Skip to main content

Fraud: 慷慨嘅捐款 | Fake Schaeffler FAG Foundation Donation of €4,500,000

· 26 min read
Jagdish Kumawat
Jagdish Kumawat
Founder @ Dewiride

You have been randomly selected to receive a €4,500,000 donation. A Cantonese-language donation fraud signed in the name of a real German research foundation, sent from a Rio de Janeiro fire brigade's government mailbox, and routing replies to a misspelled Gmail address.

Complete Email

from: Fag gbm23@cbmerj.rj.gov.br
date: 09/13/2026 4:52 AM
subject: 慷慨嘅捐款

Email Body

贏家

You have been randomly selected to receive a €4,500,000 donation.
你已經被隨機揀選嚟獲得450萬歐元嘅捐款。如果想知更多詳情,請聯絡下面嘅電郵地址。

電郵:schafflercorp@gmail.com

謝弗勒 FAG 基金會

English Translation

The subject line and all but one sentence of the body are written in Cantonese — colloquial, spoken-register Cantonese set down in Traditional Chinese characters, the form used in Hong Kong and Macau. Only the first sentence of the body is in English. Translated in full, the message reads:

Subject: Generous donation

Winner

You have been randomly selected to receive a €4,500,000 donation.
You have already been randomly selected to receive a donation of 4.5 million euros. If you want to know more details, please contact the email address below.

Email: schafflercorp@gmail.com

Schaeffler FAG Foundation

The choice of colloquial Cantonese, rather than the Standard Written Chinese any institution would use, is itself evidence and is taken apart in Red Flag 3.

Attacking email screenshot


Red Flags

This is a donation scam — advance-fee fraud in the costume of philanthropy. The skeleton is the one this archive has documented several times: a large sum, a benefactor you have never heard from, no reason given for your selection, and a request that you get in touch. Nothing is asked for in the first message because nothing needs to be; the fees come later, once a reply has identified you as someone who answers.

Two things make this specimen worth its own post. The first is that the foundation it names is real — a small, specialised German research foundation that almost nobody outside the bearing industry has heard of — and everything it actually does contradicts the email that borrows its name. The second is the sheer number of identities crammed into six short lines: a display name, a sending domain, a signature, and a reply address that describe four different organisations in four different countries, none of which agree with each other, and none of which agree with the language the message is written in.

1. The Schaeffler FAG Foundation Is Real — and It Does Nothing Like This

  • 謝弗勒 FAG 基金會Schaeffler FAG Foundation

Unlike the "Scott Foundation" in the MacKenzie Scott donation fraud, this foundation exists. The Schaeffler FAG Stiftung is an incorporated public foundation based in Schweinfurt, Germany, established in 1983 and today run under the Schaeffler Group — the industrial company that owns the FAG bearing brand. It is a small, respectable, entirely genuine body, and its actual work is the strongest evidence against this email.

Its charter purpose is the promotion of science, research and teaching in engineering connected to bearing technology. In practice that means a Future Technology Award for university research projects — the 2024 award was worth €90,000 — an Innovation Award for doctoral and master's theses, in which six winners recently shared a total of €18,000, and support for STEM projects in schools around Schweinfurt. The recipients are universities, faculties, and students who submitted work for consideration. The money goes to research and education, in one region of Germany, through a published process with published winners.

Set that against this message. The foundation's largest award is €90,000. This email offers fifty times that to one unidentified person, selected at random, for nothing. A foundation of this kind is bound to its charter purpose and supervised on exactly that point; it cannot pick a stranger out of a mailing list and hand over a sum equal to decades of its real grant-making, and no supervisory authority would let it. The attacker has borrowed the name for what it carries — German, industrial, foundation, money — and knows nothing about the institution behind it.

The choice of an obscure foundation is telling in its own right. MacKenzie Scott is impersonated because everyone has heard of her. The Schaeffler FAG Stiftung was not chosen for recognition. It was chosen because a search for the name returns a real foundation with a real award programme, and a reader who checks that far and stops will come away reassured. The trick depends on the reader confirming that the name exists and never reading what it does.

