Cybercrime

UK Student Sentenced to Prison for Selling Phishing Kits

Ollie Holman was sentenced to prison for selling over 1,000 phishing kits that caused estimated losses of over $134 million.

Hacker sentenced to prison

A British student was sentenced to seven years in prison for selling more than 1,000 phishing kits impersonating legitimate entities in 24 countries.

The individual, Ollie Holman, 21, of Eastcote, West London, was initially arrested in October 2023, and then again in May 2024. On both occasions, law enforcement seized devices containing digital evidence liking him to his online activities.

Holman, who pleaded guilty to seven counts, admitted to selling phishing kits containing fraudulent web pages that tricked victims into sharing their personal and financial information with cybercriminals.

According to UK law enforcement, Holman built and sold 1,052 phishing kits that targeted 69 financial institutions and large organizations, including charities, causing more than £100 million (approximately $134 million) in losses, globally.

Scripts within the fraudulent web pages collected the user-supplied information, including login credentials and banking information.

Holman sold the phishing kits over Telegram, and provided cybercriminals with advice and technical assistance in committing fraud. Authorities say that, even after he was arrested in 2023, he continued to provide support for the phishing kits through his Telegram channel.

Advertisement. Scroll to continue reading.

Following the sentencing, authorities will take Holman back to court to pursue the confiscation of the illegal proceeds.

“By creating and selling phishing kits, Ollie Holman facilitated a widespread fraud which others used to exploit innocent victims on a vast scale,” Crown Prosecution Service specialist prosecutor Sarah Jennings said.

“I hope this case sends a clear message to those who intend on committing fraud: no matter how sophisticated your methods, you cannot hide behind online anonymity or encrypted platforms. Fraudsters like Holman will be robustly pursued by law enforcement, prosecuted by the CPS, and brought to justice,” Jennings added.

Related: US Targets North Korea’s Illicit Funds: $15M Rewards Offered as American Woman Jailed in IT Worker Scam

Related: Nigerian Involved in Hacking US Tax Preparation Firms Sentenced to Prison

Related: Trump Pardons Founder of Silk Road Website

Related: Notorious Vietnamese Hacker Turns Government Cyber Agent

Related Content

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Mobile & Wireless

Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.

Cybercrime

Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL).

Cybercrime

Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group.

Phishing

The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.

Artificial Intelligence

Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version