Polish SIM-swap gang busted with FBI help after draining crypto accounts

What you need to know…

  • On June 25, 2026, Polish police arrested four people accused of running a SIM-swap gang that drained cryptocurrency accounts. The FBI and U.S. Homeland Security Investigations backed the operation.
  • The gang reportedly broke into IT systems of companies working with telecom operators, hijacked employee email accounts, then cloned victims’ phone numbers to intercept SMS codes.
  • Investigators estimate the group laundered tens of millions of Polish zlotys through bank accounts, payment platforms and crypto wallets.
  • The four suspects face up to 25 years in prison. The investigation is still active.

The bust: four arrests, two countries, one phone number

On June 25, 2026, Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four people suspected of running an organized SIM-swap operation. FBI and Homeland Security Investigations agents took part in the operation, a sign that victims or infrastructure sit beyond Polish borders.

The arrests follow a pattern documented by Bleeping Computer and covered by Help Net Security: a criminal group that treated stolen phone numbers as its main tool, and crypto exchanges as its ATM.

The four suspects are in pre-trial detention. They face charges of participating in an organized criminal group, theft through unauthorized access to computer systems, and money laundering. Each charge carries a maximum sentence of 25 years. The investigation, supervised by the Regional Prosecutor’s Office in Kraków, is still active and developing, according to the CBZC.

How the gang worked: the phone number as a master key

According to investigators, the group did not start with hacking. It started with social engineering.

  • First, the gang broke into the IT systems of companies that work with telecom operators, using specialized software and social engineering to compromise employee email accounts.
  • With internal access, the group cloned and hijacked victims’ phone numbers through SIM-swap attacks.
  • Once in control of a number, the criminals intercepted SMS authentication codes and account recovery messages.
  • That gave them access to cryptocurrency exchange accounts, which they systematically drained.
  • The stolen funds then moved through a laundering network: personal bank accounts in Poland and abroad, international payment platforms, and multi-currency crypto wallets.

Blockchain investigator ZachXBT linked one of the suspects to a known social engineer, Wojtek Kulisz (alias “Merry”), based on items visible in the police raid photos. Polish authorities did not confirm the identification.

Why SMS two-factor authentication is the weak link

The method works because many platforms still rely on phone-based verification. When your phone number is the second factor, whoever controls the number controls the account. SMS-based 2FA is the weakest form of two-factor authentication, and this gang exploited it at scale.

The U.S. has seen the same playbook. In 2021 alone, the FBI’s Internet Crime Complaint Center (IC3) recorded 1,611 SIM-swapping complaints with adjusted losses of more than $68 million, according to a February 2022 FBI public service announcement. In February 2026, a Texas man was sentenced to 70 months in federal prison after pleading guilty to a SIM-swap scheme that caused $1,769,438 in losses; two co-conspirators received 57 and 30 months.

The warning signs

A SIM swap usually starts with something you notice: your phone suddenly loses network coverage, for no reason, while it worked minutes before. Calls and texts stop reaching you. That is often the moment the attacker takes control of your line.

Other signs: an unexpected message from your carrier about a new SIM, a port-out request or a change of address you never asked for, and verification codes arriving out of nowhere.

How to protect yourself

  • Do not rely on SMS codes alone. Use an authenticator app (Google Authenticator, Microsoft Authenticator) or a physical security key when a service allows it.
  • Add a carrier PIN or account lock if your mobile provider offers it. It makes it harder for an attacker to order a replacement SIM in your name.
  • Do not overshare. Phone numbers, addresses and crypto holdings posted publicly are ammunition for social engineers.
  • React immediately if your phone loses network out of nowhere: call your carrier from another line, ask them to check your account and block any port-out or SIM order in progress.

If you have been contacted by someone who asked you to confirm a “security operation” on your phone line or bank account, do not click anything. Verify directly on official channels, and report the scam so others can see it. If you have already been a victim of a phone number takeover, share your experience in the comments below: your story is the best warning for the next target.

Leave a Reply

Your email address will not be published. Required fields are marked *