Spanish National Police, in collaboration with German authorities and Europol, arrested 34 individuals linked to the Black Axe criminal organization in a coordinated operation across Seville, Madrid, Málaga, and Barcelona. The suspects, primarily of Nigerian origin, are accused of orchestrating large-scale cyber fraud schemes, including business email compromise (BEC), romance scams, and phishing attacks, resulting in nearly €6 million in losses in Spain alone. Authorities seized cash, electronic devices, vehicles, and froze significant sums in bank accounts during the raids, while also uncovering the group's strategy of recruiting vulnerable locals as money mules to launder illicit proceeds.
The Black Axe group, originating from Nigeria and now boasting an estimated 30,000 members worldwide, has been implicated in a range of criminal activities, with cyber-enabled fraud as a major revenue stream. The investigation revealed that the Spanish cell was part of a broader European network, using sophisticated man-in-the-middle (MITM) tactics to intercept and redirect corporate payments. Four main suspects have been placed in pretrial detention, facing charges including aggravated fraud, money laundering, and membership in a criminal organization, while authorities continue to pursue additional leads and potential arrests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following the arrests, four alleged leaders were kept in custody or placed in pretrial detention. They face charges including aggravated continuous fraud, criminal organization membership, money laundering, document forgery, and obstruction of justice.
During the Spanish operation, investigators froze roughly €119,000 in bank accounts and seized more than €66,000 in cash, with some reports also noting vehicles and electronic devices were confiscated. Authorities attributed about €5.93 million to €6 million in fraud losses to the case.
Spanish authorities, supported by Europol and Germany's Bavarian State Criminal Police Office, carried out coordinated raids in Seville, Madrid, Málaga, and Barcelona and arrested 34 suspects tied to the Black Axe criminal network. The operation focused on disrupting the group's leadership, money-mule infrastructure, and broader European fraud activity.
Before the takedown, Spanish National Police, Germany's Bavarian State Criminal Police Office, and Europol coordinated intelligence sharing, analytical support, and investigative work to map Black Axe's multi-country structure and financial activity. Investigators linked the network to cyber-enabled fraud schemes including business email compromise, phishing, romance scams, and adversary-in-the-middle attacks.
Interpol's October 2022 Operation Jackal led to 75 arrests across 14 countries in an earlier international law-enforcement action against Black Axe-linked criminal activity. This is cited as prior action preceding the Spain-focused case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.