
A criminal network generating a million dollars a month has been dismantled by Ukrainian police and the SBU.
AI-generated summary
The network used advertisements on Telegram to lure victims to fake investment platforms.
A million dollars a month, without ever placing a single order. The Ukrainian National Police and the SBU, the country's security service, announced the dismantling of a network of fake investment platforms controlled from kyiv. Sixty-two victims have already been identified in more than twenty countries, including France, Germany, Spain, the United Kingdom, Poland, Canada and Israel. At the head of the system was, according to the authorities, a 25-year-old computer scientist surrounded by armed guards. More than 46 people had been recruited to operate several offices in the Ukrainian capital and its region.
Key Points
Ukrainian police and SBU dismantled a network of fake crypto investment platforms in kyiv, with 62 victims identified in more than 20 countries
Led by a 25-year-old computer scientist and with more than 46 employees, the network generated up to $1 million per month
The trap was based on a false “test transaction” which activated a drain and emptied the victim’s main wallet
34 searches, more than 100 computers, 79 SIM cards and 15 vehicles seized; prosecution can lead to twelve years in prison
Fake investments managed from offices in kyiv
According to official sources, the organization operated as a real business. Developers created the platforms and kept them online despite attempts to block them. Other employees handled calls, customers or office security. At the height of its activity, the network allegedly embezzled up to a million dollars per month, according to the SBU.
Victim recruitment began on Telegram, with advertisements promoting supposedly very profitable crypto projects. Interested people created an account, connected a wallet and transferred funds that were supposed to be invested.
However, no real operation was carried out. Employees manually edited dashboards to show increasing balances and make it appear that investments were producing profits.
The registration and verification process also allowed the group to collect personal data: copies of passports, photographs, telephone numbers, email addresses, usernames and passwords.
The test transaction which allowed the wallets to be emptied
The trap was closed when customers demanded their money back. Withdrawals were then blocked under various pretexts. To resolve the issue, the victim had to connect their main wallet and approve a small “test transaction” presented as a simple technical verification.
This validation actually granted the malicious device integrated into the site the ability to transfer assets to addresses controlled by the group. Once the funds were moved, the victim also lost access to their account on the fake platform.
Investigators found the servers containing the organization's database in the Netherlands. This listed the victims, their wallet addresses, the amounts stolen, internal correspondence and detailed information on the operation of the sites.
During 34 searches carried out in kyiv and its region, authorities seized more than 100 computers, more than 100 phones, 79 SIM cards, a GSM gateway, cash and 15 vehicles. Several cars and assets had been registered in the names of the suspects' wives or relatives.
The prosecution was initiated on the basis of part 5 of article 190 of the Ukrainian Criminal Code, dedicated to fraud committed by organized gangs or on a very large scale. The investigation continues to identify the other participants, find new victims and establish the total amount of embezzled funds.
AI outlook — possibilities, not facts
Legal proceedings against arrested suspects.
Very likely · Within months

Berlin refused to pay a ransom of 30 bitcoins to the Rhysida group after a computer hack. In retaliation, hackers published 1.4 million confidential files on the dark web, exposing sensitive personal and administrative data.

In Vern-sur-Seiche, attackers kidnapped and assaulted a family, thinking they were targeting the owner of the house, a cryptocurrency holder who was absent from the premises. An investigation is underway by the Rennes Research Section.

In San Francisco, former Google engineer Linwei Ding was sentenced to 12 months in prison for the theft of 1,255 confidential documents on AI. The judge dropped the economic espionage charges due to lack of evidence of a direct link with Beijing.

The Paris prosecutor's office has confirmed the indictment and provisional detention of an 18-year-old man suspected of belonging to the ZeroBytes group, the claimed author of the massive hacking of the DGFiP this summer. A second minor suspect under the age of 16 was released after being taken into custody. This case directly concerns cryptocurrency holders due to the increased risk of wrench attacks facilitated by the leak of 678,000 tax files containing sensitive data.

Gwangju police arrested four Uzbek nationals in April suspected of financing the terrorist group Katibat Tawhid wal Jihad by sending 4,267 USDT in seven transfers between August 2024 and April 2025. The alleged ringleader received cryptocurrencies from the group, converted them into eleven used cars and two excavators shipped to Syria, and is now in pre-trial detention in court. The other three are being prosecuted without incarceration. The investigation is based on South Korea's anti-terrorist financing law and the travel rule, while the suspects claim that the money was used to support family needs.

A fraudulent site imitating a GTA 6 fan page is offering a “leaked” copy of the game to steal cryptocurrencies. The site uses a “wallet drainer” to siphon assets from users connecting their digital wallet.