P2 High · Unlicensed Investment Advice · GDPR Violation · Misleading Financial Marketing

Case 006 — Investor Verlag / FID Verlag
Misleading Investment Advertising · boersenwissen-aktuell.de

German-language investment newsletter lead-generation site on AWS S3 making unlicensed investment recommendations ("these 3 cryptos will EXPLODE!") without BaFin authorization. Operator identified as FID Verlag GmbH / Investor Verlag, Bonn. Affiliate tracking codes expose a full multi-publisher distribution network. Cookie consent admits GDPR-violating data sharing with third parties outside the EU.

P2 High MiFID II Violation Unlicensed Investment Advice StGB §264a — Criminal Threshold GDPR / DSGVO Violation AWS S3 + CloudFront Misleading Return Claims ✓ Honeypot Confirmed 2026-08-18 lpm.fid-shop.de FID Verlag GmbH Investor Verlag · Bonn Multi-Opt-In Harvesting Passive OSINT Only
Target URLboersenwissen-aktuell.de
Status✓ Funnel Confirmed — Honeypot 2026-08-18
OperatorFID Verlag GmbH / Investor Verlag
HostAWS S3 + CloudFront (AMS1)
ViolationsMiFID II · StGB §264a · DSGVO Art.13 · UWG §5 · UWG §7
Newsletters CapturedMKR · DM · ISD (3 affiliate chains)
Last Modified2026-06-17 (S3 ETag)
● UPDATE — 2026-08-18 · Honeypot Test Completed
Full funnel confirmed live. I subscribed using a fresh Proton Mail address, active VPN, and incognito browser. The confirmation email arrived via fid-nss.de and provides verbatim proof of all documented violations, including a live 36,018% return claim crossing the StGB §264a criminal threshold. A second email confirmed the bait-and-switch: the promised PDF was never delivered — clicking "Download" opened a new payment page at lpm.fid-shop.de. Three-layer funnel fully mapped. See Findings 7 and 8.
⚡ PAYMENT PAGE OFFLINE — MAIN SITE STILL LIVE — 2026-08-25 Live IOC audit confirmed lpm.fid-shop.de (the bait-and-switch payment page) returning HTTP 404 as of August 25, 2026 — the final monetization step of the 3-layer funnel is offline. The primary domain boersenwissen-aktuell.de continues to return HTTP 200. The lead-gen and data collection chain (boersenwissen-aktuell.de → fid-nss.de) remains active. Violations still present: MiFID II, StGB §264a, DSGVO Art.13, UWG §5.
Finding 1 — Infrastructure: AWS S3 Static Site via CloudFront CDN

The site is served as a static HTML bundle from an AWS S3 bucket, distributed globally via CloudFront with edge nodes in Amsterdam (AMS1). The root domain redirects to www.boersenwissen-aktuell.de/index.html, confirming S3 static website hosting. This is a deliberate infrastructure choice: S3 provides virtually unlimited scale at minimal cost, and CloudFront ensures fast delivery — appropriate for a high-traffic lead generation campaign.

The page was built with Brizy (a drag-and-drop website builder), evidenced by the .brz-css-* class namespace throughout the HTML. Content was last updated 2026-06-17 per S3 ETag metadata.

# HTTP response — infrastructure fingerprint GET https://boersenwissen-aktuell.de/ 301 → https://www.boersenwissen-aktuell.de/index.html server AmazonS3 # redirect served directly by S3 GET https://www.boersenwissen-aktuell.de/index.html 200 server CloudFront x-amz-cf-pop AMS1-P1 # Amsterdam edge node x-amz-version-id8CYL1kMaGTywQl_SRxBW1jB60URTxaTk last-modified Wed, 17 Jun 2026 14:41:53 GMT content-length 213928 # 208 KB static bundle # DNS — AWS Route 53 + 8 CloudFront IPs NS ns-253.awsdns-31.com / ns-846.awsdns-41.net A 108.156.60.30/70/104/124 (CloudFront edge pool) TXT google-site-verification=EFsC4kbIqXYbRSb9jeXZTVyTgUKRXx8EIAeCCi74hk4 TXT facebook-domain-verification=93vxzl3jrzaktkzy5empunq75fwj9z TXT pinterest-site-verification=700b4f32c1a9c0041a8ef90f4983e72e
The presence of Google, Facebook, and Pinterest verification tokens confirms this is an active paid advertising campaign targeting retail investors across all major ad platforms. The operator has invested significantly in reaching victims at scale.
Hosting
AWS S3 + CloudFront
Edge POP
AMS1-P1 (Amsterdam)
DNS Provider
AWS Route 53
Page Builder
Brizy (brz-css-* classes)
Last Modified
2026-06-17
Registered
Changed 2023-11-23 (DENIC)
Ad Platforms
Google · Facebook · Pinterest
Analytics
GTM-KQ2VBR · GTM-KSD949H
Finding 2 — Operator Attribution: FID Verlag GmbH / Investor Verlag, Bonn

The operator is identified from two direct sources embedded in the page itself:

  • Cookie consent footer text: "E-Mail-Newsletter: Millers Krypto-Radar, Herausgeber: Investor Verlag | FID Verlag GmbH. Sie können sich jederzeit über einen Link am Ende jeder Ausgabe oder unter 0228 9550-400 abmelden." (Publisher: Investor Verlag | FID Verlag GmbH. You can unsubscribe at any time via a link at the end of each edition or by calling 0228 9550-400.)
  • Customer service email in the disclaimer: kundenservice@vnr.de — VNR = Verlag für die Deutsche Wirtschaft AG, the parent company of FID Verlag and Investor Verlag.
  • Pixel tracker: cdn.static.vnr-advance.de/pixel/0.4/advance-pixel.min.js — VNR Advance is the digital marketing arm of Verlag für die Deutsche Wirtschaft AG.
  • Risk disclosure PDF hosted at: shop.investor-verlag.de/risikohinweise/Investor-Sonderreport-Risikohinweis.pdf
# Operator entity tree (extracted from page source) Parent Company Verlag für die Deutsche Wirtschaft AG (VNR) ├── Subsidiary FID Verlag GmbH # newsletter subscription system (fid-nss.de) ├── Brand Investor Verlag # brand name on the site logo └── Digital Arm VNR Advance # pixel tracker (vnr-advance.de) Phone 0228 9550-400 # Bonn area code Email kundenservice@vnr.de Shop shop.investor-verlag.de → shop-investor.de
Context: VNR / FID Verlag are established companies with a publicly known address in Bonn. However, they operate in a legally grey area and have attracted multiple BaFin and consumer protection complaints over the years for their aggressive marketing tactics and specific investment recommendations without proper licensing. The Verbraucherzentrale (German consumer protection agency) has previously issued public warnings about VNR subsidiaries.
Finding 3 — MiFID II Violations: Unlicensed Investment Recommendations

The page makes highly specific investment recommendations without any BaFin license or disclaimer that the operator holds a §34f GewO (financial investment advisor) registration or MiFID II authorization. Under EU MiFID II and the German WpHG (Securities Trading Act), making specific buy/sell recommendations to retail investors requires a license.

The following claims extracted from the page constitute unlicensed investment advice:

# Verbatim investment claims from boersenwissen-aktuell.de (German) "Diese 3 Kryptowährungen explodieren!" → "These 3 cryptocurrencies will EXPLODE!" — specific recommendation without license "Von wegen Crash - Jetzt geht es erst richtig los!" → "No crash — Now things are really getting started!" — market timing claim "50 Prozent Verlust? Kein Problem - jetzt geht es erst richtig los!" → "50% loss? No problem — now things are really getting started!" — downplaying risk "5 Aktien reichen aus, damit Sie 2026 zu Ihrem Börsen-Erfolgsjahr machen können!" → "5 stocks are enough to make 2026 your stock market success year!" — specific count "Günstige Bewertung und enormes Potenzial treffen aufeinander!" → "Cheap valuation and enormous potential meet!" — specific valuation claim "Alle drei Coins haben das Potenzial, Ihnen hohe Gewinne zu bescheren und dabei die Erfolgsstory des Bitcoin zu übertrumpfen!" → Claims to surpass Bitcoin's performance — without disclosure of operator positions "ZDF Krypto-Experte Markus Miller" → Implies official ZDF (German public broadcaster) endorsement/employment — misleading
MiFID II Article 24 / WpHG §63: These claims constitute marketing communications for financial instruments that do not meet the requirement to be "fair, clear, and not misleading." Specific return predictions ("explode", "surpass Bitcoin") without historical context or risk disclosure are unlawful under EU financial marketing rules. The claim "50% loss? No problem" actively downplays investment risk — a direct violation of MiFID II retail investor protection requirements.
Finding 4 — Affiliate Tracking Codes: Full Distribution Network Decoded

The form embed source code reveals a structured affiliate tracking system. Each "free report" download form carries a data-nss-affiliate parameter that encodes the full marketing chain. Decoding these reveals the entire distribution network:

Affiliate CodeDecoded MeaningNewsletter
KOOP_I_MKR_IRW_INV_Krypto-x-diese-3-kryptos-explodieren_XCooperation · MKR newsletter · IRW traffic source · Investor category · Krypto-X campaignMillers Krypto-Radar (MKR)
KOOP_I_ISD_IRW_INV_5-TOP-AKTIEN_XCooperation · ISD newsletter · IRW traffic source · Investor · 5-Top-Aktien campaignISD Newsletter
KOOP_I_DM_IRW_INV_MEGATRENDS_XCooperation · DM newsletter · IRW traffic source · Investor · Megatrends campaignDM Newsletter
# Affiliate code structure decoded KOOP = Kooperation (cooperative/affiliate traffic — not organic) I = Incoming traffic type MKR/ISD/DM = Newsletter abbreviation (subscriber list identifier) IRW = Traffic source (likely Investor Relations Wire GmbH — a German financial PR company) INV = Investor category targeting Krypto-x-diese-3-kryptos-explodieren = Campaign name (matches page headline verbatim) X = Channel/variant suffix # Subscription system: fid-nss.de (FID Newsletter Subscription Service) opt_in_process_id = 1808 # MKR opt-in process opt_in_process_id = 3684 # DM opt-in process opt_in_process_id = 3713 # ISD opt-in process

What happens when a victim "downloads the free report": They submit their email address through fid-nss.de's form. They are subscribed to one or more investment newsletters (MKR, DM, ISD). The affiliate tracking ensures FID/VNR can attribute the subscription to the traffic source (IRW) and campaign. The newsletters then send ongoing investment "tips" — the classic lead-harvest funnel: create buzz, drive traffic, collect emails, send recommendations. Whether the operator profits from price movements in recommended assets (classic pump-and-dump) was not confirmed through passive OSINT; what is documented is the MiFID II-violating advertising claims and unlicensed investment marketing.

Finding 5 — GDPR / DSGVO Violations: Third-Country Data Transfer Without Adequacy

The cookie consent popup, photographically captured during investigation, contains an explicit admission of GDPR-violating data handling. The full text (translated) states:

"Depending on the function, data is thereby transferred to third parties and to third parties in countries outside the EU / EEA where there is no EU-adequate level of data protection and the security authorities of the third country have comparable legal remedies without an adequacy decision applying, or where an adequacy decision applies but its conditions are not met by every company concerned (incl. US companies)."

This statement is a direct admission of GDPR Article 44-49 violations — data transfers to third countries (specifically named: USA) without an adequate legal basis for the transfer.

  • Article 13 violation: Inadequate transparency about what data is shared with whom and which third countries
  • Article 44 violation: Transfer of personal data (email addresses) to non-adequate third countries without Binding Corporate Rules, Standard Contractual Clauses, or explicit consent for the specific transfer
  • Article 6 violation: Unclear legal basis for processing subscriber data across the affiliate network (KOOP partners)
Severity note: The admission is unusually explicit — the operator is disclosing a known GDPR violation in the consent popup rather than fixing it. This suggests either deliberate acceptance of regulatory risk or failure to implement proper data transfer safeguards (e.g., Standard Contractual Clauses with US partners like Google GTM). Under GDPR Article 83(2), fines for data transfer violations can reach €10M or 2% of global annual turnover.
Finding 6 — Prior Court Actions: Repeat Regulatory Offender

Additional public-record research confirms FID Verlag GmbH is a documented repeat offender — already subject to formal Unterlassungsklagen (cease-and-desist lawsuits) by German consumer protection agencies before this investigation:

  • Verbraucherzentrale Baden-Württemberg vs. FID Verlag GmbH (Case I-96259) — filed at Cologne District Court. Grounds: misleading advertising and illegal hidden subscription contracts. (Source: Bundesjustizamt injunction registry)
  • Verbraucherzentrale Bundesverband vs. FID Verlag GmbH (Case V-121559) — national-level consumer federation action. Grounds: deceptive commercial practices in newsletter marketing.
  • Verbraucherzentrale Baden-Württemberg vs. FID Verlag GmbH (Case III-98245) — second action by Baden-Württemberg consumer agency.

These are not allegations — they are formally registered injunction proceedings in the Bundesjustizamt Verbandsklagenregister (Federal Justice Office class-action registry), publicly searchable. FID Verlag GmbH is aware of its obligations and continues the same practices documented here.

Repeat-offender significance: Prior court actions against the same entity on the same grounds mean any new BaFin or BfDI report lands in a known enforcement context. Regulators can and do escalate fines dramatically for repeat violations after prior warnings. This case is stronger because the behavior is documented and ongoing, not a first occurrence.
Court Actions (Public Record)
3 confirmed
Registry Source
Bundesjustizamt VKlaReg
Filing Grounds
Misleading Ads / Hidden Contracts
Opposing Counsel
VZ BaWü / VZ Bundesverband
Finding 7 — Honeypot Confirmation: Full Funnel Kill Chain Mapped

On 2026-08-18, a controlled honeypot test was conducted: fresh Proton Mail account, residential VPN exit node, incognito browser session. The target: boersenwissen-aktuell.de — subscribe for the "free PDF" offer. The full funnel was captured end-to-end.

Step 1 — Email delivery confirmed. The confirmation email arrived from fid-nss.de (the activation backend identified in Finding 2). Subject line delivered verbatim:

FROM newsletter@fid-nss.de SUBJECT PDF-Report: Krypto-X: Diese 3 Kryptowährungen explodieren # "explodieren" = active investment prognosis ≡ MiFID II Article 24 violation # No BaFin §34f registration cited. No risk disclosure. No authorized intermediary disclosure.

Step 2 — Hidden dual opt-in disclosed in activation link page. The welcome page displayed a notice that was not visible at signup time:

"Gleichzeitig bestätigen Sie mit dem Klick auf den Button Ihre E-Mail-Adresse und erhalten damit ab sofort den kostenlosen E-Mail-Newsletter 'Millers Krypto-Radar'" # Translation: "By clicking the button you simultaneously confirm your email address # and from now on receive the free newsletter 'Millers Krypto-Radar'" # The secondary newsletter opt-in was never disclosed at the point of signup. # GDPR Art.7 + Art.13 violation: separate consent is required for each purpose.

Step 3 — UWG §7 admission embedded in the newsletter body itself:

"Der Informationsnewsletter 'Millers Krypto-Radar' ist werbefinanziert... Sie erhalten deshalb von Zeit zu Zeit auch Informationen zu anderen interessanten Angeboten" # Translation: "The newsletter is advertising-funded... you will therefore also # receive information on other interesting offers from time to time." # Explicit admission of commercial advertising disguised as editorial content. # UWG §7(2)(3): advertising email requires prior explicit consent for advertising — not just newsletter.

Step 4 — The payment funnel: €1 gateway + illegal return claims. The email linked to a product page for a physical book ("Reich mit Kryptowährungen") offered at "0 €" with a symbolic €1 shipping fee. This is a documented dark pattern known as the "Foot-in-the-Door" technique — extracting card or PayPal credentials for a trivial amount to lower friction for high-value upsells. The product page displayed these verbatim claims visible to retail investors:

"Schon 500 Euro reichen aus, um daraus in nur einem Jahr bis zu 180.000 Euro zu machen." # "Just €500 is enough to turn it into up to €180,000 in just one year." # €500 → €180,000 = 35,900% — operator's own arithmetic; the 36,018% figure below is their exact verbatim claim. # MiFID II Article 24(3) + WpHG §63(6): financial promotions must be fair, clear, not misleading. "Lesen Sie, wie Sie an STEUERFREIE Gewinne von bis zu 36.018% kommen." # "Read how to achieve TAX-FREE returns of up to 36,018%." # A specific mathematical return figure presented as achievable to retail investors # without BaFin investment advisory licence (§34f GewO or WpIG §15) = criminal offence. # StGB §264a (capital investment fraud) threshold: making false statements about # advantageous circumstances of a capital investment. This qualifies.

Step 5 — Affiliate tracking token exposed. The page source contained a hidden tracking string revealing the complete campaign attribution chain:

TRACKING TOKEN 98903TRK5054KOOP_I_MKR_IRW_INV_Krypto-x-diese-3-kryptos-explodieren_X-Uebersichtsseite # Decoded: KOOP = affiliate cooperative network (multi-publisher) MKR = Millers Krypto-Radar (the secondary newsletter confirmed in Step 2) IRW = Investor-Relations-Writer or internal campaign tag INV = Investor segment targeting CAMPAIGN Krypto-x-diese-3-kryptos-explodieren # matches the email subject line verbatim FUNNEL Uebersichtsseite (overview/landing page — confirms multi-page funnel architecture)

Step 6 — Pre-checked subscription upsell on payment page. The checkout page added a Spezialreport "Der neue Dollar" at €2.95/month via a pre-checked checkbox — the consumer must actively uncheck it or the subscription auto-enrolls. This violates UWG §6(2) (hidden additional charges) and the EU Consumer Rights Directive Article 22 (pre-ticked boxes for paid options are illegal in EU commerce).

Criminal threshold crossed: The 36,018% return claim is not a regulatory grey zone. Promising specific mathematical investment returns to retail investors without a BaFin-issued licence triggers StGB §264a (capital investment fraud), a criminal provision carrying up to 3 years imprisonment per count. Combined with the €1 gateway dark pattern, hidden dual opt-in, pre-checked subscription, and three prior consumer court actions, this is a complete, documented commercial fraud funnel — confirmed live by controlled test on 2026-08-18.
Honeypot Date
2026-08-18
Test Method
Proton Mail + VPN + Incognito
Funnel Steps Mapped
6 confirmed
Illegal Return Claim
36,018% (verbatim)
Gateway Price
€1 (Foot-in-the-Door)
Criminal Provision
StGB §264a
Finding 8 — Bait-and-Switch: Step 2 Redirects "Download" to Payment Page

A second email arrived following the initial confirmation. Subject line: "Ihr Download-Link zum kostenlosen PDF-Report" — explicitly promising a download link for the free PDF report the user signed up for. This email never delivered the PDF. Clicking the prominent "Download" call-to-action button opened a new checkout page at lpm.fid-shop.de, not a file download. This is a textbook bait-and-switch: the commercial offer (free PDF) is substituted at point of fulfilment with a secondary sales funnel. UWG §5 applies directly.

The new page immediately launched a fresh upsell: "Wählen Sie jetzt Ihr Geschenk aus" (Choose your gift now), offering three physical books allegedly worth €39.90 each, displayed as "0 €" — again gated behind a €1 symbolic shipping fee, repeating the foot-in-the-door credit card capture mechanic documented in Finding 7.

# Second email — subject vs. delivered action SUBJECT Ihr Download-Link zum kostenlosen PDF-Report # "Your download link for the free PDF report" CTA TEXT Download CTA HREF → lpm.fid-shop.de # payment page, not a file download # UWG §5(1): misleading about essential characteristics of a commercial offer # Distance Selling Dir. 2011/83/EU Art.6: seller must deliver what was promised before contract

Fresh unlicensed MiFID II claims on the payment page. The copy on lpm.fid-shop.de contained new unsolicited financial return promises directed at retail visitors:

"Der Traum, Millionär zu werden, ist für viele greifbarer denn je..." "...fahren Sie unglaubliche Gewinne ein!" # "The dream of becoming a millionaire is closer than ever..." # "...make incredible profits!" # MiFID II Art.24(3): marketing communications must not mislead retail clients # WpHG §63(6): investment information must be fair, clear, not misleading # No risk warning. No BaFin licence cited. No disclaimer. Presented as achievable outcome.

Second tracking token decoded. The page source revealed a new backend attribution string, structurally distinct from the first-step KOOP token. The system has shifted from lead-capture mode into product-order processing mode:

TOKEN 1 (Step 1 — lead capture) 98903TRK5054KOOP_I_MKR_IRW_INV_Krypto-x-diese-3-kryptos-explodieren_X-Uebersichtsseite # KOOP affiliate network → newsletter subscription → lead harvest TOKEN 2 (Step 2 — product order) 80466TRA5024WEB-PB_FKD_ONL_SHOP_OA_TRA-80466-PRODUKTBESTELLUNG_X # Decoded: WEB-PB = web payment/billing segment FKD = FID Kunden-Daten (customer data processing module) ONL_SHOP = online shop backend (lpm.fid-shop.de) OA = order acquisition PRODUKTBESTELLUNG = product order — backend billing trigger, not marketing # The token shift from KOOP → PRODUKTBESTELLUNG proves this is a deliberate # two-stage pipeline: Stage 1 harvests consent/contact, Stage 2 monetises via card capture. # Both stages tracked in the same backend system under different attribution namespaces.

Infrastructure note: lpm.fid-shop.de is a subdomain of fid-shop.de — a dedicated e-commerce domain operated by FID Verlag GmbH, separate from the lead-generation infrastructure (fid-nss.de) and the front-end ad domain (boersenwissen-aktuell.de). This confirms a three-layer infrastructure: ad domain → activation backend → payment backend. Each layer uses a distinct domain and tracking namespace, deliberately compartmentalised to reduce regulatory surface area per domain.

Bonus IOC: broken mail template variables in received emails. Both emails received during the honeypot test contained unrendered dynamic date placeholders visible in subject lines:

Insider-Wissen {year.plus90Days}: So können... Gewinn-Chancen {year.plus90Days}: Dieses... Nächster Boom in {year.plus90Days} steht... # {year.plus90Days} is an unresolved template variable from a bulk mail automation engine # The rendering pipeline failed — the dynamic date did not substitute # Confirms: bulk email automation stack (likely Inxmail, Mailingwork, or similar German ESP) # Intelligence value: broken tokens fingerprint the specific template engine + reveal # that these emails are programmatically generated, not manually written # Corroborates large-scale mass-mail operation, relevant to BfDI volume assessment
Complete funnel kill chain confirmed: Layer 1 (boersenwissen-aktuell.de) baits with extreme return claims. Layer 2 (fid-nss.de) locks in consent via mandatory email activation. Layer 3 (lpm.fid-shop.de) substitutes the promised PDF with a payment screen demanding card or PayPal details, embedding additional illegal MiFID II claims and a pre-checked subscription. The promised free content is never delivered — it exists only to initiate the card-capture pipeline. Every step documented with verbatim evidence from a live honeypot run on 2026-08-18.
New Domain Uncovered
lpm.fid-shop.de
Bait-and-Switch Type
PDF promised → payment page delivered
Token Stage
PRODUKTBESTELLUNG (order processing)
Total Infrastructure Layers
3 (ad → activation → payment)
Applicable Law
UWG §5 · EU CRD Art.6 · MiFID II Art.24
Evidence Method
Live honeypot — 2026-08-18
Reporting Actions Taken

Different threat class from Cases 001-005 — regulatory compliance violations by an identified, established company. Reporting to financial and data protection regulators is fully protected activity under German law (§4d FinDAG whistleblower framework). FID Verlag GmbH cannot sue for truthful regulatory complaints filed in good faith with documented evidence.

BaFin — Federal Financial Supervisory Authority

Reported to bafin@bafin.de. boersenwissen-aktuell.de makes specific unlicensed investment recommendations ("these 3 cryptos will EXPLODE!", "surpass Bitcoin") without a BaFin §34f GewO registration or MiFID II authorization. The "ZDF Krypto-Experte Markus Miller" branding implies public broadcaster endorsement without evidence. Operator: FID Verlag GmbH / Investor Verlag, Bonn (kundenservice@vnr.de, 0228 9550-400).

BfDI — Federal Data Protection Commissioner

Reported to poststelle@bfdi.bund.de. Cookie consent popup explicitly admits transferring subscriber data to US third parties without an adequate legal basis — a direct Article 44 GDPR violation. The multi-affiliate opt-in system (FID NSS, three separate newsletters) collects emails without clear disclosure of all downstream data controllers.

Verbraucherzentrale NRW — Consumer Protection

Reported via https://www.verbraucherzentrale.nrw/kontakt. Misleading advertising for financial products targeting retail investors — claims of guaranteed profits, minimization of losses ("50% loss? No problem!"), and misleading "expert" credentials violate UWG §5 (misleading commercial practices). Operator is based in NRW (Bonn — 0228 area code).

Verbraucherzentrale Baden-Württemberg — Prior Legal Action

Reported via https://www.verbraucherzentrale-bawue.de/kontakt. VZ BaWü has filed two prior injunction proceedings against FID Verlag GmbH (Cases I-96259 and III-98245) for the same misleading advertising and hidden subscription practices. This report adds new documentary evidence: boersenwissen-aktuell.de is a currently live continuation of those practices, with verbatim advertising claims and opt-in mechanics photographically captured and decoded.

AWS Abuse

Reported to abuse@amazonaws.com. AWS S3 + CloudFront infrastructure is hosting content that facilitates unlicensed financial advice and GDPR-violating data collection. AWS ToS Section 3 prohibits "deceptive, fraudulent, illegal, or misleading activities."

Method — How This Was Found & What Makes It Different

Phase 1 — Infrastructure: DNS lookup revealed AWS Route 53 nameservers. HTTP headers confirmed AmazonS3 + CloudFront. Page age from S3 ETag (2026-06-17). TXT records confirmed active Google, Facebook, and Pinterest ad campaigns.

Phase 2 — Operator attribution: Cookie consent footer text contained the publisher name, phone number, and company directly. Customer service email in disclaimer linked to VNR parent company. Pixel tracker domain (vnr-advance.de) confirmed the full corporate tree.

Phase 3 — Affiliate network mapping: The data-nss-affiliate parameters in the embedded form sources decode the entire distribution network — source, newsletter, campaign, and partner all readable in plain text from the page source.

Phase 4 — Legal analysis: Investment claims extracted verbatim, cross-referenced against MiFID II Article 24 requirements for financial marketing communications. GDPR violation lifted directly from the cookie consent text the operator published themselves.

This case demonstrates a different OSINT skill set: Regulatory intelligence from open sources — identifying financial compliance violations without any technical exploitation. The operator disclosed their identity, their data practices, their affiliate network, and their misleading claims in their own page source. The investigator's job was to read, decode, and cross-reference against applicable law. This is compliance OSINT — equally valuable to financial regulators as technical IOC extraction is to law enforcement.
IOC Table
Domain boersenwissen-aktuell.de Lead-gen site IP Range 108.156.60.0/14 AWS CloudFront (AMS1) NS *.awsdns-*.{org,uk,com,net} Route 53 GTM GTM-KQ2VBR · GTM-KSD949H Pixel cdn.static.vnr-advance.de Form System fid-nss.de © FID Verlag GmbH Shop shop.investor-verlag.de Parent Domain vnr.de Verlag für die Deutsche Wirtschaft AG Phone +49 228 9550-400 Bonn, NRW, Germany Email kundenservice@vnr.de Aff Code KOOP_I_MKR_IRW_INV_* Millers Krypto-Radar Aff Code KOOP_I_ISD_IRW_INV_5-TOP-AKTIEN ISD newsletter Aff Code KOOP_I_DM_IRW_INV_MEGATRENDS DM newsletter Payment Domain lpm.fid-shop.de Step 2 card-capture backend (fid-shop.de) Tracking Token 98903TRK5054KOOP_I_MKR_IRW_INV_* Step 1 lead-capture (affiliate) Tracking Token 80466TRA5024WEB-PB_FKD_ONL_SHOP_OA_TRA-*-PRODUKTBESTELLUNG_X Step 2 order processing
Live Evidence — Screenshot Captured 2026-08-16

Headless browser screenshot of boersenwissen-aktuell.de captured during investigation. Clearly shows the Investor Verlag logo, the cookie consent popup admitting non-EU data transfers, and the visible claim "alle drei Coins haben das Potenzial … die Erfolgsstory des Bitcoin zu übertrumpfen" (all three coins have the potential to surpass Bitcoin's success story).

boersenwissen-aktuell.de — INVESTOR VERLAG / FID VERLAG GMBH ⚠ UNLICENSED ADVICE
Screenshot: boersenwissen-aktuell.de investor newsletter lead-gen

Screenshot captured with headless Chromium. Cookie consent popup visible — admitted GDPR Article 44 violation in plain text.

Live Infrastructure Status
Loading status…
Previous: Case 005 — Amazon PhaaS Next: Case 007 — Netflix PhaaS
SevinOS BLE Radar