Back Darkreading Police Disrupt a €140M Cyber Fraud Ring in Spain
Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.
Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.
Law enforcement agents across three countries and one ocean have disrupted a Spanish cybercrime network and its sophisticated money laundering apparatus.
On July 13, Spain's national police revealed a World Cup semifinal-level takedown of an Iberian criminal gang. The gang employed more than 70 known individuals, in possession of 19 registered companies and nearly 1,000 financial accounts.
Most of those individuals were used to launder cybercrime profits. The hackers at the heart of this operation worked out of two "nerve centers," perpetrating man-in-the-middle (MitM) attacks, CEO impersonation scams, social engineering attacks involving fake invoices, and scams built off fake investment platforms. In all, they managed to steal at least €140 million ($161 million). Authorities tied €61 million of their take to CEO impersonation attacks in 2024.
In all, the authorities seized 15 computers and 170 smartphones from the gang's operations centers. The scale of the takedown is nothing to be scoffed at, and comparable to other recent Europol stings , though it's a relative drop in the bucket compared to larger cybercrime takedowns in Southeast Asia .
Four core members of the scheme were arrested. They included an unnamed "main suspect" who'd recently moved from Spain to Porto, Portugal, and was apprehended alongside his partner in their . Another primary suspect stands accused of running a fraud agency from his , and managing the group's financial infrastructure — a so-called "mule herder." He was arrested while traveling in Panama.
Like many before it, this cyber fraud operation seems to have been bottom-heavy. Authorities named only four individuals involved in malicious cyber activity, with another 67 or more underlings working as their money mules.
Cyber gangs without a cryptocurrency focus have always had to do extra legwork to move and extract cash outside of law enforcement's view, or at least fast enough that law enforcement can't keep up. That might mean coordinating lightning quick runs on hundreds of ATMs , or using some other clever loophole to beat the cops at their game.
"More often than not, [money mules] are illegal immigrants," says Matt Burch, principal security researcher at Atredis Partners. In this case, the heads of the operation recruited international citizens to travel to Spain and work as mules. "Part of the reason behind that is because if they're arrested, they typically get deported before they're interrogated by authorities, which insulates the core group of people" who actually run things.
These mules were made to register companies through which they could open new bank accounts. Revenue moved from the hackers to the mules through 19 corporations, 120 merchant accounts, and 800 bank accounts. Those bank accounts were themselves stratified, such that illicit funds went through multiple layers of financial routing and crossed multiple countries before being physically withdrawn.
Dismantling the financial structures and processes is as important as any other aspect of a cybercrime takedown. "Cybercriminals can replace servers and domains quickly, however, rebuilding a trusted financial network of bank accounts, shell companies, and money mules, is much harder," says Louis Eichenbaum, federal chief technology officer (CTO) at ColorTokens. "Spain's operation should create meaningful short-term disruption, but its lasting impact will depend on whether authorities can convert the seized financial intelligence into additional arrests, asset recovery, and action against the group's remaining infrastructure."
Ideally, Spain's latest law enforcement effort would contribute to its already slightly declining rates of cybercrime — a trend mirrored in some other parts of the world . In its latest nationwide report on the subject, the country's Ministry of the Interior reported that after years of consistent growth, Spanish cybercrime dropped 1.6% in 2024.
Qrator Labs CTO Andrey Leskin, who studies takedowns and threat patterns around botnets, argues that "large-scale law enforcement takedowns are undoubtedly valuable, but they are unlikely to provide a permanent solution to cybercrime."
"Technology evolves much faster than regulatory frameworks and enforcement capabilities, creating an inevitable period of asymmetry between attackers and defenders," he argues. "Another major challenge is that the victim, the attack infrastructure, and the threat actor are often located in different jurisdictions. An organization may be targeted in one country, the attack infrastructure hosted in another, and the operators located in a third. Collecting evidence, coordinating investigations, and ultimately prosecuting those responsible becomes an extremely complex international effort," he points out.
"Ultimately, the discussion should move beyond police versus hackers and toward ecosystem security," he argues. Across different kinds of cybercrime, "Long-term progress will depend not only on dismantling [cybercrime] after it appears, but also on reducing the number of vulnerable devices connected to the Internet, improving baseline security requirements for device manufacturers, strengthening collaboration between vendors, Internet service providers, security companies, and law enforcement, and making large-scale cybercriminal operations much harder to establish and sustain in the first place."
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure
Governing the Agent; Identity Security in the Age of Autonomous AI
Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything
Practical Zero Trust Implementation on a Budget in the Age of Mythos
Building a Risk Based Vulnerability Management Program
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
