Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FBI and Indonesian Police Disrupt W3LL Phishing Scheme

FBI and Indonesian Police Disrupt W3LL Phishing Scheme

Posted on April 13, 2026 By CWS

The U.S. Federal Bureau of Investigation (FBI), collaborating with the Indonesian National Police, has successfully dismantled the global phishing network known as W3LL. This operation targeted a sophisticated phishing toolkit responsible for attempting to defraud victims of over $20 million by stealing account credentials.

Phishing Network Disrupted

Authorities have apprehended the suspected developer, identified as G.L, and confiscated crucial domains connected to the phishing activities. This takedown is a significant step in disrupting a major cybercriminal resource that facilitated unauthorized access to numerous accounts. According to an FBI statement, the eradication of this network is crucial to safeguarding the public from cyber threats.

Operation of the W3LL Kit

The W3LL phishing toolkit was designed to create fake websites resembling legitimate login portals, tricking users into revealing their credentials. Priced at approximately $500, this kit allowed cybercriminals to deploy fraudulent sites effectively. FBI Atlanta Special Agent Marlo Graham emphasized the comprehensive nature of this cybercrime platform, underscoring the continuous efforts to protect users globally.

Initially documented by cybersecurity firm Group-IB in September 2023, W3LL was identified as part of an underground marketplace named the W3LL Store. This platform catered to around 500 threat actors, offering them access to various cybercrime tools, including the W3LL Panel phishing kit, primarily targeting business email compromise (BEC) attacks.

Long-term Cybercrime Threat

W3LL offered a suite of services, from custom phishing tools to compromised server access, and is believed to have been operational since 2017. The W3LL Store also served as a marketplace for stolen credentials and unauthorized system access, peddling over 25,000 compromised accounts from 2019 to 2023. The FBI highlighted the kit’s focus on Microsoft 365 credentials, utilizing adversary-in-the-middle techniques to bypass security measures like multi-factor authentication.

Despite the discontinuation of the W3LL Store in 2023, the operation persisted through encrypted messaging platforms. The phishing kit was rebranded and actively marketed, continuing to target thousands of victims worldwide into 2024. The developer’s role in reselling access to compromised accounts significantly broadened the scheme’s reach and impact.

With the takedown of the W3LL network, authorities aim to curtail the spread of such sophisticated cybercrime operations and continue to work with international partners to protect individuals and organizations from future threats.

The Hacker News Tags:business email compromise, Cybercrime, Cybersecurity, FBI, Fraud, Indonesian Police, multi-factor authentication, Phishing, threat intelligence, W3LL

Post navigation

Previous Post: Mozilla Critiques Microsoft’s Copilot Installation Tactics
Next Post: LinkedIn Under Scrutiny: Allegations of Privacy Invasion

Related Posts

Winning Against AI-Based Attacks Requires a Combined Defensive Approach Winning Against AI-Based Attacks Requires a Combined Defensive Approach The Hacker News
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers The Hacker News
Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362 Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362 The Hacker News
Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android The Hacker News
North Korea-Linked Hackers Steal .02 Billion in 2025, Leading Global Crypto Theft North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft The Hacker News
Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Attacks Exploit GitHub and Jira Notifications
  • Nginx 1.29.8 & FreeNginx Update Bolster Security
  • Maximize SOC ROI with Advanced Threat Intelligence
  • LinkedIn Under Scrutiny: Allegations of Privacy Invasion
  • FBI and Indonesian Police Disrupt W3LL Phishing Scheme

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Attacks Exploit GitHub and Jira Notifications
  • Nginx 1.29.8 & FreeNginx Update Bolster Security
  • Maximize SOC ROI with Advanced Threat Intelligence
  • LinkedIn Under Scrutiny: Allegations of Privacy Invasion
  • FBI and Indonesian Police Disrupt W3LL Phishing Scheme

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark