Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of carrying out SIM-swapping attacks that led to the theft of millions of U.S. dollars in cryptocurrency. The investigation, conducted with support from the FBI and U.S. Homeland Security Investigations, alleges the suspects breached telecommunications partners’ IT systems and hijacked employee email accounts using specialized software and social engineering to gather data needed to take over victims’ phone numbers.
Investigators said the group intercepted victims’ SMS messages and email communications, then used that access to compromise cryptocurrency exchange accounts and transfer digital assets. Authorities estimate the proceeds were laundered through bank accounts in multiple countries and digital wallets, with total laundering exceeding tens of millions of Polish złoty. The suspects were placed in pre-trial detention and face charges including participation in an organized criminal group, computer system intrusion, theft-related offenses, and money laundering, with the case supervised by the Regional Prosecutor’s Office in Kraków and still under investigation.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Poland's Central Bureau for Combating Cybercrime arrested four suspected members of an organized cybercrime group accused of breaching telecommunications partners, hijacking employee email accounts, conducting SIM-swapping attacks, stealing cryptocurrency, and laundering the proceeds. The operation was supported by the FBI and U.S. Homeland Security Investigations, and the suspects were placed in pre-trial detention and charged with offenses including organized crime participation, computer intrusion, theft-related hacking, and money laundering.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecysecurity.news
Open sourcebleepingcomputer.com
Open sourcecbzc.policja.gov.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.