(47k$ stolen) Cameroon scam group impersonating US weed dispensaries

In this thread I will talk about a massive scam group impersonating US weed dispensaries. A summary of the whole thing, as well as a list of their 24 websites and dozens of phone numbers will be provided at the bottom if you don’t wanna read everything, because I’ll be talking a lot.

A few weeks ago, a friend contacted me and showed me a scam that was happening on Google Maps. A group of unknown people were hijacking weed dispensaries (and even other shops) listings on Google Maps by using hacked accounts to upload a ton of AI-generated pictures of the business (example : https://imgur.com/a/elyyMhQ)

The goal with these pictures is to contact Google Maps “hey look, I’m the owner, I have so many pictures of my shop”. If it works, Google Maps will grant them the listing and they will be able to put their own fake websites & phone numbers on the listing. We have spotted a few listings that they successfully hijacked to put their advertisement

This is a list of their known hacked google accounts, that they use to hijack listings or to rate them with 5 stars : Google scam accs - cameroon weed scams - Pastes.io
And this is a list of the known Google Maps listings they have hacked or attempting to hack : google maps listings scams - Pastes.io

Their fake websites

The guys behind this scam purchases domain names and create Woocommerce websites filled with a lot of items and a few different sections just like a real shop would, except for a few parts :

  • You are forced to put at least 50/100/150$ (depending on the website) in your cart to be allowed to complete the order.
  • When you try to pay, a message tells you that you have to call a number to complete the payment. This is where the scam begins, as it’s a scammer from a call-center that will pick up the phone. We suspect (but are not sure) that most of the call-center scammers are Pakistani, as most of them have a heavy South Asian accent and they get angry when you joke about Pakistan (while they laugh when you joke about India or other countries nearby)
  • Their only payment means are Cashapp, Zelle, Venmo and Bitcoin

Of course, their website is completely fake and the orders are too, the goal of the scam is simply to take your money. The websites themselves are poorly made (some of them don’t even work properly, you can’t even make an order even if you wanted to) and poorly secured (on some of them, you can copy API requests that are made when creating orders and repeat them as long as you want)

Here is a list of all their working websites, we have caught 24 of them so far : Cameroon weed scammers - fake websites - Pastes.io

By the way, one of their websites is a skincare shop, which suggests they may target other fields unrelated to weed dispensaries

Their phone numbers & call centers

We aren’t sure if every website has a dedicated group of scammers on the phone or if it’s only 1 call-center for all the websites, but those scammers are tasked with guiding you through the order until you pay. My friend who extensively called them thinks there’s at least a dozen scammers in the call-center.

Once you paid, there seems to be a 2nd part to the scam where you will have to pay a “delivery fee” or “insurance fee” to make sure your delivery arrives safely. We got this information from reports on the BBB website made by people they scammed (I will talk about those later) since we never got to that stage

Since they have at least 24 fake websites, they have dozens of phone numbers / WhatsApp numbers that I link here : scam numbers (cameroon weed) - Pastebin.com

Their chat support

On every website, there’s a little chat icone on the bottom right corner where you can directly talk with the “support” in case you have a problem. The scammer(s) answering this is (are) one of the Cameroonian scammers behind the operation, you will see later how I know that. Those guys sometimes answers the phone too

Ongoing procedures

My friend has warned many dispensaries whose brands were stolen about the scam, so far at least 3 of them have put their legal teams on the matter and are doing requests to recover their listings, to take down the fraudulent listings and to take down the domains that copies their brand

The FBI, FTC, various state jurisdictions and the Australian Federal Police (they have an Australian fake website too) have also been contacted.

Who is behind all of this ?

With my friends, we started investigating them by looking at their website and my friend called their number (this is how we got the Pakistan thing), but things started to get interesting when we WHOISed their domains and noticed that a lot of them were registered under 3 email addresses : [email protected], [email protected] and [email protected]

The phone numbers associated with those registrants were US numbers probably belonging to the Cameroon scammers themselves, as my friend called them and the guys who picked up had an African accent and were sleeping when they got called at 1am GMT+1 (their time zone).

We originally had a strong clue that the bosses were from Cameroon because those idiots used the listing of a lake in France (now taken down by Google) where they posted the AI pics they were going to use with the hacked Google accounts they use for that, as well as many other pics, that lake was some sort of free file storage for all their scammers. And among all the images uploaded to that lake, we found this one :

This is a screenshot uploaded by one of the scammers in their lake, it was probably accidentally uploaded as they uploaded them in bulks. This shows a conversation with someone seemingly trying to get money on a bank account. The name of the bank account is “Thierry Bright”, after this there is “BIE ETONGWE”.
Both of those names point to Cameroon when searched on Google. The 237 681126158 thing is a Cameroon phone number. There is also another phone number, 673159990, that actually belongs to one of the scammers behind this (I will show how we know this later).

The chat conversation

We had a particularly good conversation with the scammer who answers to the support chat, he is so cocky he revealed all of his information himself

He started with this screenshot of his website where we can see that it’s 90f and it’s 5:50pm, it was sent at exactly 5:50 gmt+1, so it can only be West Africa. https://imgur.com/a/U0zqxVh

Then he admits he is in Cameroon: https://imgur.com/a/44x32eg

He even gives his phone number lol. Surprise, it’s the one we caught in the conversation above : https://imgur.com/a/72tf69H

When looked up, his number says it’s a valid phone number from “Limbe”, in Cameroon.
When asked about it : https://imgur.com/a/y134Sqh

He even gives us his town ! It’s in English-speaking Cameroon. And since multiple people answers to the chats at once, with different typing styles, and considering he’s sending the money to someone else in Cameroon, I think we can say that there’s a group of people in Cameroon behind this scam, not to mention the call-center workers. My friend also called the number this guy gave and he is 100% certain that the scammer who answered had an African accent and it was a totally different accent compared to the call center scammers

Their bitcoin wallets

By trying to order on all of their 24 websites, we have caught 5 bitcoin addresses they use, for a total of 0.3314 BTC (26292 USD) that were received on those wallets.

Here is their bitcoin wallets :
3HjFrGLVFui7Y9aYS9QXDohK9XHuVQXQU9

1HR66kWiDXinNEQQCgTnbNvuZaKEUmsxoE

16AVkTjWLyWSAez96LadELNtLMYxguNcQd

17kMHN1e7JTE4ajLoAXyxFyBXD1rqpCUPs

3KMnNPHB8CgJQpwyvfybyNHibypr7eSneb

BBB reports

They were reported dozens of times on the BBB website, for a total stolen of 20791 USD.

Almost all of the reports here are from their scam, and I only searched this one keyword. You can take a look at the reports to see how they operate exactly https://www.bbb.org/scamtracker/lookupscam?q=all%3Ddispensary%26from%3D0

By adding the stolen bitcoins and the stolen money that was reported on the BBB, they have made at least 47083 USD since 2021, as that is when the BBB reports & the Bitcoin revenue starts.

Since when are they doing this ?

They have been doing this since at least 2021 according to the revenues, but we found multiple clues that indicates they started in 2014-2015 !!!

Some of the emails behind the domain registration have started registering domains in 2014, and those domains were already recognized as scams at that time, according to this blogpost from 2015 : Stop 419 Advance Fee Fraud: Pharmaceutical Non-Delivery Scams

News reports

Those guys have been so present that there’s even reports from major outlets like NBC about their scam (no one knew who was behind it at that time). They put some of their 24/7 fake shops on random houses, causing customers to go there physically to buy some product… and this seems to happen in every major US metro area

By reading the news reports & posts, we can clearly see that it’s our scammers who did this as it’s the exact same modus operandi (especially for the DC ones)

https://www.reddit.com/r/Scams/comments/100psx9/my_building_got_listed_on_google_as_a_24_hr_weed/?rdt=58238

https://www.reddit.com/r/pittsburgh/comments/18hs4i1/warning_fake_dispensaries_appearing_on_google/

Summary

Those Cameroonian scammers, apparently aided by South Asian (probably Pakistani) phone scammers, have stolen at least 47000 USD in the last 4 years by impersonating US legal weed dispensaries with hacked Google Maps listings and fake shop websites that forces you to purchase a certain amount and redirects you to a call-center, where a phone scammer will pick your order and complete the payment.

Their scam is very well documented and many people have fallen victim to it, either by ordering on their website or by living in a place where they put a fake listing. But no one seemed to know who was behind it before me and my friends looked into it

List of their phone numbers : scam numbers (cameroon weed) - Pastebin.com

Scammer’s own phone number : +237 6 73 15 99 90

List of their fraudulent websites : Cameroon weed scammers - fake websites - Pastes.io

List of their Google Maps hacked accounts : Google scam accs - cameroon weed scams - Pastes.io

List of the known Google Maps listings they have hacked or attempting to hack : google maps listings scams - Pastes.io

Another fraudulent phone number that we found just before posting : +1 (602) 714-2677, from leaflybuds.com

I hope that you had fun reading this long post, and that you will have fun investigating them further or messing with those guys if you decide to ! Do not hesitate to tell me if I posted this with the wrong tag

2 Mi Piace

I was able to find https://modelswithmeds.com that looks kinda up the alley of this, when you click a link to go purchase something it leads to.

