Inside the Takedown: How the FBI and Indonesian Police Dismantled a Global Phishing Ring That Weaponized 16Shop

The FBI and Indonesian police arrested the alleged developer of 16Shop, a phishing-as-a-service platform linked to 150,000 phishing domains across 43 countries. The takedown highlights growing international cooperation against cybercrime supply chains.
Inside the Takedown: How the FBI and Indonesian Police Dismantled a Global Phishing Ring That Weaponized 16Shop
Written by Ava Callegari

For years, a slick phishing-as-a-service platform called 16Shop operated as one of the internet’s most prolific fraud engines — a turnkey kit that let even low-skilled criminals launch convincing phishing attacks against users of Apple, Amazon, PayPal, American Express, and Cash App. Now, after a sprawling international investigation, the operation’s alleged architect and key associates are in custody, and the infrastructure that powered an estimated 150,000 phishing domains has been torn apart.

The FBI, working alongside the Indonesian National Police (Polri) and supported by Interpol’s cyber directorate, arrested the suspected developer of 16Shop — a 21-year-old Indonesian national identified as Riswanda Noor Saputra — along with two facilitators, one in Indonesia and another in Japan. The coordinated takedown, which also involved law enforcement agencies from the United States, Japan, and multiple European nations, represents one of the most significant disruptions of a phishing-as-a-service operation to date, according to a report by The Hacker News.

It also underscores a growing pattern in cybercrime enforcement: the targeting not just of individual scammers, but of the platform builders who industrialize fraud at scale.

The Business Model Behind 16Shop: Phishing as a Subscription Service

16Shop wasn’t a crude operation. It was, by the standards of cybercriminal enterprise, remarkably well-designed. The platform sold phishing kits — pre-built packages of code, web templates, and backend infrastructure — that mimicked the login pages of major consumer brands with startling fidelity. Buyers could purchase kits for specific targets: an Apple kit, an Amazon kit, a PayPal kit. Each came with multilingual support, antibot detection evasion features, and real-time credential harvesting dashboards.

Prices ranged from roughly $60 to $150 per kit, payable in cryptocurrency or through online payment platforms. Buyers didn’t need technical sophistication. They needed only a domain, a hosting provider willing to look the other way, and a distribution method — typically phishing emails or SMS messages. The kits handled the rest.

This model — sometimes called “cybercrime-as-a-service” — has become the dominant framework for online fraud in the 2020s. Rather than a single attacker running a single campaign, a developer builds the tooling and sells access to hundreds or thousands of operators worldwide. The result is an enormous multiplication of criminal capacity. One developer. Thousands of attackers. Millions of victims.

According to analysis cited by The Hacker News, 16Shop’s infrastructure was linked to more than 150,000 phishing domains and had facilitated the theft of credentials and financial data from victims in at least 43 countries. The platform had been active since approximately 2017, making it one of the longer-running phishing kit operations on record.

And it was hidden in plain sight. 16Shop maintained a presence on social media, Telegram channels, and underground forums. It even had a customer support system. The developer, investigators allege, treated it like a legitimate SaaS business — with version updates, bug fixes, and feature rollouts.

How the Investigation Unfolded

The road to arrest was long and multi-jurisdictional. The FBI’s investigation reportedly began after cybersecurity researchers first flagged 16Shop’s operations in 2019. Multiple private-sector threat intelligence firms, including Group-IB, had published detailed technical analyses of the platform’s code and infrastructure, providing a breadcrumb trail that law enforcement could follow.

Group-IB, the Singapore-headquartered cybersecurity firm, played a particularly visible role. The company had been tracking 16Shop since at least 2019 and published research identifying its operator through a series of operational security failures — reused email addresses, linked social media accounts, and code artifacts left inside the phishing kits themselves. These findings were shared with Interpol’s ASEAN Cyber Capability Desk, which coordinated intelligence-sharing between national police forces.

Interpol confirmed that its role included facilitating communication between law enforcement in Indonesia, Japan, and the United States, as well as providing analytical support. The arrest of Saputra took place in Indonesia, while the facilitator in Japan — who allegedly managed infrastructure and payment processing — was arrested by Japanese authorities.

The third suspect, also based in Indonesia, is alleged to have assisted in administering the platform and managing customer relationships with buyers of the phishing kits.

No trial dates have been announced. Indonesian authorities have indicated that Saputra faces charges under the country’s electronic information and transactions law, which carries significant prison time for cybercrime offenses.

The broader significance of the case lies in the cross-border cooperation model it demonstrates. Phishing-as-a-service platforms are, by design, globally distributed. Developers sit in one country. Hosting infrastructure spans multiple jurisdictions. Buyers operate from dozens of nations. Victims are everywhere. Traditional law enforcement structures — organized around territorial jurisdiction — are poorly suited to this kind of threat. Operations like this one require the kind of sustained, multi-agency coordination that remains difficult and resource-intensive.

But they’re becoming more common. In recent years, Europol, the FBI, and allied agencies have conducted similar takedowns against other cybercrime service providers, including the Genesis Market credential bazaar and the BreachForums data leak site. The 16Shop operation fits squarely within this strategic shift toward disrupting enablers rather than chasing individual end users of criminal tools.

The phishing-as-a-service market, however, is far from defeated. Security researchers note that several competitors and successors to 16Shop have already emerged, offering similar or even more advanced capabilities. Some newer kits incorporate real-time man-in-the-middle proxying techniques that can bypass multi-factor authentication — a level of sophistication that 16Shop’s kits did not consistently achieve.

Still, the arrests send a signal. Building and selling phishing infrastructure is not a risk-free enterprise, even when conducted from jurisdictions that have historically been slow to prosecute cybercrime. Indonesia’s willingness to act on international requests in this case is notable and may reflect a broader shift in how Southeast Asian nations approach cyber enforcement.

For corporate security teams and fraud prevention units at financial institutions and technology companies, the 16Shop takedown offers both encouragement and a reminder. Encouragement because law enforcement is demonstrably investing in dismantling the supply chain of phishing attacks. A reminder because the underlying demand for stolen credentials hasn’t diminished. The tools change. The operators rotate. The threat persists.

What Comes Next for Phishing Enforcement

The trajectory of phishing-as-a-service enforcement is likely to follow the same pattern seen in other areas of cybercrime disruption: periodic high-profile takedowns that temporarily suppress specific platforms, followed by rapid adaptation by criminal entrepreneurs. The key question is whether law enforcement can increase the tempo and scope of these operations enough to impose meaningful friction on the market as a whole.

Some analysts are cautiously optimistic. The cooperation frameworks established through Interpol, Europol, and bilateral agreements between the U.S. and Southeast Asian nations are maturing. Technical attribution capabilities have improved dramatically, aided by private-sector threat intelligence firms that increasingly function as force multipliers for under-resourced national police agencies.

But structural challenges remain. Many phishing kit developers operate from countries with limited extradition agreements. Cryptocurrency payment channels, while not entirely anonymous, add layers of complexity to financial investigations. And the sheer volume of phishing activity — billions of phishing emails are sent every day, according to estimates from the Anti-Phishing Working Group — means that enforcement actions, however successful, address only a fraction of the problem.

The 16Shop case, then, is best understood as a significant tactical victory within a much larger, ongoing conflict. The platform is down. Its alleged creator is in custody. Thousands of phishing campaigns that relied on its kits have been disrupted. That matters.

So does the precedent. Every arrest of a platform developer raises the perceived risk for the next one. And in an industry built on rational calculations of risk and reward, that shift in perception — however incremental — is worth something.

The victims of 16Shop-powered phishing campaigns, spread across 43 countries and numbering potentially in the hundreds of thousands, may never recover their stolen data or financial losses. But the infrastructure that enabled their victimization has been dismantled. For now, that’s the win.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us