/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Leakbase, which indexed and sold passwords from major data breaches, shuts down; sources say closure may be tied to raid of Hansa dark web market

Brian Krebs / Krebs on Security :

Krebs on Security Brian Krebs

Context & Ripple Effects

Leakbase's closure is the second time in 2017 that a commercial breach-credential index has gone dark under legal pressure, following the January takedown of LeakedSource, which sold access to a database of 3.1B+ compromised account passwords after an alleged police raid. Brian Krebs' sourcing ties this one to the raid on the Hansa dark web market rather than to a direct action against Leakbase itself.

The story matters because it sketches a repeatable enforcement template: authorities reach these resale operations through adjacent infrastructure — marketplaces, hosting, payment rails — rather than frontally. The pattern holds across the decade, from the FBI's domain seizure of WeLeakInfo in 2020 to a 14-country operation that shut down a LeakBase forum with 142K+ members in 2026.

First-order effects

  • Leakbase's paying customers immediately lose searchable access to its indexed breach-password database, and whoever operated the service exits a business model that two prior seizures had already shown carries direct police risk.
  • Hansa's user base and vendors absorb the fallout, as the market raid that sources connect to Leakbase's closure demonstrates how action against one underground venue cascades into dependent services.

Second-order effects

  • Rival credential-resale sites face the demonstrated playbook: LeakedSource's alleged raid, then the FBI's seizure of WeLeakInfo's domain, then the multinational LeakBase takedown each raised the operational cost of running a public-facing breach-index storefront.
  • Buyers of bulk compromised credentials get pushed toward less centralized channels — private forums and brokered sales — where discovery by investigators like Krebs' sources becomes harder but so does reliable access for legitimate security researchers who used these indexes for exposure checking.

Third-order effects

  • If the enforcement arc continues, selling access to stolen breach databases as a polished commercial service becomes structurally unviable, leaving credential markets fragmented across jurisdictions and forcing defenders to rely on their own telemetry rather than third-party leak aggregators.
  • Cross-border coordination scales with the target: what began as single-site actions grows into the kind of 14-country operation seen in 2026, signaling that transnational task forces are becoming the standard instrument against cybercrime infrastructure.

The trend: Law enforcement is dismantling the commercial market for stolen breach credentials site by site, using raids on adjacent dark web infrastructure as the entry point.