you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / market watch
16 June 2026 market watch 4 min read

Operation Cookie Monster: How the FBI Dismantled Genesis Market

In early April 2023, visitors to one of the busiest credential shops on the dark web were greeted by an FBI seal and a seizure warrant from the U.S. District Court for the Eastern District of Wisconsin. Genesis Market was gone.

Operation Cookie Monster swept across 17 countries on April 4, producing 119 arrests, 208 property searches and 97 "knock and talk" interviews, while eleven domains connected to the market were seized in a single coordinated action, according to the U.S. Department of Justice.

A market that sold people, not products

What made Genesis different from most darknet markets? No drugs. No weapons. Genesis sold identities, packaged with the polish of a mainstream e-commerce site - searchable listings, FAQs, multilingual support tickets. Its inventory came as "bots": complete bundles harvested from malware-infected computers, containing saved passwords, active session cookies, browser fingerprints, partial IP addresses and autofill data. At seizure time, roughly 460,000 infected devices were listed, per Eurojust.

Fingerprints beat passwords

That packaging was the killer feature. A buyer did not simply get a username and password. With matching cookies and a cloned fingerprint loaded into Genesis's custom Genesium browser, a criminal could slip into a victim's bank or email account without triggering a password prompt - often bypassing multi-factor authentication entirely.
As Sophos researchers put it, customers weren't buying stale credentials but a de facto subscription to someone's digital life: as long as a victim's machine stayed infected, purchased profiles kept updating with new passwords, cookies and accounts (Sophos).
Prices scaled accordingly. A thin social-media profile might cost under a dollar, while access to multiple bank accounts fetched hundreds of dollars. The hackers behind the 2021 Electronic Arts breach reportedly got in via a $10 bot purchased on Genesis.

The database did the damage

The takedown's real weapon was data. The FBI obtained copies of Genesis Market's back-end servers, which held records on approximately 59,000 individual user accounts - usernames, email addresses, secure messenger handles, and full purchase and activity histories, officials briefed reporters (CyberScoop). Those records helped investigators uncover the true identities of many buyers. The FBI then sent hundreds of leads to partner agencies in Australia, Canada, Denmark, France, Germany, Italy, the Netherlands, Poland, Spain, Sweden and the United Kingdom, which executed the arrests and searches during the action days. The anonymity buyers assumed turned out to be thin. Unlike drug markets that ship physical goods and rely on crypto escrow, Genesis delivered instantly and settled directly in Bitcoin at dollar-denominated prices - leaving a clean ledger of who bought which victim, and when.

Private sector quietly paved the way

Law enforcement did not work alone. Researchers at Trellix and Computest said they were approached by investigators before the takedown to analyze Genesis-linked malware, with the explicit goal of "rendering the market's scripts and binaries useless" (Trellix). Dutch police also worked with Defion Research Labs, whose analysis of both the infostealer infection chain and the buyer-side browser extension revealed ways to detect users running the Genesis plugin. The infostealer ecosystem feeding the market included families like AZORult, Raccoon, Redline and DanaBot.
  • 119 arrests across 17 countries during the April 2023 action days
  • 208 property searches plus 97 knock-and-talk interviews
  • Roughly 460,000 infected devices listed for sale at seizure
  • About 59,000 user records exposed to investigators via seized back-end servers

Victim checks, sanctions and aftermath

The operation was as much about victims as suspects. The FBI shared millions of compromised email addresses and passwords with Have I Been Pwned, while Dutch police built a portal called CheckYourHack where anyone could check whether their credentials appeared in the Genesis leak. The U.S. Treasury sanctioned Genesis Market the same week, stating the service was believed to be based in Russia, and warned that U.S.-linked transactions with the entity would be blocked. In the UK alone, officers detained around two dozen people near Grimsby; Romanian raids reportedly surfaced cash and gold worth hundreds of thousands of dollars.

Why this takedown still matters

Seizing AlphaBay disrupted supply chains. Seizing Genesis detonated a customer database full of named, locatable buyers - the market itself was evidence. When the commodity is people, every transaction record points back to a suspect, or to a victim who never knew their browser had been cloned and sold. The practical takeaway hasn't aged a day: updated antivirus, unique passwords in a manager, phishing-resistant MFA wherever possible. Infostealer malware still feeds today's credential shops. Check your exposure via our onion status tools and related security notes, because the next Genesis is always under construction somewhere.

more notes

all news ›