{"id":5155,"date":"2026-07-17T14:46:58","date_gmt":"2026-07-17T13:46:58","guid":{"rendered":"https:\/\/kriptoblog.hu\/?p=5155"},"modified":"2026-07-19T15:40:47","modified_gmt":"2026-07-19T14:40:47","slug":"kriptocsalas-alrendorokkel-amikor-a-hivo-iranyitja-az-ellenorzest-3833","status":"publish","type":"post","link":"https:\/\/kriptoblog.hu\/en\/kriptocsalas-alrendorokkel-amikor-a-hivo-iranyitja-az-ellenorzest-3833\/","title":{"rendered":"UK Jails Three in \u00a34M Crypto Scam Using Fake Police Impersonation"},"content":{"rendered":"<p>\nLondon's Southwark Crown Court has sentenced three men to prison for a crypto fraud built on police impersonation. The group stole more than \u00a34 million in cryptocurrency from eight victims. They did not exploit a protocol flaw \u2014 they convinced victims that handing over data or transferring funds was how to protect their wealth.\n<\/p>\n<p>\nThe Metropolitan Police's July 16, 2026 statement details the sentences and the investigation. Decrypt's follow-up the next day describes the same case as a $5.3 million loss, but gives no reference exchange rate or conversion timestamp. To avoid false precision, this article uses the police's primary figure of more than \u00a34 million throughout. The real takeaway is that the criminals controlled both the danger narrative and the channel used to verify it.\n<\/p>\n<h2>The attackers hijacked the verification process<\/h2>\n<p>\nWhat the UK case and two documented Hungarian incidents share is not simply urgency. In all three, the same party controlled the entire verification loop: they named the threat, claimed authority to act, supplied the channel that appeared to confirm their story, and then dictated the \"safe\" solution.\n<\/p>\n<p>\nThe UK fraudsters posed as police officers and told victims their crypto holdings were at risk. In a Hungarian case in Szeksz\u00e1rd, the caller claimed to work for the Budapest Metropolitan Police Headquarters. In a separate Hungarian case from Szerencs, the caller claimed to be a staff member at a crypto trading platform and cited an unauthorized login. The assumed role made an outsider's instructions look like official assistance, and the danger story reframed data disclosure or a wire transfer as asset protection.\n<\/p>\n<p>\nThe second layer of deception was cutting off outside verification. The UK group built fake police websites. In the Szeksz\u00e1rd case, a second \"policewoman\" sent a confidentiality agreement and even instructed the victim not to tell the bank teller the real reason for the transfer. The call and the seeming confirmation both belonged to the same fraud infrastructure, so neither one actually verified the other.\n<\/p>\n<p>\nThe sources do not say exactly which claim each victim accepted and why. But there is independent research on the role of authority. In two experiments by Maxim Baryshevtsev and Joseph McGlynn, elements leaning on authority and sympathy increased susceptibility to phishing messages. Layered fear and urgency cues, by contrast, reduced susceptibility because they made the fraud attempt easier to spot.\n<\/p>\n<p>\nThe 2020 study examined emails, not phone-based police impersonation, so its result cannot be mapped directly onto this case. But it does warn that the \"urgency always works\" explanation is too simple. In the UK case, the authority-projecting role was paired with a fake verification site and a solution dictated by the fraudster. It was not a single psychological lever but mutually reinforcing channels that shut down verification.\n<\/p>\n<p>\nThe UK government's fraud policy material describes this method as a multi-stage, multi-channel social engineering process. According to the document, criminals impersonate trusted organizations by phone or on fake websites, then generate fear and urgency. From the three cases examined here comes a practical test: if the description of the threat, the route for verifying it, and the requested solution all come from the same inbound contact, no independent verification has taken place yet.\n<\/p>\n<h2>Eight victims, three convictions<\/h2>\n<p>\nAccording to the Metropolitan Police, Anthony Ikenwe and Kevin Nwamma each received six years for conspiracy to commit fraud and five years for money laundering. Hamza Bashir was sentenced to three years and nine months, plus three years. In all three cases the two sentences run concurrently, so Ikenwe and Nwamma serve six years in practice and Bashir three years and nine months; the terms are not added together.