News: 1714714451

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Europol op shutters 12 scam call centers and cuffs 21 suspected fraudsters

(2024/05/03)


A Europol-led operation dubbed “Pandora” has shut down a dozen phone scam centers, and arrested 21 suspects. The cops reckon the action prevented criminals from bilking victims out of more than €10 million (£8.6 million, $11 million).

The criminal network, which operated call centers in Albania, Bosnia-Herzegovina, Kosovo, and Lebanon, was responsible for "thousands" of daily scam calls, including fake police calls, investment scams, and romance cons.

And the thieves may have got away with swindling even more victims if it hadn't been for a bank teller in Germany.

[1]

Operation Pandora began in December 2023, when a customer asked a teller in Freiburg to withdraw more than €100,000 ($107,247) in cash. This request concerned the bank worker, who soon learned the customer had fallen for a fake police scam.

[2]

[3]

This type of fraud involves a criminal claiming to be a law enforcement officer to pressure victims into paying a large sum of money — usually with a false claim they have missed a fake court date and now face an arrest warrant unless they pay the fine, or some other made-up story.

Thanks to the teller, the bank customer alerted the actual police, who found and arrested the scammer.

[4]

Investigators then probed the victim's phone and discovered "that the telephone numbers used by the perpetrators could be linked to over 28,000 scam calls in only 48 hours," according to [5]Europol .

[6]

Inside one scammer's call center ... note the tacky picture of criminals in the background. Source: Europol

Beginning in December 2023, German investigators deployed more than 100 officers to trace the scam calls back to the source - call centers run by crooks - and then monitored them. That effort resulted in the interception of more than 1.3 million "nefarious conversations."

[7]That call center tech scammer could be a human trafficking victim

[8]'Serial cybercriminal and scammer' jailed for 8 years, told to pay back $1.2M

[9]SIM swap crooks solicit T-Mobile US, Verizon staff via text to do their dirty work

[10]Robocall scammers sentenced in US after netting $1.2M via India-based call centers

Baden-Württemberg State Criminal Police officers had to set up a call center of their own so that they could contact potential victims, warning more than 80 percent of them. The cops estimate over the next four months they saved people over €10 million ($11 million), intercepted over 80 percent of the scam calls, and recorded over 7,500 calls so they could get a warrant for the raids.

They also traced where the calls originated and found that each country's illicit call centers focused on a different type of crime. Bosnia-Herzegovina specialized in debt-collection fraud, Kosovo was a hotspot for banking fraudsters, while Albania leaned into investment scams. Lebanon specialized in prepaid card fraud.

On April 18, more than 60 German officers, along with hundreds of cops in Albania, Bosnia and Herzegovina, Kosovo, and Lebanon, swarmed "dozens" of homes and business. In addition to shutting down 12 call centers and arresting 21 individuals, police recovered data carriers, documents and other electronic evidence, plus cash and other assets totaling €1 million (£8.6 million, $1.1 million). ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjS1w3KrpsTHOtQWvkMhDgAAAJY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjS1w3KrpsTHOtQWvkMhDgAAAJY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjS1w3KrpsTHOtQWvkMhDgAAAJY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjS1w3KrpsTHOtQWvkMhDgAAAJY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.europol.europa.eu/media-press/newsroom/news/operation-pandora-shuts-down-12-phone-fraud-call-centres

[6] https://www.europol.europa.eu/cms/sites/default/files/styles/1400x/public/images/full_hd_1713429837112.jpg

[7] https://www.theregister.com/2023/12/08/human_trafficking_for_cyber_scam/

[8] https://www.theregister.com/2023/11/28/serial_cybercriminal_and_scammer_sentenced/

[9] https://www.theregister.com/2024/04/16/sim_swap_scam_tmobile/

[10] https://www.theregister.com/2023/09/20/court_sentences_two_to_41/

[11] https://whitepapers.theregister.com/



"plus cash and other assets totaling €1 million"

Pascal Monett

So, the rest of the money is where ?

In the pockets of the big boys who never get caught.

Good on shutting down those call centers, but Big Boss will just have more set up.

You need to cut the head off if you want the body to die.

Re: "plus cash and other assets totaling €1 million"

Potemkine!

I fear it's a Hydra and cutting one head won't be enough. But that's better than nothing.

Why is this so prevalent

Khaptain

Having worked with telephony systems and call centers, mostably Avaya, for many years I have never understood how this can go un-traced for so long. Telephone Systems keep track of everything and the operators clearly know which locations are making the most calls..

Someone in Kosovo is making many calls all over Europe everyday and this goes unnoticed. C'mon, the data is there, I would be highly surprised that the Telco Operators are not feeding Interpol, the Police, Secret Services etc with this information on a daily, even hourly basis.

Re: Why is this so prevalent

Necrohamster

They hack into an insecure phone system, use it for a few days and move on.

Caller ID seems to be spoofed in most cases with a number that's in a similar range to the target's. I guess the reasoning is someone's more likely to answer a call from a semi-familiar number?

Telcos seem to be powerless to stop it. How difficult can it be at a network level to block a call that originates in say Germany to a UK number, where the originating caller ID appears to be a UK mobile number and the originating device isn't a mobile device. Pretty difficult? Looks like some additional logic would be needed

I'm sure greater minds than mine could figure out a way if they thought about it for a while

Re: Why is this so prevalent

Anonymous Coward

VoIP complicates this significantly. Caller ID spoofing is easier, plus once you have a service you can use a VPN to access it while hiding your location.

And they're probably hacking into private SIP PBXes which by the nature of being hackable implies that the admin isn't paying much attention so won't be looking at the logs (or may not even have logging turned on)

Re: Why is this so prevalent

imanidiot

I doubt it. Far easier to pay off some of the less reputable phone company to keep schtumm or nowadays probably they're just using some sort of shady VOIP service that makes it impossible to separate the scam traffic from less disreputable users and hides it in the masses. Operations like this don't rely on hacked systems, far too unreliable.

Re: Why is this so prevalent

DJO

Telcos are not powerless to stop it but they have no incentive to stop it. They earn money from calls and it does not matter if the calls are scams or whatever, it's all revenue.

Re: Why is this so prevalent

Khaptain

Hacking in to large PBX's is not so easy, and those that do it usually creates calls to very expensive numbers, thereby generating revenue for themselves ( I know this from experience). Our Telco provides us with alerts and also automatically blocks outgoing when suspicion arises.

Spoofing SIP still requires that the originating calls goes through a Telcos switch, only the number is spoofed, the call is still very traceable at the Telco level.

"Telcos are not powerless to stop it but they have no incentive to stop it. They earn money from calls and it does not matter if the calls are scams or whatever, it's all revenue."

Unfortunately I am prone to believe that this is probably the closest case..

ChoHag

> assets totaling €1 million (£8.6 million, $1.1 million)

I didn't know the pound had fallen so far.

because of network lag due to too many people playing deathmatch