NEWS

WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

A threat actor has published a database allegedly containing 19,000 user records from WormGPT, the underground AI platform marketed for offensive hacking...

Dylan H.

News Desk

February 20, 2026
4 min read
WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

The Hacker Gets Hacked

In a deeply ironic twist, WormGPT — the underground AI platform explicitly marketed for crafting phishing emails, generating malware code, and automating cyberattacks — has itself been breached. A threat actor using the handle "Sythe" posted what they described as a downloadable WormGPT user database on a data leak forum on February 11, 2026, claiming more than 19,000 unique user records are included.

The exposed data reportedly includes email addresses, subscription details, payment method metadata, user IDs, and other account fields — creating a rich dataset that could be used to identify, target, or blackmail the very cybercriminals who used the platform.


What Was Exposed

Data FieldDescriptionRisk
Email addressesUser registration emailsIdentity exposure, phishing targeting
Subscription detailsPlan type, duration, features usedReveals depth of criminal activity
Payment metadataPayment method indicators (not full card numbers)Financial profiling
User IDsInternal account identifiersCross-referencing with other breaches
Account creation datesWhen users signed upTimeline of criminal intent

What Is WormGPT

WormGPT emerged in 2023 as one of the first "jailbroken" AI platforms explicitly designed for cybercrime. Unlike legitimate AI services that implement safety guardrails, WormGPT was marketed as an uncensored alternative capable of:

  • Generating sophisticated phishing and BEC (Business Email Compromise) content
  • Writing malware code without safety restrictions
  • Creating social engineering scripts in multiple languages
  • Automating exploit development workflows

The platform operated on a subscription model, charging users for access to its unrestricted AI capabilities. It gained significant attention in the cybersecurity community as a harbinger of AI-enabled cybercrime at scale.


Why This Breach Matters

For Law Enforcement

The leaked database is a potential goldmine for law enforcement agencies. Email addresses tied to WormGPT subscriptions could help identify individuals actively engaged in cybercrime, particularly when cross-referenced with:

  • Other breach databases
  • Dark web forum registrations
  • Cryptocurrency transaction records
  • Known threat actor aliases

For WormGPT Users

The exposed users now face several risks:

  1. Identity exposure — Linking an email to a criminal AI platform is incriminating
  2. Targeted phishing — Other threat actors could target WormGPT users with highly tailored attacks
  3. Blackmail and extortion — Threat actors could threaten to expose users' identities to employers or law enforcement
  4. Competitive targeting — Rival cybercrime operations could use the data to identify and disrupt competitors

For the Security Community

The breach provides valuable threat intelligence about the scale and demographics of the cybercriminal AI user base. Palo Alto's Unit 42 has documented how malicious LLMs like WormGPT, MalTerminal, and LameHug operate, and user data from breaches like this helps researchers understand adoption patterns.


Verification Status

The claim remains pending independent verification:

  • No confirmation from WormGPT operators
  • The full dataset is not available through legitimate channels
  • Cybersecurity firms are analyzing samples for authenticity
  • The threat actor's reputation on the forum is being assessed

However, the level of detail in the posted samples and the specificity of the data fields suggest the leak may be genuine.


The Bigger Picture: Criminal AI Platforms

WormGPT is not an isolated case. The underground ecosystem of malicious AI platforms has grown significantly:

PlatformStatusDescription
WormGPTBreachedOriginal criminal AI chatbot
FraudGPTActiveFocused on financial fraud automation
MalTerminalActiveMalware generation and C2 framework
LameHugActiveSocial engineering and phishing automation
DarkBardDefunctEarly Google Bard jailbreak wrapper

Key Takeaways

  1. 19,000 cybercriminal AI users potentially exposed — The WormGPT breach creates a unique intelligence opportunity
  2. Email addresses are the key risk — They enable identity linking and targeted operations
  3. Law enforcement has a new lead — Cross-referencing this data with existing intelligence could identify active threat actors
  4. Criminal platforms are not immune to breaches — The same security failures they exploit affect their own infrastructure
  5. Verification is ongoing — The breach claim has not been independently confirmed

Sources