logo svg
logo

August 23, 2026

Updated: August 23, 2026

BreachForums: History, Seizures, Restarts, and Controversies

BreachForums survived as a name across different operators, seizures, and disputed restarts. This evidence-led history separates confirmed events from underground claims and shows defenders how to verify posts.

Mohammed Khalil

Mohammed Khalil

Featured Image

BreachForums did not simply disappear and return unchanged. The name moved across administrators, infrastructure, databases, domains, and even different operating models. Some events were confirmed by courts or law-enforcement agencies. Others came from pseudonymous operators whose claims could not be independently verified.

That distinction matters. A forum post can be an early warning about stolen credentials, a breach, or criminal access. It can also be recycled data, extortion, marketing, impersonation, or fiction. Understanding BreachForums requires two timelines: what authorities and courts established, and what successive operators claimed about the platform.

Executive Answer

BreachForums was an English-language cybercrime forum and stolen-data marketplace launched in March 2022 after RaidForums was dismantled. Its original founder, Conor Fitzpatrick, was arrested in March 2023, but successor teams repeatedly reused the name. Authorities disrupted or seized infrastructure in 2023, 2024, and 2025; administrators were arrested or charged, and the forum's own user data later leaked. By 2026, researchers described rival successors rather than one authenticated official service. For defenders, every BreachForums post is an unverified lead not proof of a breach, actor identity, or current platform ownership.

BreachForums at a Glance

QuestionEvidence-led answer
What was BreachForums?An English-language discussion forum that also functioned as a marketplace for hacked or stolen data, compromised accounts, access devices, and related cybercrime services.
When did the original launch?March 2022, after law enforcement dismantled its predecessor, RaidForums.
Who founded the original?Conor Brian Fitzpatrick, who used the alias “pompompurin.”
Was it only on the dark web?No. Significant versions operated on the clear web and also used Tor infrastructure. “Dark-web forum” describes its underground role more than one exclusive hosting model.
What happened to the original?Fitzpatrick was arrested on March 15, 2023; an international disruption caused the forum to go offline, and the remaining administrator closed it days later.
Did one team run every version?No. The FBI explicitly distinguishes v1 and a separate v2, while later teams and claimants reused the brand.
Was it seized more than once?Yes, but different operations targeted different versions and assets. Major official disruptions occurred in 2023, May 2024, and October 2025.
What is its 2026 status?Fragmented and disputed. Current reporting describes rival successors, not one independently authenticated official continuation.

What Was BreachForums?

BreachForums was a forum organized around posts, replies, user profiles, reputation, and private communication. It also operated as a criminal marketplace because members advertised or distributed stolen databases, credentials, compromised access, and other contraband. Calling it only a “hacker forum” understates the trading function; calling it a conventional darknet market misses its community and reputation structure.

The site occupied the underground ecosystem, but major versions were reachable on the ordinary web as well as through Tor. That is why “dark web” and “cybercrime forum” should not be treated as synonyms. DeepStrike's guide to the difference between the deep web and dark web explains the underlying terminology.

The original forum appeared in March 2022 after the international dismantlement of RaidForums. It inherited a ready-made demand: people who traded breach data, sought criminal services, followed threat actors, or monitored the ecosystem needed a new gathering place. Brand familiarity and a forum-style reputation system helped BreachForums become prominent quickly.

According to the U.S. Department of Justice's 2025 resentencing release, the original grew to more than 330,000 members, offered access to at least 888 stolen datasets, and contained more than 14 billion individual records of personally identifying information. Those are government and court-record figures, not DeepStrike measurements. They describe the scale attributed to v1 and should not be silently transferred to every later restart.

BreachForums Was Not One Continuous Platform

The simplest chronology launch, seizure, return creates a false impression of continuous ownership. In reality, several kinds of continuity can break independently:

The FBI's official BreachForums and RaidForums investigative page makes this separation explicit. It describes the pompompurin-run service from March 2022 to March 2023 as BreachForums v1 and a ShinyHunters-run service from June 2023 to May 2024 as a separate v2. That distinction is more reliable than an underground claim that the same community “came back.”

This lineage problem is common after enforcement actions. A recognizable brand can carry reputation, users, and attention even when control changes. DeepStrike's history of dark-web marketplace takedowns shows the same recurring cycle of disruption, migration, imitation, and attempted revival.

How to Label a BreachForums Event Correctly

Before reading the timeline, separate six event types that are often collapsed into “takedown.”

Status labelMinimum evidenceWhat it establishesWhat it does not establish
Confirmed law-enforcement seizureAgency statement, court record, or demonstrably official seizure noticeAuthorities obtained specified domains, systems, accounts, or dataThat every backend, operator, backup, key, or alternate service was captured
Arrest or criminal chargeOfficial police, prosecutor, or court recordA named person was arrested, charged, convicted, or sentencedThat the entire forum was seized or that every alias and co-operator was identified
Operator-announced shutdownA message attributable to the operator or platform keyThe speaker claims the service was intentionally taken offlineWhy it happened, whether the account was uncompromised, or whether the claim is honest
Claimed compromise or honeypotOperator, rival, or researcher allegationA compromise theory exists and may warrant cautionLaw-enforcement control, full database exposure, or technical attribution without independent evidence
Probable successorMultiple continuity indicators plus independent reportingA later service likely inherited meaningful assets or personnelLegal or organizational identity with every earlier version
Unauthenticated cloneBrand, interface, or data copied without sufficient continuity evidenceSomeone is using the nameOwnership, legitimacy, safety, or historical lineage

This vocabulary prevents a common analytical error: inferring the cause of an outage from the outage itself. Maintenance, a voluntary shutdown, hosting failure, an attack, a domain action, infrastructure seizure, and operator arrest are different events.

BreachForums History: 2022 to 2026

DateDevelopmentEvidence statusWhy it matters
March 2022Conor Fitzpatrick launched the original BreachForums after RaidForums was dismantled.Confirmed in court and DOJ recordsEstablished v1 and its founder.
March 15–21, 2023Fitzpatrick was arrested; an international disruption caused the service to go offline; the remaining administrator closed it amid infrastructure concerns.Arrest and disruption confirmed; administrator reasoning reportedEnded the original operation and broke clear operator continuity.
June 2023A separate BreachForums v2 began operating under ShinyHunters-associated administration.Confirmed by the FBI's investigative pageThe first major reuse of the brand was a separate version, not the untouched original.
May 2024The FBI took control of v2-related infrastructure and communications and displayed a seizure notice.Confirmed law-enforcement actionAuthorities said backend data was under review; the event did not prevent later brand reuse.
Late May 2024 onwardA service using the BreachForums name reappeared, followed by additional ownership changes and outages.Contemporary reporting; continuity only partialAvailability did not prove that all seized infrastructure, records, or personnel had returned.
August 2024–January 2025The IntelBroker identity was displayed as the forum's owner.Alleged in a later DOJ charging documentConnected a prominent data seller to platform leadership while remaining an allegation in the pending case.
February–June 2025Kai West was arrested in France; U.S. prosecutors later charged him as the alleged person behind IntelBroker. French authorities also arrested four people suspected of running the forum.Official U.S. charge for West; reported French prosecutorial action for the other suspectsIntensified pressure on the post-v1 operator ecosystem. All defendants remain entitled to applicable legal presumptions.
April–July 2025The forum went offline, operators blamed an alleged MyBB vulnerability and law-enforcement access, and multiple relaunch efforts followed.Operator claims plus independent observations; technical cause not publicly provenDemonstrated why a signed announcement is not the same as an official seizure record.
Mid-August 2025An operator message claimed French and U.S. authorities controlled infrastructure and keys and warned there would be no more reboots.Attributed operator claim at the timeA serious warning, but not initially a public agency confirmation of every claimed asset.
October 2025The FBI confirmed seizure of domains associated with BreachForums after one had been repurposed as a data-leak and extortion portal.Confirmed law-enforcement seizureBy this stage, the brand described a different operating model as well as a forum lineage.
January 2026Data tied to roughly 324,000 accounts from an August 2025 incarnation was publicly leaked.Independently reported; dataset contained signs of authenticity and possible tamperingThe forum became a breach victim itself, exposing the fragility of criminal-platform trust.
April–June 2026Threat-intelligence researchers documented rival services and groups competing to inherit the BreachForums name and users.Dated secondary intelligence assessmentsThe most defensible status became fragmented, with no single authenticated official continuation.

The Original Forum and Conor Fitzpatrick

Conor Brian Fitzpatrick created and administered v1 under the alias “pompompurin.” U.S. authorities arrested him on March 15, 2023, and conducted a parallel disruption that caused the forum to go offline. The remaining administrator initially discussed migration, then announced closure after reporting suspicious access to old infrastructure. The arrest was official; the administrator's explanation for closing was a platform claim.

Fitzpatrick later pleaded guilty to access-device conspiracy, access-device solicitation, and possession of child sexual abuse material. This final offense should be stated accurately and without graphic detail. The forum case and the child-exploitation offense were both part of the prosecution, but the presence of that conviction does not mean every later BreachForums user or successor was involved in the same conduct.

The first sentence 17 days of time served and 20 years of supervised release became a major controversy. The Fourth Circuit vacated it on January 21, 2025, finding it substantively unreasonable, and remanded the case. On September 16, 2025, Fitzpatrick was resentenced to three years in federal prison. He also agreed to forfeit more than 100 domains, electronic devices, and cryptocurrency proceeds.

The case illustrates why claims that dark-web operators are “anonymous” need qualification. Investigators combine infrastructure, accounts, financial records, undercover activity, devices, and human mistakes. DeepStrike's analysis of how anonymous the dark web really is explains why pseudonymity is an obstacle to attribution, not a guarantee against it.

V2, ShinyHunters, Baphomet, and the May 2024 Seizure

After v1 closed, accounts associated with Baphomet and ShinyHunters announced a replacement. The separate v2 ran from June 2023 until May 2024 according to the FBI. It adopted the familiar name and community role, but its different administration and later infrastructure are why the agency treats it as its own version.

On May 15, 2024, the forum, associated communications channels, and administrator-controlled assets displayed FBI seizure messages. Contemporary reporting described the FBI as reviewing backend data. A public claim that Baphomet had been arrested circulated at the time, but an operator statement is not interchangeable with a charging document. The seizure itself was visible and attributable; every related arrest claim required separate proof.

A service using the name returned later that month. That rapid return did not reverse the seizure or prove that authorities had obtained nothing. It showed that criminal services can preserve or recover enough brand, data, code, accounts, backups, or audience to rebuild somewhere else. DeepStrike's overview of how law enforcement tracks dark-web criminals explains why an operation can collect intelligence and impose costs even when a successor appears.

IntelBroker and the 2025 Charges

The IntelBroker identity became one of the most visible BreachForums personas and was displayed as the site's owner from approximately August 2024 through January 2025. In June 2025, U.S. prosecutors charged British national Kai West, alleging that he operated the IntelBroker identity, stole and sold data, and caused more than $25 million in victim losses. West had been arrested in France in February 2025, and the United States sought extradition.

The charging document alleged that IntelBroker offered hacked data for sale 41 times and for free or forum credits 117 times between 2023 and 2025. It also described the identity as a forum owner for part of that period. These are allegations, not a conviction, and West is presumed innocent unless proven guilty.

This case also illustrates the forum's reputation economy. Free releases can build status and audience, which can make later sales claims more persuasive. Reputation, however, does not establish that a dataset is new, complete, authentic, obtained by the advertised actor, or tied to the named victim.

The 2025 Shutdowns, Restarts, and October Seizure

In April 2025, the service went offline. A message attributed to its operators said law enforcement had used an unknown vulnerability in MyBB, the forum software, and that the backend would be rebuilt. A June 2025 ZeroFox assessment observed a claimed relaunch and historical content, assessed meaningful continuity as likely, and explicitly noted that some source information could not be independently verified.

That is the correct analytical posture. A signed message can support continuity with a key holder. It cannot prove that the technical explanation is accurate, that the key remains exclusively controlled, that no data was taken, or that the speaker represents every previous administrator.

French authorities announced arrests of four suspected administrators in June 2025. A further classic-forum relaunch was announced in July, then went offline in mid-August. A message attributed to ShinyHunters claimed French and U.S. authorities had obtained infrastructure, accounts, and signing material and warned users against future reboots. At that point, the claim was alarming but still came from an underground actor.

In October, the evidence changed. The FBI publicly confirmed a new domain seizure. BleepingComputer's account of the October 2025 action reported that the targeted site had been repurposed as a data-leak and extortion portal and that an operator acknowledged law-enforcement access to historical backups. This was no longer merely a forum outage, and the service's function was no longer identical to the earlier community board.

The sequence is a useful lesson: an initial operator claim can later be partly corroborated without every detail becoming proven. Analysts should update confidence as evidence arrives instead of retroactively labeling every earlier statement true.

When BreachForums Was Breached

BreachForums suffered the same exposure risk it traded in. In January 2026, The Register reported a leak tied to about 324,000 accounts. The material was associated with an August 2025 incarnation and reportedly included email addresses, usernames, hashed passwords, public and private forum records, and other account data. Researchers also warned that portions appeared edited, scrubbed, or tampered with.

That last qualification matters. A dataset can contain authentic records and manipulated records at the same time. The existence of valid entries does not authenticate every row, the leaker's identity, the stated acquisition method, or claims made in an accompanying manifesto.

The episode also undermined a core promise of pseudonymous communities: that platform reputation can substitute for real-world trust. Once account records, IP information, private messages, or signing material may be exposed, every identity and past conversation needs reassessment.

For organizations, the useful takeaway is not to obtain the leaked forum database. It is to understand how exposed credentials and identity artifacts can cascade into account takeover, impersonation, and phishing. DeepStrike's compromised credential statistics provide the broader defensive context.

The Main BreachForums Controversies

1. The Fiction of a Single Continuous Forum

News headlines often say “BreachForums is back.” That can mean the old domain returned, an administrator launched new infrastructure, a copied database was restored, a leak portal adopted the brand, or a rival clone copied the interface. Those are materially different events.

2. Official Status Versus Operator Claims

Several shutdown explanations came from pseudonymous operators: a compromised server, an unknown software flaw, an arrest, a seized key, or a honeypot. Some were later supported in part; others remained unverified. Treating all signed announcements as official facts rewards whoever controls the account or key at that moment.

3. Disputed Administrator Identities

Aliases such as ShinyHunters can describe a person, a group, a shared persona, or a brand used by different participants over time. Arresting a suspected user of an alias does not automatically identify every historical operator. Conversely, later activity under the same name does not prove that authorities arrested the wrong person; the account or brand may have multiple users.

4. The Forum Became Its Own Data-Exposure Victim

The reported 2026 leak exposed the contradiction at the center of BreachForums: a service built around other organizations' stolen data could not guarantee custody of its own user records. It also created risks for researchers, undercover personnel, lurkers, and malicious users whose accounts could appear in the same dataset.

5. A Forum Post Was Often Treated as a Confirmed Breach

An advertisement can contain genuine samples and still exaggerate scope, recycle an old incident, misname the source, or combine data from several breaches. A claim of initial access may describe expired credentials, a third-party account, or a failed intrusion. DeepStrike's analysis of stealer-log exposure shows why possession of a credential artifact does not prove current control of an enterprise environment.

6. Forum, Marketplace, and Leak Portal Became Blurred

The original service combined discussion and trade. Later incarnations sometimes emphasized community functions, while the October 2025 target operated as an extortion-oriented leak portal. Describing all of them with one label hides changes in risk, audience, and evidence value.

7. Centralized Forums Lost Trust but Not Demand

Repeated seizures, database leaks, arrests, and rival claims made centralized criminal forums dangerous for their own users. Some activity moved toward smaller boards and messaging channels. DeepStrike's defensive overview of dark-web Telegram channels explains how that shift fragments visibility without eliminating the underlying economy.

The DeepStrike BreachForums Continuity Ledger

When a site or account claims that BreachForums has returned, do not ask only whether the page looks familiar. Assess six independent dimensions.

Continuity dimensionEvidence to seek through approved sourcesCommon false shortcut
Infrastructure custodyDocumented control of relevant hosting, domains, backend services, and administrative systems“The old design is online.”
Account and data custodyProvenance of restored accounts, messages, ranks, balances, and moderation records“Old usernames exist, so the database is legitimate.”
Administrator continuityIndependently supported links among operators across versions and dates“The same alias posted.”
Cryptographic continuityValid historical signatures plus evidence that the key was not seized, stolen, or shared“The signature is valid, so every claim is true.”
Governance continuityConsistent rules, moderation, dispute handling, permissions, and trust mechanisms“The categories and badges look the same.”
Independent corroborationCourt records, agency statements, or multiple independent intelligence sources“Rivals agree in reposted messages.”

Use the ledger to assign one of three outcomes:

The ledger is a triage model, not a scientific attribution score. One decisive fact can outweigh several weak indicators. An official seizure of a domain, for example, changes the meaning of later messages signed with a key alleged to have been captured.

Why Security Teams Monitored BreachForums

BreachForums concentrated public claims about stolen data, credentials, unauthorized access, vulnerabilities, and extortion. A relevant post could give a defender an early lead before a victim completed its own investigation or before an incident became public.

That value came with a high false-positive rate. Users had incentives to advertise, exaggerate, recycle, embarrass rivals, build reputation, and pressure victims. Monitoring should therefore be governed collection, not casual browsing. DeepStrike's comparison of dark-web monitoring tools is the safer path for evaluating approved coverage and alerting capabilities.

How Defenders Should Validate a BreachForums Claim

Claim typeSafe first checksEvidence that raises confidenceWhat not to do
Stolen-data claimConfirm the named entity, date, data fields, known processors, and prior incidentsUnique records match controlled internal data and incident timingDownload a public dump or contact the seller
Credential or access claimReview identity logs, resets, MFA changes, session activity, and exposed-account inventoryCurrent credentials, valid sessions, or internal telemetry align with the claimBuy access, test credentials on production, or reveal watch terms
Vulnerability claimIdentify the affected product, version, asset owner, and patch stateAuthorized scanning, vendor evidence, or internal exploitation telemetry matchesRun unknown exploit code or test systems without authorization
Extortion statementActivate legal, incident response, privacy, and communications proceduresThe actor demonstrates non-public data or access consistent with internal findingsNegotiate independently or treat a deadline as proof
Platform-status claimRecord the source, timestamp, exact wording, and evidence labelAgency confirmation or multiple independent observations support the statusSearch for mirrors or assume a working page is official

Use a controlled workflow:

  1. Preserve the alert. Record the monitoring source, collection time, displayed account, exact claim, thread context, and any provider identifier. Restrict sensitive evidence.
  2. Classify both the claim and the platform. Separate a data claim from an access sale, extortion message, vulnerability report, or forum-status announcement. Record which claimed BreachForums lineage produced it.
  3. Check source continuity. Apply the Continuity Ledger to the account and platform. A familiar alias or restored rank is not enough.
  4. Corroborate independently. Distinguish genuinely independent evidence from screenshots, reposts, and articles that all trace back to one underground message.
  5. Check internal telemetry. Compare the claim with identity, endpoint, cloud, network, email, data-loss, vulnerability, and asset evidence.
  6. Minimize exposure. Do not contact the actor, purchase material, download unknown files, paste secrets into search tools, or browse suspected clones from ordinary corporate endpoints.
  7. Escalate by impact and confidence. Route credible matches through incident response, legal, privacy, fraud, communications, executive, and law-enforcement procedures as appropriate.
  8. Validate within authorization. If the claim points to an exploitable weakness, use a clearly scoped penetration testing engagement or approved internal assessment.

The goal is not to prove that a forum user lied or told the truth. The goal is to determine whether the organization's systems, identities, and data show a real incident requiring action.

What Seizures Accomplished and What Restarts Did Not Erase

A law-enforcement operation can succeed even if a replacement appears. Authorities may collect backend records, private messages, account identifiers, financial evidence, infrastructure logs, or administrator communications. They may disrupt escrow, remove a trusted domain, expose operator relationships, and force users onto less stable services.

A restart can restore audience and brand recognition, but it cannot automatically restore trust. Every migration creates new infrastructure, administrators, code, databases, and communication paths that may be compromised, fraudulent, or monitored. Repeated enforcement also fragments the historical record, which makes actor and post attribution harder for both criminals and defenders.

This is why “the forum returned” is not the opposite of “the operation worked.” Both can be true: a service can reappear while investigators retain evidence, suspects face charges, users lose trust, and the ecosystem becomes more costly to operate.

Is BreachForums Still Online in 2026?

The most defensible answer as of August 23, 2026 is: there is no independently authenticated single official BreachForums continuation. A June 2026 KELA assessment described the post-October 2025 ecosystem as a contest among rival successors. Other 2026 researchers likewise documented competing versions, imported users, impersonated legacy brands, and disputes over who controlled the “real” forum.

That does not mean no service currently uses the name. It means the name alone cannot establish lineage, ownership, safety, or status. DeepStrike did not access or authenticate any live endpoint for this article and does not provide current domains or mirrors.

For a current-status statement to be useful, it must name the observation date, source, service lineage, and confidence level. “Online” describes reachability at a moment. It does not mean official, uncompromised, continuously available, or controlled by the people a visitor expects.

Frequently Asked Questions

What is BreachForums?

BreachForums was an English-language cybercrime forum and marketplace where users discussed hacking and advertised or distributed stolen data, credentials, compromised access, and related services. The original launched in March 2022; later teams reused the name across separate versions and operating models.

Who founded BreachForums?

Conor Brian Fitzpatrick, known by the alias “pompompurin,” founded the original version in March 2022. He pleaded guilty to three federal counts and was resentenced in September 2025 to three years in prison.

Was BreachForums the successor to RaidForums?

Yes. The original BreachForums appeared shortly after law enforcement dismantled RaidForums and served a similar English-language stolen-data community. That historical succession does not mean the same people operated both services.

How many times was BreachForums seized?

There is no useful one-number answer because different operations targeted different versions and assets. The original was disrupted in March 2023, v2-related assets were seized in May 2024, and the FBI confirmed another domain seizure in October 2025. Other outages were voluntary, technical, attacked, or only claimed to involve law enforcement.

Was IntelBroker the owner of BreachForums?

A 2025 U.S. charging document alleges that the IntelBroker identity was displayed as the forum's owner from about August 2024 through January 2025. Prosecutors charged Kai West as the alleged operator of that identity. Those are allegations in a criminal case, and they should not be described as a conviction.

Is BreachForums still active in 2026?

Services and groups still claim parts of the BreachForums legacy, but current reporting describes rival successors rather than one authenticated official platform. Reachability, identity, and ownership can change independently, so a dated observation should never be presented as a permanent status.

Does a BreachForums post prove that a company was breached?

No. It proves that an account made a claim. Confirm the affected organization, timing, data provenance, credentials, systems, and impact through independent reporting and internal incident-response evidence before taking public or disruptive action.

Conclusion

BreachForums became influential because it replaced a disrupted community and concentrated stolen-data claims, reputation, and trade. Its name survived arrests and seizures, but the platform beneath that name repeatedly changed. By 2026, brand continuity was stronger than operator, infrastructure, or governance continuity.

For defenders, that instability is not a reason to ignore the forum's legacy. It is a reason to label evidence precisely. Preserve the claim, identify the lineage, separate official action from operator assertion, corroborate independently, and let internal telemetry determine the response.

If a BreachForums-related claim appears to expose your organization, keep the evidence controlled and validate the suspected compromise through your incident-response process or an authorized security assessment.

About The Author

Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us