By NHI Mgmt Group Editorial TeamBased on SumSub: “Europol Freezes $47M in Crypto During Global Malware Crackdown” (June 26, 2026)

TL;DR: Europol’s latest Operation Endgame phase froze more than €41 million in cryptocurrency, seized 326 servers, recovered nearly 27 million stolen credentials, and cleaned almost 15,000 infected websites, underscoring how password, browser-data, and wallet theft now sits at the centre of cybercrime infrastructure, according to SumSub. Credential theft at this scale turns identity exposure into an ecosystem problem, not an isolated endpoint event.


At a glance

What this is: This is a brief on Europol’s Operation Endgame phase, which disrupted malware infrastructure tied to password, browser-data, and crypto wallet theft at global scale.

Why it matters: It matters because stolen credentials, browser data, and wallet secrets can rapidly turn into account takeover, fraud, and downstream identity abuse across human, NHI, and financial ecosystems.

By the numbers:

  • Law enforcement froze more than €41 million in cryptocurrency during the operation.
  • Authorities seized 326 servers and took down 142 domains linked to the campaign.
  • Researchers recovered nearly 27 million stolen credentials from more than 385,000 compromised devices.

Context

Malware that steals passwords, browser data, and wallet secrets turns identity compromise into an industrial process. Once the malware ecosystem can harvest credentials at scale, the security problem is no longer a single infected endpoint but a distributed identity supply chain that feeds account takeover, fraud, and persistent access.

For identity programmes, the important question is not only how malware gets in, but how often stolen credentials remain valid after theft. That is where lifecycle controls, secrets hygiene, and user recovery processes intersect with threat disruption.

This article is about a large-scale law-enforcement disruption, and the operating model it exposes is typical of modern credential theft campaigns rather than an isolated variant.


Key questions

Q: What breaks when malware steals passwords and browser data at scale?

A: What breaks is the assumption that a credential is only dangerous while the infected device is still active. Once passwords, browser artefacts, and wallet secrets are harvested, attackers can replay them elsewhere, often outside the original victim environment. That means containment has to include revocation, reset, and reuse detection, not just endpoint cleanup.

Q: Why does stolen credential volume matter for identity governance?

A: Because volume indicates whether exposure is an isolated event or a systemic trust problem. When millions of credentials are recovered in one operation, the issue is not just one account being compromised. It is whether organisations can identify reuse, revoke stale secrets, and stop the same identity from being accepted in multiple places.

Q: What are the signs that browser-based credential theft is affecting access control?

A: Watch for unexpected logins from new locations, repeated MFA prompts, session anomalies, and account activity that does not match normal device behaviour. Browser-data theft often produces access that looks legitimate at first because the attacker is replaying real credentials and session context rather than guessing passwords.

Q: Should security teams treat malware disruption and credential recovery as the same response?

A: They should be linked, but not treated as identical. Malware disruption reduces active infection, while credential recovery and revocation limit the downstream abuse of stolen identity material. The operational mistake is to stop at infrastructure takedown and assume the identity risk has disappeared with it.


Technical breakdown

How malware infrastructure turns credential theft into a pipeline

The article describes a classic malware economy: one family steals browser data and passwords, another establishes initial footholds, and a third spreads through fake update prompts to expand reach. That division of labour matters because credential theft is no longer a one-step event. Data harvest, device compromise, and downstream monetisation are separated across different operators and services, which makes the ecosystem resilient even when one node is taken down. For identity teams, the operational issue is that a stolen secret can surface far from the original infection point, often after the malware itself has been removed.

Practical implication: treat stolen credential detection and malware containment as linked workflows, not separate investigations.

Why browser-data theft is especially dangerous for identity control

Browser data is a high-value target because it often contains the working context of access: saved credentials, session artefacts, wallet extensions, and authentication breadcrumbs. When malware extracts this material, it can bypass some of the friction that password changes alone are meant to create. This is why browser-based theft is not just about passwords. It collapses the distance between a compromised endpoint and a live identity session, which is especially relevant where users rely on stored secrets or session persistence across devices.

Practical implication: harden browser and session controls wherever saved credentials or wallet extensions are part of the access path.

Why credential recovery and revocation are the real containment problem

The recovery of nearly 27 million stolen credentials shows that exposure scale can outlive the initial infection by a long margin. In practice, this turns into a governance problem: which accounts were exposed, which credentials are still active, and which systems trust the same secret in multiple places. The attack surface is not just the malware operator. It is every organisation that continues to accept stale credentials, reused passwords, or wallet secrets after the theft event has been detected.

Practical implication: build revocation and reauthentication playbooks that assume credential theft has already propagated beyond the first victim system.


Threat narrative

Attacker objective: The objective is to convert infected endpoints into reusable credential stock that supports account takeover, fraud, and broader cybercrime infrastructure.

  1. Entry occurred through fake browser update prompts on compromised websites, which distributed SocGholish and helped deliver additional malware.
  2. Credential harvesting followed as StealC and related tooling extracted passwords, browser data, and wallet seed phrases from infected devices.
  3. Escalation and spread occurred when Amadey was used to deploy additional malware after the initial infection, expanding the compromised footprint.
  4. Impact was realised through mass credential loss, infected website abuse, and support for ransomware and financial fraud operations.
  • CircleCI breach 2023: Malware stole a CircleCI engineer's SSO session; attackers exfiltrated customers' CI/CD secrets and keys, forcing a platform-wide rotation.
  • New York Times GitHub breach 2024: An exposed GitHub token gave an attacker The New York Times' repositories; the 270GB leak held 4,875 unique secrets.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Credential theft is now an ecosystem crime, not an endpoint event. The article shows malware families split across delivery, persistence, and data harvesting roles, which means no single control layer contains the harm. Identity programmes have to assume theft will be operationalised elsewhere, often long after the original compromise is cleaned up. Practitioners should treat credential abuse as a distributed lifecycle problem, not a malware-only problem.

Browser-data extraction creates an identity control blind spot. Password reuse, saved sessions, and wallet extensions turn browsers into high-yield access containers. That means the control boundary has moved from the endpoint alone to the user interaction layer where secrets are stored, cached, and automatically replayed. Teams that do not govern browser-held secrets are leaving a direct path from infection to account takeover.

Mass credential recovery exposes the weakness of static trust assumptions. Nearly 27 million stolen credentials recovered in one operation is a reminder that identity systems often trust secrets longer than attackers do. The governance assumption that a credential remains trustworthy until formally revoked is broken at scale by malware markets that trade in immediate reuse. Practitioners should recognise that trust in a secret decays the moment it is exposed.

Credential blast radius is the right concept for this threat pattern. The meaningful question is not how many endpoints were infected, but how many identities, sessions, and downstream systems became reachable after theft. That framing better aligns IAM, fraud, and security operations around the same problem set. Security leaders should measure how far one compromised credential can travel before controls stop it.

Law-enforcement disruption is useful, but it does not replace governance. The takedown of infrastructure reduces active pressure, yet the stolen data can still circulate through reuse, resale, and delayed exploitation. That creates a durable exposure tail for organisations that rely on incident timing rather than identity controls. Practitioners should assume the residual risk persists after the infrastructure is dismantled.

What this signals

Credential blast radius: The real risk is how far one stolen password, browser artefact, or wallet secret can travel before identity controls stop it. That shifts programme design toward exposure containment, reuse detection, and rapid revocation rather than only endpoint remediation.

Malware disruption campaigns can reduce active infrastructure without eliminating the underlying identity exposure. Practitioners should assume stolen credentials may remain exploitable even after the campaign is dismantled, which makes recovery workflows and trust revalidation the deciding controls.


For practitioners

  • Harden browser-based secret exposure Restrict saved passwords, session persistence, and wallet-extension use on managed devices where possible, and separate high-risk browsing from privileged work. Browser-held secrets are a direct bridge from fake update malware to identity compromise.
  • Prioritise credential revocation after malware notifications When a credential theft notification arrives, revoke the affected account and any shared or reused secrets before focusing on endpoint cleanup. The article’s scale shows that exposure often outlives the original infection window.
  • Reassess password reuse across consumer and enterprise contexts Map where the same secret could unlock both personal and corporate services, including crypto wallets and third-party logins. Reuse turns one stolen browser dataset into multiple identity compromises.
  • Tie fraud monitoring to stolen-credential intelligence Feed stolen-credential notifications into account takeover, payment fraud, and anomaly-detection workflows so security and fraud teams act on the same exposure signal.

Key takeaways

  • The article shows that malware ecosystems now industrialise credential theft across passwords, browser data, and wallet secrets.
  • Europol’s operation disrupted infrastructure at large scale, including millions of recovered credentials and thousands of infected sites.
  • Identity teams need revocation, reuse detection, and browser-secret controls because cleanup alone does not neutralise stolen access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article centres on passwords, browser data, and wallet secret theft.
NHI-07 — Long-Lived SecretsRecovered credentials remain dangerous when organisations trust them after theft.
Recommendation — Scan for exposed NHI secrets and revoke any secret that appears in malware or breach notifications. Shorten credential lifetime where possible and retire long-lived secrets that are reused across services.
MITRE ATT&CKTA0006;TA0040 — Credential Access; ImpactThe campaign’s purpose is credential harvesting that feeds wider criminal impact.
Recommendation — Map the campaign to credential-access and impact tactics to prioritise detection and containment.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementAuthenticator lifecycle governance is central when credentials are stolen at scale.
Recommendation — Apply authenticator-management controls to enforce revocation, rotation, and recovery after exposure.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsStolen credentials only become damaging when permissions remain trusted after compromise.
Recommendation — Review and reduce entitlements tied to exposed credentials so stolen access cannot move laterally.

Key terms

  • Credential Theft: Credential theft is the unauthorized capture of secrets used to authenticate a user or workload, such as passwords, MFA codes, or security questions. In SaaS environments, it usually produces login events that defenders can inspect, but it still becomes dangerous when attackers combine it with token abuse or integration misuse.
  • Browser-exposed secret: A credential, token, or other sensitive value that can be accessed through client-delivered code or related front-end workflows. These exposures are especially risky because they can be copied at scale, reused outside intended context, and remain valid until explicitly revoked.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Credential Reuse: Credential reuse happens when the same password, token, or secret can unlock multiple systems or sessions. It increases breach impact because one stolen credential can become a wide-ranging access path. The control problem is not only theft, but the amount of trust packed into each reusable secret.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org