Fact-checked by Grok 2 weeks ago

BreachForums

BreachForums was an English-language cybercrime forum that operated as a marketplace for the buying, selling, and free distribution of stolen data compromised in hacks targeting corporations, governments, and individuals, positioning itself as the primary successor to the FBI-seized RaidForums. Launched on March 16, 2022, by administrator Conor Brian Fitzpatrick under the pseudonym "pompompurin," the platform quickly scaled to more than 330,000 registered users by attracting former RaidForums members with incentives like preserved user rankings and roles. It hosted over 888 datasets encompassing more than 14 billion personal identifiable information records, including financial details, Social Security numbers, passwords, and data from critical sectors such as telecommunications, social media, healthcare, and infrastructure protection groups like InfraGard. The forum's activities facilitated widespread data extortion, tool sharing, and collaboration among threat actors, but it drew intense law enforcement scrutiny, resulting in Fitzpatrick's arrest on March 15, 2023, for conspiracy to commit access device fraud alongside possession of child sexual abuse material, prompting an initial shutdown on March 21, 2023. Despite subsequent reopenings under new operators like "baphomet" and groups including ShinyHunters and IntelBroker, BreachForums endured further seizures by the FBI in May 2024 and October 2025, in coordination with international authorities, underscoring its persistent role in underground cybercriminal ecosystems. Fitzpatrick pleaded guilty to the charges and was resentenced in September 2025 to three years in federal prison, with forfeiture of domains, devices, and cryptocurrency proceeds derived from the forum's operations.

Origins and Launch

Predecessor Context: RaidForums Shutdown

RaidForums operated as a prominent English-language forum where cybercriminals shared and traded stolen data, hacking tools, and credentials, facilitating activities such as data breaches and extortion. The platform's infrastructure was seized by international law enforcement in early 2022 as part of Operation TOURNIQUET, a coordinated effort led by the United States Department of Justice, Federal Bureau of Investigation, and partners including the UK's National Crime Agency, Sweden's Security Service, and authorities in Romania. The seizure was publicly announced on April 12, 2022, with the site's domain displaying a law enforcement notice confirming the takedown. The operation resulted in the arrest of RaidForums' founder and administrator, Diogo Santos Coelho, a 23-year-old national known online as "Omnipotent," who was detained in the UK on February 18, 2022, and later extradited to the . Coelho pleaded guilty in 2023 to charges including to commit access device fraud and aggravated , stemming from his role in operating the forum and personally victims to obtain data for sale. He was initially sentenced to over seven years in prison in 2024 but resentenced to three years in September 2025 after a successful . The shutdown disrupted a key hub for illicit data trading, but it also prompted the rapid emergence of successor platforms, including BreachForums, which launched in March 2022 to left by ' users and activities.

Founding and Early Development (2022)

BreachForums was established on March 16, 2022, by Conor Brian Fitzpatrick, a resident of Peekskill, New York, who operated under the online alias "pompompurin." The forum emerged as a direct successor to RaidForums, an English-language hacking site seized by U.S. law enforcement in February 2022 following an FBI-led operation that resulted in the arrest of its founder, Diogo Santos Coelho (known as "Diogo"). Unlike its predecessor, BreachForums was initially hosted on the clear web, facilitating easier access for users sharing and trading compromised data, malware tools, and hacking discussions. In its early months, the platform experienced modest growth as it positioned itself as a for illicit data transactions, with sections dedicated to posting breached databases, dumps, and extortion-related materials. By mid-2022, it had begun attracting active threat actors and users displaced from , though initial user numbers remained limited compared to later iterations, reflecting a cautious buildup amid scrutiny. Fitzpatrick, then approximately 19 years old, administered the site personally, enforcing basic rules against certain extreme content while allowing the trade of stolen personal information from corporate breaches. This period marked the forum's foundational shift toward specializing in data leaks over broader topics, setting the stage for its expansion into a central hub for cybercriminal activity.

Platform Operations

Technical Architecture and Features

BreachForums utilized the open-source MyBB forum software, a PHP-based platform that supported threaded discussions, user accounts, private messaging, and file attachments for uploading large datasets such as breached databases. This architecture mirrored that of its predecessors, enabling structured categorization of content into dedicated sections for data leaks, lists, claims, and tutorials. The software's modularity allowed administrators to customize permissions, moderation tools, and search functionalities tailored to illicit data trading. The platform maintained dual accessibility through clearnet domains and Tor hidden services (.onion addresses), with the latter providing onion routing for enhanced anonymity and resistance to censorship. integration relied on backend servers configured to handle hidden service descriptors, allowing users to access the forum via the Browser without exposing IP addresses. Clearnet mirrors facilitated easier access for non-Tor users but were vulnerable to domain seizures, as evidenced by multiple takedowns. Key features included optional user verification for trusted status, which unlocked privileges for buying and selling stolen , tools, and services, while basic registration permitted browsing and posting. The supported embeds, systems based on post activity, and announcement boards for administrative updates, fostering a community-driven for collaboration. However, reliance on MyBB exposed the platform to known vulnerabilities, including zero-day exploits that compromised user in incidents like the April 2025 outage.

