Daylila

Cybersecurity · Wednesday, 26 August 2026

01 · Briefing · what happened

Interpol arrested 58 people, and the ones that matter were selling domains and moving money

Cybersecurity 1 min 32 sources

Operation Jackal IV went after the suppliers rather than the fraudsters. In Argentina alone it linked 196 people to a single crime-as-a-service network providing web domains and laundering to West African fraud groups.

196

linked to one service network

in Argentina, supplying domains and laundering [1][3]

22

countries taking part

across six continents, over seven months [1][2]

$2.67m

seized in South Africa

alongside 39 arrests and 257 blocked accounts [3]

263

further suspects identified

against 58 actually arrested [2]

At a glance

  • Operation Jackal IV involved law enforcement from 22 countries across six continents, arresting 58 suspects and identifying 263 more. [1][2]
  • It ran from November 2025 to June 2026 - seven months of following money rather than chasing individual scams. [1]
  • In Argentina, 17 people were arrested and 196 were linked to a single crime-as-a-service network that supplied web domains and money-laundering support to West African groups. [1][3]
  • An Interpol director described following the financial flows across borders to what he called 'the very lifeblood of organized crime'. [1]
  • In South Africa, seven raids in Johannesburg hit a syndicate running romance and investment scams against elderly people in English-speaking countries: 39 arrests, 257 bank accounts blocked, about $2.67m seized. [1][3]
  • Romanian police arrested 11 people connected to a call centre baiting victims with promised returns on shares and cryptocurrency. [3]
  • Italian authorities identified a suspect tied to a pan-European laundering network moving money through shell companies, remittance services and cash withdrawals. [3]
  • Singapore arrested six, five of them Chinese nationals believed to be part of the same global syndicate. [4]
  • The named target throughout is Black Axe, a transnational network of Nigerian origin that law enforcement has been trying to dismantle for more than five years. [1][2]
  • Interpol says groups like it account for a significant share of the world's cyber-enabled financial fraud - romance scams, investment and cryptocurrency scams, and business email fraud. [1][2]
  • This is the fourth operation in the series. Jackal III ended in 2024 with hundreds of arrests and about $3m seized; the first two produced roughly 200 arrests between them. [2]
  • Four rounds in, the pattern of what gets caught has shifted from the people running scams toward the people selling them the means. [1][2]

Forces in play

Crime as a service High

one Argentine network of 196 people supplying domains and laundering to multiple fraud groups [1][3]

Cross-border policing Building

22 countries, seven months, and a shift from chasing scams to following money [1][2]

Victims at the far end High

the South African raids targeted a syndicate specifically working elderly people in English-speaking countries [1][3]

Resources for cyber policing High

money and mindset are named as the two biggest constraints on police forces trying to do this work [5]

In play The service network — sells domains and laundering to whoever is defrauding Black Axe — the named group, pursued for over five years 22 police forces — the only structure that can follow money across borders Elderly targets — specifically selected, in English-speaking countries

How it unfolded

  1. 2022-23 the first two Jackal operations produce about 200 arrests between them [2]
  2. 2024 Jackal III ends with hundreds of arrests and about $3m seized [2]
  3. Nov 2025 Jackal IV begins, following financial flows rather than individual scams [1]
  4. Jun 2026 the operation concludes [1]
  5. This week 58 arrests announced, with 263 more suspects identified [1][2]

Where this points

The number worth watching is not arrests but whether the Argentine service network is replaced within months: a fraud crew rebuilds in weeks, and an infrastructure supplier with banking relationships does not.

Also today

9 more stories on this beat.

  1. The breach was half the size the attackers said

    A leaked Carhartt dataset was claimed at around 24.8 million people. Analysis found large amounts of generated test data - email domains that were random strings, more customers registered in Montenegro than in the US, and an implausible number of birth dates in the early 1900s. Stripping it out left 12,933,413 genuine accounts, of which 83% had already appeared in earlier breaches. [6]

    Why it matters — The size of a breach is announced by the party with the strongest reason to inflate it, and almost nobody checks. Here somebody did, and the number halved.

  2. Hospitals had another bad week

    CareFirst BlueCross BlueShield disclosed a breach affecting 1.1 million people. Nutex Health told regulators data was stolen. Canada's SickKids children's hospital was hit again, this time through its careers site, exposing employee and job-applicant details - though not clinical systems or patient records. [7][8][9][10][11][12] Apollo Global separately disclosed exposure of personal information. [13]

    Why it matters — A job application portal holds full names, addresses, phone numbers and employment history, which is why it is worth attacking even though nobody thinks of it as a medical system. [11]

  3. A medical device maker cannot ship

    Boston Scientific disclosed that a cyberattack has disrupted its global operations and shipment processes, with investors told restoration may take weeks. No group has claimed it. Johnson Controls, which runs building systems for hospitals, airports and stadiums, was separately disrupted. [14][15][16]

    Why it matters — Last month Medtronic notified more than 3.8 million people of exposure, and Stryker's attack earlier this year had knock-on effects on US hospitals. The pattern is not data theft - it is stopping the supply of physical things hospitals need. [15]

  4. The US took down Chinese proxy tools

    The FBI disrupted proxy infrastructure used for mass hacking, run by a Nanjing-based company and used primarily by China's Ministry of State Security and the People's Liberation Army. [17][18]

    Why it matters — Same shape as the Interpol operation: the target was the shared infrastructure rather than the operators using it. A separate analysis this week argued China is pre-positioning inside civilian infrastructure rather than stealing from it. [19]

  5. Quiet fixes help the wrong people

    A widely shared argument this week: when a vendor patches a flaw silently - no advisory, no identifier, a vague changelog line - the binary on disk still changes, and anyone with a disassembler can compare versions and find what moved. [20]

    Why it matters — The people that keeps in the dark are the defenders, the detection engineers and the administrators deciding what to patch tonight. The people already capable of weaponising it are unaffected.

  6. The window to patch keeps shrinking

    A Zimbra flaw allowing remote code execution without login was being exploited with federal agencies given until Monday to fix it, and a critical GitLab flaw was exploited shortly after disclosure. Microsoft patched an Entra ID flaw already under attack. [22][25][24]

    Why it matters — The gap between a fix existing and a fix being needed is now measured in days, which is shorter than most organisations' change-approval process.

  7. An ordinary week of patches, at scale

    Chrome shipped fixes for over 300 vulnerabilities. Atlassian and Splunk patched dozens between them, Adobe and Nvidia dozens more, Cisco fixed critical flaws in two products, and Ubiquiti patched three maximum-severity flaws affecting a product with more than 100,000 instances visible online. [23][21][27][28][26] One carrier physically cut a cable to stop an intrusion. [32]

    Why it matters — None of this is news in itself, which is the point: this is a normal week, and every one of those numbers is somebody's Tuesday.

  8. Multi-factor authentication is not the finish line

    About 70% of enterprise workforce users now have multi-factor authentication, and a detailed argument this week set out how that creates a false sense of security rather than an end state. [29]

    Why it matters — A control that almost everyone has is a control attackers have had years to learn to work around.

  9. The Rust package attack was traced

    The build-time malware planted in Rust crates with 245 million downloads has been linked to North Korean actors. The malicious dependency was published, spotted and pulled within 47 minutes. [30][31]

    Why it matters — The response was fast and it did not matter much: a build script runs at build time, so anyone who compiled during those 47 minutes was affected.

02 · Lesson · why it matters

Go after the supplier, not the user

The people committing a crime can be replaced in weeks; the network selling them domains and moving their money took years to build and serves everybody at once.

How it works

  1. A criminal economy has people who commit the crime
  2. And it has people who sell them what they need
  3. The first group is large and replaceable in weeks
  4. The second is small, and hard to replace
  5. Because it needs banking relationships and reputation
  6. So the leverage sits with the suppliers, not the users

The twist

Arresting fraudsters removes people who can be replaced within a month. Removing the network that sells them domains and moves their money takes out a supplier that took years to build and that dozens of separate groups were all depending on.

Where you've seen this

Drug enforcement

street dealers are replaced within days; the chemist and the money launderer are not

Counterfeit goods

the market stall is trivial; the shipping agent who moves containers is the scarce link

Spam

the sender is disposable; the payment processor that lets the transaction settle is not

Doping in sport

one athlete is one case; the doctor supplying twenty of them is the case that matters

The catch

The supplier layer is only a chokepoint while it is concentrated. Take out one and the function can rebuild in a jurisdiction that will not cooperate - which is why the operation needed 22 countries and seven months rather than one raid.

