Interpol has arrested 11 people suspected of participating in an international BEC (business email compromise) ring.
See also: FBI: Beware! BEC scammers impersonating construction companies

BEC is a type of attack carried out via email that involves spear-phishing a company's employees, who are typically responsible for approving payments to contractors, suppliers, etc.
Impersonating a colleague, a supervisor, or a customer/supplier, malicious users manage to divert payments to their bank accounts, essentially stealing them from the company.
In Interpol's most recent operation codenamed "Falcon II", which took place between December 12 and 22, 2021, the police followed up on leads provided by cyber-intelligence firms Group-IB and Palo Alto Networks' Unit 42, to arrest suspects in Lagos and Asaba.
Based on the investigation and evidence gathered so far, Interpol believes that at least some of the arrested individuals belong to a BEC gang known as SilverTerrier (TMT).
See also: Interpol arrested 1,000 cybercrime suspects!
Interpol had also arrested other members as part of "Falcon I" in 2020.
BEC fraudsters cannot extort funds in the form of untraceable cryptocurrencies, so the only way to hide is to move the stolen amounts, trying to cover their tracks.

Unfortunately, many banks, especially in countries with more lax money laundering regulations, insist on protecting their customers' identities and refuse to reinstate transactions that were part of payment diversion fraud.
However, international cooperation and information sharing between law enforcement and intelligence agencies worldwide are making it increasingly difficult for BEC attackers to remain hidden.
See also: Microsoft: "BEC attacks targeting schools have increased significantly"!
How to protect yourself from BEC attacks
When you are asked to send money or change all payments to a new bank, you can simply call the supplier/colleague to confirm.
Therefore, call a phone number that you have confirmed is valid in previous communications and not any new numbers provided in the email.
To protect your email account, enable multi-factor authentication along with a strong and unique password.
Organizations should also protect their domain from spoofing by registering potential candidates who use typos in the domain and instructing employees not to share too much business information online.
