Threats · 94 days ago
The break was not one phishing site. It was a shared phishing service that let many crews run convincing login traps at scale, so the real asset was the operator network and tooling, not any single domain. Shutting it down cuts off the platform, but it does not erase the records and credentials already collected.
Operation Ramz disrupted Sniper Dz, a free phishing-as-a-service platform active since 2015, and authorities in 13 MENA countries made 201 arrests, including the administrator known as Guedz. Group-IB says the service collected more than 45,000 victim records and was tied to more than 20,000 domains, with templates targeting major brands like PayPal, Facebook, Instagram, Yahoo, Netflix, and Steam.
That leaves a follow-on risk after the takedown. A free phishing platform lowers the barrier to entry for low-skill operators and can leave a large pool of stolen credentials available for account takeover and secondary fraud long after the infrastructure is gone.
2 sources covering this story
INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
INTERPOL-led Operation Ramz disrupted Sniper Dz, a free phishing-as-a-service platform active since 2015 with 45,000 victim records and 20,000+ domain
Interpol Dismantles SniperDz Phishing-as-a-Service Platform
New revelations by Group-IB expose the full scale of the decade-old SniperDz phishing operation
Part of the PlainSec briefing for 2026-06-13