Illustrative image generated with AI
Operation Jackal IV: 58 Arrests in 22 Countries Against Black Axe and Cyber Fraud Networks
The results of Operation Jackal IV, coordinated by INTERPOL and conducted between November 2025 and June 2026, were made public in recent hours.
Text generated by artificial intelligence, published without human review. AI transparency
The results of Operation Jackal IV, coordinated by INTERPOL and conducted between November 2025 and June 2026, were made public in recent hours. Twenty-two countries targeted criminal networks from West Africa and the Black Axe syndicate, identifying 263 suspects and arresting 58 people. Charges range from romance and cryptocurrency investment scams to BEC fraud, with links to violent crimes. This is not a single software vulnerability, but a transnational police operation against a criminal ecosystem that uses digital infrastructure and illicit services on a large scale.
The numbers by country
The operation produced concrete results in several countries. In Argentina, 17 arrests and 196 suspects were linked to a Crime-as-a-Service network: the group offered web domains and money laundering services to other criminal organizations. In South Africa, 39 arrests, 257 bank accounts blocked, and the seizure of $2.67 million hit a group targeting English-speaking pensioners with investment and romance scams. In Romania, 11 arrests dismantled a fraudulent call center that offered fake stock and cryptocurrency opportunities. In Italy, a suspect was identified linked to a pan-European money laundering network using shell companies, money remittances, and cash.
Overall Jackal IV numbers remain lower than other parallel operations, but the value lies in cooperation extended to 22 countries and the ability to hit different nodes of the same criminal chain: from call centers to money laundering services, to web infrastructure providers.
Sextortion of minors and outsourcing of money laundering
INTERPOL reported a particularly alarming element that emerged during the operation: sextortion of minors. Criminal groups contact children and adolescents on social media, induce them to share explicit material, and then threaten to distribute it unless victims pay a ransom. Separate figures for this type of crime were not disclosed, but the presence of the phenomenon within Jackal IV shows how the same networks move easily from financial fraud to extortion of minors.
Another data point that emerged is the outsourcing of parts of criminal operations. Some groups entrusted money laundering and other activities to providers found on the dark web, in a Crime-as-a-Service model that lowers entry barriers for new criminal cells. The same model was observed in Argentina with the network offering web domains and money laundering services.
Parallel operations: Red Card 2.0 and First Light 2026
Jackal IV is not an isolated event. Between December 8 and January 30, Operation Red Card 2.0 took place, operating in 16 African countries and leading to 651 arrests. In July, Operation First Light 2026 was announced, with 97 countries involved, 5,811 arrests, and the seizure of $293 million in illicit assets.
This sequence of operations indicates an intensification of international action against organized cybercrime. The results also show a precise geography: many networks have operational roots in West Africa, but victims and money flows cross Europe, South America, and English-speaking countries. The main victims remain pensioners, people seeking online relationships, and non-professional investors attracted by promises of cryptocurrency returns.
Limits of defenses with valid credentials: the 2026 Blue Report
While police forces strike criminal networks, a defensive data point published in the 2026 Blue Report adds context. The report, based on 338 million simulations conducted in customer production environments, shows that when an attacker has valid credentials, only 37% of actions are blocked. Overall prevention scores, the document explains, can hide a significant drop after initial access: defenses work better at stopping intrusion from outside, but much worse at detecting and blocking internal movements of an already compromised account.
No specific vendors or products were indicated in the report. However, the data is directly relevant for organizations that want to reduce the impact of BEC fraud and unauthorized access, two techniques used by the networks targeted by Jackal IV.
What happens now: the prevention front
No specific technical mitigations related to this operation were disclosed. The fight against Black Axe and the targeted networks is entrusted to police actions, which will continue with international cooperation. On the defensive side, the 2026 Blue Report suggests a concrete direction: strengthen controls after initial access. Most organizations concentrate efforts on the perimeter, but the drop in effectiveness with valid credentials indicates the need for more behavioral signals, internal segmentation, and monitoring of anomalous activities after login.
For individual citizens, the typical victims of these networks remain people contacted via social media or messaging apps, pushed to invest in fake platforms or share personal data. The implicit recommendation is caution toward unsolicited financial offers and requests for intimate material, especially when they come from profiles known only online.
Sources
This article is an original reworking based on the sources below.
