Scam centers and hacking groups are different operations; they have different structures, are organized differently, and require a different skill set to operate. Understanding the difference matters, because the warning signs and the defenses for each are different.

 

What is a hacking group?

A hacking group is a technical operation. It's made up of people with programming, networking, and systems knowledge who break into computers, servers, or networks without authorization. Their tools are exploits, malware, phishing kits, and custom-built software designed to find and abuse weaknesses in code or infrastructure.

Hacking groups differ in size and capability. Some groups are loosely organized and others have professionalized experts that spend months mapping out a target's network before deploying ransomware or exfiltrating sensitive data. Groups associated with major ransomware strains often operate with the internal structure of a business which includes developers who write the malware, affiliates who deploy it, and negotiators who handle ransom payments.

 

Examples

LockBit

For several years running, LockBit was the most active ransomware-as-a-service operation, offering its malware to criminal "affiliates" in exchange for a cut of every ransom collected. However, in February 2024, an international task force code named Operation Cronos, seized 34 of the group's servers, shut down more than 14,000 accounts tied to its infrastructure, and froze roughly 200 associated cryptocurrency accounts, according to details compiled by Infosecurity Magazine.

Learn more: Ransomware group profile: LockBit

 

BlackCat/ALPHV

BlackCat, also known as ALPHV, was another ransomware-as-a-service group. In February 2024, the group breached Change Healthcare, a subsidiary of UnitedHealth Group, in an attack that froze prescription processing at pharmacies nationwide for weeks. Investigative journalist Brian Krebs reported that Change Healthcare made a roughly $22 million payment to the group, and it was later confirmed that the breach compromised the personal data of over 192 million people, making it the largest healthcare data breach in US history. Days after the payment reportedly went through, an affiliate who said they'd carried out the intrusion complained publicly that BlackCat had refused to pay their cut. The dispute appeared to trigger the collapse of BlackCat's own infrastructure.

The biggest feature of a hacking group is that their attack method is technical. They're exploiting a vulnerability in software, a misconfigured server, a weak password, or an unpatched system.

Learn more: Ransomware group profile: BlackCat/ALPHV

 

What is a scam center?

A scam center, rather than exploiting software vulnerabilities, exploits people. The "vulnerability" being targeted is psychological, not technical.

In recent years, scam centers have become famous for their scale and labor conditions. According to the U.S. Institute of Peace, the U.S.-China Economic and Security Review Commission reported that pig-butchering scams generated roughly $63.9 billion in global revenue in 2023, with scam centers in Burma, Cambodia, and Laos producing about $43.8 billion of that total. A 2026 United Nations Human Rights Office report found that credible estimates put the number of people working in Southeast Asia's scam industry at around 300,000, with trafficked workers pulled from 66 different countries. The report noted the conditions inside the compounds, stating, "The treatment endured by individuals within the context of scam operations is alarming."

 

Examples

Prince group

In October 2025, U.S. prosecutors unsealed an indictment against Chen Zhi, the Chinese-born chairman of the Cambodia-based Prince Group conglomerate, accusing him of running forced-labor scam compounds across the country. According to The Wire China, investigators described the sites as prison-like facilities surrounded by high walls and barbed wire, where trafficked migrants were made to carry out cryptocurrency investment fraud at a large scale. Washington seized roughly $14 billion in bitcoin it linked to Chen and the U.S. Justice Department described Prince Group as a front for "one of Asia's largest transnational criminal organizations." Chen was arrested in Cambodia in January 2026 and extradited to China.

 

KK Park

Along the Thailand–Myanmar border, the KK Park compound became one of the most notorious scam hubs in the region, housing thousands of trafficked workers forced to run online fraud schemes around the clock. Forbes has reported that Myanmar's military carried out a raid on the compound in October 2025 that temporarily shut the operation down.

Scam centers function like call centers, with shift schedules, scripts, performance quotas, and supervisors. Investigations have found that a number of the people making the calls are themselves trafficking victims lured with fake job offers, then trapped, threatened, and forced to work the phones under threat of violence.

 

The differences

  • Skillset - Hacking groups need technical expertise such as coding, reverse engineering, network exploitation. Scam centers need social engineering skills which includes the ability to sound convincing, and manipulate emotions over chat or phone.
  • Target - Hackers target systems and code. Scammers target individual people directly, often building relationships that unfold over weeks or months.
  • Scale of operation - A hacking group can be a handful of skilled individuals working remotely, sometimes across different countries, coordinating online. A scam center is often a large, physical operation.
  • Tools of the trade - Hackers use malware, exploit kits, phishing infrastructure, and command-and-control servers. Scam centers use scripts, fake trading apps, spoofed caller IDs, and curated social media profiles.
  • Human cost during the crime itself - Hacking groups don't require forced labor to operate, their "workforce" is often willing participants. Scam centers, particularly the large-scale ones uncovered in recent years, frequently rely on trafficked and coerced workers, meaning the operation produces victims on both ends, that is, the people being scammed and the people being forced to run the scam.

 

Where they work together

Scam centers often purchase hacking tools, stolen data, or access credentials from hacking groups to make their scams more convincing, for example, using leaked personal information to make a fake bank call sound legitimate. Researchers at CSIS have documented the rise of deepfake technology as a connective thread, noting that the UN Office on Drugs and Crime reported an increase in deepfake fraud across the Asia-Pacific region and warned that scammers are using the technology to "execute social engineering scams with alarming success rates, exploiting people's trust and emotions." That same CSIS analysis, looking at USIP research, added an observation about where the money is now coming from, "U.S. residents are now a top target of the crime networks' financial crimes."

Furthermore, both hackers and scam centers rely on crypto for laundering proceeds, and both have adapted their operations around exploiting the anonymity and irreversibility of crypto transactions.

 

FAQs

Is it illegal to work in a scam center?

It depends on the jurisdiction and the individual's circumstances, since many workers are trafficking victims rather than willing participants, which changes how they're treated legally.

 

Can someone be part of both a hacking group and a scam operation?

Yes, with hackers supplying stolen data or tools that scam centers use to run more convincing schemes.

 

Do governments cooperate internationally to fight these operations?

Yes, cross-border task forces and joint law enforcement operations are common, since both hacking groups and scam centers often operate across multiple countries.