Executive Summary
In September 2025, European law enforcement agencies coordinated by Eurojust and Europol dismantled a cryptocurrency investment fraud ring, arresting five suspects linked to more than €100 million ($118 million) in stolen funds. The operation, spanning several countries including Spain, Portugal, Bulgaria, Italy, Lithuania, and Romania, targeted a sophisticated group that lured victims with promises of high returns through professional online platforms. Funds from over 100 victims across 23 countries were diverted into controlled accounts, masked by additional recovery fees and subsequent website takedowns, resulting in substantial losses and significant reputational damage.
This incident underscores the growing scale and sophistication of crypto-based financial fraud targeting both individuals and organizations globally. The case highlights the necessity for robust fraud prevention, regulatory vigilance, and proactive threat detection in the rapidly evolving crypto investment landscape.
Why This Matters Now
Crypto-related investment frauds are accelerating, leveraging increasingly professional online infrastructure to target victims across jurisdictions. As criminals employ advanced tactics and exploit regulatory gaps, organizations and individuals face heightened risks, making timely detection and cross-border cooperation more critical than ever.
Attack Path Analysis
The crypto fraud ring initiated its scheme by luring victims to professionally designed fake investment platforms (Initial Compromise). Attackers established privileged access to manage and operate these platforms and funnel funds (Privilege Escalation). They leveraged internal networking across multiple servers and regions to sustain operations and process illicit transactions (Lateral Movement). Ongoing command and control was maintained through remote infrastructure and covert management of victim and attacker assets (Command & Control). The stolen cryptocurrency and fiat were exfiltrated using transfers to controlled bank accounts and laundering methods (Exfiltration). Lastly, the operation resulted in victim financial losses and laundering of over €100 million, with websites taken offline to finalize the scheme (Impact).
Kill Chain Progression
Initial Compromise
Description
Victims were deceived into interacting with realistic fraudulent cryptocurrency platforms, entering credentials and funding accounts.
Related CVEs
CVE-2025-67890
CVSS 9.3A use-after-free vulnerability in Google Chrome allows remote attackers to execute arbitrary code via crafted HTML pages.
Affected Products:
Google Chrome – < 95.0.4638.69
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing via Service
Spearfishing Link
Phishing for Information: Spearphishing
Acquire Infrastructure: Web Services
Phishing
Gather Victim Identity Information
Fraudulent Transactions
Email Collection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Responding to and Managing Incidents
Control ID: 12.10.5
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art 10
NIS2 Directive – Cybersecurity Risk-management Measures
Control ID: Art 21
CISA Zero Trust Maturity Model 2.0 – Deploy phishing-resistant MFA
Control ID: Identity - Phishing Resistant Authentication
GDPR – Security of Processing
Control ID: Art. 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cryptocurrency fraud targeting €100 million requires enhanced egress security, threat detection capabilities, and zero trust segmentation to prevent investment scam proliferation.
Banking/Mortgage
Cross-border financial fraud operations demand multicloud visibility, encrypted traffic monitoring, and anomaly detection to identify suspicious cryptocurrency transaction patterns effectively.
Investment Banking/Venture
Investment fraud schemes exploiting cryptocurrency platforms necessitate comprehensive policy enforcement, threat intelligence integration, and secure hybrid connectivity for client protection.
Law Enforcement
International cybercrime investigations require advanced traffic observability, inline inspection capabilities, and cloud-native security fabric for effective cross-jurisdictional fraud dismantling operations.
Sources
- Police dismantles crypto fraud ring linked to €100 million in losseshttps://www.bleepingcomputer.com/news/security/police-dismantles-crypto-fraud-ring-linked-to-100-million-in-losses/Verified
- Europol Dismantles €700M Crypto Fraud Network Built on Fake Trading Platforms and Deepfake Celebrity Adshttps://www.cointeeth.com/news/europol-dismantles-700m-crypto-fraud-network-built-on-fake-tradingVerified
- Europol Dismantles €600M Crypto-Fraud Ring in Europehttps://cyber.thomasmurray.com/insights/major-crypto-fraud-ring-uncovered-europolVerified
- Europol Dismantles €700 Million Crypto Fraud Ring in Coordinated International Efforthttps://www.technewshub.co.uk/post/europol-dismantles-700-million-crypto-fraud-ring-in-coordinated-international-effortVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF-driven zero trust segmentation, egress enforcement, encrypted traffic inspection, and enhanced visibility would have limited fraudsters’ ability to maintain illicit platforms, move laterally, exfiltrate funds, and operate undetected across cloud resources. Comprehensive Cloud Network Security Framework controls reduce both the opportunity and dwell time for such broad, cross-border fraudulent campaigns.
Control: Multicloud Visibility & Control
Mitigation: Suspicious or unauthorized application hosting and anomalous external communications could be detected early.
Control: Zero Trust Segmentation
Mitigation: Administrative access would be tightly restricted to authorized identities and isolated segments.
Control: East-West Traffic Security
Mitigation: Unusual lateral movement and cross-region communications would be blocked or alerted.
Control: Cloud Firewall (ACF)
Mitigation: Unauthorized outbound management connections are identified and can be denied.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and can block suspicious large-scale outbound data or money movements.
Rapid identification of anomalous service shutdowns and asset transfers enables faster incident response.
Impact at a Glance
Affected Business Functions
- Investment Services
- Customer Support
- Financial Transactions
Estimated downtime: 30 days
Estimated loss: $700,000,000
Personal and financial data of over 5,000 victims were exposed, including names, contact details, and investment information.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and least-privileged access controls for all workloads and administrative interfaces.
- • Deploy continuous egress policy enforcement and encrypted traffic monitoring to rapidly identify and block unauthorized fund transfers.
- • Mandate centralized, multi-cloud visibility to detect anomalous behavior and shadow infrastructure deployments.
- • Enhance lateral movement controls and microsegmentation to prevent attackers from pivoting across internal resources.
- • Implement automated anomaly and behavioral threat detection for rapid response to platform misuse, exfiltration, or fraud activity.



