breach
Poland Arrests SIM-Swap Crew Behind $5M Crypto Theft
2026-06-27

Polish authorities have arrested four people accused of running a polished SIM-swapping operation that siphoned millions from cryptocurrency accounts. The Polish Cybercrime Bureau (CBZC) made the arrests with assistance from the FBI and Homeland Security Investigations in the United States.
The technique was nothing exotic. What made it work was patience and a well-chosen target. Rather than going straight at a telco, the group went after the companies that sit alongside one, the smaller suppliers and partners whose staff happen to have access to customer data. They phished their way into employee email accounts, and from there they had everything they needed.
From inbox to exchange account
With access to the right inbox, the crew could pull the customer information required to clone a victim's phone number. Once the clone was active, every SMS the victim should have received, including two-factor codes and password reset links, landed on the attacker's device instead. Walking into a crypto exchange account after that is largely a formality.
Investigators describe the group as organised and disciplined. Stolen funds moved through bank accounts in several countries and a spread of digital wallets, with laundering totals running into tens of millions of Polish złoty. At current exchange rates, that's at least five million US dollars.
Blockchain investigator ZachXBT identified one of the suspects as Wojtek Kulisz, known online as "Merry," after recognising him in images released from the raid.
Charges and detention
The four are now in pre-trial detention. Charges include membership of an organised criminal group, hacking with intent to steal, and money laundering. The maximum penalty on the table is 25 years.
Where the break-in actually began
This is the detail worth lingering on. The compromise didn't begin at a bank. It didn't begin at a cryptocurrency exchange. It began at a third-party supplier and a member of staff who clicked on the wrong thing.
That sequence is common enough that it should stop being surprising. Big targets are protected. The companies that work next to them often aren't, and a single employee inbox is sometimes all that stands between an attacker and a customer database. From there, the rest of the chain falls quickly:
- Access to customer records held by a telco partner.
- A SIM clone or port request executed on a real victim's number.
- SMS-based two-factor codes intercepted in real time.
- An exchange account drained before anyone notices the phone has gone quiet.
SMS as a second factor has been on borrowed time for years, and cases like this are why. But the weak point this time wasn't really the SMS. It was the human who opened the phishing email at a supplier that most customers have never heard of.
Four arrests is a good week for Polish cybercrime investigators. It doesn't change the shape of the problem. Somewhere out there, another crew is reading the same news and noting which steps the Polish four got wrong, not which ones they got right.