Flagging this and will pull hosts/registers when I get home tonight

great job investigating this scam.

If you want to stop/disturb their operation you could go on and report their websites.

I collected the Registrars/Hosts and abuse contacts for each website.

What you need: Is a solid description why the site is a scam (a short version of what you discovered might be enough, quoting law violations helps as well)
You can either report to the Registrar or the Host or both (but it takes some time).
As I reported around 100 fake investment sites in the last couple of weeks and took down 80 here’s a few tips:

Registrars:

  • Don’t even bother reporting to NameSilo (they don’t give a flying fuck) so if they are the Registrar you need to report to the Host
  • Namecheap and Hostinger take reports serious and take them down quick

Hosts:

  • Hostinger and OVH take reports serious and take them down quick
  • Cloudflare: is not the real host but a proxy, you have to report to CF directly, sometimes they reveal the real host, then you can report to them directly

Some of them will request further proof (screenshots…) so this might take some work.

If you want to go down this road and try to take down as many scam sites as you can feel free to let me know I can help (I just need a good/short description of the scam itself to file the reports to the Registrars/Hosts).

Website Registrar Abuse Contact for Registrar Domain Created IP Address Hosting Provider ASN Abuse Contact for Host
TrippyOregonStore.com Cosmotown, Inc. [email protected] 2022-12-12 104.21.16.1 Cloudflare Inc. AS13335 https://abuse.cloudflare.com/
AreaGreenCo.com Network Solutions, LLC [email protected] 2024-04-30 162.241.216.191 Unified Layer AS46606 ?
aucannabisclinic.com GMO Internet, Inc. [email protected] 2024-10-17 213.133.99.48 Hetzner Online GmbH, Germany AS24940 https://abuse.hetzner.com/
lemmelive.us Hosting Concepts B.V. d/b/a Registrar.eu [email protected] 2024-08-28 157.173.209.253 Hostinger International Limited, USA AS47583 [email protected]
VereOleAfone.com Hosting Concepts B.V. d/b/a Registrar.eu [email protected] 2024-04-14 91.121.38.6 OVH SAS AS16276 [email protected]
HollyCannabis.com Hostinger [email protected] 2024-07-01 195.35.15.40 Hostinger AS47583 [email protected]
UrbanGreenReleaf.com Name.com, Inc. [email protected] 2025-01-09 66.45.251.122 Interserver Inc. AS19318 https://www.interserver.net/contact-information.html
GreenCannabisDispensaries.shop Namecheap, Inc. [email protected] 2025-02-09 162.0.215.222 Namecheap Inc. AS22612 [email protected]
LeaFlyBuds.com Namecheap, Inc. [email protected] 2023-07-20 198.54.121.162 Namecheap Inc. AS22612 [email protected]
EssenceGreenDispensary.shop Namecheap, Inc. [email protected] 2024-04-04 66.29.137.27 Namecheap Inc. AS22612 [email protected]
cbdwarehousestore.com NameSilo, LLC [email protected] 2019-05-09 37.27.55.44 Hetzner Online GmbH, Finland AS24940 https://abuse.hetzner.com/
dermalfillerspro.com NameSilo, LLC [email protected] 2024-05-06 35.215.72.185 Google, USA AS15169 Report suspected abuse on Google Cloud Platform - Google Developers Help
givingtreeweeddispensary.com NameSilo, LLC [email protected] 2024-10-15 178.16.128.109 Hostinger AS47583 [email protected]
megabudstoreonline.com NameSilo, LLC [email protected] 2021-05-31 34.120.190.48 Google, USA AS396982 Report suspected abuse on Google Cloud Platform - Google Developers Help
k2herbalshop.com NameSilo, LLC [email protected] 2019-07-04 34.149.36.179 Google, USA AS396982 Report suspected abuse on Google Cloud Platform - Google Developers Help
420pharmonline.com NameSilo, LLC [email protected] 2022-11-23 34.120.190.48 Google, USA AS396982 Report suspected abuse on Google Cloud Platform - Google Developers Help
WhiskeyBrandsCollection.com NameSilo, LLC [email protected] 2024-10-24 35.215.89.1 Google AS15169 Report suspected abuse on Google Cloud Platform - Google Developers Help
GreenIslandDispensary.com NameSilo, LLC [email protected] 2024-03-11 91.195.240.12 Sedo GmbH AS47846 ?
GreenCareCannabisDispensary.com NameSilo, LLC [email protected] 2024-06-25 51.68.176.163 OVH SAS AS16276 [email protected]
GreenWeedCo.com NameSilo, LLC [email protected] 2024-07-19 51.195.65.154 OVH SAS AS16276 [email protected]
HerbalRootBark.com NameSilo, LLC [email protected] 2024-07-14 51.68.176.163 OVH SAS AS16276 [email protected]
PremiumthcConcentrates.com NameSilo, LLC [email protected] 2019-12-20 198.187.29.27 Namecheap Inc. AS22612 [email protected]
WeedConsultantsLlc.shop Nicenic International Group Co., Limited [email protected] 2021-06-07 104.21.51.243 Cloudflare Inc. AS13335 https://abuse.cloudflare.com/
TreeHausDispensary.com Wild West Domains, LLC [email protected] 2024-01-12 104.21.87.94 Cloudflare Inc. AS13335 https://abuse.cloudflare.com/
1 Mi Piace

