HeartSender takedown
Extended pass entry, last reviewed August 21, 2026
What happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Not established
Did it stay down?
Not established in the public record. No later activity is recorded against this entry.
See what happened afterwardDOJ/FBI seized 39 domains and associated servers used to sell phishing kits and other fraud-enabling tools through the HeartSender operation.
- Date
- January 2025
- Target
- HeartSender ("Saim Raza"), cybercrime tooling marketplace
- Activity
- Fraud and stolen data
- Operational lead
- FBI
- Partners
- DOJ[1]
- United States Department of Justice , prosecuting
- Jurisdiction
- Not established
- Outcome
- 39 domains and associated servers seized.
- Status
- Completed
- Legal mechanism
- Federal seizure warrant.
- Group accounted for
- Not established
Infrastructure
39 domains seized.
- 39
- domains seized
| Identifier | Recorded as | Status | Notes |
|---|---|---|---|
| Not published | 39 domains | Seized, United States | Not established[1] |
Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Not established
The cited record does not say how large the group was or whether everyone involved has been identified.
Not established in the public record. No later activity is recorded against this entry.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
Justice Department seizes domains behind HeartSender phishing-kit operation
Establishes the 39-domain seizure targeting HeartSender.