Author: Rita Valentino
Commitee: Cybersecurity Strategic Committee
Date: 22/06/2026

The digitalization of economic and tax systems in Europe is significantly changing the way financial crimes are committed today. These crimes now lie somewhere between traditional tax evasion and offenses linked to the use of digital technologies.

In this context, Carousel VAT fraud is a clear example, as it is not based solely on tax rules, but also on how the European Single Market operates and on trade between countries.

 

This type of fraud highlights a real shift in recent years: increasing digitalization, the high volume of financial transactions, and the way financial systems communicate with each other make it possible to create complex schemes that are difficult to detect using traditional controls. [3]

 

In particular, this type of fraud exploits the mechanism of VAT-exempt intra-EU transactions. In practice, goods and invoices circulate between different companies located in several European Union countries, and within this chain, one or more companies collect VAT without remitting it to the state. At the same time, other companies generate fictitious tax credits, creating a system based on transactions that only appear legitimate. [2]

Today, this model has evolved thanks to digital tools, as it has become increasingly easy to set up companies quickly, manage electronic invoices, and enable communication between tax systems in different European countries.

From a cybersecurity perspective, this scenario shows that the main problem is not a cyber attack on systems, but rather the deceptive use of seemingly correct information.

 

A representative case of this scenario is certainly the one that emerged in March 2026 in the Naples area, coordinated by the European Public Prosecutor’s Office together with the Italian Financial Police.

The investigation involved a criminal network operating in the IT goods sector, with a transactional and fictitious structure, for a value exceeding 500 million euros.

According to the investigators, the system was based on companies that were set up and quickly shut down, used to simulate commercial exchanges between several European countries, including the Netherlands, Romania, Germany, Hungary, and Italy. In many cases, the goods were not even moved, despite the fact that they were regularly recorded in tax documents.

This investigation led to the identification of 64 suspects operating mainly in the province of Naples and, based on the evidence gathered, the Naples court ordered the preventive seizure of shares in 5 companies, 4 commercial complexes, and an industrial warehouse, for a total value exceeding 32 million euros.

In this case, the role of the European Public Prosecutor’s Office was certainly crucial. It is, in fact, the first supranational body capable of coordinating investigations beyond national borders. With this structure, it is possible to bring together information from different countries and act in a coordinated manner, preventing evidence or financial flows from being dispersed across different jurisdictions. [1]

 

All of this highlights how financial fraud in Europe has become increasingly complex to detect and closely linked to digital technologies. [3]

As a result, the role of the European Public Prosecutor’s office is increasingly important, not only for investigations, but also for improving the reliability of data monitoring capabilities within the European economic system.

Furthermore, it is clear that today cybersecurity also plays a role in verifying the quality and veracity of the information on which the internal economic system is based.

 

Thanks to technological development, we now have tools that allow us to discover if information has been manipulated to make it appear only apparently legitimate.

The most effective tool for this type of this type of fraud is definitely Transaction Network Analysis (TNA). This tool is configured as cross-checking software for VAT return data provided by companies carrying out transactions involving multiple Member States. More precisely, through a data extraction process aimed at finding unknown information from other already know information. The software aims to carry out a preliminary, and pervasive, collection of formal indications to be processed in order to identify both any inconsistencies between purchases and sales made by companies, whose activity has been the subject of reporting by the system, and other elements sympathetic of the presence of fraudulent operations: in this way, the Union intended to place individuals to whom the report is addressed in a position to prevent the finalization of the fraud or, where it is carried out, to combat it immediately.

It is certainly a fundamental tool at EU level that facilitates the rapid exchange and automated analysis of VAT data on cross-border transactions. It allows tax authorities to intervene in near real time, before the “missing trader” disappears [4].


[1] European Public Prosecutor’s (EPPO), investigation “Carosello”- VAT fraud in the IT sector in Italy (2026)

https://www.eppo.europa.eu/en/media/news/investigation-carosello-eppo-investigates-large-scale-vat-carousel-fraud-it-sector-italy

 

Eunews, frodi iva nel settore informatico, la Procura europea smantella rete criminale con cabina di regia a Napoli (2026)

https://www.eunews.it/2026/03/13/frodi-iva-nel-settore-informatico-la-procura-europea-smantella-rete-criminale-con-cabina-di-regia-a-napoli/

 

[2] Studio Cataldi, IVA intracomunitaria e frodi carosello

https://www.studiocataldi.it/articoli/34570-frodi-carosello.asp

 

[3] VAT IT, MTIC/ Carousel VAT fraud mechanism

https://vatit.com/blog/what-is-a-carousel-scheme-vat-carousel-fraud/

 

[4] Potenziali benefici, rischi e limiti del “Transaction Network Analysis” quale strumento di prevenzione e contrasto alle frodi IVA infra-UE.

https://www.rivistadirittotributario.it/wp-content/uploads/2019/08/Purpura.pdf

0
Would love your thoughts, please comment.x