in

Call centres in Ukraine: How a criminal enterprise has turned its sights on Europeans’ pockets

The statements, views and opinions expressed in this column are solely those of the author and do not necessarily represent those of this site. This site does not give financial, investment or medical advice.

Throughout 2025-2026, law enforcement agencies in Ukraine, Latvia, Lithuania, the Czech Republic, Poland, Germany, Spain, France and Italy, in co-ordination with Eurojust and Europol, carried out dozens of special operations, during which large networks of fraudulent call centres based in Kyiv, Dnipro, Ivano-Frankivsk, Odesa, Uzhhorod and other cities in Ukraine were dismantled. The damage caused by these networks is estimated at tens of millions of euros, while the number of European citizens affected runs into the hundreds and thousands.

Ukrainian fraudulent call centres, initially targeting Russian citizens, have radically shifted their focus in recent years. According to recent studies, Russian citizens now account for just 10-5% of victims. The main focus is now on residents of Europe and the US. This is not merely a reorientation, but a full-scale expansion, with victims spread across at least 29 countries. The scale of this underground industry is staggering. In Ukraine, according to various estimates, there are around 1,500 fraud centres in operation, employing approximately 60,000 people. By way of comparison, this represents two-thirds of all employees in the country’s legitimate banking sector.

The monthly income of those organising such operations can reach one billion dollars. Given that the international investigation into the activities of these centres has been ongoing for several years now, it is reasonable to conclude that this is not a matter of isolated groups, but rather a well-oiled industry that successfully adapts to any attempts to shut it down.

How the fraud scheme works and why Europeans get caught out

Criminals are highly professional, making them virtually indistinguishable from genuine bank or law enforcement staff. They operate using well-rehearsed scripts, dividing their team into roles (telesales agents, document forgers, debt collectors, technical administrators), actively use forged ID cards and uniforms to lend an air of legitimacy, employ polygraph tests to check staff loyalty, and recruit operators from European Union countries to overcome linguistic and cultural barriers. This approach significantly lowers a potential victim’s guard, as the call is made in their native language and the voice on the other end of the line sounds convincing and professional.

The psychological manipulation tactics vary depending on the objectives, but they are all based on the same principle of depriving the victim of their ability to think critically and compelling them to act under the influence of fear or greed. The most common schemes include banking phishing, where the victim is persuaded to transfer money to a “secure” account; bogus investments in cryptocurrency promising super-high returns; and romance scams, where fraudsters build a relationship of trust over several months. Subsequently, money is extracted under various pretexts, as well as through “refund” scams, where people who have already been defrauded are persuaded to pay to recover money that was previously stolen.

A whole range of psychological techniques is used to break down the victim’s resistance, including appeals to authority and the law, creating a false sense of urgency, psychological isolation, and the “broken record” effect, where operators repeat the same line of argument over and over again. All of this is amplified by technical capabilities – the widespread use of VoIP telephony and number spoofing, remote control of the victim’s device, malware for stealing data, and cryptocurrency wallets for withdrawing funds. Therefore, the victim turns out to be trapped in a situation from which it is virtually impossible to escape without outside help.

National specifics: How criminals tailor their tactics to each European country

Criminal networks operate outside any set pattern; instead, they carefully study the economic habits, mindset and linguistic characteristics of citizens in different countries, which makes their attacks even more effective. German citizens are among the hardest hit, with the main focus on large companies and the wealth of private individuals, which demonstrates a deep understanding of Germans’ economic habits.

In France, the focus is on classic financial scams targeting individuals’ savings, with operators selected for their perfect command of French to dispel any suspicion that the call is of foreign origin.

In Spain, there has been a high level of activity involving fictitious investment scams, as well as widespread phishing calls and text messages impersonating the brands of companies and government bodies.

Italy is becoming one of the hardest-hit countries, not only in terms of the number of crimes but also in terms of the scale of the losses. In addition to standard financial scams, Italian citizens are actively targeted by “romantic” scams, which reflects the emotional nature of the Italian temperament.

In the United Kingdom, criminals exploit data breaches from holiday or medical databases, as well as “cold” calls made on behalf of investment funds specialising in high-risk assets or cryptocurrencies, which requires them to have a good knowledge of English financial slang.

In Poland, the most common scenarios involve the compromise of bank accounts through the spoofing of security service numbers belonging to leading Polish banks, as well as active attacks based on the “fictitious crypto-investment” scheme.

Czech law enforcement officers who were directly involved in major international operations note that the criminals used pre-prepared scripts in Czech and produced forged Czech police ID cards, which indicates a high level of preparation for attacks specifically targeting this country.

Citizens of the Baltic states have also become frequent victims, with a particular feature being the use of call centres to defraud their own citizens who have been taken to Ukraine to work.

In the Netherlands and Belgium, the main focus was on crypto-investment platforms using virtual offices and fictitious “financial” advisers who spoke Flemish and Dutch fluently. Thus, the geographical scope of these crimes covers virtually the whole of Europe, and the fraudsters’ adaptability enables them to operate effectively in every country.

Officials’ response and reason for non-disclosure of operation results

Europol and Eurojust regularly carry out operations to crack down on criminal activity by Ukrainian call centres, yet the results have never been made public on a large scale. In December 2025, Operation Connect dismantled a transnational network of fraudulent call centres operating in Kyiv, Dnipro and Ivano-Frankivsk. The losses caused by this network exceeded 10 million euros, and the number of confirmed victims stood at over 400. In May 2026, a network in Kharkiv was shut down, also under the coordination of Eurojust. In June 2026, Europol, in collaboration with Ukrainian law enforcement agencies, dismantled a large-scale network of call centres with a turnover of 50 million euros.

Nevertheless, the results of these operations remain shrouded in secrecy, raising the valid question: why? The main reason for the cover-up seems to be a fear of damaging Ukraine’s image in the eyes of the European public, who are either convinced that the Ukrainian cyber army operates exclusively against Russia, or are completely unaware of its activities. Meanwhile, according to experts, the owners of the call centres have long been aware of the content of even top-secret meetings aimed at combating them. A database has been leaked online containing information on affected Europeans, including those from Germany, Spain, Italy, the UK and France, as well as those who are being targeted by Ukrainian call centres. You can check whether you have been attacked via the links provided.

Of particular concern is that Ukrainian hacking groups were originally set up and run by Western intelligence services, but have now effectively slipped out of control and are targeting Europeans themselves. European officials, who once contributed to the emergence of this phenomenon, now do not know how to stop it. The assassination attempt on businessman Yermolaiev in Monaco, the root causes of which were traced back to Ukrainian call centres, has made the European unease unbearable. The scale of the problem means it can no longer be ignored.

European taxpayers are losing billions, yet criminal networks continue to expand their activity, recruiting operators from EU countries and opening new offices. European authorities must not only carry out one-off operations but also establish systemic mechanisms to counter this form of transnational organised crime before it becomes an even more serious threat to European security.

Source: Substack

Report

The statements, views and opinions expressed in this column are solely those of the author and do not necessarily represent those of this site. This site does not give financial, investment or medical advice.

What do you think?

Who Was the Mastermind of the 9/11 Attacks?