VORANT. Threat Intelligence Sign in Get the full feed

FBI's Operation Eagle Sweep nets 65 BEC arrests

low threat financial-servicesenergy

A coordinated international law enforcement operation arrested 65 suspects tied to Business Email Compromise schemes that caused over $51 million in losses.

The FBI, alongside international partners including Nigeria, South Africa, Canada, and Cambodia, conducted Operation Eagle Sweep, a three-month coordinated law enforcement action targeting Business Email Compromise (BEC) actors. The operation, building on prior efforts like Operation Wire Wire and Operation reWired, resulted in 65 arrests globally and targeted scammers responsible for victimizing over 500 U.S. victims with losses exceeding $51 million. BEC schemes typically involve criminals compromising or spoofing business email accounts to trick employees into sending wire transfers to attacker-controlled bank accounts, often exploiting real estate transactions and elderly victims as well.

Several specific cases were detailed, including arrests in Houston, Texas and Lagos, Nigeria related to victimization of a Puerto Rico-based renewable energy supplier, involving an international money laundering network that moved at least $4.5 million in fraud proceeds. Additional indictments in Houston covered laundering of nearly $900,000 from BEC proceeds, while a Toronto-based scheme resulted in arrests for BEC and check fraud impacting hundreds of victims with attempted losses exceeding $16 million. According to IC3, BEC and related email account compromise schemes caused nearly $2.4 billion in reported losses in 2021 alone.

This is primarily a law enforcement disruption and prosecution story rather than a technical threat report — it involved no malware analysis or novel TTPs, but rather multinational police cooperation to arrest individuals and money mule networks facilitating BEC fraud. The operation involved numerous agencies including the U.S. Postal Inspection Service, Australian Federal Police, Nigerian EFCC, Toronto Police, and Microsoft's Digital Crimes Unit.

Mentioned in this report

Threat actors BEC actors (unnamed criminal network)

Source reporting: https://www.fbi.gov/news/stories/coordinated-operation-disrupts-global-bec-schemes-033022

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free