CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Disruption of W3LL phishing ecosystem linked to $20 million in fraud

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A coordinated takedown by US and Indonesian law enforcement dismantled the W3LL phishing operation, which facilitated large-scale Business Email Compromise (BEC) fraud amounting to approximately $20 million. The operation centered on the W3LL phishing kit, a modular toolset sold via the members-only W3LL Store from 2019 to 2023 for $500, enabling threat actors to craft convincing login-page impersonations for credential harvesting. Post-marketplace closure in 2023, the ecosystem persisted through encrypted messaging channels, targeting over 17,000 victims globally between 2023 and 2025.

Timeline

  1. 13.04.2026 13:35 1 articles · 3h ago

    W3LL phishing operation disrupted after global law enforcement takedown

    US and Indonesian authorities dismantled the W3LL phishing network, seizing the w3ll.store domain and identifying the alleged developer. The ecosystem, which enabled credential harvesting for Microsoft 365 and other platforms, had been active since 2017 and facilitated over $20 million in fraud across more than 17,000 victims between 2023 and 2025.

    Show sources

Information Snippets

  • W3LL phishing kit enabled credential harvesting via spoofed Microsoft 365 login pages and other services.

    First reported: 13.04.2026 13:35
    1 source, 1 article
    Show sources
  • W3LL Store operated as a members-only marketplace from 2019 to 2023, with over 500 active users and 12,000+ items listed at one point.

    First reported: 13.04.2026 13:35
    1 source, 1 article
    Show sources
  • The FBI identified the alleged developer behind W3LL, publicly referenced as ‘G.L.’, and seized the w3ll.store domain.

    First reported: 13.04.2026 13:35
    1 source, 1 article
    Show sources
  • W3LL Store reportedly generated $500,000 in revenue for the actor over a 10-month period during its operation.

    First reported: 13.04.2026 13:35
    1 source, 1 article
    Show sources
  • Group-IB reported the W3LL ecosystem had been linked to 850 phishing sites during its active period.

    First reported: 13.04.2026 13:35
    1 source, 1 article
    Show sources
  • Investigators estimate over 25,000 compromised accounts were sold via W3LL Store until its 2023 shutdown.

    First reported: 13.04.2026 13:35
    1 source, 1 article
    Show sources
  • The takedown involved the FBI Atlanta field office in collaboration with Indonesian law enforcement authorities.

    First reported: 13.04.2026 13:35
    1 source, 1 article
    Show sources