Thank you so much, we will try to report them all and report the new websties that they create

1 Mi Piace

Is there a way to get the email addresses they use for registration ? I found a few of their websites like this with reverse whois, but a lot of their current domains are protected by some whois privacy companies

yeah most of them use some privacy service for the whois data (or simply fake it I assume).

1 Mi Piace

Found more websites and victims by looking for the scam on Google. According to someone who created a thread on Google Business help, they created 1700 listings in 3 months

Website : embarcdispensary(.)com
Number : +1 (917) 383-4899

Website: tropicalsbud(.)shop/
Numbers : +1 (260) 623-4135 and +1 (334) 220-0140

Website : thegreendispensary(.)com
Number : +1 (804) 656-8870

Website : essencedispensary(.)shop

Website : greenvalleydispensarys(.)com
Number : +1 (862) 201-3814
This one has a btc wallet that received 360$ in 3 months

1 Mi Piace

nice findings. Here’s the info for the new sites.

Website Registrar Abuse Contact for Registrar Domain Created IP Address Hosting Provider ASN Abuse Contact for Host
TheGreenDispensary.com Name.com, Inc. [email protected] 2024-11-19 66.45.251.122 Interserver Inc AS19318 https://www.interserver.net/contact-information.html
TropicalsBud.shop Namecheap, Inc. [email protected] 2024-09-10 162.0.229.54 Namecheap Inc. AS22612 [email protected]
EssenceDispensary.shop Namecheap, Inc. [email protected] 2024-09-11 162.0.229.246 Namecheap Inc. AS22612 [email protected]
EmbarcDispensary.com NameCheap, Inc. [email protected] 2025-01-14 67.223.118.85 Namecheap Inc. AS22612 [email protected]
greenvalleydispensarys.com NameSilo, LLC [email protected] 2024-09-02 35.215.113.148 Google AS15169 Report suspected abuse on Google Cloud Platform - Google Developers Help

Reported all of those and a bunch got taken down

Idk if i talked about it before but there’s a domain that they took down themselves because they were getting trolled a lot on it, it’s back
wholesomecodispensary.com
Here is the hacked listing that goes with it, it was hacked a few weeks ago, taken back but hacked again recently, the fake pics weren’t even taken down : Google Maps

Phone number : (+1) 442-447-5185

1 Mi Piace

great job, congrats for being a pain in the arse for those scammers :sign_of_the_horns:

I have 2 good news :

  • The call center guys are starting to disconnect the numbers where they are being trolled. Since it’s a different team than the website owners, they have to wait for them to update the website with the new number, and it takes a few hours since they have very weird sleep schedules. So it disrupts them a lot
  • They added captchas to a few (3-4) of their websites to prevent order spamming, but since they don’t know anything in coding, they destroyed their own websites by doing this.
    A captcha triggers when you send more than 10 orders, but somehow it replaces the shipping form for EVERY user of the website (and the captcha doesn’t even show up for the other users since they didn’t send 10 orders)
    This means that if someone spams 10 orders and trigger the captcha’s appearance, no one can order for a while

I also found 12 new websites & a bunch of numbers by typing in “colorado dispensary shipping worldwide” in Google.
Here is the list : new websites - Pastebin.com

1 Mi Piace

The scammers now seem to be focusing on the original “wholesomecodispensary.com” website with a new number : (+1) 213-320-0218

Too bad for them, we’ve been reporting them so much that they’re not listed on Google or Google Maps anymore, and my friend has been bothering their new number so much that they’re sending every call straight to the voicemail. Another L for them so far

The wholesomecodispensary website is down, huge W as it was their main website and they’re not very happy about it :slight_smile: Took down a bunch of their fraudulent listings too

We also found another website : https://highleafbuds.shop/
Phone numbers : +1 980 221 0859 and +1 (925) 452-6782

2 Mi Piace