The United States Treasury Department announced sanctions against Funnull Technology , a Philippines-based company that allegedly provided infrastructure for hundreds of thousands of malicious websites involved in scams that have cost U.S. citizens more than $200 million

According to authorities, Funnull facilitated cryptocurrency investment fraud – also known as “pig butchering scams” – by purchasing IP addresses in bulk from cloud providers, which it resold to cybercriminals. Through this infrastructure, the perpetrators hosted deceptive websites with fake investment opportunities.
See also: US: Charges against 12 people for crypto fraud
The perpetrators of these scams usually approach their victims through social media, dating apps and messaging apps. After building a relationship of trust, they convince them to invest in non-existent platforms, extracting large sums of money that end up in accounts they control.
Funnull is also accused of offering technological tools such as domain generation algorithms (DGAs) to mass-generate unique domain names, as well as ready-made web templates that mimic well-known brands, enhancing the credibility of malicious websites. At the same time, it provided services that helped fraudsters switch domains and IPs, making it more difficult to detect and take down the websites.
“Funnull is associated with the vast majority of crypto investment scams reported to the FBI. The financial losses to victims in the US exceed $200 million , with an average loss of over $150,000 per individual ,” the Office of Foreign Assets Control (OFAC) said .
Also targeted by the sanctions was Liu Lizhi, a Chinese national and manager of Funnull, who allegedly played an active role in supervising the company's employees and monitoring operational performance.
See also: Celsius founder Alex Mashinsky convicted of crypto fraud
Following the sanctions announced by the US Treasury Department, citizens and businesses in the United States are now prohibited from doing business with Funnull Technology and its manager, Liu Lizhi. At the same time, all assets they hold in the US are to be frozen. The measure also extends to financial institutions or foreign entities that may continue to do business with them, which now run the risk of facing secondary sanctions.
The sanctions against Funnull Technology and Liu Lizhi are significant and well-targeted, and mark some critical developments in cybersecurity and international economic policy. The US sends a clear message to similar companies around the world: “If you provide services to fraudsters, even if you do not commit the fraud yourself, you will be held complicit.”
However, despite the measures, platforms social networking and dating remain the main channels of communication between fraudsters and victims. If they are not combined with increased prevention and user education, fraud and, by extension, losses will continue.

FBI sheds light on Funnull's infrastructure
At the same time, the FBI issued an alert with technical details about the scope and nature of Funnull’s fraud infrastructure. The report reveals that as of January 2025, authorities have identified 548 unique Canonical Names (CNAMEs) associated with over 332,000 unique domains, indicating a vast and sophisticated fraud infrastructure.
See also: Google: Bringing protection for telephone banking fraud?
“In April 2025, a sample of eight domains was analyzed to illustrate a CNAME analysis that was linked to the Funnull infrastructure. Between February 2023 and April 2025, the eight domains exhibited three distinct patterns of CNAME activity,” the FBI reported.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The FBI also observed that between October 2023 and April 2025, multiple patterns of IP address activity were observed from various domains using the Funnull infrastructure. During this time frame, hundreds of domains using the Funnull infrastructure were simultaneously transferred from one IP address to another either on the same day or within the same time frame.
Sharp increase in cyber fraud
The above comes in the wake of a disturbing report published by the FBI, according to which cybercriminals stole $16.6 billion from American citizens in 2024. Investment fraud contributed more than $6.5 billion, recording an increase of more than 33% compared to the previous year.
Source: www.bleepingcomputer.com
