Refactoring in the dark edges of the web.

Terminal-style genealogy tracing Hive to Hunters International to World Leaks to an unconfirmed next rebrand

A ransomware brand is a liability, not an asset. The crew behind it — the operators, the tooling, the affiliate relationships, the exfiltration infrastructure — is the asset. Once you internalise that split, the last three years of one particular lineage stop looking like three separate groups and start looking like what they are: one operation changing its shirt whenever the old one gets too much heat on it.

This is a writeup of that lineage — Hive → Hunters International → World Leaks — the pivot that took the ware out of the ransomware, and the two sectors that end up absorbing the damage regardless of which banner is flying. Healthcare and education aren’t in here because they make a sympathetic headline. They’re in here because the exfiltration-first model does its worst work exactly where the data is most sensitive and the security budget is thinnest.

cat table_of_contents.txt
  1. The lineage
  2. When the ware left the ransomware
  3. Healthcare: where exfiltration hurts most
  4. Education: the vendor blast-radius sector
  5. The pattern nobody wants to underwrite
  6. Remedies: reactive vs proactive
  7. Attribution notes
  8. Sources (defanged)

The lineage

git log --oneline --follow the-operation/

Hive [2021–2023]. Ran as ransomware-as-a-service, extorted north of $100M, and got dismantled in a coordinated law-enforcement takedown in January 2023. That should have been the end of the story. It wasn’t.

Hunters International [late 2023–2025]. Surfaced around October 2023 and was quickly flagged as a probable Hive successor on the strength of code overlap. The administrators pushed back on the rebrand framing, claiming instead that they’d purchased Hive’s source code — a distinction that conveniently muddies attribution without changing who benefits. Ran classic double extortion: encrypt the data, steal a copy, threaten to leak it if the ransom went unpaid. Claimed somewhere in the 280–300+ victim range, heavily weighted toward North America.

World Leaks [2025– ]. In November 2024, administrators told affiliates the Hunters “project” was winding down — declining margins, law-enforcement pressure. In April 2025, Group-IB reported the group was mid-rebrand. On 1 January 2025, World Leaks launched as an extortion-only operation. By July 2025 Hunters formally closed its leak site, scrubbed victim names, and offered “free decryptors” — which Group-IB read not as goodwill but as a deliberate move to sever the public link between the two brands. Reputation laundering, dressed up as a parting gift.

Which brings us to the part everyone wants to skip ahead to.

The next rebrand [confidence: low]. By mid-2026 the operational signals point in a familiar direction — listing cadence dropped by roughly a third month-over-month on public trackers, with short inactivity gaps by late July. That is consistent with the early quiet that preceded the last transition. It is not proof of a fourth-generation named successor, and I haven’t found primary reporting that names one. So: the pattern strongly predicts another refactor, the telemetry is suggestive, and anyone asserting a specific new brand right now is running ahead of the evidence. The prediction is defensible. The attribution isn’t — yet.

When the ware left the ransomware

World Leaks markets itself as encryption-less: pure data theft and extortion, no file-encrypting payload, built on a custom exfiltration platform (Accenture tracks the tool as RustyRocket) that moves data over a SOCKSv5 proxy through TOR with metadata indexing, so full datasets don’t transit central servers. The pressure model is a four-part TOR setup — leak site, negotiation portal, affiliate panel, and an “Insider” journalist portal that hands media outlets 24-hour early access to stolen data to maximise reputational damage before the victim can get ahead of it.

The strategic logic is sound from their side of the table. Encryption is loud, it triggers incident response immediately, and — crucially — backups defeat it. Pure exfiltration is quiet, and there is no backup for confidentiality. Once the data is gone, it’s gone.

One caveat that belongs in the record, because the marketing invites the wrong conclusion: the encryption capability never actually left. In early 2026 Darktrace detected a World Leaks intrusion that both exfiltrated and encrypted victim data — initial access via a FortiGate appliance, roughly three months of dwell time, C2 over a Cloudflare Tunnel. The inherited Hunters codebase still has the encryptor in it. Defenders who retire encryption from the threat model on the strength of the group’s own press release are taking the adversary at their word. Don’t.

Healthcare: where exfiltration hurts most

The FBI’s April 2026 IC3 reporting put healthcare as the number-one targeted sector in 2025 [confidence: medium — figure from secondary summaries; confirm against the primary IC3 report before you cite the raw counts]. Independent trackers agree on direction if not on the decimal: BlackFog’s mid-2026 data puts healthcare at ~35% of reported ransomware activity, with nearly half of all incidents still unattributed — which is itself the story. Most of this activity can’t be pinned to a named crew.

The most active named groups against providers in 2025 were Qilin, INC Ransom, Akira, RansomHub, and Interlock. The incidents that anchor the period:

  • Change Healthcare (ALPHV/BlackCat), Feb 2024 — the landmark. HHS ultimately confirmed ~192.7M individuals affected, close to two-thirds of the US population. Change Healthcare paid a reported $22M ransom; BlackCat kept it and never returned the data. If you need a single case to demonstrate that payment resolves nothing, this is it.
  • DaVita (Interlock), Apr 2025 — a 19-day access window into a lab database holding PHI on ~2.69M individuals. Critical dialysis care continued throughout — but the data was already exfiltrated. Continuity of care and confidentiality are different problems; solving one does nothing for the other.
  • University of Mississippi Medical Center, Feb 2026 — a nine-day shutdown of non-emergency operations and a reported ~20% revenue drop for the month.
  • ApolloMD (Qilin), claimed Feb 2026 — group claimed exfiltration of patient data.

The dimension that makes healthcare unlike any other sector: Ponemon/Proofpoint research found more than 20% of healthcare organisations hit by the common attack types reported increased patient mortality, with nearly one in four reporting the same specifically after ransomware. This is a patient-safety problem wearing an IT costume.

Worth noting for the myth-busting file: the classic encrypt-and-pay model is shrinking as a share of this. Only ~36% of healthcare victims worldwide paid in 2025, down from ~61% in 2022, with median paid ransoms falling to roughly $150K (Sophos). Attack volume up, payment rate down — which is precisely the economic pressure that pushed the World Leaks lineage toward data-only extortion in the first place.

Education: the vendor blast-radius sector

Education splits. K-12 ransomware declined ~26% worldwide into 2026 while higher-ed rose ~8%. The specialist to watch is Interlock, which in Q1 2026 aimed ~27% of its victims at education against a sector average near 7% — a deliberate concentration. The other mover is The Gentlemen, whose education attacks jumped 275% H2-2025 → H1-2026, with the large majority of claims against higher-ed. LockBit and Nova also climbed.

Confirmed incidents in the window:

  • PowerSchool, disclosed Dec 2024 — the defining education breach, and the largest breach of children’s data in US history. ~62M students and ~9.5M educators exposed through a single compromised credential into a support portal with no MFA. The intrusion ran ~9 days undetected. PowerSchool paid ~$2.85M in Bitcoin and received a video purportedly showing deletion. By May 2025, the same data was being used to extort individual districts directly. Paying didn’t delete anything; it just funded the next round. The perpetrator — a 19-year-old, Matthew Lane — was arrested and sentenced to four years. The platform that wired a remote support portal to decades of children’s records is still operating.
  • Mount Royal University (Canada), Jun 2026 — disruption persisting over a month past the June 17 start, with a confirmed breach.
  • Alamo Heights ISD (Texas), Mar 2026 — five days of downtime, ~26,600 residents notified.
  • Delano Public Schools (Minnesota), May 2026 — a day of cancelled classes; LockBit claimed it in June.
  • Community College of Beaver County (PA), Mar 2026 — full encryption of college data, access to grades/transcripts/financials blocked.

The structural why is the same every time: a single LMS or SIS aggregates records from hundreds of institutions, the attack surface is enormous, the security budget is not, and FERPA exposure means institutions calculate they’re better off paying fast than fighting. Attackers have done that math too.

The pattern nobody wants to underwrite

Here’s the through-line that outranks any single breach: the highest-impact incidents in both sectors were not the hospitals or schools. They were the platforms holding the data. Change Healthcare, PowerSchool, and the 2026 Instructure/Canvas incident are all one-compromise-many-victims events. Verizon’s 2025 DBIR found healthcare breaches involving a business associate or vendor doubled in a year, from 15% to 30% of incidents.

If you’re defending an org in either sector, your own perimeter is the part you can see and the part least likely to be the entry point. The vendor you onboarded three years ago with a checkbox security questionnaire is the blast radius. That’s the uncomfortable, under-resourced, unglamorous control that would have mattered most in every headline above.

Remedies: reactive vs proactive

The reactive layer — what victims and regulators actually do. The PowerSchool response is the template: external forensics (CrowdStrike / Mandiant), breach notification to downstream customers and families, free identity/credit monitoring for affected individuals, class-action litigation, and criminal prosecution where the actor is reachable. Regulatory exposure runs through HIPAA (60-day notification), FERPA for student data, and state regimes like CCPA. None of it un-leaks anything. It’s cleanup, not defence.

The proactive layer — what actually prevents it. The authoritative baseline is CISA/FBI/MS-ISAC’s #StopRansomware guidance, reinforced by the actor-specific advisories (Interlock AA25-203A, Rhysida AA23-319A, Medusa AA25-071A, Black Basta AA24-131A). The controls that recur, in priority order for this threat model:

  1. Phishing-resistant MFA everywhere — VPN, webmail, remote access, support portals especially. Nearly every incident above traces to a credential without MFA. This is the single highest-leverage control and it keeps being the thing that wasn’t there.
  2. Third-party / vendor risk management — given the blast-radius pattern, this is the control most correlated with the actual damage and the one most orgs under-invest in. Contractual security requirements, real assessment, notification SLAs that are shorter than “we told you a week later.”
  3. Offline, encrypted, tested backups + a rehearsed IR plan — necessary, but note the ceiling: backups defend against encryption, not exfiltration. Against the data-theft model they’re table stakes, not a solution.
  4. Segment networks, patch known-exploited vulns fast, harden RDP/VPN.
  5. Data minimisation — PowerSchool held records going back decades, including medical and guardianship notes that never needed to be retained. You can’t leak what you didn’t keep.

For education specifically, CISA maintains dedicated K-12 prevention/response/recovery resources. Use them; they’re free and they’re better than most vendor whitepapers selling you the fix in the last paragraph.

Attribution notes

Stated with confidence levels, per house rules:

  • Hive → Hunters International succession — high (code overlap + corroborating vendor reporting).
  • Hunters International → World Leaks rebrand — high (Group-IB reporting + infrastructure and TTP continuity).
  • World Leaks → a named next-generation successor — low (activity dip is suggestive; no primary reporting names a successor at time of writing).
  • Individual sector incidents above — attributed per-incident to the claiming or confirmed group; do not read the aggregate sector stats as any single actor’s work. ~47% of healthcare ransomware activity is unattributed, and lumping it under one banner would be exactly the kind of flattening this blog exists to push back on.

Sources

No live links to hostile infrastructure; all references below are reporting and guidance, defanged as a matter of habit.

  • hxxps://www[.]group-ib[.]com/blog/hunters-international-ransomware-group/
  • hxxps://www[.]bleepingcomputer[.]com/tag/world-leaks/
  • hxxps://www[.]darktrace[.]com/blog/when-reality-diverges-from-the-playbook-darktrace-identifies-encryption-in-a-world-leaks-ransomware-attack
  • hxxps://www[.]halcyon[.]ai/threat-group/worldleaks
  • hxxps://www[.]ransomware[.]live/group/worldleaks
  • hxxps://www[.]comparitech[.]com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
  • hxxps://www[.]comparitech[.]com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
  • hxxps://cybelangel[.]com/blog/ransomware-in-healthcare-attack-timeline/
  • hxxps://www[.]govtech[.]com/education/k-12/ransomware-attacks-on-k-12-trend-down-higher-ed-trend-up-in-2026
  • hxxps://www[.]techtarget[.]com/whatis/feature/PowerSchool-data-breach-Explaining-how-it-happened
  • hxxps://www[.]cisa[.]gov/stopransomware/ransomware-guide
  • hxxps://www[.]cisa[.]gov/news-events/cybersecurity-advisories/aa25-203a
  • hxxps://www[.]cisa[.]gov/stopransomware/k-12-resources
  • hxxps://www[.]hhs[.]gov/ (OCR breach portal — Change Healthcare)