Back to BlogEmail Security Insights

Do BEC Scammers Get Caught? What INTERPOL's 5,811 Arrests Mean for Your Business

StopSpoofingMe TeamPublished 6 min read

Some do. INTERPOL announced on July 9, 2026 that Operation First Light 2026 led to 5,811 arrests and intercepted USD 293 million across 97 countries and territories, targeting social-engineering scams including business email compromise. Police can't promise to recover a payment already sent, so prevention still matters most: verify payment changes by phone and protect your domain with DMARC.

Key takeaways

  • INTERPOL says Operation First Light 2026 led to 5,811 arrests and USD 293 million in illicit assets intercepted, across 97 countries and territories.
  • The operation ran from January 15 to April 30, 2026 and targeted social-engineering scams, including business email compromise (BEC), and the money laundering behind them.
  • INTERPOL says more than 142,000 victims were identified.
  • BEC usually opens with a harmless-looking message from a fake boss, colleague or supplier. Microsoft's Q1 2026 email threat report counted about 10.7 million BEC attacks from January to March 2026.
  • For a small business, the controls that work are call-back verification, DMARC on your domain, and reporting fast to your bank and the FBI if money moves.

What happened?

On July 9, 2026, INTERPOL announced the results of Operation First Light 2026, a global crackdown on social-engineering fraud. According to INTERPOL:

  • 5,811 people were arrested.
  • USD 293 million in illicit assets was intercepted.
  • 97 countries and territories took part.
  • The operation ran from January 15 to April 30, 2026.
  • It targeted social-engineering scams and the money laundering behind them. INTERPOL lists business email compromise, sextortion, romance, impersonation and investment scams among the fraud types involved.
  • More than 142,000 victims were identified.

INTERPOL says the operation was funded by China's Ministry of Public Security, with the regional policing bodies ASEANAPOL, GCCPOL and Europol taking part. Help Net Security and The Crypto Times reported the same headline figures on July 9.

INTERPOL describes the money as intercepted; some headlines, including Help Net Security's, said "seized." We use INTERPOL's term.

Do BEC scammers actually get caught?

Some do. But keep two things in mind:

  • The totals cover the whole operation, not BEC alone. INTERPOL reported the 5,811 arrests and USD 293 million for an operation that also targeted romance, sextortion, investment and other scams.
  • Results take time. The operation ended on April 30, and its results were announced on July 9.

The FBI's advice for BEC victims centers on speed: contact your bank as soon as you recognize the fraud to request a recall or reversal of the transfer, and file a detailed complaint with the FBI's Internet Crime Complaint Center (IC3).

What does business email compromise look like?

In its Q1 2026 email threat report, published April 30, Microsoft defines BEC as "a text-based attack targeting enterprise users that impersonates a trusted entity for the purpose of persuading a recipient into initiating a fraudulent financial transaction or sending the threat actor sensitive documents."

The report counted approximately 10.7 million BEC attacks in the first quarter of 2026. According to Microsoft, generic outreach such as "Are you at your desk?" made up 82–84% of first-contact emails each month, while only 9–10% asked outright for a payment or documents. The scam usually starts with a friendly question, not a demand.

What you might see What's really going on What stops it
"Are you at your desk?" under your boss's name Rapport-building before a request Check the actual sender address, then ask in person or by phone
A request to update an employee's direct deposit Payroll diversion Verify any payroll change through a channel you already trust
A request to buy gift cards Gift card fraud A standing rule: no gift card purchases because of an email
Your own domain in the From line, sent by a stranger Exact-domain spoofing DMARC at p=quarantine or p=reject on your domain
A real message from a colleague's or supplier's account A compromised mailbox Strong MFA, checks for suspicious forwarding rules, call-back verification

Microsoft's report noted payroll update requests rising 15% in February, and gift card requests staying under 3% of BEC messages. For the bigger picture on losses, see our BEC statistics roundup.

Why does this matter for your business?

The scams Operation First Light targeted are social engineering: they persuade a person to act. Technology covers part of that risk, not all of it.

