The raid that exposed the scale of the problem
On April 29, 2026, Dubai Police officers moved on nine properties across the emirate, arresting 275 people in a single coordinated sweep. The U.S. Department of Justice, which unsealed related charges in San Diego the same day, called it a joint operation with the FBI and China's Ministry of Public Security, describing "unprecedented cooperation" among the three agencies. A Thai police unit made one additional arrest.
The suspects, prosecutors allege, ran three front "companies" β Ko Thet Company, Sanduo Group and Giant Company β that operated scam centers built around a fraud scheme known as pig-butchering. Scammers cultivate fake friendships or romances with victims over weeks or months, then steer them into fraudulent cryptocurrency investment platforms and drain their accounts. Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division said the case reflected "an international consensus that scam centers are unwelcome everywhere and must be rooted out."
Four defendants β from Myanmar and Indonesia, ages 23 to 29 β face wire fraud and money laundering conspiracy charges carrying up to 20 years in prison. Two remain fugitives. FBI San Diego opened the investigation in 2025 after agents identified a cluster of scam compounds through complaints filed with the bureau's Internet Crime Complaint Center, then traced the financial and cryptocurrency trail back to Dubai.
The raid was not an isolated action. It landed in the middle of the busiest 12 months of cybercrime enforcement the Gulf region has seen, and it illustrates a dynamic regulators, police and cybersecurity researchers now describe consistently: the Gulf is simultaneously a magnet for cyber fraud targeting its own residents and, increasingly, a node in the infrastructure criminal networks use to defraud victims elsewhere.
The main report: a region under sustained digital assault
The numbers describing the threat are large and, by several measures, worsening. The UAE Cyber Security Council has told regional media that the country is absorbing roughly 600,000 cyberattacks or probing attempts a day, up from around 200,000 before hostilities between the United States, Israel and Iran escalated in February 2026 β a shift the council links to the wider regional conflict spilling into cyberspace. The council has also reported a 32% rise in cyber incidents in 2026.
The financial toll is well above the global average. Cybersecurity incidents in the Middle East cost businesses $8.05 million per breach on average, according to the World Economic Forum's review of regional resilience efforts β nearly double the $4.45 million global figure. Distributed denial-of-service attacks account for the majority of recorded incidents in the Gulf, and dark web forums show the UAE and Saudi Arabia are the two most discussed regional targets among threat actors, according to threat-intelligence data cited by insurance-sector analysts.
Ordinary consumers, not just corporations, are absorbing losses. A 2025 survey by the Global Anti-Scam Alliance covering roughly 3,000 respondents in the Middle East found that half had encountered a scam in the past year and about a quarter had lost money to one β slightly above the global average. Saudi victims lost an average of $2,511 each, one of the higher per-victim figures recorded in the 42-country survey, according to regional business publication AGBI's review of the data.
Cryptocurrency fraud has become the dominant strain of loss. The 2026 Chainalysis Crypto Crime Report puts global losses tied to pig-butchering-style scams at roughly $17 billion, with artificial intelligence tools now used to generate more convincing, personalized approaches to victims β a trend the report's authors say has made these scams several times more profitable than earlier fraud models. The FBI separately reported that crypto fraud losses reached $11.3 billion in the United States alone last year, more than half of all internet crime losses the bureau tracked.
Legal background: how the Gulf regulates and prosecutes cybercrime
The UAE's principal cybercrime statute, Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes, took effect in January 2022, replacing an earlier 2012 law. It is broad by design, covering hacking, unauthorized data access, online fraud, defamation and the promotion of unlicensed financial products.
Article 48 specifically targets cryptocurrency promotion, criminalizing false advertising or encouragement of investment in virtual assets not recognized by UAE authorities. The UAE Public Prosecution has publicly warned residents that violations can carry imprisonment of up to five years alongside fines of up to AED 500,000. Separately, unauthorized access to government systems that causes damage or disruption can draw prison terms of five years or more and fines reaching AED 1.5 million; where national security is implicated, sentences can extend to 15 years. The law applies extraterritorially β a provision that lets UAE prosecutors pursue cases where a UAE-based party was harmed even if the offense originated abroad. A breakdown of penalties across the UAE's criminal code shows cybercrime offenses now carry some of the harshest sentencing ranges in the federal system, alongside financial crimes and offenses against the state.
That legal architecture sits alongside a financial-crime framework administered by the Central Bank of the UAE, the Securities and Commodities Authority and Dubai's Virtual Assets Regulatory Authority, which licenses and supervises virtual asset service providers. Regional governments have also moved to plug gaps in cross-border cooperation. Saudi Arabia joined the United Nations Convention against Cybercrime in October 2025, alongside Turkey, Algeria and other states, a step that formalizes data-sharing and joint investigative mechanisms among signatories.
Enforcement capacity has scaled alongside the legislation. Dubai Police's role in the April 2026 takedown β arresting 275 people in a single operation and disrupting scam infrastructure through what the Justice Department called a "parallel investigation" β reflects an operational maturity regional forces did not display a decade ago, when most Gulf cybercrime cases were prosecuted individually and rarely involved coordinated multinational raids.
Timeline of events
- October 2025: Saudi Arabia and other states join the U.N. Convention against Cybercrime, expanding formal cross-border cooperation mechanisms.
- October 2025βFebruary 2026: INTERPOL runs Operation Ramz, its first large-scale coordinated cybercrime enforcement campaign in the Middle East and North Africa, involving 13 countries including the UAE, Saudi Arabia, Bahrain, Oman and Qatar.
- February 2026: Conflict between the United States, Israel and Iran escalates; the UAE Cyber Security Council reports cyberattack volumes against the UAE roughly tripling.
- April 29, 2026: Dubai Police, the FBI and China's Ministry of Public Security announce the coordinated takedown of nine pig-butchering scam centers, resulting in 276 arrests and unsealed federal charges in San Diego.
- May 18, 2026: INTERPOL publicly announces the results of Operation Ramz: 201 arrests, 382 additional suspects identified, 3,867 victims identified and 53 servers seized.
Expert analysis
INTERPOL's director of cybercrime, Neal Jetton, framed Operation Ramz as evidence that fragmented national responses are giving way to shared infrastructure. "Operation Ramz demonstrates the effectiveness of global collaboration," he said in a statement announcing the operation's results, adding that cybercriminals "exploit the digital landscape without borders."
Cybersecurity researchers who supported that operation β including Group-IB, Kaspersky, the Shadowserver Foundation and Team Cymru β contributed threat intelligence used to locate malicious infrastructure, according to INTERPOL and reporting on the operation. Team Cymru told the cybersecurity outlet The Record that it had identified several malicious servers underpinning phishing, malware and large-scale scam operations targeting the region.
U.S. officials involved in the Dubai case were similarly direct about the shift in tactics required to disrupt these networks. FBI Assistant Director Heith Janke said the bureau could not act alone and credited coordination with "our partners to hold accountable those who work to enable and facilitate these scams." U.S. Attorney Adam Gordon for the Southern District of California put it more bluntly, telling reporters the operation showed that alleged scammers "thought they were safe half a world away" but now face "global justice."
Not every regional cybersecurity assessment paints an equally alarming picture. Bahrain's national digital economy strategy, running through 2026, has focused on workforce development rather than crisis response, aiming to train 20,000 citizens in cybersecurity skills through partnerships with the SANS Institute and local labor authorities β an approach that treats the threat as a long-term capacity problem rather than an emergency.
Practical implications
For businesses operating in the Gulf, the legal exposure runs in two directions. Companies can be victims of fraud and ransomware, absorbing the region's above-average breach costs, but they also face steep compliance obligations under laws like the UAE's Article 48, which criminalizes promoting unlicensed virtual asset schemes β a provision that has already been used to prosecute individuals for advertising unregistered crypto products. Corporate intermediaries that fail exit-protocol and data-security obligations after employee departures face separate criminal exposure under the same decree-law, according to legal analysts who track UAE compliance practice.
For individual residents and investors, the practical risk is concentrated in cryptocurrency investment platforms and romance-based social engineering. Regulators including the Central Bank of the UAE and Dubai's Virtual Assets Regulatory Authority have stepped up anti-fraud standards, but researchers note licensing gaps remain a target for scammers. Residents who suspect they have been targeted have formal channels available: UAE authorities operate a dedicated portal and mobile app for victims, and a step-by-step guide to reporting cybercrime in the UAE outlines how complaints move from initial filing to police investigation. Fraud that results in compromised personal data can also escalate into identity theft, a related risk explained in a separate legal guide to identity theft in the UAE, which notes that phishing and malware remain the most common entry points for stolen credentials.
For governments, the events of the past year suggest that unilateral enforcement is no longer sufficient. Operation Ramz's reliance on 13-country coordination, and the Dubai-FBI-China cooperation on the April 2026 takedown, both point to cross-border investigative partnerships as the emerging enforcement model β one that depends on intelligence-sharing agreements, extradition cooperation and private-sector data from companies like Meta, which the Justice Department credited with providing "critical information" in the San Diego case.
What's next
Federal prosecutors in San Diego are pursuing the four defendants charged in the April 2026 case, two of whom remain fugitives. The FBI's Operation Level Up, a separate initiative that has notified nearly 9,000 potential victims and prevented an estimated $562 million in losses since 2024, continues to run in parallel, according to the Justice Department. FBI San Diego has also disclosed an active investigation into a separate network of scam compounds in Myanmar's Karen State, suggesting the region's exposure to organized fraud networks based in Southeast Asia is unlikely to diminish soon.
Regionally, INTERPOL and its MENA partners have not announced a successor to Operation Ramz, but the operation's scale β the largest coordinated cybercrime enforcement effort in the region's history, according to INTERPOL β sets a template regional police forces are likely to repeat. Whether Gulf governments can convert enforcement wins into a durable reduction in victim losses, rather than a temporary disruption of a highly adaptable criminal economy, remains the open question for regulators, insurers and the public heading into next year.
Sources and references
- U.S. Department of Justice, Office of Public Affairs, press release: Coordinated Takedown of Scam Centers Leads to at Least 276 Arrests, April 29, 2026
- INTERPOL: 201 arrests in first-of-its-kind cybercrime operation in MENA region
- Internal Revenue Service, Criminal Investigation: Coordinated takedown of scam centers
- FBI: Operation Level Up victim resources
- World Economic Forum: "How the GCC is strengthening its cybersecurity resilience", April 2025
- AGBI: "Gulf governments step up efforts to fight cybercrime", November 2025
- Lexology: "What 2025 has taught us about cyber risks in the Gulf region", December 2025
- The Record from Recorded Future News: "More than 200 arrested in cyber raids aimed at Middle East scam networks", May 2026
- Dark Reading: "Interpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle East", May 2026
- Finance Magnates: "Dubai Police, US and China Avert $562M in Crypto Scam Losses, Unravel 'Pig Butchering' Network", April 2026
- Cybernews: "FBI, Dubai police bust 9 crypto scam centers, 276 arrested", April 2026
- The National: "Prosecutors issue new warning over cryptocurrency scams", June 2022
- Wirestork: "How To Report Cybercrime In UAE?"
- Wirestork: "Criminal Case Punishments in UAE & Dubai Jail Terms: The Complete Guide"
- Wirestork: "Is Identity Theft the Hidden Cause of Your UAE Visa Rejection?"
This article is intended as independent journalism. It does not constitute legal advice.