Skip to main content

Poster: Longitudinal Analysis of Romance Scam Infrastructure Evolution: Evidence of Strategic Legitimization

Nayeon Ryu ; Heeyeong Suh ; Seyoung Lee (2025) — Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security

What do these research terms mean?
Preprint
A manuscript shared before formal peer review and publication. Check whether a later published version is available.
Dataset
A collection of data or examples for others to inspect or reuse. It can appear in Library search and topic mapping, but RSRC does not use dataset records as evidence in Research Insights.
Dissertation or thesis
Research submitted for an academic degree. This describes its format, not its reliability.
Journal article
An article published in a journal. This label alone does not establish peer review, study quality, or how well the findings apply elsewhere.
Qualitative research
Examines experiences, meanings, or processes, often through interviews or observations. It can explain how something happens without estimating how common it is.
Quantitative research
Uses numerical measurements to describe patterns or test relationships. A relationship between two measurements does not by itself show that one causes the other.
Systematic review
Uses a planned, documented method to find and assess research addressing a question. Its conclusions still depend on the included studies and what the search covered.
Meta-analysis
Statistically combines results from multiple studies. Combining studies does not remove weaknesses in their design or make unlike populations interchangeable.
Not classified
This record has no recognized label in this filter. It does not mean the publication used no method, or that no research exists.

Definitions draw on DataCite resource types; Cochrane review methods; NLM: association and causation. RSRC’s dataset and classification rules are explained in our methodology.

Citation tools


              
              

Transparency

Evidence and review status

This page contains AI-generated content. No human content review or subject-matter-expert review is recorded.

Source basis
Downloaded PDF
Source updates
No notice found at last check
AI-generated page content
Yes
Automated checks
Passed
Administrative approval
Yes
Human content review
Not recorded
Subject-matter-expert review
Not recorded
How this was prepared
Source basis

RSRC downloaded and privately stored a copy of the paper for internal analysis. The PDF is not offered to viewers from this page.

  • PDF added to RSRC:
Source updates

No incoming update notice was found in the dated Crossref response. Coverage is incomplete, particularly for corrections and expressions of concern; this is not a guarantee that the source is valid or unchanged.

  • Last source-status attempt:
AI-generated page content

AI-generated research notes displayed on this page: Synopsis, Identified gaps, Methods, Limitations, Future work. The paper itself is not described as AI-generated.

  • Document analysis recorded:
  • Page record updated:
Automated checks

The current, source-bound synopsis passed the recorded versioned publication checks.

  • Checks completed:
View passed checks (3)
  • Length, completeness, repetition, refusal, boilerplate, and active-markup screening
  • Numerical claims checked against the available source text
  • English-source lexical grounding check
Administrative approval

An authenticated administrator approved the bibliographic record for public Library display. This is not a review of every research claim.

  • Approved for public display:
Human content review

No human review is recorded for the AI-generated content displayed on this page.

Subject-matter-expert review

RSRC has not recorded review of this content by a subject-matter or methods expert.

Review-state definitions
Found a possible error? Request a correction.

Synopsis

This longitudinal infrastructure study analyzed 11,674 verified ScamDigger romance-scammer profiles dated May 2012 through December 2024. It geolocated reported IP addresses, mapped them to autonomous systems, and classified providers as traditional internet service providers, cloud or hosting services, or proxies. The authors identify 2019 as a major change point: average proxy use fell from 90.6% before 2019 to 53.1% afterward, traditional-provider use rose from 29.5% to 50.2%, and autonomous-system diversity contracted 31.3%. They interpret the shift as strategic use of more legitimate-looking infrastructure rather than simple technical advancement. Community reporting, English-language platform bias, imperfect IP and provider attribution, and country thresholds limit representativeness.

Identified Gaps

Prior romance-scam research has concentrated on psychological and social-engineering aspects and fake-profile detection. Existing technical infrastructure studies have been temporally limited. The paper identifies a scarcity of decade-scale longitudinal analyses, particularly analyses at Autonomous System Number and infrastructure-role levels.

Methods

The study longitudinally analyzes 11,674 verified romance-scammer profiles from ScamDigger, dated May 2012 to December 2024. It uses IPinfo IP geolocation to assign geographic and Autonomous System data, classifies ASNs as Traditional ISP, Cloud/Hosting, or Proxy providers, and uses ASN-name and keyword matching to identify suspicious infrastructure. It compares infrastructure measures before and after the 2019 change point and examines geographic specialization and shared-IP patterns.

Limitations

Community-reported data may bias the sample toward detected operations and English-speaking platforms. Validation may not remove all false positives. ASN organizational mapping only approximates operational boundaries. The country analysis is limited to countries with more than 180 profiles, which may underrepresent smaller-scale operations.

Future Work

Develop behavioral inconsistency analysis that does not rely primarily on proxy indicators. Test targeted interventions focused on operational concentrations in Nigeria and Ghana. Establish coordinated multinational enforcement approaches for deceptive infrastructure distributed across Western cloud providers. Anticipate adversarial adaptation toward abuse of legitimate services rather than reacting only to known network-layer signals.

See how this publication connects to RSRC's living evidence syntheses through current citations and research-topic mapping.