Interpol’s Operation First Light 2026: 5,811 Arrests, $293 Million Seized in Global Crackdown on Social Engineering Fraud
Interpol has announced the results of Operation First Light 2026, one of the largest coordinated actions against social-engineering fraud and money laundering in recent years. Between 15 January and 30 April 2026, police and financial-crime units from 97 countries and territories arrested 5,811 individuals and seized illegal assets worth $293 million.
The operation focused on criminals who impersonate company employees, government officials, or romantic partners to trick victims into transferring funds. Common tactics included business-email compromise, interference in commercial correspondence, fake investment platforms, romance scams, and sextortion. Investigators examined more than 152,000 cases, blocked over 31,000 bank accounts, and solved nearly 24,000 crimes, ultimately identifying 15,600 suspects and 142,000 victims globally.
Fake Brazilian Police Station Uncovered in Eswatini
One of the most elaborate schemes was discovered in Eswatini, where fraudsters constructed a realistic replica of a Brazilian federal police station, complete with uniforms, signage, and official-looking equipment. During video calls, they posed as Brazilian officers, convinced victims they were targets of crime, and instructed them to move money to “safe” accounts. Authorities arrested 82 people and seized 240 electronic devices at the site.
Cryptocurrency Laundering in Thailand and Major Prevented Losses
In Thailand, investigators dismantled a money-laundering network that moved proceeds from romance scams through multiple cryptocurrency blockchains. A single 20-year-old suspect’s wallet processed more than $122.5 million in just ten months. Meanwhile, authorities in Singapore and Oman used Interpol’s urgent-payment-stop system to block a $6.6 million business-email-compromise transfer after fraudsters altered supplier bank details in a Singaporean company’s correspondence.
In Macau, police intervened during a public awareness session when one participant was about to send nearly $372,000 to fraudsters posing as government officials. The funds were frozen before the transaction could be completed, demonstrating the real-time protective value of the operation.
Related articles
Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities
A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.
Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers
Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.
Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes
Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.
Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions
Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.