Poster: Longitudinal Analysis of Romance Scam Infrastructure Evolution: Evidence of Strategic Legitimization

Ryu, Nayeon ; Suh, Heeyeong ; Lee, Seyoung (2025) — Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security

Synopsis (AI-Generated)

This longitudinal infrastructure study analyzed 11,674 verified ScamDigger romance-scammer profiles dated May 2012 through December 2024. It geolocated reported IP addresses, mapped them to autonomous systems, and classified providers as traditional internet service providers, cloud or hosting services, or proxies. The authors identify 2019 as a major change point: average proxy use fell from 90.6% before 2019 to 53.1% afterward, traditional-provider use rose from 29.5% to 50.2%, and autonomous-system diversity contracted 31.3%. They interpret the shift as strategic use of more legitimate-looking infrastructure rather than simple technical advancement. Community reporting, English-language platform bias, imperfect IP and provider attribution, and country thresholds limit representativeness.

Identified Gaps (AI-Generated)

Prior romance-scam research has concentrated on psychological and social-engineering aspects and fake-profile detection. Existing technical infrastructure studies have been temporally limited. The paper identifies a scarcity of decade-scale longitudinal analyses, particularly analyses at Autonomous System Number and infrastructure-role levels.

Methods (AI-Generated)

The study longitudinally analyzes 11,674 verified romance-scammer profiles from ScamDigger, dated May 2012 to December 2024. It uses IPinfo IP geolocation to assign geographic and Autonomous System data, classifies ASNs as Traditional ISP, Cloud/Hosting, or Proxy providers, and uses ASN-name and keyword matching to identify suspicious infrastructure. It compares infrastructure measures before and after the 2019 change point and examines geographic specialization and shared-IP patterns.

Limitations (AI-Generated)

Community-reported data may bias the sample toward detected operations and English-speaking platforms. Validation may not remove all false positives. ASN organizational mapping only approximates operational boundaries. The country analysis is limited to countries with more than 180 profiles, which may underrepresent smaller-scale operations.

Future Work (AI-Generated)

Develop behavioral inconsistency analysis that does not rely primarily on proxy indicators. Test targeted interventions focused on operational concentrations in Nigeria and Ghana. Establish coordinated multinational enforcement approaches for deceptive infrastructure distributed across Western cloud providers. Anticipate adversarial adaptation toward abuse of legitimate services rather than reacting only to known network-layer signals.

AI-Generated Content Notice

The synopsis and research notes on this page were generated with AI from available publication information and, when available, the uploaded paper text. They may contain errors, omissions, or interpretation issues. Readers should follow the DOI or source link, review the original publication, and make their own judgment about the content.

Found a possible error? Request a correction.