The Straits Times took apart a fake Singapore think tank with twelve invented experts and an address nobody occupied. This teardown breaks down what the operation cost to build, where its structural limits lay, and what registries, platforms, and regulators must change for the next fake to fail automatically.
The case, in sixty seconds
IEASS presented itself as a Singapore-based think tank publishing analytical security reports on Asia. However, an investigation by ST revealed no valid Singapore business registration, a listed office address with no physical presence, and twelve named experts who appeared in no public records or professional databases several with headshots displaying telltale signs of AI generation. When subjected to direct verification, every checkable claim collapsed. Both institutions listed on the experts' profiles, MDIS and SUSS, confirmed they had no record of the individuals. SUSS further clarified that the specific degree programme cited on the profiles does not even exist.
The operation was active, not dormant. Its synthetic personas targeted security analysts and intelligence-linked professionals, including a NATO employee, offering competitive fees for off-the-record analysis on behalf of undisclosed clients. Chatham House associate fellow Bill Hayton raised the initial public alarm, after which Foundation for Defense of Democracies (FDD) analyst Max Lesser linked IEASS to two sister entities. All three fronts were registered within a three-month window and built using the same AI web-development platform.
As soon as investigative enquiries began, the contact details vanished from the website and the fake LinkedIn accounts were scrubbed. While every fact above stems from The Straits Times' reporting, the strategic analysis below is entirely ours.
Fraud as a Service (FaaS)
The IEASS build sheet reads like a shopping list: a domain, a site assembled on an AI builder, a staff page of generated faces, a stream of generated commentary to make the faces look employed, professional network accounts to distribute it, and a job advertisement to scale the outreach.
In 2020, Singaporean Dickson Yeo ran the same playbook. One fake consultancy and a professional network account, by hand, ending in a U.S. guilty plea for acting as an agent of a foreign intelligence service [DOJ, CNA]. Six years later, the same method fields a dozen personas across three institutional fronts. The method held; the unit cost collapsed.
The product IEASS deployed offered money rather than asking for it. The real asset being manufactured was a personal relationship with individuals close to sensitive information, priced and disguised as routine consulting work. That funnel is target-agnostic: pointed at a government ministry, it yields intelligence sources; pointed at a bank, it yields a trusted vendor, introducer, or expert adviser. That is why this case belongs on a chief compliance officer’s desk, not just in a national security report.
The change this demands is a default, not a tool: run the checks on entities that look respectable, not just the ones that look suspicious, because looking respectable is now the cheap part.
What would cause the next synthetic operation to fail automatically?
The unsettling reality of the IEASS case is that it was solved purely through manual investigation: a reporter stood in an empty commercial hallway, a registrar fielded an enquiry, and analysts cross-referenced notes on public forums. While every single check worked, none of them scaled.
Every check that caught the operation was manual: a visit, a call, an enquiry to a registrar.
Company registries must evolve to answer machines, not just people.
The public registers that exposed IEASS remain siloed and human-paced. Transitioning to machine-readable, cross-border registry lookups, a trajectory already pioneered by the Legal Entity Identifier (LEI) system for financial entities, would transform uncovering a false corporate claim from a reporter's afternoon investigation into an instant onboarding API response.
Credentials should verify cryptographically. Singapore already issues OpenCerts, digitally verifiable education certificates. In a world where a claimed degree is a signature check rather than an email to a registrar, the single most abused line on a synthetic CV dies at intake.
Professional platforms should surface their own signals. Account age, identity-verification status and synthetic-image detection are data the platforms already hold; establishing them for IEASS took investigative work. Regulation is moving toward mandatory disclosure of AI-generated content, and profile photos of non-existent employees are exactly the case that direction should reach.
Infrastructure providers can see what no single victim can. Three institutional sites on near-identical templates, registered within weeks of each other, is a pattern visible to site builders and registrars, the same way hosting providers already detect phishing kits. Today, nobody owes anyone that analysis.
And the legal gap is commercial, not national-security. Singapore has FICA for covert foreign influence operations. But the identical toolkit pointed at a vendor-onboarding queue is not an influence operation, it is fraud, and the counter to industrialised fraud is not security law. It is verification infrastructure that answers in milliseconds.
Do not wait for the infrastructure
None of that arrives this quarter, and your onboarding queue is open today. Four defaults fall straight out of the teardown.
Treat affiliation as a claim, not a credential. "Research fellow at a Singapore institute" is an assertion to verify with the registry and the institution, both of which, in this case, had never heard of the entity.
Verify the entity and the people, separately. IEASS failed both layers. A real registration fronted by fabricated staff, or real people fronting a hollow entity, should each fail on its own.
Make infrastructure checks routine. Domain age, shared templates and hosting overlap connected the three fronts within days of someone looking. Those signals are free to collect at onboarding.
Assume polish is free. A professional website, consistent branding, credentialed headshots and a stream of publications no longer imply an organisation exists. They imply someone wanted it to look like one.
The operation was one verification pass from collapse at every point in its life. The fakes got cheaper, and checking still wins, but only where somebody actually runs the checks. The institutions that internalise that first are the ones the next synthetic counterparty will bounce off.