Breachforums -
Despite being illegal, BreachForums (and its data corpus) offers valuable intelligence for defenders:
The story did not end there. Within weeks, a new administrator known as ShinyHunters—an alias tied to a notorious threat group responsible for massive data thefts from Microsoft and AT&T—relaunched the forum under the same name, claiming to have a full backup of the original database.
For another 12 months, the forum operated with impunity, refining its security. They required users to deposit cryptocurrency for access to premium leak sections, and they introduced strict OpSec (Operational Security) guidelines. BreachForums
However, in May 2024, a coordinated international law enforcement operation dubbed "Operation Endgame" (or subsequent follow-up actions) led to the seizure of BreachForums’ servers and the arrest of its administrator, later identified as a individual in the United States.
To understand BreachForums, one must first understand the void it filled. In 2022, the FBI and international law enforcement agencies executed "Operation Tourniquet," seizing the infrastructure of RaidForums, a platform responsible for leaking data from over 3.2 billion user accounts. Despite being illegal, BreachForums (and its data corpus)
Enter a user known as "Pompompurin." Just weeks after RaidForums fell, Pompompurin launched BreachForums (previously known as Breached). The platform was not just a clone; it was an upgrade. It boasted faster servers, a user-friendly interface (rare for the Dark Web), and a strict "mirror" system for verifying data leaks.
Unlike anonymous drug markets, BreachForums specialized in information. This included: The hubris of BreachForums was its downfall
The hubris of BreachForums was its downfall. By hosting the DC Health Link data (which included sensitive information on U.S. House members and staff), Pompompurin painted a target on his back.
In March 2023, the FBI, in collaboration with the UK’s National Crime Agency (NCA), Europol, and other international agencies, launched Operation Cookie Monster.
On March 15, 2023, agents arrested Conor Brian Fitzpatrick (Pompompurin) in Peekskill, New York. Simultaneously, the FBI seized the BreachForums domain and replaced it with a seizure banner.
The Aftermath:
