Last updated 2 weeks ago
Operation Endgame 4.0, conducted on 18 June 2026, targeted the SocGholish malware operation, a prolific malware distribution network. Coordinated by international law enforcement with Europol and Eurojust, the operation remediated nearly 15,000 compromised websites and disrupted over 100 servers and domains. Authorities provided Have I Been Pwned (HIBP) with 154,000 impacted email addresses and over half a million previously unseen passwords recovered during the operation. A subsequent week brought an additional 4 million email addresses and 9 million passwords related to the StealC malware operation, totaling almost 4.2 million unique email addresses.
The attack chain involved the SocGholish malware distribution network, which compromised websites to deliver malware payloads. The operation disrupted the infrastructure used for malware distribution, including servers and domains. The data exfiltrated included email addresses and passwords, with the passwords being previously unseen. No specific threat actor or ransomware group was attributed in the article.
No post-incident developments such as regulatory actions, litigation, ransom payments, or breach notifications were mentioned in the article.
Law enforcement operation disrupted malware distribution infrastructure and recovered compromised credentials
Sign in to join the discussion.
Company
Industry
Disclosed
Records Affected
Attack Vector
Industry
Attack Vector