# Polish Authorities Dismantle International SIM-Swapping Syndicate, Recovering Millions in Stolen Cryptocurrency
A major international law enforcement operation has dismantled a sophisticated cybercriminal group operating out of Poland that orchestrated high-value SIM-swapping attacks targeting cryptocurrency investors across the United States and beyond. The coordinated takedown, led by Poland's Cybercrime Bureau (CBZC) in partnership with the FBI and Homeland Security Investigations (HSI), exposed a well-organized criminal enterprise responsible for stealing millions of dollars through coordinated breaches of telecommunications infrastructure and coordinated account hijacking.
## The Threat: How a SIM-Swap Syndicate Emptied Crypto Wallets
The four arrested individuals—now identified through blockchain analysis as members of a professional criminal network—ran what law enforcement describes as a systematic theft operation targeting high-net-worth cryptocurrency investors. Using a combination of technical hacking and social engineering, the suspects infiltrated the networks of telecommunications partners and service providers, gaining access to critical infrastructure that controls SIM card issuance and phone number management.
Once inside these systems, the attackers could perform the core attack vector of their operation: SIM swapping—a form of account takeover that exploits the telecom industry's vulnerabilities to two-factor authentication (2FA) mechanisms.
The mechanics are straightforward but devastatingly effective:
1. Research the target – The group identified high-value cryptocurrency account holders
2. Breach telecom infrastructure – They compromised telecommunications company systems or partner networks to gain access to SIM provisioning databases
3. Clone or hijack the phone number – By manipulating the telecom backend, they transferred the victim's phone number to a SIM card they controlled
4. Intercept recovery codes – All SMS-based authentication messages and email recovery links now routed to the attackers
5. Empty the wallet – With access to the victim's phone and email, they reset passwords on cryptocurrency exchange accounts and authorized withdrawals
The result: victims found their crypto holdings liquidated and transferred to untraceable wallets before they even realized their phone numbers were compromised.
## Background and Context: SIM-Swapping's Growing Sophistication
SIM-swapping is not a new attack. What distinguishes this operation is its industrial scale and the level of infrastructure access the group achieved.
Historically, SIM-swapping attacks required social engineering a telecom customer service representative into transferring a victim's phone number to a new SIM card. While effective against isolated targets, this approach is detectable and limits the volume of attacks an operator can conduct.
This Polish gang evolved the playbook by directly compromising telecommunications infrastructure—a significantly more difficult feat requiring both technical expertise and sustained access to telecom partner systems. This approach allowed them to:
The sophistication mirrors trends seen in other state-sponsored and organized cybercrime operations that increasingly target telecom infrastructure as a strategic vulnerability.
## Technical Details: Breaching the Telecom Perimeter
According to CBZC's technical assessment, the suspects employed specialized software tools alongside manual exploitation techniques. Their attack chain operated across multiple systems:
| Component | Attack Method |
|-----------|---|
| Telecom Partner Networks | Compromised partner systems used for billing, subscriber management, or SIM provisioning |
| Employee Email Accounts | Phishing, credential theft, or purchased credentials from insider contacts |
| SIM Management Systems | Direct access to systems controlling number assignments and SIM activation |
| Authentication Bypasses | Exploitation of weak security controls in legacy telecom infrastructure |
The group reportedly leveraged both zero-day-like vulnerabilities in telecom systems and known weaknesses in access control mechanisms. Polish investigators note the attackers used "specialized software," suggesting either custom-developed tools or commercially available penetration testing frameworks repurposed for criminal activity.
Critically, the fact that this group maintained sustained access indicates the telecom partners involved may have had weak detection capabilities—a reality that extends far beyond Poland and highlights systemic vulnerabilities in global telecom infrastructure.
## The Investigation and Arrests: Law Enforcement's International Response
The operation represents a significant escalation in international law enforcement focus on SIM-swapping attacks. CBZC coordinated with the FBI and HSI, suggesting the victims and financial flows crossed U.S. borders—a jurisdictional trigger that elevates the operation's priority within federal law enforcement.
Polish authorities arrested four individuals and placed them in pre-trial detention. One suspect was publicly identified through blockchain forensics conducted by independent researcher ZachXBT as Wojtek Kulisz, known online as "Merry"—a public attribution that suggests law enforcement is willing to name members of organized cybercrime groups, potentially to disrupt recruitment and reputation within criminal forums.
The financial investigation revealed the sophistication of their money laundering operation:
## The Charges and Penalties
The suspects face prosecution under serious organized crime statutes:
The maximum penalty: 25 years imprisonment per suspect—reflecting the gravity with which Polish and U.S. authorities treat organized cybercrime targeting financial systems.
## Implications for Cryptocurrency Users and Telecom Customers
This operation exposes critical vulnerabilities affecting three distinct populations:
Cryptocurrency Investors: If your 2FA relies solely on SMS or phone-based recovery methods, you remain vulnerable to SIM-swapping attacks regardless of the strength of your account password. The incident underscores why hardware security keys and app-based authentication (TOTP) should be prioritized.
Telecom Customers: The fact that criminal actors maintained sustained access to telecom infrastructure suggests many carriers have not adequately segregated or monitored SIM provisioning systems. Customers with high-value accounts (business owners, investors, executives) face elevated risk.
Financial Institutions: Cryptocurrency exchanges and payment platforms that relied on SMS-based 2FA verification in their account recovery workflows enabled these attacks. This operation vindicates security researchers who have long criticized SMS as an inadequate authentication layer for high-value accounts.
## Recommendations for Defense
For Individuals:
For Cryptocurrency Exchanges:
For Telecommunications Providers:
---
## HackWire Analysis
This takedown represents a watershed moment for law enforcement focus on organized SIM-swapping, yet it also exposes how *normalized* these attacks have become within criminal ecosystems. The Polish gang didn't innovate; they industrialized an attack vector that security researchers have warned about for years.
What distinguishes this case is not the sophistication of the attack—it's the casualness with which they targeted telecom infrastructure. They didn't break in to steal secrets; they broke in to provision SIM cards. This suggests that many telecommunications carriers still treat SIM management systems as lower-priority targets compared to customer-facing applications or billing systems. In reality, SIM provisioning is a keys-to-the-kingdom resource that can compromise millions of accounts in minutes.
The financial scale—millions in cryptocurrency stolen through what CBZC describes as a distributed money laundering network—signals that organized crime groups view SIM-swapping as a *business model*, not a one-off attack. This criminalization, combined with the operational sophistication required, indicates that victims will see increasing attacks from well-resourced threat actors rather than script-kiddies testing social engineering.
For defenders, the takeaway is brutal: SMS and phone-based authentication for financial accounts is security theater. Every cryptocurrency exchange, every bank, every platform holding sensitive assets must urgently move away from SMS-based 2FA. The technical solutions exist—hardware keys, TOTP, biometric authentication. The barrier is not capability; it's the friction that comes with requiring users to adopt new tools.
The other critical insight: carriers themselves remain inadequately defended against insider threats and external compromise of provisioning infrastructure. Until telecommunications companies treat SIM management with the same rigor applied to encrypted trunk lines and signaling networks, these attacks will continue at scale.
— HackWire Editorial
---
## Related Coverage