INTERPOL operation recovers 439 million dollars from cyber fraud, with the UAE and Qatar taking part

Reading Time: 5 min
18
techkahwa.net | 25 September 2025

INTERPOL announced on 24 September that a months-long operation against online fraud recovered USD 439 million in cash and assets, and the UAE and Qatar were among the 40 participating countries and territories. One of the cases INTERPOL highlighted ended in Dubai, where money stolen through an email scam was stopped before it disappeared.

What happened

The operation is called HAECHI VI, the latest round of a series first started by South Korea and coordinated by INTERPOL. It ran from April to August 2025 and focused on the kinds of fraud that hit ordinary people and small businesses every day: voice phishing, romance scams, online sextortion, investment fraud, money laundering linked to illegal online gambling, business email compromise and e-commerce fraud.

According to INTERPOL, the operation recovered “USD 342 million in government-backed currencies, along with USD 97 million in physical and virtual assets.” Authorities also blocked “68,000 associated bank accounts” and froze “close to 400 cryptocurrency wallets.”

The case that caught my attention involves a Japanese company. It fell for a business email compromise scam, the kind where criminals pose as a supplier or executive and ask for a payment to a new account. The Korean National Police Agency worked with Emirati authorities, and together they recovered “KRW 6.6 billion (USD 3.91 million)” that had been intercepted in Dubai. A Japanese victim, Korean police and a Gulf financial centre: that is what cross-border recovery looks like when it works.

INTERPOL’s Theos Badege summed up the message simply: “recovery is indeed possible.”

Who is affected

Everyone who uses email to approve payments, or who can be reached by phone, text or social media, is in the target group for these crimes. That covers most of us. Business email compromise mostly hits companies, from large firms to a small trading business that pays suppliers by bank transfer. Romance scams, investment fraud and sextortion mostly hit individuals.

For readers in the Gulf and the wider Arab region, the Dubai case matters in two ways. It shows that stolen money can pass through the region’s financial hubs, and it shows that local authorities can and do cooperate to stop it. INTERPOL has not published arrest or recovery figures per country, so I cannot tell you how much of the total came through the UAE or Qatar beyond the Dubai case.

By the numbers

Item Figure
Total recovered USD 439 million
Government-backed currencies USD 342 million
Physical and virtual assets USD 97 million
Bank accounts blocked 68,000
Crypto wallets frozen Close to 400
Participating countries and territories 40
Operation period April to August 2025
Recovered in the Dubai case KRW 6.6 billion (USD 3.91 million)

What to do now

The US FBI’s Internet Crime Complaint Center (IC3) publishes guidance on business email compromise that fits the Dubai case closely. These four steps are the ones I would put on the wall of any small finance team:

  1. Verify any change to payment details by phone, using a number you already have on file. Never use a phone number that appears in the email asking for the change, because it may belong to the scammer.
  2. Turn on multi-factor authentication (MFA) for business email accounts. Some of these scams start with a real mailbox being taken over, which makes the fake request look genuine.
  3. Treat urgency as a warning sign. Be suspicious of requests to transfer money quickly, especially when they appear to come from a senior executive or a regular supplier and ask you to skip the usual checks.
  4. If you are defrauded, contact your bank and the police immediately. Fast reporting improves the chances of recovery. The Dubai case worked because the money was intercepted before it vanished, and speed is what makes that possible.

Why it matters

Online fraud can feel like a one-way street: money leaves and never comes back. HAECHI VI is a useful correction. Hundreds of millions of dollars were recovered, tens of thousands of accounts were blocked, and at least one scam was reversed in a Gulf city.

In my view the most practical takeaway is the last step in the checklist. Recovery depends on time. A company that notices a fraudulent transfer within hours and calls its bank has a real chance. One that discovers it at the end of the month usually does not. Build the verification habit, protect your mailboxes, and make sure everyone on your team knows who to call the moment something looks wrong.

Sources

  • INTERPOL, “USD 439 million recovered in global financial crime operation”, 24 September 2025, https://www.interpol.int/en/News-and-Events/News/2025/USD-439-million-recovered-in-global-financial-crime-operation
  • FBI Internet Crime Complaint Center (IC3), business email compromise guidance and reporting portal, accessed 25 September 2025, https://www.ic3.gov/