Dutch police arrest 21-year-old for alleged involvement in JokerOTP password stealer
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”这样的开头。首先,我得通读一下这篇文章,看看主要讲了什么。 文章讲的是荷兰警方逮捕了一名21岁的男子,他涉嫌分发一个叫做JokerOTP的恶意软件。这个软件被用来窃取一次性密码,绕过双重认证。看起来这是一个比较严重的网络犯罪案件。 接下来,我需要找出关键点:逮捕的人是谁,他做了什么,这个软件的功能和影响是什么。还有提到荷兰和英国警方进行了三年的调查,已经逮捕了三个人,包括开发者和分销商。 然后,我需要把这些信息浓缩到100字以内。要确保涵盖主要事件、人物、工具及其影响。同时要注意用词简洁明了。 可能的结构是:荷兰警方逮捕了一名男子,他涉嫌分发JokerOTP恶意软件用于窃取一次性密码。该软件被广泛用于绕过双重认证,导致大量账户被盗和资金损失。警方已经逮捕了三名相关人士,并计划继续追查购买该软件的人。 最后检查一下字数是否符合要求,并且确保没有使用任何不需要的开头语。 </think> 荷兰警方逮捕一名21岁男子,涉嫌分发用于窃取一次性密码的恶意软件JokerOTP。该工具被广泛用于绕过双重认证系统,导致多国数千起账户被盗案件及至少1000万美元损失。荷兰与英国警方已逮捕三人,并计划追查更多购买者。 2026-2-12 14:15:54 Author: therecord.media(查看原文) 阅读量:1 收藏

Police in the Netherlands arrested a 21-year-old as part of a larger investigation into a tool built to steal one-time passwords.

The Dordrecht native was detained on Tuesday by police in East Brabant on accusations he distributed a bot called JokerOTP. The tool is used widely by cybercriminals to intercept the codes delivered by many platforms as part of multi-factor authentication sign-ins. 

Dutch police did not name the man arrested but said this is the third person connected to JokerOTP that has been detained, with the system’s developer and co-developer arrested in April and August 2025 during operations in the Netherlands and the U.K.

The man arrested on Tuesday allegedly sold the bot to other criminals through Telegram and had the bot’s license keys when he was arrested. 

The Cleveland Police Department in the U.K. said last year that over a two-year stretch, JokerOTP was used over 28,000 times in 13 different countries. The hackers behind it were allegedly able to steal at least $10 million. 

Most one-time passwords are sent to a person’s phone by a bank or payment service. According to Dutch officials, JokerOTP allowed cybercriminals to “automatically call victims and then trick them into entering a one-time password to gain access to someone's account.”

"Victims were automatically called by the bot, informing them that criminals were trying to access their accounts. The bot then asked them to enter their one-time password. Victims think they're protecting themselves by providing information,” said Anouk Bonekamp, ​​cybercrime team leader with the East Brabant Police Unit.

“This plays on feelings of uncertainty and fear, while a one-time password is intended to prevent malicious actors from logging into your account. Using the bot, two-factor authentication can be bypassed, allowing the cybercriminal to access victims' accounts and commit fraud."

Officials noted that they have identified multiple people in the Netherlands who purchased JokerOTP and plan to track them down for prosecution. 

Bonekamp said those who purchased it “create many victims, causing not only financial but also emotional harm, such as stress and embarrassment."

The arrests came after a three-year investigation by police departments in The Netherlands and the U.K. One of the two men arrested last year was nabbed in the English town of Middlesbrough. 

Cybersecurity researchers at Bitdefender previously said JokerOTP was a powerful phishing tool that typically involved attackers “impersonating trusted organizations such as banks, cryptocurrency exchanges, and other major service providers.”

“Attackers contact potential victims, posing as customer service representatives. Victims are alerted to supposed suspicious activities on their accounts. Victims are pressured into verifying their identities by willingly offering OTPs or 2FA codes received via text messages or mobile applications,” Bitdefender explained. 

“Once obtained, attackers use the stolen codes to access victims' accounts. Attackers then carry out fraudulent transactions or altered security settings to maintain persistent access. The stolen credentials were usually sold or traded among cybercriminals. In other situations, they were used for identity theft and various criminal activities.”

The platform also had fake websites that looked like legitimate login portals for real financial institutions. 

“Users of the JokerOTP bot platform can rest assured that law enforcement has been watching and will be in touch,” said Kevin Carter, an official with the Cleveland Police’s Cyber Crime Unit.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/dutch-police-arrest-man-over-jokerotp-password-stealer
如有侵权请联系:admin#unsafe.sh