Skip to main content

Giving the Caffeine Store a Jolt: How Feds Use Seizure and Forfeiture To Battle Phishing Scams

Kit Yona, M.A.

Article by: Kit Yona, M.A.

Legal Writer

Reviewed by Joseph Fawbush, Esq. | Last updated on

You tried. You warned your parents, aunts, uncles, and grandparents to be careful with any suspicious emails, texts, or phone calls. Implored them to always check and double-check before providing any important private information, to think twice before sending money, and to confirm that the message came from the actual source. Given the ever-increasing levels of sophistication employed by scammers, it may have been inevitable that a loved one would trip up.

Who are these con artists, and why are these scams so effective? As shown by a recent Federal Bureau of Investigation (FBI) forfeiture warrant from February 2026, cybercrime has come a long way from the days of rich Nigerian “princes” and malware like AOHell. Phishing, which involves deceptive tactics to obtain and use someone else’s personal and financial information, continues to claim new victims, aided by extremely effective AI-generated emails. The online criminal world even contains operations like the Caffeine Store, which offers the tools necessary for phishing scams through monthly subscriptions.

Or, more accurately, the Caffeine Store offered criminal facilitation before the FBI used a seizure warrant in 2023 to freeze over $2 million in cryptocurrency from an online account believed to belong to a scammer based in Egypt. Let’s take a look at how federal agents are adapting to strip cybercriminals of their online anonymity and reclaim their ill-gotten gains, along with red flags to watch for to avoid becoming a cautionary tale yourself.

Back in My Day, We Had To Go Door-to-Door Selling Fake Magazine Subscriptions To Scam People

The internet has brought previously unimaginable ease and convenience to communication, commerce, and a host of other aspects of life. It’s also created fertile ground and easy pickings for a new breed of criminals, who have brought their illegal schemes into the virtual world. One of the most pernicious has been phishing, which attempts to use digital sleight of hand to grift its unwary victims.

Digital phishing scams can manifest in several different ways. In some cases, potential victims may receive an email that appears to be from one of their financial institutions, citing a problem that requires their immediate attention and requesting that they use the convenient link to sign in to their account. The link is false and allows the scammers to gain access to the victim’s account.

Other phishing cons involve pretending to be a family member, either in dire need of money or offering once-in-a-lifetime investment opportunities. Payment is usually requested to be in untraceable gift cards or digital currency. The latter is quickly shuttled through numerous crypto wallets, putting it beyond the victim’s reach.

For those lacking the technical savvy to perpetrate phishing scams on their own, the Caffeine Store offered a monthly subscription plan to its customers. For $250 per month (or, for those willing to commit to an extended grift, $850 for six months), the online platform allowed users to launch their own customized phishing attacks. It even had a YouTube channel with videos showing how to use their products. As might be expected, the Caffeine Store accepted crypto as payment.

You’re Anonymous on the Internet Until You Aren’t

Despite the anonymity offered by the internet, law enforcement investigations can sometimes peel back layers of obscuring and misleading information to identify the subject of their criminal inquiries. If successful with showing probable cause to obtain warrants, arrests, and seizures can follow.

The Caffeine Store was first identified by a cyber-defense company in October 2022 as one of the likely forces behind the continued surge in phishing activity, prompting the FBI to open an investigation later that month. Tracking criminals online is a complicated endeavor, as evidenced by the credit card used to pay for the store’s Cloudflare proxy account being traced to a compromised account with a fake address. However, other digital footprints could be followed.

According to federal authorities, an examination of the IP addresses used revealed that the owner of the Caffeine Store was based in Egypt. A court order presented to Google for the email address associated with the YouTube channel returned a name: Abanoub Nady Gamil Khalil. Using cookies and phone numbers associated with the same subscriber, the FBI identified other accounts believed to be held by Khalil, including a Binance account number.

Alleging criminal acts that included wire fraud, identity theft, money laundering, and unlawful monetary transfers in excess of $10,000, the FBI was granted a seizure warrant on November 15, 2023. It was served to Binance the following day, with the funds being frozen on the 18th. On March 6, 2024, the crypto funds were transferred to a digital government wallet. If the court grants the recently filed forfeiture warrant, the seized currency will become the government's property. It’s believed no arrest warrant has been issued for Khalil yet.

Keeping Your Money Where It Belongs

While some phishing attempts are easy to spot due to misspellings and fractured sentences, the addition of AI has allowed scammers to make their fake emails more difficult to spot. Since getting rid of all your email accounts isn’t feasible for most people, being aware of what to watch for is the next best defense.

Phishing emails often end up in your inbox as spam. Setting filters can weed many of those out, as can reporting them to your email provider when they get through. Be wary of offers that sound too good to be true, because they likely are. Make sure to update security measures on all your internet-accessible devices, including your phone.

Most legitimate companies won’t include links to update your account or billing information in their emails. Even if you think the email might be real, sign in through the company’s website or your usual portal instead. If it turns out you did get a phishing attempt, let the company the scammer impersonated know about the attack.

Consider using multi-factor authentication when signing in to sensitive accounts. Requiring extra verification provides an additional layer of protection, making it more difficult to be compromised. Methods include security questions and one-time passcodes to be entered for access. It’s also a good idea to back up your data. Keep your phone locked when you’re not using it.

While these methods are useful, the threat of being successfully phished is always a possibility. There’s no guarantee law enforcement will be able to recover your funds, so think twice, or maybe even three times, before clicking that link in an email purporting to be from your bank.

Was this helpful?

Copied to clipboard