Probe4Good investigates messaging-fraud networks from inside their own platforms. Victim lists extracted, infrastructure traced, willfulness documented — packaged for counsel before the evidence can disappear.
Every engagement ends the same way: a structured evidence package your firm can evaluate in an afternoon and file on.
Authenticated access to scam-platform accounts, live monitoring, and full state capture before takedowns can destroy evidence. We document what operators can't delete.
Gateway groups, 10DLC campaigns, number pools, carrier chains (OCN-level), shell-brand linkage. We prove one operator behind many personas.
Complete recipient extraction with exact-count verification, deduplication, and area-code geography. The class list is built before you file, not after discovery.
Notice letters, founder responses, platform opt-out flags, post-notice sending. We build the actual-knowledge record that supports treble damages.
Chain of custody, raw HTML artifacts, delivery analytics, timelines, and an investigation dashboard. Counsel gets a case, not a research project.
Scheduled re-probes track renewal dates, credential rotations, number-pool changes, and continued sending — converting inaction into spoliation evidence.
A stock-scam SMS network running through a NY-based sending platform and a national CPaaS gateway. Fully documented. Still live.
A single SignalHouse-provisioned 10DLC campaign (group GX4EWF00) was shared across multiple TextTorrent sub-accounts, letting one operator run two shell brands — Greenbridge Partners LLC and Bluestone Financial LLC — off the same vetted registration. 46 sender numbers in snowshoe rotation; 8 coordinated ~2,500-recipient batches in under 3 hours on peak day.
On July 21, 2026, the gateway's founder was personally notified of stock-scam SMS on his platform. He admitted in writing he could terminate accounts — and terminated one. The same day, this operation blasted 28,037 texts. He left it running. The numbers were renewed in August. Treble damages rest on his own email.
A repeatable pipeline refined on live operations.
Source intelligence surfaces an illegal operation. We obtain access and establish persistent, authenticated monitoring before the operator knows anyone is watching.
Account state, gateway configuration, contact lists, campaign history, inbox traffic, and platform-side harm flags — captured with timestamps and exact-count verification.
Gateway group IDs, 10DLC campaign records, carrier thousands-blocks, and KYC identities link shell brands to one operator and one provisioning chain.
Notice is served on the gateway and platform. Every response, partial action, renewal, and ignored demand is logged — the willfulness record writes itself.
Counsel receives a structured evidence room: victim list, defendant map, exposure model, knowledge timeline, and a plaintiff-ready declaration template.
We evaluate referrals from recipients, investigators, and counsel. If the operation is real, we can usually document it end-to-end.
Start a referral →