/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LeakedSource, a site that sold access to a database of 3.1B+ compromised account passwords, taken offline after alleged police raid

Dan Goodin / Ars Technica :

Ars Technica Dan Goodin

Context & Ripple Effects

LeakedSource ran a search engine over more than 3.1 billion compromised account passwords, drawing data from major 2016 breaches at LinkedIn, MySpace, and VK.com and claiming it could crack 99% of the passwords from the FriendFinder Networks breach affecting 412M accounts. Its willingness to actively crack stored hashes into plaintext is what separated it from passive archive sites — and what made it a target.

First-order effects

  • The alleged police raid takes offline the easiest commercial lookup point for credentials tied to hundreds of millions of accounts across LinkedIn, MySpace, VK.com, and FriendFinder Networks, cutting off both paying subscribers and the site's own cracking pipeline.
  • LeakedSource's operators now face direct legal exposure rather than the takedown-and-rebrand cycle that breach-archive sites previously treated as a cost of doing business.

Second-order effects

  • Rivals in the same trade read the raid as enforcement against the business model itself: within months, Leakbase shut down, with sources tying its closure to the Hansa dark web market raid, and in 2020 the FBI seized WeLeakInfo's domain outright.
  • Defenders lose a convenient (if unsavory) way to check whether their users' credentials appear in breach corpora, shifting exposure-checking toward services like Have I Been Pwned-style lookups that don't sell plaintext.

Third-order effects

  • If the pattern holds — LeakedSource raided, Leakbase closed, WeLeakInfo seized — paid credential-search engines migrate from the open web to dark-web infrastructure, where the same data resurfaces as extortion leverage, as Lapsus$'s threatened release of ~1B Salesforce-hosted records on a dark-web leak site illustrates years later.
  • Enforcement against breach-data brokers becomes a recurring law-enforcement category rather than a one-off, forcing the market for stolen credentials to price in seizure risk.

The trend: Law enforcement is treating commercial breach-data search engines as criminal infrastructure, steadily pushing the stolen-credentials market off the indexed web and onto dark-web leak sites.