Ukrainian authorities dismantled 94 fraudulent call centers in a nationwide operation involving the National Police of Ukraine, the Cyber Police Department, the Security Service of Ukraine, the Prosecutor General’s Office, and German law enforcement. Investigators carried out more than 400 searches—reported as 411 raids—and formally identified 26 suspects tied to schemes that targeted victims through fake banking, investment, and law-enforcement impersonation scams.
According to investigators, operators persuaded victims to hand over money, disclose banking access, or install remote-access software, while some operations also marketed bogus medical products. Police seized large quantities of computer equipment, phones, SIM cards, bank cards, cash, vehicles, gold, and tools used to access cryptocurrency wallets, and authorities are now conducting forensic analysis to identify victims, calculate losses, and build cases against organizers, money mules, and laundering networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Police began forensic examinations of the seized equipment after the raids. Investigators said the analysis is intended to identify victims, determine the extent of losses, and gather evidence against organizers, money mules, and money launderers.
Authorities formally notified 26 individuals that they are suspects in the fraudulent call center scheme. The suspects may face charges under Parts 4 and 5 of Article 190 and Part 3 of Article 209 of the Criminal Code of Ukraine, carrying penalties of up to 12 years in prison and confiscation of property.
Ukrainian authorities, working with the Security Service of Ukraine, the Prosecutor General’s Office, and German police, shut down 94 fraudulent call centers involved in investment scams and schemes to gain access to victims’ bank accounts. The operation included 411 searches and seizures of cash, equipment, SIM cards, bank cards, cryptocurrency wallet access tools, vehicles, and gold.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcecyberpolice.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.