The Wrong-Number Opener Behind SMS Pig-Butchering Scams
The Wrong-Number Opener Behind SMS Pig-Butchering Scams
A polite wrong-number text is rarely a mistake: it is the engineered first move of an SMS pig-butchering operation built to turn one reply into a long con. Throughout early 2026 we tracked a durable opener pattern that fronts an SMS romance and crypto-investment ecosystem: an unsolicited text from an unknown US number that fabricates a plausible reason to have messaged the recipient at all. The opener carries no link, no threat, and no urgency. It asks only for a reply, and the reply is the entire point. Once a recipient corrects the sender or answers out of politeness, the operator pivots into grooming and, eventually, a fake trading platform that ends in extraction.
Key Takeaways
- The opener is a distinct, reusable scam component built from three interchangeable parts: a mistaken-identity hook, a fabricated mutual-context referrer, and an apologetic soft lock-in that keeps the channel open after pushback.
- The lure is deliberately benign. It contains no URL, no financial vocabulary, and no brand impersonation, so URL reputation, link checking, and blocklist heuristics have nothing to bite on at first contact.
- Sender numbers are disposable US and Canadian VoIP or MVNO lines dispersed across roughly 200 area codes, with most numbers sending only one or two messages before abandonment.
- The endgame is a move off SMS. A WhatsApp handoff dominates the observed pivots, followed by Telegram, then Google Chat and Signal, which places the rest of the con beyond carrier-side scanning.
- Persona names rotate freely across more than a hundred first names, while the opener mechanic stays constant. The shape is the durable correlator, not any single name, number, or pretext.
Background
Pig-butchering, or sha zhu pan, is a long-con fraud model: a cold opener leads to sustained trust-building over days or weeks, then an introduction to a fake crypto or foreign-exchange trading platform that shows fabricated gains, then escalating deposits, and finally a slaughter phase where withdrawals are blocked or new fees are demanded. The model is increasingly run as a service from organized compounds, and the opener is the mass-market top of that funnel.
The numbers behind the model are large and growing. The FBI Internet Crime Complaint Center reported more than $16 billion in total losses for 2024, with digital-asset losses near $9.3 billion and crypto investment fraud the top category at roughly $5.8 billion. The FTC separately reported $5.7 billion in investment-scam losses for 2024, its largest fraud category, alongside roughly $470 million in text-initiated scam losses, about five times the 2020 figure. Consumer and press coverage through 2025 has repeatedly flagged the wrong-number text as the current growth vector, including FTC consumer alerts and reporting on the same odd-text pattern.
This report isolates the opener phase as its own object of study. The grooming, platform-migration, and extraction phases have been documented widely; what receives less attention is how these operations solve the hardest problem in the whole chain, which is getting a cold stranger to answer at all.
Discovery and Infrastructure
The investigation began with a user-submitted screenshot of a new-neighbor text and expanded through content sweeps of URL-free inbound SMS from US-formatted numbers. That expansion surfaced a cohort of operator numbers running the same three-part opener, all consistent with a broader ecosystem of more than a hundred actors observed across the full scam lifecycle.
The sending infrastructure is built for disposability. Numbers are provisioned in bulk through VoIP and second-line apps, MVNO or prepaid SIMs, and wholesale number pools that feed smaller resellers. They are cheap, provisioned by API, and geographically flexible, so an operator can rotate through fresh, real-looking US numbers faster than reputation systems can score them. Each number carries little or no sending history, which leaves per-number reputation and rate models with nothing to score.
Two structural traits stand out across the opener cohort. First, geographic dispersion rather than concentration: operator numbers spread across roughly 200 distinct area codes, with the single busiest code carrying only a handful of senders. Texas metro codes appear near the top of the distribution but account for under a tenth of the cohort, so dispersion, not a regional cluster, is the signature. Second, low volume per number: most operator lines send only one or two captured messages before going dark, and a line only runs a long multi-day thread once a recipient has engaged.
How It Works
The opener exists to convert a cold text into a sustained conversation. Direct romantic approaches and overt scam pretexts are easy to ignore, so the wrong-number and fake-neighbor framing gives the recipient a socially expected reason to reply: to politely correct the sender, decline a misdirected message, or clear up a misunderstanding. Any reply validates the number as live and opens the door to grooming.
The opener is assembled from three parts, mixed and matched per actor.
The first part is a mistaken-identity hook, a short claim that the recipient is somebody else. It ranges from a direct question (is this a named person's phone number) to an apologetic dial error (I think I dialed wrong, I texted the wrong person but nice to meet you).
The second part is a fabricated mutual-context referrer, an unverifiable but plausible reason the sender had the number in the first place. The most common are a new-neighbor or property-management referral, a claim of having met in a hospital, a dating-site introduction, a work-phone or business-contact story, and a cleaning-up-my-contacts pretext. These are chosen to be plausible and uncheckable.
The third part is an apologetic soft lock-in that keeps the channel open even after the recipient pushes back. The sender volunteers a name, neighborhood, or profession without being asked, reframes the recipient's suspicion as a misunderstanding, and sends ambient follow-up pings days later. A recipient who says wrong number does not end the exchange; it triggers a warmer, more apologetic reply.
Each part is independently disposable. Personas, referrer pretexts, and recovery tones all swap out without changing the underlying mechanic, and that mechanic is what persists across numbers and months.
Sample Lures
All samples are SMS. Recipient names, addresses, and any personal identifiers have been redacted, and operator contact handles are defanged. Attacker-side content is shown as observed.
New-neighbor and property-management pretext, with all three parts present in one thread:
"Don't leave leftover"
[recipient: "Who is that?"]
"Please excuse me, my tone was not very polite just now. I got your number
from the property management; I was just reminding you not to leave building
materials in front of my door. I'm your new neighbor; my name is Mia"
[recipient: "What is your address Mia?"]
"This is the Pacific Heights neighborhood in California. Do you need me to
tell you my house number?"
[recipient: "You probably got a wrong number then"]
"Huh? This is confusing me. The property management gave me your number. So I
wanted to confirm again, are you Ms. [recipient], who just moved to CA?"
[recipient: "No"]
"Oh my! This is really awkward. Maybe the property management gave me the
wrong number. I'll go check right now. I certainly don't want to be the one
sending spam messages. I hope you weren't joking with me."
[days later, no reply:]
"I hope you have a wonderful Saturday. Good morning."
"Have a great weekend! I hope you have a wonderful Sunday with your family today."
Wrong-number hook with a relocation backstory:
"Excuse me. Is this Louise's phone number? This is Emily."
"Oh, I'm so sorry. That's probably the most embarrassing..."
"I found my friend Louis's number, and I hope this pleasant misunderstanding
hasn't affected your life."
"My name is Emily, and I'm from Roubaix, France. This is my fifth year in the
United States... I hope you'll be my first friend of 2026."
Dating-site referrer:
"Hello [recipient]"
"My name is Peggy from the dating site"
"Hello Handsome"
"I am new to the dating site... My aim of joining is to find a solid friend..."
Wrong-number hook pivoting to a WhatsApp handoff, the move that takes the con off SMS:
"howdy."
"Is this Lisa's phone number? I'm Alice."
"I'm Alice from Miami, I'm 36 years old, how about you?"
"How about this, do you have WhatsApp? Can we chat there?"
"hxxps://wa[.]me/1-305-765-xxxx"
The eventual ask, opened in the same wrong-number style but carrying the investment pitch:
"Goods! my name is [persona], with [a fabricated investment group]. A few
strong-performing stocks with the potential for 120% returns have been
selected. A quick 'Yes' will include you in the group."
Technical Analysis
Opener Grammar and the Referrer Taxonomy
The opener is best read as a grammar with three slots. A message qualifies as an opener when a mistaken-identity hook co-occurs with a fabricated-context referrer, and the apologetic recovery is the fallback that fires on pushback. Single slots on their own are noisy, because real wrong-number texts, real dating introductions, and real apologies all exist. The co-occurrence of two slots is the high-precision signal.
The fabricated-context slot is the most distinctive, and it clusters into a small, stable set of referrer families. The table below lists the families observed across the opener cohort, ranked by how many distinct sending numbers ran each.
| Referrer family | Representative phrasing | Relative prevalence in cohort |
|---|---|---|
| New neighbor | "I'm your new neighbor", "not to leave building materials" | Most common |
| Met in the hospital | "We met sometime ago in the hospital and exchanged contacts" | Common |
| Property management | "I got your number from the property management" | Common |
| Google Voice / private number | "Nope this is just my google private number" | Uncommon |
| Dating site or app | "My name is Peggy from the dating site" | Uncommon |
| Work phone / business contact | "This is my work phone", "I work in the semiconductor industry" | Uncommon |
| Cleaning up contacts | "I was cleaning up my contacts when your number popped up" | Uncommon |
| Home-purchase interest | "I'd love the opportunity to buy your home" | Rare |
The mistaken-identity slot has its own variant set: a named-person query (is this a specific person's number), a still-there variant that implies prior contact (is this still a named person's number), a dial-error or wrong-person apology, and a mistaken-send apology. An insurance-quote follow-up variant also appears, in which the persona poses as an agent from a national insurance brand confirming a quote request, which blends the wrong-number frame with brand impersonation.
Persona Rotation
Persona names are treated as consumable. Across the opener cohort, first-name self-introductions span more than a hundred distinct names, most used only once, with a small number of recurring favorites. The durable core observed directly in this campaign includes Mia, Emily, Peggy, Ashley, Lin, Jessica, Alice, Patrice, and Kennedy. Because the name pool is effectively unbounded and disposable, the persona is not a useful correlator. The opener shape is.
Message-Length Escalation
Opener messages follow a consistent length curve. First-contact hooks are short, with a median near 58 characters, and roughly half fall under 80. Once a recipient engages, message length balloons: rapport and pitch messages that carry the persona biography, the relocation backstory, the platform handoff, or the investment offer run to a median near 178 characters. The short-then-expand curve is a behavioral fingerprint of the opener stage that is independent of any specific wording.
The Cross-App Handoff
The opener is a handoff stage. Its success condition is not a click but a platform move, because carrier-side SMS scanning ends the moment the conversation leaves SMS. Across the cohort, the pivots concentrate heavily on one destination.
| Handoff destination | Relative prevalence | Notes |
|---|---|---|
| Dominant | Frequently delivered as a wa[.]me deep-link rather than a typed number | |
| Telegram | Secondary | t[.]me links and handles |
| Google Chat | Minor | Also framed as a "google private number" |
| Signal | Minor | App-context references, distinct from carrier-signal noise |
| iMessage | Rare |
The WhatsApp deep-link is notable because it is the one link that does appear at the opener stage, and it is an operator-controlled contact handle rather than a landing page. The FBI lists a request to move the conversation to WhatsApp or Telegram as a red flag for crypto-investment fraud, which matches the observed behavior exactly.
Absence as a Design Choice
The most important technical property of the opener is what it lacks. There are no URLs at first contact, no financial or crypto vocabulary, no urgency, and no brand impersonation in the core romance variants. Each absence removes a detection surface. The operator has effectively traded the efficiency of a mass blast for the stealth of a conversational cold open, accepting a low reply rate in exchange for messages that read as ordinary personal texts.
Detection Observations
The opener is engineered to read as benign in isolation, so the useful signals are structural and relational rather than lexical. The strongest single signal is co-occurrence: a mistaken-identity hook together with a fabricated mutual-context referrer in the same conversation is far more specific than either cue alone. Politeness should be treated as neutral to suspicious rather than reassuring, because apology, warmth, and gratitude are the camouflage here, not evidence of a genuine sender. These messages deliberately carry none of the urgency and threat cues that behavioral models usually key on, which is a property of the lure rather than a gap in any one defender.
