Dutch police arrested a 21-year-old man from Dordrecht suspected of selling access to JokerOTP, a phishing automation tool used to intercept one-time passwords (OTPs) and bypass multi-factor authentication. Authorities said the suspect marketed the service via Telegram and was found in possession of license keys used to provide other criminals access to the bot.
JokerOTP is described as a phishing-as-a-service capability that can automatically call victims, impersonate legitimate security alerts, and trick targets into entering OTPs; reporting also indicates it could be configured to capture additional sensitive data such as PINs, payment card data, and social security numbers, and target users of services including PayPal, Venmo, Coinbase, Amazon, and Apple. The arrest is the third tied to the JokerOTP operation, following the earlier arrests of the alleged developer (April 2025) and a co-developer (August 2025); UK law enforcement previously assessed the tool was used 28,000+ times across 13 countries and linked to at least $10 million in losses.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Investigators said they had identified dozens of suspected JokerOTP buyers in the Netherlands and expected additional prosecutions as the investigation continues. The announcement accompanied the latest arrest in the case.
Dutch police arrested a 21-year-old man from Dordrecht suspected of distributing JokerOTP via Telegram and possessing license keys for the tool. Authorities said he is the third person arrested in the case.
Authorities arrested a co-developer of JokerOTP in a follow-on action later in 2025, identified in reporting as occurring in August 2025. This marked the second arrest tied to the operation.
After a three-year joint investigation by Dutch and U.K. authorities, police dismantled the JokerOTP phishing-as-a-service operation in April 2025. The platform's developer was arrested as part of the takedown.
Over a two-year period, JokerOTP was allegedly used more than 28,000 times in 13 countries to capture one-time passwords through automated social-engineering calls, causing at least $10 million in losses. The tool enabled account takeovers and fraud by helping attackers bypass multi-factor authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.