Microsoft says DMARC validation "helps prevent spoofed senders that are used in business email compromise (BEC), ransomware, and other phishing attacks." A DMARC policy at enforcement on your domain tells receiving mail systems to quarantine or reject mail that fails authentication while using your exact domain in the From address, protecting your customers and suppliers from forged mail in your name.

DMARC can't stop a criminal who registers a lookalike domain, uses a free email account with your CEO's name, or logs in to a real mailbox. Microsoft notes that attackers often use a compromised user's mailbox to send to people inside and outside the organization. Those need account security and a payment process that doesn't trust email alone.

What should you do now?

  1. Make call-back verification a rule. Confirm any change to bank details, payroll or payment instructions by calling a number you already have on file, never one in the email. Microsoft gives small businesses the same advice: verify by finding the company's contact details yourself.
  2. Require a second approver for new payees and changed bank details, even when the request is urgent.
  3. Protect your domain. Check your SPF, DKIM and DMARC with our free domain scanner and plan the move from p=none to enforcement.
  4. Lock down mailboxes. Use multifactor authentication, and watch for the warning signs Microsoft lists, such as inbox rules that forward mail to unknown addresses. If you're on Microsoft 365 E3, check the new Defender for Office 365 protections you now have.
  5. Know the first hour. If money has gone, call your bank immediately to request a recall or reversal, and file a detailed complaint at ic3.gov. IC3 asks victims to identify the incident as "BEC" and include the banking details of both sides of the transfer.
  6. Brief your team. "Are you at your desk?" from an executive's name is a reason to check the sender, not to hurry.

Frequently asked questions

What was INTERPOL's Operation First Light 2026?

It was an INTERPOL-coordinated operation against social-engineering scams and related money laundering, run from January 15 to April 30, 2026 across 97 countries and territories. INTERPOL announced the results on July 9, 2026: 5,811 arrests, USD 293 million intercepted and more than 142,000 victims identified.

Did Operation First Light target business email compromise?

Yes. INTERPOL lists business email compromise among the social-engineering scams the operation targeted, alongside sextortion, romance, impersonation and investment scams. INTERPOL published totals for the operation as a whole, so they don't tell you how many arrests or how much intercepted money related to BEC specifically.

Can I get my money back after a BEC scam?

Sometimes, if you move fast. IC3 advises contacting your bank as soon as the fraud is recognized to request a recall or reversal, then filing a detailed complaint at ic3.gov; it says acting quickly may reduce or eliminate your losses. Don't wait to be sure before calling.

Does DMARC stop business email compromise?

It stops one kind. With DMARC at enforcement, receiving mail systems can reject or quarantine mail that forges your exact domain. It doesn't stop lookalike domains, free email accounts using an executive's name, or a real mailbox that's been hijacked. You still need call-back verification and strong account security.

Want a second pair of eyes on your payment process or DMARC setup? Call us at (818) 574-8240.

Sources

  1. INTERPOL — Over 5,800 arrests, USD 293 million intercepted in global fraud bust (July 9, 2026)
  2. Help Net Security — 5,811 arrests, $293 million seized over social engineering scams (July 9, 2026)
  3. The Crypto Times — INTERPOL Busts Global Scams: 5,811 Arrested, $293M Crypto & Cash Seized (July 9, 2026)
  4. Microsoft Security Blog — Email threat landscape: Q1 2026 trends and insights (April 30, 2026)
  5. FBI Internet Crime Complaint Center (IC3) — Business Email Compromise (reference page, undated)
  6. FBI — Business Email Compromise (reference page, undated)
  7. FBI — Business E-Mail Compromise (news story, undated)
  8. Microsoft Learn — Set up DMARC to validate the From address domain for cloud senders (reference documentation, undated)
  9. Microsoft Learn — Respond to a compromised cloud email account (reference documentation, undated)
  10. Microsoft Learn — Protect users against phishing and other attacks in Microsoft 365 for business (reference documentation, undated)

Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.

Related Topics

operation first light 2026interpol bec arrestsbusiness email compromise small businesshow to prevent business email compromisereport bec to ic3payment verification callbackdmarc business email compromise

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.