DIVD-2025-00018 - Victim Notification Operation Endgame 2.0
Our reference | DIVD-2025-00018 |
Case lead | Frank Breedijk |
Author | Max van der Horst |
Researcher(s) | |
CVE(s) |
|
Products |
|
Recommendation | If you received a notification from us, you, members of your organization or your customers had their password stolen or system infected by the Latradectus infostealer. Detailed recommendations are found below. |
Status | Open |
Last modified | 23 May 2025 18:14 CEST |
Summary
Last year, Operation Endgame marked the biggest anti-botnet operation to date. The The Dutch Police, in cooperation with police units from Germany, France, Denmark, the United States and United Kingdom and support from Europol and Eurojust had infiltrated a number of botnets. Now, they are back. Operation Endgame 2.0 marks new takedowns and new information obtained by the organizations behind this operation.
This data has been shared with us and various other parties like Have I Been Pwned, Spamhaus, Project No More Leaks, Project Check je Hack, the (Dutch) NCSC, CSIRT-DSP, and Digital Trust Center.
The data we have received consists of usernames, (redacted) passwords, and dates of these passwords last being used. It is expected that this data originates from the password managers of popular browsers.
What you can do
As these notifications mostly span user accounts, you should start with ensuring your system is clean from any malware. After, you should change the passwords of any accounts that are currently using the passwords indicated in the notification.
What we are doing
We have received the discovered data from the police, and are sending out notification to individuals and organizations that have fallen victim to compromise. To effectively do this, we are in close cooperation with the Dutch National Police as well as the NCSC, CSIRT-DSP and DTC.
Frequently asked questions
General
Q: Is this a scam?
A: It’s great that you’re skeptical. However, this is legit and definitely not a scam. This operation is a collaboration between the Dutch National Police, Europol, Digital Trust Center, NCSC and others. We, Dutch Institute of Vulnerability Disclosure (DIVD), are mentioned in the press releases from the Dutch Police and Europol. The ‘Check je Hack. (translation: Check your Hack) FAQ also mentiones DIVD and shares a link back to this casefile.
Q: Do you have my password?
A: No, we do not have your password. We may have sent you an email containing a partial password, with only the last four characters visible. This is the only part of your password we possess because the Dutch Police ensured that all passwords were hidden before sharing the data with us.
Q: Are you going to go after the criminals who stole my information?
A: No, we are not. That is a matter for law enforcement. As per article 9 of our code of conduct: We analyze online threats, not threat actors. We are researchers and don’t serve the needs of governments or law enforcement.
Q: if you “don’t serve the needs of governments or law enforcement”, why are you cooperating with the Dutch National Police on this case?
A: Acting on this data set is directly in line with article 3 of our code of conduct: Analyze databases with leaked credentials and report to the organizations or people who are compromised to take appropriate measures.
We analyze every database we receive, including those from law enforcement. However, we do this independently, without any obligation or intention to share any specific information in return.
Technical
Q: Do you know how the Dutch National Police obtained this information?
A: No we don’t know any details, but we know that Operation Endgame contains information from several criminal operations.
Q: Do you know from which criminal operation my data was obtained?
A: No, those details were not shared with us.
Legal
Q: You are processing my personal data without my consent, is that legal?
A: Yes it is. Under Dutch law and European privacy regulations, we can process this data based on a so-called “legitimate interest.” DIVD is a private foundation that operates under a strict code of conduct, with the aim to make the digital world safer.
Timeline
Date | Description |
---|---|
22 Apr 2025- 22 May 2025 |
Period of collecting data. |
23 May 2025 | Dutch National Police goes public with Operation Endgame 2.0. |
23 May 2024 ? |
DIVD sends out first notifications. |
More information
- Operation Endgame website
- Operation Endgame persbericht Nederlandse Politie
- Operation Endgame perbericht Europol
- Dedicated sub-page for Latrodectus personal accounts