Taking the shine off BreachForums – Sophos News

0
257

[ad_1]

On June 25, 2025, French authorities introduced that 4 members of the ShinyHunters (also referred to as ShinyCorp) cybercriminal group had been arrested in a number of French areas for cybercrime actions and involvement within the English-language underground discussion board often known as BreachForums. The coordinated international regulation enforcement effort focusing on the ‘ShinyHunters’, ‘Hollow’, ‘Noct’, and ‘Depressed’ personas adopted the February arrest of Kai West (also referred to as ‘IntelBroker’), who beforehand administered BreachForums.

The ShinyHunters risk group has been lively since 2020 and has compromised organizations in industries equivalent to telecommunications, e-commerce, know-how, and retail. The group is understood for promoting stolen information solely on RaidForums and BreachForums. The ShinyHunters persona was a key participant in these boards as a contributor and administrator.

Since its unique creation as RaidForums in 2015, BreachForums had been taken down quite a few instances and had been administered by a number of personas. Table 1 lists a timeline of notable occasions within the discussion board’s historical past.

Date Event Detail
March 19, 2015 RaidForums launch Diogo Santos Coelho (also referred to as ‘Omnipotent’) based
RaidForums. It turned one of many largest information leak boards, peaking
at over 530,000 customers.
January 31, 2022 Arrest Coelho was arrested within the UK on the request of U.S. authorities.
February 25, 2022 Forum offline RaidForums turned inaccessible, and a suspected
credential-harvesting clone appeared.
March 4, 2022 BreachForums (v1)
launch
Conor Fitzpatrick (also referred to as ‘Pompompurin’) launched
BreachForums as a successor to RaidForums.
April 12, 2022 Domain seizures U.S. authorities introduced the seizure of RaidForums domains as
a part of Operation TOURNIQUET.
March 15, 2023 Arrest Fitzpatrick was arrested in Peekskill, New York.
March 21, 2023 Forum offline An administrator often known as ‘Baphomet’ shut down the discussion board, citing
considerations about regulation enforcement actions.
June 12, 2023 BreachForums (v2)
launch
The ShinyHunters persona and Baphomet relaunched BreachForums (breachforums . vc).
June 18, 2023 Forum compromise BreachForums was compromised by ‘OnniForums’, and information of
roughly 4,000 members was leaked.
May 15, 2024 Domain seizures U.S. authorities seized a number of BreachForums domains.
May 29, 2024 BreachForums (v3)
launch
BreachForums resurfaced (breachforums . st). Users suspected that
it was a honeypot, however it was ultimately deemed legit.
June 14, 2024 Leadership change ShinyHunters retired, and ‘Anastasia’ assumed possession.
August 1, 2024 Leadership change IntelBroker assumed management.
January 1, 2025 Leadership change IntelBroker resigned as proprietor, and Anastasia continued because the discussion board administrator.
February 2025 Arrest International regulation enforcement arrested Kai West (IntelBroker) in
France.
April 28, 2025 Forum offline Despite quite a few claims and rumors, it’s unclear if the discussion board
directors, one other risk group, or regulation enforcement was liable for the disappearance.
June 4, 2025 BreachForums (v4)
launch
ShinyHunters relaunched the discussion board (breach-forums . st).
June 9, 2025 Forum on the market ShinyHunters introduced the discussion board was on the market.
June 22, 2025 Arrests French authorities arrested members of the ShinyHunters risk
group throughout a coordinated regulation enforcement operation.
June 25, 2025 Federal expenses U.S. authorities unsealed an indictment charging Kai West
(IntelBroker) with a number of cybercrimes.

Table 1: Timeline of main BreachForums occasions.

The ShinyHunters persona partnered with Baphomet to relaunch the second occasion of BreachForums (v2) in June 2023 and later launched the June 2025 occasion (v4) alone. The interim model (v3) abruptly disappeared in April 2025, and the trigger is unclear. ‘Dark Storm Team’ claimed that it took the discussion board down by way of a distributed denial of service (DDoS) assault (see Figure 1). Other personas reported that the Qilin ransomware operators prompted the outage in retaliation for his or her ban from BreachForums. Rumors additionally circulated that regulation enforcement was accountable.

Screenshot of Dark Storm Team post claiming responsibility for the BreachForums takedown

Figure 1: Dark Storm claiming duty for the BreachForums takedown. (Source: X)

On June 4, Counter Threat Unit™ (CTU) researchers recognized the relaunch of BreachForums (v4) underneath the administration of the ShinyHunters persona. One of the primary posts was purportedly by IntelBroker, a distinguished BreachForums contributor who took management of BreachForums (v3) in 2024. The persona maintained a status for promoting entry to database dumps and compromised techniques and was linked to cybercrime teams CNZ (redacted) and GOLD PUMPKIN (also referred to as HELLCAT). In January 2025, they stepped down as BreachForums’ proprietor (see Figure 2), and rumors of their arrest circulated. These rumors had been confirmed on June 25, when the U.S. Department of Justice (DOJ) introduced the unsealing of an indictment in opposition to Kai West, who operated underneath the IntelBroker alias. West was arrested in February, so the June BreachForums put up was submitted by somebody impersonating the persona.

Screenshot of IntelBroker post resigning as BreachForums owner

Figure 2: IntelBroker saying resignation as BreachForums proprietor. (Source: X)

The BreachForums (v4) relaunch was short-lived. On June 9, the bulletin board displayed a discover that it was closed and that the discussion board was on the market for $2,500 USD (see Figure 3). The message explicitly warned scammers to “stay away”. The ShinyHunters members had been arrested two weeks later.

Screenshot of ShinyHunters advertising BreachForums for sale

Figure 3: ShinyHunters promoting BreachForums on the market. (Source: BreachForums)

As of this publication, BreachForums stays offline. The discussion board’s future is unclear, however the sample of relaunches could proceed.

These arrests replicate growing regulation enforcement stress on cybercriminal infrastructure and operations. In the U.S. Department of Justice announcement concerning the arrest and indictment of Kai West, FBI Assistant Director in Charge Christopher G. Raia acknowledged that the arrests “should serve as a warning to anyone thinking they can hide behind a keyboard and commit cybercrime with impunity; the FBI will find and hold you accountable no matter where you are.” CTU™ researchers proceed to observe regulation enforcement actions and their impression on the cybercrime panorama.

LEAVE A REPLY

Please enter your comment!
Please enter your name here