Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

201 Arrested in Crackdown on Cybercrime in Middle East, North Africa

The 13-country effort, named Operation Ramz, targeted cyber threats in the Middle East and North Africa region.

Hacker arrested

A total of 201 individuals were arrested, and 382 additional suspects were identified in a law enforcement crackdown on phishing and malware threats in the Middle East and North Africa (MENA) region.

Named Operation Ramz, the 13-country effort also resulted in the seizure of 53 servers and in the identification of 3,867 victims across participating jurisdictions, Interpol announced.

Law enforcement agencies in Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE participated in the operation, which ran from October 2025 to 28 February 2026.

Authorities received support from multiple private partners, including Group-IB, Kaspersky, the Shadowserver Foundation, Team Cymru, and TrendAI, which helped track the illegal activities and identify the malicious infrastructure.

In Algeria, law enforcement shut down a phishing-as-a-service (Phaas) website, arrested one suspect, and seized a server, a computer, a phone, and hard drives containing malicious software and scripts.

In Jordan, police located a computer used in financial fraud scams and arrested two individuals for orchestrating the scheme. As part of the operation, 15 individuals were carrying out the scams, but all were victims of human trafficking.

Advertisement. Scroll to continue reading.

The individuals were promised employment and came to Jordan from various Asian countries. Upon arrival in Jordan, the two suspects confiscated their passports and forced them to participate in the scheme.

In Morocco, authorities arrested three individuals and seized computers, phones, and hard drives used in phishing operations.

In Oman, authorities disabled a server containing sensitive information that was affected by multiple critical vulnerabilities and was infected with malware.

In Qatar, law enforcement identified compromised devices that had been used to spread malware without their owners’ knowledge. The systems were secured, and the owners were notified.

“Cybercrime is borderless, and the only effective response is one that is equally borderless. Operation Ramz is exactly that kind of response, law enforcement and trusted private-sector partners pooling intelligence, moving in concert, and dismantling the infrastructure that criminals depend on,” said Team Cymru CEO Joe Sander.

Related: US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator

Related: Trump Administration Vows Crackdown on Chinese Companies ‘Exploiting’ AI Models Made in US

Related: In Other News: N8n Flaw Exploited, Slopoly Malware, Interpol Cybercrime Crackdown

Related: 574 Arrested, $3 Million Seized in Crackdown on African Cybercrime Rings

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.