# Polish Authorities Dismantle International SIM-Swapping Syndicate, Recovering Millions in Stolen Cryptocurrency


A major international law enforcement operation has dismantled a sophisticated cybercriminal group operating out of Poland that orchestrated high-value SIM-swapping attacks targeting cryptocurrency investors across the United States and beyond. The coordinated takedown, led by Poland's Cybercrime Bureau (CBZC) in partnership with the FBI and Homeland Security Investigations (HSI), exposed a well-organized criminal enterprise responsible for stealing millions of dollars through coordinated breaches of telecommunications infrastructure and coordinated account hijacking.


## The Threat: How a SIM-Swap Syndicate Emptied Crypto Wallets


The four arrested individuals—now identified through blockchain analysis as members of a professional criminal network—ran what law enforcement describes as a systematic theft operation targeting high-net-worth cryptocurrency investors. Using a combination of technical hacking and social engineering, the suspects infiltrated the networks of telecommunications partners and service providers, gaining access to critical infrastructure that controls SIM card issuance and phone number management.


Once inside these systems, the attackers could perform the core attack vector of their operation: SIM swapping—a form of account takeover that exploits the telecom industry's vulnerabilities to two-factor authentication (2FA) mechanisms.


The mechanics are straightforward but devastatingly effective:


1. Research the target – The group identified high-value cryptocurrency account holders

2. Breach telecom infrastructure – They compromised telecommunications company systems or partner networks to gain access to SIM provisioning databases

3. Clone or hijack the phone number – By manipulating the telecom backend, they transferred the victim's phone number to a SIM card they controlled

4. Intercept recovery codes – All SMS-based authentication messages and email recovery links now routed to the attackers

5. Empty the wallet – With access to the victim's phone and email, they reset passwords on cryptocurrency exchange accounts and authorized withdrawals


The result: victims found their crypto holdings liquidated and transferred to untraceable wallets before they even realized their phone numbers were compromised.


## Background and Context: SIM-Swapping's Growing Sophistication


SIM-swapping is not a new attack. What distinguishes this operation is its industrial scale and the level of infrastructure access the group achieved.


Historically, SIM-swapping attacks required social engineering a telecom customer service representative into transferring a victim's phone number to a new SIM card. While effective against isolated targets, this approach is detectable and limits the volume of attacks an operator can conduct.


This Polish gang evolved the playbook by directly compromising telecommunications infrastructure—a significantly more difficult feat requiring both technical expertise and sustained access to telecom partner systems. This approach allowed them to:


  • Execute attacks with minimal human contact and reduced detection risk
  • Scale operations far beyond what social engineering alone could accomplish
  • Target multiple victims in parallel
  • Maintain persistent access for months or years

  • The sophistication mirrors trends seen in other state-sponsored and organized cybercrime operations that increasingly target telecom infrastructure as a strategic vulnerability.


    ## Technical Details: Breaching the Telecom Perimeter


    According to CBZC's technical assessment, the suspects employed specialized software tools alongside manual exploitation techniques. Their attack chain operated across multiple systems:


    | Component | Attack Method |

    |-----------|---|

    | Telecom Partner Networks | Compromised partner systems used for billing, subscriber management, or SIM provisioning |

    | Employee Email Accounts | Phishing, credential theft, or purchased credentials from insider contacts |

    | SIM Management Systems | Direct access to systems controlling number assignments and SIM activation |

    | Authentication Bypasses | Exploitation of weak security controls in legacy telecom infrastructure |


    The group reportedly leveraged both zero-day-like vulnerabilities in telecom systems and known weaknesses in access control mechanisms. Polish investigators note the attackers used "specialized software," suggesting either custom-developed tools or commercially available penetration testing frameworks repurposed for criminal activity.


    Critically, the fact that this group maintained sustained access indicates the telecom partners involved may have had weak detection capabilities—a reality that extends far beyond Poland and highlights systemic vulnerabilities in global telecom infrastructure.


    ## The Investigation and Arrests: Law Enforcement's International Response


    The operation represents a significant escalation in international law enforcement focus on SIM-swapping attacks. CBZC coordinated with the FBI and HSI, suggesting the victims and financial flows crossed U.S. borders—a jurisdictional trigger that elevates the operation's priority within federal law enforcement.


    Polish authorities arrested four individuals and placed them in pre-trial detention. One suspect was publicly identified through blockchain forensics conducted by independent researcher ZachXBT as Wojtek Kulisz, known online as "Merry"—a public attribution that suggests law enforcement is willing to name members of organized cybercrime groups, potentially to disrupt recruitment and reputation within criminal forums.


    The financial investigation revealed the sophistication of their money laundering operation:


  • Minimum $5 million in stolen cryptocurrency identified (investigators estimate tens of millions of Polish złoty)
  • Funds distributed across multiple bank accounts in different countries
  • Digital wallets used for additional obfuscation
  • "Distributed financial network" employed to scatter holdings and frustrate recovery efforts

  • ## The Charges and Penalties


    The suspects face prosecution under serious organized crime statutes:


  • Participation in an organized criminal group – Treating these activities as a professional, recurring income stream
  • Computer hacking and theft – Unauthorized access to IT systems with intent to commit theft
  • Money laundering – Deliberate obscuring of criminal proceeds' origins

  • The maximum penalty: 25 years imprisonment per suspect—reflecting the gravity with which Polish and U.S. authorities treat organized cybercrime targeting financial systems.


    ## Implications for Cryptocurrency Users and Telecom Customers


    This operation exposes critical vulnerabilities affecting three distinct populations:


    Cryptocurrency Investors: If your 2FA relies solely on SMS or phone-based recovery methods, you remain vulnerable to SIM-swapping attacks regardless of the strength of your account password. The incident underscores why hardware security keys and app-based authentication (TOTP) should be prioritized.


    Telecom Customers: The fact that criminal actors maintained sustained access to telecom infrastructure suggests many carriers have not adequately segregated or monitored SIM provisioning systems. Customers with high-value accounts (business owners, investors, executives) face elevated risk.


    Financial Institutions: Cryptocurrency exchanges and payment platforms that relied on SMS-based 2FA verification in their account recovery workflows enabled these attacks. This operation vindicates security researchers who have long criticized SMS as an inadequate authentication layer for high-value accounts.


    ## Recommendations for Defense


    For Individuals:

  • Replace SMS-based 2FA with hardware security keys (YubiKey, Titan Key) or TOTP apps (Google Authenticator, Authy) for cryptocurrency exchange accounts
  • Do not use phone number-based account recovery for sensitive accounts
  • Consider using a dedicated, isolated phone number for financial accounts that doesn't match your primary identity
  • Monitor your phone bill for unexpected SIM card changes or activation attempts

  • For Cryptocurrency Exchanges:

  • Mandate hardware key or TOTP-only 2FA for accounts with balances above a defined threshold
  • Implement account withdrawal delays (e.g., 24-48 hours) for newly added withdrawal addresses
  • Require email verification *and* in-app confirmation for address changes
  • Implement geolocation and IP-based anomaly detection for account access

  • For Telecommunications Providers:

  • Segment SIM provisioning systems from general-purpose corporate networks
  • Implement mandatory hardware tokens for all SIM management activities
  • Deploy continuous monitoring for anomalous SIM issuance patterns
  • Require multi-person authorization for high-risk SIM changes
  • Assume breach and verify—conduct red team exercises specifically targeting SIM provisioning

  • ---


    ## HackWire Analysis


    This takedown represents a watershed moment for law enforcement focus on organized SIM-swapping, yet it also exposes how *normalized* these attacks have become within criminal ecosystems. The Polish gang didn't innovate; they industrialized an attack vector that security researchers have warned about for years.


    What distinguishes this case is not the sophistication of the attack—it's the casualness with which they targeted telecom infrastructure. They didn't break in to steal secrets; they broke in to provision SIM cards. This suggests that many telecommunications carriers still treat SIM management systems as lower-priority targets compared to customer-facing applications or billing systems. In reality, SIM provisioning is a keys-to-the-kingdom resource that can compromise millions of accounts in minutes.


    The financial scale—millions in cryptocurrency stolen through what CBZC describes as a distributed money laundering network—signals that organized crime groups view SIM-swapping as a *business model*, not a one-off attack. This criminalization, combined with the operational sophistication required, indicates that victims will see increasing attacks from well-resourced threat actors rather than script-kiddies testing social engineering.


    For defenders, the takeaway is brutal: SMS and phone-based authentication for financial accounts is security theater. Every cryptocurrency exchange, every bank, every platform holding sensitive assets must urgently move away from SMS-based 2FA. The technical solutions exist—hardware keys, TOTP, biometric authentication. The barrier is not capability; it's the friction that comes with requiring users to adopt new tools.


    The other critical insight: carriers themselves remain inadequately defended against insider threats and external compromise of provisioning infrastructure. Until telecommunications companies treat SIM management with the same rigor applied to encrypted trunk lines and signaling networks, these attacks will continue at scale.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)