The Rise and Fall of BreachForums: A Cybercrime Empire Collapses

Quick Summary: BreachForums emerged in March 2022 as RaidForums’ successor and became the world’s dominant stolen data marketplace. Founded by Conor Fitzpatrick (pompompurin), it attracted major threat actors including ShinyHunters and IntelBroker. The platform collapsed between 2023-2026 through cascading administrator arrests, FBI seizures, a massive self-breach of 323,986 users, and internal power struggles. By March 2026, original moderators declared the platform dead, launching PwnForums as a replacement but trust was irreversibly broken.

Introduction

In August 2026, the ThreatMon Research Team released a definitive report documenting the complete lifecycle of BreachForums one of the largest English-language cybercrime marketplaces ever created. For four years, this single platform dominated the global stolen data economy. Yet despite its dominance, it ultimately collapsed under the weight of law enforcement operations, administrator arrests, and irreversible loss of community trust.

This story reveals a fundamental truth about underground economies: visibility breeds vulnerability. The very success that made BreachForums dominant sealed its fate.

The Predecessor: RaidForums

Before BreachForums existed, RaidForums (2015-2022) served as the premier underground marketplace for stolen data and cybercriminal services. Founded by Portuguese national Diogo Santos Coelho (known as Omnipotent), the forum became a behemoth: by 2022, it had accumulated over 530,000 registered users.

RaidForums succeeded because it was different. Unlike exclusive invitation-only forums, RaidForums remained publicly accessible. It supported multiple languages, could be indexed by search engines, and featured sophisticated reputation systems that built trust between buyers and sellers. Users advertised database dumps, credentials, phishing kits, malware, and initial network access.

On April 12, 2022, Operation TOURNIQUET by the FBI, U.S. Secret Service, and Europol seized RaidForums’ infrastructure. Omnipotent was arrested in the United Kingdom and charged with conspiracy to commit access device fraud. The platform vanished overnight.

Impact: Hundreds of thousands of cybercriminals were suddenly left without their primary marketplace for stolen information.

Birth of BreachForums

Nature abhors a vacuum. Just 11 days after RaidForums was seized, on March 4, 2022, Conor Brian Fitzpatrick operating under the alias pompompurin launched BreachForums.

Fitzpatrick came with built-in credibility. In November 2021, he had claimed responsibility for compromising the FBI’s Law Enforcement Enterprise Portal (LEEP), which was subsequently used to distribute thousands of fraudulent emails. His reputation within underground communities meant that when BreachForums launched, it had immediate visibility and trust.

Strategic Replication: BreachForums didn’t invent a new marketplace model it copied RaidForums’ structure almost exactly:

  • Identical marketplace categories
  • Reputation and vouching systems
  • Premium memberships
  • Vendor groups and private messaging
  • Discussion boards

 

This deliberate continuity allowed former RaidForums users to immediately recognize the interface and resume transactions. Many established vendors referenced their previous RaidForums identities when conducting transactions, enabling buyers to recognize trusted sellers without losing reputation scores.

Result: Within months, BreachForums became the dominant English-language marketplace for breached databases and stolen information.

The Golden Era (2022-2023)

Between 2022 and 2023, BreachForums transcended its role as a simple marketplace. It became an educational hub, operational command center, and reputation-building platform for the global cybercrime community.

What Made BreachForums Essential:

  • Database traders and access brokers conducted large-scale transactions
  • Ransomware affiliates coordinated campaigns and discussed victimology
  • Malware developers shared exploitation techniques and zero-day research
  • Threat actors built reputations through public breach announcements
  • Newcomers learned from established actors in dedicated technical sections

 

High-profile breach announcements generated hundreds of forum replies within hours. Users debated data authenticity, evaluated potential market value, and identified serious buyers. Unlike private, closed communities, BreachForums’ public nature meant that threat actors actively sought media attention to build reputation and drive up data valuations.

Platform Culture: Members exchanged operational security advice, cryptocurrency laundering strategies, and guidance on monetizing stolen data. This combination of commerce, education, and collaboration made BreachForums uniquely valuable to the cybercrime ecosystem.

Key Threat Actors Shaping the Platform

🔴 ShinyHunters: From Data Leaks to Cybercrime Brand

Among the most recognizable names on BreachForums was ShinyHunters, a threat actor collective that built its reputation through public data releases. Unlike traditional hacking groups that operated in secrecy, ShinyHunters became almost a brand within underground communities.

The group gained attention in 2020 after compromising major targets including Tokopedia (Indonesia’s largest e-commerce platform with tens of millions of user records), Wishbone, Mathway, Home Chef, and Promo.com. Their innovation was straightforward but effective: monetize the same dataset multiple times. Threat actors would first sell exclusive access privately, then advertise the database publicly, and eventually release portions to increase visibility.

Evolution: By 2024, ShinyHunters didn’t just post data on BreachForums they became associated with the platform’s co-administration alongside Baphomet, demonstrating how fluid roles within cybercrime ecosystems can be.

🔵 IntelBroker: The New Generation Data Broker

IntelBroker represented a different archetype: a threat actor who built fame not through forum administration but through high-profile data releases from recognizable targets.

Throughout 2024-2025, IntelBroker became associated with multiple significant breach claims:

TargetDateSignificance
AMD (Advanced Micro Devices)2024Internal company data and employee information from major semiconductor manufacturer
Europol (SIRIUS Platform)May 2024Sensitive law enforcement data; demonstrated willingness to target government institutions
AppleJune 2024Internal tools obtained via third-party contractor; highlighted supply-chain targeting
Verizon & Others2024-2025Multiple corporate breaches targeting high-profile brands for media value

Table 1: Major breach claims associated with IntelBroker, demonstrating targeting of high-profile organizations for reputation and financial gain

Strategy: IntelBroker specifically targeted organizations with recognizable names because high-profile breaches generate exponentially more attention, driving up reputation scores and data valuations. BreachForums provided the perfect platform for this public-facing model.

