Published Security3 min read
411 searches, 94 call centres, 26 suspects: Ukraine's fraud sweep and the remote-access thread
Police in Ukraine and Germany dismantled 94 investment-fraud and bank-impersonation call centres, seizing 1,794 workstations. The consistent tradecraft: getting victims to install remote-access software.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Authorities in Ukraine shut down 94 fraudulent call centres across the country that lured people into investment scams or tried to obtain access to bank accounts.
- A total of 411 searches were conducted during the operation.
- The operation occurred in the week of reporting and followed an investigation involving the National Police, Ukraine's Security Service, the Prosecutor General's Office and the German police.
- Police seized 1,794 fully equipped workstations and 3,336 pieces of computer equipment.
- Police seized 1,346 phones and 5,200 SIM cards.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Ukrainian authorities shut down 94 fraudulent call centres in a single coordinated week, executing 411 searches with the National Police, the Security Service of Ukraine, the Prosecutor General's Office and the German police [1][2][3]. The scale matters less as a headline number than as a description of an industry: this is not a handful of boiler rooms, it is a labour-intensive sector with staffing, scripts and equipment budgets.
The arithmetic tells you what was being dismantled. Police seized 1,794 fully equipped workstations along with 3,336 pieces of computer equipment [4]. Across 94 centres, that averages roughly 19 seats per site [2], and roughly 4.4 searches per centre closed [1]. Investigators also took 1,346 phones and 5,200 SIM cards [5], close to four SIMs per handset [3], which is the signature of caller-ID churn rather than casual use. Also seized: 90 bank cards, access tools for 20 cryptocurrency wallets, 22 vehicles, 2 million dollars, 64,000 euros and an unspecified sum in hryvnias in cash, plus one kilogram of bank gold in bars and jewellery [6][7].
Twenty-six people have been formally notified that they are suspects [8]. Set that against 1,794 workstations and the ratio is about 69 seats per named suspect [4], which is a reminder that the seat operators are the cheapest and most replaceable part of the model.
The methods are familiar and, according to the Ukrainian police, deliberately segmented. Operators posed as bankers, brokers and law enforcement officers, steered people onto fake investment platforms, and obtained access to their bank accounts [9]. Some called victims claiming suspicious transactions had been detected and threatened to block the accounts unless a payment was made [10]. Some persuaded victims to take out loans and hand over payment card details [11]. Some centres targeted citizens abroad, particularly in the European Union, on fake brokerage platforms [12]. Some ran recovery scams, promising to help victims retrieve money already lost and taking a second cut [13]. Some sold products marketed as medical treatments that had no medicinal properties [14]. Police also found dedicated teams whose only job was identifying people with a genuine interest in investing [15], which is lead qualification by another name.
The thread running through both the domestic and the export-grade schemes is remote-access software installed on the victim's phone or computer [11][12]. That is the step that converts a persuasive phone call into durable control of a device and a session, and it is the step that defeats controls built around blocking external attackers rather than the account holder's own screen. For banks and brokers, the practical implication is that fraud signals need to account for a legitimate customer on a legitimate device being driven by someone else.
Charges under Parts 4 and 5 of Article 190 and Part 3 of Article 209 of Ukraine's Criminal Code carry up to 12 years in prison and confiscation of property [16].
What to watch: the forensic examination of the seized equipment, which police say should identify victims and quantify losses, and should surface evidence against organisers, money mules and launderers [17]. Watch the gap between 26 suspects and the number of organisers eventually charged, and whether the German involvement [3] produces prosecutions of the people who bought the leads and moved the money on the receiving end. Also watch how quickly comparable seat counts reappear elsewhere; 1,794 workstations [4] is a capital cost, not a barrier to entry.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Authorities in Ukraine shut down 94 fraudulent call centres across the country that lured people into investment scams or tried to obtain access to bank accounts.
- [2]
A total of 411 searches were conducted during the operation.
- [3]
The operation occurred in the week of reporting and followed an investigation involving the National Police, Ukraine's Security Service, the Prosecutor General's Office and the German police.
ReportedView cited source - [4]
Police seized 1,794 fully equipped workstations and 3,336 pieces of computer equipment.
ReportedView cited source - [6]
Police seized 90 bank cards, access tools for 20 cryptocurrency wallets and 22 vehicles.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasAug 13Ukraine shuts down 94 fraudulent call centers, seize millions in cash
Additional citations
- Ukrainian police, via BleepingComputer
- Ukrainian police press release



