An investigation by The420.in and independent researchers traces a viral Instagram video, built on a stolen identity and false credentials, through a manufactured payment deadline and a scripted phone call, to a real offshore brokerage already flagged by regulators in Japan and Australia and accused by its own users of blocking withdrawals.

EXCLUSIVE – “Forbes Named Me a Top Business Innovator”: Inside the Deepfake AI-Trading Video Duping Indians on Instagram

Shashank Shekhar
22 Min Read

NEW DELHI: “How can you earn more than Rs 34 lakh in just three days?” the man on screen asks, looking straight into the camera. “In this video, I’ll show you the system that made me this money and how it can do the same for you.” He introduces himself as Rahul and claims that Forbes named him one of the top business innovators of 2025. He says his life changed after he stopped trading stocks himself and let artificial intelligence do it instead. 

His pitch is simple – If you watch the video and follow the same system, he suggests you could be a millionaire soon enough.

None of it is true. The man in the video is Akash Anand, a Bengaluru real estate entrepreneur, whose publicly available footage was allegedly lifted and repurposed without his consent, according to investigation done by Eshan Singh, Content Engineer at Trisec Labs and reviewed by The420.in. His name has been erased and replaced with “Rahul.” The Forbes recognition is invented. His team has denied any connection to the campaign or the platform it promotes, and there is no evidence he endorsed the scheme or had any involvement in it.

Scammers allegedly misused publicly available footage of Bengaluru real estate entrepreneur Akash Anand, repurposing it without his consent to falsely portray him as “Rahul,” a supposed Forbes-recognised business innovator. The claims shown in the manipulated video are false.
Scammers allegedly misused publicly available footage of Bengaluru real estate entrepreneur Akash Anand, repurposing it without his consent to falsely portray him as “Rahul,” a supposed Forbes-recognised business innovator. The claims shown in the manipulated video are false.

This is the video now circulating on Instagram, and an investigation by The420.in, working alongside independent researchers, has traced exactly where it leads and what runs behind it.

TRCKPB.COM landing page using prominent AI-brand imagery alongside the promotional video
TRCKPB.COM landing page using prominent AI-brand imagery alongside the promotional video

A script built to disable scepticism, line by line

Every line in the video is doing a specific job. “Even if you have no experience with technology, barely know how to use a computer, or simply don’t have the time, this can still become your reality,” it says, before cutting to shots of a luxury car and a sprawling house. “This is my home. I bought it in cash. It took me just two months to earn enough to pay for it.” The message is aimed squarely at people who feel left behind by markets they never understood, and it tells them, explicitly, that understanding is no longer required.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Then comes the pitch dressed up as inevitability. The video invokes AI systems generating thousands of images, writing books in an hour, defeating chess champion Garry Kasparov decades ago, and claims “we invested nearly 170 million rupees to develop this system,” describing it as “100% automated” and requiring “no prior skills or experience.” It draws on the biggest financial regrets people carry, Bitcoin bought for a few rupees and sold for crores, Amazon stock missed fifteen years ago, and frames the viewer’s own hesitation as the mistake still waiting to happen. “Making mistakes is human. Repeating them is not,” it says, quoting Einstein on insanity for good measure. It even walks through a chart showing a sharp fall in gold prices, explaining, with the tone of a market analyst, why the AI system supposedly knows the price will recover within eight days.

ALSO READ: Cyber Fraud Money Trail Leads Police to 903 Gaming Accounts

None of this is trading advice. It is a script engineered to move a viewer from scepticism to urgency in under three minutes, using a stolen face to make the leap feel safe.

Where the video actually leads

Anyone who follows the video’s prompt lands on trckpb.com, a landing page that collects a name, phone number and email address before showing a message announcing that a call will follow and that ₹21,250 must be paid promptly or a claimed seat will be given away. Shweta Patel, Co-Founder, Phishbowl Solutions, found during her investigation that trckpb.com functions as a hidden, programmatic funnel domain designed to resemble an AI market-analysis or automated trading tool, and that similar funnels have been used to redirect victims who click on deceptive advertisements or links circulated over WhatsApp and Telegram, not social media alone. The payment deadline on the page is manufactured urgency, timed to arrive before anyone has a chance to check whether any of it is real.

