25 cases

Back Ukraine, Germany, Norway, Poland, Latvia, United States, Finland, Portugal, Lithuania, United Kingdom, France: International operations conducted by the Cyber Police Department on cyber-enabled and cyber-dependent crimes

Ukraine, Germany, Norway, Poland, Latvia, United States, Finland, Portugal, Lithuania, United Kingdom, France: International operations conducted by the Cyber Police Department on cyber-enabled and cyber-dependent crimes

Since the beginning of 2026, the Cyber Police Department of the National Police of Ukraine has conducted 12 international cyber operations in co-operation with law enforcement authorities from Europe and North America. These operations targeted a broad spectrum of cyber-enabled and cyber-dependent crimes, including ransomware attacks, transnational hacking groups, online fraud, phishing campaigns, cryptocurrency-based money laundering, and organised cybercrime. Throughout these activities, the Cyber Police Department worked closely with foreign partners through joint investigations, mutual legal assistance, coordinated operational measures, and the exchange of digital evidence. All of these international operations relied on the practical co-operation mechanisms established by the Convention on Cybercrime (Budapest Convention), which served as the legal foundation for timely cross-border investigations and operational coordination.

International operation against a transnational hacker group

The Cyber Police, together with German law enforcement authorities, identified members of an international hacker group responsible for unauthorized access to information systems of foreign corporations and critical infrastructure. Operational measures resulted in searches, the seizure of digital devices, and the collection of electronic evidence for further criminal proceedings.

International cyber-enabled fraud investigation (Norway)

Acting upon a request for mutual legal assistance from the Kingdom of Norway, Ukrainian authorities located and detained a suspect involved in large-scale financial fraud related to the sale of used vehicles. The operation resulted in the execution of a foreign arrest warrant and initiated extradition proceedings.

International money laundering investigation (Poland)

In support of Polish law enforcement authorities, the Cyber Police participated in an operation targeting organised financial crime involving tax fraud, fuel smuggling, and money laundering. A wanted suspect was detained in Ukraine to facilitate further extradition procedures.

Operation "Scammer"

In co-operation with Latvian authorities and under the coordination of Europol, the Cyber Police disrupted a cross-border network of fraudulent call centres targeting Latvian citizens. The operation resulted in coordinated searches, the identification of key organizers, the seizure of digital evidence, and criminal charges against suspects involved in laundering criminal proceeds.

International operation against an AvosLocker affiliate

Working alongside United States law enforcement authorities, investigators identified a Ukrainian national involved in cyberattacks against U.S. governmental institutions, municipalities, and private organisations as a member of the AvosLocker ransomware group. Searches and forensic examinations produced valuable digital evidence supporting the ongoing investigation.

Operation "Pietari 3"

The Cyber Police supported Finnish authorities in dismantling a criminal network involved in laundering proceeds from illicit drug trafficking through virtual assets. Joint operational activities included multiple searches and the seizure of electronic devices, financial documentation, and cryptocurrency-related evidence.

Operation "Tycoon"

In cooperation with law enforcement agencies from Latvia, Portugal, Lithuania, Poland, the United Kingdom, and Europol, investigators disrupted phishing infrastructure used to defraud citizens of European Union Member States. The operation enabled the preservation of critical digital evidence and the complete dismantling of malicious server infrastructure located in Ukraine.

Operation "ENDGAME"

Together with French law enforcement authorities, the Cyber Police participated in an operation targeting the infrastructure supporting the DarkGate malware and the BlackBasta ransomware ecosystem. The investigation identified individuals involved in cryptocurrency laundering and malware infrastructure, while searches produced significant electronic evidence for further prosecution.

Joint operation against an organised fraud group

In co-operation with Latvian law enforcement authorities, Ukrainian investigators dismantled an organised criminal group conducting sophisticated online banking fraud against Latvian citizens. Coordinated searches, simultaneous arrests, and notifications of suspicion were carried out during the joint operation.

Operation "Makop"

Supporting German criminal proceedings, the Cyber Police investigated individuals responsible for ransomware attacks against German victims. Through cryptocurrency tracing and digital forensic analysis, investigators identified key suspects and secured electronic evidence during coordinated searches.

Operation "SEMTECH"

In response to a request from United States authorities, the Cyber Police identified an individual linked to an information-stealing malware operation responsible for compromising thousands of online accounts. Searches conducted in Ukraine resulted in the collection of digital evidence supporting the investigation into large-scale cyber-enabled financial crime.

International operation against an online fraud group

Together with Czech law enforcement authorities, the Cyber Police carried out coordinated searches targeting members of an organised fraud scheme involving fraudulent online advertisements for drone components. The operation contributed to documenting criminal activity, securing evidence, and advancing the ongoing investigation.

The Budapest Convention as a cornerstone of international cybercrime co-operation

The successful implementation of these international cyber operations once again demonstrated the practical value of the Convention on Cybercrime (Budapest Convention) as the cornerstone of international co-operation in combating cybercrime. By providing a common legal framework for the rapid exchange of electronic evidence, mutual legal assistance, and coordinated investigative measures, the Convention enables law enforcement authorities to respond effectively to cyber threats that transcend national borders.

The operational results achieved throughout 2026 clearly illustrate that international cybercrime investigations depend not only on strong partnerships between competent authorities but also on reliable legal instruments that facilitate timely and trusted co-operation. In this regard, the Budapest Convention remains an indispensable mechanism for identifying offenders, preserving digital evidence, dismantling criminal infrastructure, and ensuring that cybercriminals are brought to justice regardless of the jurisdictions involved.


The SBU, National Police, and French law enforcement expose developer of one of the world's most notorious hacking platforms

In 2025, cyber specialists of the Security Service of Ukraine, together with the National Police of Ukraine, the law enforcement authorities of the French Republic, and Europol, dealt a significant blow to the reputation of one of the world's leading online platforms used by the global cybercriminal community.

For more than a decade, hackers from around the world had relied on the forum to purchase advanced spyware, malicious software, and access to confidential databases.

As a result of the international operation, the developer of the platform was identified in Kyiv. The forum had more than 50,000 registered users, including notorious ransomware groups such as REvil, LockBit, Conti, and Qilin.

By using the platform's services, cybercriminals targeted automated systems of banks, government institutions, and major corporations across the United States and the European Union. For example, attackers purchased malware and unauthorized access to the computer networks of international companies, which they later used to extort money from victims. Those who refused to pay were threatened with the public release of confidential data and the disruption of their organizations' operations.

Investigators also documented numerous instances in which the platform was used to recruit new members into cybercriminal groups and to distribute sophisticated malware.

A key factor behind the success of this international operation was the effective use of the legal and operational framework provided by the Council of Europe Convention on Cybercrime (the Budapest Convention). The Convention facilitated the rapid exchange of information, effective operational coordination, and mutual legal assistance between the competent authorities of the participating countries. These international co-operation mechanisms enabled the SBU, the National Police of Ukraine, French law enforcement authorities, and Europol to combine their efforts in identifying one of the principal developers of the infrastructure that had long been used by some of the world's most prominent cybercriminal groups.

 

 

  Back to the '25 cases' webpage

2026 and 2025
  • Diminuer la taille du texte
  • Augmenter la taille du texte
  • Imprimer la page