INTERPOL has coordinated a first-of-its-kind cybercrime crackdown throughout the Center East and North Africa (MENA) that led to 201 arrests and the identification of an extra 382 suspects.
The initiative concerned the efforts of 13 nations from the area, aiming to analyze and neutralize malicious infrastructure, arrest perpetrators behind these actions, and stop future losses. It happened between October 2025 and February 2026.
“The operation focused on neutralizing phishing and malware threats, as well as tackling cyber scams that inflict severe cost to the region,” INTERPOL stated in an announcement. “In addition to the arrests made, 3,867 victims were identified, and 53 servers were seized.”
The operation, codenamed Ramz, led to the disruption of a phishing-as-a-service (PhaaS) by Algerian authorities after its server was confiscated, together with a pc, a cell phone, and arduous drives containing phishing software program and scripts. One suspect was arrested in reference to the scheme.
Elsewhere, Moroccan officers seized computer systems, smartphones, and exterior arduous drives that contained banking information and software program used for phishing operations.
Authorities additionally recognized a legit server situated in a non-public residence in Oman that contained delicate info. The server suffered from a number of vital safety vulnerabilities and was contaminated by malware. INTERPOL stated actions had been taken to disable the server.
In an identical case, compromised gadgets had been found in Qatar, with the homeowners themselves unaware that their techniques had been getting used to unfold “malicious threats.” Though the precise nature of those threats was not disclosed, the impacted machines are stated to have been secured, and the machine homeowners had been alerted to take applicable safety measures.

Lastly, Jordanian police recognized a pc that was used to run monetary fraud scams, the place unsuspecting customers had been tricked into investing their belongings in a seemingly legit buying and selling platform, just for it to close down as soon as the funds had been deposited.
“A raid uncovered 15 individuals carrying out the scams, but investigators determined that they were victims of human trafficking who had been recruited under the false promise of employment from their home countries in Asia,” INTERPOL stated.
“Upon arrival in Jordan, their passports were confiscated, and they were forced or coerced into participating in the scheme. Two individuals suspected of orchestrating the operation were arrested.”

Group-IB, which was one of many personal sector corporations that participated within the effort, stated it offered “actionable intelligence” on over 5,000 compromised accounts, together with people who had been related to authorities infrastructure, and shared particulars about lively phishing infrastructure throughout the area.
“Cybercrime is borderless, and the only effective response is one that is equally borderless,” Joe Sander, CEO of Group Cymru, stated. “Operation Ramz is exactly that kind of response, law enforcement and trusted private-sector partners pooling intelligence, moving in concert, and dismantling the infrastructure that criminals depend on.”
Nations that took half in Operation Ramz included Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the U.A.E.
Collection of Legislation Enforcement Actions
The arrests come towards the backdrop of a string of legislation enforcement actions introduced by Germany and the U.S. Division of Justice (DoJ) in current weeks –
The sentencing of Thomasz Szabo (aka Plank, Jonah, and Cypher), 27, of Romania, to 48 months in jail for his position because the mastermind of a web-based swatting ring that focused greater than 75 public officers, 4 spiritual establishments, and a number of journalists.
The indictment of Owe Martin Andresen (aka Speedstepper), the suspected most important administrator of the illicit darknet market, Dream Market, on cash laundering expenses, following his arrest in Germany final week.
The shutdown of a relaunched model of the Crimenetwork market (it was initially dismantled in December 2024) and the arrest of a suspected administrator, a 35-year-old German citizen, on the Spanish island of Mallorca.
The conviction of Sohaib Akhter, 34, of Alexandria, Virginia, by a federal jury for deleting 96 databases storing U.S. authorities info and stealing the plaintext password of a person who had submitted a grievance to the Equal Employment Alternative Fee’s Public Portal.
The sentencing of Alan Invoice, 33, of Bratislava, the Slovakian Administrator of Kingdom Market, to 200 months (greater than 16 years) in jail after he pleaded responsible to a conspiracy to distribute managed substances, unlawful medication, stolen monetary information, counterfeit paperwork, and malware earlier this January.
The sentencing of David Jose Gomez Cegarra, 25, of Venezuela to time served and pay restitution totaling $294,820 in reference to a string of ATM jackpotting incidents between October 5 and November 11, 2024, within the U.S. states of New York, Massachusetts, and Illinois.
The arrest of a 21-year-old from Dordrecht for his or her involvement in a software known as JokerOTP that is utilized by cybercriminals to intercept one-time passwords (OTPs) and two-factor authentication (2FA) codes for hijacking on-line accounts by impersonating trusted organizations comparable to banks, cryptocurrency exchanges, and different main service suppliers.
The sentencing of Marlon Ferro (aka GothFerrari), 20, of Santa Ana, California, to 78 months in jail in reference to a social engineering conspiracy that stole greater than $250 million in cryptocurrency from victims throughout the U.S. between late 2023 and early 2025.
“This [social engineering] scheme blended sophisticated online fraud with old-fashioned burglary to drain victims of millions of dollars in digital assets,” U.S. Lawyer Jeanine Ferris Pirro acknowledged.
“The conspiracy’s operatives typically targeted individuals believed to hold significant cryptocurrency holdings. Its members manipulated victims into surrendering access to their digital wallets through elaborate fraud schemes. When victims stored their cryptocurrency in hardware wallets, physical devices that cannot be accessed remotely, the enterprise turned to Ferro.”