The phone call that follows, a recording of which was reviewed as part of this investigation, describes an AI trading system that requires no effort, promises a “senior account manager” to configure it, and tells the prospective investor that profits will simply appear in a wallet. When the caller learned the prospective investor was elderly, the standard entry price of ₹20,000 to ₹30,000 dropped to a “senior citizen” rate of ₹15,200, not a courtesy but a calculation, since an older investor with retirement savings and less exposure to online trading is judged an easier sale, and a smaller opening amount makes that first, most important payment easier to hand over. The caller also asked for Aadhaar or similar identification, claimed an association with Infosys and an office in Noida Sector 63, claims researchers found no evidence to support, and introduced urgency around limited availability whenever the prospective investor hesitated.

The AI platform that doesn’t exist

The video promises an AI system trading on the viewer’s behalf. What it actually leads to is Bullfxo, a real, functioning brokerage. Researchers found two UK-format telephone numbers, +44 1339 264918 and +44 1339 264920, connecting the campaign’s payment page link to a Bullfxo account-opening link, the intended flow being to get a prospective investor to open an account and then invest, rather than the link itself functioning as a payment gateway.

Bullfxo’s own website tells a different story from the one in the video. It describes a CFD (contract for difference) trading platform offering forex, stocks, commodities, cryptocurrencies and indices, with leverage of up to 1:400 and a minimum deposit of $250. It makes no claim anywhere of AI-driven or automated trading. Its own risk disclosure states plainly that CFD trading carries significant risk and can result in the loss of an investor’s entire balance, and that past performance offers no guarantee of future results, the exact opposite of what the video and the phone call promise. At 1:400 leverage, a trader is exposed to roughly ₹4 lakh of market movement for every ₹1,000 deposited, a structure in which an ordinary price swing can erase a deposit entirely, a risk never mentioned to anyone sold on the idea that AI had made trading safe.

Beyond the leverage math, Shweta Patel, Co-Founder, Phishbowl Solutions, found during her investigation more direct evidence that Bullfxo functions as a scam in practice. Reviews on the consumer platform Trustpilot describe users depositing funds, being shown fabricated profits on their dashboards, and then finding themselves blocked from withdrawing any money at all, the classic pattern of a fake broker rather than a merely high-risk one. Patel’s research also found that WikiFX, an app that aggregates global broker regulation data, lists concerns against the platform, that a terms-of-use page linked from a related Bullfxo domain, bullfxoltd.com, was entirely blank, and that the phone number listed as Bullfxo’s official contact, +81 50 3114 8492, traces to a Japanese internet-calling (VoIP) service rather than any verifiable office line.

A shell address rented out to hundreds of fake brokers

Bullfxo says it is registered as Bullfxo Ltd on Mwali Island in the Comoros, authorised by the Mwali International Services Authority, at an address, P.B. 1257 Bonovo Road, Fomboni, Comoros. That address, Shweta Patel, Co-Founder, Phishbowl Solutions, found during her investigation, is not Bullfxo’s office at all. It is the registered address of Moheli Corporate Services Ltd, a corporate services provider on the island that, for a registration fee, supplies a mailbox, a certificate of incorporation and a brokerage licence from the Mwali International Services Authority to any business that wants one, with no requirement of actual staff, operations or premises in the Comoros. Patel’s research found that other trading platforms flagged or reviewed negatively online, including Phyntex Markets, Proxtrend Ltd, Investrex Ltd, Capital Crest Ltd (also operating as Mirrox), and OnFin Ltd, list this same mailbox on their own legal pages. This is, in effect, an address for rent that gives dozens of brokers the appearance of offshore regulatory legitimacy while placing them beyond the practical reach of international law enforcement.

Japan’s Financial Services Agency currently lists Bullfxo Ltd among overseas entities warned for soliciting derivative transactions without registration, an entry dated December 2025 that names the warned service directly as “Bullfxo.” The same regulatory page lists a second firm, Fxonet Ltd, at a substantially similar Comoros address, and researchers found that Bullfxo and Fxonet share a common website security certificate; a Comoros filing shows the same named entity, Muhammed Sait Kilicarslan, appearing in the registration records of both firms, an overlap worth flagging even though it does not establish that the two companies are legally one, or that this name identifies a specific real-world individual beyond what appears in that filing.

ALSO READ: Odisha Lost ₹370 Crore to Cyberfraud in Three Years, Recovered Just 2.7%

A toolkit, not a single video

Prasenjit Gautam, CEO, Vallum Research and Eshan Singh, Content Engineer at Trisec Labs told The420.in the video is not a one-off production. Its footage was delivered from a separate server, wtcprojects.com, through a web address pattern, wtcprojects.com/denivideo/ENtrckpb.com/, that embedded the campaign’s own domain name directly into the file path. After researchers found the first file this way, 3_preview.mp4, the same indexing pattern led them to two more, 2_preview.mp4 and 1_preview.mp4, simply by testing nearby file names. Similar domain-encoded video-delivery patterns later turned up on other websites entirely, which is what made this a useful pivot into the wider infrastructure rather than a one-time coincidence, including on soragateway.com and drburdette.com, with ewfrick.com and dpcssrl.com flagged as further leads.

Shweta Patel, Co-Founder, Phishbowl Solutions, found during her investigation a separate, parallel cluster of clone websites sharing an identical fake UK contact template, an address at 51 Russell Rd, Shifford, UK, and a non-standard phone number, 479 8042 4547. Shifford is a small rural hamlet in Oxfordshire with no commercial or technology premises of any kind. Patel’s research traced that same address and number to a platform called Nanoluthix, which Australia’s securities regulator, the Australian Securities and Investments Commission, formally blacklisted through its MoneySmart scam alert service. The identical contact details also appear, per Patel’s findings, on other domains, including insightfulaitech.com and dzgpa.com, and on a site called wifiendoskop.com that appears to have been an unrelated electronics domain before being overwritten with the same fraud template, down to a Croatian and Eastern European-language terms-of-use page. Patel’s research describes the underlying hosting setup as a deliberate evasion pattern: content served through Google’s own infrastructure, which lends the sites a legitimate-looking Google security certificate, with traffic then routed through Cloudflare to mask the real server location and frustrate infrastructure-mapping tools.

A single lead-collection script tied to the campaign, adict.js, hosted on a public GitHub account, was found running across more than 1,286 separate web pages scanned by researchers, the vast majority unconnected to this specific video. Independent researchers traced the same underlying infrastructure to a nearly identical “AI trading” pitch called “X AI” running as far back as January 2024, and to a similar setup surfacing again in early 2026, evidence that this is a toolkit reused and rebranded across campaigns for more than two years, not a single video built for one audience. The Meta advertising page pushing this particular version, “The Prestige Circle,” was created on 11 September 2026 and was already running multiple paid advertisements within nine days.

Taken together, researchers have now identified more than 200 domains carrying similar infrastructure patterns to those documented here, a scale that investigators say points toward a possible second phase of this investigation, focused on connecting the wider domain network and tracing where the financial trail ultimately leads. Neither this investigation nor the researchers’ wider inquiry has yet identified the final bank account, UPI identifier or cryptocurrency wallet where victims’ money ends up.

“What started as a single AI-investment scam lead turned into a much broader infrastructure trail,” said Ayansh Kumar, independent threat intelligence researcher who worked on the investigation. “We found reusable lead-generation code, shared video infrastructure and historical registration data connecting the shmek004 and syimono1488 identities across multiple domains. The evidence points to a long-running, reusable fraud ecosystem, although we still cannot say that every piece of infrastructure is controlled by the same operator.”

“The most interesting part of this investigation is the separation between what victims see and what sits behind it,” Kumar said. “The front end is heavily localized for India, with rupee deposits, Aadhaar verification and Indian sales calls, while the underlying code and historical infrastructure reveal a much broader developer and domain ecosystem. This looks less like one scam website and more like reusable fraud infrastructure.”

