What happened
Interpol announced in August 2025 that Operation Serengeti 2.0, conducted from June to August across 18 African countries and the UK, led to 1,209 arrests, the dismantling of 11,432 malicious infrastructures and the recovery of about $97.4 million. The operation targeted ransomware, business email compromise, online scams and investment fraud affecting some 88,000 victims, with total losses estimated at roughly $485 million.
How the deception worked
The networks disrupted ran industrialised deception. Business email compromise crews compromised or spoofed corporate mailboxes, watched invoice threads, then sent payment-diversion instructions from an address one character off the real one, timed to arrive when a genuine payment was due. Romance and investment crews cultivated victims over weeks on dating and messaging apps before introducing fake trading platforms that displayed fabricated gains to encourage larger deposits. In both cases the trust signal abused was an established relationship, commercial or personal, and the pressure was a closing window: a supplier deadline, or a limited investment opportunity.
The control that would have caught it· our reading, not a claim from the sources
Verified callback to a previously known phone number before any change of bank details, and platform-level friction on first-time large transfers to new payees, cut the largest share of these losses.
Sources (2)
- African authorities dismantle massive cybercrime and fraud networks, recover millionsInterpol·interpol.intOpen ↗
- Massive anti-cybercrime operation leads to over 1,200 arrests in AfricaBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.