By visiting our site, you agree to our privacy policy regarding cookies, tracking statistics, etc.
Apply now for free support from our Cybersecurity Services Centre
Apply for free cybersecurity support
Attend the Ransomware Defence Summer Bootcamp in Amsterdam, June 2026
Attend our free summer bootcamp on ransomware defence
Enroll in the Foundations of Cybersecurity and AI online live course
Learn online about the foundations of cybersecurity and AI
From May 16-21, Microsoft’s Digital Crimes Unit, with U.S. and European authorities, carried out a takedown of the Lumma Stealer infostealer infrastructure. Following a U.S. court order, Microsoft seized and helped block ~2,300 domains used to distribute the Lumma malware. Lumma Stealer (malware-as-a-service) had infected ~394,000 Windows computers globally and was being used by multiple ransomware groups to steal credentials for follow-on attacks. The operation (“Disrupting Lumma”) significantly hampered the malware’s reach, though criminals later attempted to reconstitute their infrastructure.