Global Crackdown on West African Crime Networks Leads to 58 Arrests
![]()

![]()

![]()

![]()

![]()
A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide.
The main suspect, a 46-year-old dual Israeli and Polish national, was arrested at an airport in Poland on May 26 at the request of Dutch authorities. Investigators believe he played an indispensable role in the organization, which allegedly carried out large-scale investment fraud targeting victims across multiple countries.
According to Dutch police, the organization functioned like a professional company with approximately 700 employees spread across nearly 20 offices globally. Individuals working as financial advisors scam operators allegedly contacted victims daily through online platforms and telephone calls while posing as legitimate investment professionals.
Authorities said the organization was structured with a central headquarters overseeing multiple teams, each assigned to target victims in specific countries. Employees reportedly worked under pseudonyms and used technical measures to hide their identities and locations.
![]()
As part of the investigation, Belgian police arrested five individuals believed to have worked as fraudulent financial advisors.
The investigation resulted in several coordinated arrests during May and July.
On July 7, authorities arrested two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian, all residing in Cyprus. A 25-year-old suspect was also arrested in Belgium the same day. On July 10, police arrested a 44-year-old Dutch national in Athens.
The main suspect has since been extradited to the Netherlands, where an examining magistrate ordered 14 days of pre-trial detention. Dutch authorities indicated that additional arrests remain possible as the investigation continues.
Investigators said the online investment scam relied on building long-term trust with victims. Individuals posing as account managers or financial advisors maintained frequent contact through phone calls and online communication, sometimes over several months.
Victims were encouraged to begin with relatively small investments that appeared to generate immediate returns. Police said the investment platforms displayed convincing but fabricated profits, even though no actual investments were being made.
As confidence grew, victims were persuaded to transfer increasingly larger amounts, often in the form of cryptocurrency fraud payments. Instead of being invested, investigators said the funds were diverted directly to the criminal organization.
Authorities also warned that victims who stop investing may later be contacted by so-called recovery companies requesting upfront deposits to recover lost funds. Police believe these recovery operations may also be connected to the same fraud networks.
Dutch authorities have received approximately 550 reports connected to the organization, while Belgian police have recorded around 200 complaints. Investigators estimate the total number of victims worldwide could reach tens of thousands.
The financial losses reported by victims in the Netherlands alone amount to nearly €25 million, with many individuals losing well over €10,000.
Dutch police said officers proactively contacted some victims after discovering that many remained unaware they had fallen victim to cyber fraud.
Financial investigators are now examining whether assets linked to the suspects can be frozen or seized.
Investigators said the criminal organization remained active since at least 2021 and relied heavily on concealed digital infrastructure to evade law enforcement.
By tracing financial transactions, IP addresses, and other digital evidence, the Dutch police identified offices, suspects, and critical infrastructure supporting the operation. Authorities worked with commercial service providers to take key elements of the network offline.
The investigation also involved Europol, with intelligence shared across multiple countries to support ongoing criminal prosecutions.
Officials said the case demonstrates the scale and sophistication of modern investment fraud operations and highlighted continued international cooperation to dismantle cyber-enabled financial crime networks.

![]()
Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware.
Led by Europol and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch ransomware attacks, financial fraud, and attacks against critical infrastructure.
During the coordinated action, authorities targeted the infrastructure supporting malware delivery rather than focusing on a single malware family.
Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting malware distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.
According to Europol, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.
[caption id="attachment_112936" align="aligncenter" width="600"]The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.
Microsoft reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.
One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.
Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish botnet by taking control of domains and shutting down supporting servers.
Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.
The Dutch Police urged WordPress administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.
Authorities said SocGholish has been linked to Evil Corp, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.
Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.
Europol's European Cybercrime Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.
The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.
Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.
![]()
Two Venezuelan nationals have been sentenced to 78 months in prison for their role in an ATM jackpotting scheme that used malware to force cash machines across the United States to dispense money illegally. The operation, which authorities say was part of a broader transnational criminal network, involved the deployment of Ploutus malware on ATMs and resulted in losses exceeding $1.5 million.
Carlos Javier Padron, 36, was sentenced after pleading guilty to conspiracy to commit bank burglary and computer fraud. His co-defendant, Oddry Arnoldo Cabrera Torrealba, 37, received the same sentence on June 11 after pleading guilty to identical charges.
According to court documents, Padron and Torrealba were members of a criminal network responsible for carrying out ATM jackpotting attacks across the United States. Their role involved physically installing a variant of Ploutus malware on targeted ATMs.
Once activated, the malware enabled attackers to send commands directly to the ATM's cash dispensing module, allowing unauthorized withdrawals of currency. Investigators said the malware was also designed to erase traces of its presence, making it more difficult for financial institutions to detect the compromise.
The two men were arrested by the Lincoln Police Department during an ATM jackpotting incident in October 2024.
Along with their prison sentences, Padron and Torrealba were jointly ordered to pay $1,537,696 in restitution to the affected financial institutions.
Officials said the investigation uncovered a much larger criminal operation following their arrests. Authorities have since indicted 96 additional individuals connected to the conspiracy on charges including bank burglary conspiracy, money laundering, computer fraud, unauthorized access to protected computers, bank fraud, and providing material support to a designated foreign terrorist organization.
U.S. officials stated that the investigation established direct and indirect links between several indicted co-conspirators and Tren de Aragua, a transnational criminal organization that originated in Venezuela.
According to investigators, the group has expanded its operations throughout the Western Hemisphere and has been involved in crimes including drug trafficking, firearms trafficking, kidnapping, robbery, extortion, commercial sex trafficking, and financial fraud.
Authorities allege that ATM jackpotting became one of the organization's revenue-generating activities, targeting financial institutions across the United States through coordinated cyber-enabled attacks.
Assistant Attorney General A. Tysen Duva said the defendants helped deploy malware as part of a criminal network that stole millions of dollars from ATMs across the country. He added that disrupting such operations is critical to protecting financial institutions from technology-enabled fraud.
U.S. Attorney Lesley Woods for the District of Nebraska described ATM jackpotting as a significant revenue source used to finance the criminal activities attributed to the organization and said federal prosecutors would continue targeting its financial networks.
The FBI's Omaha Field Office said it continues to adapt its investigative efforts as criminal organizations increasingly rely on cyber-enabled financial crimes. Homeland Security Investigations also stated that the prosecution was intended to protect both consumers and the U.S. financial system from organized criminal activity.
The investigation was led by the FBI Omaha Field Office and Homeland Security Investigations, with assistance from numerous federal, state, and local law enforcement agencies across the United States.
The case is being prosecuted by the Justice Department's Computer Crime and Intellectual Property Section, the U.S. Attorney's Office for the District of Nebraska, and Joint Task Force Vulcan.
Officials said the case forms part of a broader federal effort targeting transnational criminal organizations involved in cybercrime, financial fraud, and other organized criminal activities. The investigation into the wider network remains ongoing.

![]()

![]()

![]()

![]()

![]()

![]()

![]()