[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyezhngf7tguf":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":4,"company":33},"68e3266eda11adda488252fa","operation-endgame2","Operation Endgame 2.0 2025 Data Breach","operation-endgame-20","operation-endgame.com","2025-05-23T00:00:00.000Z","2025-05-23T20:47:34.000Z","2026-07-29T12:19:53.122Z","Verified breach record","https:\u002F\u002Fwww.europol.europa.eu\u002Fmedia-press\u002Fnewsroom\u002Fnews\u002Foperation-endgame-strikes-again-ransomware-kill-chain-broken-its-source",[15,17,18],"https:\u002F\u002Fwww.operation-endgame.com\u002F","https:\u002F\u002Fwww.operation-endgame.com\u002Fseasons\u002F",15436844,"known",null,"email_identifiers","Critical",[25,26],"Email addresses","Passwords","\u003Cp>Operation Endgame 2.0 is a verified credential-exposure record linked to 15,436,844 victim email addresses in May 2025.\u003C\u002Fp>\n\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The validated dataset associated with this event contains email addresses and passwords. The email addresses relate to victim information recovered from devices affected by malware. Passwords were assessed as a separate collection; no evidence establishes that every password is paired with a particular email address. That distinction matters: the existence of a password list does not mean a known password exists for every email or that both fields were taken together from the same account.\u003C\u002Fp>\n\u003Cp>The separate password collection was reported as 43.8 million values, but that figure is not a count of affected accounts. One password can be used by many people, and repeated values can influence the total. By contrast, 15,436,844 is the number of unique victim email addresses used for notification. An email address alone does not provide direct account access, but it can be a starting point for targeted phishing, password attempts, and fraudulent security alerts.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\n\u003Cp>In May 2025, coordinated law-enforcement and judicial action targeted malware infrastructure used to provide initial access before ransomware attacks. Between 19 and 22 May, authorities took down about 300 servers, neutralised 650 domains, and issued international arrest warrants for 20 targets. That timeline is consistent with the record's breach and added date of 23 May 2025.\u003C\u002Fp>\n\u003Cp>Operation Endgame is the name of the international enforcement action; it does not mean that the initiative itself or its official website was breached. The page concerns credential data set aside from seized criminal infrastructure for victim notification. The 15,436,844 email addresses and 43.8 million separate password values are different measures and must not be presented as email-password pairs. Those limits are essential to interpreting the event accurately.\u003C\u002Fp>\n\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\n\u003Cp>People who used a device affected by malware face a higher risk, particularly when they stored passwords in a browser or reused one password across services. Not every person whose email address appears has the same level of exposure; some may have only contact information present. Even so, use of the same address across accounts can make password-reset attempts and targeted messages look more convincing.\u003C\u002Fp>\n\u003Cp>People who use the same device for a primary inbox, financial services, work accounts, or administrative access should act first. Reusing older passwords on active accounts can increase risk when the exposed email is combined with information from another dataset. Unfamiliar sign-in alerts, unknown browser extensions, unexpected password-reset messages, and unrecognised devices all warrant review.\u003C\u002Fp>\n\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\n\u003Cp>When the email address has a match, change accounts that use the same or a similar password without delay. Choose a long, unique password for every service, prioritising the primary inbox, bank, payment, work, and account-recovery access. Enable multi-factor authentication and, where possible, use an authenticator application or physical security key. Review active sessions, recovery email addresses, and phone numbers as well.\u003C\u002Fp>\n\u003Cp>Run a trusted security scan on a suspected device, review browser extensions, and remove extensions you do not recognise. Keep the operating system, browser, and security tools up to date. Rather than following links in urgent verification messages received by email or text, sign in through the known website. Personal details known by a sender do not prove that a request is legitimate.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\n\u003Cp>A password manager makes it easier to create a different, strong password for every service. Protect the primary email account especially well because password-reset messages usually arrive there. Keep authentication and recovery codes offline with limited access. Reducing password reuse lowers the chance that one exposure spreads across many accounts.\u003C\u002Fp>\n\u003Cp>Current software, careful extension use, and regular device checks reduce malware risk. Avoid storing unnecessary passwords in a browser and close sessions that are no longer needed. Review account activity, password-reset notices, and multi-factor prompts regularly. Verifying requests through the official website or a known support channel adds protection against social-engineering attempts.\u003C\u002Fp>\n\u003Ch2>Record Check and User Action\u003C\u002Fh2>\n\u003Cp>Check the email address in the breach search. A match means that the address appears in the validated email set used for victim notification; it does not by itself prove an active account was taken over or that a password matched to the address is known. A match is still a meaningful signal to renew passwords, enable multi-factor authentication, and review device security.\u003C\u002Fp>\n\u003Cp>When a match appears, review the email account first, then payment, work, and shopping accounts tied to the same address. Contact the relevant provider through its official support channel without delay when you notice an unfamiliar sign-in, password-reset request, device, or financial activity. Even without a match, unique passwords, multi-factor authentication, and current device security remain effective protection against malware-related credential exposure.\u003C\u002Fp>","","Operation Endgame 2.0 2025 Data Breach (15.4 Million Email Identifiers)","Operation Endgame 2.0 2025 Data Breach. 15.4 Million email identifiers were reported. Reported data: Email addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Foperation_endgame_official.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":21},"Operation Endgame","Government","International"]