logo

Authorities Dismantle ‘W3LL’ Phishing Empire Powering Global Business Email Attacks

ID: 1dc56359-7980-5ca5-8a49-0e1d12b046e4

STIX ID: report--1dc56359-7980-5ca5-8a49-0e1d12b046e4

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-04-13

Date Updated: 2026-05-11

Author: Mihir Bagwe

...
...

An international operation led by the FBI Atlanta Field Office and Indonesian law enforcement disrupted the W3LL phishing-as-a-service ecosystem, which facilitated credential harvesting and sale (over 25,000 compromised accounts traded), enabled more than $20 million in attempted fraud, targeted corporate email systems (notably Microsoft 365), used adversary-in-the-middle techniques to bypass MFA, and involved roughly 500 threat actors; domains and infrastructure were seized and a suspected developer was detained.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.