Financial Forensics - Litigation Consulting - QuickRead Top Story

26 Years of Internet Crime Reports: From Beanie Babies to Investment Scams (Part I of II)

Internet fraud continues to thrive. In this article, the author summarizes the types of fraud and how online fraud will continue to evolve, and what readers can do to recognize what form fraud will take.


When the FBI’s Internet Fraud Complaint Center (IFCC, later renamed to IC3) first opened its doors in May 2000, it took in a mere 20,014 complaints in the first partial year of operation.[1] A quarter-century later, it has taken in more than 9 million complaints, with $11.366 billion in cryptocurrency related losses alone in a single year.[2] These annual reports are a chronicle of growing victimization and a record of analysts who flagged threats that would later dominate the landscape.

The IC3 was initially established as a partnership between the FBI and the National White Collar Crime Center to collect and analyze data, and to develop referrals related to cybercrime. One of its first reports was titled, Internet Auction Fraud, which identified six categories of fraud complaint items: “Beanies” at 27 percent, video games at 24 percent, laptops at 18 percent, cameras at 14 percent, desktops at 9 percent and jewelry at 8 percent. Data trends showed that 64 percent of internet fraud complaints were related to auctions, 99.2 percent were under $10,000, and 92.2 percent of perpetrators were in the United States.[3] At this time, the word online could be spelled with a hyphen, “on-line” and visible site maps were a thing.[4] Reported losses the next year, in 2001, totaled $17.8 million across all complaint types combined.[5] In 2005, a colorful report cover with a world map overlaid with 0s and 1s that never goes out of style.

What makes cryptocurrency interesting is that it amplified existing patterns documented in IC3 reports since 2001. Just as the Crypto Wars and the 2008 U.S. Financial Crisis primed bitcoin, the same elements informed and exacerbated underlying perpetrator patterns. The early IFCC analysts were right about who would be victimized, how they would be reached, and where the money would go. The chart below shows total complaint losses as they were reported each year.

Figure 1: Total Losses Reported to IC3 over Time

IC3 Historical Eras

The categories tracked in reported crime types shifted in waves; early warnings in the annual reports repeatedly identified what would become a dominant threat. The first era of IC3 history, 2001 to 2007, is eBay Nation when internet fraud largely followed internet commerce and the reports are basically love letters to the peer-to-peer auction site. The first statistics in 2000 show auction fraud at 64.1 percent of all complaints, and by 2004 it peaked at 71.2 percent of all referrals.[6]

The complaints exemplify dot-com optimism gone wrong where people won and paid for Pontiac Trans Ams, restored ATVs, designer handbags, and Beanie Babies, but their beloved treasures never arrived. The reports of this era treat the internet as something users used cautiously. The 2005 case highlights include a Beanie Baby fraud. The most trusted federal cybercrime entity in America was, in 2005, taking Beanie Baby fraud seriously enough to use it as a case study; this tells you pretty much everything you need to know about American culture at the time. Fraud followed the places where people spent their time and money. In the early 2000s, that place was eBay.

Buried in the 2001 report is an astute observation that the proportion of individuals losing at least $5,000 is higher for those 60 years and older than for any other age category. That single sentence anticipated two decades of attention with the Elder Abuse Prevention and Prosecution Act in 2017, a DOJ Elder Justice Initiative shortly after, and a standalone Elder Fraud Report every year since.

The next era, 2008 through 2014, is Trust Me, Bro, where fraud primarily targeted relationships over transactions. The victim might trust a government agency, an employer, a lender, a romantic partner, or eventually a social media persona. The reported losses for 2009 were more than double 2008, but the increase is dwarfed by more recent years. Once the 2008 U.S. financial crisis hits, the patterns change. The 2009 report introduces an Economic Stimulus Scam in which fraudsters used a recorded voice mimicking President Barack Obama that promised government funds at websites called nevergiveitback and myfedmoney.[7] The same report describes work-from-home scams, survey scams between employee and employer relationships during the current economic crisis, and pop-up ads for fake antivirus software.

In 2011, the annual report gets a dark mode cover and the top complaint category becomes FBI impersonation and related scams at 35,764 total, which is a little meta. Impersonation became a dominant fraud type when the FBI’s pop culture brand was saturated with do-gooder authority (for instance, the original CSI shows, Without a Trace, and Criminal Minds were all running concurrently). Criminals weaponized that newfound market awareness. The 2011 report also flags Loan Intimidation Scams with 9,968 complaints, which really feels like the foreclosure crisis reskinned in scam form.

By 2012, the trust model evolved into the romance/Match.com phase of the broader trust first trend. It is love online, plus some scams. The 2012 report dedicates a section to romance scams, and the language is poetic like a PBS period narrator, “Be cautious of individuals who claim it was destiny or fate and you are meant to be together, or claim God brought you to him/her. They often claim to love you within 24 to 48 hours.” The IC3 tries to describe online dating fraud and issues warnings to people who had just discovered online dating. The 2012 to 2014 reports also show changes in the 419/overpayment fraud, with versions of the scam migrating from e-mail to dating sites without much change in its essential script.[8] The 2014 report flagged social media as a growing trend and noted that complaints had quadrupled over five years. Social media would continue to be traced as a descriptor for another seven years, showing consistency in the number of complaints. Viewed with hindsight, the warning foretells the adaptation of social media to expedite identification and access to victims, and maximize inherited trust through online acquaintances.

The next era, 2015 through 2019, is Crypto Enters the Chat. Following the seizure of the Silk Road Marketplace and the collapse of the exchange controlling 70 percent of crypto at the time (Mt. Gox), crypto enters the proverbial chat. The 2014 report is the first to dedicate a section to Popular Virtual Currency Schemes, but these years are not included in subsequent recaps.[9] The 2015 and 2016 reports specifically called out the fact that ransomware payments were demanded “typically in virtual currency such as BitCoin.”[10] Tech support fraud appeared as a category (Microsoft, IRS, and Apple impersonations) and click-jacking, doxing, and pharming appear as defined terms in the glossaries. The years immediately preceding the pandemic saw growth in nearly everything. In 2018, the Recovery Asset Team was introduced and in 2019, it was the Elder Justice Initiative. Sextortion appears as a tracked category and SIM swap becomes a recognized thing. BEC scams evolved from fake letters from princes needing help to lawyers demanding confidential wires, then real estate closings and payroll deposits. Fraud was becoming broader, faster, and more interconnected, and all the changes set the stage for what came next.

The years 2020 through 2022 represent The Great Compression. The pandemic did not create entirely new forms of internet crime so much as it compressed years of technological, economic, and social change into a very short period of time.[11] In these years, crime adapts to lockdown (as we all did) and prime targets become the places where people seek help such as CARES Act fraud, PPP loan fraud, fake PPE, vaccine scams, and deepfake Zoom calls for e-mail compromise. By 2022, investment fraud overtakes BEC scams and pig butchering first emerges from its curiosity cocoon to become an identifiable pattern among complaints.[12] That shift foretold the integration of investment scams, romance scams, crypto scams, and recovery scams into a single model aimed at high value targets.

Crypto collapses also plagued 2022 with Terra Luna, FTX, and oh, about a dozen others. These collapses and the early days of pig butchering contributed to the creation of a large group of newly desperate, financially literate, semi-shamed people, which is exactly the target market for pig butchering; the wide availability of targets, paired with easier access, created the perfect conditions for expansion.[13] Previously separate fraud categories began collapsing into one another. A victim might be recruited through a romance narrative, directed into an investment opportunity, advised to transact with cryptocurrency, and later targeted by a recovery scam. The boundaries between crime types became increasingly difficult to draw. The final era, 2023 through 2025, is Rise of the Machines (and arguably, is also the current era). Pig butchering becomes industrialized and recovery scams arrive with the help of voice clones, deepfake employment interviews, generative AI investment clubs, and AI-written romance scam scripts. Criminals increasingly rely on systems capable of producing convincing content faster, cheaper, and at greater scale than any human operation that preceded them.[14] 

In Conclusion

Viewed through the IC3 reports, the progression of internet crime is a coherent flow of user preferences: eBay Nation tracked how commerce moved online; Trust Me, Bro tracked relationships online; Crypto Enters the Chat tracked assets online; The Great Compression pushed everyone and everything online; and the Rise of the Machines increasingly automates deception itself. The 2025 AI-Related descriptor, with about $893 million in reported losses, suggests the next shift may be automation of the trust-building process itself.[15] Internet crime is not suddenly changing beyond recognition every time you turn around. These annual reports are much more than the sum of their parts because they show a long-running record of indicators, warning signs, and trends long before the next big thing was even a thing. For investigators, analysts, attorneys, and policymakers, the next big thing is probably already in the data as a descriptor, a glossary entry, or a footnote. History suggests early signals warrant attention as actionable intelligence instead of curiosities or outliers.

[1] Original website for the Internet Fraud Council as it appeared on May 20, 2000, https://web.archive.org/web/20000520042835/http://www.internetfraudcouncil.org/ and the original November 2000 statistics, https://web.archive.org/web/20010417233659/http://www.ifccfbi.gov/strategy/stats110300.asp.

[2] 2025 Annual Report, Internet Crime (1) Complaint (2) Center (3), aka IC3.

[3] Six-Month Data Trends Report, May–November 2000, Internet Fraud Complaint Center. Original archived at https://web.archive.org/web/20010801181604/http://www.ifccfbi.gov/strategy/6monthreport.PDF

[4] See the National White Collar Crime Center’s website as it appeared on May 10, 2000, https://web.archive.org/web/20000510191914/http://www.nw3c.org/about.htm

[5] In 2025, the value of losses reported in the cryptocurrency category alone achieves over 638 times that figure.

[6] IC3 works as a central complaint collection point and then assesses and/or routes the complaint for investigation.

[7] The original report apparently used auto correct on the President’s actual first name, Barack. The word Barrack appears in the report instead, but this term is not his name, this term is a building for soldiers.

[8] These were originally described as Nigerian letter scams. The crime type 419 is a reference to the Nigerian criminal code that relates to a specific type of Advance Fee schemes; however this crime type was reported alongside the Advance Fee crime type and disappears in more recent years (possibly replaced by Overpayment in 2016).

[9] The cryptolocker ransomware is in the 2013 report. The brief synopsis says payment is sent to the perpetrator “using various methods”. All ransomware complaints in 2013 total $539,562.

[10] Yes, that is the original capitalization. The examples listed for cryptocurrency were Bitcoin, Litecoin, and Potcoin, etc.

[11] The COVID-19 pandemic accelerated the adoption of virtual appearance, delivery, streaming, and other digitizations.

[12] As in, a butterfly that is also a butcher by trade, not a person who butchers butterflies because that would not make any sense. The 2021 report mentions it but more as a variant of a romance scam and even now, people have a hard time differentiating between the two because the quickest way to a person’s dollars is apparently an arrow to the heart (and not the knee, who knew?).

[13] Well, those characteristics plus a retirement account large enough to make it worth a scammer’s while.

[14] As you do in most businesses.

[15] I also have the benefit of writing this more than halfway through 2026.


Dorothy Haraminac, MBA, MAFF, CFE, LPI, provides financial forensics, digital forensics, and blockchain forensics under YBR Consulting Services, LLC and teaches software engineering and digital forensics at Houston Christian University. Ms. Haraminac is one of the first court-qualified testifying experts on cryptocurrency tracing in the United States and provides pro bono assistance to victims of cryptocurrency investment scams to gather and summarize evidence needed to report to law enforcement, regulators, and other parties. If you or someone you know has been victimized in an investment scam, report it to local, state, and federal law enforcement as well as federal agencies such as the FTC, the FCC, and the IRS.

Ms. Haraminac can be contacted at (346) 400-6554 or by e-mail to dh@ybr.solutions.

The National Association of Certified Valuators and Analysts (NACVA) supports the users of business and intangible asset valuation services and financial forensic services, including damages determinations of all kinds and fraud detection and prevention, by training and certifying financial professionals in these disciplines.