Security1 distinct publisher3 min readUpdated
Ukraine's week-long sweep shut 94 impersonation call centres and found 1,794 equipped workstations. The itemised haul is a usable sizing model for anyone tuning fraud detection.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Ukraine's week-long sweep shut 94 impersonation call centres and found 1,794 equipped workstations. The itemised haul is a usable sizing model for anyone tuning fraud detection.
Ukraine's National Police, working with the Security Service of Ukraine and the Prosecutor General's Office, spent a week running simultaneous searches across several regions and stopped the operations of 94 fraudulent call centres whose staff posed as bankers, brokers and law enforcement officers [1]. What makes the announcement useful is not the arrest count but the inventory: the police published enough itemised detail to size the physical footprint of industrial impersonation fraud.
The headline figures are 411 searches, 94 centres closed, 1,794 fully equipped workstations found on the premises, and 26 people served with notices of suspicion [2][3]. Seizures included 3,336 pieces of computer equipment, 1,346 phones, more than 5,200 SIM cards, 90 bank cards, access to 20 crypto wallets and 22 vehicles, alongside roughly USD 2m, EUR 64,000, hryvnia cash, a kilogram of bank gold in bars and jewellery [4][5]. Territorial units worked through 867 addresses of possible call centre activity [6].
Divide those out. That is about 19 staffed seats per centre [1] and roughly 2.9 SIM cards per seat [2]. SIM cards at that ratio are a consumable, not an asset, which means number-level blocklists decay at whatever rate the operator can buy new cards. Computer equipment ran to about 1.9 units per workstation [3]. Only 411 searches came out of 867 candidate addresses, about 47 percent [4], so roughly half of the target list did not convert.
The cash-out side is much narrower. Investigators identified 67 financial instruments used in the offences: 40 bank cards or accounts, 12 crypto wallets and 15 money mules [7]. Across 94 centres, that is fewer than one identified instrument per centre [5]. Call capacity is cheap and replaceable; the accounts that receive the money are not, and that asymmetry is where detection spend belongs.
Behind ordinary-looking offices the police describe administrators, operators, ready-made call scripts, databases of potential victims, purpose-built software and tools for concealing and moving funds [8]. Some centres specialised in finding people interested in investing, collecting their contact details into databases that were then used for calls or sold on to other call centres [9]. Lead lists are a traded good in this market, which means a customer who reports one call has probably already been resold.
Three script families recur: a bank warning about supposedly suspicious transactions or an account block, a broker pitching fictitious investment and crypto platforms, and a recovery-room pitch offering to retrieve money already lost to fraud [10]. The asks were transfers to controlled accounts, taking out loans, disclosing card details and confirmation codes, and installing remote access software on phones and computers [11]. That last one is the hard case for banks, because the session arrives from the customer's own device. A separate line of business sold dietary supplements with no therapeutic properties as treatments for illnesses [12]. Some centres targeted foreign nationals, and in one case Ukrainian and German police are documenting a network that defrauded EU citizens through fake broker platforms and remote access, moving funds via crypto exchanges [13].
Charges fall under parts 4 and 5 of Article 190 and part 3 of Article 209 of the Criminal Code, fraud and legalisation of criminally obtained property, with a maximum of 12 years and confiscation [14][15].
Police say they are still analysing seized equipment and financial transactions to identify victims, total losses, the organisers and the people who handled the laundering [16]. Twenty-six suspects against 94 centres works out to one per 3.6 sites [6], which suggests the seat-level staff are in hand and the organisers largely are not. Two things worth tracking: whether the German joint case produces charges, and whether inbound impersonation reports at EU banks dip measurably now that 1,794 seats have gone quiet. If they do not, the capacity was either replaced quickly or was never the bulk of it.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Over the course of a week, Ukraine's National Police, together with the Security Service of Ukraine and the Prosecutor General's Office, conducted a large-scale coordinated operation in various regions of Ukraine, simultaneously checking the infrastructure of fraudulent call centres whose operators posed as bankers, brokers and law enforcement officers, lured people onto fictitious investment platforms and obtained access to their bank accounts.
In total, 411 searches were conducted and the activity of 94 fraudulent call centres was stopped; 1,794 fully equipped workstations were found on the premises.
Seizures during investigative actions included 3,336 units of computer equipment, 1,346 phones, more than 5,200 SIM cards, 90 bank cards, means of access to 20 crypto wallets and 22 vehicles.
Also seized were about USD 2 million, EUR 64,000, cash in hryvnia, a kilogram of bank gold in bars, and jewellery.
Territorial units of the National Police of Ukraine worked through 867 addresses of possible fraudulent call centre operation.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary official inventory, single source, unaudited
The figures come first-hand from the agency that ran the operation and are unusually itemised (searches, centres, seats, devices, SIMs, wallets, financial instruments, legal articles). But it is one publisher with no independent corroboration, no case identifiers, no victim count and no damage total, and the agency's own release says the analysis is still in progress — so the counts are credible as reported yet unverifiable outside the release.
Physically counted infrastructure, one jurisdiction, one week
This is real, seized, enumerated deployment rather than announced intent: 94 operating centres, 1,794 equipped seats and thousands of devices, plus a live cross-border case with German police. It is bounded, though — a single country over a single week, with the money-movement layer traced to under one financial instrument per shuttered centre and most sites lacking a named suspect.
Counts are solid; 'sizing model' framing runs slightly ahead of them
The story's framing — fraud infrastructure you can actually count, usable for tuning detection — leans on figures that are self-reported by the agency running the operation and cover one week in one country. The seat, device and SIM counts support the framing reasonably well; the gap comes from what is absent: no victim or loss totals, 26 suspects against 94 sites, 67 financial instruments against 94 sites, and derived per-seat ratios that assume the seized inventory maps cleanly onto the shuttered centres. Mild overstatement rather than inflation.
Enforcement agency publicising its own operation
The sole source is the communications department of the National Police of Ukraine reporting on a police operation, an arrangement with a clear institutional interest in emphasising scale, seizures and maximum penalties. The incentive is transparent rather than hidden — the release is openly attributed and the legal qualification is specified — but it shapes what is foregrounded (totals, gold, cash, 12-year maximum) versus what is left open (victims, losses, organisers).
Internally consistent single-source official account
Confidence is moderate: the numbers are specific, internally consistent and attributable to the responsible authority, and the tradecraft description matches well-documented impersonation-fraud patterns. It is held down by the absence of any second publisher, the pending state of the investigation, and unquantified damage, all of which would change the picture if later filings differ from the press-release totals.
security
Kimwolf's new flood wears Chrome's fingerprints and takes orders from a blockchain1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026