HomeCyber SecurityTaking the shine off BreachForums – Sophos Information

Taking the shine off BreachForums – Sophos Information


On June 25, 2025, French authorities introduced that 4 members of the ShinyHunters (also referred to as ShinyCorp) cybercriminal group had been arrested in a number of French areas for cybercrime actions and involvement within the English-language underground discussion board often known as BreachForums. The coordinated world legislation enforcement effort concentrating on the ‘ShinyHunters’, ‘Hole’, ‘Noct’, and ‘Depressed’ personas adopted the February arrest of Kai West (also referred to as ‘IntelBroker’), who beforehand administered BreachForums.

The ShinyHunters menace group has been energetic since 2020 and has compromised organizations in industries resembling telecommunications, e-commerce, know-how, and retail. The group is thought for promoting stolen information completely on RaidForums and BreachForums. The ShinyHunters persona was a key participant in these boards as a contributor and administrator.

Since its unique creation as RaidForums in 2015, BreachForums had been taken down quite a few occasions and had been administered by a number of personas. Desk 1 lists a timeline of notable occasions within the discussion board’s historical past.

Date Occasion Element
March 19, 2015 RaidForums launch Diogo Santos Coelho (also referred to as ‘All-powerful’) based
RaidForums. It turned one of many largest information leak boards, peaking
at over 530,000 customers.
January 31, 2022 Arrest Coelho was arrested within the UK on the request of U.S. authorities.
February 25, 2022 Discussion board offline RaidForums turned inaccessible, and a suspected
credential-harvesting clone appeared.
March 4, 2022 BreachForums (v1)
launch
Conor Fitzpatrick (also referred to as ‘Pompompurin’) launched
BreachForums as a successor to RaidForums.
April 12, 2022 Area seizures U.S. authorities introduced the seizure of RaidForums domains as
a part of Operation TOURNIQUET.
March 15, 2023 Arrest Fitzpatrick was arrested in Peekskill, New York.
March 21, 2023 Discussion board offline An administrator often known as ‘Baphomet’ shut down the discussion board, citing
issues about legislation enforcement actions.
June 12, 2023 BreachForums (v2)
launch
The ShinyHunters persona and Baphomet relaunched BreachForums (breachforums . vc).
June 18, 2023 Discussion board compromise BreachForums was compromised by ‘OnniForums’, and information of
roughly 4,000 members was leaked.
Might 15, 2024 Area seizures U.S. authorities seized a number of BreachForums domains.
Might 29, 2024 BreachForums (v3)
launch
BreachForums resurfaced (breachforums . st). Customers suspected that
it was a honeypot, nevertheless it was finally deemed reliable.
June 14, 2024 Management change ShinyHunters retired, and ‘Anastasia’ assumed possession.
August 1, 2024 Management change IntelBroker assumed management.
January 1, 2025 Management change IntelBroker resigned as proprietor, and Anastasia continued because the discussion board administrator.
February 2025 Arrest Worldwide legislation enforcement arrested Kai West (IntelBroker) in
France.
April 28, 2025 Discussion board offline Regardless of quite a few claims and rumors, it’s unclear if the discussion board
directors, one other menace group, or legislation enforcement was accountable for the disappearance.
June 4, 2025 BreachForums (v4)
launch
ShinyHunters relaunched the discussion board (breach-forums . st).
June 9, 2025 Discussion board on the market ShinyHunters introduced the discussion board was on the market.
June 22, 2025 Arrests French authorities arrested members of the ShinyHunters menace
group throughout a coordinated legislation enforcement operation.
June 25, 2025 Federal fees U.S. authorities unsealed an indictment charging Kai West
(IntelBroker) with a number of cybercrimes.

Desk 1: Timeline of main BreachForums occasions.

The ShinyHunters persona partnered with Baphomet to relaunch the second occasion of BreachForums (v2) in June 2023 and later launched the June 2025 occasion (v4) alone. The interim model (v3) abruptly disappeared in April 2025, and the trigger is unclear. ‘Darkish Storm Staff’ claimed that it took the discussion board down through a distributed denial of service (DDoS) assault (see Determine 1). Different personas reported that the Qilin ransomware operators brought on the outage in retaliation for his or her ban from BreachForums. Rumors additionally circulated that legislation enforcement was accountable.

Screenshot of Dark Storm Team post claiming responsibility for the BreachForums takedown

Determine 1: Darkish Storm claiming accountability for the BreachForums takedown. (Supply: X)

On June 4, Counter Risk Unit™ (CTU) researchers recognized the relaunch of BreachForums (v4) underneath the administration of the ShinyHunters persona. One of many first posts was purportedly by IntelBroker, a distinguished BreachForums contributor who took management of BreachForums (v3) in 2024. The persona maintained a fame for promoting entry to database dumps and compromised methods and was linked to cybercrime teams CNZ (redacted) and GOLD PUMPKIN (also referred to as HELLCAT). In January 2025, they stepped down as BreachForums’ proprietor (see Determine 2), and rumors of their arrest circulated. These rumors had been confirmed on June 25, when the U.S. Division of Justice (DOJ) introduced the unsealing of an indictment in opposition to Kai West, who operated underneath the IntelBroker alias. West was arrested in February, so the June BreachForums put up was submitted by somebody impersonating the persona.

Screenshot of IntelBroker post resigning as BreachForums owner

Determine 2: IntelBroker saying resignation as BreachForums proprietor. (Supply: X)

The BreachForums (v4) relaunch was short-lived. On June 9, the bulletin board displayed a discover that it was closed and that the discussion board was on the market for $2,500 USD (see Determine 3). The message explicitly warned scammers to “keep away”. The ShinyHunters members had been arrested two weeks later.

Screenshot of ShinyHunters advertising BreachForums for sale

Determine 3: ShinyHunters promoting BreachForums on the market. (Supply: BreachForums)

As of this publication, BreachForums stays offline. The discussion board’s future is unclear, however the sample of relaunches might proceed.

These arrests replicate growing legislation enforcement stress on cybercriminal infrastructure and operations. Within the U.S. Division of Justice announcement concerning the arrest and indictment of Kai West, FBI Assistant Director in Cost Christopher G. Raia said that the arrests “ought to function a warning to anybody pondering they will disguise behind a keyboard and commit cybercrime with impunity; the FBI will discover and maintain you accountable irrespective of the place you might be.” CTU™ researchers proceed to watch legislation enforcement actions and their influence on the cybercrime panorama.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments