[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fthogn57uy1l0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":4,"company":34},"68e3266eda11adda488252f2","operation-endgame","Operation Endgame Malware Exposure","operation-endgame.com","2024-05-30T00:00:00.000Z","2024-05-30T04:19:45.000Z","2026-07-29T12:19:53.122Z","Malware","https:\u002F\u002Fwww.troyhunt.com\u002Foperation-endgame\u002F",[14,16,17,18,19],"https:\u002F\u002Fwww.operation-endgame.com\u002F","https:\u002F\u002Fwww.operation-endgame.com\u002Fseasons\u002F","https:\u002F\u002Fwww.europol.europa.eu\u002Fmedia-press\u002Fnewsroom\u002Fnews\u002Flargest-ever-operation-against-botnets-hits-dropper-malware-ecosystem","https:\u002F\u002Fwww.operation-endgame.com\u002F_astro\u002Flogo.DWKb31q1_miqRe.webp",16466858,"known",null,"email_identifiers","Critical",[26,27],"Email addresses","Passwords","\u003Cp>The May 2024 Operation Endgame malware record covers 16,466,858 unique email addresses and a separate set of password hashes obtained by law enforcement.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified collection contained email addresses and password data. The corpus supplied by law enforcement included \u003Cstrong>16,466,858 unique email addresses\u003C\u002Fstrong> and approximately 13.5 million unique passwords. Passwords were processed as SHA-1 and NTLM hashes rather than plaintext, and they did not appear beside email addresses or as account-level pairs. The record count therefore represents unique email addresses, not an equal number of unique people or email-password combinations. The only confirmed data classes are email addresses and passwords. Operation Endgame is not a breach of a company's database; it is a malware-related incident record assembled from data seized across criminal infrastructure so potential victims could learn of their exposure.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>In late May 2024, international law enforcement and private-sector teams launched the coordinated Operation Endgame action against infrastructure used by malware loaders including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee. Four people were arrested and more than one hundred servers were taken down or disrupted around the world. Email addresses and password hashes found in the seized data were then transferred into a secure notification process so potential victims could check their exposure. \u003Cstrong>The password hashes were disassociated from the email addresses\u003C\u002Fstrong>, so the collection cannot reveal which password belonged to a particular address. The canonical date of 30 May 2024 reflects the public disclosure of the operation and data transfer. The record does not claim that a particular website was breached or that every item came from one malware family.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The greatest risk applies to people whose devices may have encountered botnet or malware activity and who reused a password across multiple services. An email match alone does not prove that a particular password was published beside that address, that an account remains compromised today or that malware is still running on the device. However, any old password that survives on other accounts can support automated login attempts and account takeover. Appearance of an address in data linked to criminal infrastructure can also enable targeted phishing, fake security alerts, password-reset traps and fraudulent device-cleaning offers. Every result must be interpreted with the key limitation that the email corpus and the separate password corpus were not linked to one another.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If you receive a match, secure the devices you use before changing credentials; otherwise, active malware could capture the replacements. Update the operating system, browser and applications, run a full scan with trusted security software, and remove unfamiliar browser extensions, startup items and remote-access tools. If suspicious behavior continues, disconnect the device and consider professional investigation or a clean installation. From a device you trust, change credentials for critical services, beginning with the primary email account. \u003Cstrong>Replace every reused password with a unique, randomly generated one\u003C\u002Fstrong>; minor variations are not sufficient. Sign out active sessions, review recovery addresses and forwarding rules, and enable multi-factor authentication or passkeys wherever available. Open services independently instead of signing in through links in warning messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to create a long, unique credential for every account so one stolen password cannot spread to other services. Prefer phishing-resistant security keys or passkeys on email, financial and administrative accounts. Keep automatic updates, firewalls and real-time protection enabled, obtain software only from official sources and avoid running unexpected attachments. Review browser-stored passwords, sessions and extensions regularly. Organizations can reduce the effect of malware-derived credential loss through managed endpoint protection, centralized logging, privileged-access controls and mandatory multi-factor authentication. Offline, tested backups improve recovery when a malware loader leads to ransomware. Do not trust a sender merely because they know a real email address; verify security notices through an independent channel and open the service's known domain yourself.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check each current and historical email address you used around the Operation Endgame period. A match means the address appears among the 16,466,858 unique emails transferred from the law-enforcement operation; it does not mean a specific password hash was linked to that address or that your device is currently infected. If you receive a result, confirm device security before removing old password reuse, then inspect mailbox sessions and recovery settings and enable multi-factor authentication on important accounts. Because passwords were separated from addresses in this collection, assess password exposure separately through a privacy-preserving password check or a trusted password manager. Never enter a password, password hash, one-time code or payment detail into the search field. No result is an absolute guarantee because a different address, unidentified malware dataset or another incident may apply. If a device shows suspicious symptoms, investigate the device as well as changing account credentials.\u003C\u002Fp>","","Operation Endgame Malware Exposure (16.5 Million Email Identifiers)","Operation Endgame Malware Exposure. 16.5 Million email identifiers were reported. Reported data: Email addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Foperation_endgame_official.webp",false,{"name":35,"sector":36,"country":29,"website":9,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":22},"Operation Endgame","Law enforcement and malware disruption"]