ConfirmedData breach

Operation Endgame 4.0: data obtained by malware

On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.

The record

Organisation
Operation Endgame 4.0as named by the source; not matched to a verified organisation
Records affected
4,348,526 records
Data exposed
Email addresses, Passwords
Sector
Not recorded
Occurred
2026-06-18
Disclosed
2026-06-18
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-06-18

Operation Endgame 4.0: data obtained by malware | NexaPulse