INTERPOL Arrests 201 in First-Ever MENA Cybercrime Sweep: Operation Ramz
Operation Ramz, the first INTERPOL-coordinated cybercrime operation of its scale in MENA, resulted in 201 arrests, 3,867 victims identified, and 53 servers seized across 13 countries, with Group-IB and Kaspersky providing critical intelligence support.

Cybercrime investigator reviewing network intelligence data with seized hardware devices on desk in a law enforcement operations room
A landmark cybercrime enforcement operation across the Middle East and North Africa has resulted in 201 arrests, the identification of 3,867 victims, and the seizure of 53 servers, making it the largest and most coordinated law enforcement action against cyber fraud infrastructure in the region's history.
INTERPOL's Operation Ramz ran from October 2025 through 28 February 2026, bringing together 13 MENA countries to investigate and dismantle malicious infrastructure, arrest perpetrators, and prevent further financial and personal harm across the region. Nearly 8,000 pieces of actionable data and intelligence were disseminated among participating countries to support ongoing investigations.
The operation targeted three categories of threat: phishing and malware infrastructure, financial fraud platforms, and cyber scams that have imposed significant costs on individuals and businesses across the region. The full list of participating countries included Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE.
The operation was funded in part by the European Union and the Council of Europe under the CyberSouth+ project, with additional support from the Qatar Ministry of Interior.
Private Sector Intelligence at the Core
The operation's success was built on intelligence provided by five private sector partners: Group-IB, Kaspersky, the Shadowserver Foundation, Team Cymru, and TrendAI.
Group-IB delivered actionable intelligence on more than 5,000 compromised accounts, including accounts linked to government infrastructure, giving investigators a precise picture of the scale of credential compromise across the region. Group-IB analysts also identified and mapped active phishing infrastructure, tracking two distinct threat actor clusters: those responsible for creating and distributing phishing resources, and separate actors engaged in selling and distributing leaked data.
Kaspersky's Threat Research team provided technical data on region-specific cyberthreats and malicious infrastructure, including command-and-control server details used to distribute and manage malware. Kaspersky Threat Intelligence maintains visibility across more than 300 threat actors and over 500 active malicious campaigns.
Team Cymru, Shadowserver Foundation, and TrendAI contributed additional tracking and infrastructure identification capability, enabling the coordination of intelligence across 13 jurisdictions in parallel.
Country-Level Outcomes
In Algeria, authorities identified and dismantled a phishing-as-a-service (PhaaS) platform. A server, computer, mobile phone, and hard drives containing phishing software and scripts were seized. One suspect was taken into custody.
Moroccan authorities seized computers, smartphones, and external storage devices containing banking data and phishing tools used in active operations. Three individuals are currently undergoing judicial proceedings, with additional suspects still under investigation.
In Jordan, police traced a computer used to operate a financial fraud scheme in which victims were persuaded to invest through a platform that appeared legitimate but shut down immediately after funds were received. A subsequent raid uncovered 15 individuals involved in conducting the fraud. Crucially, investigators determined that these individuals were themselves victims of human trafficking, recruited from Asian countries under false employment promises, their passports confiscated upon arrival in Jordan and they were coerced into participating in the fraud operation. Two individuals suspected of orchestrating the scheme were arrested.
In Qatar, intelligence gathered through Operation Ramz led to the discovery of compromised devices whose owners had no knowledge their machines had been hijacked and repurposed to distribute malware. The affected systems were secured, and device owners were notified.
Oman investigators identified a server at a private residence containing sensitive data. The server's owner had legitimate access to the information, but the server carried multiple critical security vulnerabilities including an active malware infection. The server was disabled to prevent further harm.
What the Numbers Mean for Enterprise Security
The scale of the operation reveals several threat patterns with direct relevance to enterprise security teams across the GCC.
The presence of phishing-as-a-service infrastructure in Algeria confirms that industrialised attack tooling is no longer limited to well-resourced threat actors. Commodity PhaaS platforms enable lower-capability actors to run technically sophisticated phishing campaigns at scale, lowering the barrier to enterprise credential compromise significantly.
The figure of more than 5,000 compromised accounts identified by Group-IB, including government accounts, signals the depth of credential exposure across the region. For enterprise security teams, this is a reminder that stolen credentials from regional breaches circulate across darknet markets and are actively used in targeted intrusions, even when the original breach did not involve the targeted organisation directly.
The Jordan case highlights an increasingly documented convergence of cybercrime and human trafficking networks, a development that complicates attribution and creates legal complexity for organisations and law enforcement agencies seeking to understand who is actually operating behind an attack.
The UAE, despite participating in the operation, faces a threat environment that has continued to intensify. According to risk consultancy Gallagher, the country faces up to 800,000 cyberattacks daily, a 3.5 times increase linked to the rise in regional conflict activity.
Industry and Law Enforcement Response
Neal Jetton, INTERPOL's Director of Cybercrime, said the operation demonstrated the power of cross-border collaboration: "In a world where cybercriminals exploit the digital landscape without borders, Operation Ramz demonstrates the effectiveness of global collaboration. INTERPOL is dedicated to working with its member countries and private sector partners to take down malicious infrastructure, disrupt criminal groups, and bring perpetrators to justice."
Dmitry Volkov, CEO of Group-IB, noted the role of regional intelligence infrastructure: "The MENA region has seen a sharp rise in phishing and scam infrastructure targeting financial platforms, government services, and individual victims. Operation Ramz shows what coordinated, intelligence-led action can achieve. This operation was the result of strong collaboration between our Digital Crime Resistance Centers across the MENA and APAC regions."
Joe Sander, CEO of Team Cymru, said: "Cybercrime is borderless, and the only effective response is one that is equally borderless. Operation Ramz is exactly that kind of response, law enforcement and trusted private-sector partners pooling intelligence, moving in concert, and dismantling the infrastructure that criminals depend on."
Yuliya Shlychkova, Vice President of Global Public Affairs at Kaspersky, said the operation showed how public-private collaboration can dismantle criminal networks at scale, enabling investigators to act swiftly on timely threat intelligence before further harm occurs.
For enterprise security and compliance teams operating across the MENA region, Operation Ramz is both a signal and a precedent. It confirms that regional law enforcement is now operationally capable of acting on intelligence at scale, and that organisations which invest in threat intelligence sharing, supply chain visibility, and behavioural detection controls are better positioned to both contribute to and benefit from enforcement actions of this kind.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.