Visualização de leitura

Global Crackdown on West African Crime Networks Leads to 58 Arrests

West African Organized Crime Groups

An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat posed by West African criminal networks, including Black Axe and similar groups. These networks have been linked to a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise fraud.

Operation Jackal IV Targets West African Organized Crime Groups

Operation Jackal IV also targeted money laundering activities used to move and conceal criminal proceeds across borders. INTERPOL coordinated cross-border intelligence sharing, analysis and operational support during the operation. It also provided specialized training to strengthen international investigations into financial crime. Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said the operation showed the importance of international cooperation in following illicit financial flows and disrupting criminal networks. [caption id="attachment_113806" align="aligncenter" width="600"]West African Organized Crime Groups Image Source: INTERPOL[/caption]

Major Arrests and Financial Crime Investigations

In Argentina, authorities identified 196 individuals linked to a major Crime-as-a-Service network suspected of providing website domains and money laundering support to West African organized crime groups. The investigation resulted in 17 arrests, with an INTERPOL Operational Support Team assisting with analysis of seized data and identification of suspects and criminal networks. South African authorities raided seven locations in Johannesburg linked to a syndicate involved in romance and investment scams targeting retirees in English-speaking countries. Investigators arrested 39 people, seized USD 2.67 million and blocked 257 bank accounts. In Italy, investigators identified an individual connected to a pan-European money laundering network that used shell companies, remittance services and cash withdrawals. One account processed EUR 845,000, or about USD 736,000, through 560 transactions involving 20 financial instruments. Romanian authorities dismantled a criminal group operating an investment scam through a call centre. The group promoted high returns from stocks and cryptocurrencies, with victims' money transferred to electronic wallets controlled by perpetrators. Authorities estimated that EUR 143 million had been stolen and laundered globally. Eleven people were arrested, while cash, cryptocurrency, six real estate properties and luxury watches were seized.

Sextortion and Crime-as-a-Service Emerge

Beyond individual investigations, the operation highlighted emerging threats involving sextortion and Crime-as-a-Service. INTERPOL identified an increase in West African organized crime groups using sextortion to target minors, including victims as young as 14. In these cases, offenders typically contacted minors through social media, established trust and persuaded them to share explicit images or videos. They then threatened to distribute the material to the victim's contacts unless a ransom was paid. Investigators also found that some criminal syndicates were procuring Crime-as-a-Service from external providers, including through the dark web. These services were used to outsource activities such as money laundering and other operational functions. While several cases from Operation Jackal IV remain under investigation, the preliminary results demonstrate the scale and international reach of the networks targeted during the eight-month operation. The participating countries were Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.

INTERPOL Busts Massive Cybercrime Network Across MENA, 201 Arrested

Operation Ramz

A large-scale cybercrime crackdown led by INTERPOL has resulted in 201 arrests and the identification of 3,867 victims across the Middle East and North Africa region. The coordinated operation, known as Operation Ramz, is being described as the first cybercrime operation of its scale conducted by INTERPOL in the MENA region. The operation ran between October 2025 and February 28, 2026, bringing together law enforcement agencies from 13 countries to disrupt malicious cyber infrastructure linked to phishing, malware campaigns, and online scams. Authorities also identified 382 additional suspects and seized 53 servers during the operation. Operation Ramz focused on tackling cyber threats that continue to cause financial and operational damage across the region. Participating countries included Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE. According to INTERPOL, nearly 8,000 intelligence packages and data points were shared among participating countries to support investigations and help authorities trace malicious infrastructure connected to cybercriminal activity. INTERPOL said the operation highlighted the growing importance of cross-border collaboration in combating cybercrime networks that often operate across multiple jurisdictions. “In a world where cybercriminals exploit the digital landscape without borders, Operation Ramz demonstrates the effectiveness of global collaboration,” said Neal Jetton. He added that INTERPOL remains committed to working with member countries and private-sector partners to dismantle malicious infrastructure and bring cybercriminals to justice.

Cybercrime Investigations Across MENA

Authorities involved in Operation Ramz uncovered several cybercrime operations tied to phishing schemes, malware distribution, and financial fraud. In Qatar, investigators used intelligence gathered during the operation to identify compromised devices that were unknowingly being used to spread malicious threats. Officials secured the infected systems and notified affected users to prevent further misuse. Jordanian authorities uncovered a fraudulent investment scam operating through what appeared to be a legitimate online trading platform. Victims were convinced to deposit funds before the platform disappeared. During a raid, police found 15 individuals carrying out the scams. However, investigators later determined the workers themselves were victims of human trafficking who had been lured from Asian countries with fake job offers. Their passports were confiscated upon arrival, and they were forced into cyber fraud operations. Two individuals suspected of organizing the scheme were arrested. In Oman, investigators identified a server hosted in a private residence containing sensitive information. Although the owner had legitimate access to the data, authorities found the server had multiple critical vulnerabilities and malware infections. Officials disabled the server to reduce further cybersecurity risks. Authorities in Algeria dismantled a phishing-as-a-service website during the operation. Law enforcement seized servers, computers, mobile devices, and hard drives containing phishing scripts and malicious software. One suspect was arrested in connection with the activity. Meanwhile, Moroccan authorities seized computers, smartphones, and external hard drives containing banking data and phishing software. Three individuals are currently facing judicial proceedings while investigations continue into other possible suspects.

Private Sector Partners Supported Operation Ramz

Several cybersecurity and threat intelligence organizations, including Team Cymru, Kaspersky, Group-IB, the Shadowserver Foundation, and TrendAI, supported operation Ramz. These organizations worked with INTERPOL to provide threat intelligence, internet visibility, and technical support to identify malicious servers and track illegal cyber activity linked to phishing, malware, and online scam networks. Joe Sander said cybercrime requires a coordinated international response involving both law enforcement and private-sector intelligence partners. “Cybercrime is borderless, and the only effective response is one that is equally borderless,” Sander said. “Operation Ramz is exactly that kind of response.” Team Cymru stated that it contributed external threat intelligence and internet-scale telemetry to help authorities map cybercriminal infrastructure and generate operational leads during the investigations.

Rising Focus on MENA Cybercrime Threats

The success of Operation Ramz reflects the growing focus on cybersecurity cooperation in the MENA region as phishing attacks, malware campaigns, and financial cyber scams continue to evolve. The operation also demonstrated how intelligence sharing between governments and cybersecurity firms can help authorities rapidly identify malicious infrastructure and prevent additional victims. Operation Ramz received support from Qatar’s Ministry of Interior and partial funding from the European Union and the Council of Europe under the CyberSouth+ project.
❌