Operation Delilah (2022): patience, partnerships and the arrest of a BEC kingpin
Most business email compromise stories end with money leaving a victim's account. Operation Delilah is the rarer story: the one that ends at an airport in Lagos, with an alleged gang leader in handcuffs after years of quiet, coordinated work across four continents.
What happened
In May 2022, INTERPOL announced the arrest of a 37-year-old Nigerian man alleged to head a transnational cybercrime syndicate within the SilverTerrier cluster — the umbrella name Palo Alto Networks Unit 42 has used since 2014 for the ecosystem of Nigerian business email compromise actors. He was detained at Murtala Muhammed International Airport in Lagos by the Nigeria Police Force.
The operation, codenamed Delilah, began in 2021 after intelligence referrals and was coordinated through INTERPOL's Cybercrime Directorate and its African Joint Operation against Cybercrime (AFJOC), with law-enforcement participation from Australia, Canada, Nigeria and the United States. Private-sector partners — including Palo Alto Networks Unit 42 and Group-IB — contributed the threat intelligence that helped identify and track the suspect, who INTERPOL noted had been monitored as he moved between countries before the arrest.
Delilah followed directly on two earlier actions against the same ecosystem: Operation Falcon (2020, three arrests) and Operation Falcon II (2021, eleven arrests).
How the attack worked
Unit 42's long-running SilverTerrier research describes not one gang but an economy: hundreds of distinct actors who, over the years, produced tens of thousands of samples of commodity malware — information stealers and remote-access tools — and used them to harvest corporate email credentials at scale.
The core scheme is consistent. Phishing emails, often disguised as invoices, quotations or shipping documents, deliver credential-stealing malware or link to fake login pages. Once a corporate mailbox is compromised, the actors study it: who pays whom, when, in what format, with what tone. Then comes the pivot — a supplier's "updated bank details", an executive's "urgent confidential transfer" — sent from or in reply to genuine correspondence, so that every technical signal looks legitimate. Mule accounts and rapid onward transfers do the rest.
What made the alleged Delilah target notable, according to the announcement and accompanying research commentary, was his role at the organising layer of this economy rather than at the keyboard of a single scam.
The impact
One arrest does not dismantle an ecosystem of hundreds of actors, and BEC losses worldwide have continued to climb. But Delilah demonstrated three things defenders should register: cross-border cooperation against African cybercrime works when intelligence is shared; private-sector research can translate directly into arrests; and even leadership figures who feel untouchable — moving between jurisdictions, years into their careers — can be reached. For African organisations, it was also a reminder that the threat is well documented, patient and professional.
Lessons for African organisations
- BEC is a professional industry. Assume your finance team is being studied by adversaries who have read thousands of real invoice threads.
- Compromised mailboxes are the pivot point. MFA on email, alerts on new inbox rules and impossible-travel logins close the door early.
- Process beats trust. Bank-detail changes and urgent transfers need out-of-band verification — every time, regardless of seniority.
- Awareness must be continuous. The lures evolve with each Unit 42 and Group-IB report; annual training cannot keep pace alone.
- Cooperate and report. Delilah was built on referrals; silence is a gift to the next syndicate.
Sources
- INTERPOL public announcement of Operation Delilah (2022)
- Palo Alto Networks Unit 42 SilverTerrier research series (2014–2022)
- Group-IB statements on its contribution to the operation (2022)
The gangs study your people; the fair response is to prepare them. See where your organisation stands with our free Human Risk Maturity Assessment.