Global Cybercrime Hub Dismantled: LeakBase Admin Arrested in Russian Takedown
The alleged mastermind behind LeakBase, one of the world's largest stolen credential marketplaces, has been arrested in Russia as law enforcement secures data on over 147,000 cybercriminals.

A visual representation of the LeakBase cybercrime forum seizure and the arrest of its administrator in Taganrog, Russia.
In a major blow to the global underground data economy, Russian law enforcement authorities have arrested the alleged administrator of the notorious LeakBase cybercrime forum. The suspect, a resident of Taganrog, is accused of managing a platform that facilitated the trade of hundreds of millions of stolen personal records since 2021.
A Hub for Global Fraud
According to MVD Media and state news agency TASS, the platform served as a central repository for:
- 147,000+ Registered Users: A massive community dedicated to buying and selling illicit data.
- Hundreds of Millions of Records: Including bank details, hashed passwords, and sensitive corporate documents obtained through high-profile hacks.
- Account Takeover Tools: Credentials and routing information specifically designed for financial fraud.
Irina Volk, spokesperson for the Russian Ministry of Internal Affairs, confirmed that technical equipment and evidentiary items were confiscated during the raid. The U.S. Department of Justice (DoJ) previously identified LeakBase as one of the world's largest hubs for cybercriminals.
The Face Behind the Alias
Intelligence reports from KELA and TriTrace Investigations have linked the forum's activities to a 33-year-old individual known online by aliases such as Chucky, beakdaz, and Sqlrip.
While the forum briefly attempted a comeback on a new domain with DDoS protection from a Russian "bulletproof" hosting provider, the site now displays a permanent seizure notice. The notice warns that all forum content, including IP logs and private messages, has been secured for evidentiary purposes.
Regional Impact
This arrest signals a rare instance of high-profile cooperation and domestic enforcement within Russia against a platform that targeted citizens and institutions globally. For MENA-based organizations, this takedown significantly reduces the immediate availability of credentials used in credential stuffing attacks across the region.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.