The Civil Guard has arrested 13 people and is investigating five others, one of them in Palma, for belonging to a criminal organization dedicated to bank fraud through smishing and phishing. The gang is believed to have caused at least 2,000 victims and managed a database containing personal and banking information of 500,000 people.
The Civil Guard has dismantled a criminal organization specialized in bank cyber fraud operating from Palma and other Spanish provinces. As part of the operation, 13 people have been arrested and five others, including one in Palma, have been investigated for crimes of fraud, money laundering, and belonging to a criminal organization. The network is believed to have caused at least 2,000 victims and managed a database containing personal and banking information of half a million people.
The investigation began in 2024 after a victim lost 30,000 euros upon receiving a false banking communication. Following that report, agents gathered new testimonies and confirmed they were dealing with a perfectly structured criminal network, with branches in various parts of the country.
Investigators identified the 18 members of the organization, ten men and eight women aged between 23 and 43. Each had a specific role within the criminal machinery. After the exploitation phase, all have been placed at the disposal of the judiciary.
The 'modus operandi' of the cybercriminals involved the mass sending of SMS messages that appeared to come from banking entities. Victims were induced to access fraudulent websites where they entered their credentials. Subsequently, the scammers contacted them pretending to be bank employees to obtain the verification codes necessary to complete the transactions.
Once they gained control of the accounts, they transferred the available funds and requested pre-approved loans and other financial products in the victims' names, causing them significant economic harm. The funds were distributed across various accounts to make tracking difficult and subsequently laundered.
The complexity of the investigation was increased by the use of false identities, accounts opened through third parties, immediate transfers between entities, and a technological infrastructure deployed in several countries. All of this necessitated intense financial intelligence work and technological analysis by the Civil Guard.
During the final phase of the operation, three searches were conducted, two in Valencia and one in Madrid, where mobile phones, computer equipment, electronic devices, documentation, and cash were seized. Among the confiscated material was a database containing personal and banking information of 500,000 people, the analysis of which has so far allowed the identification of 2,000 victims.
The Civil Guard reminds that banking entities never request access keys, passwords, or verification codes from their clients via phone, SMS, or email. In case of any suspicious communication, it is recommended not to provide personal or banking data, access online banking through official channels, and contact the entity directly to verify the authenticity of the message.
For the residents of Mallorca, this operation serves as a warning about the importance of taking extra precautions against messages or calls pretending to be from their bank. In case of doubt, the safest option is to hang up and call the bank's official number.

