European law enforcement agencies have dismantled a sophisticated cybercrime network that provided phone numbers and SIM cards to criminals, enabling a wide range of fraudulent activities across Europe. The operation, coordinated by Europol, involved authorities from Latvia, Austria, and Estonia, and resulted in the arrest of at least five to seven individuals, including the alleged organizer of the illicit service. During the raids, police seized 1,200 SIM box devices containing 40,000 active SIM cards, as well as five servers and hundreds of thousands of additional SIM cards. The network operated an online platform that allowed criminals to rent phone numbers registered in more than 80 countries, which were then used to create fake accounts on social media and messaging platforms. These accounts facilitated crimes such as phishing, investment scams, account intrusions, credential and financial data theft, extortion, migrant smuggling, and the distribution of child sexual abuse material. Investigators linked the group to over 3,000 cyber fraud cases, with financial losses exceeding 5 million euros ($5.8 million), primarily in Austria and Latvia. The infrastructure supporting the operation was described as highly advanced and professionally organized, featuring a polished website and a global logistics network for procuring SIM cards. The service appeared to operate as a legitimate business, masking its true purpose and scale. Authorities estimate that more than 49 million online accounts were created using the illicit service, allowing criminals to conceal their identities and locations. The operation, dubbed "SIMCARTEL," involved 26 searches in Latvia and was described by Latvian police as unprecedented in scale and complexity. One of the main suspects had a prior criminal history in Estonia, including arson and extortion. The takedown of this network is considered a significant blow to cybercriminals who rely on anonymous phone numbers to evade detection and law enforcement. Europol emphasized the unique and novel nature of the scheme, noting that it posed a new challenge for European authorities. The successful operation demonstrates the effectiveness of international cooperation in combating organized cybercrime. The seized infrastructure and arrests are expected to disrupt ongoing and future cyber-enabled fraud schemes across Europe and beyond. Authorities continue to investigate the full extent of the network's activities and its connections to other criminal enterprises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Investigators arrested five Latvian nationals and seized servers, SIM-box equipment, SIM cards, and luxury vehicles as part of the takedown. Officials said the investigation was ongoing to determine the full scope of the operation and associated fraud losses.
European law enforcement agencies carried out Operation SIMCARTEL, raiding infrastructure in countries including Latvia, Austria, and Estonia and dismantling the network used to supply phone numbers to scammers. Authorities also took down websites used to rent numbers for criminal activity.
A transnational criminal organization used about 1,200 SIM-boxes and 40,000 SIM cards to rent out phone numbers for phishing, smishing, investment fraud, impersonation, extortion, and the creation of more than 49 million fake online accounts. The activity was linked to more than 3,200 fraud cases and millions of euros in losses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.