INTERPOL said Operation Synergia III led to the arrest of 94 suspects, the seizure of 212 devices and servers, and the sinkholing or takedown of more than 45,000 malicious IP addresses tied to cybercrime infrastructure across 72 countries and territories. The operation ran from July 2025 through January 2026 and targeted infrastructure supporting phishing, malware, ransomware, romance scams, credit card fraud, and related online fraud. Authorities said 110 additional individuals remain under investigation, underscoring that follow-on enforcement activity is still ongoing.
Preliminary case details show broad international participation and a focus on both technical infrastructure and fraud operators. In Macau, investigators identified more than 33,000 phishing and fraudulent websites, including fake casino, banking, government, payment, and other critical-service sites used to steal credentials and payment data. In Bangladesh, authorities arrested 40 suspects and seized 134 devices linked to loan scams, employment scams, identity theft, and credit card fraud, while in Togo police arrested 10 suspects tied to a fraud ring whose members split responsibilities between account compromise and social-engineering schemes such as romance and sextortion scams. The reporting describes a coordinated law-enforcement disruption of active criminal infrastructure rather than a vendor announcement or generic security guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
INTERPOL disclosed the results of Operation Synergia III, highlighting the scale of the multinational crackdown and the role of cross-border law enforcement and private-sector intelligence sharing.
The operation ended on 2026-01-31 after sinkholing or taking down more than 45,000 malicious IP addresses and servers, seizing 212 devices and servers, arresting 94 people, and placing 110 more under investigation.
India's Central Bureau of Investigation searched locations across four states in a transnational online investment and part-time job fraud case linked to Dubai-based fintech platform Pyypl, and identified Ashok Kumar Sharma as a key member taken into custody.
Bangladeshi authorities took major enforcement action against a cybercrime network tied to scams, identity theft, and credit card fraud, arresting 40 people and seizing 134 devices.
Authorities in Togo disrupted a fraud ring involved in hacking, romance scams, sextortion, and related fraud schemes, resulting in 10 arrests during the operation.
During Operation Synergia III, authorities in Macau, China identified over 33,000 phishing and fraud websites, including sites impersonating casinos, banks, and government platforms.
INTERPOL launched Operation Synergia III on 2025-07-18 to disrupt cybercrime infrastructure tied to phishing, malware, ransomware, and related fraud, with support from private-sector partners Group-IB, Trend Micro, and S2W.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceinterpol.int
Open sourcedatabreaches.net
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.