The internet has an interesting relationship with memory.
We delete accounts. Change usernames. Hide domain-registration details. Migrate servers. Remove repositories. Abandon email addresses. Replace payment processors.
From our perspective, something has disappeared.
From the internet's perspective, fragments often remain.
A DNS record.
A certificate.
An archived webpage.
An old WHOIS entry.
A username used years earlier.
A company name exposed inside a screenshot.
Individually, these fragments may mean very little.
Correlated together, they can begin telling a very different story.
In July 2026, Bellingcat and New Zealand publication The Press published an investigation examining the infrastructure and digital footprints surrounding LeakedBB, a large online forum associated with the sharing and monetisation of intimate material, including content described by users as hacked, stolen or "leaked."
The investigation did not begin with a breached administrator database.
There was no anonymous insider handing journalists a list of operators.
Instead, investigators worked backwards through years of public digital residue.
Payment screenshots.
Company records.
Archived websites.
DNS history.
TLS certificates.
WHOIS records.
Email identifiers.
Social-media accounts.
GitHub repositories.
The resulting investigation is interesting not merely because of whom those indicators appeared to point toward.
It demonstrates something fundamental about OSINT:
Digital identities are rarely exposed by one catastrophic mistake.
More often, they are reconstructed from dozens of smaller ones.
What Was LeakedBB?
Before looking at the investigation, it is worth understanding the scale and nature of the platform.
LeakedBB was established in 2019.
By May 2026, statistics displayed on the forum itself claimed approximately 2.2 million registered users and more than 2.6 million posts. Web-traffic estimates showed approximately two million visits per month during the months leading up to its disappearance. Semrush recorded around 1.96 million visits in May 2026 alone, with users averaging more than nine minutes per visit.
This was not a small, obscure message board hidden in some forgotten corner of the internet.
It had become a substantial community.
Its content also evolved.
During its early period, LeakedBB included sections involving software, eBooks and other types of supposedly "leaked" material. But Bellingcat found that within months the forum had increasingly centred around intimate photographs and videos.
Some material appeared to originate from commercial creator platforms such as OnlyFans and Fansly.
Other sections concentrated on so-called "amateur" material.
More troublingly, archived discussions included users requesting hacked Snapchat material, offering hacking services, trading intimate photographs of people they personally knew, and attempting to identify women appearing in images.
Bellingcat also documented posts where women's purported real names, social-media accounts and locations accompanied the material being shared.
This distinction matters.
Calling such a platform simply a "leak forum" risks making the activity sound technically abstract.
Behind the datasets were people.
Behind the usernames were victims.
And in some cases, the consequences had already entered criminal courtrooms.
A Criminal Case That Led Back to LeakedBB
One of the clearest examples involved former US college track-and-field coach Steve Waithe.
| Behind LeakedBB’s usernames and forum threads were real victims. The Steve Waithe case showed how material traded online could intersect directly with criminal cyberstalking and exploitation. |
Waithe was sentenced in March 2024 to five years in federal prison after a criminal investigation involving cyberstalking, computer fraud and schemes targeting more than 100 women. According to US authorities, Waithe stole intimate photographs from some student-athletes' phones and created false online identities to contact women.
One technique was particularly manipulative.
Authorities said he contacted victims claiming he had discovered intimate photographs of them on the internet and offered to help remove them.
He would then request additional images supposedly so he could determine whether the photographs online were authentic.
In reality, investigators said this was part of an effort to obtain more intimate material.
Bellingcat discovered something important while examining the case.
Court documents reproduced wording from an online post in which Waithe offered to trade nude photographs of women he personally knew.
Bellingcat found a cached November 2020 LeakedBB post containing the same wording.
Another cached thread from several months later showed the same user offering images of athletes, including women the poster claimed personally to know.
That connection does not explain who operated LeakedBB.
But it illustrates what type of ecosystem investigators were dealing with.
This was not merely a forum collecting pirated subscription content.
It provided infrastructure in which stolen and potentially non-consensual intimate material could circulate, acquire economic value and attract further demand.
