LeakNet is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 7 intelligence report mentions.
LeakNet is a ransomware_group tracked across 2 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed March 17, 2026; most recent activity May 25, 2026.
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
LeakNet, a ransomware group, has adopted new tactics involving ClickFix social engineering and a Deno-based fileless loader. This shift allows them to gain initial access through compromised websites, prompting users to…
LeakNet is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 7 intelligence report mentions.
The most recent intelligence report mentioning LeakNet on ThreatCluster is dated May 25, 2026. Activity was first observed March 17, 2026, giving a tracked span from then to May 25, 2026.
Across ThreatCluster reporting, LeakNet most frequently co-occurs with Data Breach, Malware, Phishing, Ransomware, Sql Injection, among 12 tracked related entities.
The most significant recent cluster is “Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign” (17 articles · Updated May 25, 2026). LeakNet appears across 2 threat clusters in total, listed above with sources.
LeakNet appears in 7 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.