This article is about ‘TeamPCP Threat Actor’.
BreachForums was one of the most influential English-language cybercrime forums of the last decade, serving as a major marketplace for stolen data, initial access, cybercrime services, and collaboration between threat actors. Although the original forum ultimately collapsed following law enforcement actions, internal disputes, and failed attempts to restore the platform, its influence continues to shape today’s underground ecosystem.
This report provides a chronological examination of the complete lifecycle of BreachForums, beginning with the rise and fall of RaidForums, the platform that laid the foundation for its successor. It follows the creation of BreachForums under pompompurin, its rapid growth into the dominant English-language cybercrime forum, the arrests of key administrators, repeated law enforcement operations, leadership transitions involving Baphomet, ShinyHunters, and IntelBroker, and the platform’s multiple attempts to remain operational despite increasing pressure.
The report also examines the activities of several prominent threat actors and administrator figures, including members of CyberNiggers, and documents major events that shaped the forum’s history, including high-profile data breaches, ownership changes, administrator arrests, internal conflicts, the emergence of PwnForums, the exposure of the individual operating under the aliases N/A and Caine, and the eventual leak of BreachForums’ own user database.
Rather than focusing solely on individual cybercriminals, this report documents the broader evolution of one of the underground ecosystem’s most significant communities from its origins and rapid expansion to its fragmentation and eventual collapse. Drawing on publicly available reporting, court documents, law enforcement announcements, threat actor statements, and open-source intelligence, it provides a historical reference for cybersecurity professionals seeking to understand how modern cybercrime forums evolve, how they are disrupted, and why even the most influential underground platforms ultimately fail.
We see the full picture of the evolving cyber threat landscape thanks to unique tools for monitoring the infrastructure used by cybercriminals and data from battlefields: