Operation Falcon (2020): the takedown that showed the industrial scale of BEC

Business email compromise is often imagined as a lone scammer with a Gmail account. Operation Falcon, a joint law-enforcement action announced in November 2020, showed something very different: an organised criminal operation whose phishing infrastructure had touched hundreds of thousands of organisations worldwide.

What happened

In November 2020, INTERPOL announced that the Nigeria Police Force, working with INTERPOL's Cybercrime Directorate and threat-intelligence firm Group-IB, had arrested three men in Lagos. The suspects were alleged members of an organised cybercrime group that Group-IB tracks under the name TMT, part of the broader cluster of Nigerian BEC actors that researchers such as Palo Alto Networks Unit 42 have long labelled SilverTerrier.

The scale reported by investigators was striking. INTERPOL stated that the gang was believed to have compromised government and private-sector organisations in more than 150 countries since 2017 — with the number of organisations targeted put at around 500,000. Group-IB reported that data from roughly 50,000 targeted victims had been confirmed during the investigation. A follow-up phase, Operation Falcon II, led to eleven further arrests in December 2021.

How the attack worked

According to Group-IB's published analysis, TMT ran mass phishing campaigns rather than bespoke intrusions. The playbook was industrial:

Phishing emails impersonated purchase orders, product enquiries and even COVID-19 aid notices, carrying attachments that installed widely available commodity malware — information stealers and remote-access tools of the AgentTesla, Loki, AzoRult, NanoCore and Remcos families. These tools cost little, require modest skill, and quietly harvest browser-saved passwords and, crucially, email credentials.

With mailbox access, the operators monitored correspondence, identified payment conversations, and inserted themselves at the decisive moment — redirecting invoice payments or issuing fraudulent payment instructions from genuine, trusted mailboxes. Stolen data and compromised accounts were also resold to other actors, making the group a supplier to the wider BEC economy.

The impact

Three arrests, followed by eleven more in Falcon II, did not end Nigerian BEC — no single operation could. But Operation Falcon mattered for two reasons. First, it demonstrated working cooperation between African law enforcement, INTERPOL and private-sector researchers, a model later repeated in Operation Delilah. Second, its numbers reframed BEC for defenders: when one gang's infrastructure can touch half a million organisations, receiving a credential-phishing email is not bad luck. It is the statistical default for any organisation with an inbox.

Lessons for African organisations

  • BEC begins with commodity phishing, not sophistication. A cheap information stealer in a fake purchase order is enough to start a six-figure fraud.
  • Email credentials are the crown jewels. Protect mailboxes with strong MFA and alert on suspicious inbox rules and logins.
  • Train the whole workforce, not just finance. TMT's lures targeted anyone who might open an attachment; the mailbox compromised first is rarely the one that pays.
  • Verify payment changes out-of-band. A genuine mailbox sending fraudulent instructions defeats purely technical email filtering.
  • Report incidents. Falcon was built on shared intelligence; victims who stay silent protect the next gang.

Sources

  • INTERPOL public announcement of Operation Falcon (2020) and Operation Falcon II (2021)
  • Group-IB published research on the TMT cybercrime group (2020)
  • Palo Alto Networks Unit 42 SilverTerrier research series (2014–2022)

If a fake purchase order landed in your team's inboxes tomorrow, how many would open it? Our free Human Risk Maturity Assessment helps you answer that question honestly.