The Civil Guard has dismantled, after two years of investigation, a criminal organization specialized in committing bank scams through smishing and phishing―two fraud techniques involving identity impersonation of legitimate entities― in an operation that has resulted in 13 arrests and five individuals under investigation in Madrid, Palma de Mallorca, Valencia, and Toledo. The operation, named Fragmenta and carried out by the Telematic Crimes Team (Edite) and the Castellón Civil Guard Command Team, has also allowed the seizure of a database with personal and banking information of approximately 500,000 citizens, of whom nearly 2,000 potential victims have been identified so far.
The arrested and investigated individuals are accused of the alleged crimes of fraud, money laundering, and belonging to a criminal organization. The investigation began in 2024 after a person reported losing nearly 30,000 euros after receiving a fake bank communication. Based on that complaint, agents linked new reports and uncovered this criminal network operating in different parts of the national territory.
During the investigation, agents identified the 18 members of the organization ―10 men and eight women, aged between 23 and 43― and determined the roles each played within the group. The operation allowed the network to be dismantled and its main members brought before the courts.
According to the Civil Guard, the members of the organization massively sent SMS messages that appeared to come from banking entities with the aim of getting victims to access fraudulent websites and enter their online banking credentials.

Subsequently, they contacted them by phone, posing as bank employees to obtain the necessary verification codes and complete the operations. Once they gained control of the accounts, they transferred the available money and requested pre-approved loans or other financial products in the victims’ names. They then distributed the funds through numerous bank accounts to hinder their tracing and launder the obtained money.
The Civil Guard points out that the investigation was marked by the use of false identities, accounts opened through third parties, immediate transfers between different entities, and a technological infrastructure distributed in several countries, circumstances that forced the development of “financial intelligence and technological analysis” work, as stated by the security force in a statement.
In the final phase of the operation, three searches were carried out, two in the province of Valencia and one in Madrid. Mobile phones, computer equipment, electronic devices, documentation, and cash related to the investigated activity were seized.
Among the seized material, a database with personal and banking information of about 500,000 people stands out. The analysis of this documentation has so far allowed the identification of nearly 2,000 potential victims, although the investigation remains open and the Civil Guard does not rule out the appearance of new affected individuals.

The armed force reminds that banking entities do not request access keys, passwords, or verification codes from their clients by phone, SMS, or email. In the event of any suspicious communication, it recommends not providing personal or banking data, accessing online banking only through official channels, and contacting the entity directly to verify the authenticity of the message or call. It also advises periodically reviewing account movements and immediately reporting any unauthorized operation.
Read more A witness reveals that the Andic’s therapy included an extreme situation in a ravine