Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actionunderground-data-leakcybercrime-service-ecosystemthreat-infrastructure-tracking

Law Enforcement Disrupts BreachForums and Targets Its Administrators

Updated 28d agoFirst seen May 25, 20265 sources

BreachForums, a cybercrime forum widely used to trade and leak stolen data, faced repeated disruption after administrators said they would shut it down over fears of law-enforcement infiltration. The closure concerns emerged after pressure on the forum's operators, underscoring growing operational risk for one of the most prominent marketplaces tied to breached databases and criminal data sales.

Authorities later escalated that pressure by seizing BreachForums infrastructure in an FBI-led action, and subsequent reporting said French police arrested five alleged administrators linked to the site. The combined actions marked a sustained international crackdown on the forum's operators and supporting infrastructure, disrupting a major venue used by threat actors to advertise, sell, and publish compromised information.

Share:
Law Enforcement Disrupts BreachForums and Targets Its Administrators
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 23, 20251y ago

French police reportedly arrest five BreachForums administrators

French police reportedly detained five people described as BreachForums administrators. The arrests represented a further law enforcement action targeting the forum's operators after the earlier seizure.

May 15, 20242y ago

Authorities seize BreachForums infrastructure

Law enforcement seized BreachForums and replaced the site with a seizure banner, identifying the FBI and international partners as involved. The action disrupted a major cybercrime forum used to trade and leak stolen data.

Mar 22, 20233y ago

BreachForums administrators announce forum shutdown

Following the founder's arrest, BreachForums administrators said they would shut down the forum, citing fear of law enforcement infiltration. The decision marked the apparent end of the site in its original form.

Mar 15, 20233y ago

BreachForums founder arrested in New York

U.S. authorities arrested BreachForums founder Conor Brian Fitzpatrick, known online as 'Pompompurin,' in New York. The arrest triggered uncertainty about the forum's future and concerns among members about law enforcement access.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.