The Sapphire Network: How an International Fraud Empire Operates from Shadows to Call Centers

Infographic illustrating the Sapphire Network scam.
The Global Reach of Sapphire: Visualizing the multi-layered assembly line used by the Sapphire Network scam to target Western investors through "bait" domains and deceptive crypto-narratives.

The Sapphire Network scam is a multi-layered financial syndicate targeting European and Western citizens. Coordinated by an Israeli-led management team, the operation relies on technical developers based in Bulgaria and aggressive boiler-room call centers operating out of Georgia.

Quick Summary:

  • What it is: A multi-layered financial fraud syndicate targeting Western and European citizens through fake investment packages.
  • Current Status (2026): Active; the syndicate frequently rotates its 60+ domains and leverages privacy-first web hosts to evade takedowns.
  • Key Operations: Led by an Israeli management core, utilizing software developed in Bulgaria, and deploying high-pressure boiler-room call centers in Georgia.
  • Red Flags: Demands for cryptocurrency deposits, minimum entry fees (usually 250 EUR), and offshore privacy hosting.

Despite international scrutiny and domain takedowns, the network remains active in 2026. Rather than collapsing, the syndicate continues to adapt by rapidly cycling through new bait websites, leveraging privacy-focused web hosts, and deploying automated crypto-investment packages.

Key Takeaway: If you or someone you know has lost funds to platforms associated with this syndicate, report the scam through our secure reporting page to contribute to ongoing investigations and explore recovery options.

2026 Status Report: Active & Evolving Domains

According to threat intelligence reports from the Qurium Media Foundation and independent tracking, the Sapphire Network constantly rotates its active domains to evade blacklisting.

Original EntitySubsequent DomainCurrent Operational Status
BTCcapitalbtccapital.ioActive. Pivoting to “Fixed-Return” crypto packages during market volatility; uses manufactured “Capital Outflow” urgency.
Tactixinvestingtactix-invest.com / tactix.protactix-invest.com is unreachable; tactix.pro redirects to an unrelated business (tactix.ca).
Finxocapfinxocap.comActive and operational.
Orbonexorbonextrades.comActive and operational.
BproTradebprotrade.ioActive and operational.
Finbokfinbok.ioActive and operational.
Onyx-tradersonyx-traders.comActive and operational.
Rivobancrivobanc.comCurrently in a “warming” phase.
SIFXsifx.comActive, but utilizing geolocation-filtering software to block visitors from specific jurisdictions.
Tradomatixtradomatix.comActive and operational.
Ubsinvestingubsinvesting.pro / ubs-platform.ccImpersonating the legitimate UBS Group.
Vptradevptrade.comActive and operational.
Xnvestxnvest.comWarming up and preparing for relaunch.
Table showing the active status and current operational domain updates for entities linked to the Sapphire Network scam syndicate.

Additional Linked Brands

Independent digital forensics confirm that the Sapphire Network scam is also tied to the following entities:

A comprehensive blacklist containing over 60+ domains connected to this ongoing 2026 syndicate is available for download in PDF format.

The Leadership and Technical Infrastructure

Unlike standalone fraudulent websites, the Sapphire Network scam operates with corporate-level structure and compartmentalization:

  • The Israeli Strategy Core: Management, strategic direction, and proprietary software development are directed from Israel.
  • Tracking & Affiliate Software: The network relies on GetLinked.io, an affiliate lead-tracking platform developed by the Bulgarian firm Perspecta LTD and managed by Gal Friedman.
  • Marketing Leadership: An individual operating under the alias “James Collins” (real name: Ronen Nimrod Kapeika) serves as the Chief Marketing Officer, bridging the technical software with financial back-office operations.
  • Front Companies: Illicit cash flows are frequently masked behind corporate fronts, including MDR Solutions LTD (Madar), BTCcapital, BproTrade, FX Capital Group, Dukasbanc, and Vptrade.

The Georgian Call Centers

While management remains centralized abroad, the “muscle”(the sales agents interacting directly with victims)is outsourced to call centers in the Republic of Georgia to exploit lax local regulatory enforcement. Key operational clusters include:

  • The King David Business Center: A modern twin-tower complex situated along the Mtkvari River.
  • Vake District Offices: Discreet commercial suites allowing for rapid staff turnover.
  • Saburtalo Business Hubs: Dense tech and business districts housing mass telemarketing setups.

These hubs employ fluent speakers of English, German, French, and Spanish, trained extensively in high-pressure psychological manipulation and false-brokerage sales pitches.

The 6-Step Victim Lifecycle

The Sapphire Network scam relies on a systematic, industrial funnel to guide victims from initial ad exposure to total financial loss:

Step 1: Deploying Bait Campaign Web Pages

Fraudsters launch landing pages disguised as legitimate fintech or crypto opportunities. Common bait names include Bitcoin 360 AI, Bitcoin Circuit, Bitcoin Banker, and Bitcoin Bank.

To maintain uptime, these pages rely on offshore privacy-first web hosts that ignore international abuse complaints, do not require real ID verification, and accept cryptocurrency payments.

Some common web hosts that either knowingly or unknowingly make it easy for scammers to operate include:

  • Shinjiru Web Hosting (shinjiru.com.my – Malaysia)
  • AbeloHost (abelohost.com – Netherlands-claimed)
  • AlexHost (alexhost.com – Moldova)
  • FlokiNET (flokinet.is – Iceland)
  • Njalla (njal.la – Laos/Privacy-focused)
  • BlueAngelHost (blueangel.host – Bulgaria)
  • KoDDoS (koddos.net – Hong Kong)

Other Ways In Which the Sapphire Network Scam Masterminds Hide

It isn’t just shady or questionable hosts that protects them; these scammers use a multi-layered approach:

  • Besides favourable hosts, they use conducive registrars that offer the Whois privacy, conveniently hiding their email contacts and phone numbers from public records.
  • Many use Cloudflare or similar services as a front, conveniently hiding their “real” IP addresses. This makes it look like their sites are  hosted in the US when they are actually offshore.
  • They may hide their malicious traffic inside the encrypted traffic of a legitimate service (like Google or Amazon) to bypass security filters.

Before you sign up for any so-called “investment”, check the website’s hosting details. If it’s hosted by a host that prioritizes the privacy of their customers at the expense of vulnerable internet users, stay away. It’s a major red flag. Protect your money and your data by walking away immediately.”

Step 2: Contracting Lead Trackers

The Sapphire Network scam has contracted a “tracker service” known as “GetLinked”, which acts as a broker between the syndicate and dubious affiliate marketers. 

In this context, a “tracker service” is specialized software (and often a company/platform) that manages, tracks, and optimizes affiliate marketing campaigns, especially performance-based ones.

Run by an individual called Gal Friedman, the service assigns affiliates the “offers” that need to be promoted, the geolocation of those offers and to which target group (by language) the offer is targeting. These “offers” are linked to genuine-sounding brands and the affiliates are provided with information on how much compensation they can claim for each victim (conversion).

Then there’s an individual called Ronen Nimrod Kapeika a.k.a “James Collins”. He acts as the point of contact between the entity behind the tracking software and the core backoffice of the entire Sapphire Network scam.  

Step 3: Recruiting Through Major Affiliate Networks

Affiliate marketers are recruited through major affiliate networks such as ROI Collective, Supremedia and Affilomania-TrafficOn. They strategically choose these notable entities to increase their outreach and maximize  conversions. The affiliate marketers are responsible for “generating traffic” to the Sapphire Network’s dubious offers, essentially leading victims to the scammers.  

It is important to understand that the affiliates do not directly promote the brands owned by the Sapphire Network but rather use generic and legitimate-sounding entity names.

The reason here is to hide the Network’s brands from the general public, an approach that makes it harder for victims of previous scams linked to the network to connect the dots. 

Step 4: Social Media & Ad Spoofing

The affiliate marketers use different techniques to promote the so-called investments, including placing paid ads in Social Media.

To attract attention, gain credibility, and vouch for their “investments”, they often use names of celebrities and/or successful individuals, e.g. Elon Musk. 

Below are a few screenshots showing the use of Elon Musk’s photos and a video to direct unsuspecting visitors to Quantum AI and Immediate Granimator, two questionable online investment platforms. 