2. A "Winner" of a Donation, Chosen at Random

  • 贏家Winner — the entire salutation
  • You have been randomly selected to receive a €4,500,000 donation.

The message opens with a single word, Winner, where a greeting should be, and its first sentence says the recipient was selected at random. Between them, those two claims describe a lottery. But the message calls the money a donation (捐款), and it signs off as a foundation.

Those are two different things and neither matches the other. Lotteries have winners and draws, and nobody wins one they did not enter. Foundations have grants and applications, and no foundation anywhere distributes its endowment by random draw to people who never applied — least of all one whose purpose is funding bearing-technology research. The email has taken the vocabulary of a prize scam (winner, randomly selected) and pasted the vocabulary of a donation scam (donation, foundation) over it, and the join is visible in the first two lines.

There is also no name anywhere in the message — not the recipient's, not a signatory's, not a case officer's. "Winner" is how you address someone when you do not know who they are, and that is the sender's situation exactly: the mailbox this arrived at came off a scraped list, and the one fact the sender holds about its owner is the address. A foundation that had genuinely selected you for €4.5 million would, at minimum, know what to call you.

3. Written in Colloquial Cantonese — the Register of a Text Message, Not a Grant Letter

  • 慷慨嘅捐款
  • 你已經被隨機揀選嚟獲得450萬歐元嘅捐款。如果想知更多詳情,請聯絡下面嘅電郵地址。

The Chinese in this message is not Mandarin, and it is not the Standard Written Chinese used for formal correspondence everywhere in the Chinese-speaking world. It is written Cantonese — the spoken language of Hong Kong, Macau, and Guangdong transcribed into characters — and the markers are unmistakable to anyone who reads it:

  • (ge) as the possessive particle, where Standard Written Chinese uses 的. It appears three times, including in the subject line.
  • (lei), the Cantonese "to come", where standard usage would be 來.
  • 揀選 (gaan syun) for "select", built on 揀, the everyday Cantonese verb for choosing. A Mandarin writer would reach for 挑選 or 選擇.
  • 想知 (soeng zi) for "want to know", a Cantonese contraction that standard usage writes as 想知道.
  • 電郵 and 聯絡 for email and contact — the Hong Kong vocabulary, where the mainland-targeted MacKenzie Scott version used 联系.

That matters because of where written Cantonese is used. It is the language of chat messages, social media, tabloid headlines, and street advertising. It is not the language of a bank letter, a government notice, or a foundation informing you of a grant. A Hong Kong institution writing formally writes in 書面語, Standard Written Chinese; a German foundation writes in German or English. Nobody, anywhere, announces a €4.5 million grant in the register of a text message.

What produces this is a machine translator with "Cantonese" selected as the target language — an option that Google Translate, for one, only added in 2024. Run "You have been randomly selected to receive a €4.5 million donation. For more details, please contact the email address below" through such a tool and you get, near enough, the body of this email. The first sentence, left in English above the Cantonese, is the source text. The attacker's template is English; the Cantonese block is one of a set of translations, swapped in per target list.

That also explains the geography. This is a Cantonese message, built for a Hong Kong list, delivered to a company in India that does not read it. The sender's targeting extends exactly as far as choosing a language for a list, and the lists are not clean.

4. A German Foundation's Letter, Sent From a Brazilian Fire Station

  • from: Fag gbm23@cbmerj.rj.gov.br

Read the address from the right. .gov.br is the namespace of the Brazilian government. It is not something anyone can buy — it is reserved for public bodies — and rj.gov.br beneath it belongs to the State of Rio de Janeiro. cbmerj is the Corpo de Bombeiros Militar do Estado do Rio de Janeiro, the state's military fire brigade. And gbm23 is not a person: it is the 23º Grupamento de Bombeiros Militar, the brigade's 23rd operational group — a fire station in the city of Resende, in the south of the state. gbm23@cbmerj.rj.gov.br is the contact address the brigade publishes for that station on its own website.

