A Multi-Agency Strike on the Numbers Behind the Scam

On 25 September 2026, German law-enforcement and regulatory bodies confirmed the latest phase of Operation Heracles, a joint initiative aimed at dismantling international cyber investment fraud. In the three months leading up to the announcement, investigators flagged and switched off 9,304 German telephone lines that they assessed had been exploited for fraudulent trading schemes. Counting back to the operation's inception, a cumulative total of 13,888 numbers have been neutralised — 13,397 of them German and 491 Austrian.

The campaign is notable for the breadth of agencies involved. The Cybercrime Centre at the Karlsruhe Public Prosecutor General's Office and the Baden-Württemberg State Criminal Police Office led the effort in coordination with the Federal Criminal Police Office (BKA), the financial regulator BaFin, the Federal Network Agency, and counterpart authorities in Austria. BaFin supplied the intelligence needed to flag suspicious numbers, while the Federal Network Agency imposed supervisory requirements on telecommunications providers.

Why Traders Should Care: Fraud That Looks Like a Brokerage

From a scam-alert perspective, the most important takeaway is how polished the front end of these operations has become. German authorities describe cybertrading fraud as a mass phenomenon now running at industrial scale, with both the number of cases and the value of losses trending upward. Victims routinely encounter what appears to be a full-service brokerage: targeted advertising, professionally designed trading platforms, real-time account dashboards, named 'brokers,' and a responsive customer-support desk.

For a retail FX or CFD investor, the practical risk is that the visual and functional hallmarks of a legitimate provider no longer serve as a reliable filter. Authorities in Germany have explicitly warned that the pipeline feeding these fake brokerages is growing faster than traditional takedown measures can keep pace with.

The Website Takedown Problem and the AI Factor

A recurring frustration for regulators is that pulling down a single fraudulent domain rarely stops the scheme. Scammers can register a new domain within hours, clone the interface, and redirect existing clients to the fresh URL. BaFin has previously cautioned that artificial-intelligence tools are now being used to mass-produce convincing investment websites, dramatically lowering the cost and time needed to spin up a new front end.

Operation Heracles reflects a strategic pivot away from treating websites as the primary target. The latest enforcement step focused squarely on the fixed-line, mobile, and VoIP telephone numbers that fraudsters rely on for cold-calling, 'customer service,' and verification codes. Authorities characterised these numbers as components of a wider 'Crime-as-a-Service' ecosystem — a rental infrastructure that international criminal groups can procure and deploy across multiple fraud typologies, not just investment scams.

Telecom Providers Under New Compliance Pressure

The Federal Network Agency's role in this phase is arguably the most consequential for the long-term landscape. Telecommunications companies were not simply asked to deactivate the identified numbers. They were also directed to overhaul their registration procedures and to tighten compliance controls that extend to their sales partners and reseller channels. In other words, the obligation now reaches the entire distribution chain through which a number is purchased and activated.

Authorities added that they have put in place structural mechanisms designed to allow large batches of criminally exploited numbers to be identified and switched off systematically going forward, rather than relying on case-by-case requests. This shift from reactive takedowns to a standing detection-and-disabling pipeline is a meaningful change for the resilience of the telecom layer that underpins phone-based fraud.

What Retail Traders Should Watch For

The German operation reinforces a broader warning for anyone trading FX or CFDs: the absence of a visible red flag on a website is no longer sufficient assurance of legitimacy. Traders should verify that a broker is registered with a recognised regulator in their jurisdiction, confirm that the entity behind the domain matches the licence holder, and treat any unsolicited phone call from an 'account manager' as a potential red flag. The infrastructure behind these scams is now industrial, cross-border, and increasingly automated — and the fact that authorities are moving up the stack from websites to the very phone numbers and registration channels that support them signals how deeply embedded the problem has become.