How churn-and-burn websites are reshaping financial crime

Online fraud has become a relentless cycle. Criminals are spinning up thousands of short-lived scam websites, some lasting only a single day, to collect money and disappear before investigators can detect them.

These sites tend to follow a familiar pattern:

  • Strange, hard-to-pronounce domain names, such as anbajfsg.shop
  • Generic, over-the-top promises of “unique” or “high-value” products
  • Copy-and-paste language that appears across hundreds of sites
  • Social media ads fronted by fake accounts

Individually, each site may appear legitimate. However, the larger pattern often only emerges when investigators combine data from multiple sources. This can reveal networks of coordinated fraudulent activity that would otherwise remain hidden.

A business model built on speed

Most churn-and-burn websites survive for just a day or two, which is long enough to trick unsuspecting customers into making a purchase. Once criminals have processed a burst of transactions, they shut down the site and reappear under a new identity.

Payment service providers are seeing networks capable of launching thousands of fresh sites every day. In one example, a supposed “t-shirt shop” appeared, processed the equivalent of 8,000 sales in a single day and then disappeared.

The speed of these operations is critical. Investigators face a constant race against time. By the time traditional checks and alerts trigger, the websites may already be gone.

Criminals rely on this speed to exploit gaps in monitoring and move illicit funds rapidly. It reflects a wider change in financial crime, where criminals increasingly combine digital infrastructure with faster ways of moving money. Our article on how criminals are digitising the laundering chain explores this shift in more detail.

Why traditional detection struggles

Conventional fraud detection workflows, including manual reviews, complaints and slow-moving alerts, cannot keep pace with websites that exist for only a few hours.

This is where technology can make a difference. Tools that quickly analyse large volumes of transactions can identify patterns and highlight suspicious activity earlier. As a result, investigators can act before the scam disappears.

Technology can reduce work that once required months of manual review to days or even hours. This gives teams a better chance of keeping pace with fast-moving criminal networks.

However, no single organisation sees the full picture. Criminal activity can stretch across websites, social media accounts, financial transactions, digital identities and multiple platforms. That makes connecting information increasingly important.

Where OSINT tools make a real difference

Open-source intelligence helps investigators look beyond the narrow view provided by internal transaction data. By bringing together signals from across the open web, OSINT and financial intelligence can provide the wider context needed to understand how churn-and-burn operations function.

Instead of investigating each scam website in isolation, OSINT can help uncover recurring behaviours, shared infrastructure, repeated tactics and other signals that connect seemingly unrelated sites to a wider fraud network.

It also gives investigators the ability to identify emerging trends earlier, understand how criminals adapt their methods and recognise when a new wave of scam sites forms part of something much larger.

This becomes increasingly important as criminals adopt more sophisticated technology. Fraud-as-a-service and agentic AI are making advanced fraud tools more accessible, allowing criminal operations to increase their speed and scale without requiring the same level of technical expertise.

Keeping pace with fast-moving fraud

Churn-and-burn websites aren’t slowing down. At the same time, fraud is learning and investigations need to evolve faster.

OSINT-powered investigations can give teams greater visibility across the wider digital landscape. Rather than viewing individual websites, accounts or transactions as isolated incidents, investigators can start connecting the signals between them.

Ultimately, that wider picture helps investigators identify networks, uncover patterns and keep pace with criminals who rely on speed, scale and obscurity.

Share this article, choose your platform:

Find the right solution for your organisation.

Email us on: info@altiaintel.com