logo

FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts

ID: cf5e7e53-8912-532e-9bb6-0c7ff33d3653

STIX ID: report--cf5e7e53-8912-532e-9bb6-0c7ff33d3653

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The FBI, in coordination with the Indonesian National Police, dismantled the infrastructure behind the W3LL phishing kit and detained the alleged developer (identified as G.L.). W3LL enabled adversary-in-the-middle phishing that harvested credentials and hijacked session cookies to bypass multi-factor authentication—primarily targeting Microsoft 365—was marketed via an underground storefront to hundreds of threat actors, sold more than 25,000 compromised accounts between 2019–2023, and was linked to over $20 million in attempted fraud and thousands of victims worldwide.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.