German prosecutors have formally charged the main suspects in “Operation Chargeback,” one of the largest card fraud cases ever investigated in Europe. The Koblenz Public Prosecutor General’s Office filed the charges in early July, Bloomberg reported on July 7, 2026. The network allegedly took more than €300 million from 4.3 million cardholders in 193 countries, and it did so from inside regulated payment companies rather than by attacking them from outside.
Among those charged are Mirko Hüllemann, founder of the German PSP Unzer (formerly Heidelpay), and Brigitte Häuser-Axtner, a former manager at Wirecard AG. The case comes after nearly five years of investigation, opened in the wake of the Wirecard scandal, and it carries an uncomfortable lesson for the industry: the most effective fraud operates through the payment system’s own licensed players.
Millions of small subscriptions, built to avoid disputes
Between 2016 and 2021, the network used data from more than 4.3 million cards to create nearly 19 million fake recurring subscriptions. They ran through about 2,000 sham websites posing as streaming services, dating platforms or adult content sites. Each charge was set at around €50 a month, under deliberately obscure descriptors. The small ticket size was the core of the strategy.
Most cardholders overlook a single €50 debit, or put it down to a subscription they forgot about, and never dispute it. Multiplied across millions of cards and dozens of months, those charges add up to a huge flow of money while keeping the dispute rate low enough to stay under the card schemes’ monitoring thresholds. Hence the irony in the operation’s name: the fraudsters built their model around avoiding chargebacks.
The fraud entered through the PSPs themselves
What sets “Operation Chargeback” apart from ordinary card fraud is the point of entry. According to investigators, the network worked through payment service providers and compromised four large German PSPs to inject fraudulent transactions directly into the payment rails. Executives and compliance staff allegedly gave the network access in exchange for fees, and one provider is said to have installed software written specifically for laundering. The proceeds then moved through more than 100,000 laundering transactions via German bank accounts.
| Link | Role in the scheme |
|---|---|
| Shell companies (UK, Cyprus) | Straw directors and forged KYC documents to set up merchants that looked legitimate |
| ~2,000 fake websites | Polished streaming, dating and adult storefronts with no real business behind them |
| Compromised German PSPs | Entry point for the transactions, with alleged insider help on the compliance side |
| Pass-through bank accounts | More than 100,000 transactions to disperse and launder the proceeds |
| Victims’ cards | 4.3M cardholders charged about €50 a month under opaque descriptors |
German press reports name the four providers whose systems were allegedly used: Unzer, Payone, Nexi Germany (formerly Concardis), and Wirecard, which has since collapsed. The three still operating account for a significant share of German e-commerce acquiring, which shows how much systemic risk builds up when internal compliance is corrupted.
Five years from first reports to charges
Lessons for acquirers and PSPs
The case exposes a blind spot in fraud controls, which are too often designed to catch a single outlier transaction. Here, every transaction was small, regular and plausible. Only the overall pattern gave the fraud away. Several lessons follow:
- KYB beyond the storefront: a polished online shop does not prove a real business. Merchant onboarding has to verify economic substance (beneficial ownership, a coherent business model, a track record), not just surface plausibility.
- Monitoring of small recurring payments: treating small recurring amounts as “noise” is a mistake. Their deliberate smallness was the laundering tool. Models need to score patterns (frequency, geographic spread, generic descriptors) as well as amounts.
- Chargeback ratio as a weak signal: an unusually low dispute rate at a high-volume merchant deserves as much scrutiny as a high one.
- Insider risk: controls are only as good as the people who run them. Segregation of duties and audits of privileged access in compliance teams matter as much as automated rules.
- The value of shared intelligence: the breakthrough came when the FIU connected isolated reports. The quality and volume of suspicious activity reports determine what a country can detect.
Beyond the €300 million in confirmed losses, and the roughly €750 million the network allegedly tried to charge in total, “Operation Chargeback” is a reminder of how the payment system works. Trust is delegated down a chain, from the issuer through the PSP to the acquirer, and the chain is only as strong as its most compromised link. Secure rails are not enough if the people who govern them can be bought.