Cybercrime

VerifTools Fake ID Operation Dismantled by Law Enforcement

Authorities say VerifTools sold fake driver’s licenses and passports worldwide, enabling fraudsters to bypass KYC checks and access online accounts.

FBI

Law enforcement in the US and the Netherlands on Thursday announced the seizure of domains and servers associated with VerifTools, one of the largest marketplaces for fraudulent identification documents.

As part of the operation, the FBI seized two domains and one blog associated with VerifTools, while the Dutch police seized two physical servers and 21 virtual servers hosted at a data center in Amsterdam.

The marketplace, the US Department of Justice says, was used to sell counterfeit identification documents, including driver’s licenses and passports, that allowed individuals to bypass identity verification systems, assume other people’s identities, and access online accounts.

According to the DoJ, the FBI started investigating VerifTools in August 2022, upon learning of a conspiracy to use stolen identities to access cryptocurrency wallets. Undercover agents used the marketplace to generate and purchase fake New Mexico driver’s licenses.

The investigation uncovered that VerifTools could be used to buy counterfeit identification documents for all 50 US states, as well as for various foreign countries. The fake IDs were offered for as little as $9.

The FBI estimates that VerifTools generated approximately $6.4 million in illicit proceeds for the cybercriminals selling the fake documents.

Advertisement. Scroll to continue reading.

The Dutch police, which seized the marketplace’s entire infrastructure, says that VerifTools could be accessed from multiple URLs (on the surface web) to generate images of fake IDs.

Visitors could upload a passport photo and provide false personal information, and then download the ID’s image after payment. These images could be used to bypass the ‘know your customer’ (KYC) verification that multiple companies rely on.

With all the data from VerifTools’ servers in their hands, the police will attempt to identify the marketplace’s administrators and users, who face imprisonment for their actions.

“The removal of this marketplace is a major step in protecting the public from fraud and identity theft crime. Together with our partners, we will continue to target and dismantle the platforms that criminals depend on, no matter where they operate,” FBI special agent Philip Russell said.

Related: Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects

Related: Europol Says Qilin Ransomware Reward Fake

Related: Silicon Valley Bank Seized by FDIC as Depositors Pull Cash

Related:Global Police Sting Nets 179 Dark Web Sellers

Related Content

Malware & Threats

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Cybercrime

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

Cybercrime

Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Phishing

The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version