breach
€140m Cyber Fraud Ring Taken Down in Spain: 800 Accounts, 67 Mules
2026-07-15

Spanish police have dismantled a cybercrime and money-laundering operation that pulled in around €140 million through investment scams and business email compromise. Four people were arrested across Spain, Portugal and Panama, with raids in Barcelona, Girona, Tarragona and Porto.
The numbers are what make this one worth sitting with for a moment.
An industrial-scale laundry
Investigators say the group ran more than 800 personal bank accounts and 120 business accounts, supported by 67 outside accomplices acting as money mules. Roughly €94 million flowed through the network overall, with another €61 million tied specifically to business email compromise in 2024 alone.
Police called the setup industrial, and that feels about right. Fifteen computers and more than 170 smartphones were seized when the raids went in, which gives you a sense of how many parallel conversations, transfers and forged payment instructions the crew was juggling at any given time.
How it unravelled
The investigation started when Spanish authorities picked up money-laundering signals across 19 linked companies. From there it grew into a joint effort with Interpol and Europol, tracking the network as it moved money through third countries. Two of the suspects had already left Spain but were still working the scheme from abroad when they were picked up.
Around €3 million of the proceeds has been frozen and set aside for victims. It's something, but it's a long way short of what was taken. The rest follows the familiar pattern: funds dispersed through chains of accounts until the trail goes cold.
The bit finance teams should read twice
Strip away the geography and the arrest count and this is, at its heart, a story about ordinary businesses paying invoices that looked fine.
Business email compromise doesn't need malware. It doesn't need a zero-day. It needs someone impersonating a chief executive convincingly enough, or slipping in a fake invoice with updated bank details plausible enough, that a busy finance team approves the payment and moves on with their day.
€61 million in a single year, from a single network, says that plenty of finance teams did exactly that.
The mechanics are simple and unglamorous:
- An email arrives from what appears to be a supplier, a partner or the CEO.
- Bank details on an existing invoice have quietly changed, or a new urgent payment is requested.
- The request has enough context, tone and timing to feel legitimate.
- The payment is approved. The money lands in an attacker-controlled account and starts its journey through the laundry.
By the time anyone notices the real supplier hasn't been paid, the funds have already been broken up and moved. That is the whole crime. The laundering infrastructure exposed by Spanish police, all those hundreds of accounts and dozens of mules, exists because the first step, the fraudulent payment itself, works often enough to keep the pipeline full.
Four arrests will slow this particular operation. The technique behind it is not going anywhere.