Operation Ramz shows where Southeast Asia's scam compounds go when they get shut down- 241
June 28, 2026
INTERPOL's Operation Ramz, the largest coordinated cybercrime operation the organization has ever run in the Middle East and North Africa, arrested 201 people and identified 382 additional suspects across thirteen countries between October 2025 and February 2026. But its more significant finding sits beneath the headline arrest count: several of the people initially treated as suspects were themselves victims of human trafficking, recruited under false promises of legitimate work and forced into running scam operations after their passports were confiscated — the same exploitative labor model long documented in Southeast Asia's scam compounds, now surfacing in a region international law enforcement had not previously treated as a comparable hub.
The operation's scale reflects a genuinely coordinated regional response rather than a single-country crackdown. Backed by Qatar and the European Union, INTERPOL worked with the governments of Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE, alongside cybersecurity partners Group-IB, Kaspersky, the Shadowserver Foundation, Team Cymru, and Trend Micro. The results reported were substantial by any regional cybercrime enforcement standard: 3,867 identified victims, 53 servers seized, and nearly 8,000 intelligence records shared between participating countries — INTERPOL's Director of Cybercrime, Neal Jetton, framed the operation as evidence that borderless cybercrime requires an equally borderless enforcement response.
The country-level cases documented within the operation reveal a range of criminal infrastructure rather than a single scheme. In Jordan, authorities dismantled a fraud compound running fake investment schemes and arrested the two individuals running the operation — but of the fifteen people found actually carrying out the scam work on-site, investigators determined all were trafficking victims, recruited from Asian countries under promises of legitimate employment, then stripped of their passports upon arrival and coerced into the scheme. Algeria's contribution centered on dismantling a phishing-as-a-service platform traced to a single server, while Moroccan authorities seized hard drives containing stolen banking data and phishing software from a compound raid, arresting three suspects. Qatari and Omani cases involved disabling malware-infected servers and compromised devices being used, in some instances, without their owners' knowledge.

The trafficking discovery in Jordan is the detail that connects Operation Ramz to a wider geopolitical pattern this publication has tracked developing over the past year. Southeast Asian nations — Cambodia, Myanmar, and Laos most prominently — have spent recent months disrupting the large-scale scam compounds that made the region synonymous with forced-labor cybercrime operations, and experts have warned for months that displaced organizers would simply relocate rather than disband. Operation Ramz suggests that relocation is already underway, with the Middle East and North Africa emerging as a genuine next destination for the same trafficking-fueled business model. Indonesia's own separate crackdown — more than 500 arrests in the past month, alongside consideration of tightening its 30-day visa-free entry rules specifically to block scam operators from re-entering the country — indicates the pressure in Southeast Asia hasn't relented even as the MENA front opens. What Operation Ramz ultimately documents is not the end of a criminal ecosystem but its geographic diffusion: enforcement success in one region is displacing the same exploitative infrastructure into the next, faster than international law enforcement coordination can currently track it.
