It puzzles me that all these spam/fishing operations are being uncovered by an accident and there's no proactive private or nonprofit organizations pursuing these criminals.
Overall our current state of (an average user) security can be described as Swiss cheese where anyone with malicious intent can poke a hole and use it without any repercussions.