Key Highlights
- Polish authorities arrested four members of an organized cybercrime group.
- The operation was conducted with support from the FBI and HSI agents.
- Suspects allegedly used SIM-swap attacks to hijack crypto exchange accounts and steal digital assets.
Polish authorities have dismantled an organized cybercrime group accused of carrying out sophisticated SIM-swap attacks, cryptocurrency theft, and large-scale money laundering operations, according to an announcement from the Central Bureau for Combating Cybercrime (CBZC).
According to the official release, the operation was conducted with active support from U.S. federal agencies, including the Federal Bureau of Investigation (FBI) and Homeland Security Investigations (HSI). Authorities arrested four individuals believed to be key members of the criminal network.
The investigation is being supervised by the Regional Prosecutor’s Office in Kraków.
How the SIM-Swap scheme worked
According to investigators, the suspects systematically targeted IT systems belonging to entities that cooperated with telecommunications operators. Authorities said the group used a combination of specialized software and social engineering techniques to gain unauthorized access to employee email accounts and telecommunications infrastructure.
The stolen information allegedly enabled the attackers to carry out SIM-swap attacks, allowing them to clone and hijack victims’ phone numbers.
Once control of a victim’s phone number was established, the perpetrators reportedly gained access to SMS messages and email communications, enabling them to bypass security measures and take over cryptocurrency exchange accounts.
Crypto accounts became main target
Investigators said the group focused on gaining access to digital asset accounts, where they allegedly stole cryptocurrency holdings from victims after taking control of their communications channels.
Authorities described the operation as a highly organized criminal enterprise that relied on cyber intrusion, identity compromise, and financial laundering to generate revenue. The CBZC said the perpetrators turned the activity into a regular source of income and operated within a structured criminal organization.
After stealing the funds, the suspects allegedly moved the proceeds through a distributed network of bank accounts, international payment platforms, and multi-currency cryptocurrency wallets. Authorities estimate that the value of the laundered assets exceeded tens of millions of Polish zlotys.
Investigators said the laundering infrastructure spanned multiple jurisdictions, making it difficult to trace the movement of stolen funds and identify the ultimate beneficiaries.
Accused face serious charges
The four individuals were charged with participation in an organized criminal group, hacking-related theft, and money laundering offenses. Polish authorities noted that the charges carry penalties of up to 25 years in prison.
Following requests from prosecutors, a court ordered all four suspects to remain in pre-trial detention while the investigation continues.
Crypto crime continues to evolve
The Polish case is the latest example of how cryptocurrency-related crime is evolving beyond conventional exchange hacks and malware attacks.
In May, blockchain investigator ZachXBT helped expose an alleged $19 million cryptocurrency theft operation involving Dritan Kapllani Jr., who was accused of using social engineering tactics to gain access to victims’ digital assets. Authorities also charged meme coin influencer YeloTree for allegedly laundering stolen funds through a Miami-based rental car business.
Around the same time, the U.S. Department of Justice charged three Tennessee men accused of orchestrating a $6.5 million crypto theft scheme in California, allegedly using disguises and physical intimidation to gain access to victims’ cryptocurrency wallets.
Together, these cases highlight how criminals are increasingly combining cyberattacks, social engineering, identity theft, financial fraud, and even physical coercion to target digital asset holders.
International investigation remains active
The involvement of the FBI and Homeland Security Investigations highlights the growing international cooperation between law enforcement agencies tackling crypto-related crime. Authorities noted that criminal groups increasingly operate across multiple jurisdictions, making cross-border coordination essential for tracking stolen assets and identifying suspects.
The Central Cybercrime Bureau (CBZC) said the investigation remains ongoing and includes a significant international component. Due to the active nature of the case, officials declined to disclose details about the victims, targeted exchanges, or assets seized during the operation.
Authorities added that further information may be released as investigators continue tracing the stolen funds and identifying additional individuals connected to the criminal network. The case serves as a reminder of the risks associated with SIM-swap attacks, which remain one of the most common methods used to compromise cryptocurrency accounts.
Also read: Thailand Hunts Chinese Businessman Over $28M Illegal Crypto Mining Ring

