Disclaimer

This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.

← Back to Incident Lab
Case 09 / Financial Scam / Crisis Exploitation2026

Storm Relief Donation Scam

Cluster two fake disaster-donation domains through shared registration metadata and a reused payment wallet, and separate them from the legitimate relief foundation they impersonate.

Source Assessment

Good. Disaster-donation scam clusters are consistently documented by consumer-protection agencies; the storm, foundation, domains, and wallets here are fictional.

Last Audited:2026-07-02

Incident Brief & Analytical Mission

Days after the fictional Cape Meridian storm of February 2026, social posts push two donation sites ('meridian-storm-relief' and 'capemeridian-donate') that imitate the long-established Meridian Relief Foundation. Both were registered within 48 hours of landfall, share a privacy proxy and nameserver pool, and list the same crypto wallet, which public scam trackers previously flagged during a 2024 flood campaign. This mirrors the disaster-donation scam wave documented by consumer-protection agencies after every major storm, earthquake, and flood. All organizations, domains, and wallet addresses in this case are synthetic.

Investigative Mission

Use registration metadata to cluster the suspicious domains as one operation, pivot on the shared wallet to connect them to earlier scam activity, verify the real foundation's official donation channel, and write guidance donors can follow during any crisis.

Evidence Console#01 / 03

Donation Domain Registration Cluster

WHOIS/RDAP metadata for the legitimate foundation and the two suspicious donation domains. Synthetic records, .test defanged.

CVE IDENTIFIER

Vulnerability Type:

CVSS v3.1 SEVERITY

Patch Released:

CVSS VECTOR STRING

Investigative Checklist Tasks

  • 01

    Explain which registration attributes (age, registrar, proxy, nameservers) separate the legitimate foundation domain from the two crisis-timed lookalikes.

  • 02

    Use the wallet pivot to argue that both suspicious domains belong to one operation with prior scam history.

  • 03

    Verify what the foundation's official donation channel is and how a donor could confirm it independently.

  • 04

    Write three donor-safety rules that would have prevented losses in this scenario.

Analyst Notebook

Evidence Notebook

Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.

No evidence records logged yet.

Report Desk

Report Drafting Board

REPORT PREVIEW
# CSINT Incident Lab Report

## Research Question
Are the 'meridian-storm-relief' and 'capemeridian-donate' sites legitimate storm-relief fundraisers or a coordinated donation scam?

## Summary
No analyst summary provided yet.

## Fact
- No forensic facts recorded in the notebook.

## Signal
- No analytical signals logged.

## Inference
- No alternative explanations recorded.

## Recommendation
- No next-pivot recommendations recorded.

## Confidence
Low

## Limitations
No limitation notes entered.

## Source reliability
Not assessed. Annotate each source with its reliability tier before publishing.

## Information validity
Not assessed. Confirm whether each item is directly observed, reported, or inferred.

## Missing context
Not recorded. List what data is missing or could not be verified from public sources.

## Next safe steps
- No next safe steps specified.

## Sources used
- No source references listed.

---
Generated at: 2026-07-24T18:30:25.235Z