/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FBI seizes the domain of WeLeakInfo, a site offering usernames and passwords from data breaches for sale; WeLeakInfo claims to have 12B+ usernames and passwords

Site aggregated 12 billion usernames and passwords from over 10,000 breaches.  —  On Wednesday, police in the Netherlands

Ars Technica Sean Gallagher

Context & Ripple Effects

WeLeakInfo's seizure is the third takedown in this corpus of a site whose business was reselling breached credentials. LeakedSource went offline after an alleged police raid in 2017 (LeakedSource's takedown), and Leakbase shut down weeks later with sources tying its closure to the Hansa dark web market raid (Leakbase's shutdown).

What distinguishes the WeLeakInfo action is scale and coordination: the site claimed 12 billion usernames and passwords aggregated from over 10,000 breaches, and the FBI acted alongside Dutch police — the same cross-border playbook later applied when the FBI took down BreachForums in 2024 (BreachForums seizure).

First-order effects

  • WeLeakInfo's paying customers lose access to a searchable database of 12 billion+ credential pairs, cutting off a ready-made toolkit for credential-stuffing and account-takeover attempts.
  • The FBI and Dutch police gain the site's infrastructure and records, a template for identifying both the operators and the buyers of stolen data.

Second-order effects

  • Credential resellers face a demonstrated enforcement pattern — LeakedSource, Leakbase, WeLeakInfo — pushing remaining operators toward darker channels like forums and dark web markets rather than open subscription sites.
  • Organizations breached in the underlying 10,000+ incidents get a window: credentials exposed on a commercial marketplace are harder for attackers to reach while the aggregator is down, briefly lowering account-takeover pressure on their users.

Third-order effects

  • The recurring pattern points toward credential-market takedowns as routine, internationally coordinated law enforcement work rather than exceptional actions — raising the operating risk of any site that monetizes breach data at scale.
  • If aggregators keep getting seized, breach data monetization migrates to decentralized or invitation-only channels, which are harder to seize but also harder for ordinary criminals to access.

The trend: Law enforcement is systematically dismantling the commercial market for breached credentials, with each seizure — LeakedSource, Leakbase, WeLeakInfo, BreachForums — normalizing cross-border action against sites that resell stolen data.

Discussion

  • @nca_lynneowens Lynne Owens on x
    A significant international investigation targeting every bit of the crime network. Please read to understand how crime is changing & how we are responding https://twitter.com/...
  • @josephfcox Joseph Cox on x
    @x0rz Arrested in Northern Ireland and Netherlands https://nltimes.nl/...
  • @nca_uk @nca_uk on x
    A website hosting stolen credentials has been taken down following an NCA-led investigation, in collaboration with international law enforcement partners @PoliceServiceNI, @Politie & @FBI. Full story ➡️ https://nationalcrimeagency.gov.uk/ ... https://twitter.com/...
  • @troyhunt Troy Hunt on x
    Turns out that takedown notice of @weleakinfo was real: “The website sold subscriptions so that any user could access the results of these data breaches” https://www.justice.gov/...