/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

US DOJ says it seized the servers and domains of SlilPP, a marketplace for stolen login credentials, in a joint operation with Germany, Netherlands, and Romania

The US Department of Justice announced today it seized the servers and domains of SlilPP, a well-known online marketplace …

The Record Catalin Cimpanu

Context & Ripple Effects

The 2019 seizure of the xDedic hacked-server marketplace by the FBI and EU partners established the template this operation follows: seize domains and servers, then mine what is on them. SlilPP extends that playbook from access-to-servers to access-to-accounts — stolen login credentials are the raw input for account takeover, making this a strike at an upstream supplier rather than one crew's tooling.

It also continues a transatlantic pattern that has since hardened into routine: the DOJ's joint disruption of the RSocks botnet, its takedown of DDoS-for-hire websites, and Europol's arrests and server seizures behind Cracked and Nulled all paired US agencies with European counterparts against infrastructure that crosses borders even when the operators do not.

First-order effects

  • Credential sellers on SlilPP lose their storefront overnight, and buyers who relied on it for bulk stolen logins face immediate disruption to whatever fraud or intrusion pipelines depended on it.
  • Seized servers hand the DOJ, Germany, Netherlands, and Romania transaction records and communications identifying both vendors and buyers — turning a takedown into an investigation pipeline.

Second-order effects

  • Rival credential shops inherit displaced traffic, which raises their visibility and prices while concentrating risk in fewer targets for the next seizure.
  • Buyers shift toward channels harder to seize at once — Telegram groups, invite-only forums, direct broker relationships — forcing future operations to target people rather than domains.

Third-order effects

  • If the joint-seizure model keeps repeating — xDedic, RSocks, booter services, Cracked and Nulled, SlilPP — it becomes the standard operating procedure for cybercrime enforcement, with European partners as permanent co-signatories rather than occasional collaborators.
  • Each successful domain seizure erodes the open-market layer of the stolen-data economy, pushing it structurally toward closed, trust-based networks where entry costs rise and smaller operators are squeezed out.

The trend: Cross-border law-enforcement seizures of cybercrime marketplaces have become a recurring playbook that progressively displaces stolen-data trading from public markets into closed channels.

Discussion

  • @miekeeoyang Mieke Eoyang on x
    It's been a good week for DOJ & the @FBI. It's been a bad week for cyber criminals. https://www.justice.gov/...
  • @fbiwfo FBI Washington Field on x
    Today, #DOJ announced its participation in a multinational operation involving actions in the U.S., Germany, the Netherlands, and Romania to disrupt and take down the infrastructure of the online marketplace known as Slilpp. Learn more at @TheJusticeDept: https://www.justice.gov/…
  • @ericgeller Eric Geller on x
    DOJ says it worked with authorities in several other countries to take down a cybercrime marketplace selling more than 80 million usernames and passwords for more than 1,400 websites. https://www.justice.gov/... https://twitter.com/...
  • @thejusticedept Justice Department on x
    Slilpp Marketplace Disrupted in International Cyber Operation Slilpp was a Marketplace for Allegedly Stolen Online Account Login Credentials, Offering Over 80 Million Stolen Credentials for Over 1,400 Victim Providers Worldwide https://www.justice.gov/...
  • @campuscodi Catalin Cimpanu on x
    NEW: The FBI has seized SlilPP, one of the oldest marketplace for selling stolen login credentials https://therecord.media/... https://twitter.com/...