Hashim Bin Hasan Investment Scam: Fake Project Deal Demands Fees Upfront

A stranger named Hashim Bin Hasan says he represents a wealthy investor looking for an experienced person to manage a major project. The message is vague, but it makes your business background sound like the missing piece in an extraordinary deal.

The Hashim Bin Hasan investment scam begins with that flattering invitation. The real terms appear only after you reply and the supposed capital starts collecting fees before it ever arrives.

Reconstructed Hashim Bin Hasan investment scam email offering a project deal

Overview

The email offers an undefined international investment

The sender introduces “Hashim Bin Hasan” as an intermediary for a private investor. Recipients are asked whether they own or represent a company and whether they can manage a substantial investment as a project manager.

There is usually no verifiable fund, mandate, company registration, investment thesis, or reason the investor selected that particular recipient. Ambiguity is intentional because it encourages a reply without giving the target much to verify.

The name supports a fictional identity, not a proven investor

The criminal may add a passport scan, business card, bank letter, attorney introduction, or profile photograph as the discussion develops. These materials can be fabricated, altered, stolen, or attached to an innocent person’s name.

A face-to-face meeting may be mentioned to make the approach feel serious, but it rarely happens. Travel problems, compliance holds, representatives, and changing locations keep the relationship online.

The deal becomes an advance-fee and identity-theft scheme

After the recipient shows interest, the supposed investment is approved unusually quickly. Then a fee appears for legal documentation, tax clearance, anti-money-laundering certification, insurance, courier delivery, or international transfer authorization.

The operation may seek both payment and information, including:

  • Passport and driver’s license images
  • Company incorporation documents
  • Bank account and routing details
  • Signatures and company letterhead
  • Financial statements and tax records
  • Names of business partners and employees
  • Access to online banking or a cryptocurrency account

The promised investment does not exist. Any payment is a loss, while the collected documents can be reused in new frauds that make the victim appear to endorse the fictional project.

What the Initial Hashim Bin Hasan Message Is Trying to Do

The first email is deliberately restrained. It may not contain a link, attachment, dramatic sum, or immediate fee. That quiet approach helps it pass spam filters and feels less like the familiar inheritance messages many people already distrust.

Its immediate goal is simply to identify who will answer. A reply confirms that the address is active and that the recipient is willing to discuss private finance with an unknown intermediary.

The invitation uses professional language about experience, capabilities, networks, and project management. Those terms flatter entrepreneurs and consultants while allowing the sender to adapt the eventual story to almost any industry.

The request for “relevant connections” also provides intelligence. A victim may volunteer the names of banks, lawyers, regulators, suppliers, or influential contacts that the scammer can later impersonate.

Once the conversation becomes personal, the sender may claim that discretion is essential. Secrecy isolates the victim from colleagues who could question the deal or notice that the supposed investor has no independent history.

Professional restraint at the beginning should not be mistaken for legitimacy. A real investment approach can identify the firm, representative, investment parameters, jurisdiction, and lawful diligence process without asking a stranger to trust an anonymous mailbox.

Reconstructed Hashim Bin Hasan scam investment transfer page demanding clearance fees

How the Hashim Bin Hasan Investment Scam Works

Step 1: A broad email reaches business owners and professionals

The campaign targets addresses published on company websites, professional directories, social media pages, and industry databases. Messages may begin with “Dear Info” because the sender collected a general contact address rather than researching a specific person.

The email asks whether the recipient owns or represents a company. That question lets the scammer qualify targets without paying for detailed research.

Step 2: The recipient is invited into a confidential opportunity

Hashim supposedly represents an investor who needs a local project manager, business partner, or channel for deploying capital. The amount may remain unstated until the victim expresses interest.

Confidentiality is framed as a normal feature of private finance. In reality, it prevents the recipient from forwarding the proposal to an accountant, lawyer, regulator, or experienced investor.

Step 3: The scammer collects a business profile

The victim is asked for a résumé, project plan, company records, bank relationship, and proof of identity. Every detail helps the criminal tailor the story and assess how much money the target might pay.

Information can also be used to prepare realistic contracts or to approach someone else while pretending to represent the victim’s company.

Step 4: A fictional investor and professional team appear

New participants may enter as a bank officer, international lawyer, compliance consultant, diplomat, or courier. Separate email accounts make the deal look as though several organizations are independently confirming it.

They are not independent. Fraud groups routinely operate multiple identities, and one person can answer through several mailboxes with different signatures.

Step 5: Forged documents make the capital look real

The target receives a memorandum, bank statement, transfer advice, investment certificate, or government authorization. Logos, stamps, reference numbers, and signatures create a dense paper trail.

Documents should be verified with the institution through contact details found independently. Calling the number printed on a forged bank letter only returns the victim to the same operation.

Step 6: The first fee is described as procedural

A relatively small payment is required for a compliance certificate, lawyer’s retainer, due-diligence report, tax stamp, or transfer code. The scammer says the investor cannot pay it because the beneficiary must be the party on record.

That explanation has no economic sense. An investor offering millions can pay legitimate professional expenses through counsel and deduct agreed costs transparently at closing.

Step 7: Each payment creates another obstacle

After the first fee is sent, the transfer supposedly triggers insurance, customs, currency, or anti-terror financing requirements. A fake banking portal may display the investment as “pending” to keep the victim hopeful.

The criminal exploits sunk cost. Someone who already paid $2,000 may risk another $800 because refusing would force them to accept that the first payment is gone.

Step 8: The identities vanish or return as recovery agents

When the target stops paying, the investor, lawyer, and transfer officer disappear together. Telephone numbers stop working, websites go offline, and mailboxes begin rejecting messages.

Weeks later, someone may claim to have discovered the fraud and offer recovery for another fee. The new helper already knows the case because the same group retained the victim’s documents and payment history.

Why Successful Professionals Still Answer This Email

The pitch is not aimed only at people who believe in effortless wealth. It is designed for owners and consultants who regularly receive introductions and understand that private deals can begin through networks.

The scammer mirrors that environment while removing the parts that protect real participants: regulated intermediaries, verified beneficial owners, conflict checks, independent counsel, signed engagement terms, and accountable banking channels.

Flattery makes the opportunity feel earned rather than random. The message says the recipient’s expertise and connections are valuable, which is more believable than announcing that they simply won money.

The criminals also let victims build parts of the story themselves. When asked what projects they can manage, recipients reveal an industry and funding need. The next letter then describes an investor interested in exactly that field.

A long conversation can feel like due diligence, even when all verification happens inside documents supplied by the sender. Time invested is not evidence. It can be another tool for creating commitment.

The safest response is procedural. No private opportunity is too important to survive independent identity checks, lawyer-to-lawyer contact, and confirmation with a regulated financial institution.

Company, Address, and Fulfillment Checks

Identify the legal investment entity

Ask for the exact registered name, company number, jurisdiction, physical office, directors, regulator, and audited history of the entity providing the capital. Search official registries rather than directories linked in the email.

A name without a legal entity is not an investor. A certificate image should match a live government record and the people actually communicating with you.

Verify every professional independently

Find the bank, law firm, and adviser through their official websites or regulatory listings. Contact them through numbers you locate yourself and ask whether the named individual, document, and transaction are genuine.

Do not accept a conference call arranged by Hashim as independent confirmation. Everyone on that call may be part of the same script.

Inspect domains and addresses as a connected record

Compare the email domain, reply address, website, registered office, and payment beneficiary. Recently registered domains, free mailboxes, virtual offices, and unrelated recipient accounts are strong contradictions.

One real address in a footer proves nothing. Fraudsters copy the public address of banks, ministries, and international organizations every day.

Require lawful closing and cleared funds

Use your own qualified lawyer and bank. Do not pay an intermediary selected by the sender, and do not sign documents that misstate ownership, beneficial interest, or the purpose of a transfer.

An investment is fulfilled only when your independent bank confirms cleared funds under a lawful agreement. A screenshot or balance inside the sender’s portal is not capital.

Ask who ultimately owns the investing entity, where its capital came from, and which regulated institution holds it. Those are ordinary diligence questions, not insults. A legitimate counterparty can provide answers that your own professionals verify.

A fraudster may respond with anger, a deadline, or another impressive PDF because the operation cannot survive contact with records it does not control. Pressure is not a substitute for verifiable capital.

Never agree to receive funds and forward a portion elsewhere. Even if a transfer initially appears in your account, moving it can make you part of a money-laundering chain or expose you to a later reversal. Stop and let your bank examine any unexpected incoming payment.

What to Do if You Have Fallen Victim to This Scam

  1. End communication and refuse every new fee. Taxes, certificates, recovery charges, and account-unlocking payments are further parts of the same advance-fee sequence.
  2. Contact the financial provider immediately. Tell the bank, wire service, card issuer, payment app, or crypto exchange that the transfer was induced by fraud and ask whether it can be stopped.
  3. Preserve the full record. Save original emails with headers, attachments, contracts, domains, account numbers, wallet addresses, receipts, chats, and telephone numbers.
  4. Secure your email. Change the password, sign out unknown sessions, remove forwarding rules, review recovery details, and enable multifactor authentication.
  5. Notify your company and bank. Explain which letterhead, account data, signatures, employee names, and business documents were disclosed so they can monitor impersonation attempts.
  6. Protect your personal identity. Freeze credit and create a recovery plan at IdentityTheft.gov if passports, licenses, SSNs, or personal banking records were shared.
  7. Report the fraud. Submit the evidence at ReportFraud.ftc.gov and contact the relevant national fraud or cybercrime agency in your country.
  8. Warn named professionals. If a real bank, law firm, or public official was impersonated, send its security team the fraudulent documents and contact addresses.
  9. Scan devices that handled files. Opened attachments and remote meeting tools can create malware risk. Run a full Malwarebytes scan and remove unapproved remote-access software.
  10. Block known scam pages. AdGuard may prevent later visits to reported phishing and tracking domains used by the operation.
  11. Tell affected contacts. If your mailbox or company identity may be compromised, warn partners not to trust changed bank details or urgent investment messages sent in your name.
  12. Ignore private recovery promises. Work with banks, law enforcement, insurers, and lawyers you choose. Do not pay an unsolicited investigator who guarantees success.

Frequently Asked Questions

Is Hashim Bin Hasan a real investment manager?

The unsolicited message provides no independently verified mandate or investment entity. Treat the identity and proposal as fraudulent unless every participant can be confirmed through official records and separate channels.

Why does the first email ask only for a reply?

A low-pressure opening identifies responsive targets and avoids revealing the fee too early. The detailed investment story is adapted after the recipient volunteers information.

Can a private investor legitimately request confidentiality?

Confidentiality can exist in real deals, but it does not prevent independent legal, regulatory, banking, and identity checks. Secrecy used to isolate you from advice is a warning.

What if the sender provides a passport and bank letter?

Images can be stolen or forged. Verify the institution and person through contact information you obtain independently, not the telephone numbers printed on those documents.

Should I pay a transfer or compliance fee?

No. Do not pay a stranger to release promised investment capital. Legitimate transaction costs belong in a transparent agreement handled by verified lawyers and financial institutions.

Can a pending balance in an online portal be real?

A portal controlled by the sender can display any number. Only your own bank’s confirmation of cleared funds under a lawful agreement demonstrates fulfillment.

The Bottom Line

The Hashim Bin Hasan investment scam does not begin with a crude demand. It begins with professional flattery, a vague private investor, and a request to discuss what you could do with substantial capital.

Once you engage, forged professionals and documents turn the opportunity into a chain of fees. Verify the legal entity, use your own advisers, and never pay money or surrender identity documents to unlock an investment that arrived through an unsolicited email.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

United Safety Standard Scam: Fake $995 Glove Invoices Target Businesses

Next

David Steiner USPS Scam Email: Fake $5.4M Parcel Demands Delivery Fees