So the letter from a German research foundation, written in Hong Kong Cantonese, was sent from the public mailbox of a fire station in Brazil. There is no arrangement under which that happens. The address was borrowed the way the German online shop's info@ mailbox and the car dealership in the UAE were borrowed in earlier posts in this archive: either the station's account has been taken over, or its address has simply been forged onto the envelope. The domain's public DNS shows a self-hosted mail server and a DMARC policy asking receivers to quarantine anything that fails its checks — which is consistent with where this message landed — but without the full headers the two cases cannot be told apart, and for the reader it does not matter. The address is not the sender's.

Why a fire brigade? Because a government domain is worth something to a spammer that a freshly registered .com is not. Filters extend credit to .gov addresses that have been sending legitimate mail for years; a message from one is more likely to reach an inbox, and one message that reaches an inbox is worth more than a hundred that do not. Published departmental contact addresses are scraped constantly, are shared between many people, and are rarely watched for outbound traffic. The fire station in Resende is a victim of this message too, and almost certainly does not know its address is signing letters as a German foundation.

5. The Display Name Is "Fag" — an Acronym Written as a Word

  • from: Fag

Look at the display name on its own. Not Schaeffler FAG Foundation, not Schaeffler FAG Stiftung, not the name of any person. Three letters — Fag — with only the first capitalised.

FAG is an acronym. It stands for Fischers Aktien-Gesellschaft, the Schweinfurt bearing maker that grew out of Friedrich Fischer's 1883 invention of the ball-grinding machine, and whose bearings still carry the name under Schaeffler ownership. The brand has been written in capitals for over a century, on every bearing, catalogue, and press release the company has issued, and the foundation uses the same capitals in its own name. Nobody who works for either would write it Fag, because to them it is not a word.

To whoever set up this mailing it was a word — typed in lowercase into a sender field and auto-capitalised by the tool, or lifted from the signature and retyped without knowing what it stood for. Written that way it is no longer a brand at all — in English it is an offensive word — which is precisely the kind of thing a corporate communications team exists to prevent. The display name is the first thing a recipient sees, and it is the first thing in this message that a real Schaeffler employee would never have sent.

6. The Reply Address Misspells the Company, Calls It a "Corp", and Lives on Gmail

  • 電郵:schafflercorp@gmail.com

The one precise, actionable thing in the message is the address you are told to write to, and it is wrong in three separate ways.

It is misspelled. The company is SchaefflerS-c-h-a-e-f-f-l-e-r, the ae standing in for the ä of the family name Schäffler. The address drops the e: schaffler. The Chinese signature gets the name right — 謝弗勒 is the standard transliteration of Schaeffler — but in the one place where the Latin spelling actually has to be correct, it is not. A foundation cannot misspell the name of the industrial group that runs it.

It is a "corp". Schaeffler is a German Aktiengesellschaft — Schaeffler AG — and nothing about it is a corporation in the American sense. And a foundation is not a corp in any sense. The signature says 基金會, the address says corp, and even the attacker has not decided which of the two is writing to you.

It is on Gmail. The Schaeffler Group has owned schaeffler.com for decades. A foundation administering a €4.5 million gift does not conduct that correspondence from a free webmail account that anyone on earth can open in ninety seconds without showing identification. It writes from the domain it owns, or it does not exist.

Now count the identities in this short message: a display name (Fag), a sending domain (a fire brigade in Brazil), a signature (Schaeffler FAG Foundation), and a reply address (schafflercorp, a corporation, on Gmail). Four names, and no two of them describe the same organisation. There is a reason the reply address is the odd one out: it is the only one the attacker controls. The .gov.br mailbox can be shut off the moment the fire brigade notices, and a reply sent to it might never be read. Directing responses to a Gmail account moves the conversation onto ground the attacker keeps — which is the entire job of the first email.

7. €4,500,000, With Nothing Attached to It

  • €4,500,000 / 450萬歐元

Strip out the number and see what remains to check: no recipient name, no reference or file number, no application, no deadline, no conditions, no signatory, no postal address, no phone number, no website. The amount is the only fact in the message, and it is unverifiable by construction.

