● OVERVIEW OF 2024
PHISHERS
caught on the hook
The international police operation PhishOFF shut down LabHost,
one of the world’s largest platforms used by phishing scammers,
with over a million people impacted. The Estonian police played
a key role in preparing the raid.
Y
ears ago, simple scams like “Nigerian
letters” offering vast sums of money
were the subject of jokes. Today, however, cyber fraud has taken a giant
leap forward, often orchestrated by sprawling
international networks and organised crime.
These operations function like well-oiled
machines with distinct roles: some criminals
breach systems, others create virtual environments such as phishing websites, while another
group devises ways to quickly and effectively
drain bank accounts using stolen data. Finally,
specialist teams help launder the illicitly
obtained funds. Dedicated platforms now allow
criminals to purchase phishing services, denial-of-service attacks, ransomware and other
malware as a service.
OVER A MILLION VICTIMS
One of the largest operations of its kind, LabHost, focused specifically on facilitating phishing scams. It was dismantled in April 2024 during the international police operation PhishOFF,
with significant contributions from the Estonian police. Coordinated by Europol, the five-day
raid resulted in the arrest of 37 organisers of
phishing scams worldwide. The operation
involved 18 countries, primarily in Europe, but
also included the United States, Canada, Australia and New Zealand.
Launched in 2021, LabHost was a public platform offering pre-built fake websites, phishing
24
systems and distribution solutions (via SMS or
email) while also selling stolen data collected
on its platform. Thousands of regular criminal
clients purchased access to phishing packages
to execute their schemes. These packages
included fake websites mimicking major banks
and services across dozens of countries, enabling fraudsters to steal authentication details
and money from victims’ bank accounts.
Higher-tier packages cost between €230 and
€350 per month, with quarterly and annual subscriptions also available. Payments were made in
cryptocurrency, and LabHost reportedly earned
around €1 million from its services, but the
financial damage to victims was far greater. The
platform handled the most tedious and time-consuming aspects of cybercrime; its administrators
offered technical support to criminals through a
dedicated Telegram channel.
The international investigation uncovered at
least 66,000 websites used by nearly 10,000
criminals to steal data or money. Globally, over
a million people have fallen victim to scams
that have been executed through this platform.
LabHost facilitated the theft of 480,000 bank
card details, 64,000 PIN codes and over a million passwords. Stolen funds were transferred
between various bank accounts to obscure their
origins before being withdrawn as cash. In
Estonia alone, up to 30 criminals used LabHost
for phishing attacks, with around 10 of the most
active offenders arrested in different countries.
CYBER SECURITY IN ESTONIA 2025