Someone emailed a target claiming to be an investor backed by a Chinese bank. Two days later, the "bank" emailed to back the story up. Here's how the pieces fit together.
The Players
Entity 1: sjrcbank.com, impersonating Shandong Juancheng Rural Commercial Bank, a real institution (SWIFT code SJRCCNB1).
Entity 2: tzr-investment.com, with a "CFO" named Thomas Knight sending a "Letter of Intent" two days before the bank email.
The Slow Build
The References header on the investor email shows this is an ongoing thread. The longer the scammers keep the target talking, the more legitimate the whole thing feels. That's the playbook of an advance fee scheme: the victim is promised something big, like an investment or a loan, and is asked to pay money upfront to get it.
Domain Red Flags
Registration details below come from public domain records, which anyone can check with ICANN’s registration data lookup.
sjrcbank.com
- Registered February 16, 2025
- Privacy-masked, with a California address
- A real rural bank with years of history would have a much older domain
tzr-investment.com
- Registered November 8, 2025, under a year old
- Fully hidden registrant
- Name servers on truewebhost.eu and truewebhost.us, a cheap offshore host
- Registered for one year only
The Missing Legal Disclosures
China's Measures for the Administration of Licenses of Banking and Insurance Institutions (NFRA Order No. 2 of 2026, in force since June 1, 2026) require banks to publicly display their business scope, their responsible person, and, where it applies, their operating region. Under Article 18, a bank doing business through an online platform has to show those details "in a clear and prominent manner" on the relevant web pages.
The sjrcbank.com site shows none of them. A real licensed bank doing business online would have to.
Verdict
Don't send money. Don't share personal or financial information. Don't pay any "processing," "transfer," or "release" fees. Legitimate lenders don’t demand payment first. Every document they sent should be treated as fabricated.
If you've already engaged, stop replying, preserve the full email headers, and report the domains to the registrars' abuse contacts (listed in the domain records) and to your own IT or security team. In the US, you can also report it to the FBI’s Internet Crime Complaint Center and the FTC.
Sources
- Measures for the Administration of Licenses of Banking and Insurance Institutions, National Financial Regulatory Administration, Order No. 2 of 2026, Article 18. Official text on gov.cn (Chinese).
- SWIFT code SJRCCNB1: Shandong Juancheng Rural Commercial Bank Co., Ltd., Remitly SWIFT directory.
- Registration Data Lookup Tool, ICANN. Source for the domain registration dates, registrants, and name servers.
- Business and Investment Fraud: Advance Fee Schemes, FBI.
- What To Know About Advance-Fee Loans, Federal Trade Commission.
- Internet Crime Complaint Center (IC3), FBI, and ReportFraud.ftc.gov, FTC.