ctipilot.ch

World Leaks

actor · actor:worldleaks single-source

Data-theft extortion group without encryption; rebrand of Hunters International.

Aliases: Hunters International

Coverage timeline
3
first 2026-05-04 → last 2026-07-19
Peak priority
high
1 high · 2 notable
Sources cited
5
5 hosts
Sections touched
3
active-threats, weekly-incidents-recap, weekly-sector-patterns
Co-occurring entities
1
see Related entities below
ATT&CK techniques
3
pinned v19.2 · see below
2026-05-043 appearances2026-07-19

ATT&CK techniques

3 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-07-19/weekly-w29-third-party-mediated-breaches · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-19/weekly-w29-third-party-mediated-breaches · 2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach · ATT&CK page ↗

Collection TA0009

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach · ATT&CK page ↗

Story timeline

  1. 2026-07-19Nearly every breach disclosed this week entered through someone else's infrastructure — a service provider, a data-centre host, an ITSM platform and a CI/CD pipeline, not the victim's own perimeter
    weekly-incidents-recapW29 breaches were third-party-mediated — IWB Basel, Kudankulam/Reliance, Ernst & Young and AsyncAPI entered through a trusted supplier, host or pipeline
  2. 2026-07-16World Leaks posts ~858,000 files tied to India's Kudankulam nuclear-plant contractor; Reliance confirms a third-party-hosting breach
    active-threatsWorld Leaks leaks ~858k files from a Kudankulam nuclear-plant contractor breached at a third-party data-centre host — a lesson for energy-CI operators
  3. 2026-05-04Media and political (HU, DE)
    weekly-sector-patterns

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • weekly-sector-patterns1
  • active-threats1
  • weekly-incidents-recap1

Source distribution

  • microsoft.com1 (20%)
  • oag.ca.gov1 (20%)
  • therecord.media1 (20%)
  • theweek.in1 (20%)
  • wiz.io1 (20%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about World Leaks (3)

2026-07-19 · view entry permalink →

HIGHNATOB2

Nearly every breach disclosed this week entered through someone else's infrastructure — a service provider, a data-centre host, an ITSM platform and a CI/CD pipeline, not the victim's own perimeter

Read as a set, the week's breaches make one point: the perimeter that failed was rarely the victim's own. Four disclosures, four different trust boundaries.

A service provider was the vector for Basel utility IWB — a compromised external provider exfiltrated ~40,000 customer meter records while IWB's own systems and supply were unaffected. A data-centre host was the vector for the Kudankulam nuclear-plant contractor Reliance Group, which confirmed a "partial breach" originating from a server hosted by third-party provider Yotta, after World Leaks posted ~858,000 files (their authenticity only claimed, with Reuters reviewing a sample) (The Week/Reuters, 2026-07-15). An ITSM/IT platform was the vector for Ernst & Young, whose client tax data was exposed through a third-party software breach disclosed in a California Attorney General filing (CA OAG, 2026-07-15).

The CI/CD pipeline case is the most instructive for defenders because it broke an assumed control. The AsyncAPI compromise reached packages with over three million weekly downloads by abusing the org's own trusted-publishing workflow (Wiz, 2026-07-14); Microsoft's timeline then showed the trojanized versions carried cryptographically valid npm/OIDC provenance attestations that correctly name the real repo, commit and workflow — "even though the triggering commits were unauthorized" — and executed at import time, so --ignore-scripts did not stop them (Microsoft, 2026-07-15).

Builds on: 2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records · 2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach · 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions · 2026-07-16/asyncapi-npm-compromise-valid-provenance-attestations-delta

incident19 Jul 23:58Zmulti-sourceOpen finding ↗

2026-07-16 · view entry permalink →

NOTABLENATOB2

World Leaks posts ~858,000 files tied to India's Kudankulam nuclear-plant contractor; Reliance confirms a third-party-hosting breach

The data-theft-extortion group World Leaks — the rebrand of Hunters International already tracked in this store — posted roughly 858,000 files on its dark-web leak site attributed to Reliance Group, a contractor involved in India's Kudankulam Nuclear Power Plant (KNPP), the country's largest nuclear facility (The Week / Reuters, 2026-07-15). Reuters reviewed a subset of about 19,000 files dated 2016–2025 that purport to show facility blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies; the files are only claimed to originate from the plant and their authenticity is not established. Reliance Group confirmed to Reuters that a "partial breach" of its data occurred from a server hosted by Yotta, a third-party Indian data-centre provider, and that the government has been informed; India's CERT-In is investigating and a Nuclear Threat Initiative expert warned the exposure could pose a serious plant-safety risk.

They admitted to Reuters that a "partial breach" of its data had taken place from a server hosted by Yotta, a third-party Indian data centre service provider, and that the government has been informed about the incident.

19,000 of these files appeared to be highly sensitive, the report added, noting that the documents were dated between 2016 and 2025, and reportedly featured blueprints, supplier details, meeting and inspection records, equipment reviews and insurance policies.

The Week (India), relaying Reuters 2026-07-15
incident16 Jul 04:42Zsingle-sourceOpen finding ↗

2026-05-04 · view entry permalink →

NOTABLE

Media and political (HU, DE)

Two European political / media targets in the week: Mediaworks Kft (Hungary) — World Leaks claimed 8.5 TB of exfiltrated data including payroll, contracts, and internal editorial communications; Mediaworks confirmed "a significant amount of illegally obtained data may have come into the possession of unauthorized persons"; no public regulator notification announcement at window close (The Record, 2026-05-04 · daily 2026-05-06). Die Linke (Germany) — German federal political party confirmed Qilin ransomware encryption and 1.5 TB exfiltration; state DPA notified; no public ransom figure (heise online — covered in daily, 2026-05-08). Two distinct operators (data-theft-only WorldLeaks versus encrypt-and-exfiltrate Qilin), shared targeting of politically significant European entities. The defender lesson: data-theft-only operators defeat backup-centric ransomware defences entirely — effective detection requires egress monitoring and data-loss-prevention tooling capable of alerting on large-volume exfiltration before the attacker goes public on a leak site.

synthesis04 May 05:00Zsingle-sourceOpen finding ↗