OTHER

Cybercrime Forum Leak Zone Exposes Users’ IP Addresses to the Public

A self-identified “leaking and cracking forum” where users exchange and promote compromised databases, hacked credentials, and pirated software has been discovered exposing the IP addresses of its registered users to the public internet, according to security experts.

Investigators at UpGuard found that Leak Zone had left an Elasticsearch database unprotected and available online without any password security. In a blog post shared with TechCrunch before publication, they reported the discovery of the database on July 18, noting that its data was accessible to anyone with internet connectivity.

The exposed database contained over 22 million records, including the IP addresses and precise timestamps of when users accessed Leak Zone. These records were dated June 25, and the database was updating continuously.

While the records were not directly linked to individual users, the information could potentially identify those who logged into Leak Zone without employing any anonymization tools. Some records observed by TechCrunch indicated whether a user logged in through a proxy, such as a VPN, which can mask their actual whereabouts.

Founded in 2020, Leak Zone positions itself as a repository for a “vast collection of leaks, from compromised databases to cracked accounts,” referring to unauthorized credentials that allow access to various online services. The forum also features a marketplace that openly advertises “illegal services,” according to its guidelines. A section of Leak Zone’s site claims to have over 109,000 registered users.

UpGuard reported that 95% of the exposed records are associated with user logins on Leak Zone. The remainder pertains to accounts related to AccountBot, another platform that sells access to compromised streaming service accounts.

TechCrunch verified that the exposed database was monitoring user logins by creating a new account and logging in, which resulted in an instant record being generated in the database that included our IP address and the exact login timestamp.

The cause of the public exposure of the database remains uncertain. Such incidents typically arise from human mistakes or misconfigurations rather than intentional wrongdoing.

TechCrunch reached out to the Leak Zone administrators for comment, but the forum’s software blocked our attempt to send messages. It remains unclear whether the administrators are aware of the data breach or if they plan to notify users regarding this security concern.

According to UpGuard, the exposed database is no longer available online.

In recent years, both U.S. and international authorities have intensified efforts against cybercrime forums and websites for their roles in facilitating hacking, identity theft, and other illicit activities. This week, Europol announced the arrest of the suspected administrator of XSS.is, a long-standing Russian-language cybercrime forum, which was also dismantled in a broader takedown operation.