INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
An INTERPOL-led operation disrupted Sniper Dz, a long-running phishing platform, and arrested its administrator. Authorities from 13 MENA countries made 201 arrests.
Intelligence analysis by GPT-5.4 Mini

Group-IB says an INTERPOL-led operation shut down Sniper Dz, a free phishing-as-a-service platform active since at least 2015. The action also led to 201 arrests across 13 MENA countries and the seizure of phishing-related hardware.
Sniper Dz was like a free toolkit and rented store for thieves online. Police and investigators shut it down and arrested people running it, which should make it harder for scammers to trick people into giving away passwords and personal details.
Analysis
What happened
Group-IB says an INTERPOL-led effort disrupted Sniper Dz, a long-running phishing-as-a-service platform, during Operation Ramz. The operation ran from October 2025 to February 2026 and involved authorities from 13 countries in the Middle East and North Africa. Group-IB says the action led to 201 arrests, including the arrest of Guedz, described as the platform's primary developer and administrator, by the Algerian National Police.
What Sniper Dz did
According to Group-IB, Sniper Dz had been active since at least 2015 and evolved into a criminal service that offered ready-made phishing kits, hosting infrastructure, and operational support. The platform rebranded over time as Joker Dz, Storm Dz, and Spam Dz. Authorities also seized hardware containing phishing software and scripts, and the service's website was taken down.
The report says the platform had been linked to more than 45,000 victim records and over 20,000 unique domains. Its phishing toolkit targeted about 30 major global organizations, including PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam, and used 80 phishing templates in five languages: Arabic, English, French, Spanish, and Hebrew.
Why it stood out
Group-IB says Sniper Dz was unusual because it offered its infrastructure for free, which made it easier for other criminals to launch phishing campaigns at scale. The platform's operators then monetized traffic and stolen credentials through schemes such as carrier billing fraud, premium SMS subscriptions, browser notification abuse, and affiliate scam redirects.
The company also says the operation used social engineering tied to public figures in the region. Fake accounts impersonating political personalities were used to spread phishing links disguised as promotions or free internet access. The story underscores how phishing services can combine technical kits, hosting, and social manipulation into one repeatable criminal business.
Key points
- INTERPOL-led Operation Ramz disrupted Sniper Dz, a phishing-as-a-service platform active since at least 2015.
- Authorities from 13 MENA countries made 201 arrests, including the platform's alleged administrator in Algeria.
- Group-IB says Sniper Dz collected more than 45,000 victim records and used over 20,000 domains.
- The service targeted major brands and used phishing templates in Arabic, English, French, Spanish, and Hebrew.
- Its unusual model offered infrastructure for free and relied on credential theft plus scam traffic monetization.
If the shutdown holds, one of the easier-to-use phishing services in circulation is now gone, which could slow down copycat campaigns. The arrests and seizure of infrastructure may also help investigators identify more people and related sites tied to the same network.
The platform's past rebrands show that phishing operators can regroup under new names if pressure eases. The same playbook of free kits, fake brands, and social engineering can be rebuilt elsewhere, so the disruption may be temporary if follow-up enforcement is weak.



