Lekoil announced a $184 million loan only to discover that the supposed sovereign investor was part of a complex facade. Cases across five countries show why professional documents, valid licence numbers and even video calls cannot replace independent verification at each transaction gate.
- ·Professional websites, term sheets and proof-of-funds documents can be instruments of fraud rather than evidence against it.
- ·Verification is only independent when it uses contact details or systems the counterparty did not supply or control.
- ·A valid regulatory number proves little unless the caller, domain and bank account belong to the regulated entity.
- ·Refund promises and escrow language offer no protection unless the funds, payee and escrow arrangement are separately authenticated.
- ·Identity must be checked again when the deal moves from conversation to disclosure, fees, exclusivity or payment.
- ·Boards need a repeatable verification protocol, not confidence in their ability to spot suspicious people.
On 2 January 2020, Lekoil appeared to have solved the problem that shadows almost every ambitious oil project: money.
The Nigeria-focused company, listed on London’s AIM market, announced a binding $184 million loan from the Qatar Investment Authority for OPL 310, its offshore oil project. This was not presented as a speculative introduction. There had been meetings with purported representatives, supposed legal and technical checks, retained UK counsel, an open-source report on the introducer and a signed facility agreement.
It looked like a financing process because it behaved like one.
Then, on 12 January, the real Qatar Investment Authority contacted Lekoil’s advisers. Trading in the company’s shares was suspended. Lekoil disclosed that the counterparties had constructed a “complex facade”. It had paid approximately $600,000 in arrangement and legal fees. At the end of December, it had only about $2.7 million in cash remaining, according to the company’s January 2020 market disclosure.

Lekoil announced a $184 million loan before discovering that the supposed sovereign investor was part of a complex facade. Photo: Matthew Ọbańlá / Pexels, Pexels licence (free commercial use).
The failure was not that Lekoil had ignored every warning. The disturbing part is that it had accumulated many of the things boards normally find reassuring. Meetings. Advisers. Documents. Diligence. A large institutional name.
One check was missing. Nobody had contacted the Qatar Investment Authority through an independently sourced institutional channel before the loan was announced and the fees were paid.
That omission raises a harder question than the usual advice about suspicious emails: what if a fake investor does not look fake at all?
The scam is no longer outside the deal
The conventional picture of a fake investor scam is almost comforting. An unsolicited message arrives. The grammar is poor. The promised loan is implausibly cheap. An advance fee appears. A sensible executive spots the trick and deletes it.
That version still exists. But it is not the version that should worry a board most.
Modern fundraising fraud often copies the legitimate workflow: introduction, proposal, diligence, term sheet, proof of funds, legal paperwork, fee and transfer. The attacker does not merely tell a false story. The attacker builds a process in which every apparent confirmation points back to something else under the attacker’s control.
Call it closed-loop diligence. The website confirms the document. The person on the document answers the telephone. The licence number is real, but belongs to somebody else. The supposed lawyer confirms the supposed investor. Nothing is independent, although everything appears consistent.
This is where most people stop looking. They ask whether the pieces look authentic when they should be asking whether the pieces actually belong together.
The UK Financial Conduct Authority warns that clone firms copy genuine names, websites and Firm Reference Numbers. Its instruction is precise: use contact information independently published on the regulator’s register, rather than details supplied by the person approaching you.
A regulatory number can therefore make a fraud more persuasive. Verified badly, it is not a shield. It is a borrowed uniform.

Anthony Weber. Photo: Supporterhéninois / Wikimedia Commons, CC0.
The final administrative step
In November 2012, companies were approached by people claiming to represent the Abu Dhabi Investment Authority, the sovereign investment institution known as ADIA.
The process had recognisable stages. Businesses were asked for proposals. They received an “ADIA Terms Sheet Request Form”. Proposals were declared approved. Then came what appeared to be the final administrative requirement: a $12,000 registration payment to a UAE account.
The documents looked official because parts of them were. The scammers had altered publicly available forms from the Dubai Financial Services Authority, replacing the regulator’s name with ADIA’s. Neither institution had authorised the paperwork, the DFSA later reported.
The $12,000 request was not placed at the beginning, where suspicion would be highest. It arrived after apparent approval. By then the company had already invested time, disclosed information and begun imagining the money as real.
That sequencing matters. A fee is easier to rationalise when it appears to unlock funding already “won”. The victim is no longer assessing a cold approach. It is trying to avoid losing a transaction that feels nearly complete.
Professional fundraising documents are supposed to reduce uncertainty. In this case, the documents manufactured it, then sold the victim a way out.
A $400 million bank account that did not exist
The alleged US operation involving Jason Torres and Anthony Weber went further. A 2019 federal affidavit described shell companies including Mindful Investments, Global Acquisition Ventures and Reinhart Holdings offering loans that commonly exceeded $100 million.
Borrowers received broker agreements, term sheets, supposed due diligence, refund promises and bank statements showing funding capacity. Six identified victims transferred approximately $7 million.
One company seeking a $20 million loan was shown a Capital One statement with roughly $400 million in the account. Law enforcement found that the account did not exist.
Here is the twist. Proof of funds sounds like the answer to a fake lender. It can also be the bait.
A document supplied by the party making the claim is not proof of that claim. It is the claim in a more expensive-looking format. The same applies to a refundable commitment fee. A refund clause has value only if the party promising repayment controls real assets and can be held to the agreement.
Another aviation project seeking $261 million was asked for $4.95 million. It requested escrow, meaning the money would be held by an independent party until agreed conditions were met. The purported lenders refused.
That refusal was more informative than the term sheet, bank statement and refund language combined. It moved the question away from appearances and towards control: who would hold the money, under whose authority, and on what independently verified terms?
This distinction also matters when founders prepare a data room for lenders. A company may need to disclose detailed commercial information to raise capital. But a polished request for diligence is not permission to release everything. Identity and authority come first. Data access comes later, in layers.
When the licence is genuine but the lender is not
Australia’s corporate regulator warned in 2013 about Mike Morgan Loans, a website appearing to operate from South Africa. It claimed to be an Australian-licensed credit provider and offered loans from A$10,000 to A$20 million at 3%.
Later investigations found a broader method. Overseas operators hacked the websites of legitimate small lenders, used genuine Australian company and credit-licence numbers, rerouted local telephone numbers and issued convincing loan contracts. Reported victims sent more than A$33,000 for supposed insurance, tax or processing costs before learning that no loan existed, according to ASIC.
The licence could be real. The company could be real. Even the local telephone number could appear real. The false step was the connection between them.
A proper check therefore asks more than, “Does this licence exist?” It asks whether the legal entity, licence, website domain, representative and receiving bank account form one verified chain.
Imagine finding the name of a real doctor in a public register. That does not prove the person emailing you controls the doctor’s clinic, prescription pad or bank account. Fundraising verification works the same way.
Then the people on the video call became fake
In January 2024, a finance employee at Arup’s Hong Kong operation joined a video conference. The UK-based engineering firm’s chief financial officer and other colleagues appeared to be present.
They were synthetic representations.
The employee subsequently made 15 transfers totalling HK$200 million, approximately US$25.6 million, to five accounts. Arup confirmed the incident, which Hong Kong police classified as obtaining property by deception.

Arup’s Hong Kong loss showed that even a multi-person video conference cannot replace separate payment verification. Photo: Jimmy Chan / Pexels, Pexels licence (free commercial use).
Email had long been treated as vulnerable. Video felt different. It offered faces, voices and the apparent social pressure of several colleagues agreeing at once.
But direct contact is not necessarily independent contact. If the same attacker controls the meeting, its participants and the payment request, adding more convincing faces does not add another layer of verification. It merely improves the production.
The FBI’s 2025 Internet Crime Complaint Center report, published in 2026, recorded 24,768 business-email-compromise complaints and $3.047 billion in reported losses. It also recorded $155.9 million categorised as advance-fee fraud. These are reported US-linked complaints, not a measure of global incidence. Crucially, the FBI’s modern definition covers compromised email, telephone and virtual-meeting communications.
The channel changed. The control did not.
Payment instructions still needed confirmation through a separate route that the request did not initiate or control.
Five countries, one repeated mistake
Put Nigeria, the UAE, the United States, Australia and Hong Kong side by side and a pattern appears that none of the individual case reports states outright.
The fraud did not defeat one universal identity check. It attacked a different claim at each stage.
Lekoil’s counterparties counterfeited institutional authority. The ADIA impersonators turned genuine regulatory material into a fake approval workflow. The US lenders fabricated funding capacity. The Australian schemes borrowed licences and local infrastructure. The Arup attackers manufactured internal executive approval.
Loss also occurred at different gates. Lekoil paid fees and disclosed the financing to the market. US borrowers funded commitment payments. Australian borrowers paid processing-related charges. Arup reached the last gate and transferred money.
That is why a one-off “know your customer” exercise is inadequate. A person verified at introduction may still lack authority to commit the institution. A legitimate intermediary may not be licensed or mandated for the work being performed. A real investor may send altered payment instructions after its email is compromised.
Trust is not a permanent status. It is permission for one specific next step.
This challenges a common idea in capital raising: that once the relationship feels credible, the company can shift from verification to execution. In reality, higher stakes require fresh verification. The discipline resembles the way serious investors move from interest to commitment through specific decision signals. Founders should demand comparable evidence from the people claiming to fund them.
What this evidence does not prove
Not every fee request establishes fraud. Nor does every administrative error, unfamiliar domain or delayed response mean that a counterparty is false. The evidence here also does not measure the global scale of fake-investor activity.
Controls can create friction. Excessive suspicion can delay a legitimate deal or offend a real counterparty.
The answer is not improvisational paranoia. It is a standard process applied to everyone. A genuine institution should be verified through the same independent route as an unfamiliar lender. The procedure, rather than the founder’s intuition, makes the decision defensible.
What companies should change on Monday
First, separate the excitement of the offer from permission to act. No announcement, fee, sensitive disclosure, exclusivity promise or transfer should occur merely because a term sheet has arrived.
Second, obtain the counterparty’s exact legal name and the representative’s role. Contact the institution using a regulator’s register, an established portfolio-company relationship or another source the counterparty did not provide. Do not call the number printed on the document you are trying to authenticate.
Third, verify authority. Ask whether the representative can sponsor, approve or sign the proposed transaction. If an intermediary is involved, confirm the written mandate directly with the investor or lender.
Fourth, check regulatory permissions, not just registration. In the United States, the Securities and Exchange Commission says that finding investors and receiving compensation tied to a transaction will commonly require broker-dealer registration, meaning authorisation to arrange securities deals. The label “placement agent” does not automatically create an exemption.
Fifth, release information by role. Confirm the non-disclosure agreement and give each participant only the data needed for that stage. A detailed request can be evidence of genuine diligence, but it can also be an efficient way to steal contracts, customer information or negotiating intelligence.
Finally, make payment changes deliberately awkward. New account details, fee demands and transfer instructions should trigger a callback to a previously verified contact and approval from people outside the communication thread.
GI Network’s view: A capital raise should never have one moment called “verified”. Identity, authority, funds and payment instructions can fail separately, so each new exposure needs a new independent check.
What experienced investors understand about the money
Investors perform diligence because a persuasive founder can still be wrong. Companies must adopt the same logic in reverse. A prestigious name can still be borrowed. A term sheet can still be counterfeit. A large stated bank balance can still be fictional.
The psychology is uncomfortable. Founders are often most vulnerable when capital is scarce, deadlines are close and the proposed investor appears to solve several problems at once. Verification then feels like a threat to momentum.
Experienced decision-makers look instead at what each request transfers. A fee transfers cash. Exclusivity transfers negotiating leverage. A data-room invitation transfers information. A board or control provision transfers future power. Payment instructions transfer the asset itself.
The more valuable the transfer, the less acceptable closed-loop evidence becomes.
GI Network’s role in this situation would be concrete: map every transaction gate before outreach, test the investor or intermediary’s legal identity and mandate, check whether proposed fees and control terms fit the funding structure, restrict data-room access by role, and rehearse the verification questions a board should resolve before announcement or payment. It would also identify which claims require confirmation from regulators, banks, institutions or independently appointed escrow providers rather than from the counterparty’s own materials.
The Six-Lock Rule
The cases leave boards with one memorable test. Before the next consequential action, close six locks:
- 1.Identity: Is this the exact person and legal entity claimed?
- 2.Authority: Can that person commit the institution or act under a confirmed mandate?
- 3.Permission: Does the firm and individual hold the regulatory permissions required for the role?
- 4.Funds: Has funding capacity been authenticated independently of supplied statements?
- 5.Exposure: Is the next fee, disclosure, exclusivity term or control right proportionate and approved?
- 6.Payment: Have the receiving account and instructions been confirmed through a separate, previously trusted channel?
If one lock remains open, the next step waits.
That is the lesson of Lekoil, the fabricated ADIA forms, the nonexistent $400 million account, the borrowed Australian licences and the synthetic executives in Hong Kong. The decisive question is not whether the investor looks real.
It is whether the company can prove, independently, that this person has permission to ask for this action now.
- OPL 310 Appraisal Funding Secured · Lekoil RNS · 13 January 2020
- Clone firms and individuals · Financial Conduct Authority · 14 May 2025
- False DFSA and Abu Dhabi Investment Authority documents used to promote advance-fee scam · Dubai Financial Services Authority · November 2012
- Federal affidavit concerning Mindful Investments, Global Acquisition Ventures and Reinhart Holdings · United States Department of Justice · 2019
- ASIC warns consumers about Mike Morgan Loans · Australian Securities and Investments Commission · August 2013
- ASIC investigations into cloned lender websites and advance-fee loan scams · Australian Securities and Investments Commission · 10 March 2014 and 4 November 2015
- Engineering group Arup lost HK$200m in deepfake video conference scam · The Guardian · 17 May 2024
- 2025 IC3 Annual Report · Federal Bureau of Investigation Internet Crime Complaint Center · 2026
- Broker-dealers and capital raising · US Securities and Exchange Commission · 24 April 2026
- Clone firms and individuals | FCA
- Investegate | Company Announcement
- False DFSA and Abu Dhabi Investment Authority (ADIA) Documents used to Promote an Advance Fee Scam | DFSA
- https://www.justice.gov/usao-nj/press-release/file/1190026/dl
- 13-238MR ASIC warns consumers about Mike Morgan Loans | ASIC
- UK engineering firm Arup falls victim to £20m deepfake scam | Engineering | The Guardian
- Deepfake-Eval-2024: A Multi-Modal In-the-Wild Benchmark of Deepfakes Circulated in 2024
- https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- SEC.gov | Broker-Dealers
- Business Email Compromise — FBI
Raising capital? Open a capital file and let the advisory team assess your position.
Apply for Capital