German-language investment newsletter lead-generation site on AWS S3 making unlicensed investment recommendations ("these 3 cryptos will EXPLODE!") without BaFin authorization. Operator identified as FID Verlag GmbH / Investor Verlag, Bonn. Affiliate tracking codes expose a full multi-publisher distribution network. Cookie consent admits GDPR-violating data sharing with third parties outside the EU.
fid-nss.de and provides verbatim proof of all documented violations, including a live 36,018% return claim crossing the StGB §264a criminal threshold. A second email confirmed the bait-and-switch: the promised PDF was never delivered — clicking "Download" opened a new payment page at lpm.fid-shop.de. Three-layer funnel fully mapped. See Findings 7 and 8.
The site is served as a static HTML bundle from an AWS S3 bucket, distributed globally via CloudFront with edge nodes in Amsterdam (AMS1). The root domain redirects to www.boersenwissen-aktuell.de/index.html, confirming S3 static website hosting. This is a deliberate infrastructure choice: S3 provides virtually unlimited scale at minimal cost, and CloudFront ensures fast delivery — appropriate for a high-traffic lead generation campaign.
The page was built with Brizy (a drag-and-drop website builder), evidenced by the .brz-css-* class namespace throughout the HTML. Content was last updated 2026-06-17 per S3 ETag metadata.
The operator is identified from two direct sources embedded in the page itself:
kundenservice@vnr.de — VNR = Verlag für die Deutsche Wirtschaft AG, the parent company of FID Verlag and Investor Verlag.cdn.static.vnr-advance.de/pixel/0.4/advance-pixel.min.js — VNR Advance is the digital marketing arm of Verlag für die Deutsche Wirtschaft AG.shop.investor-verlag.de/risikohinweise/Investor-Sonderreport-Risikohinweis.pdfThe page makes highly specific investment recommendations without any BaFin license or disclaimer that the operator holds a §34f GewO (financial investment advisor) registration or MiFID II authorization. Under EU MiFID II and the German WpHG (Securities Trading Act), making specific buy/sell recommendations to retail investors requires a license.
The following claims extracted from the page constitute unlicensed investment advice:
The form embed source code reveals a structured affiliate tracking system. Each "free report" download form carries a data-nss-affiliate parameter that encodes the full marketing chain. Decoding these reveals the entire distribution network:
| Affiliate Code | Decoded Meaning | Newsletter |
|---|---|---|
| KOOP_I_MKR_IRW_INV_Krypto-x-diese-3-kryptos-explodieren_X | Cooperation · MKR newsletter · IRW traffic source · Investor category · Krypto-X campaign | Millers Krypto-Radar (MKR) |
| KOOP_I_ISD_IRW_INV_5-TOP-AKTIEN_X | Cooperation · ISD newsletter · IRW traffic source · Investor · 5-Top-Aktien campaign | ISD Newsletter |
| KOOP_I_DM_IRW_INV_MEGATRENDS_X | Cooperation · DM newsletter · IRW traffic source · Investor · Megatrends campaign | DM Newsletter |
What happens when a victim "downloads the free report": They submit their email address through fid-nss.de's form. They are subscribed to one or more investment newsletters (MKR, DM, ISD). The affiliate tracking ensures FID/VNR can attribute the subscription to the traffic source (IRW) and campaign. The newsletters then send ongoing investment "tips" — the classic lead-harvest funnel: create buzz, drive traffic, collect emails, send recommendations. Whether the operator profits from price movements in recommended assets (classic pump-and-dump) was not confirmed through passive OSINT; what is documented is the MiFID II-violating advertising claims and unlicensed investment marketing.
The cookie consent popup, photographically captured during investigation, contains an explicit admission of GDPR-violating data handling. The full text (translated) states:
"Depending on the function, data is thereby transferred to third parties and to third parties in countries outside the EU / EEA where there is no EU-adequate level of data protection and the security authorities of the third country have comparable legal remedies without an adequacy decision applying, or where an adequacy decision applies but its conditions are not met by every company concerned (incl. US companies)."
This statement is a direct admission of GDPR Article 44-49 violations — data transfers to third countries (specifically named: USA) without an adequate legal basis for the transfer.
Additional public-record research confirms FID Verlag GmbH is a documented repeat offender — already subject to formal Unterlassungsklagen (cease-and-desist lawsuits) by German consumer protection agencies before this investigation:
These are not allegations — they are formally registered injunction proceedings in the Bundesjustizamt Verbandsklagenregister (Federal Justice Office class-action registry), publicly searchable. FID Verlag GmbH is aware of its obligations and continues the same practices documented here.
On 2026-08-18, a controlled honeypot test was conducted: fresh Proton Mail account, residential VPN exit node, incognito browser session. The target: boersenwissen-aktuell.de — subscribe for the "free PDF" offer. The full funnel was captured end-to-end.
Step 1 — Email delivery confirmed. The confirmation email arrived from fid-nss.de (the activation backend identified in Finding 2). Subject line delivered verbatim:
Step 2 — Hidden dual opt-in disclosed in activation link page. The welcome page displayed a notice that was not visible at signup time:
Step 3 — UWG §7 admission embedded in the newsletter body itself:
Step 4 — The payment funnel: €1 gateway + illegal return claims. The email linked to a product page for a physical book ("Reich mit Kryptowährungen") offered at "0 €" with a symbolic €1 shipping fee. This is a documented dark pattern known as the "Foot-in-the-Door" technique — extracting card or PayPal credentials for a trivial amount to lower friction for high-value upsells. The product page displayed these verbatim claims visible to retail investors:
Step 5 — Affiliate tracking token exposed. The page source contained a hidden tracking string revealing the complete campaign attribution chain:
Step 6 — Pre-checked subscription upsell on payment page. The checkout page added a Spezialreport "Der neue Dollar" at €2.95/month via a pre-checked checkbox — the consumer must actively uncheck it or the subscription auto-enrolls. This violates UWG §6(2) (hidden additional charges) and the EU Consumer Rights Directive Article 22 (pre-ticked boxes for paid options are illegal in EU commerce).
A second email arrived following the initial confirmation. Subject line: "Ihr Download-Link zum kostenlosen PDF-Report" — explicitly promising a download link for the free PDF report the user signed up for. This email never delivered the PDF. Clicking the prominent "Download" call-to-action button opened a new checkout page at lpm.fid-shop.de, not a file download. This is a textbook bait-and-switch: the commercial offer (free PDF) is substituted at point of fulfilment with a secondary sales funnel. UWG §5 applies directly.
The new page immediately launched a fresh upsell: "Wählen Sie jetzt Ihr Geschenk aus" (Choose your gift now), offering three physical books allegedly worth €39.90 each, displayed as "0 €" — again gated behind a €1 symbolic shipping fee, repeating the foot-in-the-door credit card capture mechanic documented in Finding 7.
Fresh unlicensed MiFID II claims on the payment page. The copy on lpm.fid-shop.de contained new unsolicited financial return promises directed at retail visitors:
Second tracking token decoded. The page source revealed a new backend attribution string, structurally distinct from the first-step KOOP token. The system has shifted from lead-capture mode into product-order processing mode:
Infrastructure note: lpm.fid-shop.de is a subdomain of fid-shop.de — a dedicated e-commerce domain operated by FID Verlag GmbH, separate from the lead-generation infrastructure (fid-nss.de) and the front-end ad domain (boersenwissen-aktuell.de). This confirms a three-layer infrastructure: ad domain → activation backend → payment backend. Each layer uses a distinct domain and tracking namespace, deliberately compartmentalised to reduce regulatory surface area per domain.
Bonus IOC: broken mail template variables in received emails. Both emails received during the honeypot test contained unrendered dynamic date placeholders visible in subject lines:
boersenwissen-aktuell.de) baits with extreme return claims. Layer 2 (fid-nss.de) locks in consent via mandatory email activation. Layer 3 (lpm.fid-shop.de) substitutes the promised PDF with a payment screen demanding card or PayPal details, embedding additional illegal MiFID II claims and a pre-checked subscription. The promised free content is never delivered — it exists only to initiate the card-capture pipeline. Every step documented with verbatim evidence from a live honeypot run on 2026-08-18.Different threat class from Cases 001-005 — regulatory compliance violations by an identified, established company. Reporting to financial and data protection regulators is fully protected activity under German law (§4d FinDAG whistleblower framework). FID Verlag GmbH cannot sue for truthful regulatory complaints filed in good faith with documented evidence.
Reported to bafin@bafin.de. boersenwissen-aktuell.de makes specific unlicensed investment recommendations ("these 3 cryptos will EXPLODE!", "surpass Bitcoin") without a BaFin §34f GewO registration or MiFID II authorization. The "ZDF Krypto-Experte Markus Miller" branding implies public broadcaster endorsement without evidence. Operator: FID Verlag GmbH / Investor Verlag, Bonn (kundenservice@vnr.de, 0228 9550-400).
Reported to poststelle@bfdi.bund.de. Cookie consent popup explicitly admits transferring subscriber data to US third parties without an adequate legal basis — a direct Article 44 GDPR violation. The multi-affiliate opt-in system (FID NSS, three separate newsletters) collects emails without clear disclosure of all downstream data controllers.
Reported via https://www.verbraucherzentrale.nrw/kontakt. Misleading advertising for financial products targeting retail investors — claims of guaranteed profits, minimization of losses ("50% loss? No problem!"), and misleading "expert" credentials violate UWG §5 (misleading commercial practices). Operator is based in NRW (Bonn — 0228 area code).
Reported via https://www.verbraucherzentrale-bawue.de/kontakt. VZ BaWü has filed two prior injunction proceedings against FID Verlag GmbH (Cases I-96259 and III-98245) for the same misleading advertising and hidden subscription practices. This report adds new documentary evidence: boersenwissen-aktuell.de is a currently live continuation of those practices, with verbatim advertising claims and opt-in mechanics photographically captured and decoded.
Reported to abuse@amazonaws.com. AWS S3 + CloudFront infrastructure is hosting content that facilitates unlicensed financial advice and GDPR-violating data collection. AWS ToS Section 3 prohibits "deceptive, fraudulent, illegal, or misleading activities."
Phase 1 — Infrastructure: DNS lookup revealed AWS Route 53 nameservers. HTTP headers confirmed AmazonS3 + CloudFront. Page age from S3 ETag (2026-06-17). TXT records confirmed active Google, Facebook, and Pinterest ad campaigns.
Phase 2 — Operator attribution: Cookie consent footer text contained the publisher name, phone number, and company directly. Customer service email in disclaimer linked to VNR parent company. Pixel tracker domain (vnr-advance.de) confirmed the full corporate tree.
Phase 3 — Affiliate network mapping: The data-nss-affiliate parameters in the embedded form sources decode the entire distribution network — source, newsletter, campaign, and partner all readable in plain text from the page source.
Phase 4 — Legal analysis: Investment claims extracted verbatim, cross-referenced against MiFID II Article 24 requirements for financial marketing communications. GDPR violation lifted directly from the cookie consent text the operator published themselves.
Headless browser screenshot of boersenwissen-aktuell.de captured during investigation. Clearly shows the Investor Verlag logo, the cookie consent popup admitting non-EU data transfers, and the visible claim "alle drei Coins haben das Potenzial … die Erfolgsstory des Bitcoin zu übertrumpfen" (all three coins have the potential to surpass Bitcoin's success story).
Screenshot captured with headless Chromium. Cookie consent popup visible — admitted GDPR Article 44 violation in plain text.