What Happened
An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday. The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests. Included among them was Guedz, the primary
Why It Matters
The reported operation describes INTERPOL’s Operation Ramz, in which Group-IB intelligence helped identify and dismantle SniperDz, a long-running phishing-as-a-service (PhaaS) platform active since at least 2015 that used more than 20,000 domains and around 80 phishing templates to target users of 30+ major online services, leading to 201 arrests and the seizure of infrastructure across 13 MENA countries.[1][2][3] The article states that the platform, administered by an individual known as "Guedz," provided turnkey phishing kits, hosting, and operational support to cybercriminals via Telegram and Facebook channels, significantly lowering the technical barrier for large-scale credential theft.[1][2][3] From a CyberSE.AI perspective, this illustrates malicious service-style infrastructure that could readily be augmented by or integrated with AI (for targeting, content generation, and automation), so AI-enabled defenses must assume adversaries have access to scalable, service-based cybercrime ecosystems. Organizations should use Continuous AI Red Teaming to test how their AI agents and workflows withstand phishing and social-engineering campaigns modeled on PhaaS operations, and apply
CyberSE Analysis
This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html