Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cybercrime-service-ecosystemenforcement-actionunderground-data-leak

International Law Enforcement Takedown of LeakBase Cybercrime Marketplace

Updated 3mo agoFirst seen Mar 6, 20262 sources

An international law-enforcement operation involving the FBI, Europol, and authorities across 14 countries seized infrastructure used by LeakBase, a major cybercrime marketplace/forum used to trade stolen data, exploits, and hacking services. Investigators reportedly seized LeakBase domains, displayed seizure banners, executed search warrants, and made arrests; forum data (including user accounts, messages, and IP logs) was preserved to support follow-on investigations and deterrence efforts.

Separate reporting in the same news cycle described other unrelated cyber developments, including Europol-led disruption of the Tycoon2FA phishing-as-a-service platform (used for adversary-in-the-middle MFA bypass), a guilty plea tied to the Phobos ransomware operation, a newly documented China-linked espionage cluster (CL-UNK-1068) targeting critical sectors in Asia, an unverified ShinyHunters extortion claim against Woflow, suspected DPRK-linked intrusions against cryptocurrency firms, and a pro-Iranian/pro-Palestinian ransomware ecosystem shift from Sicarii to BQTLock. Those items do not materially change the core LeakBase takedown but indicate continued pressure on cybercrime infrastructure alongside ongoing ransomware and espionage activity.

Share:
International Law Enforcement Takedown of LeakBase Cybercrime Marketplace
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 6, 20264mo ago

Researchers observe spike in retaliatory hacktivist activity

Security researchers reported a surge in retaliatory hacktivist operations following U.S.-Israel strikes on Iran, with most activity involving DDoS attacks, data leaks, and service disruption. The reporting also noted concurrent threats including SMS phishing malware and alleged IRGC-linked targeting of regional energy and digital infrastructure.

Researchers disclose Coruna iOS exploit kit and PlasmaLoader activity

Researchers reported a previously unknown iOS exploit kit called Coruna, with multiple exploit chains affecting iOS 13 through iOS 17.2.1. They said it had been used in surveillance-vendor-linked activity, suspected Russian espionage watering holes, and financially motivated fake sites, followed by deployment of a loader named PlasmaLoader for data theft.

Phobos-linked operator Evgenii Ptitsyn pleads guilty

Russian national Evgenii Ptitsyn, identified as a key figure in the Phobos ransomware ecosystem, pleaded guilty to conspiracy to commit wire fraud. Authorities said the ransomware operation affected more than 1,000 victims and generated tens of millions of dollars in ransom payments.

Authorities disrupt Tycoon2FA phishing-as-a-service platform

A multinational law-enforcement effort led by Europol disrupted the Tycoon2FA phishing-as-a-service operation and seized hundreds of domains used for phishing and command-and-control. The action was reported alongside the LeakBase takedown as a separate operation.

Mar 5, 20264mo ago

Operation Leak dismantles LeakBase cybercrime forum

An international law-enforcement operation involving 14 countries took the LeakBase cybercrime marketplace/forum offline. Europol and partner agencies publicly described the action as part of Operation Leak.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Affected products
3 linked
TelegramWebkitIos
Organizations
4 linked
RadwareAppleTelegramAT&T
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.