Policy & Regulation
LeakBase forum shut down by U.S. and European authorities
U.S. and European authorities have seized LeakBase, a forum accused of hosting stolen credentials, in a worldwide operation resulting in over 13 arrests.
U.S. and European law enforcement have seized the database from LeakBase, effectively shutting down a platform that has been operating since 2021. The seizure of the site occurred earlier this week, ending the operations of a forum that authorities say hosted over 142,000 members. According to officials, the platform’s database also contained more than 215,000 messages sent between its members. Earlier on Wednesday, the FBI—the U.S. federal law enforcement agency—redirected the site’s domain to nameservers controlled by the agency, completing the technical shutdown of the platform.
The shutdown was part of a coordinated response between the FBI and Europol, the European Union’s law enforcement agency. Together, police forces executed around 100 enforcement actions worldwide. A key focus of the operation was targeting the top 37 active users on the forum. According to Brett Leatherman, an FBI cyber official, the investigation resulted in over 13 arrests, searches, and interviews with 33 suspects. In an interview with the publication The Record, Leatherman confirmed that the joint operation also succeeded in capturing the forum’s entire database.
Prosecutors have characterized LeakBase as “one of the world’s largest online forums for cybercriminals,” pointing to its role in sharing stolen passwords and hacking tools. Before the seizure, the platform served as a continuously maintained archive of hacked databases. This archive included hundreds of millions of account credentials, credit card numbers, and banking account and routing information. Visitors attempting to access LeakBase are now greeted by a law enforcement seizure notice. The notice explicitly states that the forum’s contents, private messages, and IP address logs have been preserved by authorities.
Why it matters
This takedown is part of a broader, ongoing effort to dismantle sites that trade in stolen credentials, which are increasingly used to break into people’s accounts and steal data and cryptocurrency.