INTERPOL coordinated a major crackdown cybercrime in the Middle East and North Africa (MENA), which led to 201 arrests and the identification of an additional 382 suspects . The initiative involved the efforts of 13 countries in the region from October 2025 to February 2026, with the aim of investigating and disrupting malicious infrastructure, apprehending the perpetrators behind these activities and preventing future losses.
“The operation focused on neutralizing threats and malware, as well as tackling cyber fraud that is causing serious costs in the region,” INTERPOL said in a statement. “In addition to the arrests made, 3,867 victims were identified and 53 servers were seized.”
Operation Ramz: Arrests, seizures and disruption of illegal services
The operation, codenamed Ramz, led to the dismantling of a phishing-as-a-service (PhaaS) by Algerian, after its server was seized, along with a computer, a mobile phone and hard drives containing software and phishing scripts. In addition, a suspect allegedly associated with the service was arrested.
See also: Operation Synergia III: INTERPOL dismantles digital criminal networks

Elsewhere, Moroccan seized computers, smartphones and external hard drives containing banking data and software used for phishing operations. Authorities also located a legitimate server located in a private residence in Oman that contained sensitive information. The server was vulnerable to multiple critical security vulnerabilities and was infected with malware. INTERPOL said steps were taken to disable the server.
In a similar case, compromised devices were found in Qatar, with the owners themselves unaware that their systems were being used to spread “malicious threats.” While the exact nature of these threats was not disclosed, the affected machines are said to have been secured and the owners of the devices have been notified to take appropriate security measures.
Finally, Jordanian police have identified a computer used to carry out financial scams , where unsuspecting users were tricked into investing their assets on a seemingly legitimate trading platform . Once they deposited their money, the platform was shut down.

“A raid uncovered 15 people carrying out the scams, but investigators determined they were victims of human trafficking who had been recruited with the false promise of employment from their home countries in Asia,” INTERPOL said. “Upon arrival in Jordan, their passports were confiscated and the people were forced or coerced into participating in the scam. Two people suspected of organizing the operation were arrested.”
See also: Operation Red Card 2.0: 651 arrests for online fraud in Africa
Group -IB, one of the private sector companies involved in the crackdown, said it provided “useful information” on over 5,000 compromised accounts, including those linked to government infrastructure. It also shared details of active phishing infrastructures across the region.
International cooperation brings results
“Cybercrime knows no borders and the only effective response is one that is also borderless,” said Joe Sander, CEO of Team Cymru. “Operation Ramz is exactly that kind of response, with law enforcement and trusted private sector partners gathering intelligence, moving in concert and dismantling the infrastructure that criminals depend on.”
Countries participating in INTERPOL's Operation Ramz included Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia and the United Arab Emirates.
Operation Ramz is a prime example of the importance of international cooperation in tackling modern cybercrime. The arrests, seizures of equipment and the neutralisation of malicious infrastructure demonstrate that coordinated actions between states, international organisations and private companies can deliver significant blows to criminal networks exploiting cyberspace. At the same time, the operation highlighted the ever-increasing complexity of cyber threats, which are now linked not only to financial fraud and phishing, but also to human trafficking and forced participation in illegal activities.
See also: Black Basta leader on EU and INTERPOL's most wanted list
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, the case highlights that cybercrime is evolving into a global threat without geographical boundaries, requiring constant vigilance, information sharing and investment in cybersecurity. The protection of critical infrastructure, personal data and citizens can no longer rely solely on national initiatives, but requires collective action and transnational cooperation. In an increasingly interconnected world, businesses like Ramz show that effectively addressing cyber threats depends on the speed, coordination and cooperation of all stakeholders.
