Back to Insights
Threats5 min read23 July 2026

3,000 Workers Freed From Myanmar Scam Compound as Investigators Warn the Industry Is Moving Deeper Into the Jungle

The Karen National Liberation Army liberated captive fraud workers from Shunda Park in 2025. The United Nations puts the total number of people still trapped across Myanmar at 120,000. The crackdowns are not working.

t2s
train2secure NewsdeskSecurity awareness team
Photoreal aerial editorial photograph looking down into dense jungle canopy in Southeast Asia at dusk, a large walled co

Armed fighters from the Karen National Liberation Army walked into a jungle compound in Myanmar's border region in 2025 and freed roughly 3,000 captive workers from a site called Shunda Park.

What Is Shunda Park?

Shunda Park is one of Myanmar's largest known scam operations, hidden behind razor wire and dense tree cover. The Karen National Liberation Army, an ethnic armed group in active conflict with Myanmar's military government, retook the surrounding territory and discovered the facility. The Free Burma Rangers, a humanitarian organisation, went in afterward and documented conditions on the ground.

The site is not unique. The United Nations Office on Drugs and Crime estimates at least 120,000 people are currently held inside scam compounds across the country. Shunda Park was simply large enough to be found.

How These Operations Work

People are trafficked into compounds like Shunda Park through deception or outright kidnapping. Ivan, a Malaysian man freed from the site, described being lured through Thailand under false pretences before crossing into Myanmar against his will. Once inside, workers were assigned online fraud duties.

The dominant method is called "pig butchering." Criminals spend weeks or months building fabricated romantic relationships with strangers online, often targeting people in the United States and Australia. When the target trusts them, the criminal steers the conversation toward cryptocurrency investment, directing victims to fake platforms before draining their funds. Troops who entered Shunda Park recovered thousands of phones, SIM cards, and hard drives alongside printed training manuals that scripted exactly how this grooming process should work.

Failing to meet daily quotas brought brutal punishment. Ivan said workers were suspended by chains and confined in dark rooms with minimal food and water. Guards reportedly carried rubber-coated batons calibrated to cause severe pain without leaving visible marks. Lin, a Taiwanese man held in a separate compound, said he was caged and handcuffed outdoors in direct sunlight after attempting to alert police. He told aid workers he could feel his ribs grinding when he breathed.

Productivity, not humanity, determined living conditions. Workers who generated the most money for criminal bosses were housed on higher floors with better food and beds. Those who did not produce were isolated. Internet access stayed on throughout because the scam had to continue.

Crackdowns Are Not What They Appear

"Scam centres require only a small footprint: a rented hotel, computers, electricity, an internet connection and permissive local law enforcement," one regional analyst noted. That combination makes this industry extraordinarily resistant to conventional enforcement.

KK Park, once one of the best-known sites and reported to have held up to 25,000 people, became a symbol of the crackdown narrative. Anti-trafficking investigators now say those announcements were, in many cases, staged. Buildings near main roads were made to look damaged for cameras. Operations shifted elsewhere. One investigator stated publicly that KK Park remains standing and operational.

Satellite imagery analysed by the Australian Strategic Policy Institute shows new, smaller compounds appearing throughout 2024, concentrated along the Moei River in southern Myanmar, away from border crossings where Thai or international observers might notice. These newer sites hold fewer workers and, according to analysts, apply more physical violence precisely because they cannot recruit freely from nearby border towns.

Why This Matters to Anyone With a Smartphone

The fraud flowing out of these compounds reaches ordinary people on every continent. If you have been contacted online by someone who became romantic unusually fast and later asked you to move money or invest through an unfamiliar platform, you have encountered the output of this system. Stop all contact, notify your bank immediately, and report the interaction to your national consumer protection authority.

The fraud is industrial in scale and organised like a corporation. Workers follow scripts. Supervisors track conversion rates. Finance teams handle cryptocurrency flows. The people on the sending end are often victims themselves, trapped and brutalised into compliance.

Which Controls Failed, and What Defenders Must Learn

The scam compounds in Myanmar expose a specific failure at the awareness layer that security professionals sometimes underestimate. The initial contact in a pig-butchering attack is not a crude phishing email with a misspelled sender. It is a carefully cultivated human relationship, run over weeks, designed to generate trust before any request for money is made. By the time the victim hands over funds, emotional manipulation has already bypassed rational risk assessment. Standard technical controls, spam filters, domain reputation checks, and browser warnings, cannot stop a fraud that arrives through a legitimate social media account or messaging app.

Organisations have a role here that goes beyond protecting their own systems. Employees defrauded through personal cryptocurrency accounts often face financial devastation that spills into workplace productivity, absenteeism, and even insider-risk scenarios when desperate people make poor decisions to cover losses. Regular, scenario-based training that walks staff through the specific mechanics of romance and investment fraud is the only control with a realistic chance of intervening before money moves. Train2Secure's simulation-based awareness modules include social-engineering scenarios built around exactly this attack pattern, not just email phishing.

The second systemic failure here is the absence of friction at the money-transfer stage. Pig-butchering attacks almost always route funds through cryptocurrency because transfers are irreversible and pseudonymous. Security teams that have trained employees to pause before any wire transfer or crypto transaction, to seek a second opinion and verify independently, can dramatically reduce the probability of a successful outcome for the attacker. A single policy requiring a phone call to a known contact before any transfer above a set threshold would have stopped a significant share of the losses that funded the compounds described in this article. Building that habit is a training problem, not a technology problem.

Meeting the NIST Cybersecurity Framework's "Govern" and "Protect" functions requires that employees understand current threat patterns, not just yesterday's ones. The pig-butchering model is now documented, industrialised, and operating at scale. Any organisation that has not briefed its staff on this specific fraud mechanic has a measurable gap.

For teams considering a structured programme, Train2Secure's pricing page outlines per-seat options that cover social-engineering threats alongside phishing and ransomware scenarios.

How your organisation can protect staff from romance and investment fraud

  • Train employees to recognise the slow-build trust tactics used in pig-butchering attacks, not just fast-moving phishing emails.
  • Establish a simple policy requiring a verified second contact before any wire transfer or cryptocurrency transaction above a defined threshold.
  • Run scenario-based simulations that place staff inside a realistic romance-fraud conversation so they experience the manipulation dynamic before an attacker does.

Train2Secure's social-engineering modules cover pig-butchering and investment-fraud scenarios alongside standard phishing simulations, giving your team context for the threats that technical controls cannot catch.

Start free, no card required

Frequently asked questions

What is a pig-butchering scam and how does it start?

A pig-butchering scam begins with a stranger initiating contact online, often through a dating app or social media, and spending weeks building a romantic or friendly relationship. Once trust is established, the criminal introduces a fake cryptocurrency investment platform and persuades the victim to transfer funds. The term refers to the idea of fattening a pig before slaughter. The contact is nearly always a scripted role played by a trafficked worker inside a compound.

How many people are estimated to be held in Myanmar scam compounds?

The United Nations Office on Drugs and Crime estimates at least 120,000 people are currently trapped inside scam compounds across Myanmar. The Shunda Park liberation freed roughly 3,000 of those workers. Analysts say the total is likely higher because new, smaller sites are being built in remote jungle areas that are difficult to monitor.

Are the announced crackdowns on Myanmar scam sites effective?

Investigators say largely no. Announced demolitions of well-known sites such as KK Park appear in many cases to have been staged near roads visible to cameras, while operations continued elsewhere. Satellite analysis shows new compounds appearing throughout 2024 along the Moei River, further from border crossings and international oversight. The industry is relocating, not contracting.

What should someone do if they think they have been targeted by a pig-butchering scam?

Stop all contact with the individual immediately. Do not send any additional funds or personal information. Contact your bank or financial institution to report the transaction and request a freeze if funds have moved. Report the fraud to your national consumer protection or cybercrime authority. In the United States that is the FBI's Internet Crime Complaint Center (IC3). In Australia it is Scamwatch, run by the Australian Competition and Consumer Commission.

Ready to Reduce Your Human Cyber Risk?

Sign up and start training your team in minutes. No sales calls, no demos — just pick a plan and go. Phishing simulations, video courses, and certificates from day one.

train2secure analytics dashboard showing training completion stats and user progress