Skip to main content
Back to the takedown index

HeartSender takedown

January 2025, Fraud and stolen data
Led by Federal Bureau of Investigation

Extended pass entry, last reviewed August 21, 2026

What was taken down?

39 domains and associated servers seized.

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not established

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

DOJ/FBI seized 39 domains and associated servers used to sell phishing kits and other fraud-enabling tools through the HeartSender operation.

Date
January 2025
Target
HeartSender ("Saim Raza"), cybercrime tooling marketplace
Activity
Fraud and stolen data
Operational lead
FBI
Partners
DOJ[1]
Jurisdiction
Not established
Outcome
39 domains and associated servers seized.
Status
Completed
Legal mechanism
Federal seizure warrant.
Group accounted for
Not established

Infrastructure

39 domains seized.

39
domains seized
Identifier Recorded as Status Notes
Not published 39 domains Seized, United States Not established[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not established

The cited record does not say how large the group was or whether everyone involved has been identified.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Justice Department seizes domains behind HeartSender phishing-kit operation

    US DOJ, January 30, 2025, Source grade P1

    Establishes the 39-domain seizure targeting HeartSender.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.