks down the two support layers that keep cybercrime running: bulletproof hosting infrastructure and the money mule networks that launder the proceeds, plus the 2025-2026 sanctions crackdown and what it means for CTI analysts.
Frequently asked questions
Fraud intelligence applies threat intelligence methods to scams and financial crime: it studies how fraud groups find victims, move money and cash out, and turns that into alerts, rules and referrals that stop the next payment. It sits between the fraud, cyber and anti-money laundering teams and gives them one picture of the same crime.
No. Every artifact comes from court filings, government releases, published research or the fictional case files in the missions. The path also teaches why a fraud intelligence team never registers on, deposits to or chats with a live scam.
No. Financial and blockchain terms are explained where they first appear. You do need the basics from the Cyber Threat Intelligence path, such as intelligence requirements, estimative language and TLP, which this path uses without re-teaching.
Relationship and investment scams, including pig butchering and fake trading platforms, the scam compounds behind them, business email compromise, authorised push payment fraud, card fraud, phishing kits and synthetic identities, and the money mule and professional laundering networks that move the proceeds.
Yes. A six-lesson module covers reading transactions, clustering addresses, finding the exchange deposit address, stablecoin freezes, chain hopping and mixers, and a mission has you trace funds through fictional blockchain exports.
Start from the victim's own records, such as the exchange withdrawal or the wallet they paid from. Read each transaction for its inputs and outputs, and cluster addresses with care: when an exchange sweeps many customers' deposit addresses together, one cluster swallows strangers, and one wrong guess at a change output sends every later hop after someone else's money. The usual goal is an exchange deposit address, because a regulated exchange runs know-your-customer checks and its records can be reached through legal process. State your confidence for each link rather than for the whole trace.
Yes, by the issuer, while the funds are still in that token. An issuer can freeze only its own token, so Tether can freeze USDT held at an address, as it did at the FBI's request in a case this path studies, but not money already swapped into something else. The catch is time: TRM Labs reports that many fraud-linked networks often move stablecoin funds onward within 48 hours, so a referral has to be ready to send. A freeze only stops movement. Turning frozen tokens into money a court can forfeit takes further legal steps, and someone has to show how much of the frozen balance belongs to which victim.
A money mule is a person whose bank or crypto account moves fraud proceeds on towards the criminals. Some know their role, some ignore obvious red flags, and some never realise, often because they were recruited through a fake job. Europol notes that a fake job recruiting mules always involves using your own bank account to move money, whatever the job title claims. Mules far outnumber the herders who direct them, so an investigation starts from the many accounts and works towards the few people behind them.
No. It is an intelligence course. You learn what a suspicious activity report needs from a threat intelligence analyst and what must never leak, but not how to run a compliance programme.
About ten hours: the lessons take roughly seven and the five missions about two to three.
Yes. Completing every step of the path, all eleven modules and the five missions, issues a CTI Academy certificate in your name. Each certificate carries a unique ID, and its QR code opens a public verification page, so an employer can confirm it without contacting us.
The first two modules, eight lessons on how fraud works as an industry and how a fraud intelligence team works, are free. The later modules and the missions need a premium subscription.