User Community and Content Moderation

BreachForums attracted a diverse base centered on , including initial access brokers, data traders, and hackers specializing in breaches and exploits. The forum's English-language interface and focus on illicit data markets drew over 340,000 registered members by mid-2023, with many migrating from the shuttered . engaged in posting compromised datasets, credential dumps, tools, and services like access, often verifying leaks through samples to build trust in transactions. While the emphasized practical operations, a subset included professionals passively monitoring for , though active participation risked legal exposure. Content moderation relied on a team of administrators and volunteer to enforce rules prioritizing member protection and transaction integrity over ethical constraints. Core prohibitions barred distribution targeting users, doxxing or sharing personal details of members, material, and unauthorized redistribution of premium or hidden , with violations triggering permanent bans. Harassment, begging for promotions, or disrespecting also warranted warnings or expulsion, while civil discussions on breaches and tools were permitted to sustain forum utility. confined to specific sections, tagged and isolated in NSFW areas, and direct without shorteners or surveys ensured operational hygiene, reducing scams that could erode user confidence. Enforcement mechanisms included user reporting systems, where frivolous submissions risked penalties, and staff curation of disputes to maintain credible listings amid high-volume posts. Assisting rule-breakers implicated accomplices in penalties, fostering self-policing within the community. These policies, while curbing internal , imposed few limits on external harms like sales, enabling the forum's role as a hub for over 800 datasets encompassing billions of records. Later iterations introduced revamped moderation to reassure returning users post-disruptions, but core allowances for facilitation persisted.

Cybersecurity Implications

Facilitation of Illicit Data Trade and Extortion

BreachForums operated as a prominent where cybercriminals traded stolen data, including breached databases, credentials, and personal information harvested from hacks. Users frequently posted "data dumps" containing millions of records, such as addresses, passwords, and financial details, either for free distribution to build reputation or for direct sale through auctions and fixed-price listings. For instance, in February 2025, threat actors advertised 20 million compromised user on the , offering stolen credentials for purchase to enable further account takeovers and . These transactions often involved cryptocurrencies, with vendors providing samples to verify data authenticity before full payment, facilitating a for initial access brokers and fraudsters. The platform's structure encouraged competitive trading, with dedicated sections for categories like "," "Credentials," and "Leaks," where sellers competed on volume and freshness of —such as records from recent or healthcare breaches—to attract buyers ranging from lone hackers to organized groups. Cybersecurity analyses noted that this ecosystem lowered barriers for downstream crimes, as purchased enabled , , and entry points, with forums like BreachForums serving as hubs for verifying and monetizing breaches that might otherwise remain undetected. By March 2023, prior to its initial shutdown, the site hosted threads for selling access to over 100 terabytes of corporate , underscoring its scale in amplifying the economic value of illicit acquisitions. Extortion activities on BreachForums typically involved threat actors posting partial victim datasets to coerce payments, leveraging the forum's audience for maximum pressure and proof-of-breach dissemination. Ransomware affiliates and data groups, such as , used dedicated leak threads to threaten full data releases unless ransoms were paid, often targeting enterprises like customers whose records—exceeding one billion in volume—were siphoned via vishing and traded or leaked starting in early 2025. In these schemes, actors like collaborated with affiliates (e.g., ) to auction access or demand payments in , with forum posts serving as public shaming tools to escalate urgency; for example, October 2025 threats against victims explicitly used BreachForums domains for leak announcements, prompting immediate data dumps when demands went unmet. This model mirrored broader trends where forums amplified by providing verifiable leak platforms, distinct from private negotiations, and enabled groups to monetize non-encrypted data thefts that bypassed traditional encryption.

Contributions to Threat Intelligence and Breach Exposure

BreachForums served as a centralized platform where threat actors frequently posted stolen datasets from high-profile breaches, enabling cybersecurity researchers and threat intelligence teams to monitor and analyze emerging risks in . Security firms, including those specializing in intelligence, routinely scraped the forum for indicators of compromise, such as exposed credentials, internal documents, and victim lists, which could alert organizations to undetected intrusions before public disclosure. For instance, groups like utilized the site to advertise and partially leak data from incidents involving entities such as (now X) in early 2022 and subsequent targets, providing raw material for verifying breach authenticity and assessing damage scope. This exposure mechanism inadvertently accelerated notifications and mitigation efforts, as companies often learned of their compromises through postings rather than internal detection alone. Cybersecurity reports highlight cases where BreachForums led to proactive credential resets and forensic investigations; for example, identified leaks of K-12 student directories posted by like "," prompting immediate security enhancements. Threat intelligence providers emphasized that such forums offered visibility into ecosystems, including sales of access brokers' tools and payloads, aiding in the development of behavioral profiles and predictive defenses. Beyond raw data dumps, the forum's discussions contributed to understanding cybercriminal methodologies, with threads detailing techniques and victim that informed broader industry . Providers like SOCRadar noted the value in tracking actor migrations and tool evolutions post-seizures, as centralized platforms like BreachForums simplified aggregation compared to fragmented channels. However, this intelligence utility depended on ethical monitoring practices, as unrestricted access risked aiding criminals; reputable firms prioritized passive observation to avoid direct engagement.

Controversies

Accusations of Enabling Cybercrime

BreachForums has faced repeated accusations from U.S. agencies of functioning as a primary marketplace that enabled by allowing users to buy, sell, and trade stolen , hacking tools, and credentials obtained through breaches. The U.S. Department of Justice (DOJ) specifically alleged that the platform, launched in March 2022 as a successor to the seized , attracted over 300,000 users who facilitated the distribution of databases containing millions of records, including details, numbers, and Social Security information from high-profile victims. These activities were said to directly contribute to downstream crimes such as , financial fraud, and campaigns, with forum sections dedicated to verifying and auctioning breach data to maximize its illicit value. For instance, in 2023, users advertised tens of thousands of stolen healthcare records from Nonstop Health on the site, including sensitive patient data like Social Security numbers, which an later faced a $700,000 fine for enabling through lax moderation. Law enforcement contended that the forum's structure, including vendor shops and services, lowered barriers for novice cybercriminals to exploit leaked information, thereby amplifying the economic impact of initial hacks. Accusations intensified around specific threat actors like , who leveraged BreachForums domains in 2025 to host sites for stolen customer data, threatening to release records unless ransoms were paid. The FBI described the platform as a "major criminal marketplace" that supported groups such as , , and IntelBroker in trafficking data and coordinating attacks, leading to multiple domain seizures in May 2024, August 2025, and October 2025. Federal prosecutors argued that operators like founder Conor Fitzpatrick knowingly profited from these operations, with the site's resilience after relaunches perpetuating a cycle of data monetization that fueled groups and operations.

Perspectives on Information Freedom and Vigilantism

Monitoring BreachForums and similar platforms provides cybersecurity teams with actionable threat intelligence, as leaked datasets often reveal ongoing or undetected compromises before official notifications. Security firms emphasize that scanning such forums enables early detection of stolen credentials, customer records, and internal documents, allowing organizations to implement countermeasures like password resets or forensic investigations. For instance, posts detailing breaches have alerted companies to vulnerabilities exploited by groups like ShinyHunters, who dumped data from entities including Microsoft and AT&T on the forum between 2023 and 2025. Proponents of freedom argue that restricting to these forums stifles in an ecosystem where corporations underreport incidents to avoid reputational damage or regulatory scrutiny. By facilitating the public dissemination of breached data, platforms like BreachForums compel entities to address systemic weaknesses, such as inadequate or controls, that persist due to profit motives over . This view holds that once data is compromised—often through preventable lapses—the unrestricted sharing aligns with principles of open , empowering individuals and researchers to verify exposures independently rather than relying on delayed corporate disclosures. Cybersecurity analysts have noted that such forums act as "early warning systems" for threats, with monitoring yielding insights into actor tactics that inform defensive strategies across industries. Vigilantism emerges in defenses of actors who leverage BreachForums to release data without ransom payments, positioning dumps as punitive measures against negligent organizations. Hackers affiliated with the platform, including those relaunching versions post-seizure, have invoked free speech rationales to justify operations, claiming they expose elite networks' failures while evading . For example, ' 2025 relaunch of BreachForums v4 framed it as a venue resistant to monitoring mandates, arguing that suppressing leak sites hinders accountability for breaches affecting millions, such as the campaign involving over 400 organizations. However, this self-styled overlooks collateral risks, including for non-culpable victims, and prioritizes unauthorized exposure over legal channels like vulnerability disclosures. Empirical data from forum activity shows dumps often follow failed extortions rather than pure ethical imperatives, with over 100 major leaks documented from 2022 to 2025 blending profit and purported . Critics within the , while acknowledging intel value, contend that the forum's structure incentivizes further breaches by providing markets for stolen , undermining any benefit from vigilance. Law enforcement disruptions, including the FBI's October 10, 2025, seizure of domains tied to extortion, highlight how such platforms aggregate harms exceeding isolated exposures. Nonetheless, the persistence of mirrors and Telegram migrations post-takedown underscores a resilient viewpoint that information freedom outweighs containment efforts in a decentralized landscape.

2023 Founder Arrest and Domain Seizure

On March 24, 2023, Conor Brian Fitzpatrick, a 20-year-old resident of Peekskill, New York, who operated under the online alias "Pompompurin," was arrested by U.S. federal authorities on charges related to his role as founder and administrator of BreachForums. He faced a one-count criminal complaint for conspiracy to commit access device fraud, stemming from the forum's function as a marketplace where cybercriminals bought, sold, and traded stolen personal data, login credentials, and tools for unauthorized access. The arrest disrupted initial operations, leading to a temporary shutdown of the site, though community members quickly relaunched it under new administrative oversight. Fitzpatrick's platform had succeeded , which he acquired after its 2022 seizure by authorities, and emphasized structured categories for data leaks, services, and tutorials, attracting over 150,000 members by early 2023. investigators highlighted the forum's role in enabling real-world harms, such as and , through the dissemination of millions of compromised records from corporate breaches. Following his arrest, Fitzpatrick was released on bail posted by his parents, but the case underscored law enforcement's focus on forum operators as key enablers of ecosystems. Three months later, on , 2023, the FBI, in coordination with partners, seized the clearnet domains associated with the relaunched BreachForums, replacing the site's content with an official . This action targeted the forum's primary accessible presence, aiming to interrupt ongoing illicit trading amid heightened scrutiny of platforms hosting breach announcements and demands. The followed the forum's resurgence post-arrest, during which it continued to host leaks from high-profile incidents, but did not immediately affect Tor-hidden services or mirrors used by users to evade restrictions. The June operation reflected a pattern of targeted disruptions against English-language forums, building on prior takedowns like , and involved forfeiture of domains linked to Fitzpatrick's activities, though the forum's decentralized user base and backup infrastructures allowed for partial continuity via alternative access points.

2024 International Law Enforcement Operation

On May 15, 2024, the United States Federal Bureau of Investigation (FBI), in coordination with international law enforcement partners, seized the clearnet domain of BreachForums, displaying a government seizure notice on the site. This operation targeted the forum's infrastructure, which had been relaunched approximately a year earlier by administrator "Baphomet" in partnership with the hacking collective ShinyHunters after the prior 2023 disruption. The seizures encompassed not only the primary domain but also the forum's official Telegram channel and a secondary channel operated by Baphomet. Law enforcement actions disrupted access to these platforms, which facilitated the trading of stolen data, hacking tools, and related services among over 150,000 registered users. While underground discussions speculated on Baphomet's potential arrest, no official announcements from U.S. or partner agencies confirmed such an outcome during the operation. The disruption proved temporary, as forum operators regained control of the domain within hours using its Emergency Provider Portability (EPP) code, enabling a reboot under continued administration by . By mid-June 2024, BreachForums had reinstated operations at its original , underscoring the challenges in permanently dismantling decentralized platforms reliant on mirrors and resilient administrative networks. This event represented the second major U.S.-led intervention against the forum within 12 months, highlighting ongoing efforts to interrupt illicit data markets without fully eradicating their underlying ecosystem.

2025 MyBB Zero-Day Infiltration and Admin Arrests

In April 2025, BreachForums administrators announced that the forum had been compromised through a suspected zero-day vulnerability in the MyBB forum software, prompting a voluntary shutdown to prevent further law enforcement access. The incident, detected around April 15, 2025, involved trusted sources alerting admins to an infiltration attempt attributed to global law enforcement agencies, leading to the site's inaccessibility and data preservation measures. While administrators publicly blamed a MyBB-specific exploit for enabling unauthorized access to administrative functions, no independent verification of the zero-day's existence or its exploitation by authorities has been disclosed by involved agencies. The infiltration heightened operational risks for operators, resulting in of credentials and details online, which further eroded trust among users and prompted copycat domains to emerge amid community confusion. This event followed prior disruptions but marked a shift toward suspected technical compromise rather than domain seizures, with admins emphasizing the zero-day as a novel vector for and evidence gathering. Subsequent investigations culminated in arrests of alleged BreachForums administrators and affiliates in June 2025. On June 26, 2025, French cyber police detained four French nationals accused of managing the forum and facilitating major data breaches, in coordination with U.S. authorities who confirmed the apprehension of five individuals linked to high-profile hacks advertised on the platform. Among those identified was IntelBroker, revealed as British national Kai West, alongside members of the ShinyHunters group, whose activities included extortion via leaked data hosted on BreachForums mirrors. These actions were part of broader international operations targeting cybercrime forums, though direct causation between the MyBB incident and arrests remains inferred from timing and admin disclosures rather than explicit law enforcement attribution.

October 2025 FBI Seizure Involving ShinyHunters

On October 10, 2025, the (FBI), in coordination with authorities including the Brigade de Lutte contre la Cybercriminalité (BL2C) and , seized domains associated with , a notorious underground facilitating breaches and . The targeted a specific on the platform exploited by the hacking collective to threaten the release of stolen customer unless demands were met. had publicly announced via a pinned Telegram post that from non-paying victims would be dumped at 11:59 PM Eastern Time on that date, escalating pressure on affected organizations. The seizure displayed an FBI takedown banner on the affected BreachForums domains, such as breachforums.hn, redirecting to official FBI contact points like breachforums#fbi.gov and the (IC3). This action disrupted ' operations, which had leveraged BreachForums for data leaks tied to high-profile breaches, including those linked to groups like (also known as Scattered Lapsus$ Hunters). According to statements attributed to post-seizure, the FBI's intervention compromised not only the primary domains but also backup databases, systems, and backend servers, effectively dismantling the forum's at that time. The FBI formally announced the seizures on October 12, 2025, via its official account and , describing BreachForums as a "major criminal marketplace" utilized by actors including and for illicit activities. This marked at least the fourth major U.S. disruption of BreachForums or its predecessors since the 2023 arrest of alleged founder Conor Fitzpatrick, highlighting persistent challenges in permanently neutralizing such resilient platforms. Despite the takedown, issued a PGP-signed message asserting the forum was "officially dead" but vowed to proceed with data releases independently, underscoring the limitations of domain seizures in deterring decentralized threat actors.

Resilience and Legacy

Patterns of Shutdowns and Relaunches

BreachForums has demonstrated a recurring pattern of operational disruptions through law enforcement seizures and arrests, followed by rapid relaunches under new administrative control or domains, often announced via Telegram channels or successor platforms. This cycle began after the initial 2023 takedown, with the forum re-emerging within weeks or months despite domain forfeitures and admin captures, reflecting the decentralized nature of underground cybercrime communities that migrate to alternative hosting or the Tor network. Following the June 2023 FBI domain seizure of breachforums.is—three months after founder Conor Fitzpatrick's arrest—the forum saw informal revivals through mirrors and partial operations, but sustained activity resumed more prominently after subsequent interventions. In May 2024, a multinational operation led by the FBI seized the rebooted site on May 15, yet it resurrected by May 29 under new management, including claims by actors like ShinyHunters, who reinstated it at the original .st domain by June 12. This quick recovery involved re-claiming domains and shifting to resilient infrastructures, with user discussions on Telegram facilitating continuity. In 2025, the pattern intensified with fragmented outages and relaunches amid escalating pressure. April disruptions were attributed to hacking collectives like R00TK1T, but the forum re-emerged with new domains by late , suffering reputational hits yet retaining core users. French authorities dismantled key admins in June, targeting a May 2024 relaunch variant active into February, but ShinyHunters announced a "classic form" revival in July. An August 12 shutdown followed claims of infiltration, only for another iteration to launch mid-year, culminating in the October 10 FBI seizure of servers tied to ' Salesforce extortion campaign. By October 26, the forum had resurfaced again with a new administrator and upgraded infrastructure, underscoring persistent adaptability despite repeated clearnet domain losses.
DateEventOutcome
June 2023FBI domain seizure post-arrestInformal mirrors; full relaunch delayed
May 15, 2024Multinational seizureRelaunch by May 29; reinstated June 12
April 2025Outages by collectivesNew domain relaunch by late April
July 2025 revivalActive until August infiltration claims
October 10, 2025FBI server seizureResurfaced by October 26 with new admin
These iterations highlight how takedowns disrupt but fail to eradicate the ecosystem, as operators leverage anonymity tools, international hosting, and community loyalty to rebuild, often within days of seizures.

Broader Impact on Underground Forums and Cybercrime Evolution

The shutdowns and relaunches of BreachForums have underscored the resilience of underground forums, prompting cybercriminal communities to adopt more agile operational models, such as rapid domain migrations and invite-only access systems to evade detection. Following the FBI's October 10, 2025, seizure of domains linked to the forum, which disrupted activities tied to groups like ShinyHunters, the platform resurfaced under new administration and infrastructure by October 26, 2025, illustrating how such sites evolve through decentralized hosting and quick administrative handovers rather than permanent cessation. This pattern mirrors broader shifts in cybercrime forums, where law enforcement disruptions, including the 2022 RaidForums seizure that BreachForums succeeded, have accelerated the use of ephemeral domains and alternative platforms like dark web successors, reducing reliance on single points of failure. BreachForums significantly influenced evolution by commoditizing stolen data, transforming breach sharing from niche exchanges to accessible clearnet-adjacent marketplaces that amplified the scale of , follow-on attacks, and campaigns. At its peak, the forum hosted nearly 225,000 members and served as a primary venue for trading databases, credentials, and initial access broker services, enabling threat actors to monetize breaches more efficiently and collaborate on large-scale operations, such as the 2025 Salesforce data linked to its portals. This accessibility lowered barriers for lower-skilled actors, contributing to a surge in data leak volume and the integration of breach forums with -as-a-service models, where leaked datasets serve as proof-of-concept for affiliate recruitment and victim shaming. The forum's prominence also highlighted vulnerabilities in the cybercrime ecosystem, fostering internal conflicts and infiltration tactics, such as the 2025 MyBB zero-day exploit used against administrators, which exposed the risks of centralized forum software and spurred a trend toward custom or hardened platforms in successor sites. Despite repeated interventions, including international operations in 2024, BreachForums' legacy persists in elevating data es as a core cybercrime vector, with underground markets now prioritizing verifiable leak authenticity and real-time sharing to outpace victim remediation efforts. This evolution has intensified pressure on organizations to enhance detection, as forums like BreachForums democratized access to exploitable intelligence, thereby sustaining a feedback loop of escalating attack sophistication and frequency.

References

  1. [1]
    BreachForums - Flashpoint.io
    Breach Forums was an English-speaking illicit forum that was on-track to become the replacement for Raid Forums. Established in March 2022 by pompompurin, ...
  2. [2]
    Founder of One of World's Largest Hacker Forums Resentenced to ...
    Sep 16, 2025 · We will not allow criminals to hide in the darkest corners of the internet and will use all legal means to bring them to justice.” “The FBI is ...
  3. [3]
    Feds Charge NY Man as BreachForums Boss “Pompompurin”
    Mar 17, 2023 · The US Federal Bureau of Investigation (FBI) this week arrested a New York man on suspicion of running BreachForums, a popular English-language cybercrime ...
  4. [4]
    One of the world's biggest hacker forums taken down - Europol
    Apr 12, 2022 · The illegal marketplace 'RaidForums' has been shut down and its infrastructure seized as a result of Operation TOURNIQUET, a complex law enforcement effort.Missing: details | Show results with:details
  5. [5]
    U.S. Leads Seizure of One of the World's Largest Hacker Forums ...
    Apr 12, 2022 · of the Justice Department's Criminal Division. “This is another example of how working with our international law enforcement partners has ...
  6. [6]
    Raidforums marketplace shut down in global operation - BBC
    Apr 12, 2022 · An online forum providing criminals with stolen personal data has been taken down, in a global operation which saw its founder arrested.
  7. [7]
    Founder of one of world's largest hacker forums resentenced to ...
    Sep 16, 2025 · BreachForums emerged as a replacement to RaidForums, a then major English-language hacking forum that law enforcement seized in February 2022.
  8. [8]
    The rise and fall of the BreachForums cybercrime network
    Oct 24, 2024 · In the cybersecurity world, the success of cybercriminal activities can be dependent upon and closely tied to the transfer of tools, ...<|separator|>
  9. [9]
    Justice Department Announces Arrest of the Founder of One of the ...
    Mar 24, 2023 · Conor Brian Fitzpatrick, 20, of Peekskill, New York, allegedly operated BreachForums as a marketplace for cybercriminals to buy, sell, and trade hacked or ...
  10. [10]
    Six Months Into Breached: The Legacy of Raidforums? - KELA Cyber
    Sep 12, 2022 · After RaidForums' shutdown, Breached emerged as a leading cybercrime forum, attracting thousands with leaked data and active threat actors.
  11. [11]
    Original BreachForums Admin Gets 3-Year Prison Sentence
    Sep 16, 2025 · Conor Brian Fitzpatrick, founder and administrator of the first iteration of the BreachForums cybercrime forum, received a three year prison ...
  12. [12]
    BreachForums Saga Continues. What's Next? - Intel 471
    Jul 18, 2024 · BreachForums, an infamous cybercriminal forum, is back in action after authorities disrupted it. Here's a look at the forum, including why ...
  13. [13]
    Breachforums: A complete retrospective and a look at its return
    Jul 27, 2025 · Message from breachforums admins announcing the forums shutdown on April 15, 2025. PGP signature was intact at this time. There was a lot of ...<|separator|>
  14. [14]
    BreachForums Resurfaces on Original Dark Web (.onion) Address
    Jul 25, 2025 · The site appears to be fully restored, including its infrastructure, user-leaked databases, official breach listings and forum posts. For your ...
  15. [15]
    FBI takes down BreachForums portal used for Salesforce extortion
    Oct 10, 2025 · On Tuesday, both the clearnet breachforums.hn data leak site and its Tor counterpart went offline. While the Tor site was quickly restored, the ...
  16. [16]
    Intro to Deep and Dark Web Forums - ZeroFox
    Jun 25, 2025 · BreachForums can be accessed via the surface web and TOR and does not require a verified personal account. However, the marketplace does require ...
  17. [17]
    Analysis of the April 2025 BreachForums Outage - OSINT Team
    Apr 20, 2025 · With this write-up / report, I want to look at the likely causes behind the latest disappearance of the Breach Forums aka breachforums.st ...
  18. [18]
    The Fall of Breach Forums & the Future of Data Leak Marketplaces
    Jun 22, 2023 · Breach Forums was established in March 2022, only a month after US law enforcement seized the popular hacking and data leak marketplace RaidForums.Missing: launched growth
  19. [19]
    Help Documents - BreachForums
    BreachForums - The premiere forum for data breaches and discussions ... Helping another member break the rules, results in you also being in fault for that exact ...
  20. [20]
    Why Do Users Get Banned from Cybercriminal Forums? - ReliaQuest
    Jun 24, 2021 · ReliaQuest examines bans on cybercriminal forums, from scams to rule violations. Discover the dynamics of underground enforcement in this ...
  21. [21]
    20 million OpenAI accounts offered for sale | Malwarebytes
    Feb 7, 2025 · But the stolen credentials could also be used to abuse the ... BreachForums, the Dark Web forum where the accounts were offered for sale ...
  22. [22]
    BreachForums risks: impact and defense for security teams
    BreachForums has faced repeated seizures, yet threats persist. Discover its key events, data traded, business impacts, and steps to secure your ...
  23. [23]
    ShinyHunters Wage Broad Corporate Extortion Spree
    Oct 7, 2025 · A cybercriminal group that used voice phishing attacks to siphon more than a billion records from Salesforce customers earlier this year has ...
  24. [24]
    FBI Seizes BreachForums Portal Used in Salesforce Extortion ...
    Oct 10, 2025 · The FBI, in collaboration with French authorities, has taken down the BreachForums domain used by the ShinyHunters group to extort companies ...
  25. [25]
    FBI seizes BreachForums servers as threatened Salesforce data ...
    Oct 10, 2025 · It was a threat that the criminals behind the site, a super-alliance of the ShinyHunters, Scattered Spider, and LAPSUS$ ransomware groups ...
  26. [26]
    CTA "mud" Actively Leaking K-12 Directories on Breach Forums
    A cyber threat actor (CTA) on “Breach Forums” who's employing the username “Mud” is actively leaking K-12 entities' student/faculty directories.
  27. [27]
    Dark Web Cybercrime Forums You Should Monitor
    Jan 22, 2024 · Advantage: Monitoring these platforms can alert organizations to breaches involving their data, allowing for timely response and mitigation ...
  28. [28]
    Key Dark Web Forums to Monitor - Flare
    Apr 6, 2023 · However, the benefit to implement dark web monitoring as part of your overall security posture can help your organization stay on top of ongoing ...
  29. [29]
    BreachForums Seized (Yes, Again) - SOCRadar
    Oct 10, 2025 · The U.S. Department of Justice, FBI, and France's BL2C cybercrime unit, with support from the Paris Prosecutor's Office, have seized the ...
  30. [30]
  31. [31]
    Breachforums Boss to Pay $700k in Healthcare Breach
    May 15, 2025 · Class-action attorneys sued Nonstop Health, which added Fitzpatrick as a third-party defendant to the civil litigation in November 2023, several ...
  32. [32]
    BreachForums Admin Fined $700,000 Over Major Health Care Data ...
    May 19, 2025 · On January 18, 2023, cybercriminals using BreachForums advertised tens of thousands of stolen records from Nonstop Health, including Social ...Missing: facilitation | Show results with:facilitation
  33. [33]
    US Authorities Seize BreachForums Domains - Infosecurity Magazine
    Jun 26, 2023 · Fitzpatrick, 20, of Peekskill, New York, is accused of operating BreachForums and thereby enabling cyber-criminals to trade in stolen data and ...
  34. [34]
    BreachForums, a key English-language cybercrime forum, seized by ...
    May 15, 2024 · A seizure notice posted to the site Wednesday said the site had been seized by the FBI and the DOJ, along with enforcement agencies in the U.K., ...
  35. [35]
    Notorious data leak site BreachForums seized by law enforcement
    May 15, 2024 · operating as a clear-net marketplace for cybercriminals to buy, sell, and trade contraband, including stolen access devices, means of ...
  36. [36]
    What Hacker Forums Reveal About Your Exposed Data
    Jul 11, 2025 · Ransomware and Data Extortion: This tactic involves encrypting a victim's files and demanding a monetary ransom for the decryption key.
  37. [37]
    FBI Strikes Major Blow Against Global Cybercrime: BreachForums ...
    Oct 14, 2025 · June 2023: ShinyHunters and Baphomet relaunched BreachForums v2, continuing operations as a marketplace for stolen data, hacking tools, and ...
  38. [38]
    BreachForums Shut Down in Apparent Law Enforcement Operation
    May 16, 2024 · The popular hacking forum BreachForums appears to have been shut down as part of an international law enforcement operation led by the United States.Missing: freedom | Show results with:freedom
  39. [39]
    FBI takedown banner appears on BreachForums site as Scattered ...
    Oct 10, 2025 · ... BreachForums platform. The site now bears an FBI seizure notice ... The group still plans to post stolen data on Friday night at 11:59 p.m. ...
  40. [40]
    Eastern District of Virginia | United States v. Conor Brian Fitzpatrick
    Jun 20, 2023 · Whistleblower Non-Prosecution Pilot Program · Careers · Contact Us ... BreachForums. This court-ordered notice is to help identify any ...
  41. [41]
    Police Arrest BreachForums Owner 'Pompompurin' on Hacking ...
    US law enforcement have arrested and charged the owner of BreachForums, a notorious platform hackers use to leak and sell data taken from data breaches.
  42. [42]
    BreachForums founder resentenced to three years in prison
    Sep 16, 2025 · A man who pleaded guilty in 2023 for charges related to his work as founder and operator of the notorious BreachForums website was ...
  43. [43]
    BreachForums Seized by FBI: Inside the Notorious Cybercrime ...
    May 16, 2024 · BreachForums, run by ShinyHunters and Baphomet, was an active hacking forum for cybercriminal activities, facilitating the trading of stolen goods and services.
  44. [44]
    Flash: BreachForums Marketplace Seized By Law Enforcement
    May 15, 2024 · On May 15, 2024, the popular English-language DDW forum BreachForums was seized in an operation likely coordinated by multiple international law enforcement ...
  45. [45]
    BreachForums Reveals Law Enforcement Crackdown Exploiting ...
    Apr 28, 2025 · Shuts Down After Suspected MyBB 0-Day Exploit. According to an official statement released by BreachForums' administrators, the incident was ...
  46. [46]
    BreachForums is Offline: A New Twist or Just Another Cyber ...
    Apr 16, 2025 · Deep dive into MCP server architecture, execution, threat intel use cases, security, and best practices. Compliance. Free Tools SOCRadar ...Breachforums Is Offline: A... · Unconfirmed Claims: The Dark... · Breachforums Reboots
  47. [47]
    BreachForums Disruption Sparks Darknet Chaos - DarkOwl
    May 15, 2025 · BreachForums Disruption Sparks Copycat Domains and Darknet Chaos ... forum software. This vulnerability was reportedly exploited either ...
  48. [48]
    BreachForums Archives - Security Affairs
    BreachForums, a major data leak marketplace, shut down on April 15 after a MyBB 0-day exploit allowed law enforcement infiltration. On April 15, BreachForums ...Missing: zero- | Show results with:zero-
  49. [49]
    BreachForums The Latest Updates - Cyberint
    The FBI, DOJ and others have taken control of BreachForums following a significant data leak from the Europol portal.
  50. [50]
    BreachForums admins arrested as IntelBroker's identity revealed
    Jun 26, 2025 · According to Le Parisien, French cyber police arrested four French nationals allegedly responsible for running the forum. The alleged hackers ...
  51. [51]
    US, French authorities confirm arrest of BreachForums hackers
    Jun 26, 2025 · US and French authorities have confirmed the arrests of five hackers accused of being behind several major hacks and being part of a notorious cybercrime forum.
  52. [52]
    ShinyHunters Members Arrested, IntelBroker Identified as Kai West
    Jun 26, 2025 · Four alleged ShinyHunters members arrested, IntelBroker exposed as British national Kai West in global crackdown linked to BreachForums and major data breaches.<|separator|>
  53. [53]
    Feds Shutter ShinyHunters Salesforce Extortion Site - Dark Reading
    Oct 10, 2025 · The group warned that law enforcement crackdowns are imminent in the wake of the takedown, but its extortion threats against Salesforce ...
  54. [54]
    BreachForums seized, but hackers say they will still leak Salesforce ...
    Oct 10, 2025 · Law enforcement agencies in the United States and France have seized control of domains linked to the notorious BreachForums hacking forum, ...
  55. [55]
    FBI seizes clear web domain linked to Scattered Lapsus$ Hunters
    Oct 10, 2025 · BreachForums has been taken down once again, but hackers defy law ... Comments will undergo moderation before they get published.
  56. [56]
    FBI 'seizes and destroys' website linked to hackers threatening to ...
    Oct 10, 2025 · ... BreachForums website domains had been taken down. ... The FBI and Qantas have not publicly commented on the claims about the website seizure.
  57. [57]
    FBI - X
    Oct 12, 2025 · The FBI and our partners have seized domains associated with BreachForums, a major criminal marketplace used by ShinyHunters, Baphomet, ...
  58. [58]
    FBI – Federal Bureau of Investigation - Facebook
    Oct 12, 2025 · The FBI and our partners have seized domains associated with BreachForums, a major criminal marketplace used by ShinyHunters, Baphomet, ...
  59. [59]
    BreachForums Returns Just Weeks After FBI Seizure - Honeypot or ...
    May 29, 2024 · BreachForums is back! Just two weeks after a coordinated law enforcement takedown, the notorious cybercrime marketplace has resurfaced.<|control11|><|separator|>
  60. [60]
    Flash Report: BreachForums Allegedly Relaunched With New Domain
    It is very likely that numerous threat actors will seek to capitalise on the uncertainty surrounding the new domain by creating alternative ...
  61. [61]
    French Authorities Dismantle BreachForums Core Team
    Jun 26, 2025 · Executive Summary. French law enforcement, in a significant international operation, has successfully dismantled the core administrative ...
  62. [62]
    Flash Report: Dark Web Discussion Centers on BreachForums Outage
    Apr 17, 2025 · BreachForums experienced several outages during 2024. Notably, in April, hacking collective “R00TK1T” claimed responsibility for the disruption ...Missing: shutdown | Show results with:shutdown
  63. [63]
  64. [64]
    Top 5 Data Leak Forums in the Cybercrime Underground Market
    Sep 5, 2025 · Cybercrime forums on the dark web serve as the primary channels for attackers to obtain leaked databases. These forums foster entire ...
  65. [65]
    August 2025 Cybercrime Update: Forums, Ransomware & GenAI
    BreachForums went dark in mid-April 2025 after a series of arrests and takedowns led by French authorities, leaving a chaotic power vacuum in the data breach ...Missing: relaunch | Show results with:relaunch