700-Agent Call Center Scam Stole €100M/Month

Help Net Security · Medium sophistication
Last updated July 30, 2026

Police say an organized crime group ran around 20 fraudulent call centers with over 700 staff who posed as “financial advisers” to trick people into fake investments. Victims were contacted by phone and online for weeks or months, shown fake profits on fraudulent trading platforms, then pressured to deposit larger amounts, often in cryptocurrency. Authorities also warned that “recovery companies” offering to get money back may be part of the same scam network.

How the attack worked

According to police, an organized crime group ran roughly 20 call centers staffed by more than 700 people who posed as financial advisers. These agents contacted victims by phone and online, sustaining relationships over weeks or even months to build trust before introducing an investment opportunity. Once a victim made an initial deposit, they were shown fabricated profits on trading platforms specifically designed to display fake returns. Believing their investment was succeeding, victims were then encouraged to deposit larger sums, often in cryptocurrency, which is harder to trace and recover.

A second layer of the scheme targeted people after they had already lost money. Police warned that so-called recovery companies offering to retrieve lost investment funds in exchange for an upfront payment may in fact be part of the same fraudulent organization, effectively victimizing people a second time.

Why it succeeded

The scam's effectiveness came from patience and manufactured credibility rather than technical sophistication. Building rapport over an extended period allowed the fraudsters to establish trust before asking for money. The fake trading dashboards gave victims tangible, visible evidence of "success," which made it easier to justify larger deposits. The follow-on recovery company pretext exploited the emotional aftermath of a loss, when victims were most motivated to act quickly to get their money back.

What to watch for

  • Unsolicited calls or messages from someone claiming to be a financial adviser with a time-sensitive opportunity
  • Online dashboards or platforms showing quick or unusually high investment returns
  • Pressure to increase deposits, particularly when payment is requested in cryptocurrency
  • Cold contact from a "recovery company" claiming it can retrieve previously lost funds for an upfront fee

How to build resistance

Employees and consumers should treat unsolicited investment outreach as high-risk by default and independently verify any firm through a regulator registry or a known, previously verified contact number rather than one provided by the caller. Skepticism toward on-screen "profits" is essential, especially when combined with requests for additional deposits or cryptocurrency payments. Organizations should also make clear that legitimate recovery of lost investment funds does not require paying an upfront fee to a third party, and that such cases should be routed to legal, compliance, or law enforcement channels rather than handled informally. Building this awareness across finance teams and leadership, not just general staff, is important since these roles are often specifically targeted given their access to funds and investment decisions.

Key findings

  • Police say the group operated ~20 call centers with 700+ staff posing as financial advisers.
  • The scam used long-running trust-building outreach “by phone and online” over weeks or months.
  • Victims were shown “fake returns” on fraudulent trading platforms to encourage larger follow-on deposits.
  • Deposits were often pushed into cryptocurrency.
  • Police warned secondary “recovery company” scams may be linked to the same criminal organizations.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance teams, Executives/leadership.
  • Affected industries: Consumers/retail investors, Financial services (investment/trading platforms).
  • Attack channels: vishing, website.
  • Impersonated: Financial adviser / investment broker, Recovery company / fund recovery specialist.

Red flags to watch for

  • Unsolicited investment outreach and pressure to act based on “quick profits”
  • Being pushed to deposit larger sums after seeing on-screen “returns”
  • Requests to pay via cryptocurrency
  • Upfront fee required to recover money
  • Cold call referencing prior losses to trigger urgency/emotion
  • Unverified third party claiming special access to get funds back
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake investment call center scam work?

Fraudsters posing as financial advisers contacted victims by phone and online over weeks or months to build trust, then showed them fake returns on fraudulent trading platforms before pushing for larger deposits, often in cryptocurrency.

What is the recovery company scam mentioned alongside this fraud?

Police warned that so-called recovery companies offering to retrieve victims' lost investment funds for an upfront fee may actually be part of the same criminal network, targeting people a second time.

How many people were involved in this call center operation?

Police say the group operated around 20 call centers staffed by more than 700 people posing as financial advisers.

What red flags should investors watch for?

Unsolicited investment outreach, pressure to deposit larger sums after seeing on-screen profits, and requests to pay in cryptocurrency are all warning signs, as is any request for an upfront fee to recover lost funds.

Read the video transcript

Imagine a ‘financial adviser’ calling you, one of 700 people in a fake call center stealing over €100 million a month. They call for weeks, sound legit, then say: “Can you log into our trading platform? Look, you’re already in profit.” The dashboard shows fake returns, then they push you to “just add more”, often in crypto. Then comes the sequel scam: a ‘recovery company’ calls about your loss, “We can get it back, but we need an upfront fee.” Same network, second hit. Your move: if anyone cold-calls you about investments or recovering losses, hang up, and call the firm back using a regulator-listed number or our compliance team’s number you already trust.

Similar attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Impostor Calls Target US Finance With Spoof Sites

Impostor Calls Target US Finance With Spoof Sites

Researchers reported a real campaign against large U.S. financial firms where callers pretend to be coworkers or IT to trick employees into entering passwords and multi-factor codes on spoofed websites. After access is gained, the attackers pressure victims with data-leak threats and demand large…

August 10, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026