Group-IB, a leading developer of cybersecurity technology to prevent, investigate and combat digital crime, announces that the company contributed to the INTERPOL-led Operation Ramz, one of the first major coordinated cybercrime operations in the Middle East and North Africa (MENA).
The operation was conducted between October 2025 and February 2026 and targeted phishing infrastructure, malware, and cyber fraud that caused significant financial and personal harm to both individuals and organizations in the region.
The effort covered 13 countries in the MENA region and resulted in 201 people were arrested, while further 382 suspects identified. The investigators also identified 3,867 victims, seized 53 servers and almost shared 8,000 intelligence records between participating countries to support ongoing and future investigations.
As part of the operation, Group-IB delivered intelligence on more than 5,000 compromised accounts, including accounts linked to government infrastructure. The information gave investigators a clearer picture of the extent of compromised credentials in the region.
Group-IB analysts also identified and mapped active phishing infrastructure across the MENA region. The analysis revealed two distinct groups of threat actors: those who created and distributed phishing resources, and those who sold and disseminated stolen data. The actor-centric threat intelligence helped strengthen the overall results of the operation.


Fraud, malware and phishing infrastructure exposed
Operation Ramz uncovered several types of cybercriminal schemes in the region.
IN Qatar Investigators identified compromised devices whose owners had themselves been subjected to cyberattacks, unaware that their systems were being used to spread malicious threats. The affected systems were secured and the owners were informed of necessary protective measures.
IN Jordan Authorities dismantled a fraud operation that posed as a legitimate trading platform. The investigation revealed that the 15 people who carried out the fraud were themselves victims of human trafficking. They had been recruited from Asian countries under false promises of work, had their passports confiscated upon arrival, and were forced to participate in the fraud. Two people suspected of organizing the operation were arrested.
IN Oman A server in a private residence containing sensitive information was identified. Although the owner had legitimate access, several serious security vulnerabilities were discovered, including an active malware infection, and the server was shut down to prevent further damage.
IN Algeria A phishing-as-a-service platform was identified and shut down. A suspect was arrested and hardware with phishing software and scripts was seized.
IN Morocco Authorities seized computers and external hard drives containing banking information and phishing tools, while three people were charged with criminal offenses.

”The MENA region has seen a sharp increase in phishing and fraud infrastructure targeting financial platforms, government agencies and individual victims. Operation Ramz demonstrates what coordinated, intelligence-led efforts can achieve,”, says Dmitry Volkov, CEO of Group-IB.

”In a world where cybercriminals exploit the digital landscape without borders, Operation Ramz shows how effective global cooperation can be. INTERPOL remains committed to working with member states and private partners to dismantle malicious infrastructure and bring cybercriminals to justice,”, says Neal Jetton, Head of Cybercrime at INTERPOL.
Public-private cooperation remains crucial
Group IB has long-standing collaborations with international law enforcement organizations such as INTERPOL, Europol and AFRIPOL, where the company contributes threat intelligence and investigative support to global cybercrime investigations.
Through its network of Digital Crime Resistance Centers (DCRC), regional expertise, and advanced threat and fraud intelligence, the company helps transform technical indicators into operational information that can be used in coordinated efforts against cybercrime.
As cybercrime becomes more advanced and widespread, public-private collaboration is highlighted as a continuing critical factor in identifying new threats, disrupting criminal infrastructure, and strengthening cyber resilience in the MENA region and globally.
About Group IB
Founded in 2003, Group-IB is a leading provider of predictive cybersecurity technology to investigate, prevent and combat digital crime globally. Headquartered in Singapore, Group-IB operates digital crime countermeasure centers in the Americas, Europe, the Middle East and Africa, Central Asia and the Asia-Pacific region. The company delivers predictive, intelligence-driven defense by analyzing and neutralizing regional and country-specific cyber threats through its Unified Risk Platform . The company offers unparalleled defense through its industry-leading Cyber Fraud Intelligence Platform , Cloud Security Posture Management , Threat Intelligence , Fraud Protection , Digital Risk Protection , Managed Extended Detection and Response (XDR) , Business Email Protection and External Attack Surface Management- solutions, targeting government, retail, healthcare, gaming, financial sectors and more. Group-IB works with international law enforcement agencies such as INTERPOL, Europol and AFRIPOL to strengthen cybersecurity worldwide and has been awarded by advisory firms such as Datos Insights, Gartner, Forrester, Frost & Sullivan and KuppingerCole.








