FBI seizes the domain of WeLeakInfo, a site offering usernames and passwords from data breaches for sale; WeLeakInfo claims to have 12B+ usernames and passwords
Site aggregated 12 billion usernames and passwords from over 10,000 breaches. — On Wednesday, police in the Netherlands …
Context & Ripple Effects
The seizure closes a loop that opened in 2017, when the FBI's takedown of LeakedSource — a subscription service selling access to 3.1 billion compromised credentials — first established that law enforcement would treat breach-data resale sites as criminal infrastructure rather than passive archives. Months later, Leakbase shut down with sources pointing to the Hansa dark-web raid, showing the pattern extended beyond US jurisdiction.
WeLeakInfo reprised the model at larger scale — 12 billion-plus credentials from over 10,000 breaches, sold as searchable access — and the joint FBI-Netherlands action shows the 2017 playbook is now standard: seize the domain, disrupt the customer base, and signal that aggregation-for-sale is a target category. The same logic later reached forums, when the FBI took down BreachForums and its Telegram channel in 2024.
First-order effects
- WeLeakInfo's paying customers immediately lose access to the credential database, and the site's operators face exposure of their buyer records to investigators in both the US and the Netherlands.
- Anyone whose breached credentials were indexed in the service loses a criminal marketplace that made lookups of their passwords trivially easy for other attackers.
Second-order effects
- Credential-stuffing operations that relied on WeLeakInfo as a cheap lookup source must migrate to rival services or raw breach dumps, raising their cost and fragmenting the market.
- The joint US-Netherlands seizure gives other hosting and registrar jurisdictions a worked template, pressuring the next breach-data site to distribute its infrastructure across more countries to survive.
Third-order effects
- The repeated takedowns — LeakedSource, Leakbase, WeLeakInfo, BreachForums — point to breach-data resale consolidating into a cat-and-mouse cycle where each seizure raises operational cost but does not eliminate demand, pushing the trade toward decentralized or invite-only channels.
- For defenders, each seizure is a reminder that breached credentials circulate commercially for years, strengthening the case for organizations to assume credential reuse and prioritize breach-notification monitoring and passwordless authentication over breach-by-breach response.
The trend: Law enforcement is treating breach-data aggregation services as recurring targets for coordinated international seizures, converting a once-tolerated gray market into serially disrupted criminal infrastructure.