Sentinel Vault
← All field notes
Cyber Leadership & Risk · June 1, 2026

Mrs. Lao Lost $475,000. Local Law Enforcement Is Losing the Race to Stop It.

Mrs. Lao Lost $475,000. Local Law Enforcement Is Losing the Race to Stop It.

Mrs. Joslyn Lao walked into a police front desk holding three months of bank statements and a printout of an account balance that read $1,075,000. She put in $475,000 of her own money. The screen said it grew to a million. When she tried to withdraw the gains, the platform stopped responding. The man who introduced her to the investment, the one she'd been talking to for weeks on a messaging app, was gone. His profile was deleted. His phone number didn't ring.

She tested the platform first. Months earlier, she put in $500 and watched it grow to $900, then to $3,200 across two deposits. She pulled $2,300 back out, into her own bank account. The system worked. She verified it.

Then she put in $90,000. Another $90,000 the next week. More after that. By the time it stopped, the total reached $475,000, and the screen showed her gains were larger than her principal. Her friend told her this was the window. The platform was capped, only people he introduced could get in.

When she tried to withdraw the second time, every button stopped working.

This isn't a one-off case. It happens every day, several times over. The FBI's Internet Crime Complaint Center received more than a million complaints in 2025 and tracked $20.9 billion in reported losses, a 26 percent jump in a single year. Cryptocurrency investment fraud, the bucket pig butchering lives in, accounted for $7.2 billion of that across more than 61,000 complaints. Adults 60 and over absorbed $7.7 billion of the total. Over 12,000 of them each lost more than $100,000.

The numbers aren't the story. The story is what happened when Mrs. Lao walked into that police station.

The Trust Ladder

People who haven't lived this case keep saying the same thing: how could anyone fall for that? It's a fair question, and the answer matters.

Mrs. Lao didn't fall for a fantasy. She fell for a system that proved itself.

That's the mechanism of pig butchering, and it's the part most reporting misses. The scammer doesn't ask for $475,000. They ask for $500. They let her see it grow on a slick web interface that looks indistinguishable from a real trading platform. Then they let her withdraw. The successful withdrawal is the scam. The screen, the chart, the price action: none of that's the trap. The trap is the moment $2,300 hits her real bank account.

After that moment, she isn't being asked to trust a stranger on the internet anymore. She's being asked to trust the platform that already paid her. Those are different decisions. The first one she'd have refused. The second one she made, and almost anyone would have made it.

Then comes the relationship. The man on the other end of the messaging app isn't running game in a single afternoon. He's running it for weeks, sometimes months. He sends pictures of his life. He asks about her kids. He texts good morning. He builds a person, and she builds a friendship around that person, and inside that friendship he places an investment opportunity that's already proven itself with a successful withdrawal.

Greed didn't put $475,000 into that platform. Manufactured evidence did.

The operations running this script aren't improvising. They aren't lone scammers on a laptop. They're forced-labor compounds in Cambodia, Myanmar, and Laos, staffed by trafficked workers running standardized playbooks for organized criminal enterprises. In October 2025, the U.S. Department of Justice seized $15 billion in cryptocurrency from one such operation: the Prince Group, run out of Cambodia by Chen Zhi. That single indictment described at least ten forced-labor camps. The seizure was the largest in DOJ history. It involved zero local police departments.

What Mrs. Lao Got

When she walked into the front desk, she got a report number. A polite officer took her information and copied her account statements. He told her honestly that the case would be hard. He suggested she also file with the FBI's IC3.

That was the right thing for him to do. It was also about the maximum his department could do.

Her case went into a queue with shoplifting, stolen catalytic converters, residential burglaries, and warrants service. Somewhere down the line a detective got assigned to it. That detective carried sixty other cases. The suspect was in Cambodia. The money moved through a US-based "investor's" account into a cryptocurrency exchange, then through wallets in Southeast Asia within forty-eight hours of leaving her bank. There was no scene to process, no witness to interview, no warrant to serve.

Six months later, no charges, no recovery, no updates.

This is the rule, not the exception. It's why local law enforcement is losing.

Local Law Enforcement Is Losing

They're losing. Every quarter, the gap widens.

The FBI's Recovery Asset Team is the closest thing the system has to a functioning rapid-response mechanism. In 2025, the team initiated 3,900 fraud response actions against attempted thefts totaling $1.1 billion, and successfully froze $679 million. That's a 58 percent success rate on the cases they touch, which is excellent work. It's also 3.3 percent of total reported losses. The other 96.7 percent has no equivalent.

Detectives aren't lazy and chiefs aren't incompetent. The case management architecture local law enforcement uses was designed for a different problem. It assumes a crime has a scene, a perimeter, a suspect within reach, evidence on a hard drive or in a glove compartment, and a single victim whose case is the unit of investigation. Cybercrime has none of those properties.

When a department gets a pig butchering report, the case file describes one victim, one suspect (a name on a messaging app), one transaction history, one jurisdiction (whichever the victim lives in). What the file doesn't describe, because the system has no field for it, is that 47 other departments received nearly identical reports the same week from the same compound, that the same domestic mule account received deposits from three other victims, or that the wallet addresses match an enforcement intelligence package the federal government already has open.

A single $475,000 case is hard to investigate. Fifty consolidated cases against the same operation, totaling $25 million, with the same mule network, the same IP infrastructure, the same playbook screenshots, the same Telegram handles: that's a case the system already knows how to make. It's the case the system makes against narcotics networks every day.

Local law enforcement doesn't currently consolidate.

That's the architecture failure. Everything downstream of it is a symptom.

Three Reinforcing Failures

The architecture failure is the root cause. Three inputs make it harder to fix.

Executive leadership. Police chiefs and sheriffs in the United States come up through patrol, then detective, then sergeant, then command. The model of policing they learned was built before cybercrime existed as a major loss category. When they make budget cases to mayors and county commissioners, they ask for what they were trained to ask for: more patrol, more gang work, more visible presence. Cyber doesn't get a seat at that table because nobody at the table came up understanding it. This is a generational problem and it won't solve itself.

Budget. Cybercrime work costs real money before it makes any visible difference. A capable digital forensics lab, blockchain analysis subscriptions, training certifications, and one or two analysts who can actually read a wallet trace will run a mid-sized agency a quarter million dollars before they close a single case. Compared to a marked patrol car, which is visible, politically defensible, and the kind of expenditure a county commissioner can show his constituents, it's the worst possible budget ask. So it doesn't get made.

Staffing the right people. You can't retrain a 25-year patrol veteran to be a cybercrime investigator on a two-week course. The skills are different. You need someone who came up with computers, who can read network logs, who's comfortable with court records and crypto wallets in the same sitting. Most departments have one such person buried somewhere in patrol because nobody upstream knew where to put them. Many departments have none. Even the agencies that recognize the need are struggling to hire: the talent pool is small, the pay is below market, and police reform pressures have made the recruiting pipeline thinner across the board.

Fix any one of these three and you still lose, because the architecture problem dominates. Fix all three without fixing the architecture and you have a well-staffed, well-funded department playing whack-a-mole at scale.

We Know How to Do This. We're Choosing Not To.

We already operate task forces against every other category of organized crime. Joint Terrorism Task Forces handle terror. OCDETF handles narcotics. The Secret Service runs Electronic Crimes Task Forces for high-dollar financial cybercrime. These are mature multi-jurisdictional structures with federal funding. They consolidate cases across agencies, share intelligence in close to real time, and target the network instead of the individual node.

We don't currently have an equivalent structure aimed at the consumer-level fraud emptying retirement accounts a quarter-million dollars at a time. There are pieces. The FBI has the Recovery Asset Team, the Scam Center Strike Force, IC3 itself. The USSS has ECTFs that occasionally absorb pig butchering work when the dollar values are high enough. The DOJ has had real wins at the very top, like the Prince Group seizure. But the bottom of the funnel, where Mrs. Lao stood at the front desk, has no consolidating mechanism that loops her case into the same intelligence flow that produced the seizure.

A real task force structure for this category would do four things local law enforcement currently doesn't.

Consolidate at intake. When a victim reports a pig butchering case to a local department, the IOC fingerprints (wallet addresses, exchange accounts, Telegram handles, platform URLs, mule account numbers) get pushed into a shared intelligence repository within hours, not weeks. Other departments matching the same fingerprints get notified automatically. The investigation has national context within 24 hours of intake, not never.

Target the mules first. Money doesn't move directly from Mrs. Lao to Cambodia. It moves through a domestic mule account, usually a US-based person, often unwitting and often recruited via a different romance or job scam. The mules are the only domestic touchpoint local law enforcement can realistically reach. Arrest the mule, seize the phone, and you get wallet addresses, Telegram messages, payment screenshots, instructions from handlers. Those artifacts feed federal investigations. The mules are the wedge.

Synthesize across cases. Once you have ten, fifty, a hundred consolidated reports tied to the same operation, the case writes itself. Federal prosecutors care about $25 million enterprise crime. They have categories for it. There's no category for one woman who lost $475,000 in isolation.

Trigger federal escalation at attribution. When IOC consolidation links a domestic mule network to a named overseas criminal organization, the federal task force takes the next step. That hand-off is the mechanism. It's exactly the model the OCDETF system uses for narcotics, and it works.

None of this requires inventing new authority. It requires a deliberate decision to apply existing architecture to a category of crime the current architecture wasn't designed for.

The model doesn't exist today at the consumer-fraud scale this problem demands. Every quarter we operate without it, the gap widens.

What to Tell Your Family. What to Tell Your Team.

If you're reading this on behalf of someone you love, or an organization you're responsible for, here's the short version.

Real investments don't come through a relationship that didn't exist 90 days ago, don't reward small test withdrawals to set up larger ones, and don't have closing windows introduced by a new friend. If the introduction is social, the chart is private, and the gains beat the broad market for weeks, the platform is engineered. A successful test withdrawal isn't proof. It's bait.

Slow down. Talk to the person who pays you, not the person who texts you. Run the platform name past your bank's fraud team before you put in money you can't afford to lose. There's no such thing as rich-quick. Every pig butchering case ends the same way.

If this has already happened to you or someone you love:

Call the bank first, the same day. If the money left within the last 72 hours, the FBI's Recovery Asset Team has a real chance of freezing some of it through the Financial Fraud Kill Chain process, but only if your bank moves quickly.

If the money went into crypto, recovery is very hard. File anyway. Report to IC3.gov immediately with every detail you have: wallet addresses, exchange screenshots, the platform URL, the handler's social media profile, the dates and amounts of every transaction. Also file with your state Attorney General's consumer protection unit and your local police department.

Don't expect your local police to investigate. Hope for it, but plan for the actual outcome. The IC3 filing is what feeds the consolidating intelligence that eventually makes a Prince Group seizure possible, even when your individual case will never see a courtroom.

To Chiefs and Sheriffs Reading This

Cybercrime is organized crime. It isn't a specialty. The architecture you already deploy against narcotics task forces is the architecture this category requires. The case management model that's served patrol crime well for forty years wasn't built for this problem, and individual detectives working harder can't retrofit it into one.

Every quarter you don't make this case to your county commissioners, your state legislators, and your federal partners, the people who pay your salaries lose more. Mrs. Lao's $475,000 is part of that gap. So is every retirement account being emptied this week in your jurisdiction by an operation you have no architecture to consolidate against.

The model exists. The will to deploy it at the scale this problem requires is what's missing.

That part is a leadership decision.

This isn't a budget problem, a staffing problem, or a technology problem. It's a decision.

About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end: the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Keep pulling the thread
The fiction version

Fleeced Nation is a crime series about industrialized fraud, from the elder-fraud call centers to the quiet machinery that turns dirty cash clean. Same terrain as the case files, minus the parts a report will not hold. I started it as fiction. The case files keep publishing the sequel.

fleecednation.com ↗
Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.