94 Scam Call Centers Shut Down: Verify Before Sharing Any Secret
Ukrainian authorities say they shut down 94 fraudulent call centers after 411 searches across the country, disrupting schemes that impersonated banks, brokers and law enforcement to obtain money or access to victims' bank accounts. Police reported that some operators persuaded people to disclose payment-card details, take out loans or install remote-access software on phones and computers. Some of the centers targeted people in European Union countries through fake investment platforms.
The scale is significant, but the precise human impact is not yet known. The Ukrainian Cyber Police confirms the enforcement operation; BleepingComputer independently reports the announcement and its published details. Authorities are still examining seized equipment to identify victims, organizers and the total losses.
What Ukrainian police confirms
According to the Cyber Police statement, the operation involved Ukraine's National Police, Security Service, Prosecutor General's Office and German police. Law enforcement conducted 411 searches and reported stopping the work of 94 fraudulent call centers. Twenty-six people were formally notified that they were suspects.
Police reported seizing large volumes of call-center and payment infrastructure, including workstations, phones, SIM cards, bank cards and access tools associated with cryptocurrency wallets, as well as cash and other assets. Those seizure counts describe evidence collected during the operation; they are not a verified count of victims or completed frauds.
The scams manufactured urgency and authority
The reported scripts followed several paths. Some callers posed as bank employees and warned that a suspicious transaction would cause an account to be blocked unless the target acted immediately. Others promoted fake investments, offered to recover money from an earlier scam, or requested remote access to a device under the guise of assistance.
These approaches share one mechanism: the caller tries to become the victim's trusted recovery channel. Once that happens, a request for a card number, password, one-time code or remote-control session can feel like a security step rather than the attack itself. Encryption cannot repair that identity failure. A secret delivered securely to an impostor is still compromised.
Verification must happen outside the incoming call
Do not rely on caller ID, the caller's knowledge of personal details or a website they send as proof. End the conversation and use a contact route obtained independently: the number printed on the bank card, the institution's official mobile application or a URL typed directly from a known source. A real fraud alert can wait for that verification.
Never install a remote-access tool because an unsolicited caller says it is required. Never disclose a banking password, card PIN, wallet backup, recovery phrase or one-time authentication code. If the person claims to be helping recover money lost in an earlier scam, treat that as a new verification event, not as evidence that they know the case.
A safer response when access may already be exposed
- Disconnect remote access. Take the affected device offline if an unknown party still has control, but preserve useful evidence before deleting software or messages.
- Contact the financial institution independently. Use the official number or application, explain exactly what was disclosed and ask it to protect accounts and transactions.
- Use a known-clean device. Change affected passwords and revoke sessions from a device that was not controlled by the caller.
- Replace exposed factors. Reissue cards, reset compromised recovery methods and re-enroll authentication factors when the bank or identity provider advises it.
- Check connected accounts. A compromised email inbox or mobile account can reopen access even after a banking password changes.
- Report without extending the scam. Preserve phone numbers, messages and transaction references, but do not continue engaging or send additional identity documents.
Organizations need the same discipline for internal secrets
Finance, support and IT teams face a business version of the same pressure. A caller may claim that a vendor integration is failing, an executive needs emergency access or an API token must be replaced immediately. High-impact secret requests should require a named owner, a ticket or change record created through an established system and a callback to a directory entry that the requester did not supply.
For privileged credentials, use two-person review when practical and record who approved the transfer, what system it covers and when it expires. Do not place the plaintext in the incident ticket merely because the request itself has been verified.
Where Secretus fits—and where it does not
After identity, authority and destination are verified, Secretus can help an authorized team deliver a temporary password, API token or recovery code without leaving the plaintext in a persistent inbox or chat. Short-lived one-time links reduce durable copies; Team Split can support pre-planned multi-person release for a high-impact recovery value.
Secretus does not verify a caller, detect a fraudulent investment platform, remove remote access software or recover stolen funds. Never use it to send bank passwords, payment-card PINs, wallet backups or authentication codes to an unsolicited requester. The secure channel comes after independent authorization—not instead of it.
What remains unknown
Authorities have not published a final victim count or aggregate loss figure. The public reporting does not establish that every searched location used every described scam, nor that every seized workstation or SIM card was active. The investigation and forensic review continue, and formal suspicion is not a conviction.
