BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Operation Herakles disconnects 13,888 phone numbers: what to check on crypto investment calls

Six authorities from Germany and Austria published a joint set of figures at 9:35 a.m. on September 25, 2026: over the past three months, Operation Herakles has taken 9,304 German phone numbe

AnonymousCryptoCompass newsroom
September 26, 2026
11 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

Six authorities from Germany and Austria published a joint set of figures at 9:35 a.m. on September 25, 2026: over the past three months, Operation Herakles has taken 9,304 German phone numbers out of service, numbers investment fraudsters had used to call their victims. Since the operation began the total stands at 13,888 numbers, 13,397 of them German and 491 Austrian. If a call about a crypto investment reaches you in the coming weeks, that figure is precisely why you should handle the conversation differently than before.

The announcement comes from the Karlsruhe public prosecutor general’s office with its cybercrime centre, the Baden-Württemberg state criminal police office, the Federal Criminal Police Office, the Federal Financial Supervisory Authority, the Federal Network Agency and the Austrian Federal Criminal Police Office. It targets a form of fraud the authorities call cyber trading fraud: simulated trading in crypto-assets, foreign exchange or shares on platforms that never held a licence.

Operation Herakles on September 25, 2026: 9,304 phone numbers disconnected in three months

The figures in the press release are tiered. Over the past three months, 9,304 German phone numbers were taken off the network. The cumulative total since the operation started stands at 13,888 numbers. The authorities state the split explicitly: 13,397 from Germany, 491 from Austria.

Earlier steps of the same operation add to that. In June and October 2025 investigators took more than 2,200 domains offline by their own account, and in December 2025 some 3,500 phone numbers. Operation Herakles is therefore not a single raid but a series of measures running for more than a year, and its pace has picked up lately: the 9,304 numbers of the last quarter are more than double the December action.

Placed within the authorities’ anti-scam strategy, the point is not the criminal prosecution of the people behind the scheme but their tools. That distinction matters for the question of what the operation changes for you, and it comes up again below.

Cyber trading fraud: how the fake trading platform scheme works

Cyber trading fraud describes investment fraud in which a platform merely simulates trading in crypto-assets, foreign exchange or derivatives while the money paid in never reaches a market. The press release puts that core unambiguously: the funds paid in are at no point channelled into any investment.

According to the authorities the sequence follows a fixed pattern. Victims first come across a fraudulent investment platform holding no financial supervisory licence. Brokers from call centres abroad then get in touch by phone and push for larger deposits. The presentation is professional, and the deception holds for months: the gains displayed in the user account rise while the money has long since left through the perpetrators’ account. In the end it is usually lost in full, as investigators describe it.

The phone call is not background noise here but the centrepiece. Without the voice on the line, a made-up platform remains a website that talks nobody into a second deposit. That is exactly why the authorities are going after it.

What separates this scheme from phishing

In phishing, somebody captures your login credentials and empties an existing account. In cyber trading fraud you transfer the money yourself, voluntarily, believing you are paying for an investment. For recovery that is a considerable difference, because an authorised transfer is treated differently from an unauthorised one. How to spot a pretextual check designed to make you connect your wallet is set out in our article on the fake AML check for crypto wallets.

An abandoned call centre headset with a severed cable in front of rows of unoccupied workstations, with a gold coin bearing the Bitcoin symbol in front The calls come from call centres abroad: disconnected numbers hit the perpetrators’ sales channel, not the perpetrators themselves.

Why the phone number is the point of attack and not the platform

A domain can be registered anew within minutes. A German phone number cannot: it has to be allocated to a telecommunications provider and assigned to a holder. A call starting with a German dialling code is valuable to fraudsters because the people called pick up. A foreign number gets rejected.

So the Federal Network Agency intervenes where that benefit of the doubt arises. As the authorities describe it, the agency has taken supervisory measures against telecommunications companies: providers had to disconnect the numbers concerned and overhaul their registration processes. On top of that they are to vet their sales partners and dealers more strictly, so that numbers do not end up in the same hands again.

That is the genuinely new part of the announcement. Not the number of disconnections, but the requirement on providers to control access to phone numbers differently than before.

Checking licence status: how to tell a licensed crypto exchange from an invented one

In their statement the authorities explicitly recommend verifying the licence status of a financial provider before any money moves. For crypto-asset services in Germany that is a reasonable check to ask of anyone, because the licence is a matter of public record.

Anyone providing crypto-asset services in the European Union needs authorisation under the EU regulation on markets in crypto-assets. Crypto-asset service provider is the legal term for companies that hold, exchange, place or trade crypto-assets on behalf of others. The obligations that come with it, and the way an authorisation granted can be recognised, are matters we have covered separately in our overview of the MiCA licensing duties for crypto companies.

In practice this means looking the provider up in the company database of the financial supervisory authority and in the public list of authorised service providers. Failing to find it there is not proof of fraud in itself, but it is the point at which no deposit may take place. A selection of trading venues whose licensing position we have checked is in our comparison of the best regulated crypto exchanges. The supervisory authority also publishes warnings about individual providers on an ongoing basis, and a look there belongs to the same check.

Matching the name alone is not enough

A recurring pattern from earlier warnings: perpetrators use the name of a genuinely authorised company and rebuild its website. The database entry then really does exist but belongs to a different firm. So compare not only the name but also the domain, the address and the register number in the entry against what has been put in front of you. If the domain differs while the name matches, the matter is settled.

The warning signs in the conversation: time pressure, remote access, document copies

The authorities name three rules of conduct that can be applied on the call itself: do not let yourself be pressured, do not pass on confidential data or copies of documents, and obtain precise information about the platform before registering.

In the conversation itself you recognise the scheme by its dramaturgy. There is an opportunity that ends today. There is a personal adviser who will call back if you hesitate. There is a screen share so that he can help you set things up. And there is the request for a scan of your ID, formally justified by identity verification.

The last point deserves a remark of its own because it looks harmless. Identity verification is indeed mandatory at an authorised provider. There, however, it runs inside the provider’s own closed process, not as a photo you send to a caller by messenger. A scan of your ID in someone else’s hands opens further accounts in your name, and that damage remains even if you never paid anything in.

What a genuine platform never asks of you

Four things do not occur at an authorised service provider, and each one on its own ends the conversation:

  • remote access or screen-sharing software you are asked to install in order to open an account
  • a deposit into a private account, an account in a third country, or straight into a wallet address read out to you over the phone
  • a request to enter your seed phrase or photograph it so that a balance can be released
  • a payment so that a gain supposedly already made can be paid out

The last point is the second stage of the fraud. Anyone who has paid once is called again later, this time with the promise of recovering the money lost. Anyone who wants to keep their crypto-assets permanently out of reach of others cannot avoid self-custody; what separates the devices is set out in our hardware wallet comparison.

A large brass magnifying glass over a round wax seal with an abstract ring pattern, next to a gold coin bearing the Bitcoin symbol Licence status is a matter of public registers: checking takes two minutes and is the one step the authorities recommend to every investor.

When money has already moved: criminal complaint, evidence and the time factor

The authorities recommend filing a criminal complaint in the event of fraud, and point to consumer advice centres or independent financial advice. What counts for the complaint is what you can produce.

So secure above all the payment records with date, amount and recipient details, the complete communication including phone numbers and timestamps, the addresses of every wallet you transferred to, and screenshots of the user account with the gains it displayed. The last of these matter more than they look: they document the deception. With a bank transfer, inform your bank in parallel, because recovery is only possible at all within a narrow window of time.

What you have to bear in mind for tax purposes in a case of investment fraud is a separate question, because the tax office may under certain circumstances treat phantom gains as taxable even though no money ever reached you. The details are in our article on phantom gains in crypto investment fraud.

What the disconnections achieve, and what they do not

At this point we separate what is documented from our own assessment. Documented is the number of phone numbers disconnected, documented is the requirement imposed on telecommunications providers, documented is the constellation of authorities involved. Everything that follows is our reading and not a statement by the authorities.

A disconnected number ends a call, yet it does not end a call centre. The call centres sit abroad as investigators describe it, and access to new numbers is the bottleneck the Federal Network Agency wants to narrow with tighter registration duties. Whether that holds depends, in our view, on how consistently providers vet their sales partners, and from the outside that can only be read off the next set of figures.

A second expectation follows from the rhythm of the operation, and we state it explicitly as a supposition: after more than 2,200 domains in 2025 and 13,888 phone numbers to date, the pressure is more likely to shift the perpetrators to other channels of contact than to make them stop. Messenger groups and messages on social networks need no allocated phone number. There is no reliable figure for that, which is why we give none.

For you something uncomfortable follows from it. The disconnections do not take the check off your hands. They reduce the number of calls that reach you at all, and they raise the likelihood that a call getting through comes from a newly procured number. The decision still falls in the moment you either check the licence status or fail to.

Austria, Germany and the question of jurisdiction

That 491 of the disconnected numbers are Austrian and that the Austrian Federal Criminal Police Office is involved shows the reach of the operation across the border. For you as an investor in Germany, however, the German financial supervisory authority remains the competent supervisor, and you file your criminal complaint with the German police. A platform domiciled abroad changes none of that.

Putting Operation Herakles in context: what to take away

  1. Check the licence before you pay, not afterwards. Look the provider up in the supervisory authority’s company database and compare the name, the domain and the address, not just the name. A vetted selection of trading venues is in our comparison of the best crypto exchanges.
  2. End every conversation that involves time pressure, remote access or a scan of your ID. When in doubt, call back on the provider’s officially published number instead of accepting the call-back. Which exchanges are under supervision is set out in the comparison of regulated crypto exchanges.
  3. Move your holdings out of reach of others. Anyone holding their own keys cannot grant a release over the phone, because there is nobody who could grant one. The devices and their differences are in the hardware wallet comparison.

The joint press release of the authorities involved can be read in the original; a detailed assessment of the technical side has been published by heise online.

(As of September 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)