The Mistake That Exposed a Global Cyber Crime Operation
Check Point, Tuesday, August 18th, 2026
Check Point Research says OPSEC failures by the StopAndProtect operation exposed its own infrastructure and 5,000+ victims.
Check Point Research describes an unusual investigation into a cyber crime operation called StopAndProtect, in which the attackers exposed themselves.
While analyzing the newly identified operation, researchers found a series of operational security mistakes that left the group's own infrastructure open. What they recovered included victim logs, screenshots, source code, internal management tools and evidence of a campaign affecting more than 5,000 infected computers worldwide.
Most investigations reveal only the aftermath of an attack, whereas this one exposed the attackers themselves. The investigation also uncovered files pointing to the operators' identities.