Reverse-Hacking Scam Centres: The Documented Cases Behind the Viral Clips

Original illustration created for Cyber Security Briefing.
Interpol's Operation First Light 2026 produced 5,811 arrests and the interception of $293 million across 97 countries between January 15 and April 30, the agency reported on July 9. That is the largest verified enforcement number in the current wave of scam-center takedowns, and it involved police work, not private actors, breaching a compound's network from a laptop overseas.
The gap between that fact and the genre of clips now circulating, screen recordings claiming to show a researcher or vigilante "inside" a scam center's own machines, is where the current debate actually sits. The documented cases treat reverse-hacking as, at most, a policy the US government has just started building the legal scaffolding for.
What the executive order actually authorizes
Executive Order 14390, signed March 6, 2026, set the policy predicate: a "commensurate response that includes law enforcement, diplomacy, and potential offensive actions" against cyber-enabled transnational criminal organizations. It did not authorize anyone to start hacking scam centers that week. It directed the Attorney General and the Secretary of Homeland Security to review operational and technical frameworks for combating scam centers — a review, not a green light.
What private companies have done so far is disruption, not intrusion
The closest documented instance of private firms acting against scam infrastructure predates the memo by months, and it looks nothing like a hack-back. During "Disruption Week," held May 18–21, 2026, the Department of Justice worked with Apple, Google, Meta, and Microsoft to disable millions of scam accounts and freeze $3.8 million in cryptocurrency, according to a DOJ release published June 3. Assistant Attorney General A. Tysen Duva said the department would work "shoulder-to-shoulder" with private firms to keep American money from flowing to criminal groups. FBI Director Kash Patel framed the goal as leveraging partnerships to "impose cost on criminals."
The action was account-level: platform bans and asset freezes executed under existing terms of service and legal process, coordinated with law enforcement rather than run independently by a company deciding to go on offense.
Microsoft's own casework follows the same pattern. On January 14, 2026, its Digital Crimes Unit took down "RedVDS," a marketplace selling disposable virtual computers to scammers for as little as $24 a month, linked to $40 million in reported fraud losses since March 2025, including $7.3 million from a single Alabama pharmaceutical company. The unit didn't hack the scammers' machines; it pursued coordinated legal action in the US and UK to seize the infrastructure they rented.
Microsoft repeated the approach on a larger scale in a report published June 24, describing AI-assisted analysis used to target what it called the "cybercrime assembly line", simultaneously disrupting tools like Amadey and StealC, which were linked to 140,000 infected computers globally in May 2026 alone. Microsoft said it identified 18,000 victim computers and severed criminal control while working with internet service providers to protect affected customers. That is takedown-and-remediation work performed with ISP cooperation.
The $15 billion figure traces to one trade outlet, not the FBI
The largest figure attached to the crackdown — more than 30 cases opened and over $15 billion in assets restrained — comes from a single source: a July 28 report by Coinfomania, a crypto-focused news site, citing FBI Director Kash Patel. No DOJ or FBI release corroborates either number. If the $15 billion figure holds, it matters what kind of hold it describes. Assets restrained by court order are frozen pending litigation, not forfeited to the government. A distinction the Coinfomania report does not address. It should be treated as a claim awaiting confirmation from a primary DOJ or FBI release, not as a settled number to build analysis on.
What is corroborated across multiple government sources is the enforcement pattern behind those cases. A joint operation between the FBI, Dubai Police, and the Royal Thai Police dismantled nine scam centers used for cryptocurrency investment fraud, the DOJ announced on April 29, resulting in at least 276 arrests. Thet Min Nyi, a Burmese national, was among those charged in San Diego for managing the compounds. U.S. Attorney Adam Gordon said "global crime now faces global justice," adding that scammers are no longer safe "half a world away." That line describes cross-border police and prosecutorial coordination: extradition, joint task forces, and physical raids on hotels and compounds, the kind Interpol detailed in its July 9 release, which described police dismantling a network in Eswatini using a "realistic replica of a Brazilian police station" and dismantling two scam centers operating out of hotels in Palau, leading to 22 deportations.
Why the tactic doesn't scale the way the clips imply
Every private-sector action documented in the interim, Disruption Week's account bans, the RedVDS seizure, the Amadey/StealC takedown, operated through legal process against infrastructure the companies themselves control or can compel through court action.
That distinction matters for anyone weighing the viral clips against what's actually checkable. A researcher gaining visibility into a scam operation's tooling through a service takedown, a seized command-and-control server, or a cooperating ISP produces evidence law enforcement can use. A claim of directly accessing and controlling a scam center's internal network is a much harder thing to verify and a much easier thing to fake for engagement.
The FBI's own alert on July 20 is a reminder of how thoroughly the scam ecosystem has adopted the same visual language now used to sell the reverse-hacking narrative. The bureau warned that scammers are using AI-generated videos to impersonate FBI personnel and revictimize people who have already lost money, luring them to spoofed websites to harvest personal information. The IC3 clarified in that alert that it does not work with private law firms or other non-law-enforcement entities to recover lost funds. A fabricated video of an FBI agent recovering someone's crypto and a fabricated video of a vigilante seizing a scam center's desktop are the same production technique aimed at two different audiences, victims in one case, an online audience of practitioners in the other.
What the documented record supports
The verifiable disruption activity so far is government-led, court-authorized, and infrastructure-focused: account bans coordinated with platforms, marketplace seizures pursued through legal filings in multiple jurisdictions, and physical raids resulting in arrests. Interpol's 5,811 arrests, the DOJ's 276 arrests in the Dubai-Thailand operation, and Microsoft's two documented takedowns are the checkable baseline. No DOJ, FBI, or Microsoft release describes a private company accessing a scam center's own systems.
Sources
This article was reported from the following sources.
Over 5,800 arrests, USD 293 million intercepted in global fraud bust - Interpol — Interpol, 2026-07-09
Scam Center Strike Force Announces Results of U.S. & Private Industry 'Disruption Week' — U.S. Department of Justice, 2026-06-03
Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens (Executive Order 14390) — The White House, 2026-03-06
Microsoft disrupts global cybercrime subscription service responsible for millions in fraud losses — Microsoft On the Issues, 2026-01-14
FBI Opens More Than 30 Cases in Global Crackdown on Scam Centers — Coinfomania / edgeX Exchange, 2026-07-28
Scaling cybercrime disruption through innovation and AI — Microsoft On the Issues, 2026-06-24
Coordinated Takedown of Scam Centers Leads to at Least 276 Arrests — U.S. Department of Justice, 2026-04-29
The State of Ransomware 2026: Payments Drop as Encryption Climbs — Sophos, 2026-07-15
FBI Warns of Scammers Impersonating the IC3 — FBI (IC3), 2026-07-20
All above links verified at time of publishing.
