The eight-month international operation Jackal IV, coordinated by INTERPOL and involving 22 countries across six continents, resulted in the arrest of 58 individuals and the identification of 263 suspects linked to West African organized crime groups. As INTERPOL reports, the operation targeted networks responsible for a significant share of global cyber fraud — from romance scams and cryptocurrency investment schemes to business email compromise (BEC). The results affect a wide range of potential victims: retirees in English-speaking countries, private investors, and companies exposed to BEC attacks.
Key outcomes of the operation
The operation ran from November 2025 to June 2026 and covered Austria, Argentina, Australia, Canada, Côte d’Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the UAE, the United Kingdom and the United States. According to INTERPOL, the investigation uncovered three major lines of criminal activity.
Dismantling a “crime-as-a-service” network
Investigators identified 196 individuals allegedly involved in a large crime-as-a-service (CaaS) network which, according to INTERPOL, provided West African criminal groups with domains for fraudulent websites and infrastructure for money laundering. Seventeen people were arrested in connection with this case. The CaaS model is particularly dangerous because it lowers the barrier to entry for cybercriminals: instead of building their own infrastructure, perpetrators can purchase ready-made tools and services, exponentially increasing the scale of fraud.
Fraud operations in Johannesburg
Law enforcement carried out searches at seven locations in Johannesburg where a syndicate was reportedly operating that specialized in romance and investment scams targeting retirees in English-speaking countries. The organizational structure of this group is noteworthy: it functioned according to a legitimate business model, assigning participants the roles of “conversion agents” (initial contact and victim engagement) and “retention agents” (maintaining contact and maximizing extracted funds). This division of labor indicates a high degree of professionalization of fraudulent operations.
Call center in Romania: €143 million in losses
In Romania, a fraudulent call center was shut down whose operators promised victims high returns from investments in stocks and cryptocurrency assets. Victims’ funds were diverted to wallets controlled by the fraudsters. INTERPOL estimates the total damage at €143 million, stolen and laundered through international channels. In this case, 11 people were arrested; approximately €330,000 in cash and cryptocurrency, six properties and several luxury watches were seized.
Separately, an individual was identified as part of a pan-European money laundering network that used shell companies, money transfer services and cash withdrawals to conceal the origin of funds. A single account processed €845,000 through 560 transactions using 20 different financial instruments — a telling example of the complexity of schemes employed to circumvent anti-money-laundering systems.
Context: the evolution of the Jackal series
Jackal IV is the fourth iteration in a series of operations targeting financial crime linked to West African groups, in particular Black Axe and similar structures. The trajectory of previous waves helps illustrate the scale and evolution of these efforts:
- Jackal I (September 2022) — 75 arrests, 49 searches, €1.2 million intercepted in bank accounts
- Jackal II (May 2023) — 103 arrests, 1,110 suspects identified, 208 accounts blocked, €2.15 million seized or frozen
- Jackal III (April–July 2024) — 300 arrests, 400 suspects, more than 720 accounts blocked
- Jackal IV (November 2025–June 2026) — 58 arrests, 263 suspects
At first glance, the lower number of arrests in the fourth wave may seem like a step backwards. However, the shift of focus to infrastructural elements — dismantling a 196-member CaaS network, taking down call centers and exposing laundering schemes — points to a strategic move away from mass arrests of low-level operators toward the targeted destruction of the infrastructure that enables criminal activity.
Impact assessment and risks
West African cybercriminal networks pose a threat to several categories of victims:
- Older people and retirees — the primary target audience for romance scams, especially in English-speaking countries
- Private investors — victims of investment schemes touting high returns in cryptocurrency and stocks
- Businesses — vulnerable to BEC attacks, in which fraudsters impersonate executives or partners to authorize transfers
The loss amount from the Romanian scheme alone — €143 million — shows that this is not petty fraud but theft on an industrial scale. The existence of specialized CaaS infrastructure means that even when specific fraudsters are arrested, new groups can quickly launch operations as long as services providing domains and money laundering remain available.
Practical recommendations
For organizations and individuals in at-risk groups:
- Verify investment offers: any promises of guaranteed high returns in cryptocurrency or stocks from unknown contacts are a red flag for fraud. Check investment platforms’ licenses through financial regulators’ registers
- Protection against BEC: implement dual-approval procedures for financial transfers, especially when counterparties’ banking details change. Use DMARC, SPF and DKIM to protect corporate email
- Awareness of romance scams: warn elderly relatives about schemes in which an online “partner” asks for financial help or proposes joint investments
- Transaction monitoring: financial institutions should watch for patterns identified during the operation — multiple transactions through a single account using heterogeneous financial instruments and shell companies
The dismantling of CaaS infrastructure under Jackal IV is a more significant result than the absolute number of arrests. Organizations handling international payments should review their counterparty due diligence procedures and strengthen monitoring of transactions passing through the jurisdictions mentioned in the operation — especially those involving shell companies and money transfer services. For individuals, the key rule remains unchanged: any offer of guaranteed returns from an unknown source is fraud until proven otherwise.