FBI, Indonesian Authorities Team to Take Down Site Ripping Off Users for Millions
嗯,用户让我总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。我得先仔细阅读文章内容。 文章讲的是FBI和印尼警方合作打击了一个全球性的钓鱼组织,涉案金额高达2000万美元。他们使用了W3LL钓鱼工具包,能够模仿合法登录页面,窃取用户名和密码,甚至绕过多因素认证。这个工具包在市场卖了四年,导致2.5万个账户被入侵,1.7万名受害者。后来工具包改名通过加密应用销售。 文章还提到AI让钓鱼攻击更难察觉,专家建议加强身份安全措施,比如多因素认证和安全意识培训。最后提到未来AI可能让攻击更自动化。 现在我需要把这些要点浓缩到100字以内。要包括FBI和印尼的合作、钓鱼组织的规模、W3LL工具包的功能、受害者数量、AI的影响以及防范建议。 可能的结构:FBI与印尼合作打击全球钓鱼组织,涉案金额2000万美元。使用W3LL工具包窃取信息,导致大量账户被入侵。AI提升攻击复杂度,专家建议加强安全措施。 检查字数是否在限制内,并确保信息准确全面。 </think> FBI与印尼警方合作打击全球性钓鱼组织,涉案金额达2000万美元。该组织利用W3LL钓鱼工具包窃取用户信息并绕过多因素认证,导致2.5万个账户被入侵及1.7万名受害者受骗。AI技术使钓鱼攻击更难察觉,专家建议加强身份安全措施以应对威胁。 2026-4-27 08:36:57 Author: securityboulevard.com(查看原文) 阅读量:9 收藏

The FBI’s Atlanta Field Office joined forces with law enforcement authorities in Indonesia to put the kibosh on a phishing organization that stretched around the globe and to date has resulted in $20 million in attempted fraud.  

The cybercriminals used the full-service W3LL phishing kit to act as if they were legitimate login pages. When targets gave up their usernames and passwords, the kit would snag that information. And the miscreants would use them to access accounts.  In addition, the tool can also grab session data, offering a path around multifactor authentication. All for the bargain basement price of $500. 

“The true danger of many phishing schemes lies in their ability to grant attackers access to credentials, enabling them to masquerade as trusted insiders,” says Rex Booth, CISO at SailPoint. 

And in a four-year period, up to 2023, the kit had a considerable number of takers on the W3LLSTORE marketplace, which ultimately resulted in the sale of more than 25,000 compromised accounts and more than 17,000 victims were targeted in the state of Georgia and globally, the Times of India reported. That store shuttered in 2023 but that didn’t stop the W3LL phishing kit from proliferating; it was simply rebranded and sold through encrypted messaging apps. 

The kit’s developer, referred to by the FBI as “G.L.,” was picked up in Indonesia by authorities. The takedown represents the first time the FBI and Indonesian authorities have worked together in pursuit of cybercriminals.  

AI has upped the phishing game. “Traditional phishing emails used to carry clear warning signs such as poor grammar, inconsistent branding, or unusual formatting,” says Nicole Carignan, senior vice president, security & AI strategy, and Field CISO at Darktrace.  

But these days, “AI has removed many of those indicators,” she says, explaining. That “attackers can generate highly polished, brand-consistent communications that closely mirror legitimate organizations, and even tailor messages using publicly available or previously compromised data.”  

With AI, adversaries can “operate with greater speed and precision” and “campaigns can be created, tested, and refined in real time, producing large volumes of highly targeted messages that are far more likely to succeed,” Carignan says.  

“As a result, phishing is no longer just a volume-based threat; it’s become a quality and personalization problem, making it increasingly difficult to detect with the human eye alone,” she adds.  

Because AI makes phishing campaigns more sophisticated and harder to detect, Booth says, it’s “imperative for users to adopt robust identity security best practices, including changing passwords frequently and enabling multi-factor authentication, and for organizations to prioritize identity as the new control plane.” 

Noting that “people are trained to obey authority, and deepfake and callback phishing attacks are designed to push people into bypassing normal checks,” Hoxhunt Co-founder and CEO Mika Aalto urges organizations “to normalize ‘see something, say something’ behavior and make verification frictionless. Behavioral monitoring tools can help flag unusual actions, but the real challenge is cultural: giving employees confidence that slowing down to verify is expected, supported, and reinforced through Human Risk Management practices.” 

Since phishing has evolved beyond static text, “awareness must do the same,” Aalto says, because the “entire concept of ‘security awareness training’ is outdated if it stops at awareness.” 

Aalto believes the next generation of defense is “behavioral, not informational” with defenders “moving from telling people what to do to shaping whatthey actually do, in real time. We are building an innate set of security reflexes and instincts.”  

Security pros believe that, unfortunately, the worst is yet to come, making speed an imperative. “We’ve been waiting for this offensive disruption from AI for a while now,” says Booth. “Attacks at scale and superhuman speed are the most obvious first step.” 

At least for now, many campaigns “require human intervention to execute,” he says, stressing that the “scarier scenario is when adversary AI starts running rampant through your enterprise without the need for action by the victim.” 

Recent Articles By Author


文章来源: https://securityboulevard.com/2026/04/fbi-indonesian-authorities-team-to-take-down-site-ripping-off-users-for-millions/
如有侵权请联系:admin#unsafe.sh