Other behavioral separators are available to defenders. URL-free inbound texts from unknown US or Canadian numbers that introduce a persona and volunteer unsolicited personal context fit the pattern. A short first message followed by a sharp expansion in length once a reply lands is characteristic. An early push to move onto WhatsApp, Telegram, or Signal, especially delivered as a deep-link contact handle, is a high-value pivot to flag. None of these depend on the specific persona name or referrer wording, which is what makes them durable as the operator rotates surface details.
Indicators of Compromise
All indicators below are operator-controlled sending numbers observed running the opener. Recipient data has been removed. This is a representative set of verified-malicious numbers from the campaign; operators rotate numbers continuously, so the value is the pattern each number illustrates, not the individual line.
Phone Numbers
| Value | Role | Notes |
|---|---|---|
| +1 (223) 206-8890 | Sender | Dating-site referrer persona |
| +1 (226) 387-3139 | Sender | Wrong-number hook plus France relocation backstory (Canadian NPA) |
| +1 (317) 893-8511 | Sender | Work-phone and cleaning-contacts pretext |
| +1 (334) 472-9931 | Sender | Bare romantic introduction opener |
| +1 (351) 233-0213 | Sender | Cleaning-up-contacts pretext |
| +1 (365) 767-4215 | Sender | New-neighbor and property-management pretext (Toronto NPA, Canadian VoIP) |
| +1 (409) 201-0008 | Sender | Met-in-the-hospital referrer |
| +1 (501) 382-3675 | Sender | Old-friend reconnection plus google-private-number claim |
| +1 (559) 215-1985 | Sender | Casual dial-error opener |
| +1 (604) 657-8357 | Sender | Apologetic mistaken-send (Canadian NPA) |
| +1 (614) 412-1182 | Sender | Home-purchase interest plus pre-emptive apology |
| +1 (726) 230-6780 | Sender | Wrong-number hook pivoting to WhatsApp handoff |
| +1 (814) 636-0194 | Sender | Texted-wrong-person dial-error opener |
| +1 (956) 303-3011 | Sender | Fabricated business referrer carrying an investment pitch |
| +1 (970) 684-4447 | Sender | Still-there wrong-number hook plus insurance-quote variant |
MITRE Fight Fraud Framework Mapping
The public matrix at ctid.mitre.org/fraud is the MITRE Fight Fraud Framework (F3). It exposes seven tactics and uses ATT&CK T-numbers alongside F3-native F1-prefixed identifiers; it does not publish FT-prefixed IDs. Several romance-grooming behaviors have no stable public technique ID in the current framework, which we note rather than invent an identifier.
| Tactic | Observed behavior | ID | Note |
|---|---|---|---|
| Initial Access | Phishing (SMS / smishing) | T1660 | Best fit for the unsolicited wrong-number opener text |
| Initial Access | Impersonate Official | F1032 | Partial fit for the insurance-agent quote variant |
| Resource Development | Bulk disposable-number provisioning | No stable public ID | Framework exposes no discrete technique ID for this |
| Execution | Rapport and reciprocity building | No stable public ID | Not exposed as a discrete F3 technique |
| Execution | Move victim to an encrypted app | No stable public ID | Framework references multi-channel phishing but no discrete handoff ID |
Conclusion
The opener is cheaper to run and harder to see than any later phase of a pig-butchering operation, and it is where defense has the most leverage. Numbers, personas, and referrer pretexts are all disposable, so chasing any one of them is a losing game. The durable target is the three-part shape and the behavioral tells around it: an unsolicited personal cold open with no link, a suspiciously warm recovery after a brushoff, and an early push onto an encrypted app. Once the mechanic is recognized, the rotating surface details (numbers, personas, pretexts) stop mattering.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.