Cryptocurrency‑related fraud continues to evolve, and one of the most persistent threats facing victims today is the rise of second‑stage recovery scams—fraudulent operations that target individuals after they have already suffered losses. These groups monitor social media platforms, especially posts discussing pig‑butchering scams, romance‑investment fraud, and other crypto‑related crimes. When victims speak publicly about their experiences, recovery scammers often attempt to insert themselves into the conversation, posing as “investigators,” “forensic analysts,” or “asset‑retrieval specialists.”
This week, I encountered the third instance of such a hijacking attempt on LinkedIn. A brand‑new profile with no followers and only a single comment attempted to promote a supposed recovery service called TechY Force Cyber Retrieval (TFCR). The comment followed the familiar pattern: professional‑sounding language, promises of blockchain forensics, and a WhatsApp number as the primary contact method. These tactics are consistent with known recovery‑fraud operations that prey on victims seeking help.
Red Flags Identified
Several indicators immediately confirmed that this was not a legitimate cybersecurity firm:
- Brand‑new LinkedIn profile: No followers, no history, and only one comment—the one posted on my scam‑awareness article.
- Newly registered website: A WHOIS lookup showed the domain was created only weeks ago.
- Website downtime and sudden content changes: The site went offline for a period and later reappeared with new material, a common sign of evasive behavior.
- WhatsApp contact number: Legitimate forensic firms do not conduct business through anonymous messaging apps.
- Copycat‑style “security alert”: The LinkedIn post included a link and graphic referencing a security notice published by TechYForceCyberRetrievals. This alert was created by TechYForceCyberRetrievals itself, not by CipherTrace or Ciphertraces. While there is no evidence that Ciphertraces is involved in this particular outreach, the structure, tone, and presentation of the notice closely resemble the type of fraud warnings issued by legitimate cybersecurity firms. Publishing self‑generated alerts that imitate industry standards is a known tactic used by impersonation‑based recovery scams to create the appearance of legitimacy. The similarity in messaging and website behavior mirrors patterns previously observed in other fraudulent recovery operations, including Ciphertraces, even though no direct link exists in this case.
Why This Matters
Recovery scammers represent a particularly harmful form of fraud because they target individuals who have already been victimized. Their goal is not to help recover lost assets but to extract additional payments, personal information, or wallet access. Regulators including the FTC, FBI, and FCA have repeatedly warned that no private company can recover stolen cryptocurrency, and unsolicited offers of recovery services are almost always fraudulent.
The appearance of this third instance reinforces a troubling trend: scammers are actively monitoring public discussions about pig‑butchering scams and attempting to exploit victims by hijacking posts, comments, and conversations. Their tactics are becoming more sophisticated, but the underlying pattern remains the same—unsolicited outreach, unverifiable credentials, newly created digital footprints, and promises that no legitimate investigator would ever make.
Protect Yourself
If you have been targeted by a crypto scam:
- Be extremely cautious of anyone offering recovery services.
- Verify all claims independently.
- Avoid communication through WhatsApp or other anonymous channels.
- Report suspicious profiles and websites to the appropriate platforms.
- Seek guidance from law‑enforcement agencies or reputable consumer‑protection organizations.
Recovery promises are a major red flag. This latest incident serves as another reminder that scammers are continually adapting their methods, and vigilance remains essential.
Original Message on Linkedin:
From: Larry Oberg
Message: Cryptocurrency scams continue to affect individuals and businesses worldwide, with victims losing digital assets through fake investment platforms, phishing attacks, romance scams, business email compromise (BEC), ransomware, and other forms of cyber fraud. At TechY Force Cyber Retrieval (TFCR), we help victims fight back through professional blockchain investigations and digital asset recovery services.
Website (https://techyforcecyberretrievals.com)
WhatsApp (+.1.5.6.1.7.2.6.3.6.9.7)
Every case begins with a detailed blockchain transaction analysis and digital forensic investigation. Our cybersecurity professionals trace the movement of stolen cryptocurrency, identify destination wallets and exchanges, and gather digital evidence to develop a recovery strategy tailored to each client’s situation. Using advanced blockchain forensics and investigative techniques, we focus on identifying the parties behind fraudulent transactions and building evidence that supports potential recovery efforts.

This is also the second recovery scam in a row linked to a Minneapolis/St. Paul location. Fraud rings often cluster around a single U.S. city to create the illusion of legitimacy, and the repetition here is a significant red flag. While LinkedIn does not verify geographic data, scammers routinely reuse the same city across multiple burner accounts, making this pattern noteworthy and concerning.
Follow-up: My response to the fraudulent post was mysteriously deleted on Linkedin. Is this a sign of a scammer fighting back. So of course, I reposted it. Stay tuned!

Rae Stonehouse is a Canadian author, publisher, and advocate committed to exposing publishing scams and supporting writers through education and community. As the creator of Authors Against Scammers, Rae provides clear, practical guidance to help writers protect their work, their money, and their peace of mind. His books and resources reflect a lifelong dedication to empowering others through knowledge, clarity, and real‑world experience.



