CSIDB logo
Incident

Breach Forums

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 02:23

Linked entities

Victim
Breach Forums
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Undetermined
Disclosed
Jan 2026
Resolved
Pending

Summary

The notorious hacking forum BreachForums experienced a leak of a database containing approximately 324,000 user records that appeared on a domain unrelated to the original extortion group. The leaked data includes a password‑protected PGP private key file and a lengthy manifesto titled ‘Doomsday’ authored by someone using the name James. The breach occurred months before a law‑enforcement takedown of the forum’s dark‑web extortion site and follows a series of arrests and seizures involving its administrators. The database holds email addresses and IP addresses, many of which are loopback addresses, with Gmail being the most common registration service. Analysts note that the leak undermines trust in the platform, may have limited forensic value, and could be used to spread disinformation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

BreachForums originated as the successor to RaidForums after the latter was seized by US authorities in 2022, positioning itself as a discussion platform for data breaches, illegal sexual content, ransomware and hacking tools. In 2023 the site’s alleged founder and administrator, Conor Brian Fitzpatrick, was arrested and its clearnet domains were seized three months later; he was later sentenced to three years in prison by a US court. The following year, a replacement administrator known as Baphomet was reportedly arrested, and in 2025 five additional individuals accused of involvement with the forum were taken into custody. In October 2025 law enforcement executed a takedown of the BreachForums dark‑web extortion site, seizing its servers amid threats from the group Scattered Lapsus$ Hunters to release one billion Salesforce records. On January 9 2026 a zip archive containing a MySQL database of 323,986 BreachForums users appeared on the domain shinyhunte[.]rs, marking the public emergence of the leak. Have I Been Pwned dated the breach to August 2025, noting that the database carried an August 11 timestamp that coincided with the administrators’ announcement of a shutdown due to feared law‑enforcement compromise. Resecurity reported that the leaked archive included a password‑protected PGP private key file and a 4,400‑word manifesto titled ‘Doomsday’ authored by someone using the name ‘James’ who claimed responsibility for the disclosure. The PGP key was subsequently posted on January 10 2026 and was identified as likely used to sign messages from BreachForums’ administrators.

The leaked database contains email addresses and IP data associated with the forum’s users; analysis indicated that many of the IP addresses correspond to loopback addresses, limiting their direct investigative value. The most common email service used for registration was Gmail, which could provide a forensic link for users who failed to conceal their tracks. Michael Jepson, penetration testing manager at CybaVerse, stated that the breach significantly undermines trust in the platform, a critical element for any cybercrime forum, and that the exposure damages confidence, likely prompting more sophisticated criminals to migrate to smaller, invite‑only communities. Michael Tigges, senior security operations analyst at Huntress, noted that while the data may be useful for authorities and researchers studying adversarial activity, its forensic value is limited and its integrity is questionable if the leak originated from another cybercrime group. Tigges also warned that data leaks of this nature could be employed as a cover for disinformation campaigns, emphasizing that any attempt to map activity nuclei must scrutinize the reliability of the information. Law‑enforcement agencies have not publicly confirmed whether they already possessed the leaked data, leaving the immediate utility of the breach for investigative purposes uncertain.

In response to the leak, security analysts and threat‑intelligence firms have examined the archive for signs of tampering and have shared indicators of compromise with relevant stakeholders. The appearance of the PGP key and manifesto has prompted further scrutiny of the authenticity of the leaked material and of any subsequent communications purporting to originate from BreachForums administrators. Ongoing monitoring of dark‑web forums has been conducted to assess whether the leak triggers a shift in criminal activity toward alternative platforms. No additional public actions, such as new arrests or seizures directly tied to the January 2026 leak, have been reported in the source material.

Sources

Sources available to members: 1 source.

CSIDB