Police have long warned how dangerous opening suspicious links and providing login details for mobile banking can be. – Officers from the Cybercrime Division of the Provincial Police Headquarters in Wrocław, together with police officers from the Central Police Headquarters’ Cybercrime Bureau, detained two men as part of an operational investigation. Using one of these methods, they defrauded nearly 380,000 victims across Poland – reports junior inspector Wojciech Jabłoński of the Provincial Police Headquarters in Wrocław. – The police stopped this criminal operation, but the case is developing and further arrests cannot be ruled out.

The suspects are Ukrainian citizens aged 24 and 25. Spokesperson:

The men are suspected of acting jointly and in concert with other persons who have not yet been identified, with the aim of gaining financial benefit, and of attempting to induce and inducing nearly 380,000 people to dispose of their property unfavorably.

How did the fraudsters operate?

The perpetrators sent victims a fake link intended to mislead them into believing that they needed to settle a debt. To do so, they had to provide their mobile-banking login details. The result? The fraudsters gained access to the victims’ bank accounts. The total value of the losses caused in this way amounts to tens of thousands of złotys—and is still growing.

The police also seized 11 mobile phones, a router, SIM cards and money. The proceedings are being conducted by the Wrocław Psie Pole Police Station. The court ordered the temporary detention of both Ukrainian suspects for three months.

Police:

We warn against suspicious messages concerning the need to pay various bills, for example for electricity, gas or other utilities. Fraudsters threaten that the service will be disconnected if an overdue payment is not made. Such a message usually contains a link infected with malware. As a result, malicious software may be installed on our phone, enabling the criminal to take control of it and access mobile banking. Remember that such a link may also redirect us to a fake bank website. The fraudsters can then easily obtain the login and password to our online bank account.

And they appeal:

Let us beware of fake SMS messages demanding payment. Officers advise that, if you receive a suspicious message, you should contact the helpline and clarify the matter concerning your account. Under no circumstances should you open any links sent to you by SMS or email.