LeakedBB Was Not Simply Hosting Content
Perhaps the most important detail about LeakedBB was its economic model. The platform did not merely allow users to upload content. It created incentives to contribute.
Most material within its "leaks" sections was reportedly restricted behind membership levels or an internal credit system.
Paid memberships could cost as much as US$99.99.
Users could alternatively earn credits by contributing material themselves.
According to Bellingcat's review of the forum, members could receive credits when posting content and when other users spent credits unlocking their contributions.
Those credits could then be used to unlock other material.
Some highly active contributors were also able to redeem credits for cryptocurrency, with rates reportedly reaching the equivalent of approximately 15 US cents per thread for certain contributors.
That creates an important distinction.
LeakedBB was not simply storing leaked material.
It was attempting to create an economy around participation.
The basic mechanism looked something like this:
The system therefore encouraged a feedback loop.
More content created more access.
More access encouraged more contribution.
More contribution increased the value of the platform.
Even its community events reflected this incentive structure.
Bellingcat found that LeakedBB held an annual Christmas competition.
For its 2025 competition, prizes worth more than US$4,000 in cryptocurrency were reportedly offered to members who posted or interacted with the most threads.
What looks superficially like a discussion forum therefore begins to resemble something more structured.
A marketplace.
A reputation system.
A contribution economy.
And crucially, a payment problem.
Monetisation Creates Exposure
Running an anonymous forum is one challenge.
Making money from one is another.
The moment a platform accepts payments, it must interact with infrastructure outside itself.
Payment processors.
Merchant accounts.
Companies.
Banking systems.
Cryptocurrency gateways.
Checkout pages.
Domains.
Invoices.
These relationships create investigative surface.
LeakedBB accepted cryptocurrency payments through NOWPayments, a cryptocurrency payment gateway.
Bellingcat reported that membership purchases could redirect users to a NOWPayments transaction page.
When approached by Bellingcat, NOWPayments said LeakedBB's activity violated its terms of service and that it deactivated and blacklisted the platform's account on 4 June 2026.
But cryptocurrency was only part of the payment infrastructure.
And another payment mechanism would become one of the most important pivots in the investigation.
The Screenshot That Exposed Logica LTD
One of the most consequential clues came from something completely ordinary. A support post.
In May 2021, a LeakedBB administrator using the alias Lucifer NightStar responded to a user having difficulty making a payment with Apple Pay.
The administrator uploaded a screenshot demonstrating how the payment screen should appear.
| One screenshot. One company name. One investigative pivot. The appearance of “Logica LTD” in a LeakedBB payment post helped turn a routine support image into a significant OSINT lead. |
Visible inside that screenshot was a company name:
Logica LTD
That was the breadcrumb.
Investigators searched New Zealand corporate records.
They found Logica Limited, incorporated in February 2021.
| New Zealand company records connected Logica Limited to Jitendra Vishal Maharaj, strengthening the OSINT trail from LeakedBB’s payment screenshot to a real-world corporate entity. |
Its sole director was Christchurch entrepreneur Jitendra Maharaj.
Maharaj had also described himself on LinkedIn as CEO of Logica NZ during approximately the same period.
The timing immediately made the screenshot more interesting.
Logica Limited had been incorporated only months before the administrator posted the payment instructions bearing its name.
But a single company name inside a screenshot could still have many explanations.
The investigation needed another connection.
It found one.
The Strange Business of Digital Avatar Packs
On 4 May 2022, a YouTube account using the display name "LeakedBB" uploaded a tutorial explaining how users could purchase LeakedBB memberships.
The video was also embedded on LeakedBB itself.
What happened during the transaction was unusual.
Users selecting a LeakedBB membership were redirected away from the forum.
Instead of apparently buying access to an adult-content forum, they were sent to another website to purchase something much less controversial:
digital avatar packs.
The prices of those avatar packs corresponded with LeakedBB membership levels.
After completing the purchase, users could receive their LeakedBB upgrade.
Archived LeakedBB discussions contained hundreds of users reporting purchases of products with names such as:
Mystic Avatar Pack
and
Pixel Avatar Pack
Some users explicitly stated that they had purchased those products from:
logica.nzArchived copies of logica.nz contained avatar products whose descriptions, prices and thumbnails matched those displayed in LeakedBB's payment tutorial.
The site's footer also identified:
Logica LTD
And OpenCorporates identified logica.nz as the website associated with Logica Limited.
Now the original screenshot was no longer isolated.
The evidence chain had grown:
Then:
Two separate paths were beginning to converge.
Why Disguise a Membership as an Avatar Purchase?
The payment structure itself is worth examining.
A payment described openly as:
LeakedBB Premium Membership
would immediately reveal the nature of the merchant relationship.
Instead, a user's bank statement could show a transaction involving an apparently ordinary digital product.
The avatar mechanism therefore created abstraction between what the user was really purchasing and what the transaction appeared to represent.
Bellingcat noted that such a model could also help obscure the underlying nature of the transaction from payment providers whose acceptable-use policies prohibited non-consensual sexual content.
From an OSINT perspective, this is important.
Financial investigation does not always mean tracing a cryptocurrency wallet directly to a person.
Sometimes the more revealing question is what commercial infrastructure had to exist to make the transaction possible.
That can include:
company names,
checkout domains,
product catalogues,
merchant descriptors,
payment tutorials,
customer comments,
and archived transactions.
This is exactly what happened here.
The attempt to abstract the payment created another layer of infrastructure.
And infrastructure leaves traces.
The Forum Also Made Removal Difficult
There was another aspect of LeakedBB's design worth noting.
The site provided a process for people seeking removal of material through the US Digital Millennium Copyright Act.
On paper, that might look like an attempt to provide a takedown mechanism.
But according to Bellingcat's investigation, LeakedBB required complainants to provide information including a physical address and business email address.
The forum reportedly rejected requests submitted from common free-email providers such as Gmail and ProtonMail.
Bellingcat noted that those requirements appeared more demanding than some mainstream DMCA processes.
For someone already dealing with non-consensual intimate imagery, providing additional personally identifying information to the same platform hosting that material creates an obvious dilemma.
Victims therefore faced an asymmetry.
The people distributing content could hide behind usernames.
The people attempting to remove it could be required to identify themselves.
That is not merely a technical detail.
It tells us something about how the platform was structured and whose interests its mechanisms appeared designed to protect.
Google Had Already Seen the Scale of the Problem
The scale of removal requests involving LeakedBB was enormous.
According to Google's Transparency Report data cited by Bellingcat, Google received more than 95,000 requests involving over 350,000 LeakedBB URLs.
More than 169,000 pages were reportedly removed from Google search results.
Think about what that means.
The forum itself could continue operating even while enormous numbers of individual URLs were being challenged elsewhere.
Removing search visibility did not eliminate the underlying content.
Removing one post did not dismantle the marketplace.
And taking down one account did not necessarily reveal who operated the infrastructure.
The operational question remained:
Who controlled the systems behind LeakedBB?
That is where the investigation moved from platform behaviour into historical infrastructure.
Then DNS Started Talking
The investigators examined the historical Domain Name System records associated with LeakedBB.
This produced another connection.
In 2020, the MX record for:
leakedbb.comwas configured to use:
leakedbb.netAn MX record determines which mail server accepts email for a domain.
Later, the configuration changed to ProtonMail.
The WHOIS registration for leakedbb.net did not expose a useful registrant.
That might have appeared to end the trail.
Instead, investigators pivoted sideways.
They found leakedbb.net among domains associated through historical certificate information with:
mybbplugins.comNow the trail became much more interesting.
Historical DomainTools WHOIS information showed that mybbplugins.com had been publicly registered to Jitendra Maharaj from December 2011 until February 2019, before its registration information became privacy redacted.
That gave investigators a historical identity associated with infrastructure connected to the LeakedBB domain ecosystem.
But they kept going.
Certificate Transparency Added Another Layer
Certificate Transparency logs preserved more relationships.
Investigators found that mybbplugins.com had also been associated with certificate activity involving domains including:
jitendramaharaj.comjit-pay.ccand
thejitshow.comCertificate records for these domains appeared between approximately 2016 and 2021.
DomainTools records additionally showed names such as:
leakedbbjitendramaharajjit-payand
thejitshowappearing as subdomains associated with mybbplugins.com.
Now compare the evidence graph. It had become:
Two different evidence families were pointing in a similar direction.
That does not automatically establish ownership.
But analytically, it is much stronger than a single username match.
Seven Digits Hidden Inside an Email Address
Investigators then examined the oldest archived copy they could find of a LeakedBB payment page from November 2019.
Inside the HTML associated with the PayPal form was a ProtonMail address.
The username portion contained a sequence of seven digits.
Those digits matched part of what appeared to be a Fiji-based phone number used years earlier in WHOIS records for domains registered to Maharaj, including mybbplugins.com.
Bellingcat correctly highlighted an important limitation.
The historical phone-number information came from much earlier registrations, and investigators could not establish whether Maharaj was still using that number in 2019 when LeakedBB appeared.
A different Fiji-based number had also appeared in later domain-registration records.
This is where analytical discipline matters.
A weak investigator might write:
The numbers match. Therefore the same person controlled both systems.
A stronger investigator writes:
The matching sequence represents another association that gains significance only when considered alongside independent evidence.
That distinction is crucial.
Because OSINT attribution should not be constructed from one coincidence.
It should emerge from convergence.
Then the Human Behaviour Started Matching Too
Infrastructure is only one layer of digital identity.
People create another.
Usernames.
Aliases.
Developer accounts.
Social-media handles.
Repository history.
Repeated behaviours.
Bellingcat found archived posts from an X account using the same username associated with Maharaj's historical Facebook and Instagram presence.
Those archived posts, from November 2019, promoted LeakedBB.
Investigators also examined another identifier:
Darkmew
That username appeared in connection with Maharaj's historical online presence.
A GitHub account using the Darkmew identity hosted a repository described as the official repository for Pay It Now, or PIN Token, connected with Maharaj's cryptocurrency business.
That account later redirected to a profile using the name:
JitMaharaj
But two particular forked repositories were more interesting.
One related to software designed to create a cryptocurrency-enabled subscription platform similar to OnlyFans.
Another related to software designed to scrape and report illicit material from LeakedBB.
The existence of those repositories alone does not prove operation of the forum.
But again, they added context.
On 17 June, Bellingcat documented 38 visible repositories on the GitHub account.
After The Press sent questions on 22 June asking whether Maharaj controlled the account, investigators observed that only 25 repositories remained visible by 1 July.
The two repositories described above were among those no longer visible.
Deletion is not proof.
But timing is data.
Then LeakedBB Went Offline
The chronology became particularly notable in June.
The Press sent Maharaj an email on 4 June 2026, outlining the investigation's findings and requesting comment. Two days later:
LeakedBB was offline.
According to Bellingcat, the site remained inaccessible when the investigation was published on 16 July.
Journalists later approached Maharaj personally at his Christchurch residence.
He denied operating LeakedBB and said he did not know who was behind it.
He described the evidence as strange and suggested that it could represent a targeted attempt to associate him with the platform.
He acknowledged that Logica had been his company but did not provide a detailed explanation for the specific connections identified by the investigation.
Maharaj and his representatives were given additional time to respond, but according to Bellingcat had not directly addressed many of the detailed indicators by publication.
It is important to preserve this denial.
The investigation documented a network of associations.
It was not a criminal conviction or judicial determination of ownership.
That distinction should remain visible throughout any responsible discussion of this case.
One Forum, Multiple Investigative Surfaces
What makes the LeakedBB investigation particularly valuable for OSINT practitioners is how many different surfaces became relevant. The case crossed:
None was sufficient by itself. That is the point.
Imagine investigators had stopped after discovering Logica LTD.
They would have one commercial association.
Imagine they stopped after the historical WHOIS record.
They would have one technical association.
Imagine they relied only on the GitHub repositories.
