INTERPOL’s Operation Red Card 2.0, coordinated under the African Joint Operation against Cybercrime (AFJOC), resulted in 651 arrests across 16 African countries and the recovery of over $4.3 million tied to online scam activity. The operation ran from December 8, 2025 to January 30, 2026, identified 1,247 victims, and targeted criminal activity linked to over $45 million in losses, including high-yield investment fraud, mobile money fraud, and fraudulent mobile loan applications.
Law enforcement reported significant disruption activity, including the seizure of 2,341 devices and takedowns of 1,442 malicious IPs/domains/servers (and related infrastructure). Notable actions included Nigeria dismantling an investment-fraud ring that leveraged phishing, identity theft, and social engineering (with 1,000+ fraudulent social media accounts removed) and arresting six suspects accused of breaching a major telecom provider using compromised staff credentials to steal airtime/data for resale; Kenya arrested 27 suspects tied to social-media/messaging-driven fraud schemes; and Côte d’Ivoire arrested 58 suspects linked to predatory loan-app activity with hidden fees and abusive collection practices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
INTERPOL published the results of Operation Red Card 2.0 and highlighted the transnational nature of the cybercrime syndicates, stressing the need for cross-border collaboration to combat online scams in Africa.
By the end of the operation, authorities had arrested 651 suspects, identified 1,247 victims, recovered more than $4.3 million, seized 2,341 devices, and disrupted 1,442 malicious IPs, domains, and servers linked to scams causing over $45 million in losses.
Authorities in Côte d’Ivoire arrested 58 suspects connected to predatory mobile loan fraud carried out through deceptive applications that targeted victims with abusive lending scams.
Kenyan authorities arrested 27 suspects linked to investment fraud schemes that used social media and messaging platforms to lure victims with fake opportunities.
Nigerian police arrested six suspects accused of breaching a major telecommunications provider by using stolen employee credentials as part of a separate cybercrime scheme uncovered during the operation.
During the operation, Nigerian authorities dismantled a major investment fraud network that used phishing, identity theft, social engineering, fake digital-asset investment schemes, and more than 1,000 fraudulent social media accounts.
Law enforcement agencies in 16 African countries, supported by INTERPOL and AFJOC, launched Operation Red Card 2.0 to target high-yield investment fraud, mobile money scams, and fraudulent mobile loan applications.
INTERPOL said an earlier phase of Operation Red Card, conducted between November 2024 and February 2025, led to 306 arrests and the seizure of 1,842 devices across participating African countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceinterpol.int
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.