Desk live·
ForensicPost
Ransomware/Enforcement/File 23-0404

Operation Cookie Monster Seized Genesis Market and Data From 1.5 Million Machines

Genesis Market offered data from more than 1.5 million infected computers — cookies, browser fingerprints and autofill alongside credentials. A stolen session is already past the login, which is why multi-factor authentication was not the obstacle buyers had to solve.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetGenesis Market
ActorUnattributed
D. Kennedy11 min readConfidence: high3 sources reviewed

On 4 April 2023 Genesis Market was seized in an operation led by the FBI and the Dutch National Police, coordinated across 17 countries and reported as Operation Cookie Monster. Reporting describes 119 arrests and 208 property searches.

The market offered data taken from more than 1.5 million computers, covering login details for more than 80 million accounts, with over two million people listed. What it sold was packaged as bots: browser fingerprints, cookies, saved logins and autofill data from an infected machine.

A Session Is Past The Door Already

The significant part of that inventory is the cookies. A password is a claim that has to be checked; a session cookie is the receipt showing the check already happened.

Replay a valid session and the second factor is not presented, because from the service’s perspective the authentication is historic. That is why we have recorded so many incidents where multi-factor authentication was in place and irrelevant — 22-0915, 22-1101, 22-0524 all defeated the factor at the moment of use, and a stolen session skips the moment entirely.

The Fingerprint Was The Product Feature

Selling the browser fingerprint alongside the cookie is what made the market unusual. Fraud detection works substantially by noticing that a session is being used from an unfamiliar device configuration; supplying the configuration defeats that check.

This is an anti-detection product, sold as a subscription with updates as the victim’s machine changed. We have recorded infostealer output at 26-0802 as the single most common origin it can name, and this is where that output was refined into something usable by people with no technical capability of their own.

What A Takedown Is Worth

This was among the largest operations of its kind, and the corpus does not treat it as decisive. At 26-0707 a botnet was reported rebuilt within six days of seizure.

The durable value of a takedown of this shape is the 1.5 million victims whose infections became known, and the two million identities that stopped being for sale on that particular counter. Whether the counter reopened elsewhere is the question the corpus keeps asking at 26-0716b and 26-0725, and the answer has generally been yes.

How we reported this

Compiled from law enforcement statements and contemporaneous reporting, listed below. The explanation of why a replayed session bypasses a second factor is this desk’s reasoning from how session authentication works, presented as such. No marketplace addresses, successor services or indicators are named or reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Takedown of online market that sold stolen account credentials — Operation Cookie MonsterEuropol / Eurojust
  2. Global police operation: arrests for online identity theft with millions of victimsPolitie
  3. ‘Operation Cookie Monster’: FBI seizes popular cybercrime forum used for large-scale identity theftCNN Politics
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary