Policy & Regulation
FBI says it dismantled global phishing operation W3LL
The FBI said it dismantled the W3LL phishing operation, which allegedly helped hackers target more than 17,000 victims worldwide.
The FBI announced on Monday that it “dismantled” a global phishing operation that allegedly helped hackers target more than 17,000 victims worldwide. The website of the operation, known as W3LL, now displays a notice saying it has been seized by the FBI.
The bureau said it worked with Indonesia’s police in the takedown, which led to the detention of the alleged W3LL developer, identified only by the initials G.L., and the seizure of what the FBI called “key domains.”
Cybercriminals could buy the W3LL phishing kit for $500 to deploy fake versions of websites that mimicked the login pages of legitimate services, letting the criminals steal passwords and multi-factor authentication codes from victims. The FBI said the kit enabled cybercriminals to “attempt more than $20 million in fraud.”
The W3LL online marketplace also allegedly let criminals buy and sell stolen credentials and access to hacked systems, which the FBI said “facilitated the sale of more than 25,000 compromised accounts.” The FBI did not immediately respond to a request for comment asking for more information.
Why it matters
The takedown shows international law enforcement increasingly coordinating across borders to dismantle phishing-as-a-service operations that lower the technical bar for large-scale credential theft.