BSN 3.22.2021

The Hacker Got Hacked

BSN 3.22.2021
 

WeLeakInfo was a data breach site that offered paid subscriptions to users who could then access their searchable database which contained stolen records.  This now defunct site contained 12.5 BILLION records of data that was illegally obtained through various means.  This included names, phone numbers, addresses, passwords, and email addresses. 

Cybercriminals used this site as a resource for when they would hack corporate networks or run phishing campaigns to deploy ransomware or other threats.  The FBI seized the WeLeakInfo domain in January 2020 after an international law enforcement operation allowed them to do it.  This group was comprised of the FBI, the UK NCA, the Netherlands National Police Corps, the Police Service of Northern Ireland, and the German Bundeskriminalamt – quite a lineup.  This led to the site being shut down and cease of operations for the hackers.

Karma Came Knocking

Recently data containing archived payment processing information from WeLeakInfo was released on another hacking forum called RaidForums.  It included the information that WeLeakInfo used via the payment method Stripe.  The cost to obtain the records was about $2.54 and was posted by a forum administrator who found it in a data dump from when they themselves had used the service.

Apparently, the FBI had allowed the wli.design domain to expire, and the WeLeakInfo data was accessible as the new site owner informed viewers that he or she “was able to register this domain and then reset the password on their stripe account, giving me full access to all customer information for people that paid via stripe”.  Getting burned at your own game.  The exposed information included account information and spreadsheets that contained customer lists, payment information, and invoices.  Additionally, they found corporate data that included email addresses, names, credit card information, IP addresses, and other identifying information for close to 24,000 payments. 

While some of the found information was for businesses that used the service, they were likely security companies using the service to ward off future attacks. 

While illegally obtaining any information is not something we would support in any manner, in this case, the irony and humor are not lost on us that the hacker got hacked.

badge w light burst white (1)
Exclusively for Our MSP Partners

Now Available: Gen AI Certification From BSN

Lead Strategic AI Conversations with Confidence

Breach Secure Now’s Generative AI Certification helps MSPs simplify the AI conversation, enabling clients to unlock the value of gen AI for their business, build trust, and drive growth – positioning you as a leader in the AI space.

More on blogs

The AI Boomerang Effect: Why Companies (and AI) Still Need People

The AI Boomerang trend is proving that AI does not eliminate the need for skilled employees. Instead, organizations need people who know how to use

From MSP to MIP: BSN’s Key Takeaways from Pax8 Beyond 2026

The BSN team returned from Pax8 Beyond 2026 with valuable insights on AI adoption, cybersecurity, compliance, and the industry's shift from Managed Service Providers to

Social Engineering: The Cyber Threat That Targets People, Not Technology

Social engineering remains one of the most effective cyberattack methods because it targets human behavior instead of technical vulnerabilities. From phishing emails and executive impersonation
Take the First Step

Experience Training That Makes a Difference

during the demo you’ll:

Take the First Step

Experience Training That Makes a Difference

During the demo you’ll: