Sunday, April 6, 2025
HomeCyber Security NewsEuropol Dismantled 50+ Servers Used For Fake Online Shopping Websites

Europol Dismantled 50+ Servers Used For Fake Online Shopping Websites

Published on

SIEM as a Service

Follow Us on Google News

Europol, in collaboration with law enforcement across Europe, has taken down a sophisticated cybercriminal network responsible for large-scale online fraud.

Over 50 servers were seized, a trove of digital evidence was secured, and two primary suspects are now in pretrial detention, marking a significant victory in the fight against cybercrime.

Discovery of a Criminal Network

The investigation, spearheaded by Germany’s Hanover Police Department (Polizeidirektion Hannover) and the Verden Public Prosecutor’s Office (Staatsanwaltschaft Verden), began in late 2022 after reports surfaced of fraudulent phone scams.

Victims were tricked into disclosing sensitive information by callers posing as bank employees.

Free Webinar on Best Practices for API vulnerability & Penetration Testing:  Free Registration

The stolen data was traced to a specialized online marketplace—a central hub for trading illegally obtained personal information, sorted conveniently by region and account balance.

This marketplace served as the foundation for the criminal operation, enabling scammers to purchase targeted data and commit fraud with alarming precision.

Investigators also uncovered an intricate network of fake online shopping websites, designed to phish consumers’ payment credentials. The stolen information was then sold on the marketplace, generating substantial profits for the operators of the scheme.

On December 4, authorities carried out synchronized enforcement actions across several European countries.

Investigations and raids were conducted in Germany and Austria, while the infrastructure supporting the criminal network, including over 50 servers, was dismantled in Germany, Finland, the Netherlands, and Norway.

In total, over 200 terabytes of critical digital evidence were seized, shedding light on the network’s extensive operations.

Two primary suspects—a 27-year-old arrested in Germany and a 37-year-old detained in Austria—are currently facing pretrial detention under European arrest warrants.

Europol’s European Cybercrime Centre (EC3) played a pivotal role in the operation, providing expertise, resources, and intelligence-sharing platforms to assist national authorities.

With its advanced forensic capabilities and a dedicated task force of data scientists, Europol analyzed vast amounts of digital evidence to uncover critical links in the network. On the day of the action, three EC3 experts were deployed to Germany and Austria to support local law enforcement.

The operation is a testament to effective multi-agency cooperation, with contributions from law enforcement agencies in Austria, Czechia, Finland, Germany, the Netherlands, and Poland.

The success of this operation highlights the growing strength of international collaboration in combating cybercrime and protecting digital ecosystems from criminal exploitation.

Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing...

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of...

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM)...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing...

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of...