Ukraine has signed a new law creating specific criminal liability for fraudulent call centres, with organisers facing up to 12 years in prison amid a wider cybercrime crackdown.

Ukraine Criminalises Scam Call Centres With Up to 12 Years in Prison

The420 Web Correspondent
8 Min Read

Ukraine has introduced tougher criminal penalties for fraudulent call centres, with people who establish or run such operations facing up to 12 years in prison as Kyiv intensifies its crackdown on large-scale cyber fraud.

The Verkhovna Rada passed Bill No. 10190 on September 16 with 313 lawmakers voting in favour. President Volodymyr Zelenskyy said later the same day that he had signed the legislation, bringing a long-running effort to create specific criminal liability for scam call centres closer to implementation.

The law targets not only the people who organise such centres but also those who knowingly work for them, recruit operators or provide services and information that help the criminal network function.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Scam call centres now become a specific criminal offence

The legislation introduces a new offence covering what Ukrainian law describes as an “electronic communications fraudulent organised group”.

That means a stable group of at least three people organised to systematically obtain another person’s property through deception or abuse of trust using electronic communications.

The law covers the creation and management of such groups, knowingly participating in them and supplying services, information or other assistance.

Recruiting workers by offering jobs or payments is also specifically covered.

Officials who deliberately help such organisations operate or create conditions allowing members to escape criminal responsibility can also face liability.

Ukrainian judicial reporting says leading a fraudulent call centre can carry imprisonment of seven to 12 years.

The law also creates a possible route out for lower-level participants. Ordinary members, excluding organisers and leaders, may be released from criminal liability if they voluntarily report the group to law enforcement and help expose its activities.

Stolen banking and personal data also comes under focus

The legislation goes beyond phone operators sitting inside a physical call centre.

Ukraine is also introducing a specific offence for electronic communications fraud involving the unlawful collection, storage, processing or use of personal data, bank secrecy information, account details, payment-card information or authorisation codes to steal property.

That matters because modern scam centres rarely depend only on cold calls.

Operators may already possess a victim’s name, bank information or other personal details before making contact. That information can make a fake bank employee, broker or government official sound convincing.

Fraudsters can then use social engineering to pressure victims into transferring money, revealing security codes or installing software that gives remote access to their devices.

The new framework attempts to address that wider ecosystem rather than treating each phone call as an isolated fraud.

Law follows massive crackdown on 94 scam centres

The legislation comes after one of Ukraine’s largest operations against suspected fraudulent call centres.

In August, the National Police, Security Service of Ukraine and prosecutors conducted 411 searches across the country and shut down 94 suspected scam call centres. Police found 1,794 equipped operator workstations and said 26 people had already been notified of suspicion.

Investigators said operators had posed as bankers, brokers and law-enforcement officers while directing victims towards fake investment platforms or trying to gain access to bank accounts.

Authorities seized more than 3,000 pieces of computer equipment, bank cards, access to cryptocurrency wallets, vehicles and large amounts of cash during the operation.

Victims were reported across Ukraine, the European Union, Israel, Kazakhstan and Central Asia, showing how these operations can function as cross-border businesses rather than local fraud cells.

A month earlier, Kyiv cyber police dismantled another call centre accused of stealing more than $500,000 from over 20 American victims.

Police said English-speaking operators, including recruits from the United States, West Africa and Europe, posed as financial advisers and persuaded victims to put money into fictitious investments.

Corruption probe added political urgency

The issue became politically explosive after Ukraine’s anti-corruption agencies opened an investigation into alleged protection of fraudulent call centres by officials linked to the Prosecutor General’s Office.

The National Anti-Corruption Bureau and Specialised Anti-Corruption Prosecutor’s Office said they had uncovered a criminal organisation allegedly involving an official from the prosecutor’s office who was suspected of accepting payments from scam centres and laundering proceeds. Five people were identified in the proceedings.

Former Prosecutor General Ruslan Kravchenko was not charged in the case.

He publicly denied involvement in protecting illegal call centres or receiving money from them. He later submitted his resignation, which parliament approved, and Zelenskyy formally dismissed him.

Reuters reported that a subordinate was accused of facilitating the alleged fraud network, while Kravchenko said his departure was a political decision intended to prevent his office becoming part of a wider confrontation.

Those allegations remain under investigation and should not be treated as proven wrongdoing by people who have not been convicted.

Why scam call centres are difficult to dismantle

Fraudulent call centres can operate much like legitimate sales businesses.

Operators may work from organised offices, follow scripts, receive commissions and use customer databases or specialised software.

But the actual product is deception.

One team may impersonate bank employees, while another pushes fake cryptocurrency or stock investments. Separate people can manage stolen data, mule bank accounts, cryptocurrency transfers and recruitment.

That structure allows the people speaking to victims to remain several layers away from those controlling the money.

The new Ukrainian law attempts to close that gap by targeting the organisation itself, including recruitment and deliberate support services, rather than prosecuting only the individual call used to steal money.

Cybercrime expert and former IPS officer Prof. Triveni Singh said effective action against such networks requires investigators to follow the money, digital infrastructure and recruitment chain alongside the front-line operators.

What this means for you

A convincing caller may already know your name, bank or account details because the information was obtained elsewhere. Never share OTPs, card credentials or remote-access permissions simply because the caller appears to know genuine personal information.

The420 Insight

Ukraine’s new law recognises that scam call centres are no longer informal groups of people making fraudulent calls. They can operate as structured criminal businesses with recruiters, managers, stolen databases, banking channels and international victims. The law now aims at that entire organisation rather than only the final phone call.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected