Leakbase, which indexed and sold passwords from major data breaches, shuts down; sources say closure may be tied to raid of Hansa dark web market
Brian Krebs / Krebs on Security :
Context & Ripple Effects
Leakbase's closure is the second time in 2017 that a commercial breach-credential index has gone dark under legal pressure, following the January takedown of LeakedSource, which sold access to a database of 3.1B+ compromised account passwords after an alleged police raid. Brian Krebs' sourcing ties this one to the raid on the Hansa dark web market rather than to a direct action against Leakbase itself.
The story matters because it sketches a repeatable enforcement template: authorities reach these resale operations through adjacent infrastructure — marketplaces, hosting, payment rails — rather than frontally. The pattern holds across the decade, from the FBI's domain seizure of WeLeakInfo in 2020 to a 14-country operation that shut down a LeakBase forum with 142K+ members in 2026.
First-order effects
- Leakbase's paying customers immediately lose searchable access to its indexed breach-password database, and whoever operated the service exits a business model that two prior seizures had already shown carries direct police risk.
- Hansa's user base and vendors absorb the fallout, as the market raid that sources connect to Leakbase's closure demonstrates how action against one underground venue cascades into dependent services.
Second-order effects
- Rival credential-resale sites face the demonstrated playbook: LeakedSource's alleged raid, then the FBI's seizure of WeLeakInfo's domain, then the multinational LeakBase takedown each raised the operational cost of running a public-facing breach-index storefront.
- Buyers of bulk compromised credentials get pushed toward less centralized channels — private forums and brokered sales — where discovery by investigators like Krebs' sources becomes harder but so does reliable access for legitimate security researchers who used these indexes for exposure checking.
Third-order effects
- If the enforcement arc continues, selling access to stolen breach databases as a polished commercial service becomes structurally unviable, leaving credential markets fragmented across jurisdictions and forcing defenders to rely on their own telemetry rather than third-party leak aggregators.
- Cross-border coordination scales with the target: what began as single-site actions grows into the kind of 14-country operation seen in 2026, signaling that transnational task forces are becoming the standard instrument against cybercrime infrastructure.
The trend: Law enforcement is dismantling the commercial market for stolen breach credentials site by site, using raids on adjacent dark web infrastructure as the entry point.