LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Operation Endgame 2.0 Data Breach (2025)

CRITICAL severityConfirmedHow we verify

Operation Endgame 2.0 Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 23, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Operation Endgame 2.0 Data Breach (2025)

Reported May 23, 2025. Approximately 15.4M people affected.

CRITICAL
Severity
15.4M
People affected
2
Data types exposed
May 23, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Operation Endgame 2.0 data breach disclosed on May 23, 2025, exposed email addresses and passwords of 15.4 million individuals. Check if your credentials appear in breach databases and change passwords or enable two-factor authentication where necessary.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Operation Endgame 2.0 Data Breach (2025) breach?
15.4M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In May 2025, law enforcement agencies involved in the second phase of Operation Endgame provided a large set of victim records recovered from dismantled criminal malware infrastructure to the public breach-notification service Have I Been Pwned (HIBP). The material consists of approximately 15.4 million email addresses and a larger collection of passwords. Public reporting places the disclosure on 23 May 2025. The data originated from systems used by criminals to support ransomware attacks rather than from a conventional corporate network intrusion.

Because the records belong to people previously victimised by malware, the release matters for anyone whose credentials may have been harvested earlier. Exact technical details of how the infrastructure was seized remain limited in open sources, but the scale of the email list alone makes the incident relevant to millions of individuals.

Breaking down the breach

According to the available facts, a coalition of law enforcement agencies executed a new phase of Operation Endgame in May 2025. The action targeted criminal infrastructure that had been used to deploy malware for ransomware campaigns. This followed an earlier Operation Endgame exercise roughly one year prior. As a direct result of the latest takedown, law enforcement supplied HIBP with 15.3 million victim email addresses; a further 43.8 million victim passwords were also handed over for inclusion in HIBP’s Pwned Passwords service. The headline figure of people affected is given as 15.4 million. No additional counts, file inventories, dollar losses, or internal timelines have been disclosed in the source material. The method by which the data were extracted from the seized systems is not described beyond the statement that they were provided by law enforcement after the infrastructure was taken down.

How a breach like this happens

Incidents of this type typically begin when malware operators build and maintain large collections of stolen credentials obtained through phishing, trojans, or other infection vectors. Those collections sit on servers or botnets controlled by the criminals. When law-enforcement agencies identify and seize the infrastructure—through warrants, international cooperation, or technical disruption—they often recover the stored victim data. Rather than leave the material unused, agencies may share cleaned or hashed versions with public services such as HIBP so that affected people can check whether their addresses or passwords appear. The process does not require a fresh compromise of a legitimate company; it is the secondary release of data already stolen by criminals. Timing, exact seizure methods, and any intermediate handling steps are frequently kept confidential for operational reasons, which is consistent with the limited public detail available here.

Who is Operation Endgame 2.0?

Operation Endgame is a coordinated law-enforcement initiative aimed at dismantling the technical backbone of malware and ransomware operations. The “2.0” designation refers to a subsequent phase of activity that built on an earlier exercise. Participating agencies typically include national police forces, cybercrime units, and international partners. Their work focuses on servers, domains, and command-and-control systems rather than on any single commercial organisation. Because the operation recovers data belonging to victims of prior malware infections, the material it surfaces can include large volumes of email addresses and passwords that criminals had already collected. A release of this size is consequential precisely because it places previously private victim records into a publicly queryable database, allowing individuals to learn of exposure they might otherwise never discover.

The information in question

The facts name two categories of data as exposed: email addresses and passwords. Approximately 15.3 million email addresses and 43.8 million passwords were supplied to HIBP. No further data types—such as names, financial details, or device identifiers—are listed in the source material. Organisations and criminal infrastructures of the kind targeted by Operation Endgame commonly hold credential dumps harvested from infected machines; however, the exact contents beyond the two named categories remain unconfirmed. Readers should treat only the stated email addresses and passwords as verified elements of this release.

The real-world impact

For individuals whose email addresses appear in the set, the primary risk is that those addresses are now known to be associated with prior malware infections and may attract further phishing or credential-stuffing attempts. Passwords that match the supplied list, if still in use anywhere, can enable unauthorised access to accounts that reuse the same secret. The organisation—here the law-enforcement coalition—faces the operational necessity of handling large volumes of sensitive victim data responsibly while balancing transparency with ongoing investigations. No evidence in the facts indicates financial loss figures or confirmed secondary attacks stemming from this particular release; the concrete impact remains the public availability of the credential material itself.

If your data was in this breach

Anyone who suspects their information may have been among the recovered records can take a small number of practical steps:

These measures reduce the chance that previously stolen credentials can still be used against you. Public detail on the precise composition of the password list is limited to the count provided by law enforcement, so treating any reused password as potentially compromised remains the safest approach.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyOperation Endgame 2.0 security record
68/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Operation Endgame 2.0’s full breach history →

More recent breaches

WhiteDate Data Breach (2025)December 29, 2025Raaga Data Breach (2025)December 15, 2025Dragonica Lunaris Data Breach (2025)December 6, 2025Operation Endgame 3.0 Data Breach (2025)November 13, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Operation Endgame 2.0 Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram