The World Leaks extortion group claimed it breached Hungarian media company Mediaworks and published nearly 8.5 TB of allegedly stolen data on its leak site. Mediaworks confirmed an incident involving unauthorized access to a significant volume of illegally obtained data and opened an investigation, while warning that use or publication of the leaked material could be criminal. Local reporting said the exposed files included payroll records, contracts, financial statements, internal communications and notes from a January 2025 editorial meeting that allegedly referenced possible contact with Moscow over articles targeting Ukrainian President Volodymyr Zelensky; the authenticity of that memo has not been independently verified.
Separately, the Everest ransomware group began leaking what it said was a 108 GB dataset tied to insurer Liberty Mutual after alleging the company did not respond to its demands. Liberty Mutual acknowledged the claims and said its investigation so far indicates the incident appears linked to a third-party vendor rather than a compromise of its own systems or networks. The allegedly stolen files reportedly contain policyholder data, including names, addresses, policy numbers, and financial and insurance details, underscoring how extortion groups are continuing to pressure victims by publishing sensitive data even when direct network encryption is not evident.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Mediaworks confirmed that unauthorized parties may have obtained a significant amount of illegally acquired data and said it had launched an investigation. The company also warned journalists that using or publishing the leaked material could be criminal and reportedly sought removal of coverage about the leaked memo.
World Leaks claimed responsibility for a ransomware-related breach of Hungarian media company Mediaworks and said it published nearly 8.5 terabytes of allegedly stolen data on its leak site. The incident was described as the group's first known operation in Hungary.
Liberty Mutual said it was aware of the online claims and immediately launched an investigation. The company stated its review indicated the incident appeared to involve a third-party vendor rather than a compromise of Liberty Mutual's own systems.
The Everest ransomware group began publishing what it claimed was Liberty Mutual data after alleging the insurer did not respond to its demands. The leak was described as being replicated across hacker forums and leak database sites.
Telex published reporting on a leaked Mediaworks document that allegedly described phone assistance from Moscow for discrediting Zelensky. This public reporting revealed part of the contents of the broader Mediaworks leak.
Everest said the dataset tied to Liberty Mutual was stolen on April 30, 2026, and described it as more than 108 gigabytes. The allegedly stolen files reportedly included policyholder names, addresses, policy numbers, and financial and insurance details.
A leaked internal Mediaworks note from a January 2025 editorial meeting reportedly referenced possible phone contact with Moscow regarding articles targeting Ukrainian President Volodymyr Zelensky. The memo later became part of reporting on the broader Mediaworks data leak.
The World Leaks cyber-extortion group emerged in early 2025 as a rebrand of the Hunters International operation. The group primarily shifted to data theft and extortion rather than file-encrypting ransomware attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcetelex.hu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.