Evidano is an AI-powered qualitative data analysis platform that ingests mixed-format evidence, automates thematic coding, and links textual, infrastructure, and financial signals. The Associated Press / FRONTLINE investigation (June 30, 2026) documents how American AI and infrastructure are being exploited to industrialize scams. This post shows researchers and analysts how to run a focused qualitative analysis of scam networks (from leaked files and device logs to interview transcripts) and how to operationalize findings to produce reproducible themes, segment comparisons, and visual evidence for policy or product decisions.
Key Takeaways
Evidano is an AI-powered qualitative data analysis platform that ingests mixed-format evidence, automates thematic coding, and links textual, infrastructure, and financial signals.
AP’s June 30, 2026 investigation found U.S.-based hosting, AI models (chiefly ChatGPT and Gemini), and Starlink connectivity were used to scale scams, and analysts can reproduce insights by coding transcripts, device logs, and blockchain traces.
- AP sampled 202, 013 device connections (Feb 2025–Jan 2026) and reported approximately 50, 000 victims in one month.
- Estimated U.S. losses cited by AP include nearly $200 billion (FTC estimate) and at least $75 million in illicit network-level profits (TRM Labs / AP reporting).
- Use a seven-step checklist to collect transcripts, device/IP logs, and blockchain IDs, run transcription and auto-coding, validate codes, and produce visual evidence for policy or takedown actions.
Fast take + source
Fast take: AP’s June 30, 2026 investigation found AI models, U.S.-based hosting, and Starlink connectivity were used to scale scams from Myanmar to dozens of countries.
Read the original reporting here: AP / FRONTLINE investigation.
- Why analysts should care: the report links textual artifacts (scripts, chat logs), infrastructure signals (202, 013 device connections analyzed) and financial traces (crypto flows), exactly the heterogeneous corpus qualitative research tools must ingest and code.
- Payoff: we show a pragmatic workflow to extract themes, compare segments, and produce visualizations you can share with policymakers or platform safety teams.
Findings snapshot
| Date / Metric | Value | Source / Note |
|---|---|---|
| Published | June 30, 2026 | AP / FRONTLINE |
| Device connections sampled | 202, 013 | AP analysis of scam-compound connections (Feb 2025–Jan 2026) |
| Victims targeted (example) | ≈50, 000 in one month | Testimony and smuggled records from one scammer |
| Estimated US losses (2024) | Nearly $200 billion | FTC estimate cited by AP |
| Blockchain payments to one 007TG wallet | $860, 000 (Apr 2024–Dec 2025) | TRM Labs analysis |
| Illicit profits (network-level) | At least $75 million | TRM Labs / AP reporting |
| People trafficked into scam centers | ≈300, 000 | United Nations estimate (reported by AP) |
What happened (plain English)
What happened: AP and FRONTLINE combined leaked scam-center files, satellite imagery, 58 victim interviews, device connection logs, C4ADS analysis, and TRM Labs blockchain work to show a multi-layered abuse chain.
- Tools used: ChatGPT and Google Gemini integrated into scam suites to produce automated replies, role-play bots, and more than 100-language translation.
- Infrastructure role: one in five device signals from sampled scam compounds routed via U.S.-registered providers, and Starlink was the top ISP in Myanmar during sampled periods.
- Evidence types analysts can collect: chat transcripts, platform account logs, device/IP mappings, satellite imagery timestamps, and blockchain transaction traces.
Implications for researchers & analysts
Implications for researchers and analysts: combine thematic coding with infrastructure and financial traces to produce actionable findings for product, policy, or enforcement.
Implications for researchers & analysts
UX researchers and trust teams
UX researchers and trust teams should code for persuasive language, escalation patterns, and ask sequences such as money asks, urgency, and isolation.
Romance and investment scams use nuanced conversational tactics, so code for persuasive language, escalation patterns, and ask sequences and perform cross-segment analysis (age, geography) to reveal which hooks succeed where.
Policy and law enforcement analysts
Policy and law enforcement analysts should combine qualitative coding of scripts and victim interviews with IP/device timelines and crypto trails to build evidentiary narratives.
Timestamped themes and visual co-occurrence networks help explain modus operandi to policymakers and support takedown or legal action.
Security / threat intel teams
Security and threat intel teams should merge operational signals with thematic coding to prioritize takedown targets.
Operational signals such as hosting providers, VPN usage, and Starlink device patterns should be merged with thematic coding of scam scripts to quantify repetitive patterns and automate detection rules.
Do more, faster with Evidano
Do more, faster with Evidano: use a single workspace to ingest mixed-format evidence, run automated thematic coding, and map texts to infrastructure and blockchain signals.
- Evidano transcribes audio, applies custom dictionaries (names, slang), and translates content while preserving original timestamps and metadata when you upload leaked files, chat transcripts, interview audio, device logs, and CSVs.
- Run thematic coding across thousands of documents, then compare themes by segment (victim country, scam type, platform) and export frequency tables and codebooks to support reports or legal briefs.
- Map IP/device fields and blockchain identifiers into the same workspace, run cross-variable queries (for example, show transcripts where IP X appears and theme Y is present), and visualize co-occurrence networks for briefings.
- Data is encrypted, stored privately, and not used to train third-party models, and you can use AI chat over your corpus to iterate hypotheses without exposing data externally.
Checklist: run this analysis in 7 steps
Checklist: follow these seven steps to reproduce the core insights from the AP investigation and extend them for your stakeholders.
- 1) Collect: centralize transcripts, leaked files, device/IP logs, and blockchain tx IDs.
- 2) Clean & ingest: upload to Evidano; run transcription and translation with a custom dictionary.
- 3) Auto-code: apply an initial codebook (scripts, persuasion tactics, infrastructure signals) and let Evidano suggest subcodes.
- 4) Validate: spot-check auto-codes, refine the codebook, and lock for reproducibility.
- 5) Cross-segment queries: compare themes by country, platform, or time window (for example, pre/post Starlink cutoffs).
- 6) Visualize: generate co-occurrence networks and hierarchical theme charts for briefings.
- 7) Produce evidence pack: export coded quotes, timeline visuals, and a brief for legal and policy teams.
FAQ: qualitative analysis of scam networks
What did the AP / FRONTLINE investigation find?
The AP / FRONTLINE investigation found that AI models, U.S.-based hosting, satellite internet, and crypto rails were used to scale scams across dozens of countries.
The investigation combined leaked scam-center files, satellite imagery, 58 victim interviews, device connection logs, C4ADS analysis, and TRM Labs blockchain work to document the abuse chain and estimated impacts.
What evidence types should researchers collect to study scam networks?
Researchers should collect chat transcripts, platform account logs, device/IP mappings, satellite imagery timestamps, interview recordings, leaked files, and blockchain transaction traces.
These heterogeneous evidence types allow analysts to link textual themes to infrastructure signals and financial flows to build robust narratives.
How can teams reproduce the AP analysis in practice?
Teams can reproduce the AP analysis by centralizing mixed-format evidence, running transcription and translation, applying thematic coding, validating codes, and producing visual co-occurrence networks and timelines.
Follow the seven-step checklist to collect data, ingest into a qualitative workspace, auto-code, validate, query across segments, visualize, and export an evidence pack.
Is data secure when running this analysis in Evidano?
Data is encrypted and stored privately in Evidano, and it is not used to train third-party models.
Evidano supports secure, reproducible research with private storage and an AI chat over your corpus that does not expose data externally.
Wrapping up & next steps
Wrapping up: AP’s June 30, 2026 report shows that combining qualitative evidence with infrastructure and financial traces creates the strongest narratives for disruption and policy.
- Try a pilot: ingest one scam-center dataset, run thematic and cross-segment analysis, and produce a stakeholder brief in two weeks. Try Evidano for free.