What the video wants you to forget

Every claim in that video, the Forbes recognition, the cash-bought house, the guaranteed ₹85,000 a day, is designed to be believed quickly and questioned never. Forbes never named this man anything, because the man in the video and the man the script names are not the same person. No AI system, however it is described, can guarantee stock market profits, and a company’s own risk warnings, in this case, directly contradict the promise made to sell it, while its own users describe being blocked from withdrawing their money entirely.

Before any money changes hands, verify a platform’s registration with SEBI and its trading membership of the relevant exchange directly, using resources such as the BSE’s membership directory (bseindia.com/members/membershipdirectory) and SEBI’s own recognised-entity listings, never on the strength of a video or a phone call. A borrowed face and a stolen quote are not proof of anything except that someone built a very convincing lie.

This report is the result of an investigation by The420.in in collaboration with independent researchers, including Ayansh Kumar and Shweta Patel, Co-Founder, Phishbowl Solutions, cross-checked against Japan’s Financial Services Agency warning list, Australia’s ASIC MoneySmart scam alerts, Bullfxo’s own published terms, Trustpilot and WikiFX user reports, and the video script circulating on Instagram. Akash Anand’s team was contacted and issued a statement denying any association with the campaign.

The Infrastructure Behind the Video: What Investigators Found

  • The video’s real address: Hosted not on trckpb.com but on wtcprojects.com, at a web address that embedded the campaign’s own domain name. Finding one file this way (3_preview.mp4) led researchers to two more (2_preview.mp4, 1_preview.mp4) simply by testing nearby names, a pattern later found reused on other sites entirely.
  • Reused across many sites: The same video-delivery pattern turned up on soragateway.com and drburdette.com, with ewfrick.com and dpcssrl.com flagged as further leads.
  • A second, parallel clone network : A separate cluster of sites, insightfulaitech.com, dzgpa.com, snapauragen.com, nanoluthix.com and wifiendoskop.com, share one fake UK address (51 Russell Rd, Shifford) and one non-standard phone number, previously used by a platform called Nanoluthix that Australia’s ASIC has already blacklisted.
  • Evasion setup: Sites are hosted on Google’s own infrastructure for a trustworthy-looking security certificate, then routed through Cloudflare to hide the real server and block infrastructure-mapping tools.
  • Real victim complaints: Trustpilot reviews and WikiFX flags describe deposits accepted, profits faked, and withdrawals blocked; Bullfxo’s linked terms-of-use page was found blank, and its listed contact number traced to a Japanese VoIP service.
  • A rented shell address: The Comoros address on Bullfxo’s site belongs to Moheli Corporate Services Ltd, a registration agency whose same mailbox is used by several other flagged brokers, including Phyntex Markets, Proxtrend Ltd, Investrex Ltd, Capital Crest Ltd/Mirrox and OnFin Ltd.
  • One script running over a thousand scam pages: adict.js, hosted on GitHub, was found on 1,286 separate scanned web pages, most unconnected to this specific campaign.
  • At least two years old: The same video infrastructure traces back to xelence.orderready.com (January 2024) and blagabo.com (early 2026), both running near-identical “AI trading” pitches.
  • Code language clues: Ukrainian-language developer comments in trckpb.com’s code, sitting beside anti-inspection code; Russian-language comments and a Russian default language in the shared lead-collection script.
  • Identity leads, unconfirmed: Two email addresses, shmek004@gmail.com and syimono1488@gmail.com, tie multiple domains together, including zjcok.com and godatahawk.com.
  • Fresh ad accounts: The Meta page “The Prestige Circle” was created on 11 September 2026 and was running paid ads within nine days; a second page, “Sovereign Heights,” did the same.
  • Bullfxo–Fxonet overlap: The two firms share a website security certificate, and the same named entity, Muhammed Sait Kilicarslan, appears in registration records tied to both.
  • Scale and next steps: Researchers have now identified over 200 domains with similar infrastructure patterns, suggesting a possible Phase 2 investigation to map the wider network and trace where victims’ money ultimately goes.
  • Unresolved: No bank account, UPI ID or cryptocurrency wallet receiving victim payments has yet been identified.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected