The defunct data breach site WeLeakInfo has suffered its own data breach, as a hacker appears to have leaked the service's payment details and customer data.

WeLeakInfo was a site that allowed users to access a database of 12.5 billion user records that had been stolen during data breaches. Of course, to gain access to the stolen files, users had to pay a subscription fee.
The stolen data included email addresses, phone numbers, and in many cases passwords. For this reason, many cybercriminals exploited the site to obtain information that they could use in phishing, credential stuffing, and other attacks.
See also: WeLeakInfo users arrested in the UK
However, in January 2020, an international police operation allowed the FBI to take control of the WeLeakInfo domain and shut down the site.
See more: FBI: WeLeakInfo.com shut down for selling stolen data

WeLeakInfo: The site that sold data from data breaches fell and became a victim of a data breach itself
Last Thursday, a hacker released a file with payment data, which WeLeakInfo used when processing payments through Stripe.
The data was posted on a popular hacking forum called RaidForums, where other criminals could download WeLeakInfo data by paying eight credits, a type of currency used on the forum.

One of the administrators of the hacking forum reported that his data have been leaked since he used WeLeakInfo.
The hacker behind the WeLeakInfo breach says that access to the site’s payment processing data was possible thanks to the expiration of the “wli.design” domain. WeLeakInfo is said to have used this domain for emails related to Stripe payments.
“I took control of the stripe account, as the FBI did not secure all the domains that belonged to WeLeakInfo and, as a result, the “wli.design”, the domain used for emails related to the payments, expired“.
See also: Scammers impersonate FBI agents and threaten with imprisonment!
“I was able to register this domain and then reset the password on their Stripe account, thus gaining full access to all customer information that was paying through Stripe,” the attacker explained in a post.
Last weekend, the company Cyble said that data from about 10,000 customers had been leaked.
The attacker has leaked spreadsheets with personal and corporate data, such as email addresses, names, billing addresses, the last four digits and expiration dates of credit cards, IP addresses, order history, IP addresses and phone numbers.
The leaked data also includes information about businesses that had used the service.
Most of these businesses are security companies, which were likely using the site to warn about stolen data.
Source: Bleeping Computer