They would have behavioural context.
Instead, different evidence classes began reinforcing one another.
This is what makes OSINT correlation powerful.
Infrastructure Has Memory
The live internet tells us what exists today.
Historical OSINT tells us what existed yesterday.
Sometimes yesterday is far more useful.
Consider domain registration.
A registrant may eventually enable privacy protection.
But historical WHOIS data can preserve earlier registrations.
Consider email infrastructure.
An organisation may move to ProtonMail or another provider.
Historical MX records may preserve previous relationships.
Consider TLS certificates.
A domain can disappear.
Certificate Transparency logs may still record that it existed.
Consider repositories.
A project can be deleted.
Forks, archives, commit history or cached references may survive.
The LeakedBB investigation demonstrates this beautifully.
At the time investigators examined certain assets, today's configuration concealed much of the historical context.
But the internet had already recorded earlier states. The investigative model therefore becomes:
This is what I think of as infrastructure memory.
The internet does not preserve everything.
But different systems remember different pieces.
An investigator's job is to reconstruct them.
The Real OSINT Technique Was Correlation
None of the individual techniques in this investigation was particularly magical.
WHOIS.
DNS.
Certificate Transparency.
Company registries.
Web archives.
GitHub.
Social media.
HTML inspection.
Payment records.
These are normal sources.
The sophistication came from the pivots.
A screenshot produced a company.
The company produced a domain.
The payment flow produced another association with that domain.
DNS produced another historical domain.
Certificate records linked that domain to older infrastructure.
WHOIS provided historical registration data.
Archived HTML exposed an email identifier.
That identifier resembled historical contact data.
Social-media archives produced promotional activity.
GitHub added another behavioural layer.
This is why the obsession with "the best OSINT tool" can sometimes miss the point.
Tools retrieve artefacts.
Investigators establish relationships.
Think in Graphs, Not Search Results
One way to visualise the investigation is as a graph.
The important evidence is not always the node.
Sometimes it is the edge.
That is a subtle but important difference.
Suppose you find a company called Logica Limited.
That alone tells you almost nothing about LeakedBB.
Suppose you discover an old domain registered to Maharaj.
Again, not enough.
Suppose a GitHub account forked software associated with subscription platforms.
Still insufficient.
The investigative value appears when these elements begin forming repeatable connections around the same infrastructure and identities.
Five Artefacts Do Not Necessarily Mean Five Sources
Correlation also introduces danger.
Analysts can easily overestimate confidence.
Imagine you discover five webpages repeating the same allegation.
You might conclude it as five sources confirm it.
But after tracing provenance:
Original post -> Blog article -> X repost -> News aggregator -> AI-generated summary
You actually have one source propagated five times.
The same principle applies to technical evidence.
Ten domains behind the same historical hosting account may effectively represent one evidence family.
A WHOIS database and another website reproducing that WHOIS record are not independent observations.
Good OSINT therefore asks:
How many independent evidence classes support the hypothesis?
That makes the LeakedBB case interesting because the investigation combined different categories:
- commercial records
- payment behaviour
- technical infrastructure
- archival evidence
- online identities
- developer activity
The convergence matters more than the raw number of artefacts.
Deletion Is Not Proof, But It Is Data
Another lesson from the case concerns disappearing information.
During the investigation:
- LeakedBB went offline.
- Maharaj's LinkedIn presence reportedly disappeared.
- A LeakedBB payment video was removed from YouTube.
- GitHub repositories became unavailable.
These events occurred during the period in which reporters were making inquiries.
That chronology is interesting.
But investigators must resist an easy cognitive trap.
Post hoc ergo propter hoc.
Because event B happened after event A does not automatically mean A caused B.
Repositories are deleted constantly.
Websites go offline.
People change account settings.
Platforms enforce policies.
Technical failures occur.
So the responsible conclusion is not they deleted the evidence because investigators discovered them.
It is these changes occurred during the investigation and form part of the chronology.
That is less dramatic.
It is also more defensible.
Capture First. Analyse Second.
