Skip to main content

Only available in English.

TECH_SCIENCE13 / 18 · story of the day4 min · 771 words · 23 sources

Police strike seizes 27 million stolen credentials

Written by AIto brief AI · 26 June 2026, 03:50
How it was written

Millions of cloned keys wait in silence for a lock that doesn't know they exist.

Image composition · tobrief
the text · 4 min read

Every time your browser offers to remember a password, it stores a small file that proves you've already logged in. A stolen copy of that file works like a cloned hotel keycard: whoever holds it walks straight past the lock. In mid-June, police from eight countries tried to shut down the factories producing those cloned keys at industrial scale.

The targets were not individual criminal gangs. They were shared services that many gangs rent and reuse, a kind of cybercrime supply chain. Between 15 and 19 June 2026, a coordinated strike called Operation Endgame neutralised 326 servers and 142 domains, recovered 27 million stolen login credentials, and flagged more than EUR 41 million in suspected criminal cryptocurrency (Europol). Authorities from Germany, Belgium, Denmark, France, the Netherlands, the United Kingdom, the United States and Canada all participated (Eurojust).

How a Password-Theft Pipeline Works

The operation targeted three malware networks, each playing a different role in the same theft chain. SocGholish tricks people into installing fake browser updates on compromised websites. Amadey acts as a loader, the digital equivalent of a lockpick that opens the door and lets other tools inside. StealC then copies whatever is valuable: usernames, passwords, browser cookies, session tokens (small files that tell a website you're already logged in) and saved card details (Microsoft Security).

What makes these infostealers different from ransomware is their silence. They do not lock files or demand payment. They copy data and leave. Stolen session cookies are especially dangerous because they bypass multi-factor authentication entirely. If a cookie says you already verified your identity, the website believes it, regardless of who is holding it (Flare).

The scale is staggering. Proofpoint and IBM X-Force, which supported the takedown, independently counted more than 25.6 million unique stolen credentials from over 385,000 compromised systems (Proofpoint). Microsoft, which used AI tools to map criminal server networks and obtained court orders to seize more than 200 web addresses used to distribute malware, reported that Amadey and StealC alone were linked to over 140,000 infected computers in just the first two weeks of May (Microsoft blog). Shadowserver, an independent threat-monitoring foundation, published a historical report covering nearly a year of StealC activity: 29.5 million individual infostealer events across 364,000 unique victim IP addresses in 231 countries (Shadowserver).

The Danish case shows what those numbers mean for a single person. Denmark's National Unit for Special Crime identified 732 Danish victims whose devices had yielded roughly 53,000 stolen login sets (Politiken). One infected device can expose an entire digital life: email, banking, cloud storage and work systems, all at once.

Why Eight Countries Had to Move Together

No single police force can handle this alone because the crime is deliberately scattered. The victim sits in Copenhagen. The compromised website runs on a server in one country. The remote switchboard criminals use to send instructions to infected machines sits in another. The stolen credentials get sold on a marketplace hosted somewhere else. The cryptocurrency flows through yet another jurisdiction.

Europol's cybercrime centre helped connect evidence across countries, trace cryptocurrency and identify who controlled which server (Europol). Germany was both an enforcement hub and a victim hotspot: around 40 of the seized servers were located on German soil, and the country ranked second behind the US in Microsoft's victim sample from mid-May to late June (Tagesschau).

What the Takedown Cannot Fix

This operation bought time. It did not make the stolen data safe again. Taking servers offline cuts criminals' ability to issue commands and receive stolen data. It does not undo credentials already harvested. Passwords already copied remain dangerous until victims change them, revoke active sessions and clean infected devices (IPBan).

Europol listed victim-notification tools including Have I Been Pwned and the Dutch NCSC, and urged affected website owners to update systems and strengthen credentials (Europol). For organisations, the risk goes beyond consumer passwords: stealer logs routinely contain VPN credentials, cloud-platform tokens and business-application access, making it essential to revoke active sessions and scan devices for lingering infections (Flare).

Operation Endgame has now run multiple phases since 2024, each targeting a different layer of the malware ecosystem. The pattern suggests law enforcement is shifting from chasing individual hackers toward dismantling the rental infrastructure that makes cybercrime scalable. Whether that shift can outpace criminals who rebuild remains the open question. Password managers and browser convenience are not the real vulnerability here. Stolen sessions and infected devices are. Anyone relying on multi-factor authentication alone should know: a copied cookie walks right past it.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
6/26/2026, 3:23:22 AM
Pipeline run:
eu_pipeline_20260626_015006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology