Desk live·
ForensicPost
Ransomware/Enforcement/File 26-0624

Operation Endgame Seized 326 Servers and Recovered 27 Million Credentials

The June 2026 phase of Operation Endgame disrupted the infrastructure behind Amadey, StealC and SocGholish. The credential recovery figure is the part defenders can act on.

Constructed geometry · not a chart of case data
TargetAmadey, StealC, SocGholish infrastructure
ActorMultiple
S. Rosler11 min readConfidence: high2 sources reviewed

Between 15 and 19 June 2026, Europol and agencies from Canada, Denmark, Germany, the Netherlands, the United Kingdom and the United States disrupted infrastructure behind three malware families — Amadey, StealC and SocGholish — as the latest phase of Operation Endgame.

The published totals: 326 servers and 142 domains taken down, more than $46 million in cryptocurrency identified and frozen, and approximately 27 million stolen credentials recovered from over 385,000 compromised systems.

The Recovered Credentials Are The Useful Output

Server seizure figures are the headline and the least durable result. Infrastructure is rented, and rebuilding it is a procurement exercise measured in days.

Twenty-seven million credentials recovered from 385,000 systems is different in kind. Those are specific accounts belonging to specific people and organisations, and once in the hands of agencies and notification services they can be pushed into password-reset workflows and breach-notification feeds. That effect does not depend on the operators staying offline.

Loaders Are The Layer Worth Disrupting

None of the three families named is ransomware. Amadey and StealC are loaders and stealers; SocGholish is a delivery framework. They sit upstream of ransomware in the access market — establishing the foothold and harvesting the credentials that ransomware affiliates later buy.

That targeting is deliberate and, we think, correct. Ransomware brands are numerous, rebrand frequently and are difficult to attribute to individuals. The access layer underneath them is more concentrated, more commercial and more traceable — because somebody has to be paid.

The measure worth watching over the next two quarters is not whether these families return. It is whether the price of initial access moves.

How we reported this

Compiled from published law-enforcement announcements and reporting, listed below. Seizure and recovery figures are as published by the agencies involved. Corrections: corrections@forensicpost.com.

Sources
  1. Europol seizes 326 servers targeting ransomware supply chainPaubox
  2. Europol disrupts AudiA6 crypto laundering service used by ransomware gangsThe Hacker News
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary