1 hour ago · 3 min read · Threat Hunters Journal

Inside Operation Jackal IV: How Interpol Mapped and Dismantled Black Axe's Global Fraud Machine

Of everything that crossed the wire today, no single story pulled in as much independent coverage as Interpol's Operation Jackal IV. Dark Reading, The Cyber Express, The Hacker News, Security Affairs, The Record, CyberScoop, and Help Net Security all filed on it, which tells you something: this wasn't just another arrest blotter. It's a rare, detailed look at the actual plumbing behind West African organized cybercrime, and that plumbing is more industrialized than most defenders probably assume.

What actually happened

Operation Jackal IV ran from November 2025 to June 2026, coordinated by Interpol across 22 countries on six continents. The headline numbers are 58 arrests and 263 identified suspects, but the more instructive figures are the financial ones. Investigators seized roughly USD 2.67 million in South Africa alone, and traced an estimated EUR 143 million laundered through a single Romanian investment scam call center. The Record adds a detail worth sitting with: a crime-as-a-service network based out of Argentina, with around 196 members, was supplying website domains and money-laundering services to West African groups. This wasn't one country running one scam. It was a distributed service economy, with different nodes in different jurisdictions each renting out a piece of the fraud supply chain.

The primary target was Black Axe, the transnational network Interpol has flagged repeatedly as a driver of romance scams, cryptocurrency fraud, and business email compromise. But the operation's real value was in mapping the infrastructure around Black Axe rather than just chasing individuals — domain registration services, laundering pipelines, and the dark-web marketplaces where these capabilities get sold as Crime-as-a-Service.

Why the CaaS framing matters

What separates this from a routine takedown is the acknowledgment, echoed across nearly every outlet, that these networks operate as service providers rather than closed gangs. A group doesn't need to build its own laundering channel or spin up its own phishing domains anymore; it rents those capabilities from specialists like the Argentina-based network Interpol dismantled. That's the same commoditization pattern we've watched happen with ransomware-as-a-service, ransomware initial-access brokers, and now, increasingly, phishing-as-a-service platforms. The barrier to entry for large-scale fraud keeps dropping because the tooling and infrastructure are modular and for hire.

Help Net Security's coverage flags a detail that deserves more attention than it's getting: the operation surfaced an escalation toward sextortion targeting minors alongside the more familiar romance-scam and BEC playbooks. That's a signal the same infrastructure and operator base is diversifying into more predatory categories as the financial fraud model matures and gets crowded.

What this means for defenders

Most of the immediate targets in these campaigns — BEC, romance scams, crypto investment fraud — hit finance teams and consumers, not infrastructure. But the operational lesson for security teams sitting inside banks, payment processors, and enterprises with wire-transfer exposure is that the laundering layer is the choke point. The EUR 143 million Romanian call center and the South African seizures show that money movement, not just message delivery, is where these networks are most traceable and most disruptable. Fraud and financial crime teams should treat this as validation for investing in identity-and-relationship mapping tools rather than only transaction-level anomaly detection — understanding the network of mule accounts, shell domains, and shared infrastructure behind a fraud cluster is what actually breaks these operations, as opposed to blocking one phishing domain at a time.

For BEC-exposed organizations specifically, Jackal IV is a reminder that the actors behind your invoice-fraud attempts may be the same infrastructure supplying romance scams and sextortion campaigns elsewhere. Interpol's coordinated, cross-continent approach worked here because it treated the criminal ecosystem as a single interconnected market rather than isolated incidents. Security teams evaluating BEC and fraud risk should be doing the same — pulling in threat intel that maps infrastructure reuse across seemingly unrelated fraud categories, since that reuse is exactly what took this network down.

Inside Operation Jackal IV: How Interpol Mapped and Dismantled Black Axe's Global Fraud Machine | Threat Hunters Journal