ThreatPaper
Verified

The credential database remained active after the indictment was returned

Assessment

The indictment was returned under seal on 4 November 2025. The Justice Department's seizure announcement of 22 December 2025 states that web3adspanels.org "continued to host a backend server used in furtherance of the bank account takeover fraud as recently as November 2025." The domain's registry record shows creation on 20 October 2023, five weeks before the conspiracy's alleged start, and nameservers now pointing to fbi.seized.gov. The indictment's Counts Seven and Eight place possession of the credentials on 6 October 2025 "outside of the United States"; whether the November activity was the co-defendant's or a third party's is not stated.

Where this claim appeared

US Department of Justice · 2025-12-22

https://www.justice.gov/opa/pr/justice-department-announces-seizure-stolen-password-database-used-bank-account-takeover

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Sponsored-Link Bank Phishing: How a Google Ad Above the Real Login Took $14.6 Million

Think this assessment is wrong? Report an error.