Skip to content

WorldLeaks

WorldLeaks is a ransomware and data-extortion operation that emerged in 2025 and has been described as a spin-off of Hunters International, which itself has been linked historically to the Hive ransomware lineage.

Profile source: Mallory opens in a new tab

WorldLeaks

Family profile

WorldLeaks is a ransomware and data-extortion operation that emerged in 2025 and has been described as a spin-off of Hunters International, which itself has been linked historically to the Hive ransomware lineage. The group is associated with double-extortion activity in which data is stolen from victims and then used for coercion through leak-site publication deadlines and public exposure. Reported victimology spans multiple countries, with notable concentration in the United States and the United Kingdom, and sector targeting has prominently included healthcare, manufacturing, and business services.

WorldLeaks has been tied to large-scale data theft incidents and operation of a data leak site used to announce victims and publish stolen material. In at least one reported case, the group shortened its publication deadline from a previously observed seven-day window to roughly two days, indicating an aggressive extortion tempo. The operation has also been associated with RustyRocket, an in-house exfiltration tool reportedly built for both Windows and Linux, reinforcing the assessment that data theft is a core component of its tradecraft.

Reporting also places WorldLeaks among ransomware-group alliances that share tactics or cooperate operationally with other extortion actors. The group has been characterized as capable of handling large stolen datasets and participating in broader collaborative ecosystems targeting enterprise organizations. High-confidence reporting supports its role as a ransomware-led extortion actor rather than a purely opportunistic leak brand.

Capabilities

  • Exfiltration
  • Extortion

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Recent claims

MITRE ATT&CK

WorldLeaks in ATT&CK

3 distinct techniques

Reporting

Research mentioning WorldLeaks

Jul 20
The Record Media

India says allegedly leaked nuclear plant files pose no safety risk | The Record from Recorded Future News

The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.

Jul 17
Cyberveille

Fuite de données : 19 000 fichiers de la centrale nucléaire de Kudankulam exposés par World Leaks | CyberVeille

Jul 17
Theravenfile

KUDANKULAM NUCLEAR POWER PLANT LEAK: AN ACCIDENTAL DISCLOSURE - THE RAVEN FILE

Jul 16
Cysecurity News

Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned - CySecurity News - Latest Information Security and Hacking Incidents

Jul 16
Teiss News

teiss - News - NPCIL denies sensitive data breach at Kudankulam nuclear plant, says leaked files involve only conventional systems

Jul 16
Teiss News

teiss - News - Ransomware group leaks data stolen from India’s largest nuclear plant

Jul 15
Malware News

Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach - Malware News - Malware Analysis, News and Indicators

Jul 15
Teiss News

teiss - News - Exclusive-Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.