Case File: Inside the Xinbi Guarantee Scam Marketplace

This week, U.S. authorities announced they had disrupted Xinbi Guarantee, a large online marketplace used by criminals to buy and sell stolen data, fake documents, and scam tools. As part of the action, 52.8 million dollars in cryptocurrency was frozen.

On the surface, this sounds like a story about organised crime on the other side of the world. But the reality is much closer to home. Marketplaces like Xinbi are the engine room behind the scam calls, texts, and emails that land on UK phones every day.

How the scam supply chain works

The person who rings you pretending to be from your bank is rarely working alone. They are part of a supply chain. Stolen logins are gathered, often by infostealer software that quietly grabs saved passwords from a device. Those logins are then sold on marketplaces like Xinbi. Scammers buy them, along with scripts, fake documents, and even ready-made fake websites.

Separately, researchers this week highlighted infostealer logs that exposed AI tokens. In some cases those tokens could be replayed to bypass multi-factor authentication. In plain terms: if your login is stolen, even a code sent to your phone may not be enough to stop someone getting in.

What an active ransomware leak site means

DarkWatch also flagged an active dark web leak site today. These are shame pages run by ransomware groups, where stolen files are dumped to pressure victims into paying. We won't name it, and you should never go looking for it.

What you can actually do

If your details are already out there, you cannot undo that. But you can make them far less useful:

  • Stop reusing passwords. Use a password manager if you can.
  • Turn on two-factor authentication wherever it is offered.
  • Update your devices and apps when prompted.
  • If someone calls claiming to be your bank, hang up, wait a minute, and call the number on the back of your card.

The supply chain behind scams is complex. Your defence does not have to be.