World Leaks is a cyber extortion group and former ransomware operation that emerged in 2025 as a rebrand of Hunters International. The group is also referred to as WorldLeaks, world_leaks, and by its predecessor name Hunters International. Reporting indicates that after the rebrand the operators shifted emphasis away from file encryption and toward data theft, leak-site publication, and extortion based on stolen information. World Leaks has claimed responsibility for more than 100 breaches globally and has targeted organizations across a wide range of sectors and geographies, including manufacturing, financial services, healthcare, transportation, technology, agriculture, and critical-infrastructure-adjacent contractors. Publicly reported victims and claimed victims include major enterprises such as Nike, Tata Group and Tata Electronics, Reliance Group, and healthcare provider Centers Laboratory, as well as numerous mid-sized regional organizations in North America, Europe, Asia, and Latin America. The group’s operating model centers on unauthorized access, data exfiltration, and coercive publication of stolen material when ransom demands are not met. In multiple cases, World Leaks publicly claimed large-scale thefts of corporate and sensitive records and then released samples or broader datasets on its leak site. Reported victim data has included internal corporate documents, engineering and procurement records, supplier information, inspection and meeting records, financial and insurance documents, and in healthcare incidents, personal and medical information. World Leaks has been linked to several high-profile extortion events in 2025 and 2026. These include claims involving internal Nike data, extortion activity against Tata-linked entities, and publication of files associated with Reliance Group that were described as relating to the Kudankulam Nuclear Power Plant project in India. In the Kudankulam-related incident, the leaked material was reported to concern contractor-held engineering and balance-of-plant documentation rather than reactor safety or core nuclear systems, but the case drew attention because it involved data tied to a major critical infrastructure project. The group has also been associated with a significant healthcare breach affecting Centers Laboratory, where it claimed large-scale exfiltration of patient and corporate data. World Leaks should be understood as a financially motivated cybercriminal threat actor rather than a nation-state group. Its behavior is consistent with modern double-extortion and data-leak operations: compromise victim environments, steal high-value information, pressure victims for payment, and use public exposure to increase leverage. Its victimology and claimed activity indicate broad opportunistic targeting with willingness to pursue both large multinational brands and smaller regional enterprises.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Former ransomware operation identified as the predecessor brand from which World Leaks emerged.
Ransomware/extortion group accused of posting allegedly stolen Reliance-linked files, including material associated with the Kudankulam Nuclear Power Project, and seeking ransom payments before publishing data.
Conducted a ransomware-linked data exfiltration incident involving more than 19,000 files from infrastructure associated with the Kudankulam Nuclear Power Plant project.
Posted a large cache of allegedly stolen files on the dark web related to the Kudankulam Nuclear Power Plant, including purported facility blueprints and supplier details.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.