securitylab_nJuly 18, 2026🇷🇺Translated from Russian

Dutch Police Arrest Leader of 700-Person Investment Scam Network That Stole Over €100 Million Monthly

Police in the Netherlands have detained the alleged leader of an international investment fraud network that operated like a large corporation with more than 700 employees working in approximately 20 offices across multiple countries. The organization is believed to have stolen over 100 million euros per month by posing as financial consultants and convincing victims to transfer funds to fake trading platforms.

The main suspect, a 46-year-old dual Israeli-Polish citizen, was arrested on May 26 at a Polish airport while arriving from Dubai. He was extradited to the Netherlands and remanded in custody for at least 14 days. Authorities describe him as a key figure responsible for the technical infrastructure of the scam and note that he was previously known as a hacker targeted for breaching foreign government systems.

The fraudulent network functioned as a structured company since at least 2021, with one central division overseeing multiple offices. Separate teams focused on specific countries to identify and contact potential victims by phone and online. Employees used the titles of financial consultants and account managers, initially encouraging small investments that appeared profitable on rigged platforms before pressuring victims to deposit much larger amounts, often in cryptocurrency.

In the Netherlands, police have linked the scheme to around 550 complaints involving nearly 25 million euros in losses, with most victims losing more than 10,000 euros. Belgium has recorded approximately 200 additional reports. The total number of victims worldwide is estimated in the tens of thousands. Some victims described devastating personal impacts, including one man who could no longer afford food for his family and another who began contemplating suicide after losing all savings.

Further arrests took place in July. Two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian citizen, were detained in Cyprus. A 25-year-old suspect was arrested in Belgium, and a 44-year-old Dutch national was taken into custody in Athens. Belgian authorities had previously detained five additional employees of the scam centers.

Investigators used financial records, IP addresses, and seized equipment to locate offices and identify suspects. Technology companies hosting the network’s infrastructure assisted in disabling key components, while Europol shared intelligence with multiple countries. Police continue to search for assets that can be frozen or confiscated and warn that victims may face secondary scams from fake “recovery” companies promising to return funds in exchange for upfront payments.

Related articles

HabrFraud & Social Engineering

Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints

Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fitts’s law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.

BoletimSecFraud & Social Engineering

Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics

The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.

BoletimSecFraud & Social Engineering

OpenAI Disables Coordinated ChatGPT Network Used for Financial Scams and Identity Forgery

OpenAI has deactivated a coordinated network of ChatGPT accounts that supported financial fraud, romance scams, and identity forgery operations. Criminals leveraged the AI to generate fake personas, translate conversations, and craft targeted messages aimed at victims across multiple schemes. The investigation originated from reports of suspicious activity observed on WhatsApp. Scammers used the tool to produce forged documents including stock confirmations, legal notices, passports, and fake financial interfaces to increase credibility. Operations typically began on social media or messaging apps, building emotional trust or urgency before requesting deposits, activation fees, or nonexistent fines. Indicators of possible human trafficking and forced labor were also uncovered through job advertisements and internal discussions about worker control in Poipet. OpenAI has blocked the accounts and shared operational indicators with law enforcement and technology companies.

AntiMalwareFraud & Social Engineering

Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels

Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.