ZeroHour

worldleaks

ransomware group · aka WorldLeaks, WorldLeaks extortion group (widely reported as the successor to Hunters International) · unknown; vendor reporting in 2025 described WorldLeaks as the rebrand/successor of Hunters International, the operation that itself inherited the affiliate ecosystem of the Hive ransomware group · active since 2025 - Hunters International's pivot to the WorldLeaks brand was reported by security media in mid-2025; this dashboard's tracking of the group begins 2026-06-20

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
8
All-time (tracked)
178since 2025-05-12
Last post
07-22 18:56UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

WorldLeaks is a data-extortion group that emerged in 2025 as the successor to Hunters International, the operation widely described as inheriting the Hive ransomware group's affiliate network. Vendor reporting in 2025 characterized the rebrand as a shift away from encrypting systems toward exfiltration-only extortion, pressuring victims by threatening to publish stolen data. The group maintains a public leak site listing victims; dashboard tracking shows a low posting cadence, with 8 victims since 2026-06-20 and the most recent post on 2026-07-22. Listed victims span manufacturing, education, financial services, IT services, and professional services, with no confirmed concentration in a single region. No specific initial-access techniques, exploited vulnerabilities, or revenue figures have been widely reported for this group.

Tactics & tooling
  • Exfiltration-only extortion: steals victim data and publishes it on a leak site; encryption reportedly abandoned after the Hunters International rebrand (vendor reporting, 2025)
  • Inherits Hunters International lineage: reportedly reuses the affiliate network and infrastructure tied to the former Hive/Hunters International ecosystem (vendor reporting, 2025)
  • Leak-site publication of victim data used as negotiation leverage (observed site behavior)
  • Direct extortion negotiations with victim organizations (specific methods unknown)
  • Initial access techniques: unknown - no widely documented access method or exploited CVE for this group
  • Targets a mix of small, mid-sized, and larger organizations across multiple sectors, based on listed victims
Targeted sectors
ManufacturingEducationFinancial servicesIT servicesProfessional services (accounting/legal)Healthcare and human servicesConsumer goods
Notable public victims

Tata Electronics, PinnPACK, First Federal Savings & Loan, Reliance Group, Treet Group of Companies, Starpool, COMHAR, Centra Sota Cooperative, St. Francis Xavier Catholic School System, Service IT

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Landscape Hawaii · Jun 28, 2025
Dynamic Netsoft · Jun 28, 2025
Tech Mahindra · Jun 28, 2025
T.O. Brasil · Jun 25, 2025
Informatika A.D. · Jun 25, 2025
Myrtue Medical Center Hospital · Jun 24, 2025
Agaris · Jun 16, 2025
Freedman HealthCare · Jun 15, 2025
Brett-Robinson · Jun 15, 2025
Lake Region Healthcare · Jun 12, 2025
Eastern Platinum Limited · Jun 11, 2025
Center for Clinical Research · Jun 11, 2025
A&R Engineering · Jun 11, 2025
Chain IQ · Jun 11, 2025
AntFarm · Jun 7, 2025
J-Kraft · Jun 4, 2025
Zeus Tecnología · Jun 4, 2025
Kel Campbell · Jun 4, 2025
Jardin De Ville · Jun 2, 2025
ASCOMA Cameroon · May 31, 2025
Canadian Rocky Mountain Resorts · May 30, 2025
ASC Machine Tools · May 29, 2025
Valiant Energy Solutions · May 27, 2025
Sylvania · May 27, 2025
A M King · May 27, 2025
Indigo Group S.A. · May 20, 2025
Asco Tools · May 12, 2025
Horecamaterialen De Meester NV · May 12, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .