Executive Case Brief: The Infrastructure of a Digital Con (2026)| Project: Bullyish by Lillee Jean
- Jun 18
- 4 min read

In the era of digital, the mechanics of a "con" have shifted massively from traditional financial schemes into organized internet racketeering (see my article on this). True digital con artists operate as structured, profit-driven syndicates disguised as media entities, marketing agencies, and "sole" people. They intentionally use false stories to drive global ad revenue, employing DARVO (Deny, Attack, and Reverse Victim and Offender) to position themselves as victims when held accountable.
This infrastructure relies on systematic asset theft, minor exploitation on private servers, and SEO-poisoning tactics designed to pollute search indexes with fabricated long-tail phrases. This article serves as a summary of my official Thread, where I document out a racket, and how this constitutes the modern "CON" harming innocent people, vulnerable minors, for pure greed.
Actionable Steps: Countering a Digital Racket
When independent professionals are targeted by a coordinated deception network, defensive or reactive posting plays into the syndicate's traffic model. It is always my suggestion to not just TWEET about something - have action, by moving through formal, legal, and technical channels:
Secure Ironclad Forensic Logs: Document all network tracking strings, unauthorized server access attempts, database alterations, and IP visitor logs with precise timestamps.
Isolate and Authenticate the Assets: Catalog the exact instances where copyrighted material, professional work, or archival minor imagery are unauthorizedly hardcoded next to corporate advertisements or sponsorships.
File Active Reports with Law Enforcement: Direct all verified data packages, threatening communication logs, and tracing data straight to appropriate local and federal agencies, such as the NYPD.
Maintain Platform Compliance Channels: Utilize formal statutory mechanisms, such as federal copyright registrations and privacy directives, to force platforms to review corporate liability regarding the hosting of synthetic media or explicit deepfakes (and report to your local precinct to open a police case, as it is against the law to host deepfake material).

"I have been absolutely proactive with law enforcement, ensuring every single tracking string, server intrusion log, and aggravated criminal harassment vector is securely turned over to official authorities. You should be too. Never remain passive when your safety, minor security, or intellectual footprint is being compromised by anonymous bad actors hiding behind standard platform vulnerabilities. For any instances where I have observed the involvement of children on these networks, I have immediately reported it directly to the police. To preserve minor safety, any imagery or data related to youth exploitation shown across my articles, such as my recent investigative report on minor safety within this specific hate-for-profit racket, has been strictly redacted to ensure absolute protection while exposing those who con the public with fabricated stories for commercial profit."

The following resource provides further visual context regarding the architectural framework of this case study. For a deeper look at the directorial legacy of the project, check out Project: Bullyish: Shattering the 10-Year Hoax, an informational segment highlighting the long-term mechanics of synthetic media and asset protection
Reference Portals
Case Analysis & Media Monetization: Project Bullyish News Portal
Technical Studies: Digital Racketeering & Safe Harbor Analysis
Please visit the official Site:
Forensic Methodology and Estimations: The financial figures, expenditure projections, and infrastructure valuations presented in this report (specifically the "Forensic Bill" and "Total Estimated Expenditure") are forensic estimates formulated by the author. These projections are based on a comparative analysis of industry-standard market rates for enterprise-level cloud egress, global proxy rotation, high-compute data center bandwidth, and AI API consumption during the period of October 2025 – June 2026. Because the private invoices and internal service agreements of the identified third-party infrastructure providers are not public record, these figures represent a good-faith expert projection based on the documented volume and frequency of server logs. No Malice / Investigative Intent: This article is a work of investigative journalism and forensic study published as part of Project: Bullyish. The purpose of this publication is to document patterns of cyber-harassment, educate the public on digital safety, and provide a transparency report regarding the security of the author’s intellectual property. Any mention of specific entities or service providers (e.g., Tencent, Alibaba, Microsoft) is based on direct forensic evidence captured in server logs (IP addresses and User-Agents) and is intended to describe the technical path of the traffic, not to imply that the parent infrastructure providers are intentionally complicit in the harassment. Legal Characterization: Terms such as "Racketeering," "Computer Trespass," and "Digital Shakedown" are used in a descriptive and investigative context to characterize the pattern of conduct observed in the forensic data. These characterizations are the opinion of the author based on the documented "course of conduct" and are not intended to serve as a legal determination of guilt, which is the sole province of a court of law. Reporting and Evidence: All original, unredacted logs, timestamped data, and TCP handshake records referenced in this study have been preserved and submitted to the FBI’s Internet Crime Complaint Center (IC3) and the NYPD Cyber Crimes Unit as part of an active, ongoing criminal investigation.
© 2026 Lillee Jean. All rights reserved.
