The backbone is gone, but the real risk is now in the websites that were already compromised. Taking down SocGholish servers stops the current delivery network, yet stolen CMS credentials and unpatched WordPress, Joomla, or Drupal sites can be used to bring the same access path back.
Authorities in the Netherlands, Canada, the US, and Germany, with Europol support, seized 106 SocGholish servers and domains and disinfected about 15,000 infected WordPress sites. Site owners whose credentials were identified were told to change logins, enable MFA, delete suspicious accounts, and keep their CMS updated; SocGholish itself has long spread through fake browser-update prompts on legitimate sites.
That makes this a cleanup handoff, not a finish line. The infrastructure seizure reduces immediate distribution, but the compromised CMS layer can still be reused for reinfection and follow-on abuse if access and hidden persistence are not removed.