Swiss authorities arrested 10 suspected members of the Nigerian criminal organisation Black Axe in coordinated raids across several cantons, including the group’s alleged Regional Head for Southern Europe. Prosecutors and police in Zurich said the suspects were tied to romance scams, other cyber-enabled fraud schemes, and money laundering that caused losses of millions of Swiss francs.
The Swiss-led investigation was carried out with German law enforcement and supported by Europol, which provided intelligence analysis, cross-border coordination, and a data sprint in Madrid to map the group’s structure and links to related cases, including in Spain. Authorities described Black Axe as a highly structured transnational network with global reach and criminal proceeds estimated in the billions of euros, and said the operation aimed to disrupt its distributed model and support asset seizures with assistance from the EU-funded @ON Network.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On 28 April 2026, Swiss authorities carried out coordinated searches across several cantons and arrested 10 suspects linked to the Black Axe criminal organisation, including its alleged Regional Head for Southern Europe. The suspects were accused of romance scams, other cyber fraud offences, and money laundering tied to millions of Swiss francs in losses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
europol.europa.eu
Open sourcehelpnetsecurity.com
Open sourcezh.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.