Skip to main content

Fraud: Re: Investment Funds. | Fake Olena Zelenska Investment Partnership

ยท 26 min read
Jagdish Kumawat
Jagdish Kumawat
Founder @ Dewiride

Please I'm consulting you for my personal investment plan. An advance-fee approach signed in the name of Ukraine's First Lady, sent from a car dealership's mailbox at a UAE internet provider, asking you to reply to a Gmail address.

Complete Emailโ€‹

from: FIRST CHOICE MOTORS fcm@emirates.net.ae
date: 08/30/2026 4:19 AM
mailed-by: emirates.net.ae
signed-by: emirates.net.ae
subject: Re: Investment Funds.

Email Bodyโ€‹

--

Dear Friend,

Please I'm consulting you for my personal investment plan which I would like to discuss with you and know the possibility of how we can co-operate and work together to carry it out as business partners; which I believe will be beneficial to both parties if handled with honesty.

If you have an idea of any business in your country where we can invest the sum of USD$18 Million, kindly reply to me urgently and we will discuss on how to achieve this effectively.

However, due to the crises in my country, I find it necessary to diversify my investments outside my country to safeguard against the future of my family. For your kind assistance, I'm willing to offer you 25% of the total amount for your assistance, Please your religion does not matter to me, what matters most is using the fund with the fear of Almighty God.

I will be waiting for your reply for more details at olenazelenska68@gmail.com

Please contact me only on this email olenazelenska68@gmail.com

Best regards

Mrs. Olena Zelenska

Attacking email screenshot


Red Flagsโ€‹

This is advance-fee fraud in its oldest and most recognisable dress: the wealthy foreigner with money trapped by circumstance, looking for an honest stranger to help move it, and offering a life-changing percentage for the favour. The genre is usually called 419 fraud, and it has been arriving in inboxes for forty years in essentially this form. What changes is the cover story, and the cover story is always whatever is in the news.

Its opening move is not to ask you for anything. Read it again and notice how little the email actually wants: no link, no attachment, no document, no bank details, no password. It wants a reply. Everything expensive happens after that, in a conversation that has not started yet, and the entire purpose of these nine paragraphs is to make starting it feel like curiosity rather than commitment.

What makes this particular specimen worth taking apart is that it carries four different identities and no two of them agree. The display name sells cars. The domain belongs to a Gulf telecom company. The signature belongs to a real, living, extremely public head of state's spouse. The reply address is a free Gmail account with a number bolted onto the end. Every one of those is visible in the screenshot above, before a single word of the body is read.

1. The Signature Belongs to the First Lady of Ukraineโ€‹

  • sign-off: Mrs. Olena Zelenska

Olena Zelenska is the First Lady of Ukraine โ€” the wife of President Volodymyr Zelenskyy. She is one of the most documented public figures in Europe: she gives interviews, addresses parliaments and the United Nations, and runs a named charitable foundation with published accounts, a press office, and a public communications team.

That is the whole analysis, and it needs no technical skill whatsoever. Heads of state and their families do not cold-email strangers about money. They have foreign ministries, ambassadors, sovereign wealth managers, international law firms, and private banks whose entire business is placing capital discreetly. A person in that position who genuinely wished to invest USD 18 million abroad would have it done by professionals, under contract, in a jurisdiction of their choosing, without ever writing an email that begins Dear Friend.

The impersonation is also self-defeating in a way worth naming. The premise requires the money to be hidden โ€” quietly moved out of the country, into a business belonging to a stranger, for a 25% cut. But Ukraine operates one of the more rigorous public asset-declaration regimes in the world for senior officials and their families, administered by its anti-corruption agency and published for anyone to read. The story asks you to believe in eighteen million undeclared dollars belonging to the single most scrutinised family in the country, being smuggled out through an unsolicited email to somebody they have never met.

This is not a subtle brand impersonation of the kind that needs a magnifying glass on a URL. It is a name anyone can search in five seconds, and searching it is the complete defence.

2. Four Identities in One Message, and No Two of Them Matchโ€‹

Lay the message's own metadata side by side:

ElementWhat it saysWhat it implies
Display nameFIRST CHOICE MOTORSA car dealership
Sending addressfcm@emirates.net.aeA UAE internet provider's mailbox
SignatureMrs. Olena ZelenskaThe First Lady of Ukraine
Contact addressolenazelenska68@gmail.comA free consumer webmail account

There is no story that reconciles those four rows. A motor trader in the United Arab Emirates is not the First Lady of Ukraine, does not send her correspondence, and would not route her replies to a Gmail account.

The fcm@ local part is the giveaway that the mailbox is genuinely a dealership's โ€” it is the company's initials, which is what a real business chooses and an impersonator would not invent. Nothing has been spoofed or forged here. Somebody is simply sending mail out of an account that belongs to a car dealer, and signing it with a borrowed name.

That mismatch is not carelessness so much as economy. The attacker needs a mailbox with a clean reputation that will pass filtering, and they need a name with emotional pull. Those two requirements have nothing to do with each other, so they are satisfied separately and never reconciled. Nobody proof-reads a message that is going to a hundred thousand strangers.

3. emirates.net.ae Passes Authentication, and That Proves Only Mailbox Controlโ€‹

  • mailed-by: emirates.net.ae
  • signed-by: emirates.net.ae

Gmail shows both lines, which means the message passed SPF and carried a valid DKIM signature aligned to the sending domain. In plain terms: this is authentic mail, genuinely sent from a genuine mailbox on a genuine domain. No forgery is involved.

emirates.net.ae is the long-established mail domain of Etisalat, the UAE's principal telecom operator โ€” the address your internet subscription came with. It is real infrastructure with two decades of accumulated sending reputation, which is precisely why it is valuable to an attacker and precisely why this message reached an inbox rather than being scored away at the gateway.

The lesson generalises, and it is the single most misunderstood point in email security: SPF, DKIM, and DMARC authenticate the mailbox, not the human. They answer "was this sent by someone with permission to use this domain?" They cannot answer "is the person writing who they claim to be?" When a real account is compromised through a phished password, a reused credential, or an abandoned ISP mailbox nobody closed, all three checks pass perfectly while the message is a complete fabrication.

The most likely history of this account is dull and common. An old dealership mailbox, a password reused somewhere that was later breached, no multi-factor authentication, nobody watching it. It is now sending 419 mail on somebody else's behalf, and the dealership almost certainly has no idea.

4. "Please contact me only on this email" โ€” the Line That Does the Real Workโ€‹

  • I will be waiting for your reply for more details at olenazelenska68@gmail.com
  • Please contact me only on this email olenazelenska68@gmail.com

The Gmail address appears twice in three lines, the second time with an explicit instruction not to use anything else. In a message that is otherwise vague about every fact it contains, this is the one point of absolute precision โ€” which tells you it is the part that matters operationally.

It is a channel shift, and there are three reasons for it, all of them the attacker's:

  • The sending mailbox is borrowed and temporary. Whoever controls fcm@emirates.net.ae controls it only until the real owner notices, changes the password, or the provider suspends it. The Gmail account belongs to the attacker outright and survives the takedown.
  • It breaks the trail. Replies never touch the dealership's mailbox. If that account is later investigated by its owner or its provider, there is no conversation to find โ€” only outbound spam and no thread showing who answered.
  • It costs nothing and scales. A free webmail account takes two minutes to create, needs no verification worth the name, and can be abandoned the moment it is reported.

Now read the address itself: olenazelenska68@gmail.com. The First Lady of Ukraine has a foundation, an office, and a state apparatus behind her. She does not correspond from consumer webmail, and she certainly does not correspond from consumer webmail with 68 appended โ€” a suffix that exists for one reason only, which is that the versions without it were already taken. The number is the attacker's registration attempt showing through, and it is a small, perfect contradiction of the identity the signature claims.

5. "Dear Friend," on a "Re:" That Replies to Nothingโ€‹

  • subject: Re: Investment Funds.
  • salutation: Dear Friend,

These two are worth reading together, because they contradict each other inside a single screen.

Re: is a reply prefix. It asserts that you wrote first and this is the answer. Search your sent folder and there is nothing โ€” no earlier message, no quoted history, no On [date], you wrote: block beneath the signature. The prefix is bolted on for two reasons: it makes a busy reader assume a thread they have simply lost track of, and reply-prefixed subjects are statistically less likely to be scored as unsolicited by filters, because most genuine ones are replies.

