WorldLeaks
WorldLeaks is a ransomware and data-extortion operation that emerged in 2025 and has been described as a spin-off of Hunters International, which itself has been linked historically to the Hive ransomware lineage.
Profile source: Mallory opens in a new tabWorldLeaks
Family profile
WorldLeaks is a ransomware and data-extortion operation that emerged in 2025 and has been described as a spin-off of Hunters International, which itself has been linked historically to the Hive ransomware lineage. The group is associated with double-extortion activity in which data is stolen from victims and then used for coercion through leak-site publication deadlines and public exposure. Reported victimology spans multiple countries, with notable concentration in the United States and the United Kingdom, and sector targeting has prominently included healthcare, manufacturing, and business services.
WorldLeaks has been tied to large-scale data theft incidents and operation of a data leak site used to announce victims and publish stolen material. In at least one reported case, the group shortened its publication deadline from a previously observed seven-day window to roughly two days, indicating an aggressive extortion tempo. The operation has also been associated with RustyRocket, an in-house exfiltration tool reportedly built for both Windows and Linux, reinforcing the assessment that data theft is a core component of its tradecraft.
Reporting also places WorldLeaks among ransomware-group alliances that share tactics or cooperate operationally with other extortion actors. The group has been characterized as capable of handling large stolen datasets and participating in broader collaborative ecosystems targeting enterprise organizations. High-confidence reporting supports its role as a ransomware-led extortion actor rather than a purely opportunistic leak brand.
Capabilities
- Exfiltration
- Extortion
Operational record
Recent claims
MITRE ATT&CK
WorldLeaks in ATT&CK
3 distinct techniquesReporting
Research mentioning WorldLeaks
India says allegedly leaked nuclear plant files pose no safety risk | The Record from Recorded Future News
The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.