In a first-of-its-kind joint cyber investigation, the FBI Atlanta Field Office and Indonesian law enforcement authorities have dismantled a sophisticated global phishing operation that enabled cybercriminals to steal thousands of victims’ account credentials and attempt more than $20 million in fraud.
The operation centered on the W3LL phishing kit, a widely used cybercrime tool that allowed criminals to impersonate legitimate login pages to trick victims into handing over their usernames and passwords. For a fee of about $500, users could purchase access to the phishing kit and deploy fake websites designed to look nearly identical to trusted login portals.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Operation HAECHI IV: USD 300 million seized and 3,500 suspects arrested in international financial crime operation
December 19, 2023
LYON, FRANCE – A transcontinental police operation against online financial crime has concluded with almost 3,500 arrests and seizures of USD 300 million (approx. EUR 273 million) worth of assets across 34 countries. The six-month Operation HAECHI IV (July-December 2023) targeted seven types of cyber-enabled scams: voice phishing, romance scams, online sextortion, investment fraud, money laundering ...
- Europol publishes IOCTA spotlight report on online fraud schemes
December 19, 2023
Europol’s spotlight report on online fraud highlights that online fraud schemes represent a major crime threat in the EU and beyond as online fraudsters generate multiple billions in illicit profits every year to the detriment of individuals, companies and public institutions. Fraud schemes are perpetrated with the intention of defrauding victims of their assets using false ...
- ALPHV ransomware gang returns, sorta
December 14, 2023
The ALPHV ransomware gang, arguably the second most dangerous “big game” ransomware operator, appears to be back in business after its infrastructure went down for five days. But all does not appear to be going well for group. ALPHV’s dark web leak site may be back but it is only showing a single victim with no ...
- Apple will require court order to give push notification data to law enforcement
December 13, 2023
Apple will now require a court order or search warrant to give push notification data to law enforcement in a shift from the previous practice of accepting a subpoena to hand over data. In Apple’s guidelines, which are made publicly available online, the company said the Apple ID, which is a user’s Apple account, and the ...
- PSNI data breach ‘wake-up call’ for UK forces, review says
December 11, 2023
A major data breach within the Police Service of Northern Ireland (PSNI) has been described as “a wake-up call” for forces across the UK. A report into the data leak has made 37 recommendations for improving information security within the PSNI. In August, the surnames and initials of all the PSNI’s 9,500 staff were released by ...
- No confirmation on rumored ALPHV/BlackCat site takedown by law enforcement
December 11, 2023
As the week started there was still no official confirmation from law enforcement that the notorious ALPV/BlackCat site had been taken down. Late last week, various research groups and news organizations reported, and RedSense on Dec. 8 confirmed, that law enforcement took down the ransomware group’s site, but short of official confirmation from the FBI or ...
