Spanish police have arrested 13 people in a major crackdown on a bank fraud ring. The group used stolen data from half a million users. Nearly 2,000 victims have been identified so far.
A major criminal network specializing in bank fraud has been dismantled by the Guardia Civil after a two-year investigation that exposed the theft of personal and financial data from around 500,000 people across Spain. The operation, which led to 13 arrests and five additional suspects under investigation in Madrid, Palma de Mallorca, Valencia, and Toledo, was triggered by a complaint from a victim who lost €30,000 to a fake SMS purporting to be from his bank.
Authorities revealed that the group relied on smishing and phishing tactics, sending out mass text messages that mimicked legitimate banking communications. Victims were lured to fraudulent websites where they entered their online banking credentials. The fraudsters then followed up with phone calls, posing as bank employees to extract verification codes needed to finalize unauthorized transactions.
Once the criminals gained access to accounts, they transferred available funds and applied for pre-approved loans or other financial products in the victims’ names. The stolen money was quickly moved through a web of bank accounts to obscure its origin and launder the proceeds. The investigation uncovered a sophisticated structure, with members using false identities, third-party accounts, and a distributed technological infrastructure spanning several countries.
During the final phase of the operation, police carried out three searches—two in Valencia province and one in Madrid—seizing mobile phones, computers, electronic devices, documents, and cash linked to the criminal activity. Among the confiscated materials was a database containing the personal and banking details of approximately half a million individuals. So far, nearly 2,000 potential victims have been identified, but the Guardia Civil warns that the number could rise as the investigation continues.
The suspects, ten men and eight women aged between 23 and 43, face charges of fraud, money laundering, and membership in a criminal organization. Investigators highlighted the complexity of the case, which required advanced financial intelligence and technological analysis due to the use of fake identities, rapid transfers between banks, and international elements.
Spanish authorities remind the public that banks never request passwords or verification codes by phone, SMS, or email. They urge anyone receiving suspicious messages to avoid sharing personal or banking information, to access online banking only through official channels, and to contact their bank directly to verify any unexpected communication. Regularly checking account activity and reporting unauthorized transactions immediately is also strongly advised.
This case comes amid growing concerns about digital fraud in Spain, as highlighted by recent judicial developments in Madrid, where the courts are increasingly dealing with complex financial crimes. For example, the ongoing review of high-profile corruption cases, such as the one involving Begoña Gómez, reflects the broader challenges facing the Spanish legal system in tackling sophisticated criminal networks. More details on the judicial response to such cases can be found in this recent report on Madrid's court proceedings.
Spain has seen a steady rise in cybercrime over the past decade, with phishing and smishing attacks becoming more frequent and sophisticated. According to official statistics, financial fraud remains one of the most reported types of cybercrime in the country. The Guardia Civil and other law enforcement agencies have increased their focus on digital security, launching public awareness campaigns and specialized units to combat online threats. As digital banking becomes more prevalent, both institutions and individuals are urged to remain vigilant against evolving fraud tactics.