Operation Ramz Seizes 53 Servers in Global Cybercrime Takedown
Key Takeaways Operation Ramz, a major international cybercrime crackdown, resulted in the seizure of 53 servers and the arrest of 201 individuals across 13 countries in the Middle East and North...
Key Takeaways
- Operation Ramz, a major international cybercrime crackdown, resulted in the seizure of 53 servers and the arrest of 201 individuals across 13 countries in the Middle East and North Africa (MENA) region.
- The operation, led by INTERPOL from October 2025 to February 2026, targeted phishing infrastructure, malware campaigns, and financially motivated cyber scams.
- Authorities identified 3,867 victims and 382 additional suspects, highlighting the widespread impact of these criminal networks.
- The initiative also uncovered instances of human trafficking linked to cyber scam operations, underscoring the convergence of cybercrime and organized crime.
A significant international effort to combat cybercrime, known as Operation Ramz, has successfully concluded with the confiscation of 53 servers, the apprehension of 201 individuals, and the identification of 382 further suspects throughout the Middle East and North Africa (MENA) region.
Table Of Content
This coordinated initiative, spearheaded by INTERPOL, ran from October 2025 until February 28, 2026, marking an unprecedented scale for a cybercrime operation in the area.
Thirteen nations participated, including Algeria, Jordan, Qatar, Morocco, and the UAE. The primary objective was to dismantle infrastructure supporting phishing, various malware campaigns, and financially driven cyber scams.
Investigators also confirmed that 3,867 victims had been affected by these illicit activities, illustrating the extensive reach and impact of the criminal organizations involved.

INTERPOL reported that nearly 8,000 pieces of intelligence were exchanged among the participating countries, facilitating investigations and enabling the swift disruption of malicious infrastructure. Neal Jetton, INTERPOL’s Director of Cybercrime, stated that the operation underscores the increasing necessity of cross-border collaboration to address cyber threats that transcend national borders.
Operation Ramz Seizes 53 Servers
Operation Ramz exposed a diverse array of cybercriminal methodologies, encompassing phishing-as-a-service platforms, systems compromised by malware, and elaborate investment fraud schemes.
- Qatar: Investigators located compromised devices unknowingly used by victims to disseminate malware. These affected systems were subsequently secured, and their users received notifications.
- Jordan: Authorities successfully dismantled a fraudulent online trading scheme. Disturbingly, they also discovered 15 individuals who had been trafficked and coerced into participating in cyber scam operations, leading to the arrest of two organizers.
- Oman: A vulnerable server, found hosting malware and exposing critical data from a private residence, was immediately shut down.
- Algeria: Law enforcement dismantled a phishing-as-a-service platform, confiscating its infrastructure and arresting one suspect.
- Morocco: Authorities seized devices containing sensitive banking data and phishing tools, with multiple individuals now facing legal proceedings.
The seizure of 53 servers was instrumental in disrupting these malicious operations, particularly those used to host phishing kits, command-and-control (C2) infrastructure, and various scam platforms.

Such systems are frequently leveraged by attackers to scale their campaigns, targeting both financial institutions and individual users.
INTERPOL collaborated closely with private-sector partners, including Group-IB, Kaspersky, Shadowserver Foundation, Team Cymru, and TrendAI. This partnership focused on tracking malicious infrastructure and analyzing threat intelligence, enhancing the speed of identifying indicators of compromise (IOCs) and improving coordinated response efforts.
Operation Ramz underscores the increasing sophistication of cybercriminal ecosystems within the MENA region, particularly their reliance on distributed infrastructure and advanced social engineering tactics. The discovery of human trafficking elements within cyber scam operations further highlights the disturbing convergence of cybercrime with traditional organized crime networks.
The initiative received crucial support from the Qatar Ministry of Interior and was funded by the European Union and the Council of Europe as part of the CyberSouth+ project.
Authorities stressed that continuous intelligence sharing and joint operations will be vital for countering evolving cyber threats and preventing further financial losses across the region.
What You Should Do
- Stay Vigilant Against Phishing: Be extremely cautious of unsolicited emails, messages, or calls asking for personal or financial information. Verify the sender’s identity through official channels before clicking links or downloading attachments.
- Report Suspicious Activity: If you encounter potential phishing attempts, scams, or any suspicious cyber activity, report it immediately to your local law enforcement or cybersecurity authorities.
- Secure Your Devices: Ensure all your devices (computers, smartphones, tablets) have up-to-date antivirus software, firewalls, and operating system patches. Regularly back up your important data.
- Use Strong, Unique Passwords and Multi-Factor Authentication (MFA): Implement strong, unique passwords for all online accounts and enable MFA wherever possible to add an extra layer of security.
- Educate Yourself and Others: Stay informed about common cyber threats and educate friends, family, and colleagues about cybersecurity best practices to help prevent them from falling victim to scams.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.