Skip to content

WorldLeaks

Ransomware Group2 claimsLast activity:
Also known as:
  • Hunters International · Rebrand
  • World Leaks · Alias

Overview

WorldLeaks, also styled World Leaks, is a financially motivated cyberextortion operation launched in January 2025. Group-IB reported that the operators behind Hunters International introduced the project as an extortion-only successor, replacing the earlier brand’s double-extortion model with data theft and threatened disclosure. WorldLeaks is therefore commonly treated as a Hunters International rebrand, although public evidence does not establish that every former affiliate or operator continued with the new operation.

The group is classified here as a ransomware group because of that operational lineage and its place in the ransomware ecosystem. Its WorldLeaks-branded activity, however, is centered on exfiltration and extortion rather than routine file encryption. A leak-site listing is a claim by the operation, not proof that an intrusion, data theft or attribution has been independently verified.

Activity and targeting

MOXFIVE described an affiliate-based, extortion-as-a-service platform whose reported victims spanned multiple countries and industries. In its July 2025 review, about half of the observed victim listings involved organizations in the United States, with additional listings in Canada and Europe. Health care, manufacturing, retail and hospitality were the most represented sectors in that dataset, but the breadth of other listings suggests largely opportunistic targeting rather than a narrow industry mandate.

Public claims continued into 2026. WorldLeaks listed San Felipe Del Rio CISD School on March 31, but the listing does not independently establish responsibility for the district’s earlier outage or prove that data was stolen. Leak-site totals and victim entries should be read as actor assertions unless corroborated by victims, investigators or other reliable evidence.

Methods and operational characteristics

WorldLeaks uses stolen data as leverage, threatening publication when a victim does not pay. Group-IB reported that the platform supplies affiliates with a purportedly custom exfiltration tool designed to automate data theft. The tool was described as able to connect through a proxy and as an evolution of the Storage Software used in the Hunters International ecosystem. Those technical and infrastructure overlaps, together with the timing of the transition, support the rebrand assessment.

MOXFIVE said valid credentials used against virtual private network infrastructure were the most common initial-access route in cases it observed, particularly where multifactor authentication was absent or misconfigured. That finding describes observed cases, not a universal WorldLeaks playbook; public reporting on the group’s initial-access methods remains limited.

What type of group is it?

WorldLeaks is best understood as an affiliate-based cybercriminal extortion operation and the extortion-only successor to Hunters International. It monetizes unauthorized access through data theft, negotiation and leak pressure while reducing the operational complexity and visibility associated with encryption. No reviewed authoritative source publicly identifies the group’s members, establishes their location or links the operation to a government.

Incident claims

Alamo Heights ISD ransomware and data breach

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Ransomware.live recorded a WorldLeaks victim listing naming Alamo Heights School District on April 1. The stable listing identifies the claimant and victim name but does not authenticate alleged files, prove data theft or establish that WorldLeaks caused the March ransomware disruption. A later Qilin listing creates unresolved conflicting attribution.

San Felipe-Del Rio CISD cyber incident

View public claim
Incident date: Source: otherPublished: Discovered:

Claim details

WorldLeaks listed San Felipe Del Rio CISD School and the sfdr-cisd.org domain on March 31, 2026. The listing is treated as a claim and does not independently prove ransomware deployment, data theft or WorldLeaks responsibility.

Sources