\n<\/p>\n<p>\nIkenwe and Nwamma pleaded guilty in April. Bashir changed his plea on the eighth day of the trial, after the evidence had been presented. The court phase is closed, but the search for the wider network and the stolen assets is not: UK police continue to work with domestic and international partners to identify further participants.\n<\/p>\n<p>\nAuthorities have so far recovered approximately \u00a31 million in assets directly linked to victims. That is significant, but only a fraction of the losses exceeding \u00a34 million. The case therefore shows two separate outcomes: identifying the perpetrators can succeed even when the full stolen sum is not immediately returned.\n<\/p>\n<h2>No single blockchain trail cracked the case<\/h2>\n<p>\nVictims filed reports in January 2025. Investigators then combined several data streams: blockchain transactions, communications and financial records, crypto exchange data, and internet service provider information. They identified shared aliases, phone numbers, websites, crypto wallets, and spending patterns. Reports that at first appeared unrelated were gradually assembled into a single organized network.\n<\/p>\n<ol>\n<li>november 20-\u00e1n h\u00e9t londoni \u00e9s essexi c\u00edmen hajtottak v\u00e9gre \u00f6sszehangolt int\u00e9zked\u00e9st. Negyven mobiltelefont, tov\u00e1bbi digit\u00e1lis eszk\u00f6z\u00f6ket, luxuscikkeket \u00e9s kriptovagyont foglaltak le. A k\u00f6zlem\u00e9ny Kevin Nwamm\u00e1t olyan t\u00e1rc\u00e1kb\u00f3l indul\u00f3 utal\u00e1sokkal is \u00f6sszekapcsolta, amelyek az \u0151 k\u00f6zleked\u00e9si v\u00e1llalkoz\u00e1s\u00e1hoz k\u00f6thet\u0151 banksz\u00e1ml\u00e1kra \u00e9rkeztek.<\/li>\n<\/ol>\n<p>\nThe public data also reveals an important technical limit. The Metropolitan Police did not disclose which blockchains the assets moved across, and did not publish wallet addresses, transaction IDs, exchange names, or the analytics software used. Nor did they claim that a mixer was involved. These details cannot be responsibly reconstructed.\n<\/p>\n<p>\nThe evidence base did not rest on on-chain movement alone. Blockchain data was assessed together with exchange, communications, financial, and ISP information. Seized devices and physical assets were added on top. The statement does not break down the exact evidentiary role of each dataset, but the message is clear: the connection was made by combining different data domains, not by any single source.\n<\/p>\n<h2>The same pattern in two Hungarian cases<\/h2>\n<p>\nIn a case reported by Hungary's KiberPajzs cyber-safety program on July 16, 2026, an alleged police approach in Szeksz\u00e1rd ended with 2.47 million forints (roughly $6,900) moved to a \"secure account.\" It was not a crypto case, yet it repeated almost exactly the decision-making architecture of the UK attack: an authority role, a threat narrative, an official-looking document, and then the supposed placing of funds into safety. The KiberPajzs warning is unambiguous: no such thing as a \"security account\" exists, and neither police nor financial institutions ever ask anyone to protect their money by wiring it to a stranger's account.\n<\/p>\n<p>\nA Hungarian National Police statement from August 26, 2025 shows a different entry point. The caller posed as a staff member of a crypto trading platform, cited an unauthorized login, and then persuaded the victim to enter a recovery phrase into a Ledger app. According to the statement, more than $16,000 worth of bitcoin then disappeared; Hungarian police also reported the loss as more than 5 million forints.\n<\/p>\n<p>\nThe three cases did not ask for the same thing: account credentials or a transfer from the UK victims, a bank wire from the Szeksz\u00e1rd victim, and a recovery phrase from the Hungarian crypto holder. The shared risk was that the caller not only named the problem but also dictated the verification method and the \"solution.\" As long as all three remain in the caller's hands, there is no independent evidence that the danger is real.\n<\/p>\n<h2>Switch to an independent channel<\/h2>\n<p>\nIf an inbound call claims your crypto is at risk, the first task is not to verify anything inside that call \u2014 it is to change channels. End the conversation, do not initiate any transaction, and do not use the caller's link, phone number, or app suggestion. Then open the service provider's official site or app yourself, or look up the authority's public contact details independently.\n<\/p>\n<p>\nAfter switching channels, three things must be checked separately: whether the reported incident actually exists, whether the organization in question really contacted you, and whether they are permitted to request an action that grants access or moves assets. Two of these being off is enough to stop. Hungarian police state that legitimate financial service providers never ask for a recovery phrase, password, or device identifier by phone; KiberPajzs states that no \"secure account\" run by police or a bank exists.\n<\/p>\n<p>\nIf data has already been handed over or a transfer already made, the same rule applies: switch to an official channel. Contact the service provider and the police using details you sourced yourself, not through further discussion with the caller.\n<\/p>\n<p>\nThe UK verdict does not prove that every crypto movement is easily traceable or that every stolen sum can be recovered. It shows that with off-chain evidence added in, even a complex network can be exposed. For prevention, though, what looks like a technical problem is settled by a communication question: who chose the channel you are using to check whether the danger is real?\n<\/p>\n<h2>Sources<\/h2>\n<ul>\n<li>Metropolitan Police: <em>Men who stole more than \u00a34 million of crypto are jailed<\/em>, <a href=\"https:\/\/news.met.police.uk\/news\/men-who-stole-more-than-4-pounds-million-of-crypto-are-jailed-511271\" target=\"_blank\" rel=\"noopener\">forr\u00e1s<\/a> (megtekintve: 2026-07-19)<\/li>\n<li>Decrypt: <em>Three Men Jailed for Posing as Police in $5.3M UK Crypto Fraud<\/em>, <a href=\"https:\/\/decrypt.co\/373702\/three-men-jailed-for-posing-as-police-in-5-3m-uk-crypto-fraud\" target=\"_blank\" rel=\"noopener\">forr\u00e1s<\/a> (megtekintve: 2026-07-19)<\/li>\n<li>UK Government: <em>Unauthorised fraud in the UK: call for evidence<\/em>, <a href=\"https:\/\/www.gov.uk\/government\/calls-for-evidence\/unauthorised-fraud-in-the-uk\/unauthorised-fraud-in-the-uk-call-for-evidence\" target=\"_blank\" rel=\"noopener\">forr\u00e1s<\/a> (megtekintve: 2026-07-19)<\/li>\n<li>KiberPajzs: <em>\u201eBiztons\u00e1gi sz\u00e1ml\u00e1s\u201d csal\u00e1s a rend\u0151rs\u00e9g nev\u00e9ben<\/em>, <a href=\"https:\/\/kiberpajzs.hu\/hirek\/biztonsagi-szamlas-csalas-a-rendorseg-neveben\" target=\"_blank\" rel=\"noopener\">forr\u00e1s<\/a> (megtekintve: 2026-07-19)<\/li>\n<li>Magyar Rend\u0151rs\u00e9g: <em>Amikor a mese r\u00e9m\u00e1lomm\u00e1 v\u00e1lt<\/em>, <a href=\"https:\/\/www.police.hu\/hu\/hirek-es-informaciok\/legfrissebb-hireink\/matrix-projekt\/amikor-a-mese-remalomma-valt\" target=\"_blank\" rel=\"noopener\">forr\u00e1s<\/a> (megtekintve: 2026-07-19)<\/li>\n<li>Baryshevtsev\u2013McGlynn: <em>Persuasive Appeals Predict Credibility Judgments of Phishing Messages<\/em>, <a href=\"https:\/\/pubmed.ncbi.nlm.nih.gov\/32271628\/\" target=\"_blank\" rel=\"noopener\">forr\u00e1s<\/a> (megtekintve: 2026-07-19)<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Three men jailed in London for a \u00a34M+ crypto fraud posing as police. The real lesson: attackers controlled the verification channel, not just the story.<\/p>","protected":false},"author":1,"featured_media":5154,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[102],"tags":[958,959,955,960,956,957],"class_list":["post-5155","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-biztonsag","tag-brit-rendorseg","tag-kriptobiztonsag","tag-londoni-kriptocsalas","tag-metropolitan-police","tag-social-engineering","tag-telefonos-csalas"],"_links":{"self":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts\/5155","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/comments?post=5155"}],"version-history":[{"count":2,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts\/5155\/revisions"}],"predecessor-version":[{"id":5157,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/posts\/5155\/revisions\/5157"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/media\/5154"}],"wp:attachment":[{"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/media?parent=5155"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/categories?post=5155"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kriptoblog.hu\/en\/wp-json\/wp\/v2\/tags?post=5155"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}