And the whole of it

This is the shape of almost every enforcement problem, and it is why the visible offender is so often the wrong target. The person taking the elderly victim's money is the last link in a chain that includes a domain reseller, a payment route and a bank account, most of whom would say they were providing an ordinary service. Everyone in the middle can explain their own part; the whole is a fraud industry.

03 · Lab · your turn

Where To Put The Raid

Choose which layer of a fraud industry to hit and watch how fast each one grows back, until the layer with the fewest arrests turns out to be the one that matters.

04 · Truth · what's really going on

Stripped of the framing

Four rounds into the same operation, the target has moved. The arrests that matter here are not of people running scams but of the network selling them web domains and moving their money - a supplier that dozens of separate fraud groups were all depending on.

Why it lands — Enforcement is announced in arrest counts because arrests are countable and photographable. 58 is the number in the headline; 196 people attached to one service network is the number that describes what was actually found, and it appears several paragraphs down.

Claimed

What people said. Not yet a fact.

  • Interpol

    Groups like Black Axe are responsible for a significant share of the world's cyber-enabled financial fraud. [1][2]

    'A significant share' is doing a lot of work and no figure is attached anywhere in the reporting. It is an agency characterising the importance of its own target.

  • An Interpol director

    Following the financial flows led them to 'the very lifeblood of organized crime'. [1]

    Vivid, and the underlying claim - that the money route is the durable part - is supported by what was actually found in Argentina rather than only by the phrasing.

  • The attackers behind the Carhartt leak

    Around 24.8 million people were affected. [6]

    Independent analysis found large volumes of generated test data and arrived at 12,933,413 genuine accounts, 83% of which had already appeared in earlier breaches. The claim was roughly double.

Verified

What we could actually stand behind.

  • 58 arrested, 263 more identified, across 22 countries between November 2025 and June 2026. [1][2]

    How we checked — Consistent figures across three independent outlets reporting the same Interpol announcement, with the country-by-country breakdown matching between them. [1][2][3]

  • Argentine police linked 196 people to one crime-as-a-service network supplying domains and laundering. [1][3]

    How we checked — Reported identically by two outlets, with the same arrest count of 17 attached, so it is the announcement rather than one outlet's reading of it.

  • The Carhartt dataset contains machine-generated records - random-string email domains, more customers in Montenegro than the US, birth dates clustered in the early 1900s. [6]

    How we checked — Specific, checkable artefacts of generated test data rather than an assertion that the numbers 'look wrong'. That is what makes this a finding and not a suspicion.

Nobody knows

Open questions — ours included.

  • Whether the Argentine service network has already been replaced.

    The operation ended in June and was announced this week. Nothing published says what is now supplying the groups that lost their supplier. [1]

  • What 263 identified but not arrested means in practice.

    It could mean warrants pending, or people in jurisdictions that will not act. The distinction decides whether the operation ends here. [2]

  • Who attacked Boston Scientific, and what was taken.

    No group has claimed it. Investors were told restoration may take weeks, which describes the disruption without describing the breach. [14][15]

  • How much of any large breach claim is real.

    This week's example halved on inspection, and 83% of what remained was already public. Almost no breach claim receives that scrutiny. [6]

Who gains

  • Attackers who inflate — A bigger claimed number buys attention, leverage over the victim company and standing with buyers - and it costs nothing to state, because almost nobody counts. [6]
  • Vendors patching quietly — A silent fix avoids a public advisory and the awkward questions with it, while anyone able to compare two binaries finds the flaw anyway. The concealment only works against defenders. [20]
  • Whoever supplies the next network — Taking out one crime-as-a-service provider concentrates demand on the remaining ones, which is a market opportunity as well as an enforcement win. [1][3]

Who pays

  • Elderly people in English-speaking countries — The South African syndicate targeted them specifically, and $2.67m was recovered from an operation that had been running long enough to have 257 bank accounts. [1][3]
  • Hospital staff and job applicants — SickKids was breached through its careers site, exposing employee and applicant records - people who never chose to be in that system as patients. [10][11][12]
  • Administrators deciding what to patch tonight — A silent patch removes exactly the signal they use to triage, in a week that carried over 300 Chrome fixes alone. [20][23]

05 · Hope · carry this

Somebody actually checked the biggest breach number of the week and it fell by half. The tools to spot generated data in a leaked dataset are now good enough that an inflated claim can be taken apart in an afternoon.

Across the beats