INTERPOL has announced the results of Operation Ramz, the first large-scale cybercrime operation ever coordinated across the Middle East and North Africa (MENA) region.
Running from October 2025 through February 28, 2026, the four-month operation targeted phishing infrastructure, malware networks, and cyber-enabled financial fraud schemes inflicting severe financial and personal harm across the region.
The operation delivered sweeping enforcement outcomes across 13 MENA nations: Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE.
Authorities arrested 201 individuals, identified 382 additional suspects, and documented 3,867 victims throughout the investigation.
Operation Ramz Seizes 53 Servers
Law enforcement seized 53 servers, along with nearly €900,000 in cash, 443 computers, 238 mobile phones, and multiple data storage devices containing criminal toolkits.
Nearly 8,000 intelligence packages were disseminated among partner agencies to support active investigations.
Operation Ramz simultaneously targeted three primary threat categories: phishing-as-a-service (PhaaS) platforms, malware-infected infrastructure, and investment fraud scams.
In Algeria, authorities identified a fully operational PhaaS website. They seized a server, a computer, a mobile phone, and hard drives loaded with phishing scripts and software, resulting in one arrest.
Moroccan law enforcement recovered computers, smartphones, and external hard drives containing banking credentials and phishing toolkits, placing three individuals under judicial review, with others still under active investigation.
In Qatar, investigators found that compromised devices were silently weaponized to distribute malware, with their owners unaware that threat actors had co-opted their systems.
In Oman, a privately hosted server discovered in a residential property was riddled with multiple critical security vulnerabilities, including active malware infection. It was immediately disabled to prevent further data exposure.

One of the operation’s most alarming revelations emerged in Jordan, where authorities raided a financial fraud operation disguised as a legitimate investment trading platform.
The platform lured victims into depositing funds, according to Interpol, then vanished once transfers were complete.
When investigators raided the site, they uncovered 15 individuals running the scam who were themselves victims of human trafficking recruited from Asian countries under false employment promises, stripped of their passports upon arrival in Jordan.
INTERPOL worked alongside five private cybersecurity firms, Group-IB, Kaspersky, Shadowserver Foundation, Team Cymru, and TrendAI, to track malicious cyber activity and pinpoint rogue servers throughout the operation.
Group-IB’s intelligence contribution was particularly notable, delivering actionable data on more than 5,000 compromised accounts, including credentials linked to government infrastructure, while mapping two distinct threat actor clusters.
Operation Ramz represents INTERPOL’s third major cybercrime enforcement action of 2026. Earlier operations this year included Operation Red Card 2.0 in February, 651 arrests across 16 African countries targeting mobile money fraud, and Operation Synergia III in March, which resulted in 45,000 malicious IPs sinkholed and 94 arrests across 72 nations.
Neal Jetton, INTERPOL’s Director of Cybercrime, stated: “In a world where cybercriminals exploit the digital landscape without borders, Operation Ramz demonstrates the effectiveness of global collaboration to take down malicious infrastructure, disrupt criminal groups and bring perpetrators to justice”.
Operation Ramz received backing from the Qatar Ministry of Interior and was partially funded by the European Union and the Council of Europe under the CyberSouth+ project.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.