Skip to content
Back to the blog
Credential theft June 19, 2026

Amadey and StealC network dismantled: 27 million stolen passwords recovered

An international police operation coordinated by Europol has dealt a heavy blow to two of the tools most used by cybercriminals to steal information: Amadey and StealC. In mid-June 2026, the authorities, with the support of security companies, disconnected hundreds of servers and seized dozens of domains. The most striking result for users and businesses is that around 27 million credentials that had been stolen from infected computers have been recovered.

To understand why it matters, it helps to know how these threats work. Amadey acts as a “gateway” that paves the way for installing more malicious software. StealC belongs to the infostealer family: it scans the computer for saved passwords, session data and other sensitive files to send them to the criminals. Most worrying of all, both were sold as a service, so any criminal without much expertise could rent them. These stolen credentials are then often used for bank fraud and as a prelude to ransomware attacks.

Tip from Soporte Informático 360

If you suspect a computer may have been infected, immediately change your important passwords from a clean device and enable two-step verification. Avoid saving passwords in the browser: use a password manager and keep your antivirus and system up to date.

Source: Europol. Summary prepared by our team for informational purposes.

Do you think a device may be compromised?

We help you check it, clean it and protect it. Write to us with no obligation.

Get help