Twitter permanently suspended the Distributed Denial of Secrets (DDoSecrets) account after the group published BlueLeaks, a roughly 269GB cache of leaked U.S. law-enforcement files reportedly drawn from more than 200 police departments, fusion centers, and related agencies. The platform also blocked or flagged links to the BlueLeaks portal and DDoSecrets site under its policy on distributing hacked materials. Reports said the data originated from a breach tied to Texas-based web hosting provider Netsential, which hosted law-enforcement information-sharing portals, and that the archive contained sensitive records including personally identifiable information, financial data, suspect images, and internal communications.
The leaked documents were described as the largest known release of U.S. law-enforcement data and were reported to include material showing FBI threat referrals to local police, intelligence reporting on Black Lives Matter protests, and the labeling of protest medics and lawyers as potential extremists. DDoSecrets founder Emma Best criticized Twitter's enforcement, while coverage noted that other leak-publishing entities, including WikiLeaks, had remained accessible on the platform, raising questions about consistency in Twitter's moderation of hacked or leaked material.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Twitter disclosed in a legal filing that parts of its source code had been posted online and sought to identify the person responsible. The report marked a separate leak-related development involving Twitter itself rather than the BlueLeaks incident.
An Intercept report said the BlueLeaks archive exposed private details tied to more than 711,000 accounts from 251 law-enforcement-related websites. It also described how the sites, built and hosted by Netsential on shared Windows infrastructure with a custom ASP.NET/VBScript CMS and Microsoft Access databases, may have been broadly compromised through a single vulnerability.
German authorities seized a server in Falkenstein on 2020-07-03 at the request of the U.S. government after it hosted the BlueLeaks cache published by DDoSecrets. Prosecutors said judicial authorities would decide whether to transfer the seized server to U.S. authorities, while DDoSecrets said the data remained available via BitTorrent and Tor.
A DHS Office of Intelligence and Analysis bulletin circulated to fusion centers in late June 2020 described DDoSecrets as a 'criminal hacker group' and framed BlueLeaks as a hack-and-leak operation targeting law-enforcement databases. The characterization was disputed by DDoSecrets, but it marked a notable U.S. government attribution and escalation in response to the leak.
Twitter permanently banned the DDoSecrets account after the group published BlueLeaks, citing its policy on distributing hacked materials. The platform also began blocking or flagging links to the BlueLeaks/DDoSecrets portal as unsafe.
Distributed Denial of Secrets published BlueLeaks, a roughly 269GB trove of leaked law-enforcement data from more than 200 police departments and related entities. Reporting said the material was linked to a breach of Netsential, a Texas hosting company that maintained law-enforcement data-sharing portals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
12 references tracked. Mallory keeps watching after this page renders.
cnn.com
Open sourcethenation.com
Open sourcebusinessinsider.com
Open sourcetheverge.com
Open sourceweb.archive.org
Open sourcevice.com
Open sourcezdnet.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.