INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Europol Seizes LeakBase Data Breach Site

| 2026-03-05 09:45 MEDIUM MEDIUM
Executive Summary AI-generated
The coordinated action on March 3 has led to arrests, house searches and "knock-and-talk" interviews by police in the US, Australia, Belgium, Poland, Portugal, Romania, Spain, and the UK. Europol Operation Seizes LeakBase Data Breach Site is a global operation that recently resulted in disruption of notorious Tycoon2FA phishing-as-a-service site, responsible for tens of millions of phishing messages reaching over 500,000 organizations each month worldwide. The latest attempt to disrupt stolen data trade has been taken down following a law enforcement operation coordinated by Europol, which revealed the world's largest online forum for stolen data was dismantled and those who believed they could hide behind anonymity are being identified and held accountable.
Technical Mitigations AI-generated
* Implement robust encryption and secure communication protocols, such as HTTPS (Hypertext Transfer Protocol Secure) or TLS (Transport Layer Security), to protect data transmitted between users and the platform. * Utilize secure authentication mechanisms, like multi-factor authentication (MFA), to verify user identities and prevent unauthorized access to sensitive information. * Regularly update software and plugins to patch vulnerabilities and fix security flaws, ensuring that the platform remains secure against emerging threats. * Conduct regular backups of critical data and systems to ensure business continuity in case of a cyber attack or system failure. * Implement a robust incident response plan, including procedures for responding to data breaches, identifying and containing incidents, and notifying affected parties.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation LeakOperation LeakOperation Seizes LeakBaseOperation Seizes LeakBase
Target & Sectors
BENELUX BENELUX governmentgovernment
Incident Timeline
March 3 and 4, 2026
Threat actors used LeakBase to target the U.K. and conducted arrests in conjunction with Operation Leak, a disruption exercise codenamed Europol.
source_region Australia
source_region Belgium
source_region Poland
source_region Portugal
source_region Romania
source_region Spain
campaign Operation Leak
attribution Europol
March 3 and 4
The FBI shut down LeakBase on March 3 and 4 by seizing two of its domains.
attribution FBI
attribution Leakbase
June 2021
The incident occurred in June 2021 when threat actors used a compromised version of the LeakBase platform to target and breach Europol's website.
April 2023
Russian Federation accessed LeakBase data breach site through Europol Operation.
target_region Russian Federation
2025-03-05
Threat actors used a compromised account to gain access to the LeakBase data breach site on 2025-03-05.
data_breach 1.8 credentials
general_metric 800 %
the first half of 2025
Threat actors used a compromised account to gain access to the credentials.
data_breach 1.8 credentials
general_metric 800 %
December 2025
The threat actors used the Microsoft platform to target and disrupt Tycoon2FA, a notorious phishing-as-a-service site.
organisation the U.S. Department of Justice (DoJ
data_breach 142,000 members
general_metric 215,000 messages
victims 142,000 registered users
victims 000 registered users
general_metric 000 private messages
organisation RaidForums
organisation BreachForums
organisation Microsoft
victims 500,000 organizations
organisation Europol’s European Cybercrime Centre
organisation MFA
financial 37 Europol
2026-02-03
SpyCloud revealed that Europol's Seizes LeakBase data breach site was compromised by SpyCloud.
organisation SpyCloud
3 March
Law enforcement authorities carried out coordinated enforcement actions across multiple jurisdictions on 3 March.
March 3
Law enforcement agencies carried out coordinated actions worldwide on March 3, including arrests and house searches targeting the LeakBase forum.
source_region Australia
source_region Belgium
source_region Poland
source_region Portugal
source_region Romania
source_region Spain
source_region United States
source_region United Kingdom
attribution Coordinated
general_metric 100 enforcement actions
general_metric 37 interventions
2026-03-04
Europol announced the seizure of RaidForums, a cybercrime marketplace that had been breached in 2022 and 2023.
general_metric 100 enforcement actions
organisation Europol
organisation RaidForums
organisation BreachForums
source_region United States
4 March
Threat actors used a malware tool to compromise Europol's network and gain access to LeakBase, then moved the site to a law enforcement splash page.
Mar 05, 2026
Threat actors used a compromised version of the popular open-source web application Nginx to gain unauthorized access and subsequently breached LeakBase, a data storage service.
2026-03-05
The FBI and Europol seized the LeakBase cybercrime forum.
data_breach 142,000 members
victims 45 targets
organisation LeakBase
organisation ARES
organisation The Federal Bureau of Investigation
organisation Leatherman
organisation IP
organisation BloodyMery
organisation OrderCheck
organisation TSR
organisation Europol
organisation The Red Report 2026
organisation Recorded Future News
organisation the White House’s
organisation Europol’s European Cybercrime Centre
organisation SecurityAffairs
05, 2026
Ravie Lakshmanan  Mar 05, 2026 Malware / Dark Web.
tactic T1588.001 - Malware
organisation LeakBase
Tactical Metrics
Metrics
data_breach
142,000
Members
Metrics
victims
45
Targets
Metrics
victims
500,000
Organizations
Metrics
data_breach
1,800,000,000
Credentials
Metrics
victims
142,000
Registered Users
Metrics
financial
37
Europol
Metrics
victims
0
Registered Users
Intelligence Sources