Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

INTERPOL’s Operation Synergia, a cybercrime operation conducted from September to November 2023, resulted in 31 people being detained or apprehended and 70 additional suspects being identified. Group-IB separately reported identifying more than 1,900 IP addresses associated with ransomware, Trojans and banking malware—not ransomware alone.

What was Operation Synergia?

Operation Synergia was an INTERPOL-led effort targeting infrastructure used for phishing, malware and ransomware. INTERPOL’s operation summary says 60 law-enforcement agencies from more than 50 member countries took part. The operation ran from September through November 2023; its results were reported in 2024.

The operation paired cross-border police work with technical analysis from private-sector participants. Law-enforcement agencies carried out investigative and enforcement actions, while Group-IB’s Threat Intelligence and High-Tech Crime Investigation teams contributed intelligence and technical analysis.

What do the operation’s figures mean?

Measure Reported result Reporting frame
People detained or apprehended 31 INTERPOL and Group-IB reporting on the operation, 2023–2024
Additional suspects identified 70 INTERPOL and Group-IB reporting on the operation, 2023–2024
Suspicious IP addresses or URLs About 1,300 INTERPOL’s 2024 assessment
IP addresses associated with malware operations More than 1,900 Group-IB’s 2024 account; categories included ransomware, Trojans and banking malware
Identified command-and-control servers taken down About 70% INTERPOL’s operation reporting; remaining servers were under investigation at the time

Why are there two different IP-address totals?

INTERPOL’s assessment cited about 1,300 suspicious IP addresses or URLs overall. Group-IB reported a separate total of more than 1,900 IP addresses associated with ransomware, Trojans and banking-malware operations. The figures use different reporting frames, so they should not be added or treated as competing counts of the same list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The phrase “ransomware-linked IPs” is shorthand: Group-IB’s figure covers several malware categories. It does not establish that all those addresses belonged to ransomware operators, or that each address was taken offline.

Were all the identified IP addresses taken offline?

No. Identification and takedown are different outcomes. INTERPOL reported that about 70% of identified command-and-control servers were taken down; the rest were still under investigation when the results were reported. That percentage refers to command-and-control servers, not necessarily to every IP address in Group-IB’s larger figure.

An IP address is an infrastructure indicator that can help investigators trace or disrupt malicious activity. Identifying an address alone does not prove who controlled it: linking infrastructure to a person or group requires corroborating investigative evidence.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does the operation show about international cybercrime enforcement?

Synergia brought together agencies across more than 50 member countries and included a private cybersecurity company’s technical contribution. That arrangement can help investigators compare intelligence across jurisdictions and identify infrastructure that may be used in multiple countries. The published figures describe arrests or apprehensions, suspects identified and infrastructure disruption; they do not, by themselves, establish the operation’s effect on cybercrime overall or quantify financial losses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For organizations, the practical lesson is that a takedown does not replace defensive controls. Maintain timely software updates, use multifactor authentication where available, and have a response plan for suspected phishing or malware incidents. These steps reduce exposure but cannot guarantee protection.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.