LeakedSource, a site that sold access to a database of 3.1B+ compromised account passwords, taken offline after alleged police raid
LeakedSource garnered criticism for actively cracking the passwords it sold. — LeakedSource, a legally and ethically questionable website that sold access …
Context & Ripple Effects
LeakedSource was not a passive dump site: it sold search access to more than 3.1 billion compromised credentials and actively cracked passwords for paying customers, claiming it could crack 99% of the passwords from the FriendFinder Networks breach affecting 412M accounts, alongside data from the 2016 LinkedIn, MySpace, and VK.com breaches. The alleged police raid that took it offline is the first enforcement action against this business model in the corpus.
The pattern repeats quickly: within the year, [[a:924618|Leakbase, a similar password-indexing service, shuts down with sources tying its closure to the Hansa dark web market raid]], and by 2020 the FBI seizes the domain of WeLeakInfo, which claimed 12B+ usernames and passwords for sale. Each takedown has pushed credential monetization further from open-web subscription services.
First-order effects
- LeakedSource's paying customers immediately lose search access to the 3.1B+ credential database, and its operators face direct legal exposure from the raid rather than operating behind legal ambiguity.
- Users whose passwords LeakedSource had already cracked — including up to 412M FriendFinder accounts — now have confirmed plaintext credentials in third-party hands, sharpening the case for password resets beyond what the original breaches alone implied.
Second-order effects
- Displaced demand migrates to adjacent venues like Raidforums, where community databases such as Cracked.to's user records circulate — but those successors inherit the same enforcement target on their backs, as Leakbase's closure linked to the Hansa raid shows.
- Companies named in LeakedSource's indexed breaches (LinkedIn, MySpace, VK.com, FriendFinder Networks) face renewed pressure to force credential rotations, since a searchable, crackable index is more actionable to attackers than raw dumps.
Third-order effects
- If the enforcement sequence holds — LeakedSource raided, Leakbase closed, WeLeakInfo's domain seized by the FBI — commercial breach-data resale on the open web becomes structurally untenable, pushing monetization toward dark-web channels like the Lapsus$ leak-and-extortion site threatening ~1B Salesforce-hosted records.
- The crackdowns redefine the line between 'breach research' and criminal facilitation: services that merely indexed leaks survived scrutiny longer than ones that actively cracked passwords for sale, suggesting active cracking is what converts a database into a prosecutable enterprise.
The trend: Law enforcement is systematically dismantling commercial breach-credential marketplaces, driving credential monetization from open-web subscription services toward dark-web leak-and-extortion operations.