Security1 publisher3 min readPublished
94 call centres, 1,794 seats, 5,200 SIMs: fraud infrastructure you can actually count
Ukraine's week-long sweep shut 94 impersonation call centres and found 1,794 equipped workstations. The itemised haul is a usable sizing model for anyone tuning fraud detection.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Over the course of a week, Ukraine's National Police, together with the Security Service of Ukraine and the Prosecutor General's Office, conducted a large-scale coordinated operation in various regions of Ukraine, simultaneously checking the infrastructure of fraudulent call centres whose operators posed as bankers, brokers and law enforcement officers, lured people onto fictitious investment platforms and obtained access to their bank accounts.
- In total, 411 searches were conducted and the activity of 94 fraudulent call centres was stopped; 1,794 fully equipped workstations were found on the premises.
- 26 individuals have already been notified of suspicion.
- Seizures during investigative actions included 3,336 units of computer equipment, 1,346 phones, more than 5,200 SIM cards, 90 bank cards, means of access to 20 crypto wallets and 22 vehicles.
- Also seized were about USD 2 million, EUR 64,000, cash in hryvnia, a kilogram of bank gold in bars, and jewellery.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Ukraine's National Police, working with the Security Service of Ukraine and the Prosecutor General's Office, spent a week running simultaneous searches across several regions and stopped the operations of 94 fraudulent call centres whose staff posed as bankers, brokers and law enforcement officers [1]. What makes the announcement useful is not the arrest count but the inventory: the police published enough itemised detail to size the physical footprint of industrial impersonation fraud.
The headline figures are 411 searches, 94 centres closed, 1,794 fully equipped workstations found on the premises, and 26 people served with notices of suspicion [2][3]. Seizures included 3,336 pieces of computer equipment, 1,346 phones, more than 5,200 SIM cards, 90 bank cards, access to 20 crypto wallets and 22 vehicles, alongside roughly USD 2m, EUR 64,000, hryvnia cash, a kilogram of bank gold in bars and jewellery [4][5]. Territorial units worked through 867 addresses of possible call centre activity [6].
Divide those out. That is about 19 staffed seats per centre [1] and roughly 2.9 SIM cards per seat [2]. SIM cards at that ratio are a consumable, not an asset, which means number-level blocklists decay at whatever rate the operator can buy new cards. Computer equipment ran to about 1.9 units per workstation [3]. Only 411 searches came out of 867 candidate addresses, about 47 percent [4], so roughly half of the target list did not convert.
The cash-out side is much narrower. Investigators identified 67 financial instruments used in the offences: 40 bank cards or accounts, 12 crypto wallets and 15 money mules [7]. Across 94 centres, that is fewer than one identified instrument per centre [5]. Call capacity is cheap and replaceable; the accounts that receive the money are not, and that asymmetry is where detection spend belongs.
Behind ordinary-looking offices the police describe administrators, operators, ready-made call scripts, databases of potential victims, purpose-built software and tools for concealing and moving funds [8]. Some centres specialised in finding people interested in investing, collecting their contact details into databases that were then used for calls or sold on to other call centres [9]. Lead lists are a traded good in this market, which means a customer who reports one call has probably already been resold.
Three script families recur: a bank warning about supposedly suspicious transactions or an account block, a broker pitching fictitious investment and crypto platforms, and a recovery-room pitch offering to retrieve money already lost to fraud [10]. The asks were transfers to controlled accounts, taking out loans, disclosing card details and confirmation codes, and installing remote access software on phones and computers [11]. That last one is the hard case for banks, because the session arrives from the customer's own device. A separate line of business sold dietary supplements with no therapeutic properties as treatments for illnesses [12]. Some centres targeted foreign nationals, and in one case Ukrainian and German police are documenting a network that defrauded EU citizens through fake broker platforms and remote access, moving funds via crypto exchanges [13].
Charges fall under parts 4 and 5 of Article 190 and part 3 of Article 209 of the Criminal Code, fraud and legalisation of criminally obtained property, with a maximum of 12 years and confiscation [14][15].
Police say they are still analysing seized equipment and financial transactions to identify victims, total losses, the organisers and the people who handled the laundering [16]. Twenty-six suspects against 94 centres works out to one per 3.6 sites [6], which suggests the seat-level staff are in hand and the organisers largely are not. Two things worth tracking: whether the German joint case produces charges, and whether inbound impersonation reports at EU banks dip measurably now that 1,794 seats have gone quiet. If they do not, the capacity was either replaced quickly or was never the bulk of it.