Executive Summary
In September 2025, Eurojust and European law enforcement agencies coordinated the arrest of five individuals linked to an extensive cryptocurrency investment fraud ring that defrauded victims of over €100 million ($118 million) across at least 23 countries. Operating mainly out of Spain, Portugal, Italy, Romania, and Bulgaria, the suspects lured victims with promises of high returns from fake crypto investment platforms before illegally transferring funds using sophisticated laundering channels. The campaign targeted high-net-worth individuals in France, Germany, Italy, and Spain, and the operation included simultaneous raids and seizures of assets, including bank accounts and electronic devices.
This case highlights the persistent threat of cross-border financial crimes leveraging digital currencies and online investment schemes. The complexity and scale of the operation reflect a broader shift towards technology-enabled fraud, making swift international law enforcement collaboration and strong cyber defense practices more critical than ever.
Why This Matters Now
With digital investments becoming increasingly mainstream, highly organized fraud rings are exploiting gaps in cross-border controls and encrypted financial transactions. The urgency lies in rapidly evolving criminal tactics, regulatory scrutiny, and the demand for stronger monitoring and cybersecurity measures to protect individuals and institutions from large-scale, technology-driven financial scams.
Attack Path Analysis
The attackers initiated their scheme by compromising cloud-based investment or customer portals, likely via phishing or credential reuse. They escalated privileges to access sensitive financial applications or data. Lateral movement occurred as attackers pivoted through cloud workloads and internal east-west networks to expand access across multiple regions or environments. Command and control was maintained using covert channels to coordinate fraudulent activity and bypass cloud monitoring. Exfiltration involved moving stolen funds and personal data out through egress channels and cloud APIs. The impact was significant, with over €100M defrauded from victims across 23 countries through unauthorized financial transactions.
Kill Chain Progression
Initial Compromise
Description
Attackers gained access to cloud-based financial environments—potentially by phishing employees or tricking victims into submitting credentials via fake investment sites.
MITRE ATT&CK® Techniques
Phishing
Spearphishing Link
Valid Accounts
Obtain Capabilities: Tool
Phishing for Information
Web Service
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Policies on Risk Analysis and Information System Security
Control ID: Article 21(2)(a)
DORA – ICT Risk Management Framework
Control ID: Article 6
PCI DSS 4.0 – Incident Response Plan
Control ID: 12.10
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: Section 500.02
CISA ZTMM 2.0 – Continuous Identity Verification and Policy Enforcement
Control ID: Identity Pillar / Policy Enforcement
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Primary target for €100M cryptocurrency investment fraud schemes requiring enhanced egress security, anomaly detection, and zero trust segmentation across multi-jurisdictional operations.
Investment Banking/Venture
High-risk exposure to sophisticated online investment frauds targeting 100+ victims, necessitating threat detection capabilities and encrypted traffic monitoring for client protection.
Capital Markets/Hedge Fund/Private Equity
Vulnerable to elaborate cryptocurrency fraud schemes spanning 23 countries, requiring multicloud visibility, policy enforcement, and advanced threat intelligence for investor security.
Investment Management/Hedge Fund/Private Equity
Critical exposure to cross-border financial fraud operations demanding comprehensive east-west traffic security, anomaly response systems, and regulatory compliance frameworks.
Sources
- Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countrieshttps://thehackernews.com/2025/09/eurojust-arrests-5-in-100m.htmlVerified
- Eurojust coordinates action to halt cryptocurrency fraud of over 100 million euros across Europehttps://www.eurojust.europa.eu/news/eurojust-coordinates-action-halt-cryptocurrency-fraud-over-100-million-euros-across-europeVerified
- Inside Europe’s Largest Crypto Fraud Takedown: Five Arrested After Scam Targeting 23 Countries Since 2018 and Stealing Over €100 Millionhttps://www.coinlive.com/news/inside-europe-s-largest-crypto-fraud-takedown-five-arrested-after-scamVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, cloud egress policy enforcement, encrypted traffic, and anomaly detection would have limited attacker movement, prevented unauthorized outbound transfers, and enabled real-time detection of fraudulent activity, thus constraining the attack at multiple stages within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Segmentation limits unauthorized access to sensitive resources even upon initial compromise.
Control: Zero Trust Segmentation
Mitigation: Fine-grained identity policies restrict privilege escalation opportunities.
Control: East-West Traffic Security
Mitigation: Lateral movement is detected and controlled, containing attacker spread.
Control: Egress Security & Policy Enforcement
Mitigation: Suspicious C2 communications are blocked or detected in real time.
Control: Cloud Firewall (ACF) & Inline IPS (Suricata)
Mitigation: Outbound data theft is detected and prevented.
Anomalous activity triggers alerts and immediate response actions.
Impact at a Glance
Affected Business Functions
- Investment Services
- Financial Transactions
- Customer Support
Estimated downtime: N/A
Estimated loss: $118,000,000
Personal and financial data of over 100 victims across 23 countries were compromised, leading to significant financial losses and potential identity theft risks.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and least privilege across all cloud workloads and user identities.
- • Implement strict egress filtering and outbound policy enforcement to detect and block unauthorized data or fund transfers.
- • Deploy inline intrusion prevention (IPS) and advanced threat detection to monitor for C2, credential abuse, and lateral movement.
- • Ensure high-performance encryption (MACsec/IPsec) is enabled for all data in transit, securing sensitive financial workflows.
- • Centralize multicloud visibility and adopt continuous anomaly response to rapidly identify and remediate emerging threats.



