Fake Seizure Banners: When the Law Enforcement Notice Is Part of the Scam
A marketplace goes dark overnight and an official-looking law enforcement banner appears in its place. Most visitors assume the authorities have finally moved in. Sometimes that assumption is exactly what a scammer wants you to have.
The $22 million raid that never happened
In March 2024, days after reportedly receiving a $22 million ransom tied to the Change Healthcare breach, the AlphV/BlackCat ransomware gang posted an FBI seizure notice on its own leak site. There was just one problem: none of the agencies mentioned wanted credit for it. The UK's National Crime Agency publicly denied taking part, and researchers found the banner's HTML had been lifted from an earlier page with a simple browser save operation. Ars Technica documented how the group staged the takedown to cover an exit scam on its own affiliates."ALPHV/BlackCat did not get seized," Emsisoft researcher Fabian Wosar wrote at the time. "They are exit scamming their affiliates."The timing told the rest of the story. The notice appeared only after the ransom landed and an affiliate complained publicly about being cheated out of a cut, turning a routine disappearance into one of cybercrime's most instructive deceptions.
Why faking a takedown is trivially easy
Real seizure banners are public by design. They sit on seized domains for months or years, which puts every visual ingredient a fraudster needs on open display: agency seals, layouts, even the exact wording. Cloning one takes minutes. Copy the markup, save the image, upload it anywhere, and the illusion is complete. Because almost everyone judges the picture rather than the infrastructure, few think to ask who actually controls the server behind the page. The pattern predates ransomware. Fake "your computer has been locked by the FBI" screens were a staple of scareware a decade ago, and phishers still dress credential-harvesting pages in legal language because borrowed authority lowers suspicion.The exit scam dressed as a police raid
For a dark web operator, a staged seizure solves several problems at once. It explains a sudden outage, discourages angry users from hunting the admins, and lets the thief pose as a fellow victim of law enforcement rather than a fraudster. The ambiguity does half the work. A silent outage and a genuine seizure look identical for hours or even days, and communities routinely split between "exit scam" and "bust" until hard evidence arrives. A well-placed fake banner settles the argument in the wrong direction.What a genuine seizure looks like
Real operations leave paper trails fast. When the FBI seized Hive's payment and leak sites in January 2023, the Justice Department held a press conference the same morning, and the banner itself listed the agencies and countries involved (BleepingComputer). February 2024's Operation Cronos handed control of LockBit's leak site to the UK's National Crime Agency, complete with taunting messages on the affiliate panel and indictments announced within a day (Department of Justice). In January 2025, Operation Talent seized the Cracked and Nulled crime forums across eight countries, again with same-day warrants and announcements (DOJ). German police's December 2024 takedown of the Manson Market followed the same playbook, its banner warning users that all transactions and records were now in custody (BleepingComputer). The common thread: coordinated announcements, named agencies, court documents, and banners served from infrastructure the government demonstrably controls. Large seizures are public relations events by nature. Silence plus a banner alone should always raise an eyebrow.How to tell a real seizure from a fake
- Look for a matching announcement on the agency's own site or in reporting by established security outlets.
- Check DNS and WHOIS: genuine seizures change nameservers at the registry level, which is far harder to fake than page content.
- Treat any banner demanding payment, logins, downloads, or click-throughs as fraudulent. Real notices ask nothing of visitors.
- Distrust mirrors and "new links" appearing after a takedown; they are usually phishing clones trading on a dead brand.