Dutch Police Arrest Leader of 700-Person Investment Scam Network That Stole Over €100 Million Monthly
Police in the Netherlands have detained the alleged leader of an international investment fraud network that operated like a large corporation with more than 700 employees working in approximately 20 offices across multiple countries. The organization is believed to have stolen over 100 million euros per month by posing as financial consultants and convincing victims to transfer funds to fake trading platforms.
The main suspect, a 46-year-old dual Israeli-Polish citizen, was arrested on May 26 at a Polish airport while arriving from Dubai. He was extradited to the Netherlands and remanded in custody for at least 14 days. Authorities describe him as a key figure responsible for the technical infrastructure of the scam and note that he was previously known as a hacker targeted for breaching foreign government systems.
The fraudulent network functioned as a structured company since at least 2021, with one central division overseeing multiple offices. Separate teams focused on specific countries to identify and contact potential victims by phone and online. Employees used the titles of financial consultants and account managers, initially encouraging small investments that appeared profitable on rigged platforms before pressuring victims to deposit much larger amounts, often in cryptocurrency.
In the Netherlands, police have linked the scheme to around 550 complaints involving nearly 25 million euros in losses, with most victims losing more than 10,000 euros. Belgium has recorded approximately 200 additional reports. The total number of victims worldwide is estimated in the tens of thousands. Some victims described devastating personal impacts, including one man who could no longer afford food for his family and another who began contemplating suicide after losing all savings.
Further arrests took place in July. Two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian citizen, were detained in Cyprus. A 25-year-old suspect was arrested in Belgium, and a 44-year-old Dutch national was taken into custody in Athens. Belgian authorities had previously detained five additional employees of the scam centers.
Investigators used financial records, IP addresses, and seized equipment to locate offices and identify suspects. Technology companies hosting the network’s infrastructure assisted in disabling key components, while Europol shared intelligence with multiple countries. Police continue to search for assets that can be frozen or confiscated and warn that victims may face secondary scams from fake “recovery” companies promising to return funds in exchange for upfront payments.
Related articles
VC.ru Blocks Lawyer's Account After Article Exposing In-Platform Phishing Scheme
A Russian lawyer specializing in IT law and cryptocurrency regulation published an article on VC.ru detailing a phishing operation that abused the platform's own articles. The scheme involved posting seemingly legitimate content that later had links altered to redirect users to fake services stealing crypto assets. Within an hour of publication, the author's four-year-old account was automatically blocked under rules prohibiting multiple accounts to evade bans, despite the author having no prior restrictions or secondary accounts. After formal complaints citing Russian data protection law 152-FZ and consumer protection statutes, the platform reversed the ban but initially reclassified the account as commercial, demanding a monthly fee of 56,000 rubles for indexing. The account status was later restored following further legal correspondence. The incident highlights platform moderation challenges when reporting security threats involving paid accounts on the same site.
Email Graph Analysis Detects Impersonated Suppliers When DKIM and SPF Pass
Security researchers have outlined a practical method to identify business email compromise attempts that bypass traditional authentication checks. The approach relies solely on metadata from mail server logs to build communication profiles between external and internal addresses. By tracking first contact, one-way traffic, dormant periods, unusual sending hours, and domain similarity, analysts can flag high-risk messages requesting payment changes. The technique works against mailbox takeover scenarios where attackers reuse legitimate threads and valid signatures. Implementation uses existing Postfix or Microsoft Exchange logs and requires no new infrastructure beyond daily exports. A simplified version focusing only on lookalike domain detection can be built in a single evening and still catches most supplier impersonation attempts.
Developer Releases PhishIntel Open-Source Tool for Phishing Site Analysis and Risk Scoring
A developer has published PhishIntel, a lightweight Python-based OSINT application designed to analyze domains and evaluate phishing risk. The tool performs extensive checks including domain structure analysis, DNS records, RDAP and WHOIS data, TLS certificates, HTTP redirects, page content, security headers, and JavaScript static analysis. It generates structured JSON reports containing risk scores with explanatory indicators. Optional integrations with VirusTotal, Google Safe Browsing, URLhaus, Nmap, Nuclei, ZAP, and Playwright enable reputation checks, dynamic browser analysis, and active scanning. The project aims to help identify suspicious sites used in schemes such as the recent fake fuel sales campaign that defrauded victims of at least 3.7 million rubles. The author invites feedback from security professionals to improve the codebase.
Russian Court Bans Advertising for Renting and Selling Third-Party Bank Cards
The Chertanovsky District Court of Moscow has ruled that information promoting the rental and sale of other people's bank cards is prohibited for distribution in Russia. The decision targets a website and two Telegram channels that offered users the chance to temporarily lend or permanently sell their cards to third parties. Such schemes are commonly used to recruit drops who help receive, transfer, and cash out stolen funds. The court found that these proposals violate the rights and legitimate interests of citizens. Owners of the resources could not be identified, and domain registrars were foreign companies. VTB had previously warned about these schemes in 2024, noting that card owners risk ending up on bank blacklists, losing access to financial services, and facing criminal charges. The Ministry of Internal Affairs has also highlighted that transferring bank cards and accounts to outsiders can lead to criminal liability, with fraudsters particularly targeting children and teenagers.