Sapphire Network scam fraudulent advertisement featuring unauthorized celebrity likeness of Elon Musk
An example of a Sapphire Network scam “bait” advertisement. The scam leverages unauthorized imagery of Elon Musk to create a false sense of institutional credibility and lure victims toward fraudulent investment portals.
Sapphire Network scam screenshot of a fake BBC news report promoting QuantumAI with Elon Musk.
A screenshot of a fake BBC news article template utilized in the Sapphire Network scam.
Sapphire Network scam screenshot featuring a fake Fox News broadcast about Immediate Granimator with Elon Musk
A screenshot of a fabricated Fox News report used by the Sapphire Network scam to promote the Immediate Granimator trading platform.

Affiliates often purchase traffic through third-party ad networks such as Los Pollos or Taco Loco. Another common tactic involves exploiting publishing platforms like Medium, where they post compelling articles to drive potential victims toward active scams. Furthermore, promotional efforts frequently extend to paid influencer videos, mobile app pop-ups, and direct SMS messaging.

Step 5: Data Submission

Victims who find the “investment opportunity” ads in social media and other methods outlined above appealing are re-directed to the respective sites to complete an online application form. They innocently provide their contact details, which are submitted to the scammers’ call centers. 

The Getlinked leads tracking software keeps track of which affiliate brought a victim. 

Step 6: The Boiler-Room Call

Agents from the Sapphire Network scam use the information provided in the sign-up forms to contact potential victims directly.

They use different VoIP (voice-over-IP) services for all outgoing calls and SMS to the victims. These advanced services enable them to spoof numbers, allocate numbers for inbound calls, and integrate their voice services with the customer relationship management software smoothly. 

Notably, the VOIP service providers know the locations where the calls are placed. 

Victims are asked to complete the enrollment process, which is finalized when the victim makes a financial transaction of 250 EUR (or the equivalent in the victim’s local currency).

The data leak and forensic investigations by the Qurium Media Foundation (released in early 2025) identified five primary VoIP providers used by the Sapphire Network: 

  • Squaretalk (Israel)
  • CommPeak (Israel)
  • Local03 (Israel)
  • B-Compliance (Israel)
  • NetSapiens (Singapore/International) 

Frequently Asked Questions (FAQ)

1. What is the Sapphire Network scam?

The Sapphire Network scam is a large-scale, multi-layered financial fraud syndicate that targets European and Western citizens. It uses coordinated web campaigns, fake crypto investment packages, and high-pressure telemarketing call centers to defraud individuals of their savings.

2. How do I know if a broker is connected to the Sapphire Network?

The syndicate frequently rotates its domains and launches new brands. However, common warning signs include high-pressure sales tactics, demands for crypto deposits, fake regulatory licenses, and hosting on privacy-focused networks (like Shinjiru or FlokiNET). Reviewing a regularly updated domain blacklist can help identify active threats.

3. What should I do if I am a victim of the Sapphire Network scam?

If you have lost funds to a platform associated with this network, document all communications, transaction hashes, and bank/crypto transfer receipts. Avoid engaging with recovery scammers who promise guaranteed fund returns for an upfront fee. Instead, report the incident through a secure scam-reporting page to aid ongoing cyber-forensic investigations.

By Errolle Collins

Errolle Collins is a seasoned finance expert and the founder of ScamReader.info. With a specialized academic background in accountancy (CPA) from Strathmore University, Errolle transitioned his analytical rigors into the world of financial journalism. Over the past decade, he has served as a strategic voice for leading global finance publications, accumulating over 10 years of experience in market analysis and investigative writing. Errolle’s deep-seated passion for online trading, specifically Forex and Cryptocurrency, led him to uncover the sophisticated "dark patterns" used by offshore brokers to defraud investors. After years of witnessing the devastating impact of financial fraud, he founded ScamReader.info in 2023. His mission is twofold: to provide traders with forensic-level broker analysis and to offer a clear, actionable roadmap for victims to report scams, file claims, and pursue fund recovery. Connect with me on LinkedIn to verify my professional background and 10+ years of financial investigative experience.

Leave a Reply

Your email address will not be published. Required fields are marked *