Romanian national Gavril Sandu, 53, has been extradited to the United States and appeared in federal court in Charlotte, North Carolina, over allegations that he participated in a cyber-enabled bank fraud scheme that ran from 2009 to 2010. U.S. prosecutors say the operation compromised small businesses’ VoIP systems and used spoofed, trusted-looking caller IDs to place vishing calls while impersonating banks, tricking victims into disclosing debit card numbers and PINs.
Authorities allege the stolen credentials were used to access victim accounts, encode data onto counterfeit magnetic-stripe cards, and withdraw cash from ATMs through money mule activity, with proceeds shared among co-conspirators. Sandu was indicted in 2017, arrested in Romania in January 2026, extradited on 30 April, and now faces charges of bank fraud and conspiracy that carry a maximum sentence of 30 years in prison if convicted.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Following his extradition, Sandu appeared in U.S. court to answer charges of bank fraud and conspiracy. Prosecutors said he faces up to 30 years in prison if convicted.
Romanian national Gavril Sandu was extradited to the United States to face bank fraud and conspiracy charges related to the vishing scheme. One report specifies the extradition occurred on 30 April 2026, after which he was placed in federal custody in Charlotte, North Carolina.
After years of allegedly evading authorities, Sandu was arrested in Romania in connection with the U.S. case. Reports place the arrest in January 2026.
A U.S. federal grand jury indicted Gavril Sandu on charges tied to the cyber-enabled bank fraud scheme. The indictment was returned on 14 November 2017.
From May 2009 to October 2010, Gavril Sandu and co-conspirators allegedly compromised small businesses' VoIP systems and used vishing calls impersonating banks to steal debit card numbers and PINs. The stolen data was allegedly encoded onto counterfeit magnetic-stripe cards and used for ATM cash withdrawals, with proceeds moved through money mule activity.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.