A British student has been sentenced to seven years in prison for selling more than 1,000 phishing kits, which pretended to belong to legitimate organizations in 24 countries.
See also: Google Gemini: How email summaries lead to phishing attacks?

This is Ollie Holman, 21, from the Eastcote area of west London, who was initially arrested in October 2023 and again in May 2024. On both occasions, authorities seized devices with digital evidence linking him to his online activities.
Holman pleaded guilty to seven charges and confessed to selling phishing kits, which included fake websites that tricked victims into revealing their personal and financial information to cybercriminals.
According to British authorities, Holman built and sold 1,052 phishing kits, which targeted 69 financial institutions and large organizations — including charities — causing global losses exceeding £100 million (about $134 million).
See also: Arrests of people for phishing scam against British tax authority
Scripts contained on the fake websites collected the information entered by users, such as login details and banking data.

Holman sold the phishing kits through the Telegram and provided cybercriminals with advice and technical support to carry out the fraud. Authorities say that even after his arrest in 2023, he continued to offer support for the phishing kits through his Telegram channel.
After the sentence is announced, authorities plan to take Holman back to court, with the aim of confiscating the illegal profits.
Also, Telegram and other similar platforms have become key tools for communicating and trafficking illegal products, due to the encryption and relative anonymity they offer.
See also: Increase in phishing attacks ahead of Amazon Prime Day
This case demonstrates the need for:
- stricter international cooperation between authorities,
- better public awareness about phishing,
- technological tools to detect and prevent such attacks.
Source: securityweek
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
