ctipilot.ch

World Leaks

actor · actor:worldleaks single-source

World Leaks — rebranded Hunters International; data-theft extortion without encryption

Coverage timeline
1
first 2026-05-04 → last 2026-05-04
Entries
1
1 distinct days
Sources cited
1
1 hosts
Sections touched
1
weekly-sector-patterns
Co-occurring entities
2
see Related entities below

Story timeline

  1. 2026-05-04Media and political (HU, DE)
    weekly-sector-patternsMedia and political (HU, DE)

Where this entity is cited

  • weekly-sector-patterns1

Source distribution

  • therecord.media1 (100%)

Related entities

Entries about World Leaks (1)

2026-05-04 · view entry permalink →

Media and political (HU, DE)

notable synthesis discovered 2026-05-04 05:00 UTC single-source

Two European political / media targets in the week: Mediaworks Kft (Hungary) — World Leaks claimed 8.5 TB of exfiltrated data including payroll, contracts, and internal editorial communications; Mediaworks confirmed "a significant amount of illegally obtained data may have come into the possession of unauthorized persons"; no public regulator notification announcement at window close (The Record, 2026-05-04 · daily 2026-05-06). Die Linke (Germany) — German federal political party confirmed Qilin ransomware encryption and 1.5 TB exfiltration; state DPA notified; no public ransom figure (heise online — covered in daily, 2026-05-08). Two distinct operators (data-theft-only WorldLeaks versus encrypt-and-exfiltrate Qilin), shared targeting of politically significant European entities. The defender lesson: data-theft-only operators defeat backup-centric ransomware defences entirely — effective detection requires egress monitoring and data-loss-prevention tooling capable of alerting on large-volume exfiltration before the attacker goes public on a leak site.

ransomware organized-crime data-breach europe dach