Cyber Incident Victim: Exploit
Timeline
Summary
A cybercrime forum known as Exploit was compromised in a series of attacks targeting multiple underground platforms, resulting in unauthorized secure shell access to its proxy server used for DDoS protection and attempts to dump network traffic. The incident, part of broader breaches affecting several prominent forums, led to leaked user data including hashed passwords and email addresses, prompting discussions among users about abandoning email-based registrations to reduce exposure. While some claimed the leaked data was outdated or incomplete, the attackers' activities across forums included financial theft and fraudulent diversion of funds, though Exploit's specific financial impacts remained unclear.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Between January and March 2021, a series of breaches targeted four prominent Russian-language cybercrime forums, beginning with Verified in January, followed by Crdclub in February, and concluding with Exploit and Maza in March. The attacks exhibited varying methodologies and impacts across the platforms. Verified’s compromise involved the theft and public sale of its database on Raid Forums for $100,000, containing user registration details, private messages, posts, and threads. Additionally, threat actors exfiltrated $150,000 in cryptocurrency from Verified’s wallet. In February, Crdclub’s administrator account was compromised, enabling attackers to impersonate forum administrators and redirect users to a fraudulent money transfer service, resulting in financial losses. Forum administrators pledged to reimburse affected users, with no additional data compromise reported. Intelligence firm Intel 471 documented these incidents, noting the breaches’ operational inconsistencies with law enforcement tactics, suggesting independent threat actor involvement.

The March attacks simultaneously impacted Exploit and Maza forums. Exploit’s breach involved unauthorized SSH access to a proxy server utilized for DDoS protection, coupled with attempted network traffic dumping. Maza’s compromise redirected users to a breach notification page upon login, accompanied by a PDF file containing partially obfuscated user data, including usernames, hashed passwords, email addresses, and communication platform identifiers (ICQ, AIM, Yahoo, MSN, Skype). Flashpoint analysts validated the leaked Maza dataset, confirming its breadth but noting extensive hashing and obfuscation of sensitive fields. Exploit users publicly debated migrating away from email-based forum registrations, citing heightened exposure risks, while others contested the completeness or recency of leaked data. These incidents collectively disrupted forum operations, exposed user identities and communications, and triggered operational distrust among cybercrime communities. No remediation efforts by Exploit’s administrators were documented in available reporting.
