Threats · 154 days ago
The FBI and Indonesian police disrupted the W3LL phishing ecosystem by seizing key domains and detaining the alleged developer, halting a commercial platform that bundled phishing kits, MFA bypass tools, session-token theft, and credential resale. This takedown removes the marketplace infrastructure but does not eliminate the underlying risk from already stolen credentials and access tokens that remain in circulation.
W3LL operated as a full-service cybercrime platform since at least 2017, servicing about 500 threat actors and facilitating over 25,000 compromised accounts and $20 million in attempted fraud. The phishing kit was sold for $500 and enabled attackers to mimic legitimate login portals, capturing passwords and MFA codes. Even after the marketplace shut down in 2023, the ecosystem persisted through encrypted messaging platforms, showing resilience beyond domain seizures.
The disruption lowers the immediate supply of phishing tools and stolen credentials but does not erase the ongoing risk of account takeover and business email compromise from previously harvested data. Organizations affected before the takedown remain vulnerable, as the resale and reuse of stolen credentials can continue independently of the original platform.
6 sources covering this story
W3LL phishing service sold for $500 dismantled by the FBI - Help Net Security
FBI and Indonesian police carry out takedown of the W3LL phishing kit, arresting the developer and disrupting a global fraud operation.
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
FBI dismantles W3LL phishing network targeting 17,000 victims; crackdown disrupts $20M fraud scheme.
FBI announces takedown of phishing operation that targeted thousands of victims | TechCrunch
Cybercriminals allegedly used the W3LL phishing kit to target more than 17,000 victims worldwide, stealing their passwords and multi-factor authentication codes.
The Record from Recorded Future
FBI, Indonesia take down W3LL phishing tool
A widely used phishing tool that allowed hackers to create fake websites that looked like legitimate login portals for just $500 was disrupted by the FBI and law enforcement agencies in Indonesia.
FBI takedown of W3LL phishing service leads to developer arrest
The FBI Atlanta Field Office and Indonesian authorities have dismantled the "W3LL" global phishing platform, seizing infrastructure and arresting the alleged developer in what is described as the first coordinated enforcement action between the United States and Indonesia targeting a phishing kit developer.
FBI Dismantles $20m Phishing Operation W3LL
The W3LL phishing kit has been associated with fraud attempts totaling $20m
Part of the PlainSec briefing for 2026-04-14