Operation Endgame Disrupts Cybercrime Networks
Analysis based on 6 articles · First reported Jun 24, 2026 · Last updated Jun 29, 2026
The successful disruption of major cybercrime networks like SocGholish, Amadey, and StealC by International — Europol and its partners is expected to reduce the incidence of ransomware attacks and financial fraud, positively impacting the cybersecurity industry and potentially reducing financial losses for businesses and individuals. This action also highlights the critical role of private companies like Microsoft in combating cyber threats, potentially increasing demand for their security solutions. The seizure of Europe 41 million in crypto assets demonstrates the financial impact on criminal organizations.
Operation Endgame, a major international law enforcement effort coordinated by International — Europol and International — Eurojust, has delivered a significant blow to cybercriminal networks. Over two weeks, law enforcement agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States, alongside private partners including Microsoft, dismantled key infrastructure behind malware like SocGholish, Amadey, and StealC. The operation resulted in the seizure of over Europe 41 million (United States — United States dollar 47 million) in criminal crypto assets, the recovery of 27 million stolen login credentials, and the disruption of 326 servers and 142 domains. The focus was on disrupting the 'cybercrime-as-a-service' model, targeting the initial infection tools used for ransomware, financial fraud, and attacks on critical infrastructure. SocGholish, linked to the Russian cybercriminal group Dridex, distributed fake browser updates via compromised WordPress sites, with 14,971 such sites remediated. Amadey and StealC were also targeted for their roles in gaining initial access and extracting sensitive data, with Microsoft reporting over 140,000 infected computers linked to them in May 2026 alone. The operation represents a strategic shift to disrupt the entire cybercrime supply chain.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard