European authorities bust cybercrime gang that hijacked business payments
Lucian Constantin / PCWorld :
Context & Ripple Effects
This bust sits inside a decade-long arc of European-led takedowns against financially motivated cybercrime: a gang had already siphoned more than $15M from Eastern European banks via phishing and malware in late 2014 ($15M bank siphoning spree), and Europol later detailed how the Carbanak network extracted roughly $1.2B from over 100 banks across 40 nations. Hijacking business payments is the same playbook pointed one layer down the supply chain — not at the banks, but at the companies paying through them.
First-order effects
- Businesses that were mid-payment when the gang was busted recover hijacked transfers and regain trust in their payment workflows; the gang's operators lose their infrastructure and face prosecution.
Second-order effects
- Displaced crews reconstitute under new brands and geographies — the pattern visible in the later GozNym takedown, where Europol and the FBI arrested a leader and ten members who had compromised 44,000 computers chasing roughly $100M (GozNym network takedown), and in the 2025 arrest of nine suspects behind a €600M+ crypto fraud ring (crypto fraud ring arrests).
Third-order effects
- Cross-border takedowns are becoming a standing enforcement product rather than one-off wins: German police, Europol, the FBI, and Ukrainian authorities repeated the model against the DoppelPaymer ransomware crew, with US victims paying out €40M+ across 2019-2021 before the disruption (DoppelPaymer gang disrupted). Each operation raises the cost of operating centralized criminal brands, pushing gangs toward flatter structures and faster rebranding.
The trend: Financial cybercrime enforcement has settled into a recurring multinational-arrest rhythm, where each dismantled payment-hijacking or banking-malware crew is quickly replaced but leaves behind intelligence that feeds the next takedown.