← Back to News
Fraud

German prosecutors charge PSP insiders in €300M card fraud

Koblenz prosecutors have charged the main suspects in Operation Chargeback, a fraud of more than €300 million that hit 4.3 million cardholders in 193 countries. The scheme got in through four German payment providers, allegedly with help from executives and compliance staff.

German prosecutors have formally charged the main suspects in “Operation Chargeback,” one of the largest card fraud cases ever investigated in Europe. The Koblenz Public Prosecutor General’s Office filed the charges in early July, Bloomberg reported on July 7, 2026. The network allegedly took more than €300 million from 4.3 million cardholders in 193 countries, and it did so from inside regulated payment companies rather than by attacking them from outside.

Among those charged are Mirko Hüllemann, founder of the German PSP Unzer (formerly Heidelpay), and Brigitte Häuser-Axtner, a former manager at Wirecard AG. The case comes after nearly five years of investigation, opened in the wake of the Wirecard scandal, and it carries an uncomfortable lesson for the industry: the most effective fraud operates through the payment system’s own licensed players.

€300M+
confirmed losses for cardholders
Koblenz prosecutors
4.3M
payment cards misused
Infosecurity Magazine
193
countries affected
Bloomberg
~19M
fake subscriptions created
heise online
~2,000
fake merchant websites set up
FinanceFeeds
€750M
total amount the network tried to charge
heise online

Millions of small subscriptions, built to avoid disputes

Between 2016 and 2021, the network used data from more than 4.3 million cards to create nearly 19 million fake recurring subscriptions. They ran through about 2,000 sham websites posing as streaming services, dating platforms or adult content sites. Each charge was set at around €50 a month, under deliberately obscure descriptors. The small ticket size was the core of the strategy.

Most cardholders overlook a single €50 debit, or put it down to a subscription they forgot about, and never dispute it. Multiplied across millions of cards and dozens of months, those charges add up to a huge flow of money while keeping the dispute rate low enough to stay under the card schemes’ monitoring thresholds. Hence the irony in the operation’s name: the fraudsters built their model around avoiding chargebacks.

🔑
How transaction laundering works
Transaction laundering is at the center of the case. It means running payments for an illegal or undisclosed business through a merchant account that appears legitimate. The real beneficiary stays hidden: to the acquirer, the scheme and the issuing bank, each payment looks like an ordinary purchase from a properly onboarded online merchant. It is the payments equivalent of a shell company.

The fraud entered through the PSPs themselves

What sets “Operation Chargeback” apart from ordinary card fraud is the point of entry. According to investigators, the network worked through payment service providers and compromised four large German PSPs to inject fraudulent transactions directly into the payment rails. Executives and compliance staff allegedly gave the network access in exchange for fees, and one provider is said to have installed software written specifically for laundering. The proceeds then moved through more than 100,000 laundering transactions via German bank accounts.

LinkRole in the scheme
Shell companies (UK, Cyprus)Straw directors and forged KYC documents to set up merchants that looked legitimate
~2,000 fake websitesPolished streaming, dating and adult storefronts with no real business behind them
Compromised German PSPsEntry point for the transactions, with alleged insider help on the compliance side
Pass-through bank accountsMore than 100,000 transactions to disperse and launder the proceeds
Victims’ cards4.3M cardholders charged about €50 a month under opaque descriptors
Links in the fraud chain

German press reports name the four providers whose systems were allegedly used: Unzer, Payone, Nexi Germany (formerly Concardis), and Wirecard, which has since collapsed. The three still operating account for a significant share of German e-commerce acquiring, which shows how much systemic risk builds up when internal compliance is corrupted.

Five years from first reports to charges

2016–2021
The alleged fraud
About 19M fake subscriptions are created on roughly 2,000 sham websites.
2020–2021
First reports
Germany’s financial intelligence unit (FIU) cross-checks multiple suspicious activity reports and spots a recurring pattern.
Nov. 4, 2025
Raids
More than 60 searches, 250 officers deployed, 18 arrest warrants executed, and €35M in assets seized in Germany and Luxembourg.
July 7, 2026
Charges filed
Koblenz prosecutors bring formal charges. The case involved Europol, Eurojust and US investigators, and more than 90 requests for legal assistance in 30 countries.
Payment card on a computer keyboard, illustrating an online payment
A recurring charge of about €50 under an opaque descriptor: the amount was set to stay below the attention threshold of cardholders and fraud systems alike.

Lessons for acquirers and PSPs

The case exposes a blind spot in fraud controls, which are too often designed to catch a single outlier transaction. Here, every transaction was small, regular and plausible. Only the overall pattern gave the fraud away. Several lessons follow:

  • KYB beyond the storefront: a polished online shop does not prove a real business. Merchant onboarding has to verify economic substance (beneficial ownership, a coherent business model, a track record), not just surface plausibility.
  • Monitoring of small recurring payments: treating small recurring amounts as “noise” is a mistake. Their deliberate smallness was the laundering tool. Models need to score patterns (frequency, geographic spread, generic descriptors) as well as amounts.
  • Chargeback ratio as a weak signal: an unusually low dispute rate at a high-volume merchant deserves as much scrutiny as a high one.
  • Insider risk: controls are only as good as the people who run them. Segregation of duties and audits of privileged access in compliance teams matter as much as automated rules.
  • The value of shared intelligence: the breakthrough came when the FIU connected isolated reports. The quality and volume of suspicious activity reports determine what a country can detect.
⚠️
PSD3 and the PSR target the same gaps
The EU’s upcoming Payment Services Regulation tightens exactly these areas: more responsibility for PSPs on transaction monitoring, fraud data sharing between providers, and closer supervision of licensing. “Operation Chargeback” shows why regulators want to close the gap that lets a licensed player become the channel for fraud from the inside.

Beyond the €300 million in confirmed losses, and the roughly €750 million the network allegedly tried to charge in total, “Operation Chargeback” is a reminder of how the payment system works. Trust is delegated down a chain, from the issuer through the PSP to the acquirer, and the chain is only as strong as its most compromised link. Secure rails are not enough if the people who govern them can be bought.

Provenance

Published July 25, 2026

5 sources, 5 distinct domains

↗ Bloomberg · Germany files charges in ‘Operation Chargeback’ payment scam (July 7, 2026) · bloomberg.com↗ Infosecurity Magazine · Operation Chargeback uncovers €300m fraud scheme in 193 countries · infosecurity-magazine.com↗ heise online · “Operation Chargeback”: Large-scale fraud with credit card data uncovered · heise.de↗ FinanceFeeds · Germany, U.S. crack down on €300M global payment-fraud network · financefeeds.com↗ CPDs Academy · When the payment rails become the laundromat: what Operation Chargeback reveals about payment institution risk · cpds.academy
← All news