Europol takes down SIM farm network that scammed thousands of victims
The sophisticated operation led to crimes from simple phishing to investment fraud
Latvian police have arrested seven people over a cybercrime as a service operation that had been defrauding thousands of victims across Europe.
The group had set up technically sophisticated infrastructure for a series of fraud schemes, offering telephone numbers registered to people from more than 80 countries for use in criminal activities.
Fraudsters set up almost 50 million fake accounts for social media and communications platforms, which were then used for a range of different cybercrimes.
The law enforcement operation, codenamed SIMCartel, was carried out by authorities from Austria, Estonia, Finland, Europol and Eurojust and took place on 10 October. Law enforcement took down five servers and seized 1,200 SIM box devices and 40,000 active SIM cards.
Two websites that had been offering the illegal service – gogetsms.com and apisim.com – have now been taken over by law enforcement, while €431,000 ($374,500) in bank accounts and $333,000 in crypto accounts has also been frozen.
Law enforcement also seized four luxury vehicles as part of the operation.
Europol said the outfit was professionally organized, featuring a sophisticated website and an efficient logistics operation.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"The criminal network offering this service enabled its clients to commit a multitude of serious crimes that would not have been possible at all without masking the perpetrators’ identities," said Europol.
The service was mainly used for phishing and smishing, with some perpetrators specializing in fraud on second-hand marketplaces. They used the SIM card service to create a vast number of fake accounts, which then served as starting points for social engineering campaigns.
Other frauds include the daughter-son scam – persuading victims that their child needs financial help – along with investment fraud. Fake investment websites were set up, and, once serious investors showed interest, they were encouraged to pay large sums for alleged good business opportunities.
The criminals also set up fake online shops and fake bank websites, even impersonating police officers with the use of forged IDs, personally collecting funds from the victims.
"Other offences facilitated by this criminal service include fraud, extortion, migrant smuggling and the distribution of child sexual abuse material," Europol added.
More than 1,700 people in Austria fell victim to the scams, with losses of around $5.3 million, along with more than 1,500 in Latvia, who lost a total of $490,000 .
"Measured by volume, more than 49 million online accounts were created on the basis of the illegal service provided by suspects. The damage caused by the renters of the telephone numbers to their victims amounts to several million euros," said Europol. "The true scale of this network is still being uncovered."
MORE FROM ITPRO
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
The trends that will shape workplace culture in 2026In-depth Tech leaders share their insights on how businesses can embrace change across hiring, training, and culture
-
Why the UK is primed to lead a global charge in ‘green AI’ innovationNews UKAI says there are major economic incentives and a big opportunity for the UK to lead the world in green AI development
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
-
LastPass issues alert as customers targeted in new phishing campaignNews LastPass has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign that encourages users to backup vaults.
-
NCSC names and shames pro-Russia hacktivist group amid escalating DDoS attacks on UK public servicesNews Russia-linked hacktivists are increasingly trying to cause chaos for UK organizations
-
An AWS CodeBuild vulnerability could’ve caused supply chain chaos – luckily a fix was applied before disaster struckNews A single misconfiguration could have allowed attackers to inject malicious code to launch a platform-wide compromise
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn
-
Supply chain and AI security in the spotlight for cyber leaders in 2026News Organizations are sharpening their focus on supply chain security and shoring up AI systems
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
NHS supplier DXS International confirms cyber attack – here’s what we know so farNews The NHS supplier says front-line clinical services are unaffected
