€30,000 bank scam probe uncovers data on 500,000 people in Spain

A person counts €50 banknotes in a room during the Guardia Civil investigation.

Cash recovered during Operation Fragmenta. Credit: Guardia Civil.

One convincing bank text could end with money disappearing and loans being taken out in the victim’s name. Guardia Civil says the alleged network behind the messages held data relating to around 500,000 people, although only about 2,000 possible victims have been identified so far.

Thirteen arrests, nearly 2,000 possible victims and 500,000 people’s banking information

One person’s loss of nearly €30,000 has led investigators to an alleged nationwide bank fraud operation and a database containing personal and banking information relating to around half a million people. The Guardia Civil said on July 22 that 13 people had been arrested and another five placed under investigation during Operation Fragmenta. The measures were carried out in Madrid, Palma de Mallorca, Valencia and Toledo. 

The 18 alleged members, comprising 10 men and eight women aged between 23 and 43, are suspected of fraud, money laundering and membership of a criminal organisation. These remain allegations and the police investigation is still open. The inquiry began in 2024 after a victim reported losing close to €30,000 following a false communication supposedly from their bank. Investigators then connected the complaint with other cases.

During three searches, two in Valencia province and one in Madrid, officers seized cash, documentation, phones, computers and other electronic equipment. The database was found among that material.

Police have identified nearly 2,000 possible victims so far. However, being listed in the database does not establish that a person’s account was yet accessed or that money was taken. Guardia Civil has not disclosed which banks are involved, where the information originated or precisely what every record contains.

How the alleged bank scam moved from text to phone call

According to investigators, the operation began with large numbers of SMS messages designed to appear as though they came from genuine banks. Recipients were directed to fraudulent websites resembling online banking pages. Any login credentials entered could then be captured by the suspects. The next step was a telephone call. People allegedly posing as bank employees contacted victims and asked for the verification codes needed to complete transactions. Once an account had been accessed, the group allegedly transferred available money and applied for pre-approved loans or other financial products in the victim’s name. This meant the potential loss could exceed the balance already sitting in the account.

Investigators said money was distributed through numerous accounts, with immediate transfers between different banks making it more difficult to trace. The operation also allegedly used false identities, accounts opened through third parties and technological infrastructure spread across several countries.

A genuine security code does not make the caller genuine

The verification code received during a scam may really have been sent by the bank. That does not mean the person requesting it is a bank employee. A fraudster who already has someone’s login details can begin a real transaction, triggering the genuine bank to send its customer a code. Reading that code aloud can then allow the transaction to be completed.

Guardia Civil stressed that banks do not request login details, passwords or verification codes through unsolicited calls, text messages or emails. Suspicious communications should be checked through the bank’s official app, website or the telephone number printed on the customer’s card, rather than through a link or number supplied in the message.

What to do after entering banking details

Anyone who has entered credentials on a suspicious page or shared a verification code should contact their bank immediately through an independently verified number. Access details should be changed, account movements checked and any unauthorised transaction reported without delay.

Screenshots, telephone numbers, messages, website addresses and transaction details should be preserved in case they are needed by the bank or police. Spain’s National Cybersecurity Institute, INCIBE, also operates the free and confidential 017 cybersecurity helpline from 8am to 11pm every day.

The scale of Operation Fragmenta could still grow. Investigators are continuing to analyse the seized records and have not ruled out identifying further victims.

Google News

Follow Euro Weekly News on Google News

Get breaking news from Spain, travel updates, and expat stories directly on your Google News feed.

Follow on Google News
Written by

Harry Dennis

Born in the UK and raised on the Cádiz coast, Harry brings his background in design, music, and photography to his writing for Euro Weekly News, sharing stories that celebrate culture and lifestyle across Spain and beyond.

Comments


    Leave a comment

    Your email address will not be published. Required fields are marked *