[ad_1]
On June 25, 2025, French authorities introduced that 4 members of the ShinyHunters (also referred to as ShinyCorp) cybercriminal group had been arrested in a number of French areas for cybercrime actions and involvement within the English-language underground discussion board often known as BreachForums. The coordinated international regulation enforcement effort focusing on the ‘ShinyHunters’, ‘Hollow’, ‘Noct’, and ‘Depressed’ personas adopted the February arrest of Kai West (also referred to as ‘IntelBroker’), who beforehand administered BreachForums.
The ShinyHunters risk group has been lively since 2020 and has compromised organizations in industries equivalent to telecommunications, e-commerce, know-how, and retail. The group is understood for promoting stolen information solely on RaidForums and BreachForums. The ShinyHunters persona was a key participant in these boards as a contributor and administrator.
Since its unique creation as RaidForums in 2015, BreachForums had been taken down quite a few instances and had been administered by a number of personas. Table 1 lists a timeline of notable occasions within the discussion board’s historical past.
| Date | Event | Detail |
| March 19, 2015 | RaidForums launch | Diogo Santos Coelho (also referred to as ‘Omnipotent’) based RaidForums. It turned one of many largest information leak boards, peaking at over 530,000 customers. |
| January 31, 2022 | Arrest | Coelho was arrested within the UK on the request of U.S. authorities. |
| February 25, 2022 | Forum offline | RaidForums turned inaccessible, and a suspected credential-harvesting clone appeared. |
| March 4, 2022 | BreachForums (v1) launch |
Conor Fitzpatrick (also referred to as ‘Pompompurin’) launched BreachForums as a successor to RaidForums. |
| April 12, 2022 | Domain seizures | U.S. authorities introduced the seizure of RaidForums domains as a part of Operation TOURNIQUET. |
| March 15, 2023 | Arrest | Fitzpatrick was arrested in Peekskill, New York. |
| March 21, 2023 | Forum offline | An administrator often known as ‘Baphomet’ shut down the discussion board, citing considerations about regulation enforcement actions. |
| June 12, 2023 | BreachForums (v2) launch |
The ShinyHunters persona and Baphomet relaunched BreachForums (breachforums . vc). |
| June 18, 2023 | Forum compromise | BreachForums was compromised by ‘OnniForums’, and information of roughly 4,000 members was leaked. |
| May 15, 2024 | Domain seizures | U.S. authorities seized a number of BreachForums domains. |
| May 29, 2024 | BreachForums (v3) launch |
BreachForums resurfaced (breachforums . st). Users suspected that it was a honeypot, however it was ultimately deemed legit. |
| June 14, 2024 | Leadership change | ShinyHunters retired, and ‘Anastasia’ assumed possession. |
| August 1, 2024 | Leadership change | IntelBroker assumed management. |
| January 1, 2025 | Leadership change | IntelBroker resigned as proprietor, and Anastasia continued because the discussion board administrator. |
| February 2025 | Arrest | International regulation enforcement arrested Kai West (IntelBroker) in France. |
| April 28, 2025 | Forum offline | Despite quite a few claims and rumors, it’s unclear if the discussion board directors, one other risk group, or regulation enforcement was liable for the disappearance. |
| June 4, 2025 | BreachForums (v4) launch |
ShinyHunters relaunched the discussion board (breach-forums . st). |
| June 9, 2025 | Forum on the market | ShinyHunters introduced the discussion board was on the market. |
| June 22, 2025 | Arrests | French authorities arrested members of the ShinyHunters risk group throughout a coordinated regulation enforcement operation. |
| June 25, 2025 | Federal expenses | U.S. authorities unsealed an indictment charging Kai West (IntelBroker) with a number of cybercrimes. |
Table 1: Timeline of main BreachForums occasions.
The ShinyHunters persona partnered with Baphomet to relaunch the second occasion of BreachForums (v2) in June 2023 and later launched the June 2025 occasion (v4) alone. The interim model (v3) abruptly disappeared in April 2025, and the trigger is unclear. ‘Dark Storm Team’ claimed that it took the discussion board down by way of a distributed denial of service (DDoS) assault (see Figure 1). Other personas reported that the Qilin ransomware operators prompted the outage in retaliation for his or her ban from BreachForums. Rumors additionally circulated that regulation enforcement was accountable.
Figure 1: Dark Storm claiming duty for the BreachForums takedown. (Source: X)
On June 4, Counter Threat Unit™ (CTU) researchers recognized the relaunch of BreachForums (v4) underneath the administration of the ShinyHunters persona. One of the primary posts was purportedly by IntelBroker, a distinguished BreachForums contributor who took management of BreachForums (v3) in 2024. The persona maintained a status for promoting entry to database dumps and compromised techniques and was linked to cybercrime teams CNZ (redacted) and GOLD PUMPKIN (also referred to as HELLCAT). In January 2025, they stepped down as BreachForums’ proprietor (see Figure 2), and rumors of their arrest circulated. These rumors had been confirmed on June 25, when the U.S. Department of Justice (DOJ) introduced the unsealing of an indictment in opposition to Kai West, who operated underneath the IntelBroker alias. West was arrested in February, so the June BreachForums put up was submitted by somebody impersonating the persona.
Figure 2: IntelBroker saying resignation as BreachForums proprietor. (Source: X)
The BreachForums (v4) relaunch was short-lived. On June 9, the bulletin board displayed a discover that it was closed and that the discussion board was on the market for $2,500 USD (see Figure 3). The message explicitly warned scammers to “stay away”. The ShinyHunters members had been arrested two weeks later.
Figure 3: ShinyHunters promoting BreachForums on the market. (Source: BreachForums)
As of this publication, BreachForums stays offline. The discussion board’s future is unclear, however the sample of relaunches could proceed.
These arrests replicate growing regulation enforcement stress on cybercriminal infrastructure and operations. In the U.S. Department of Justice announcement concerning the arrest and indictment of Kai West, FBI Assistant Director in Charge Christopher G. Raia acknowledged that the arrests “should serve as a warning to anyone thinking they can hide behind a keyboard and commit cybercrime with impunity; the FBI will find and hold you accountable no matter where you are.” CTU™ researchers proceed to observe regulation enforcement actions and their impression on the cybercrime panorama.



