STOPANDPROTECT is a cybercrime operation identified by Check Point Research that has transformed nearly 2,000 hacked WordPress websites into a platform for malware distribution, data theft, and ransomware. The operation began in May 2026 and uses a deceptive CAPTCHA technique to lure visitors into executing a PowerShell command, subsequently downloading malware. This malware serves multiple purposes: encrypting files, stealing documents, providing a communication channel for attackers, and even spying on victims.
The compromised websites often utilized outdated WordPress versions, confirming the need for site security through regular updates and strong protections. Researchers discovered extensive amounts of victim data collected during the operation, leading to significant concerns over personal privacy and cybersecurity.