The Sapphire Network scam is a multi-layered financial syndicate targeting European and Western citizens. Coordinated by an Israeli-led management team, the operation relies on technical developers based in Bulgaria and aggressive boiler-room call centers operating out of Georgia.
Quick Summary:
- What it is: A multi-layered financial fraud syndicate targeting Western and European citizens through fake investment packages.
- Current Status (2026): Active; the syndicate frequently rotates its 60+ domains and leverages privacy-first web hosts to evade takedowns.
- Key Operations: Led by an Israeli management core, utilizing software developed in Bulgaria, and deploying high-pressure boiler-room call centers in Georgia.
- Red Flags: Demands for cryptocurrency deposits, minimum entry fees (usually 250 EUR), and offshore privacy hosting.
Despite international scrutiny and domain takedowns, the network remains active in 2026. Rather than collapsing, the syndicate continues to adapt by rapidly cycling through new bait websites, leveraging privacy-focused web hosts, and deploying automated crypto-investment packages.
Key Takeaway: If you or someone you know has lost funds to platforms associated with this syndicate, report the scam through our secure reporting page to contribute to ongoing investigations and explore recovery options.
2026 Status Report: Active & Evolving Domains
According to threat intelligence reports from the Qurium Media Foundation and independent tracking, the Sapphire Network constantly rotates its active domains to evade blacklisting.
| Original Entity | Subsequent Domain | Current Operational Status |
| BTCcapital | btccapital.io | Active. Pivoting to “Fixed-Return” crypto packages during market volatility; uses manufactured “Capital Outflow” urgency. |
| Tactixinvesting | tactix-invest.com / tactix.pro | tactix-invest.com is unreachable; tactix.pro redirects to an unrelated business (tactix.ca). |
| Finxocap | finxocap.com | Active and operational. |
| Orbonex | orbonextrades.com | Active and operational. |
| BproTrade | bprotrade.io | Active and operational. |
| Finbok | finbok.io | Active and operational. |
| Onyx-traders | onyx-traders.com | Active and operational. |
| Rivobanc | rivobanc.com | Currently in a “warming” phase. |
| SIFX | sifx.com | Active, but utilizing geolocation-filtering software to block visitors from specific jurisdictions. |
| Tradomatix | tradomatix.com | Active and operational. |
| Ubsinvesting | ubsinvesting.pro / ubs-platform.cc | Impersonating the legitimate UBS Group. |
| Vptrade | vptrade.com | Active and operational. |
| Xnvest | xnvest.com | Warming up and preparing for relaunch. |
Additional Linked Brands
Independent digital forensics confirm that the Sapphire Network scam is also tied to the following entities:
A comprehensive blacklist containing over 60+ domains connected to this ongoing 2026 syndicate is available for download in PDF format.
The Leadership and Technical Infrastructure
Unlike standalone fraudulent websites, the Sapphire Network scam operates with corporate-level structure and compartmentalization:
- The Israeli Strategy Core: Management, strategic direction, and proprietary software development are directed from Israel.
- Tracking & Affiliate Software: The network relies on GetLinked.io, an affiliate lead-tracking platform developed by the Bulgarian firm Perspecta LTD and managed by Gal Friedman.
- Marketing Leadership: An individual operating under the alias “James Collins” (real name: Ronen Nimrod Kapeika) serves as the Chief Marketing Officer, bridging the technical software with financial back-office operations.
- Front Companies: Illicit cash flows are frequently masked behind corporate fronts, including MDR Solutions LTD (Madar), BTCcapital, BproTrade, FX Capital Group, Dukasbanc, and Vptrade.
The Georgian Call Centers
While management remains centralized abroad, the “muscle”(the sales agents interacting directly with victims)is outsourced to call centers in the Republic of Georgia to exploit lax local regulatory enforcement. Key operational clusters include:
- The King David Business Center: A modern twin-tower complex situated along the Mtkvari River.
- Vake District Offices: Discreet commercial suites allowing for rapid staff turnover.
- Saburtalo Business Hubs: Dense tech and business districts housing mass telemarketing setups.
These hubs employ fluent speakers of English, German, French, and Spanish, trained extensively in high-pressure psychological manipulation and false-brokerage sales pitches.
The 6-Step Victim Lifecycle
The Sapphire Network scam relies on a systematic, industrial funnel to guide victims from initial ad exposure to total financial loss:
Step 1: Deploying Bait Campaign Web Pages
Fraudsters launch landing pages disguised as legitimate fintech or crypto opportunities. Common bait names include Bitcoin 360 AI, Bitcoin Circuit, Bitcoin Banker, and Bitcoin Bank.
To maintain uptime, these pages rely on offshore privacy-first web hosts that ignore international abuse complaints, do not require real ID verification, and accept cryptocurrency payments.
Some common web hosts that either knowingly or unknowingly make it easy for scammers to operate include:
- Shinjiru Web Hosting (shinjiru.com.my – Malaysia)
- AbeloHost (abelohost.com – Netherlands-claimed)
- AlexHost (alexhost.com – Moldova)
- FlokiNET (flokinet.is – Iceland)
- Njalla (njal.la – Laos/Privacy-focused)
- BlueAngelHost (blueangel.host – Bulgaria)
- KoDDoS (koddos.net – Hong Kong)
Other Ways In Which the Sapphire Network Scam Masterminds Hide
It isn’t just shady or questionable hosts that protects them; these scammers use a multi-layered approach:
- Besides favourable hosts, they use conducive registrars that offer the Whois privacy, conveniently hiding their email contacts and phone numbers from public records.
- Many use Cloudflare or similar services as a front, conveniently hiding their “real” IP addresses. This makes it look like their sites are hosted in the US when they are actually offshore.
- They may hide their malicious traffic inside the encrypted traffic of a legitimate service (like Google or Amazon) to bypass security filters.
Before you sign up for any so-called “investment”, check the website’s hosting details. If it’s hosted by a host that prioritizes the privacy of their customers at the expense of vulnerable internet users, stay away. It’s a major red flag. Protect your money and your data by walking away immediately.”
Step 2: Contracting Lead Trackers
The Sapphire Network scam has contracted a “tracker service” known as “GetLinked”, which acts as a broker between the syndicate and dubious affiliate marketers.
In this context, a “tracker service” is specialized software (and often a company/platform) that manages, tracks, and optimizes affiliate marketing campaigns, especially performance-based ones.
Run by an individual called Gal Friedman, the service assigns affiliates the “offers” that need to be promoted, the geolocation of those offers and to which target group (by language) the offer is targeting. These “offers” are linked to genuine-sounding brands and the affiliates are provided with information on how much compensation they can claim for each victim (conversion).
Then there’s an individual called Ronen Nimrod Kapeika a.k.a “James Collins”. He acts as the point of contact between the entity behind the tracking software and the core backoffice of the entire Sapphire Network scam.
Step 3: Recruiting Through Major Affiliate Networks
Affiliate marketers are recruited through major affiliate networks such as ROI Collective, Supremedia and Affilomania-TrafficOn. They strategically choose these notable entities to increase their outreach and maximize conversions. The affiliate marketers are responsible for “generating traffic” to the Sapphire Network’s dubious offers, essentially leading victims to the scammers.
It is important to understand that the affiliates do not directly promote the brands owned by the Sapphire Network but rather use generic and legitimate-sounding entity names.
The reason here is to hide the Network’s brands from the general public, an approach that makes it harder for victims of previous scams linked to the network to connect the dots.
Step 4: Social Media & Ad Spoofing
The affiliate marketers use different techniques to promote the so-called investments, including placing paid ads in Social Media.
To attract attention, gain credibility, and vouch for their “investments”, they often use names of celebrities and/or successful individuals, e.g. Elon Musk.
Below are a few screenshots showing the use of Elon Musk’s photos and a video to direct unsuspecting visitors to Quantum AI and Immediate Granimator, two questionable online investment platforms.



Affiliates often purchase traffic through third-party ad networks such as Los Pollos or Taco Loco. Another common tactic involves exploiting publishing platforms like Medium, where they post compelling articles to drive potential victims toward active scams. Furthermore, promotional efforts frequently extend to paid influencer videos, mobile app pop-ups, and direct SMS messaging.
Step 5: Data Submission
Victims who find the “investment opportunity” ads in social media and other methods outlined above appealing are re-directed to the respective sites to complete an online application form. They innocently provide their contact details, which are submitted to the scammers’ call centers.
The Getlinked leads tracking software keeps track of which affiliate brought a victim.
Step 6: The Boiler-Room Call
Agents from the Sapphire Network scam use the information provided in the sign-up forms to contact potential victims directly.
They use different VoIP (voice-over-IP) services for all outgoing calls and SMS to the victims. These advanced services enable them to spoof numbers, allocate numbers for inbound calls, and integrate their voice services with the customer relationship management software smoothly.
Notably, the VOIP service providers know the locations where the calls are placed.
Victims are asked to complete the enrollment process, which is finalized when the victim makes a financial transaction of 250 EUR (or the equivalent in the victim’s local currency).
The data leak and forensic investigations by the Qurium Media Foundation (released in early 2025) identified five primary VoIP providers used by the Sapphire Network:
- Squaretalk (Israel)
- CommPeak (Israel)
- Local03 (Israel)
- B-Compliance (Israel)
- NetSapiens (Singapore/International)
Frequently Asked Questions (FAQ)
1. What is the Sapphire Network scam?
The Sapphire Network scam is a large-scale, multi-layered financial fraud syndicate that targets European and Western citizens. It uses coordinated web campaigns, fake crypto investment packages, and high-pressure telemarketing call centers to defraud individuals of their savings.
2. How do I know if a broker is connected to the Sapphire Network?
The syndicate frequently rotates its domains and launches new brands. However, common warning signs include high-pressure sales tactics, demands for crypto deposits, fake regulatory licenses, and hosting on privacy-focused networks (like Shinjiru or FlokiNET). Reviewing a regularly updated domain blacklist can help identify active threats.
3. What should I do if I am a victim of the Sapphire Network scam?
If you have lost funds to a platform associated with this network, document all communications, transaction hashes, and bank/crypto transfer receipts. Avoid engaging with recovery scammers who promise guaranteed fund returns for an upfront fee. Instead, report the incident through a secure scam-reporting page to aid ongoing cyber-forensic investigations.
