- Service Areas / Access & Identity
Impersonation
Someone posing as your bank, a government official, or a person you know, asking you to move money urgently.
- Access & Identity
How These Cases Work
These are the most-reported frauds in most countries, and the most convincingly staged.
01
A Message, a Link, a Login Page That Looks Right.
Phishing starts with something ordinary — a text about a delayed parcel, an email from your bank, a call from someone who already knows your account details. The page you land on is a copy of the real one. What you enter goes straight to whoever built it.
02
What an Investigation Involves
Astronreturn Investigations
We start by establishing when and how the compromise happened — which message, which page, which credential. That fixes the timeline and tells us what left your accounts afterwards.
From there we trace the outbound payments: which accounts received them, which processors or exchanges they passed through, and where they came to rest.
- Inside a Phishing Investigation
Our Process
Four stages, in the order we work them.
Receiving Account Trace
We establish exactly when and how access was obtained, and what it allowed.
Onward Chain Mapping
Every transfer, card charge, and withdrawal that followed, traced to its destination.
Infrastructure Analysis
Domains, hosting, and sending addresses — often linking your case to others.
Evidence File
Findings documented so your bank, card issuer, or the police can act.
- Clients
In their own words
“It was my bank’s actual number on the screen. My bank’s first response was that I’d authorised it. The report is what changed that conversation.”
Helen
United Kingdom
4.9 Rating
aveery davis
Our Client
"Three accounts in the first afternoon, then onward. Seeing it laid out was the first time it looked like an operation rather than my own stupidity."
- FAQ
Common Questions
Not usually. Authorised push payment fraud is recognised as its own category, and in a number of jurisdictions there are reimbursement rules that apply specifically to it. Banks decline on first application routinely. What tends to change the outcome is evidence showing how the deception was staged and where the funds went.
Caller ID is straightforward to falsify and there is no verification behind it. The same applies to SMS sender IDs, which is why a fraudulent message often appears in the same thread as real ones from your bank. This is worth documenting in a claim, because it undermines any suggestion that you should have spotted it.
Immediately, if the payment was recent. Funds are moved onward within hours, and the realistic window for stopping money at the receiving bank is short. That said, tracing remains possible long afterwards, and a claim or police report is still worth pursuing once the money has moved.
Yes. Invoice redirection works on the same principle and we handle it the same way. These cases often involve a compromised email account somewhere in the chain, which is worth establishing early since it affects both the claim and whether it is likely to happen again.
Sometimes partly. We can usually establish which accounts received the money and what connects them, and occasionally that leads somewhere identifiable. More often it produces something better for your purposes: evidence that the accounts belong to a network, which is what banks and police act on.