But a reply implies a correspondent, and the salutation immediately gives the game away. "Dear Friend" is what you write when you do not know the recipient's name, company, country, or industry โ€” because the only thing the sender holds is an email address scraped from a list.

Count the facts about you anywhere in this message: there are none. No name, no organisation, no reason you were contacted, no mention of how they found you, no reference to whatever it is you actually do. A genuine investor approaching a genuine business knows, at minimum, what that business is. This one is writing to an address, exactly as the 4,800,000 Euro donation in our archive was addressed to an email account rather than a person.

6. The Investor Has No Investmentโ€‹

  • If you have an idea of any business in your country where we can invest the sum of USD$18 Million

Stop on that sentence, because it inverts how capital actually moves. The person with the money is asking the stranger to supply the idea.

Real investment arrives with a thesis. A fund or a family office that approaches you knows its sector, its stage, its ticket size, its holding period, and its return expectation, and it has usually looked at your accounts before it ever makes contact. The conversation opens with we invest in X, we have looked at your Y, here is what we propose. It does not open with do you know of anything, anywhere, in whatever country you happen to live in.

Notice how completely unconstrained the ask is. Not a sector. Not an industry. Not a stage or a structure. "Any business in your country" โ€” a phrase that works identically whether it lands in Mumbai, Manila, Lagos, or Leeds, which is exactly why it was written that way. The message has to function unmodified for every address on the list.

This is also why there is no plan, no prospectus, no company name, and no advisor. Supplying any of those would create something checkable, and nothing in this email is checkable by design. The only concrete details it contains are a number, a percentage, and a Gmail address.

7. 25% of USD$18 Million for an Idea You Have Not Had Yetโ€‹

  • I'm willing to offer you 25% of the total amount for your assistance

Twenty-five percent of eighteen million dollars is USD 4.5 million โ€” offered, unprompted, to a stranger whose name the sender does not know, in exchange for unspecified "assistance" that has not yet been described.

Put that beside reality. A placement agent introducing capital to a deal earns somewhere around 1โ€“2%. An investment manager charges a management fee of about 2% and a performance share of perhaps 20% of the profit, not of the principal. Nobody, anywhere, hands over a quarter of the capital itself for an introduction.

The disproportion is not an oversight; it is the mechanism. The figure has to be large enough to overpower the reader's scepticism and start them thinking about what they would do with it โ€” because a reader who is calculating their share has stopped auditing the story. It is the same lever that makes lottery scams work, and it is deployed here in the paragraph immediately before the sign-off, so it is the last thing in mind when the reader decides whether to answer.

The notation deserves a line of its own. USD$18 Million doubles the currency marker โ€” USD and $ both mean the same thing, and no financial document written by anybody who handles money would carry both. The conventions are USD 18,000,000, US$18m, or $18 million. This is what the phrasing of someone unfamiliar with the domain they are imitating looks like, and it sits in the one sentence where the sender is trying hardest to sound like a principal with capital.

8. "Due to the crises in my country" โ€” a Crisis With No Countryโ€‹

  • However, due to the crises in my country, I find it necessary to diversify my investments outside my country to safeguard against the future of my family.

The country is never named. It appears twice in a single sentence as "my country" and is never identified, and the "crises" are never described.

That omission is deliberate and it is doing something clever. The signature names a person whose national situation is instantly recognisable, so the reader supplies Ukraine themselves โ€” and an inference the reader draws is far more persuasive than an assertion the writer makes, because it feels like their own deduction rather than someone else's claim. It also keeps the message legally and operationally vague: nothing has been stated that can be checked and found false, because nothing has been stated at all.

Underneath the technique sits the oldest habit in this genre: using a real humanitarian catastrophe as bait. War, coup, earthquake, pandemic, sanctions, a frozen banking system โ€” the cover story is refreshed from the headlines while the mechanics never change. The same email has been sent in the name of Iraqi widows, Syrian refugees, Libyan officials, Zimbabwean farmers, and the relatives of every deposed leader of the last thirty years.

And the arithmetic of the story never closes. Where did eighteen million dollars come from? Why can it move to a stranger's business but not to a bank, a fund, or a lawyer? Why does safeguarding a family's future require the involvement of somebody found in a mailing list? The premise only survives while nobody asks the second question, which is precisely why the email asks you to reply urgently rather than to think.

9. The Religion Paragraph Is a Filter, Not a Confessionโ€‹

  • Please your religion does not matter to me, what matters most is using the fund with the fear of Almighty God.

Nobody discussing an eighteen-million-dollar placement opens by volunteering their views on the recipient's faith. The sentence is a non sequitur, wedged into the middle of the commercial paragraph, and it is one of the most durable pieces of boilerplate in the entire 419 canon โ€” it has appeared, near word for word, in these emails for decades.

It performs two jobs at once:

  • It manufactures moral common ground. By raising honesty and God before any money has been discussed, the sender pre-empts the suspicion the reader is about to feel and reframes the transaction as an act of shared conscience. Note how the first paragraph does the same thing โ€” "beneficial to both parties if handled with honesty" โ€” asserting integrity that nobody had questioned. Genuine business correspondence never needs to vouch for its own honesty, because nothing about it invites the doubt.
  • It selects. A reader who is moved by piety framing rather than alarmed by it is exactly the reader the attacker wants, and one who is put off has cost nothing to lose.

That second point explains the whole texture of this email, including its grammar. "Please I'm consulting you", "know the possibility of how we can co-operate", "we will discuss on how to achieve this", crises where crisis is meant โ€” a native speaker did not write this, and after decades of iteration the attackers have had every opportunity to hire one who could.

They do not, and there is a well-established argument for why. Microsoft Research's Cormac Herley made it in 2012 in a paper titled Why do Nigerian Scammers Say They are from Nigeria?, and the logic is uncomfortable but sound: the expensive part of this fraud is not sending the email, which is free, but the weeks of one-to-one conversation that follow a reply. Every person who engages and then backs out is pure loss. So an implausible, error-ridden, faintly absurd message is not a failure of craft โ€” it is a sieve. It filters out everybody who would eventually say no, and leaves only the small number of people who will still be there when the first fee is requested.

If this email strikes you as too clumsy to fool anyone, that reaction is the design working as intended. You were never the target.


How This Scam Worksโ€‹

The first email is bait and nothing else. It carries no link, no attachment, and no request for information, which is exactly why it does not read as an attack and why it survives filtering. Its only objective is a reply, because a reply converts an address on a list into a human being who has demonstrated interest โ€” and everything expensive happens after that, one message at a time.

  1. The List: Addresses are scraped in bulk from company websites, WHOIS records, directories, and old breach dumps. No targeting is applied, because none is needed. The message is written to work identically for every recipient.
  2. The Borrowed Mailbox: A real account at a real organisation โ€” here, a car dealership on a UAE internet provider's domain โ€” is taken over through a reused or phished password, or simply left unattended for years. Its mail authenticates cleanly and carries the domain's established reputation, so it lands in inboxes that a freshly registered domain never would.
  3. The Blast: The same text goes to enormous numbers of recipients at once. Because it is deliberately implausible, the overwhelming majority delete it, and that is an intended outcome rather than a cost.
  4. The Reply: Someone answers. This is the only thing the first email was ever for, and from this point the attacker is no longer running a campaign โ€” they are running a conversation, and they will invest real hours in it.
  5. The Move to Gmail: The thread shifts to the address the email insisted on, off the borrowed mailbox and onto infrastructure the attacker fully controls and can abandon at will.
  6. The Documents: Trust is manufactured on paper. Scanned bank statements, certificates of deposit, a passport or identity page, letters on foundation or ministry letterhead, sometimes a lawyer's engagement letter. All of it is fabricated, and all of it looks convincing on a phone screen, which is where most of it will be read.
  7. The Third Party: A bank officer, trustee, attorney, or "diplomatic courier" enters the thread from a separate address. The introduction of an apparently independent institution is a turning point, because from here the victim is no longer weighing one stranger's word but an apparatus โ€” and it gives the attacker a second voice to apply pressure the "principal" can seem too gracious to apply.
  8. The First Fee: An obstacle appears, and it is always small relative to the prize. A transfer charge, a compliance or anti-money-laundering certificate, a tax clearance, a notarisation, a courier fee, an "activation" cost. A few hundred or a few thousand dollars against a promised 4.5 million reads as trivially worth paying. This is the entire point of the exercise, and it is why the scheme is called advance-fee fraud.
  9. The Escalation: Each fee resolves the last obstacle and reveals a new one. The sums grow as the victim's sunk cost grows, and every payment makes withdrawal psychologically harder โ€” abandoning now means the previous payments were wasted, which is precisely the reasoning the sequence is engineered to produce.
  10. The Data Harvest: Alongside the money, the attacker collects bank account details, identity documents, company registration papers, and signatures โ€” "for the transfer paperwork". These have independent resale value and enable identity fraud entirely separately from the fees.
  11. The Mule Risk: In some variants money genuinely does arrive in the victim's account, with instructions to forward most of it onward. That money is stolen from someone else, the victim's account is now laundering it, and the victim is the only visible, traceable party in the chain. People have been prosecuted for this while believing themselves the injured party.
  12. The End: There is no eighteen million dollars and there never was. Contact stops, or a final catastrophic fee is demanded and the thread dies. The victim's address is then sold on to other operators, frequently as part of a "recovery" list โ€” which is why the next email will offer, for a fee, to get the earlier money back.

