The $3.2 Billion Investor Who Also Had 800 KG of Gold
Some investigations begin with a suspicious sign-in.
Others begin with PowerShell.
This one began with someone wondering why I hadn't replied to his USD $3.2 billion investment opportunity.
Apparently he'd emailed me three times.
Sorry. Been busy. 😂

Big Numbers Don't Equal Credibility
The promise was enormous. The investigation was much simpler: check the sender, check the domain, check the company and follow the evidence.
The offer was difficult to ignore
Of course.
Because when you're moving billions of dollars internationally, the obvious strategy is to cold-email a technology company and ask: “While I've got you... know anyone who wants 800 kilos of gold?” 😂
Agent Foskett noticed a few clues
Nice try. 😂
The billions were interesting. The domain was more interesting.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
let SuspiciousDomain = "suspicious-domain.example";
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ SuspiciousDomain
| project Timestamp,
SenderFromAddress,
RecipientEmailAddress,
Subject,
DeliveryAction,
ThreatTypes,
DetectionMethods
| order by Timestamp descWas I the only person they contacted?
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
let SuspiciousDomain = "suspicious-domain.example";
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ SuspiciousDomain
| summarize Emails=count(),
Recipients=dcount(RecipientEmailAddress),
FirstSeen=min(Timestamp),
LastSeen=max(Timestamp)
by SenderFromAddress, SenderFromDomain
| order by Emails descCheck the URLs before following them
EmailUrlInfo. The goal is not to click the link to see what happens. It is to inspect the URL evidence associated with messages from the suspicious domain and identify infrastructure that may deserve further investigation.- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
let SuspiciousDomain = "suspicious-domain.example";
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ SuspiciousDomain
| project NetworkMessageId, Timestamp, SenderFromAddress, Subject
| join kind=inner (
EmailUrlInfo
| project NetworkMessageId, Url, UrlDomain
) on NetworkMessageId
| project Timestamp, SenderFromAddress, Subject, Url, UrlDomain
| order by Timestamp descHunt for similar investment approaches
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
EmailEvents
| where Timestamp > ago(30d)
| where Subject has_any (
"investment",
"gold",
"funding",
"business proposal"
)
| project Timestamp, SenderFromAddress, SenderFromDomain,
RecipientEmailAddress, Subject, DeliveryAction
| order by Timestamp descWhat Agent Foskett checked
What the evidence can and cannot prove
The lesson
Don't investigate the promise.
Investigate the person making it.
Check the sender. Check the domain. Check the company. Question the urgency. And don't move the conversation elsewhere just because they ask.
And if someone with $3.2 billion and 800 kg of gold is desperately chasing you because you haven't answered their emails...
you might want to investigate that too. 😂
Related investigations
Final thought
It was the mismatch between the story being told and the evidence sitting behind the message.
A polished title can be typed. A huge number can be typed. “KYC” can be typed. Even 800 kilograms of gold can be typed. 😂
The evidence still has to stand up.
Follow the evidence. Build the timeline.
The Logs Already Knew! 🔎

