惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
B
Blog
P
Proofpoint News Feed
美团技术团队
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
A
About on SuperTechFans
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
有赞技术团队
有赞技术团队
小众软件
小众软件
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
H
Help Net Security
罗磊的独立博客
L
LangChain Blog
GbyAI
GbyAI
腾讯CDC
T
The Blog of Author Tim Ferriss
Microsoft Security Blog
Microsoft Security Blog

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
US, Indonesia shut down ‘sophisticated’ phishing kit
2026-04-13 · via Cybersecurity Dive - Latest News

An article from site logo

For a nominal fee, cybercriminals could rent access to a service that maliciously duplicated popular websites’ login portals.

Published April 13, 2026

Illustrated man with fishing hook stealing key

Getty Images

The FBI partnered with Indonesian law enforcement to take down what the bureau on Friday called “a sophisticated global phishing operation.”

U.S. authorities seized computer infrastructure powering the W3LL phishing kit, the FBI said in a statement, while the Indonesian National Police arrested the kit’s alleged developer, an individual whom the FBI identified only as G.L.

W3LL was a popular cybercrime tool that, for roughly $500 per session, made it easy for hackers to quickly create login portals that mimicked the websites of popular online services. The tool then captured not only login credentials, but also “session data that allowed criminals to bypass multi-factor authentication and maintain access to accounts,” the FBI said.

Hackers used the access that W3LL gave them to attempt more than $20 million in fraud, according to the bureau.

In addition to directly committing fraud, W3LL users also resold stolen credentials and other forms of access — including remote desktop connections — on a marketplace called W3LLSTORE that operated between 2019 and 2023.

“This wasn’t just phishing,” FBI Atlanta Special Agent in Charge Marlo Graham said in a statement. “It was a full-service cybercrime platform.”

After W3LLSTORE disappeared, criminals kept the W3LL service alive through encrypted chat platforms. Cybercriminals used the tool in attacks on more than 17,000 victims worldwide between 2023 and 2024.

Pattern of takedowns

The W3LL takedown was the first time that American and Indonesian law enforcement authorities had cooperated to dismantle a hacking platform. But it was far from the first time that the U.S. has seized infrastructure used for malicious cyber activity.

In the past two months alone, U.S. authorities have partially neutralized the Russian government’s global network of hacked routers, taken over Iran-linked hackers’ web domains, seized servers that powered massive distributed denial-of-service attacks and commandeered domain names used for residential proxy networks. Several of those operations involved international partnerships, a strategy that FBI leaders have said they plan to emphasize in the coming years.