Dutch police said they dismantled an international investment fraud operation that allegedly used fake cryptocurrency trading platforms and bogus financial advisers to steal from victims worldwide. Investigators said the network had operated since at least 2021 through roughly 20 to 24 call centers in multiple countries, with more than 700 staff persuading targets to invest and then showing fictitious profits to induce additional payments. Authorities linked at least 550 fraud reports and about $28.6 million in reported losses to the group, while estimating victims in the Netherlands alone lost nearly €25 million and that tens of thousands of people may have been affected globally.
Authorities made multiple arrests across several countries and identified a 46-year-old Israeli-Polish suspect as a central figure in the scheme. The suspect, described as a well-known hacker, was arrested in Poland on May 26 and extradited to the Netherlands; investigators allege he played a key technical and organizational role in helping the group conceal identities, mask call-center locations, and evade law enforcement. Dutch investigators said they traced IP addresses, financial routes, and other digital evidence to map the organization’s infrastructure, and believe the operation at one point generated more than €100 million per month.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The new reference states that Belgian police detained five employees linked to the investment fraud organization. This expands the known enforcement action beyond the previously documented arrests of key suspects in multiple countries.
Dutch and Belgian suspects tied to the investment fraud investigation were arrested in Cyprus, Greece, and Belgium between July 7 and July 10. The arrests expanded the enforcement action beyond the previously noted main suspect and reflected broader international coordination.
Dutch authorities said they dismantled the international investment fraud organization and made multiple arrests across several countries tied to the scheme. Investigators linked the group to tens of thousands of victims worldwide and major financial losses.
After his arrest in Poland, the main suspect was extradited to the Netherlands to face the investigation into the international investment fraud operation.
Investigators said the international investment fraud organization had been operating since at least 2021, using fake investment platforms, call centers, and technical measures to conceal identities and locations.
A 46-year-old Israeli-Polish national identified as a central technical and organizational figure in the fraud network was arrested in Poland on 2026-05-26.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcecysecurity.news
Open sourcetherecord.media
Open sourcepolitie.nl
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.