Interpol Dismantles €140 Million BEC Fraud Network Impersonating Executives Across Spain, Portugal and Panama
Police have dismantled an international criminal network that earned €140 million through sophisticated Business Email Compromise (BEC) fraud involving investment scams and the substitution of corporate correspondence. The coordinated operation took place across three countries — Spain, Portugal, and Panama — and led to the arrest of four suspected organizers.
According to investigators, the group managed more than 800 bank accounts and 120 corporate accounts, using 67 intermediaries to facilitate the withdrawal and laundering of illicit funds. The criminals primarily employed the BEC scheme, in which fraudsters impersonate company executives or send forged invoices to convince employees to transfer money to attacker-controlled accounts under the pretext of legitimate business transactions.
Once received, the stolen funds were immediately dispersed across numerous accounts. These rapid chains of transfers passed through banks in multiple jurisdictions, deliberately complicating efforts to trace the ultimate beneficiaries. Law enforcement confirmed that at least €94 million moved through this laundering infrastructure.
Investigation and International Cooperation
The investigation began after authorities detected signs of money laundering linked to 19 related companies. Following the identification of the main suspects, police launched an international operation supported by Interpol and Europol.
Officers conducted searches at six locations in Barcelona, Girona, Tarragona, and Porto. During the raids they seized 15 computers and more than 170 smartphones, devices believed to have been used to orchestrate thousands of fraudulent transfers.
Authorities also froze €3 million in assets, which will be returned to victims. Law enforcement agencies consider the network fully dismantled and its principal organizers detained.
Related articles
Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels
Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.
Russian Interior Ministry Advises Citizens Against Posting Personal Dossiers on Social Media
The Russian Ministry of Internal Affairs has issued a public warning urging citizens to reduce the amount of personal information shared on social networks. Details such as places of study and work, home addresses, and family information should remain outside public profiles to avoid attracting the attention of fraudsters and recruiters. According to materials cited by RIA Novosti, such digital self-portraits allow malicious actors to study potential victims, identify vulnerabilities, and craft personalized communication scenarios. The ministry also recommends avoiding public discussions of personal views and refraining from answering questions from strangers. Users are advised to verify profile ownership before engaging and to block suspicious accounts while reporting them to platform moderators. This marks the second such advisory from the ministry within recent months, following an October 2025 reminder about the risks of exposing full names, birth dates, and other identifiable data.
Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities
A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.
Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers
Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.