Notice which currency the story runs in. A Brazilian mailbox, a Hong Kong dialect, a German foundation, an Indian recipient — and the money is in euros, a fifth jurisdiction, and the only one connected to the foundation. The amount is in euros because the story is German. Everything else about the message contradicts the story.

The figure is also a familiar one. The 4,800,000.00 Euro "Maria" donation arrived in July; the Sigrid Trust Rim Foundation's €2,000,000 and Mr Cheng Saephan's five million dollars came in 2024. The numbers in this genre cluster in the low millions for a reason: large enough to reorganise the reader's plans, small enough that a foundation might plausibly have it. Here the second half of that fails, because this foundation's programme is public. Its largest award is €90,000, and its entire real grant-making would take decades to reach the sum promised to one anonymous "winner".

8. Sent at 1:22 AM on a Sunday in Schweinfurt, and Junked on Arrival

  • date: 09/13/2026 4:52 AM — a Sunday, Indian time

Work the timestamp back. 4:52 AM on Sunday in India is 8:22 PM on Saturday in Rio de Janeiro, where the mailbox lives, and 1:22 AM on Sunday in Germany, where the foundation is. Nobody at the Schaeffler FAG Stiftung was notifying grant recipients at twenty past one on a Sunday morning, and a fire station in Resende was not corresponding with foundations on a Saturday night. The one time zone in which the hour looks like a working morning is Hong Kong's — 7:22 AM — which fits a campaign aimed at a Cantonese-speaking list and says nothing about who sent it.

The mail client, meanwhile, had already decided. Above the body: "This message appears to be Junk. Links and other functionality will not work.", with a retention notice giving the message a deletion date. Below it, the gateway's External Email tag. Those controls worked, and they are not the point: the next copy of this template will arrive through a mailbox with a cleaner history, and the reader who recognises the shape of the message will not need the banner.


How This Scam Works

The first email is bait and nothing else. It carries no link, no attachment, and no request for money or information — which is why it reads as clumsy rather than dangerous, and why gateways that hunt for URLs let it through. Its single objective is a reply to the Gmail address, because a reply turns an entry on a scraped list into a human being who has demonstrated interest, and everything that costs money happens after that, one message at a time.

  1. The List: Addresses are harvested in bulk from company websites, WHOIS records, directories, and old breach dumps. No targeting is applied: the same message goes to a Hong Kong list, and to whatever Indian, Brazilian, or European addresses have been swept into it.
  2. The Template: An English script — Winner. You have been randomly selected to receive a donation. Contact the email below. — is run through a machine translator once per target language and pasted under the English opening line. The amount, the reply address, and the foundation's name are the parts that change between campaigns.
  3. The Borrowed Mailbox: A published government contact address — here, a fire station's — is taken over through a reused or breached password, or simply spoofed. Its .gov.br domain carries years of legitimate sending history, so the message reaches inboxes a scam domain never would.
  4. The Blast: The message goes out to enormous numbers of recipients on a Saturday night. The overwhelming majority junk it or never see it, and that is expected. A response rate far below one percent is enough.
  5. The Reply: Somebody writes to schafflercorp@gmail.com. From this point the campaign becomes a conversation, on an account the attacker controls and the fire brigade cannot switch off, and the attacker will invest real hours in it.
  6. The Paperwork: Trust is manufactured on paper. An award letter and donation certificate carrying the Schaeffler logo — lifted from the group's real website — a beneficiary reference number, and a scanned ID for the "foundation officer". The genuine foundation's existence is the fraud's best asset here: a sceptical victim who searches the name finds a real body with real awards and stops looking.
  7. The Third Party: A "disbursing bank", a "foundation attorney", or a "diplomatic courier" joins the thread from a separate address. The victim is now dealing with an apparatus rather than a stranger, and the pressure can come from process instead of from the generous benefactor.
  8. The First Fee: An obstacle appears, always trivial against the prize. A transfer charge, a tax clearance, an anti-money-laundering certificate, a notarisation, a courier fee for the cheque. A few hundred euros against a promised 4.5 million is obviously worth paying. This is the entire point of the exercise.
  9. The Escalation: Each fee clears the last obstacle and reveals a new one. The amounts grow as the victim's sunk cost grows, and every payment makes withdrawal harder — stopping now would mean the earlier payments were wasted.
  10. The Data Harvest: Alongside the money, the attacker collects identity documents, bank details, and signatures "for the transfer file". These have resale value of their own and enable fraud in the victim's name long after this thread has died.
  11. The End: There is no €4,500,000 and there never was. Contact stops, or a final, catastrophic fee is demanded and the thread goes silent. The address is then traded on as a known payer — which is why the next message will offer, for a fee, to recover the money.

Conclusion and Recommendations

There is a Schaeffler FAG Foundation, and it has nothing to do with this. It funds bearing-technology research and school science projects in one corner of Germany, through published awards worth tens of thousands of euros, to universities and students who applied. It does not select strangers at random, does not write in colloquial Cantonese, does not send mail from a fire station in Brazil, and does not take replies at a misspelled Gmail address that calls it a corporation.

The instructive part of this specimen is that a real name was not enough to make a real offer. Every earlier donation fraud in this archive invented its institution; this one borrowed a genuine one and was, if anything, easier to expose, because the foundation's actual programme is public and contradicts every line of the email. The lesson generalises: when a message names a real organisation, the question is never does it exist but does it do this — and a minute reading what the real body funds, and how, answers it.

The mail client junked the message, disabled its links, and tagged it as external before anyone read a word. Those controls did their job. They are not the reason to relax, because the next copy will come from a mailbox with a cleaner reputation. The durable defence is the one that does not depend on a filter: when a message offers you money you did not earn, from an organisation you never approached, the story is the attack — and the story is the part you can check.

Immediate Actions:

  • Do Not Reply, Not Even to Decline: A reply is the only thing this email wants. Any response to schafflercorp@gmail.com — a refusal, a question, a request to be removed — confirms a live, human-attended mailbox and moves your address onto the lists that receive hand-written attacks.
  • Do Not Write to the Fire Brigade Either: Replying to the .gov.br address will not reach the attacker and may not reach anyone. If you want to help, the brigade's own published contact channels are the place to report that its unit mailbox is being abused — not the reply button on a scam.
  • Never Pay a Fee to Receive Money: No genuine gift, grant, prize, or inheritance requires the recipient to pay first. Not a transfer charge, not a tax, not a compliance certificate, not a courier fee. The advance fee is the entire fraud, and every later stage exists only to reach it.
  • Do Not Send Identity or Banking Documents: A passport scan, an Aadhaar or ID card, a bank statement, or a company registration certificate has resale value on its own and enables fraud in your name long after this thread is dead.
  • Report and Delete: Use the mail client's phishing or junk report rather than plain deletion, so the campaign is scored and, on a corporate system, your security team sees it. The junk classification already applied here is a sign that reporting works.
  • Warn Whoever Else Reads the Shared Mailbox: Functional addresses are read by several people, and the one who opens the next copy may not be the one who would recognise it. A Cantonese message in an Indian inbox is easy to dismiss; a translated one is easier to be drawn into.
  • If Anyone Has Already Engaged, Stop and Escalate Now: Cease contact, do not send the "final" payment that will supposedly release the funds, preserve every message and receipt, and report to your national cybercrime authority — in India, the National Cyber Crime Reporting Portal at cybercrime.gov.in or the 1930 helpline. If money has moved, tell your bank immediately; the first hours are the only realistic window for a recall.

Verification Steps:

  • Search the Foundation, Then Read What It Actually Does: "Schaeffler FAG Stiftung" returns a real foundation in under five seconds. Keep reading. Its awards are worth €90,000 and €18,000, go to universities and thesis authors, and are announced publicly with named winners. Nothing in that programme can produce a random €4.5 million gift to a stranger. A real name confirms the name; only the process confirms the offer.
  • Read the Sending Domain From the Right: .gov.br is the Brazilian government, rj.gov.br the State of Rio de Janeiro, cbmerj its fire brigade, gbm23 one of its stations. Every segment is public and every one is checkable. A German foundation does not send from any of them.
  • Read the Reply Address Letter by Letter: schaffler is not Schaeffler. corp is not a foundation. gmail.com is not schaeffler.com. Three checks, each of which takes seconds, and each of which fails.
  • Count the Identities: The display name, the sending domain, the signature, and the reply address should all describe one organisation. Here they describe four, in four countries. When the parts of a message disagree about who sent it, none of them did.
  • Ask What You Applied For: You cannot win a draw you never entered or be selected from a pool you were never in. If you cannot name the application, the programme, or the relationship that would make you a beneficiary, there is nothing to verify — the question is already answered.
  • Notice the Register, Not Just the Language: Formal institutions write formally in every language. A grant notification in chat-register Cantonese is the equivalent of a bank writing to you in text-speak, and it is the signature of a machine translation rather than a person.
  • Work Out the Hour Where the Sender Claims to Be: 1:22 AM on a Sunday in Schweinfurt. Real institutions send during working hours in their own time zone; bulk campaigns send when the schedule fires.
  • Verify Through a Route You Already Had: If a real organisation is named, find its published contact details yourself — a website you navigated to directly, a switchboard number from a directory — and ask. Never use an address or number supplied by the message you are checking.

Additional Protection Tips

  • Recognise the Shape, Not the Story: The cover changes constantly — a philanthropist, a foundation, a lottery, an inheritance, a compensation fund. The skeleton never does: large sum, benefactor you never approached, you were selected, contact me for details. Learn the skeleton once and every future variant is recognisable in the first paragraph, whatever name has been borrowed this time.
  • Treat a Real Name as a Claim to Check, Not a Credential: Impersonating a genuine organisation costs an attacker nothing — the name, the logo, and the address are all on the public website. Existence proves nothing. What a real organisation does, and how it does it, is the only thing that can be compared against an email.
  • Understand That a Government Address Is Not a Government Sender: Public bodies publish hundreds of departmental mailboxes by design, and those mailboxes get scraped, spoofed, and taken over like any other. A .gov sender earns exactly as much trust as its message deserves on its own merits — which, here, was none.
  • Watch for the Reply That Goes Somewhere Else: A message sent from one domain that asks you to respond to a free webmail account is describing its own disposability. The sending address is borrowed and will be lost; the reply address is where the attacker actually lives.
  • Do Not Let a Foreign Language Lower Your Guard: A message you cannot read is not somebody else's problem. It is a bulk campaign hitting a dirty list, and running it through a translator to find out what it says is the first step into the conversation it wants to have. Recognise the shape from the number and the email address, and stop there.
  • Understand That the Absence of a Link Is Not Safety: This email contains nothing to click and nothing to open, which is why it survives filters tuned for URLs and attachments. The payload of an advance-fee approach is the conversation, and no gateway can scan for that. A clean message is not a safe one.
  • Lock Down Shared and Published Mailboxes: The fire station in the from: line is a victim who almost certainly does not know. Every organisation — companies and public bodies alike — should give each published departmental address a named owner, unique credentials, multi-factor authentication, and monitoring for unusual outbound volume or logins from unexpected countries.
  • Adopt a Two-Person Rule for Money Leaving the Business: Any payment to a new beneficiary, any change to bank details, and any fee attached to an unexpected windfall should require a second person's approval and a voice call to a number from your own records. Fraud of this kind depends on one person acting alone and slightly excited.
  • Say Out Loud What You Are About to Do: These schemes rely on isolation. Describing the situation to one uninvolved colleague, friend, or family member breaks the spell more reliably than any technical control, because the absurdity is obvious to everyone except the person inside the conversation.
  • Make It Safe to Own Up: Donation and advance-fee fraud is unusually humiliating for its victims, and shame is what turns a small loss into a large one — people keep paying rather than admit the earlier payments. A workplace where somebody can say I think I have been caught by this without consequence recovers money that a workplace built on blame never sees.

Remember: A real foundation's name is not a real foundation's offer. Genuine grant-makers publish who they fund, how, and for what — and none of it ever includes a stranger picked at random from a mailing list. When the name checks out and the process does not, it is the process that is telling the truth.


Share this post