⚫ CyberNiggers: The Publicity-Driven Collective

CyberNiggers represented yet another evolution: a collective that actively embraced publicity and branding. Members included IntelBroker, EnergyWeaponUser, wonder, and 888 all of whom became well-known through public breach disclosures on BreachForums.

The group’s signature approach included branded graphics, public statements, and downloadable proof-of-compromise samples. Their most notable operation involved Nokia, where they claimed to have compromised a third-party supplier and released source code, configuration files, SSH keys, and development assets. Although Nokia maintained that its core infrastructure wasn’t directly compromised, the public announcement gave CyberNiggers significant reputation within underground communities.

The Collapse: Law Enforcement Strikes Back

BreachForums’ decline was not caused by a single catastrophic event. Instead, the platform gradually weakened through cascading law enforcement operations, administrator arrests, and loss of community trust. Each disruption created new vulnerabilities, until the platform could no longer sustain itself.

Timeline of Disruption
DateEventConsequence
March 15, 2023Fitzpatrick (pompompurin) arrested in Peekskill, NYForum destabilizes; Baphomet takes control
June 15, 2023FBI seizes BreachForums infrastructurePlatform goes completely offline; uncertainty spreads
2024-2025Multiple administrator arrests (IntelBroker, ShinyHunters members)Leadership vacuum; competing claims for control
January 9, 2026BreachForums’ own database leaked (323,986 users)Ironic reversal; massive loss of user trust
March 27, 2026Moderation team resigns via PGP-signed statementPlatform officially declared dead

Table 2: Cascade of events leading to BreachForums’ complete collapse from March 2023 to March 2026

Key Arrests: In 2025, law enforcement accelerated operations. Kai West (operating as IntelBroker) was arrested by U.S. prosecutors. French authorities arrested Raphaël (“Hollow”), Adel (“YuroSH”), and several ShinyHunters members. Each arrest removed critical leadership figures, creating vacuums filled with distrust and competing claims.

Crisis Cycle: Every administrator arrest triggered identical questions among users: “Is my data compromised? Are investigators monitoring me? Is the forum safe?” With no trusted authority to answer these questions, users increasingly abandoned the platform.

Final Irony: The Self-Breach

On January 9, 2026, BreachForums experienced an event so symbolically perfect it seemed almost scripted: its own database was leaked.

A database containing information associated with 323,986 BreachForums user accounts was publicly released through a website linked to ShinyHunters. The leaked data included:

  • Registration metadata and account creation dates
  • Historical IP addresses
  • Email accounts and contact information
  • Password hashes
  • Private message metadata

 

The Irony: BreachForums had spent years as a marketplace for exposing others’ data. Now it became a breach victim itself. A platform built on the unauthorized disclosure of corporate, government, and personal information ultimately experienced the same fate.

Intelligence Value: The leaked data provided investigators with unprecedented intelligence for correlating BreachForums users with activity across other underground platforms and historical cybercrime investigations. From a threat intelligence perspective, the database became far more valuable than typical credential leaks.

What This Means for Cybersecurity

The rise and fall of BreachForums illustrates why even the most influential underground platforms ultimately fail. The pattern is predictable and repeatable:

The Vulnerability Cycle:

  1. Growth → Visibility: As platforms expand to dominance, they become high-priority targets for law enforcement investigation
  2. Centralization → Single Points of Failure: Dependence on key administrators means that arrests create leadership vacuums
  3. Disruption → Trust Erosion: Each law enforcement operation, infrastructure seizure, or administrator arrest reduces community confidence
  4. Fragmentation → Succession: Competing factions attempt to control the platform or launch replacements, but trust is irreversibly broken
  5. Collapse → Migration: Users scatter to successor platforms that inevitably follow the same trajectory

 

Why BreachForums Couldn’t Survive: The platform didn’t collapse because demand for stolen data disappeared. Rather, BreachForums became too visible, too centralized, and too important for international law enforcement to ignore. Its very dominance sealed its fate.

The Successor Paradox: Although BreachForums no longer exists, platforms like PwnForums have emerged as replacements. However, none have managed to recreate the same combination of scale, influence, and reputation that made BreachForums the dominant marketplace of its era. The threat actors who built their reputations on BreachForums remain active, but the platform itself is dead.

Learn More with ThreatMon

Protect Your Organization Against Emerging Cybercrime Threats

ThreatMon’s intelligence platform continuously monitors dark and surface web activities, delivering early warnings and actionable insights into evolving threats affecting your organization.

ThreatMon Services:

  • Dark Web Monitoring: Real-time detection of leaked data and breach announcements
  • Threat Intelligence: Profiles of active threat actors and their infrastructure
  • Fraud Intelligence: Detection of fraudulent activities targeting your organization
  • Attack Surface Intelligence: Identification of vulnerable external assets

More posts

This image is about multiple Nginx vulnerabilities.
This image is about multiple Microsoft IIS vulnerabilities.
This image is about SMTP open mail relay vulnerability.
SSL Expire" means an SSL certificate has expired, causing security warnings for site visitors.
What is Server Header Information Disclosure?
advanced divider

Share this article

Found it interesting? Don’t hesitate to share it to wow your friends or colleagues

advanced divider

Subscribe to our blog newsletter to follow the latest posts