The dismantlement of LeakBase under Operation LEAK in March 2026 marks the third major disruption in a chain of successor platforms that have dominated the English-language stolen data market since 2020. Each takedown has been followed by a period of user migration, platform consolidation, and eventual re-emergence of a new dominant forum, a cycle that reflects both the resilience of the cybercriminal ecosystem and the increasingly sophisticated law enforcement methodology deployed to disrupt it.
The Lineage: RaidForums → BreachForums → LeakBase
RaidForums, seized by the DOJ and Europol in April 2022, was for several years the dominant English-language forum for buying, selling, and leaking stolen databases. Its administrator, Diogo Santos Coelho, was subsequently arrested and extradited to the United States. Within months of its closure, former members consolidated around BreachForums, which rapidly inherited RaidForums' user base. BreachForums was disrupted by the FBI in June 2023, with its founder Conor Brian Fitzpatrick (alias "Pompompurin") arrested, convicted, and sentenced in 2025. LeakBase, active since 2021 and operational during the BreachForums era as a complementary platform, emerged as a primary destination for displaced users and grew to over 142,000 registered members by December 2025.
LeakBase's Distinctive Features
While broadly similar in function to its predecessors, LeakBase exhibited several differentiating characteristics. Its open-web accessibility without requiring Tor significantly lowered the barrier to entry for less technically sophisticated actors. Its focus on stealer logs (credential archives harvested by infostealer malware such as RedLine, Vidar, and Raccoon) alongside traditional database leaks reflected the broader shift in the criminal data economy toward continuous, automated credential harvesting. Its internal credit and reputation economy created structured incentives for engagement consistent with legitimate online community platforms. The documented prohibition on Russian-related data is consistent with a pattern observed across multiple Eastern European-adjacent forums and may reflect administrator origin or a deliberate policy to avoid Russian law enforcement attention.
The Deanonymization Dividend
The seizure of LeakBase's complete internal database including private messages, IP logs, credit details, and user accounts represents a deanonymization event of significant investigative scope. Europol confirmed that multiple users who believed themselves anonymous have already been identified, with law enforcement making direct contact through the suspects' own preferred digital channels. This methodology has become a consistent feature of Europol-coordinated cybercrime forum dismantlements. The investigative dividend from a complete database seizure typically extends for months or years beyond the initial takedown.
Post-Takedown Migration Risk
Historical precedent from RaidForums and BreachForums suggests a predictable post-takedown sequence. In the immediate aftermath, displaced users fragment across existing alternative platforms and Telegram channels with heightened activity as actors seek to liquidate credentials before further law enforcement action. Over the medium term, consolidation occurs around one or two successor platforms. IntelFusions assesses with moderate confidence that the seized database's scope including IP logs and private messages will deter some sophisticated actors from consolidating on a single successor platform, instead driving migration toward more compartmentalized, invitation-only Telegram-based markets or dark-web alternatives.
Intelligence Assessment
Operation LEAK demonstrates the maturation of Europol's forum dismantlement methodology: the combination of pre-action data sprints, J-CAT coordination, simultaneous multi-jurisdiction enforcement, and database seizure constitutes a repeatable playbook now successfully applied to three successive major English-language credential markets. The increasing operational tempo — RaidForums (2022), BreachForums (2023), LeakBase (2026) suggests law enforcement has developed sufficient institutional knowledge and international coordination capacity to sustain this campaign over successive platform generations. Whether this cycle of disruption and re-emergence can be permanently broken remains the central strategic question for cybercrime enforcement policy in the current period.
This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. Claims described herein have not been independently verified unless explicitly stated.