Quick Summary: BreachForums emerged in March 2022 as RaidForums’ successor and became the world’s dominant stolen data marketplace. Founded by Conor Fitzpatrick (pompompurin), it attracted major threat actors including ShinyHunters and IntelBroker. The platform collapsed between 2023-2026 through cascading administrator arrests, FBI seizures, a massive self-breach of 323,986 users, and internal power struggles. By March 2026, original moderators declared the platform dead, launching PwnForums as a replacement but trust was irreversibly broken.
In August 2026, the ThreatMon Research Team released a definitive report documenting the complete lifecycle of BreachForums one of the largest English-language cybercrime marketplaces ever created. For four years, this single platform dominated the global stolen data economy. Yet despite its dominance, it ultimately collapsed under the weight of law enforcement operations, administrator arrests, and irreversible loss of community trust.
This story reveals a fundamental truth about underground economies: visibility breeds vulnerability. The very success that made BreachForums dominant sealed its fate.
Before BreachForums existed, RaidForums (2015-2022) served as the premier underground marketplace for stolen data and cybercriminal services. Founded by Portuguese national Diogo Santos Coelho (known as Omnipotent), the forum became a behemoth: by 2022, it had accumulated over 530,000 registered users.
RaidForums succeeded because it was different. Unlike exclusive invitation-only forums, RaidForums remained publicly accessible. It supported multiple languages, could be indexed by search engines, and featured sophisticated reputation systems that built trust between buyers and sellers. Users advertised database dumps, credentials, phishing kits, malware, and initial network access.
On April 12, 2022, Operation TOURNIQUET by the FBI, U.S. Secret Service, and Europol seized RaidForums’ infrastructure. Omnipotent was arrested in the United Kingdom and charged with conspiracy to commit access device fraud. The platform vanished overnight.
Impact: Hundreds of thousands of cybercriminals were suddenly left without their primary marketplace for stolen information.
Nature abhors a vacuum. Just 11 days after RaidForums was seized, on March 4, 2022, Conor Brian Fitzpatrick operating under the alias pompompurin launched BreachForums.
Fitzpatrick came with built-in credibility. In November 2021, he had claimed responsibility for compromising the FBI’s Law Enforcement Enterprise Portal (LEEP), which was subsequently used to distribute thousands of fraudulent emails. His reputation within underground communities meant that when BreachForums launched, it had immediate visibility and trust.
Strategic Replication: BreachForums didn’t invent a new marketplace model it copied RaidForums’ structure almost exactly:
This deliberate continuity allowed former RaidForums users to immediately recognize the interface and resume transactions. Many established vendors referenced their previous RaidForums identities when conducting transactions, enabling buyers to recognize trusted sellers without losing reputation scores.
Result: Within months, BreachForums became the dominant English-language marketplace for breached databases and stolen information.
Between 2022 and 2023, BreachForums transcended its role as a simple marketplace. It became an educational hub, operational command center, and reputation-building platform for the global cybercrime community.
What Made BreachForums Essential:
High-profile breach announcements generated hundreds of forum replies within hours. Users debated data authenticity, evaluated potential market value, and identified serious buyers. Unlike private, closed communities, BreachForums’ public nature meant that threat actors actively sought media attention to build reputation and drive up data valuations.
Platform Culture: Members exchanged operational security advice, cryptocurrency laundering strategies, and guidance on monetizing stolen data. This combination of commerce, education, and collaboration made BreachForums uniquely valuable to the cybercrime ecosystem.
Among the most recognizable names on BreachForums was ShinyHunters, a threat actor collective that built its reputation through public data releases. Unlike traditional hacking groups that operated in secrecy, ShinyHunters became almost a brand within underground communities.
The group gained attention in 2020 after compromising major targets including Tokopedia (Indonesia’s largest e-commerce platform with tens of millions of user records), Wishbone, Mathway, Home Chef, and Promo.com. Their innovation was straightforward but effective: monetize the same dataset multiple times. Threat actors would first sell exclusive access privately, then advertise the database publicly, and eventually release portions to increase visibility.
Evolution: By 2024, ShinyHunters didn’t just post data on BreachForums they became associated with the platform’s co-administration alongside Baphomet, demonstrating how fluid roles within cybercrime ecosystems can be.
IntelBroker represented a different archetype: a threat actor who built fame not through forum administration but through high-profile data releases from recognizable targets.
Throughout 2024-2025, IntelBroker became associated with multiple significant breach claims:
| Target | Date | Significance |
|---|---|---|
| AMD (Advanced Micro Devices) | 2024 | Internal company data and employee information from major semiconductor manufacturer |
| Europol (SIRIUS Platform) | May 2024 | Sensitive law enforcement data; demonstrated willingness to target government institutions |
| Apple | June 2024 | Internal tools obtained via third-party contractor; highlighted supply-chain targeting |
| Verizon & Others | 2024-2025 | Multiple corporate breaches targeting high-profile brands for media value |
Table 1: Major breach claims associated with IntelBroker, demonstrating targeting of high-profile organizations for reputation and financial gain
Strategy: IntelBroker specifically targeted organizations with recognizable names because high-profile breaches generate exponentially more attention, driving up reputation scores and data valuations. BreachForums provided the perfect platform for this public-facing model.
CyberNiggers represented yet another evolution: a collective that actively embraced publicity and branding. Members included IntelBroker, EnergyWeaponUser, wonder, and 888 all of whom became well-known through public breach disclosures on BreachForums.
The group’s signature approach included branded graphics, public statements, and downloadable proof-of-compromise samples. Their most notable operation involved Nokia, where they claimed to have compromised a third-party supplier and released source code, configuration files, SSH keys, and development assets. Although Nokia maintained that its core infrastructure wasn’t directly compromised, the public announcement gave CyberNiggers significant reputation within underground communities.
BreachForums’ decline was not caused by a single catastrophic event. Instead, the platform gradually weakened through cascading law enforcement operations, administrator arrests, and loss of community trust. Each disruption created new vulnerabilities, until the platform could no longer sustain itself.
| Date | Event | Consequence |
|---|---|---|
| March 15, 2023 | Fitzpatrick (pompompurin) arrested in Peekskill, NY | Forum destabilizes; Baphomet takes control |
| June 15, 2023 | FBI seizes BreachForums infrastructure | Platform goes completely offline; uncertainty spreads |
| 2024-2025 | Multiple administrator arrests (IntelBroker, ShinyHunters members) | Leadership vacuum; competing claims for control |
| January 9, 2026 | BreachForums’ own database leaked (323,986 users) | Ironic reversal; massive loss of user trust |
| March 27, 2026 | Moderation team resigns via PGP-signed statement | Platform officially declared dead |
Table 2: Cascade of events leading to BreachForums’ complete collapse from March 2023 to March 2026
Key Arrests: In 2025, law enforcement accelerated operations. Kai West (operating as IntelBroker) was arrested by U.S. prosecutors. French authorities arrested Raphaël (“Hollow”), Adel (“YuroSH”), and several ShinyHunters members. Each arrest removed critical leadership figures, creating vacuums filled with distrust and competing claims.
Crisis Cycle: Every administrator arrest triggered identical questions among users: “Is my data compromised? Are investigators monitoring me? Is the forum safe?” With no trusted authority to answer these questions, users increasingly abandoned the platform.
On January 9, 2026, BreachForums experienced an event so symbolically perfect it seemed almost scripted: its own database was leaked.
A database containing information associated with 323,986 BreachForums user accounts was publicly released through a website linked to ShinyHunters. The leaked data included:
The Irony: BreachForums had spent years as a marketplace for exposing others’ data. Now it became a breach victim itself. A platform built on the unauthorized disclosure of corporate, government, and personal information ultimately experienced the same fate.
Intelligence Value: The leaked data provided investigators with unprecedented intelligence for correlating BreachForums users with activity across other underground platforms and historical cybercrime investigations. From a threat intelligence perspective, the database became far more valuable than typical credential leaks.
The rise and fall of BreachForums illustrates why even the most influential underground platforms ultimately fail. The pattern is predictable and repeatable:
The Vulnerability Cycle:
Why BreachForums Couldn’t Survive: The platform didn’t collapse because demand for stolen data disappeared. Rather, BreachForums became too visible, too centralized, and too important for international law enforcement to ignore. Its very dominance sealed its fate.
The Successor Paradox: Although BreachForums no longer exists, platforms like PwnForums have emerged as replacements. However, none have managed to recreate the same combination of scale, influence, and reputation that made BreachForums the dominant marketplace of its era. The threat actors who built their reputations on BreachForums remain active, but the platform itself is dead.
Protect Your Organization Against Emerging Cybercrime Threats
ThreatMon’s intelligence platform continuously monitors dark and surface web activities, delivering early warnings and actionable insights into evolving threats affecting your organization.
ThreatMon Services: