Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»FBI takedown of W3LL phishing service leads to developer arrest
    Cybersecurity

    FBI takedown of W3LL phishing service leads to developer arrest

    adminBy adminApril 14, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Phishing hook

    The FBI Atlanta Field Office and Indonesian authorities have dismantled the “W3LL” global phishing platform, seizing infrastructure and arresting the alleged developer in what is described as the first coordinated enforcement action between the United States and Indonesia targeting a phishing kit developer.

    The W3ll Store was a phishing kit and online marketplace that enabled cybercriminals to steal thousands of credentials and attempt more than $20 million in fraud. 

    “This Website Has Been Seized as part of a coordinated law enforcement action taken against W3LL STORE,” reads a seizure message on w3ll[.]store website.

    Wiz

    “The domain for w3ll.store has been seized by the Federal Bureau of Investigation in accordance with a seizure warrant issued pursuant to 18 U.S.C. §§ 981 and 982 by the United States District Court for the Northern District of Georgia as part of a joint law enforcement action by the Federal Bureau of Investigation.”

    Seizure banner shown on the W3LL Store site
    Seizure banner shown on the W3LL Store site
    Source: BleepingComputer

    The W3LL phishing kit sold for $500 and allowed attackers to create convincing replicas of corporate login portals to harvest credentials.  The kit allowed threat actors to capture authentication session tokens, enabling attackers to bypass multi-factor authentication and gain access to compromised accounts.

    W3LL Store and W3LL Panel administration
    W3LL Store and W3LL Panel administration
    Source: Group-IB

    The threat actor also offered a marketplace called W3LLSTORE, where stolen credentials and unauthorized network access were bought and sold. 

    “This wasn’t just phishing—it was a full-service cybercrime platform,” said FBI Special Agent Charge Marlo Graham. 

    Authorities say the marketplace facilitated the sale of more than 25,000 compromised accounts between 2019 and 2023, and even after W3LLSTORE shut down, the operation continued through encrypted messaging platforms, where the toolkit was rebranded and sold to other threat actors.

    Between 2023 and 2024, the phishing kit was used to target more than 17,000 victims worldwide, with investigators finding that the developer collected and resold access to compromised accounts. 

    The W3LL phishing platform was previously linked to campaigns targeting Microsoft 365 corporate accounts and was designed to support business email compromise (BEC) attacks from initial access through post-exploitation.

    The phishing kit relied on adversary-in-the-middle attacks, which is when legitimate login portals are proxied through an attacker’s infrastructure.

    This allows the threat actors to monitor for and intercept credentials, one-time MFA passcodes, and session cookies in real time. These session cookies could then be used to log into the compromised accounts without triggering MFA authentication challenges.

    Once access was obtained, attackers would monitor inboxes, create email rules, and impersonate victims to commit invoice fraud and redirect payments in BEC attacks.


    tines

    Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

    This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.

    arrest developer FBI Leads Phishing service Takedown W3LL
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleOura takes ring data into the doctor’s office with its latest partnership
    Next Article Google Messages may soon gain long-overdue chat customization tools
    admin
    • Website

    Related Posts

    How I Use a WordPress Quiz to Automatically Qualify Leads

    May 25, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Commerce media expands beyond retail sites with Demand Gen integration

    June 2, 2026

    The 50 Most-Cited Websites in Perplexity (June 2026)

    June 2, 2026

    FTC broadens Microsoft probe to cloud, AI, and software bundling

    June 2, 2026

    Google expands Data Manager API with GMP event ingestion

    June 2, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,335)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (323)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Commerce media expands beyond retail sites with Demand Gen integration

    June 2, 2026

    The 50 Most-Cited Websites in Perplexity (June 2026)

    June 2, 2026

    FTC broadens Microsoft probe to cloud, AI, and software bundling

    June 2, 2026
    Most Popular
    • Commerce media expands beyond retail sites with Demand Gen integration
    • The 50 Most-Cited Websites in Perplexity (June 2026)
    • FTC broadens Microsoft probe to cloud, AI, and software bundling
    • Google expands Data Manager API with GMP event ingestion
    • The 50 Most-Cited Websites in Copilot (June 2026)
    • What Google’s New AI Guide Actually Debunks. And What It Doesn’t
    • Broadcom, Samsung team for wireless SoC
    • What it means for your marketing strategy in 2026
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.