Dutch police dismantle €100m-a-month investment scam run out of 20 call centres

A 46-year-old suspected hacker allegedly built the tech backbone of a fraud operation that duped tens of thousands of savers worldwide.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Photoreal editorial news image, 16:9 full-frame edge to edge, dimly lit anonymous open-plan office at night with rows of empty desks, headsets on desks and moni
Share

Key points

  • Dutch police say a fraud ring earned more than 100 million euros ($114 million) a month at its peak, operating since at least 2021.
  • The gang ran 20 call centres with over 700 fake financial advisers across several countries.
  • The main suspect, a 46-year-old Israeli-Polish national with a hacking background, was arrested in Poland on 26 May 2024 and extradited to the Netherlands.
  • Dutch authorities have tied at least 550 fraud reports and $28.6 million in losses to the group so far.
  • Further arrests followed between 7 and 10 July in Cyprus, Greece and Belgium.

The Dutch national police say they have taken down one of the largest investment scam operations they have ever investigated. The numbers are eye-watering. At its peak the ring pulled in more than 100 million euros ($114 million) a month.

This was not a lone scammer with a burner phone. According to the Politie, and as first reported by BleepingComputer, the group ran 20 call centres and employed more than 700 people to pose as financial advisers.

The alleged ringleader is a 46-year-old man with both Israeli and Polish citizenship. Police arrested him in Poland on 26 May and extradited him to the Netherlands. Investigators say he has a prior record for hacking foreign government systems, and that his technical skills were what kept the operation hidden from law enforcement for years.

Between 7 and 10 July, more Dutch and Belgian suspects were picked up in Cyprus, Greece and Belgium. Police say more arrests are likely.

How did the scam actually work?

Slowly, and with a lot of patience. The fraudsters spent weeks or months building a friendly rapport with each target before ever mentioning money.

Once trust was established, victims were pointed at slick-looking investment websites. These sites are called fake trading platforms: web dashboards designed to look exactly like a real broker, complete with charts, account balances and profit figures. None of it was real.

The call-centre staff would then coax victims into topping up their "accounts", usually by sending cryptocurrency, which is digital money that moves between wallets and is very hard to reverse once sent. The dashboard would show the balance growing nicely. Behind the scenes, the money was already gone.

When victims tried to withdraw, they were stalled, asked for more "fees", or simply ghosted.

In practice this playbook, sometimes called "pig butchering" in the industry, is one of the most lucrative fraud models running today. The failure mode here is human, not technical. Nothing was hacked on the victim's side. People were talked into wiring their own savings.

Who lost money, and what should ordinary people do?

Dutch authorities have so far linked 550 fraud reports and about $28.6 million in losses to this specific group. Most identified victims lost more than 10,000 euros ($11,400) each. Police believe the true worldwide victim count is in the tens of thousands.

If you or a relative has been contacted by a stranger offering unusually good returns, especially one who wants payment in crypto, treat it as a scam by default. Real regulated brokers do not cold-call you. They also do not push you to send Bitcoin.

Anyone who has already sent money to a platform they found through a cold call or social media DM should stop sending more immediately, screenshot everything, and report it to their national police fraud unit and their bank.

One thing the eventual post-mortem will likely say is that the group survived as long as it did because its infrastructure was well-hidden: pseudonyms, disguised calling locations and layered technical setups. Investigators eventually cracked it by following IP addresses, money trails and seized equipment.

Operational takeaway: if the pitch involves crypto and a dashboard you can't withdraw from, it is not an investment, it is a story.

© 2026 Threat Vectr