WorldLeaks, also styled World Leaks, is a financially motivated cyberextortion operation launched in January 2025. Group-IB reported that the operators behind Hunters International introduced the project as an extortion-only successor, replacing the earlier brand’s double-extortion model with data theft and threatened disclosure. WorldLeaks is therefore commonly treated as a Hunters International rebrand, although public evidence does not establish that every former affiliate or operator continued with the new operation.
The group is classified here as a ransomware group because of that operational lineage and its place in the ransomware ecosystem. Its WorldLeaks-branded activity, however, is centered on exfiltration and extortion rather than routine file encryption. A leak-site listing is a claim by the operation, not proof that an intrusion, data theft or attribution has been independently verified.
Activity and targeting
MOXFIVE described an affiliate-based, extortion-as-a-service platform whose reported victims spanned multiple countries and industries. In its July 2025 review, about half of the observed victim listings involved organizations in the United States, with additional listings in Canada and Europe. Health care, manufacturing, retail and hospitality were the most represented sectors in that dataset, but the breadth of other listings suggests largely opportunistic targeting rather than a narrow industry mandate.
Public claims continued into 2026. WorldLeaks listed San Felipe Del Rio CISD School on March 31, but the listing does not independently establish responsibility for the district’s earlier outage or prove that data was stolen. Leak-site totals and victim entries should be read as actor assertions unless corroborated by victims, investigators or other reliable evidence.
Methods and operational characteristics
WorldLeaks uses stolen data as leverage, threatening publication when a victim does not pay. Group-IB reported that the platform supplies affiliates with a purportedly custom exfiltration tool designed to automate data theft. The tool was described as able to connect through a proxy and as an evolution of the Storage Software used in the Hunters International ecosystem. Those technical and infrastructure overlaps, together with the timing of the transition, support the rebrand assessment.
MOXFIVE said valid credentials used against virtual private network infrastructure were the most common initial-access route in cases it observed, particularly where multifactor authentication was absent or misconfigured. That finding describes observed cases, not a universal WorldLeaks playbook; public reporting on the group’s initial-access methods remains limited.
What type of group is it?
WorldLeaks is best understood as an affiliate-based cybercriminal extortion operation and the extortion-only successor to Hunters International. It monetizes unauthorized access through data theft, negotiation and leak pressure while reducing the operational complexity and visibility associated with encryption. No reviewed authoritative source publicly identifies the group’s members, establishes their location or links the operation to a government.