Conclusion and Recommendationsโ€‹

There is no USD 18 million, no investment plan, and no Olena Zelenska. There is a car dealership's mailbox in the United Arab Emirates that somebody else is using, a free Gmail account with a number on the end, and a template that has been circulating in some form since fax machines. The name in the signature belongs to a real, living public figure whose actual circumstances contradict every word of the story attached to it.

The genuinely instructive part is how little of this required any technical skill to detect. The message authenticated perfectly โ€” SPF passed, DKIM signed, sent from a legitimate domain with a good reputation โ€” and none of that mattered, because authentication proves who controls a mailbox and says nothing about who is typing. What exposed it was reading four fields in the header and noticing they described four different people, and then searching one name. When a message needs you to believe a stranger's story about hidden money, the story is the attack, and the story is the part you can check.

Immediate Actions:โ€‹

  • Do Not Reply, Not Even to Decline: A reply is the only thing this email wants. Any response at all โ€” including a refusal, an insult, or a request to be removed โ€” confirms a live, human-attended mailbox, which raises the value of your address and guarantees more of these. There is no version of engaging that costs the attacker anything and no version that does not cost you.
  • Do Not Send Money, Ever, for Any Reason Given: No legitimate transfer of funds to you requires you to pay first. Not a fee, not a tax, not a certificate, not a bribe, not a courier. The advance fee is the entire fraud, and every stage of the conversation exists only to reach it.
  • Do Not Send Identity or Banking Documents: A passport scan, an ID card, a bank statement, or a company registration certificate has resale value on its own and enables fraud in your name long after this particular thread is dead.
  • Report and Delete: Use your mail client's phishing or spam report rather than plain deletion, so the sending address is scored and, if you are on a corporate system, your security team sees the campaign.
  • Warn Colleagues on Shared Mailboxes: info@, sales@, and contact@ addresses are read by several people, and the one who happens to open it may not be the one who would recognise it. A thirty-second heads-up is worth more than a policy document.
  • If Anyone Has Already Engaged, Stop and Escalate Now: Cease all contact, do not send the "final" payment that will supposedly release the funds, preserve every message and receipt, and report to your national cybercrime authority โ€” in India, the National Cyber Crime Reporting Portal at cybercrime.gov.in or the 1930 helpline. If money has moved, tell your bank immediately, because the first hours are the only realistic window for a recall.
  • Treat Any Offer to Recover Lost Money as the Next Scam: Victim lists are traded, and follow-up fraud aimed at people who have already paid is a specialised business. A lawyer, agency, or "recovery service" that finds you by email and asks for a fee to retrieve earlier losses is the same criminal or their colleague.

Verification Steps:โ€‹

  • Search the Name in the Signature Before Anything Else: Five seconds in a search engine identified Olena Zelenska as the First Lady of Ukraine and ended this analysis. When a message trades on a claimed identity, the identity is the cheapest thing to check and usually the first thing to break.
  • Read Every Identity Field and Make Them Agree: Display name, sending domain, signature, and reply address should describe one person or organisation. Four different answers to "who sent this?" in a single message is a conclusion, not a curiosity.
  • Notice Where You Are Asked to Reply: A message sent from one domain that directs answers to a free webmail account elsewhere is describing its own disposability. Legitimate correspondence is answered where it came from.
  • Do Not Read Authentication as Endorsement: SPF, DKIM, and DMARC passing means the mail genuinely came from that domain's mailbox. Applied to a compromised or hijacked account, all three pass while everything in the message is false.
  • Ask What the Sender Knows About You: A real investor knows your company, your sector, and why they contacted you. "Dear Friend" and "any business in your country" prove the sender holds nothing but an address.
  • Follow the Money Backwards: Where did the funds come from, who currently holds them, which institution, under whose name, and why can they move to a stranger but not to a bank? A story that cannot answer those questions is not a story about money.
  • Distrust Any Percentage Offered to a Stranger: Real fees are small, negotiated, and documented. 25% of principal, offered unprompted to someone whose name you do not know, is a number chosen for its effect on the reader rather than its relationship to any work.
  • Verify Through a Route You Already Had: If a message claims to come from an organisation or a public figure, contact them through their own published channels โ€” a website you navigated to yourself, a switchboard number, an official foundation address. Never a contact detail supplied by the message.

Additional Protection Tipsโ€‹

  • Recognise the Shape, Not the Story: The cover changes constantly โ€” a widow, a bank officer, a dying philanthropist, a war, a frozen account, a cryptocurrency wallet with a lost key. The skeleton never does: large sum, foreign, blocked by circumstance, generous percentage, contact me privately. Learn the skeleton and every future variant is recognisable on the first paragraph, whatever the headlines happen to be.
  • Treat Unsolicited Good News as the Warning Sign: Money you did not earn, from a person you do not know, for work you have not done, is the single most reliable indicator of fraud in email. The 4,800,000 Euro donation and the Faith Isabella investment corporation messages in our archive are the same offer with different scenery.
  • Understand That the Absence of a Link Is Not Safety: This email contains nothing to click, which is why it passes filters that are largely tuned for URLs and attachments. The payload of an advance-fee approach is the conversation, and no gateway can scan for that. A clean message is not a safe one.
  • Protect Old and Forgotten Mailboxes: This campaign is being sent from somebody's real account. Legacy ISP addresses, dormant departmental mailboxes, and accounts belonging to staff who left are exactly what gets taken over, because nobody is watching them. Close what you no longer use, enable multi-factor authentication on what you keep, and audit for accounts nobody owns.
  • Never Reuse a Password on a Mailbox: A mailbox is not one account among many โ€” it is the reset mechanism for all the others, and it is the identity your customers and suppliers trust. Unique credentials and a password manager are the whole defence against the takeover that put this message in flight.
  • Adopt a Two-Person Rule for Money Leaving the Business: Any payment to a new beneficiary, any change to bank details, and any fee attached to an unexpected windfall should require a second person's approval and a voice call to a number from your own records. Fraud of this kind depends on one person acting alone and slightly excited.
  • Say Out Loud What You Are About To Do: These schemes rely on isolation, and "please contact me only on this email" is the instruction that creates it. Describing the situation to one uninvolved colleague, friend, or family member breaks the spell more reliably than any technical control, because the absurdity is obvious to everyone except the person inside the conversation.
  • Make It Safe to Own Up: Advance-fee fraud is unusually humiliating for its victims, and shame is what turns a small loss into a large one โ€” people keep paying rather than admit the earlier payments. A workplace where somebody can say I think I have been caught by this without consequence recovers money that a workplace built on blame never sees.
  • Watch for the Elderly and the Isolated Around You: The people who lose life-changing amounts to these schemes are rarely foolish; they are usually alone, and the attacker becomes the person who writes to them most attentively. Awareness that stays inside the office misses the recipients who need it most.

Remember: Nobody with eighteen million dollars needs a stranger's help to invest it, and no head of state's family has ever asked for one by email. When a message offers you a fortune for a favour, the fortune does not exist and the favour is the fee you will be asked to pay for it.


Share this post