Cyber Incident Victim: Breach Forums
Date:
Aug 2025
Location:
United States of America
Summary
BreachForums suffered a leak of a database containing roughly 324 000 user records, including email addresses and IP information, accompanied by a PGP private key and a lengthy manifesto titled “Doomsday.” The exposed data appeared months before law‑enforcement seized the forum’s servers following threats to release stolen Salesforce records. The leak adds to a pattern of arrests, domain seizures and server takedowns that have targeted the site’s administrators and operators. Experts said the breach undermines trust in the platform, noted its limited forensic value, and warned that such disclosures risk spreading disinformation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
BreachForums emerged as the successor to RaidForums after the latter’s seizure by U.S. authorities in 2022, positioning itself as a discussion platform for data breaches, illegal sexual content, ransomware, and hacking tools. In 2023 the site’s alleged founder and administrator, Conor Brian Fitzpatrick, was arrested, and its clearnet domains were seized three months later; Fitzpatrick was subsequently sentenced to three years in prison by a U.S. court. The following year, a replacement administrator known as Baphomet was reportedly arrested, and in 2025 five additional individuals linked to the forum were taken into custody. Finally, in October 2025 law enforcement executed a takedown of the BreachForums dark web extortion site after threats from the group Scattered Lapsus$ Hunters to release one billion records stolen from Salesforce customers.

On January 9 2026 a zip archive containing a MySQL database of 323,986 BreachForums users appeared on the domain shinyhunte[.]rs, a site unconnected to the extortion group of the same name. According to Have I Been Pwned, the breach had occurred in August 2025, coinciding with the August 11 date on the leaked database, the day administrators reportedly announced the site’s shutdown due to fears of law‑enforcement compromise. The archive disclosed email addresses and IP data, with many IP addresses identified as loopbacks, while Gmail was the most popular email service used for registration. A day later, on January 10, a password‑protected PGP private key file was leaked, which Resecurity indicated was likely used to sign messages from BreachForums’ administrators. The January leak also included a 4,400‑word manifesto titled “Doomsday” authored by someone using the name “James,” who claimed responsibility for the disclosure.
The leak prompted mixed reactions from security commentators. Michael Jepson, a penetration testing manager at CybaVerse, stated that the breach significantly undermines trust in the platform, which is critical for any cybercrime forum, and that the exposure damages confidence in BreachForums as a secure environment, likely pushing more sophisticated criminals toward smaller, invite‑only communities. Michael Tigges, a senior security operations analyst at Huntress, noted that while the database could be useful for authorities and researchers studying adversarial activities, its forensic value is limited and its integrity is questionable if derived from another cybercrime group; he warned that such leaks could serve as a cover for disinformation, emphasizing that any use of the data to map activity nuclei must be scrutinized for reliability. Law‑enforcement agencies continue to assess whether the leaked information provides actionable leads, acknowledging that the data may already be in their possession or may only yield limited investigative utility due to the prevalence of anonymizing services and loopback addresses. The incident adds to a series of disruptions that have eroded BreachForums’ stability and prompted shifts in how cybercriminal communities organize and communicate.
