- Messages
- 3,994
- Likes
- 1,873
- Points
- 2,130
The admin password opened the way to a $202,000 proxy empire.
A weak password like "admin" was enough to turn someone else's router into a money-making operation for a third-party operator. Researchers discovered the LeakySensey network, which over two years gained access to more than 87,000 IP addresses through old VPN devices and other internet-accessible systems, then resold connections to them as proxies. Since 2024, more than 24,000 transactions totaling approximately $202,000 have been processed through the payment infrastructure associated with the operation.
The investigation began after specialists discovered an exposed server on July 20, 2026, exposing LeakySensey's internal infrastructure. The server contained tools for mass internet scanning and password brute-force analysis, client lists, activity logs, and a database of compromised nodes, along with valid credentials. Passwords regularly included the simple combinations "admin" and "admin123."
LeakySensey searched for open PPTP, L2TP, and SSH services and then automatically checked for weak credentials. The researchers found over 63,000 hosts accessed via PPTP, over 24,000 via L2TP, and 24,000 via SSH. The primary targets were old routers, VPN gateways, network attached storage devices, and other equipment that owners still kept accessible from the internet.
PPTP and L2TP are legacy VPN protocols . Microsoft began deprecating PPTP and L2TP for incoming VPN connections in future versions of Windows Server in 2024 , recommending switching to SSTP and IKEv2. L2TP itself does not provide traffic encryption and requires additional secure transport, typically IPsec, for secure operation.
After a hack, LeakySensey converted accessible hosts into residential proxies . A client of this service can send traffic through the IP address of a home or corporate ISP, so the destination site sees the connection as coming from a regular user network, not a known data center. Such addresses are prized by attackers because they help conceal the source of automated requests and make blocking based on IP reputation more difficult.
When the server was discovered, 17,858 addresses in the LeakySensey database had a ready or connected status and were configured to act as proxies. Database dumps contained over 56,000 user records, and over 11,000 accounts were linked to Telegram. Access was sold directly through websites and Telegram bots, and was also shared with other proxy providers.
Researchers found several services in the database to which LeakySensey granted access to addresses, including VPN Pure, Pure Connect, Rich Proxy, Opm Proxy, For Friends, and SkySocks. The presence of these companies in the database alone does not prove that the service owners knew the origin of the nodes. The researchers specifically noted that this discovery raises questions about how thoroughly residential proxy vendors verify the sources of their addresses.
Another piece of artificial intelligence infrastructure was discovered on the exposed server. According to the researchers, the operator maintained an automated system of five Python scripts that modified new versions of Claude Code and distributed the modified builds through private NPM packages for Windows, Linux, and macOS.
The modified version disabled confirmation prompts, granted the agent extended file system access, and allowed it to dispatch tasks to models from various providers, including OpenAI, Google, and Qwen. Standard Claude Code, by contrast, uses a permissions system : dangerous changes and command execution by default require user control or are executed within a restricted environment. Cybernews shared information about the discovered modification with Anthropic, but the developer did not publicly confirm the researchers' findings in the published investigation.
The server also contained 12 Antigravity accounts, one Claude account, five Codex accounts, and two Gemini accounts. Requests passed through an intermediate gateway that allowed work to be distributed among different AI services. The researchers admit that this scheme could have been used to increase throughput, bypass request limits, or grant access to other users, but found no direct evidence of the sale of the modified AI service.
LeakySensey's infrastructure has also been repeatedly attacked. Third-party attackers installed a Monero miner on a server hosting Git repositories, after which the operator deleted 37 unauthorized accounts. In another case, criminals stole proxy access keys and began using the network for free until the owner discovered the compromise.
Researchers believe the LeakySensey operator likely operates from Russia, but their identity and location have not been independently confirmed. Russian-language comments in the code, configuration files, queries to language models, and the website sensey24.ru, which presents itself as an IT consulting and development service, indicate a Russian origin. The server also contained tools and materials related to research into bypassing Russian traffic filtering.
The LeakySensey server was hosted on the infrastructure of the French ISP OVH, but the port discovered by researchers later stopped responding. Experts speculate that the operator may have migrated the infrastructure after the leak.
Owners of older network equipment are advised to do more than just change their passwords. Unsupported devices should be replaced or updated, administrative and VPN services should not be left accessible to the entire internet, and legacy systems should be isolated from the main network. After suspecting a hack, experts recommend searching for unauthorized SOCKS5 proxies and other signs of compromise, as well as changing passwords, API keys, tokens, and other secrets that may have been stored on the compromised device.
A weak password like "admin" was enough to turn someone else's router into a money-making operation for a third-party operator. Researchers discovered the LeakySensey network, which over two years gained access to more than 87,000 IP addresses through old VPN devices and other internet-accessible systems, then resold connections to them as proxies. Since 2024, more than 24,000 transactions totaling approximately $202,000 have been processed through the payment infrastructure associated with the operation.
The investigation began after specialists discovered an exposed server on July 20, 2026, exposing LeakySensey's internal infrastructure. The server contained tools for mass internet scanning and password brute-force analysis, client lists, activity logs, and a database of compromised nodes, along with valid credentials. Passwords regularly included the simple combinations "admin" and "admin123."
LeakySensey searched for open PPTP, L2TP, and SSH services and then automatically checked for weak credentials. The researchers found over 63,000 hosts accessed via PPTP, over 24,000 via L2TP, and 24,000 via SSH. The primary targets were old routers, VPN gateways, network attached storage devices, and other equipment that owners still kept accessible from the internet.
PPTP and L2TP are legacy VPN protocols . Microsoft began deprecating PPTP and L2TP for incoming VPN connections in future versions of Windows Server in 2024 , recommending switching to SSTP and IKEv2. L2TP itself does not provide traffic encryption and requires additional secure transport, typically IPsec, for secure operation.
After a hack, LeakySensey converted accessible hosts into residential proxies . A client of this service can send traffic through the IP address of a home or corporate ISP, so the destination site sees the connection as coming from a regular user network, not a known data center. Such addresses are prized by attackers because they help conceal the source of automated requests and make blocking based on IP reputation more difficult.
When the server was discovered, 17,858 addresses in the LeakySensey database had a ready or connected status and were configured to act as proxies. Database dumps contained over 56,000 user records, and over 11,000 accounts were linked to Telegram. Access was sold directly through websites and Telegram bots, and was also shared with other proxy providers.
Researchers found several services in the database to which LeakySensey granted access to addresses, including VPN Pure, Pure Connect, Rich Proxy, Opm Proxy, For Friends, and SkySocks. The presence of these companies in the database alone does not prove that the service owners knew the origin of the nodes. The researchers specifically noted that this discovery raises questions about how thoroughly residential proxy vendors verify the sources of their addresses.
Another piece of artificial intelligence infrastructure was discovered on the exposed server. According to the researchers, the operator maintained an automated system of five Python scripts that modified new versions of Claude Code and distributed the modified builds through private NPM packages for Windows, Linux, and macOS.
The modified version disabled confirmation prompts, granted the agent extended file system access, and allowed it to dispatch tasks to models from various providers, including OpenAI, Google, and Qwen. Standard Claude Code, by contrast, uses a permissions system : dangerous changes and command execution by default require user control or are executed within a restricted environment. Cybernews shared information about the discovered modification with Anthropic, but the developer did not publicly confirm the researchers' findings in the published investigation.
The server also contained 12 Antigravity accounts, one Claude account, five Codex accounts, and two Gemini accounts. Requests passed through an intermediate gateway that allowed work to be distributed among different AI services. The researchers admit that this scheme could have been used to increase throughput, bypass request limits, or grant access to other users, but found no direct evidence of the sale of the modified AI service.
LeakySensey's infrastructure has also been repeatedly attacked. Third-party attackers installed a Monero miner on a server hosting Git repositories, after which the operator deleted 37 unauthorized accounts. In another case, criminals stole proxy access keys and began using the network for free until the owner discovered the compromise.
Researchers believe the LeakySensey operator likely operates from Russia, but their identity and location have not been independently confirmed. Russian-language comments in the code, configuration files, queries to language models, and the website sensey24.ru, which presents itself as an IT consulting and development service, indicate a Russian origin. The server also contained tools and materials related to research into bypassing Russian traffic filtering.
The LeakySensey server was hosted on the infrastructure of the French ISP OVH, but the port discovered by researchers later stopped responding. Experts speculate that the operator may have migrated the infrastructure after the leak.
Owners of older network equipment are advised to do more than just change their passwords. Unsupported devices should be replaced or updated, administrative and VPN services should not be left accessible to the entire internet, and legacy systems should be isolated from the main network. After suspecting a hack, experts recommend searching for unauthorized SOCKS5 proxies and other signs of compromise, as well as changing passwords, API keys, tokens, and other secrets that may have been stored on the compromised device.