Part three of our mid-year accounting, following ransomware and healthcare. We ran the same exercise at mid-2025. The 2026 numbers are larger in every category.

The Scoreboard

OperationPeriodResult
Operation Synergia IIIJul 2025 – Jan 202694 arrests, 45,000+ malicious IPs and servers taken down, 72 countries
Operation RamzOct 2025 – Feb 2026201 arrests, 382 suspects identified, 3,867 victims identified, 53 servers seized
Operation First Light 2026announced May 4276 arrests, $701 million seized, 9 scam centers dismantled
Operation SaffronMay 19–20First VPN seized, 33 servers across 27 countries, 506 criminal users exposed
AudiA6 takedownJune 102 administrators arrested, EUR 336 million laundering pipeline dismantled
Operation EndgameJune 15–19326 servers, 142 domains, $46M crypto frozen, 27M credentials recovered, 20 arrest warrants

771 arrests across the three INTERPOL-coordinated operations alone, before counting national actions.

What Was Actually Different

Volume is not the story. Arrest counts have risen every year for five years. Three things changed in the first half of 2026.

Enforcement moved from endpoints to services. Operation Saffron seized First VPN, a bulletproof VPN used by more than 25 ransomware groups since 2014 β€” the first time a VPN service has been taken down as criminal infrastructure. Ukrainian authorities interviewed the alleged administrator and searched his residence. The AudiA6 action took the laundering layer: a cryptocurrency service that processed EUR 336 million for ransomware operations and appeared in more than 15 separate international investigations. Two administrators, Ukrainian and Russian nationals, were arrested in Georgia, and the U.S. DOJ charged Ruslan Igorevich Tkachuk, 37, and Alexander Vladimirovich Ledenev, 25, with conspiracy to launder monetary instruments and sting money laundering.

Neither of those targets encrypts anything or steals anything. They are the connective tissue β€” anonymity and cash-out β€” that every ransomware crew rents rather than builds. Taking a shared service imposes cost on every tenant simultaneously.

Enforcement moved upstream of ransomware entirely. Operation Endgame’s June sprint targeted Amadey, StealC and SocGholish β€” a loader, an infostealer and a drive-by delivery framework. None of them are ransomware. All of them are how ransomware arrives. The 27 million stolen credentials recovered in that operation is the number that matters: those are initial-access commodities that will not be sold.

Enforcement started treating scam compounds as a trafficking problem. Operation First Light 2026 β€” led by Dubai Police with the FBI and China’s Ministry of Public Security, with actions in Myanmar, Indonesia and Thailand β€” dismantled nine scam centers running pig-butchering operations. The FBI’s parallel Operation Level Up identified and warned nearly 9,000 victims, preventing an estimated $562 million in further losses. And the operation documented what practitioners have argued for two years: many of the people running the scams were themselves trafficking victims, recruited with job offers and held under coercion. The U.S. DOJ stood up a Scam Center Strike Force and then a National Fraud Enforcement Division on the same premise.

And It Did Not Work

Over exactly the period covered above, the active ransomware group count rose from 127 to 146. Attack volume rose 11% to 4,217 incidents. 61 new ransomware brands entered the market between April 2025 and March 2026 β€” one a week.

That is the honest accounting. The most productive enforcement half in the history of cybercrime coincided with the ecosystem’s largest expansion.

It would be easy to read that as futility. It is closer to a category error. Consider what each of these operations actually does to the economics:

Arrests remove operators, not capability. The 276 people arrested in First Light were largely compound workers, many coerced. Removing them frees people; it does not close the market for the fraud they were forced to run.

Infrastructure takedowns impose cost, not closure. Endgame has now run enough times β€” from the Rhadamanthys and VenomRAT actions in November 2025 through CrazyRDP to June 2026 β€” that the pattern is legible: infrastructure returns, but it returns more expensive, on worse hosting, with fewer customers willing to trust it. That is a tax, and a tax is a real result even when it is not a shutdown.

Group proliferation is partly a consequence of enforcement, not evidence against it. LockBit’s dismantling did not remove its affiliates from the labor pool; it scattered them across new brands. A market with 146 small operations is more resilient than one with five large ones β€” but it is also one where no single brand commands the reputation needed to run the largest extortions. Fragmentation is a cost imposed on the ecosystem that shows up in the statistics as growth.

Where enforcement has demonstrably worked is on the shared services: the VPN, the laundering pipeline, the loader networks. Those cannot be reconstituted by rebranding, because they require infrastructure, banking relationships and years of accumulated trust. Saffron and AudiA6 are the templates worth repeating.

What To Watch in H2

Whether the service-layer strategy scales. One bulletproof VPN and one laundering service are proofs of concept. The question is whether Europol and its partners can sustain that tempo against the next dozen.

Whether Georgia becomes a pattern. Arresting Ukrainian and Russian nationals in a third country is the workaround for the jurisdictions that will not extradite. It only works where the suspects travel.

Whether the trafficking framing changes anything. Recognizing compound workers as victims is correct and changes the enforcement calculus entirely β€” the arrestable population and the culpable population are not the same people. Whether prosecutions follow the money to the operators, rather than the keyboards, is the test.

Sources