Disappearing evidence also reinforces another operational lesson.
If an artefact matters, preserve it.
Do not assume the internet will look the same tomorrow.
Depending on legal, ethical and investigative requirements, preservation might include:
- screenshots
- archived URLs
- HTML copies
- timestamps
- cryptographic hashes
- DNS records
- WHOIS history
- Certificate Transparency results
- contemporaneous investigator notes
The key word is provenance.
Months later, saying "I remember seeing this page" is weak.
Being able to demonstrate:
"This content was captured from this URL, at this time, with this hash, and this archived copy independently preserves the same state"
is considerably stronger.
OSINT is not simply about finding evidence.
It is about maintaining the chain by which the evidence can be understood.
The Ethical Boundary Is Particularly Important Here
LeakedBB makes this discussion more complicated because the underlying material involved real victims.
An OSINT investigator does not need to obtain every file associated with a platform simply because the content is technically accessible.
In investigations involving:
- non-consensual intimate imagery
- potential child sexual abuse material
- leaked credentials
- private medical information
- or other highly sensitive content
the objective should be to collect the minimum evidence necessary to answer the investigative question.
If the investigation concerns infrastructure ownership, for example, the analyst may need:
- domains
- registration records
- payment pages
- DNS relationships
- company information
- archived metadata
They may not need the underlying victim content at all.
This is an important professional distinction.
Publicly reachable does not mean ethically unrestricted.
And curiosity is not an investigative requirement.
What Defenders Should Learn From LeakedBB
It would be easy to treat this as an investigation relevant only to journalists or OSINT researchers.
That would miss the cybersecurity implication.
The same techniques can be applied to organisations.
Your company may believe an old domain has disappeared.
Historical DNS disagrees.
Your development server may have been decommissioned.
Certificate Transparency remembers its hostname.
Your engineer may have deleted a public repository.
A fork may still exist.
Your organisation may have changed naming conventions.
Old certificates expose the previous structure.
A merger may have eliminated an old brand.
Archived pages still expose employees, technologies, contact details and infrastructure.
Attack Surface Management normally asks what is exposed today while OSINT adds another question like "What did we expose historically that can still be reconstructed today?"
That question deserves far more attention because adversaries are not restricted to the present.
The Internet Remembers Relationships
The LeakedBB investigation did not succeed because investigators discovered one magical database containing the answer.
It worked because fragments accumulated.
A support screenshot exposed a company name.
Corporate records provided a director.
An unusual avatar-payment system connected forum memberships with the company's website.
Historical DNS exposed infrastructure relationships.
Certificate Transparency preserved old domain associations.
WHOIS history remembered registration information that later became private.
Archived HTML exposed another identifier.
Social-media archives preserved promotional activity.
GitHub provided additional contextual relationships.
None of these artefacts, independently, necessarily resolves the attribution question.
Together they created a pattern substantial enough to investigate and report.
And that may be the most important lesson from this case.
We often say the internet never forgets.
That is not entirely accurate.
Websites disappear.
Files are deleted.
Accounts vanish.
Platforms shut down.
Servers are rebuilt.
Databases are overwritten.
But the internet does seem remarkably good at leaving fragments of relationships behind.
One system remembers that a domain pointed somewhere.
Another remembers that a certificate existed.
A web archive remembers a checkout page.
A company registry remembers a director.
A repository remembers an alias.
A forum remembers a payment instruction.
No single system understands the whole story. The investigator reconstructs it.
Perhaps that is why modern OSINT is increasingly less about discovering isolated information and more about understanding connections.
Because hiding one artefact is relatively easy.
Deleting one account is easy.
Changing one domain is easy.
Replacing one email address is easy.
But once an identity has interacted with enough infrastructure, companies, payment systems and online communities over enough years, removing every relationship between them becomes substantially harder.
So perhaps the better OSINT question is no longer:
What information can I find about this target?
It is:
What relationships has the target already left behind?
Because long after a webpage disappears and an account has been deleted, the infrastructure may still be talking.
See you in the next blog post with a different topic.

Post a Comment
0Comments