Skip to content
Back to Blog
high severity May 23, 2025 · 3 min read

Operation Endgame 2.0 Data Breach (2025)

If you are a customer of Operation Endgame 2.0, here’s what’s now in circulation.

In May 2025, a coalition of law enforcement agencies took down the criminal infrastructure behind the malware used to launch ransomware attacks in a new phase of "Operation Endgame". This followed the first Operation Endgame exercise a year earlier, with the latest action resulting in 15.3M victim email addresses being provided to HIBP by law enforcement. A further 43.8M victim passwords were also provided for HIBP's Pwned Passwords service.

Operation Endgame 2.0 Data Breach (2025)

On May 23, 2025, law enforcement agencies from multiple countries dismantled criminal infrastructure tied to Operation Endgame 2.0, exposing 15.4 million email addresses and 43.8 million passwords that had been harvested by malware used in ransomware campaigns.

Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

What's Publicly Reported from Reporting

Public reporting indicates the data came directly from victims of infostealer malware deployed as part of ransomware operations. Law enforcement collected the compromised credentials during the takedown and provided 15.3 million unique email addresses to Have I Been Pwned along with the full set of 43.8 million passwords for its Pwned Passwords service. The breach stems from the second phase of Operation Endgame, which followed a similar international effort one year earlier. No evidence suggests the credentials were stolen from a single company database; instead they represent aggregated harvests from infected consumer and small business machines over time.

The passwords were captured in plaintext or easily reversible formats by the malware, making them immediately usable for account takeovers wherever the same credentials were reused.

Why This Matters for You and Your Family

If any of your email addresses appear in the dataset, attackers now hold a working username-and-password combination that can unlock other accounts. For ordinary families this often means personal email, online banking, shopping sites, or school portals. Children’s accounts are frequently hit because parents reuse passwords across family devices or use the same email for a child’s gaming login. Once one account falls, attackers can reset linked services, read private messages, or demand payment to stop further exposure. The scale — 15.4 million affected emails — means many households will discover at least one compromised address.

The Doxxing and Identity-Chain Implications

Stolen email-password pairs rarely stay isolated. Attackers chain them with data from earlier breaches to map usernames, phone numbers, addresses, and family relationships. A credential from this incident can unlock a gaming account, reveal linked chat handles, and eventually surface your home address or children’s names. Public reporting describes this pattern as an “identity chain” that turns a single password leak into persistent harassment or targeted extortion. Gaming accounts belonging to children are especially vulnerable because they often share the same household email or password patterns, creating a direct path from ransomware malware to doxxing.

What to Do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup to break those chains.
  • Rotate the password used on any site that appears in the Operation Endgame 2.0 data anywhere it is reused, and switch to 2FA through an authenticator app instead of SMS.
  • Enable continuous DoxxScan monitoring across 13.1 billion+ breach records and 100-plus platforms so the next credential leak is caught and handled within hours rather than months.
  • Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts that often chain back to the same addresses and passwords.
  • Let remediation specialists handle takedown requests across data brokers and exposed profiles while you focus on securing your immediate accounts.

The incident shows that even large-scale law enforcement victories against ransomware groups leave ordinary families to clean up the credential fallout. Starting with concrete steps today limits how far attackers can travel down the identity chain. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and 100-plus platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts. Families who act quickly turn a widespread breach into a contained event rather than months of worry.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Operation Endgame 2.0 customer?
Operation Endgame 2.0 is one listing. Your email is probably in others.
15.4M accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed May 23, 2025
Last reviewed July 22, 2026
Affected 15.4M
Data exposed Email addressesPasswords
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email