Research hub

Disclosure that teaches defenders, not attackers.

Every public page is redacted to a defender-oriented level. Private evidence and sensitive indicators never appear here.

Public-safe disclosures

S1AV-2027-004828.7HighRemediation In Progress2027-02-14

Linked-account intervention fails in approved multi-account simulation

An authorized test demonstrated that a cluster of sponsor-provided accounts could progress farther than expected before linked-account controls intervened.

S1WE-200ACCOUNT_FARMINGCOORDINATED_ABUSE@signalghost
S1AV-2027-004767.9HighValidated2027-02-02

Synthetic scam conversation reaches external-contact stage without expected friction

A fully synthetic conversation between two sponsor-provided test personas advanced to the external-contact stage before the expected intervention appeared.

S1WE-400ROMANCE_SCAM@trustbreaker
S1AV-2027-004516.4MediumResolved2027-01-19

Enforcement state inconsistent across approved test-account recovery flow

A restricted sponsor test account regained a subset of capabilities through the recovery flow, leaving enforcement state inconsistent between services.

S1WE-700S1WE-800ENFORCEMENT_EVASION@graphkite
S1AV-2027-004194.2MediumNew2026-12-28

Automated agent sustains sandbox listing volume above documented abuse thresholds

A scripted agent using sponsor-issued sandbox credentials maintained listing volume above the threshold documented in the program policy.

S1WE-1000AI_GENERATED_ABUSESPAM@graphkite

Campaign intelligence

S1CI-2027-00121Active

Golden Horizon

Investment fraud / romance scam

A coordinated cluster using overlapping personas, domains, and payment destinations.

18 indicatorsconfidence: HighSocial · Messaging · Crypto
S1CI-2027-00117Monitoring

Parcel Recovery

Impersonation / marketplace fraud

Impersonation of delivery and recovery services targeting marketplace buyers.

11 indicatorsconfidence: MediumEmail · SMS · Marketplace

Notes & analysis

Disclosure2027-03-02

Coordinated enrollment clusters and the limits of linked-account detection

A defender-oriented walkthrough of what an authorized cluster test revealed about intervention timing — and the control changes that followed.

Research2027-02-21

Intervention timing is the whole game in romance-scam defense

Across four sandbox programs, the gap between detection and intervention explained more risk than detection quality itself.

Intelligence2027-02-08

What mule graphs look like before the money moves

Campaign intelligence from two validated clusters shows repeatable structure in payout destinations weeks ahead of loss events.

Method2027-01-30

Reading insider disclosures without repeating the playbook

How S1ID submissions are corroborated, redacted and converted into defensive test cases rather than attack manuals.