/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FBI seizes the domain of WeLeakInfo, a site offering usernames and passwords from data breaches for sale; WeLeakInfo claims to have 12B+ usernames and passwords

Site aggregated 12 billion usernames and passwords from over 10,000 breaches.  —  On Wednesday, police in the Netherlands

Ars Technica Sean Gallagher

Context & Ripple Effects

The seizure closes a loop that opened in 2017, when the FBI's takedown of LeakedSource — a subscription service selling access to 3.1 billion compromised credentials — first established that law enforcement would treat breach-data resale sites as criminal infrastructure rather than passive archives. Months later, Leakbase shut down with sources pointing to the Hansa dark-web raid, showing the pattern extended beyond US jurisdiction.

WeLeakInfo reprised the model at larger scale — 12 billion-plus credentials from over 10,000 breaches, sold as searchable access — and the joint FBI-Netherlands action shows the 2017 playbook is now standard: seize the domain, disrupt the customer base, and signal that aggregation-for-sale is a target category. The same logic later reached forums, when the FBI took down BreachForums and its Telegram channel in 2024.

First-order effects

  • WeLeakInfo's paying customers immediately lose access to the credential database, and the site's operators face exposure of their buyer records to investigators in both the US and the Netherlands.
  • Anyone whose breached credentials were indexed in the service loses a criminal marketplace that made lookups of their passwords trivially easy for other attackers.

Second-order effects

  • Credential-stuffing operations that relied on WeLeakInfo as a cheap lookup source must migrate to rival services or raw breach dumps, raising their cost and fragmenting the market.
  • The joint US-Netherlands seizure gives other hosting and registrar jurisdictions a worked template, pressuring the next breach-data site to distribute its infrastructure across more countries to survive.

Third-order effects

  • The repeated takedowns — LeakedSource, Leakbase, WeLeakInfo, BreachForums — point to breach-data resale consolidating into a cat-and-mouse cycle where each seizure raises operational cost but does not eliminate demand, pushing the trade toward decentralized or invite-only channels.
  • For defenders, each seizure is a reminder that breached credentials circulate commercially for years, strengthening the case for organizations to assume credential reuse and prioritize breach-notification monitoring and passwordless authentication over breach-by-breach response.

The trend: Law enforcement is treating breach-data aggregation services as recurring targets for coordinated international seizures, converting a once-tolerated gray market into serially disrupted criminal infrastructure.

Discussion

  • @nca_lynneowens Lynne Owens on x
    A significant international investigation targeting every bit of the crime network. Please read to understand how crime is changing & how we are responding https://twitter.com/...
  • @nca_uk @nca_uk on x
    A website hosting stolen credentials has been taken down following an NCA-led investigation, in collaboration with international law enforcement partners @PoliceServiceNI, @Politie & @FBI. Full story ➡️ https://nationalcrimeagency.gov.uk/ ... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    @x0rz Arrested in Northern Ireland and Netherlands https://nltimes.nl/...
  • @troyhunt Troy Hunt on x
    Turns out that takedown notice of @weleakinfo was real: “The website sold subscriptions so that any user could access the results of these data breaches” https://www.justice.gov/...