Operation Leak Shuts Down LeakBase Cybercrime Forum, Authorities Seize User Data and IP Logs

In a major win for global cybersecurity, the FBI, alongside international law enforcement, executed “Operation Leak” to dismantle LeakBase, a notorious cybercriminal forum.

This platform served as a hub for threat actors to trade stolen databases, credentials, and corporate data.

On March 4, 2026, authorities seized its domains leakbase[.]ws and leakbase[.]la, redirecting them to an FBI seizure banner.

LeakBase emerged rapidly after BreachForums’ takedown, attracting hackers with sections for initial access brokers, ransomware affiliates, and data dumps.

It hosted leaks from breaches like user credentials and credit cards, mirroring markets disrupted in prior ops like Qakbot.

The operation relied on U.S. and German court orders. A warrant from the U.S. District Court for the District of Utah, led by the U.S.

Attorney’s Office and DOJ’s CCIPS invoked Title 18 (asset forfeiture) and Title 21 (access device fraud) of the U.S. Code. Domains now use FBI nameservers: ns1.fbi.seized.gov and ns2.fbi.seized.gov.

DomainRegistration DateSeizure UpdateStatus
leakbase.wsFeb 7, 2026Mar 4, 2026FBI seizure banner
leakbase.laUnknownMar 4, 2026FBI seizure banner

This mirrors tactics in Blacksuit ransomware seizures.

Secured Evidence and Investigative Risks

Authorities preserved all forum data, including user accounts, posts, private messages, stolen credentials, and full IP logs. This trove enables attribution via IOCs like logged IPs tied to posts.

IOC TypeDescriptionPotential Use Case
IP LogsFull access histories of usersGeolocation, deanonymization
User AccountsHandles, emails, crypto walletsCross-referencing breaches
Forum PostsData samples, trade logsRansomware TTP mapping (MITRE ATT&CK T1486)

The FBI warns: interference risks charges. A tip line at FBI-SU-Leakbase@fbi.gov urges users to cooperate.

LeakBase’s fall disrupts the data-leak ecosystem, raising entry barriers for new actors. Organizations should scan for exposed creds using tools like Have I Been Pwned and enforce MFA.

Mitigation StepActionPriority
Credential CheckQuery breach databasesHigh
Network MonitorBlock leakbase[.]ws/la IPsHigh
User ReportingContact FBI tip lineMedium

Timeline: Forum active ~1 month; seized Mar 4, 2026. This op signals escalating pressure on cyber forums, per CISA trends.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post Operation Leak Shuts Down LeakBase Cybercrime Forum, Authorities Seize User Data and IP Logs appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading