{"id":1880658,"date":"2026-04-13T21:21:21","date_gmt":"2026-04-13T18:21:21","guid":{"rendered":"https:\/\/analyse.optim.biz\/?p=1880658"},"modified":"2026-04-13T21:21:21","modified_gmt":"2026-04-13T18:21:21","slug":"the-feds-took-down-a-full-service-cybercrime-platform-behind-20m-in-phishing","status":"publish","type":"post","link":"https:\/\/analyse.optim.biz\/?p=1880658","title":{"rendered":"The Feds Took Down a &#8216;Full-Service Cybercrime Platform&#8217; Behind $20M in Phishing"},"content":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/www.cnet.com\/a\/img\/resize\/a3a7ab67f14322be73d9aa32bb17a0b47beb2a6f\/hub\/2026\/04\/13\/85966404-fbe4-4ad5-a5cb-4b3627f60d5a\/gettyimages-2269889340.jpg?auto=webp&amp;fit=crop&amp;height=675&amp;width=1200&#8243;]<\/p>\n<div id=\"article-dde9cbca-b1b7-43c4-aa6e-a148d57c7aac\" class=\"c-pageArticle_body sm:u-col-2 md:u-col-6 lg:u-col-6 lg:u-col-start-2\">\n<div class=\"c-pageArticle_content\">\n<div class=\"u-grid-columns\">\n<article class=\"c-ShortcodeContent c-ShortcodeContent-theme:default sm:u-col-2 md:u-col-6 lg:u-col-12\">\n<p class=\"u-speakableText-p1\">Cybercrime is a big business, driving <span><span>nearly $21 billion<\/span><\/span> in fraud and theft in 2026 alone. The FBI and the Indonesian National Police took a chunk out of that late last week when the pair took down infrastructure vital to the W3LL phishing kit, a piece of software that could steal someone&#8217;s account credentials and data to bypass multi-factor authentication.\u00a0<\/p>\n<p class=\"u-speakableText-p2\">The W3LL phishing kit was best known for targeting Microsoft 365 accounts, but a crook could purchase it for $500 online and target any number of services. They could then deploy a website that captures a user&#8217;s login information and session data, giving the criminal access to the account without going through multi-factor authentication.\u00a0<\/p>\n<p><strong>Read more:<\/strong> Best Password Manager in 2025<\/p>\n<p>The cybersecurity firm Group-IB, which\u00a0first documented the W3LL phishing kit in 2023, described it as an all-in-one phishing tool capable of making custom phishing tools, providing email lists, and granting access to compromised servers. Its developer also made a couple of bulk email spam tools called PunnySender and W3LL Sender before the W3LL phishing kit, and has been active in cybercrime since at least 2017.\u00a0<\/p>\n<p>&#8220;This wasn&#8217;t just phishing &#8212; it was a full-service cybercrime platform,&#8221; FBI Atlanta Special Agent in Charge Marlo Graham said in a press release.\u00a0<\/p>\n<div>\n<div>\n<div class=\"c-shortcodeVideoInline g-outer-spacing-bottom-large g-text-xxsmall c-shortcodeVideoInline_play\">\n<div class=\"c-shortcodeVideoInline_img\">\n<figure class=\"c-globalImage\">\n<div class=\"c-cmsImage c-globalImage_cmsImage\"><img src alt height=\"306\" width=\"768\" loading=\"lazy\"><\/div>\n<\/figure>\n<\/div>\n<div class=\"c-shortcodeVideoInline_txt g-text-xxsmall\"><strong>Watch this:<\/strong> Your Phone is Disgusting: Let&#8217;s Fix That\n      <\/div>\n<p><time class=\"c-shortcodeVideoInline_time\"><span class=\"g-text-xxxsmall\">05:07<\/span><\/time><\/div>\n<\/div>\n<\/div>\n<p>Representatives for the FBI and Group-IB did not immediately respond to requests for comment.<\/p>\n<p>According to the FBI, the kit was available in the W3LL marketplace from 2019 until the store closed in 2023. The developer, known publicly as G.L, continued selling the kit and compromised account details over encrypted messaging platforms. The FBI said authorities detained a suspect believed to be G.L.\u00a0<\/p>\n<p><strong>Read more:<\/strong><span><span>Anthropic Says Its New AI Model Is So Good at Finding Security Risks, You Can&#8217;t Use It<\/span><\/span><\/p>\n<p>The tool is responsible for quite a lot of damage. The FBI estimates that the W3LL store housed more than 25,000 compromised accounts up through 2023 and the tool was used to compromise an additional 17,000 accounts in 2023 and 2024. Criminals stole, or attempted to steal, roughly $20 million in total.\u00a0<\/p>\n<p>Cybercriminals who purchased the kit had access to customer service, including a ticketing system and web chat. Those who weren&#8217;t particularly tech savvy also had tutorial videos showing how to use the tool to craft fake websites and steal credentials. The tool was sold primarily by word of mouth, with a 10% commission for referrals and a third-party vendor program with a 70\/30 split on profits.\u00a0<\/p>\n<p>The FBI took down the main kit, but it may not be the end of the road for W3LL. Sekoia IO, a European cybersecurity company specializing in software-as-a-service, has identified similar tools, such as Sneaky 2FA, which uses some W3LL source code. Cracked versions of W3LL have also been circulating online for years.<\/p>\n<\/article>\n<\/div>\n<\/div>\n<div>\n<div data-cy=\"articleLinkBlock\" class=\"c-articleLinkBlock\">\n<div class=\"c-articleLinkBlock_blockWrapper\">\n<div class=\"c-bestListLinkBlock\">\n<h2 class=\"c-bestListLinkBlock_header\">\n    Services and Software Guides<br \/>\n  <\/h2>\n<div class=\"c-bestListLinkBlock_itemContainer\">\n<div class=\"c-bestListLinkBlockItem\">\n<div class=\"c-bestListLinkBlockItem_categoryContainer\"><span class=\"c-bestListLinkBlockItem_category\"><br \/>\n      VPN<br \/>\n    <\/span><\/div>\n<div class=\"c-bestListLinkBlockItem_listContainer\">\n<ul class=\"c-bestListLinkBlockItem_list\">\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best VPN\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best iPhone VPN\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Free VPN\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Android VPN\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Mac VPN\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Mobile VPN\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best VPN for Firestick\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best VPN for Windows\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Fastest VPN\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Cheap VPN\n        <\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"c-bestListLinkBlock_itemContainer\">\n<div class=\"c-bestListLinkBlockItem\">\n<div class=\"c-bestListLinkBlockItem_categoryContainer\"><span class=\"c-bestListLinkBlockItem_category\"><br \/>\n      Cybersecurity<br \/>\n    <\/span><\/div>\n<div class=\"c-bestListLinkBlockItem_listContainer\">\n<ul class=\"c-bestListLinkBlockItem_list\">\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Password Manager\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Antivirus\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Identity Theft Protection\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best LastPass Alternative\n        <\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"c-bestListLinkBlock_itemContainer\">\n<div class=\"c-bestListLinkBlockItem\">\n<div class=\"c-bestListLinkBlockItem_categoryContainer\"><span class=\"c-bestListLinkBlockItem_category\"><br \/>\n      Streaming Services<br \/>\n    <\/span><\/div>\n<div class=\"c-bestListLinkBlockItem_listContainer\">\n<ul class=\"c-bestListLinkBlockItem_list\">\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Live TV Streaming Service\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Streaming Service\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Free TV Streaming Service\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Music Streaming Services\n        <\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"c-bestListLinkBlock_itemContainer\">\n<div class=\"c-bestListLinkBlockItem\">\n<div class=\"c-bestListLinkBlockItem_categoryContainer\"><span class=\"c-bestListLinkBlockItem_category\"><br \/>\n      Web Hosting &amp; Websites<br \/>\n    <\/span><\/div>\n<div class=\"c-bestListLinkBlockItem_listContainer\">\n<ul class=\"c-bestListLinkBlockItem_list\">\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Web Hosting\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Minecraft Server Hosting\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Website Builder\n        <\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"c-bestListLinkBlock_itemContainer\">\n<div class=\"c-bestListLinkBlockItem\">\n<div class=\"c-bestListLinkBlockItem_categoryContainer\"><span class=\"c-bestListLinkBlockItem_category\"><br \/>\n      Other Services &amp; Software<br \/>\n    <\/span><\/div>\n<div class=\"c-bestListLinkBlockItem_listContainer\">\n<ul class=\"c-bestListLinkBlockItem_list\">\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Dating Sites\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Language Learning Apps\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Weather App\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Stargazing Apps\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Cloud Storage\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          Best Resume Writing Services\n        <\/li>\n<li class=\"g-text-xsmall g-outer-spacing-bottom-small\">\n          New Coverage on Operating Systems\n        <\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"c-pageArticle_content\">\n<div class=\"u-grid-columns\">\n<article class=\"c-ShortcodeContent c-ShortcodeContent-theme:default sm:u-col-2 md:u-col-6 lg:u-col-12\">\n<p class=\"u-speakableText-p1\">Cybercrime is a big business, driving <span><span>nearly $21 billion<\/span><\/span> in fraud and theft in 2026 alone. The FBI and the Indonesian National Police took a chunk out of that late last week when the pair took down infrastructure vital to the W3LL phishing kit, a piece of software that could steal someone&#8217;s account credentials and data to bypass multi-factor authentication.\u00a0<\/p>\n<p class=\"u-speakableText-p2\">The W3LL phishing kit was best known for targeting Microsoft 365 accounts, but a crook could purchase it for $500 online and target any number of services. They could then deploy a website that captures a user&#8217;s login information and session data, giving the criminal access to the account without going through multi-factor authentication.\u00a0<\/p>\n<p><strong>Read more:<\/strong> Best Password Manager in 2025<\/p>\n<p>The cybersecurity firm Group-IB, which\u00a0first documented the W3LL phishing kit in 2023, described it as an all-in-one phishing tool capable of making custom phishing tools, providing email lists, and granting access to compromised servers. Its developer also made a couple of bulk email spam tools called PunnySender and W3LL Sender before the W3LL phishing kit, and has been active in cybercrime since at least 2017.\u00a0<\/p>\n<p>&#8220;This wasn&#8217;t just phishing &#8212; it was a full-service cybercrime platform,&#8221; FBI Atlanta Special Agent in Charge Marlo Graham said in a press release.\u00a0<\/p>\n<div>\n<div>\n<div class=\"c-shortcodeVideoInline g-outer-spacing-bottom-large g-text-xxsmall c-shortcodeVideoInline_play\">\n<div class=\"c-shortcodeVideoInline_img\">\n<figure class=\"c-globalImage\">\n<div class=\"c-cmsImage c-globalImage_cmsImage\"><img src alt height=\"306\" width=\"768\" loading=\"lazy\"><\/div>\n<\/figure>\n<\/div>\n<div class=\"c-shortcodeVideoInline_txt g-text-xxsmall\"><strong>Watch this:<\/strong> Your Phone is Disgusting: Let&#8217;s Fix That\n      <\/div>\n<p><time class=\"c-shortcodeVideoInline_time\"><span class=\"g-text-xxxsmall\">05:07<\/span><\/time><\/div>\n<\/div>\n<\/div>\n<p>Representatives for the FBI and Group-IB did not immediately respond to requests for comment.<\/p>\n<p>According to the FBI, the kit was available in the W3LL marketplace from 2019 until the store closed in 2023. The developer, known publicly as G.L, continued selling the kit and compromised account details over encrypted messaging platforms. The FBI said authorities detained a suspect believed to be G.L.\u00a0<\/p>\n<p><strong>Read more:<\/strong><span><span>Anthropic Says Its New AI Model Is So Good at Finding Security Risks, You Can&#8217;t Use It<\/span><\/span><\/p>\n<p>The tool is responsible for quite a lot of damage. The FBI estimates that the W3LL store housed more than 25,000 compromised accounts up through 2023 and the tool was used to compromise an additional 17,000 accounts in 2023 and 2024. Criminals stole, or attempted to steal, roughly $20 million in total.\u00a0<\/p>\n<p>Cybercriminals who purchased the kit had access to customer service, including a ticketing system and web chat. Those who weren&#8217;t particularly tech savvy also had tutorial videos showing how to use the tool to craft fake websites and steal credentials. The tool was sold primarily by word of mouth, with a 10% commission for referrals and a third-party vendor program with a 70\/30 split on profits.\u00a0<\/p>\n<p>The FBI took down the main kit, but it may not be the end of the road for W3LL. Sekoia IO, a European cybersecurity company specializing in software-as-a-service, has identified similar tools, such as Sneaky 2FA, which uses some W3LL source code. Cracked versions of W3LL have also been circulating online for years.<\/p>\n<\/article>\n<\/div>\n<\/div>\n<article class=\"c-ShortcodeContent c-ShortcodeContent-theme:default sm:u-col-2 md:u-col-6 lg:u-col-12\">\n<p class=\"u-speakableText-p1\">Cybercrime is a big business, driving <span><span>nearly $21 billion<\/span><\/span> in fraud and theft in 2026 alone. The FBI and the Indonesian National Police took a chunk out of that late last week when the pair took down infrastructure vital to the W3LL phishing kit, a piece of software that could steal someone&#8217;s account credentials and data to bypass multi-factor authentication.\u00a0<\/p>\n<p class=\"u-speakableText-p2\">The W3LL phishing kit was best known for targeting Microsoft 365 accounts, but a crook could purchase it for $500 online and target any number of services. They could then deploy a website that captures a user&#8217;s login information and session data, giving the criminal access to the account without going through multi-factor authentication.\u00a0<\/p>\n<p><strong>Read more:<\/strong> Best Password Manager in 2025<\/p>\n<p>The cybersecurity firm Group-IB, which\u00a0first documented the W3LL phishing kit in 2023, described it as an all-in-one phishing tool capable of making custom phishing tools, providing email lists, and granting access to compromised servers. Its developer also made a couple of bulk email spam tools called PunnySender and W3LL Sender before the W3LL phishing kit, and has been active in cybercrime since at least 2017.\u00a0<\/p>\n<p>&#8220;This wasn&#8217;t just phishing &#8212; it was a full-service cybercrime platform,&#8221; FBI Atlanta Special Agent in Charge Marlo Graham said in a press release.\u00a0<\/p>\n<div>\n<div>\n<div class=\"c-shortcodeVideoInline g-outer-spacing-bottom-large g-text-xxsmall c-shortcodeVideoInline_play\">\n<div class=\"c-shortcodeVideoInline_img\">\n<figure class=\"c-globalImage\">\n<div class=\"c-cmsImage c-globalImage_cmsImage\"><img src alt height=\"306\" width=\"768\" loading=\"lazy\"><\/div>\n<\/figure>\n<\/div>\n<div class=\"c-shortcodeVideoInline_txt g-text-xxsmall\"><strong>Watch this:<\/strong> Your Phone is Disgusting: Let&#8217;s Fix That\n      <\/div>\n<p><time class=\"c-shortcodeVideoInline_time\"><span class=\"g-text-xxxsmall\">05:07<\/span><\/time><\/div>\n<\/div>\n<\/div>\n<p>Representatives for the FBI and Group-IB did not immediately respond to requests for comment.<\/p>\n<p>According to the FBI, the kit was available in the W3LL marketplace from 2019 until the store closed in 2023. The developer, known publicly as G.L, continued selling the kit and compromised account details over encrypted messaging platforms. The FBI said authorities detained a suspect believed to be G.L.\u00a0<\/p>\n<p><strong>Read more:<\/strong><span><span>Anthropic Says Its New AI Model Is So Good at Finding Security Risks, You Can&#8217;t Use It<\/span><\/span><\/p>\n<p>The tool is responsible for quite a lot of damage. The FBI estimates that the W3LL store housed more than 25,000 compromised accounts up through 2023 and the tool was used to compromise an additional 17,000 accounts in 2023 and 2024. Criminals stole, or attempted to steal, roughly $20 million in total.\u00a0<\/p>\n<p>Cybercriminals who purchased the kit had access to customer service, including a ticketing system and web chat. Those who weren&#8217;t particularly tech savvy also had tutorial videos showing how to use the tool to craft fake websites and steal credentials. The tool was sold primarily by word of mouth, with a 10% commission for referrals and a third-party vendor program with a 70\/30 split on profits.\u00a0<\/p>\n<p>The FBI took down the main kit, but it may not be the end of the road for W3LL. Sekoia IO, a European cybersecurity company specializing in software-as-a-service, has identified similar tools, such as Sneaky 2FA, which uses some W3LL source code. Cracked versions of W3LL have also been circulating online for years.<\/p>\n<\/article>\n<p>[analyse_source url=&#8221;http:\/\/cnet.com\/tech\/services-and-software\/fbi-w3ll-phishing-platform\/&#8221;]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/www.cnet.com\/a\/img\/resize\/a3a7ab67f14322be73d9aa32bb17a0b47beb2a6f\/hub\/2026\/04\/13\/85966404-fbe4-4ad5-a5cb-4b3627f60d5a\/gettyimages-2269889340.jpg?auto=webp&amp;fit=crop&amp;height=675&amp;width=1200&#8243;] Cybercrime is a big business, driving nearly $21 billion in fraud and theft in 2026 alone. The FBI and the Indonesian National Police took a chunk out of that late last week when the pair took down infrastructure vital to the W3LL phishing kit, a piece of software that could steal someone&#8217;s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[67,226],"class_list":["post-1880658","post","type-post","status-publish","format-standard","hentry","category-politics","tag-cnet-com","tag-crawlmanager"],"_links":{"self":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/1880658","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1880658"}],"version-history":[{"count":0,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/1880658\/revisions"}],"wp:attachment":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1880658"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1880658"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1880658"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}