Group-IB researchers attributed more than 30 attacks on banks, financial-services firms and telecom companies to a French-speaking cybercrime group they named OPERA1ER. They estimated the group stole at least $11 million; the total may have approached $30 million, but that higher figure was not confirmed as an exact or audited loss.
What was the OPERA1ER cybercrime campaign?
In a report published on November 3, 2022, CyberScoop reported Group-IB’s findings on a campaign that had targeted organizations since 2016. The researchers counted more than 30 attacks across at least 15 countries in Africa, Asia and Latin America. Targets included banks, other financial-services companies and telecommunications firms; the activity was not limited to African banks.
The countries named in the report were Côte d’Ivoire, Mali, Burkina Faso, Benin, Cameroon, Bangladesh, Gabon, Niger, Nigeria, Paraguay, Senegal, Sierra Leone, Uganda, Togo and Argentina. The group sometimes attacked the same victim twice.
How much money did OPERA1ER steal?
Group-IB estimated losses at a minimum of $11 million and said the sum might have been nearly three times higher, or close to $30 million. The $30 million figure is therefore a possible upper estimate, not a verified exact total. These figures describe the campaign as Group-IB reported it in 2022; they are not a measure of cybercrime losses across the banking sector.
#1 Best Overall
How did the attacks work?
Phishing and a long period inside victim networks
Researchers described spear-phishing and the use of commercially available tools to gain access. After entering a network, attackers reportedly waited three to 12 months before taking money. During that period, they studied key employees, fraud safeguards, back-end systems and how cash withdrawals were handled.
Moving and withdrawing funds
When ready to steal, the attackers moved funds into accounts they controlled and relied mainly on ATM withdrawals to cash out. In one attack described by Group-IB, they used a network of 400 money-mule accounts. That figure refers to one reported operation, not every attack in the campaign.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Did the attackers compromise SWIFT?
No. Group-IB said attackers accessed the SWIFT messaging interfaces of at least two victim banks, but explicitly stated that SWIFT itself was not compromised. Access to a bank’s interface is not the same as breaking into or compromising the SWIFT service.
What did Group-IB do after identifying victims?
Group-IB’s European Threat Intelligence Unit said it identified and contacted 16 affected organizations. Rustam Mirkasymov, then head of cyberthreat research at Group-IB Europe, told CyberScoop: “Group-IB has long-standing partnerships with law enforcement agencies, and we shared our findings with financial organizations, identified victims and all partners.”
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteRank #3
CyberScoop also reproduced Group-IB’s explanation for delaying publication: “At that moment we really risked losing them from our sight.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is OPERA1ER still active?
The 2022 report described the group as active at that time. That reporting does not establish whether OPERA1ER remains active in 2026, so its current status should not be inferred from the historical account.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




