Update: BreachForums is Shutting Down
One week after the arrest of the BreachForums founder, the forum was taken offline by its new administrator.
Baphomet, the new administrator, gave a statement about the closure:
This will be my final update on Breached, as I've decided to shut it down. I'm aware this news will not please anyone, but it's the only safe decision now that I've confirmed that the glowies likely have access to Poms machine.
As I said early on in all of this, anything related to production Breached infrastructure was locked down immediately - however I was kind enough to leave a few old, non-essential servers completely unchanged. One of those servers I left unchanged is an old CDN from months ago that no longer hosts any CDN files or configs but rather was used to just download large files from time to time.
Throughout the migration I checked to see if anything was going on that would cause concern during the migration. One of the servers checked, was the old CDN server described above. It seems someone logged in on Mar 19, 1:34 EST prior to me logging into the server. Unfortunately this likely leads to the conclusion that someone has access to Poms machine. Any servers we use are never shared with anyone else, so someone would have to know the credentials to that server to be able to login. I now feel like I'm put into a position where nothing can be assumed safe, whether its our configs, source code, or information about our users - the list is endless. This means that I can't confirm the forum is safe, which has been a major goal from the start of this shitshow.
As for what this means now, It's complicated. Unlike when other communities go down and everyone scatters, stupidly I will still be around. I will redirect all the Breached domains to my baph.is domain. The Telegram group and channel will remain up for now, but I will make a new Telegram group for those interested in seeing what I have planned next. I will always be willing to sign a message to prove my identity to the community.
While the community of Breached will die, I'm going to continue conversations with some of the competitor forum admins and various service operators who reached out to me over the past few days. I'm hoping to work with some of those people to build a new community, that will have the best features of Breached, while reducing the attack surfaces we never properly addressed. As with things like this, I have no doubt our userbase may be absorbed by another community but if there is patience then I hope to bring something back that will rival any other community that can take our place.
I'll be taking 24 hours from the sharing of this message to just rest and think. I'll be back online to talk with everyone, and we'll go from there. The domains for the time being shouldn't be seized, but I'll let the community know if any of that happens.
Baphomet's signed message can be found here.
End Update
Conor Brian Fitzpatrick, aka Pompompurin, was arrested by a team of investigators at his home around 4:30 p.m. Wednesday, FBI Special Agent John Longmire said in a sworn statement filed in court the next day. Fitzpatrick is charged with a single count of conspiracy to commit access device fraud.
BreachForums hosted the stolen databases of almost 1,000 companies and websites. The databases often includes personal information, such as names, emails and passwords. The information is offered for sale by users of the site and can be used for fraud. Pompompurin’s profile on BreachForums describes him as “Bossman.” Longmire, a 16-year FBI Agent who said he had led the agents in the arrest, said Fitzpatrick admitted he had used the alias “pompompurin” and was the owner and operator of BreachForums.
Despite the arrest, BreachForums remains up and online on both its Tor and clearnet URLs. Co-admin Baphomet has assumed the primary leadership role for the site, posting the following about pompompurin in a PGP-signed message in a thread on the forum:
Although I had already suspected it to be the case, its now been confirmed that Pom has been arrested: bloomberglaw.com/privacy-and-data-security/dark-web-breachforums-operator-charged-with-computer-crime
I think it's safe to assume he won't be coming back, so I'll be taking ownership of the forum. I have most, if not all the access necessary to protect BF infrastructure and users.
I pretty much already assumed the worst at nearly 24 hours of inactivity. It's not often Pom is gone an extended period of time, and he's always let me know ahead of time if that would be the case. He's also never been inactive this long on both Telegram, Element and the forum at the same time. At that point I decided to remove his access to all important infrastructure and restricted his forum account to still login but not to carry out any administrator actions. I also since that point have been constantly monitoring everything and going through every log to see any access or modifications to Breached infra. So far nothing like that has been seen.
I can’t respond to everyone at this point, as I am working through the next steps of the emergency plan for the forum. Please be patient, and try not to lose your minds.
My only response to LE, or any media outlet is that I have no concerns for myself at the moment. OPSEC has been my focus from day one, and thankfully I don’t think any mountain lions will be attacking me in my little fishing boat.
You can find a signed version of this message here.
A local newspaper listed Fitzpatrick among the 2021 graduates of Peekskill High School. A local news station posted video of FBI and Homeland Security agents, working with local police, raiding a home in Peekskill on Wednesday and carrying bags of possible evidence from the house. The report didn’t identify Fitzpatrick as the target, but the address is the one listed in online records as the house where he lived with his parents.
In November 2021, Pompompurin claimed responsibility for sending out fake emails that originated from an “fbi.gov” email address. Pompompurin claimed responsibility for the breach in an interview with Brian Krebs.
Fitzpatrick had been closely scrutinized by cybersecurity investigators for more than a year, and was considered a significant player in the cybercrime ecosystem, according to multiple people familiar with the situation who asked not to be identified because the information isn’t public.
RaidFourms, the spiritual precursor to BreachForums, was sized by the Federal Bureau of Investigation in April 2022.
“Breach Forums is one of, if not the most active, hacker forums out there,” said Allan Liska, a senior intelligence analyst at cybersecurity firm Recorded Future. “They are well-known for leaking sensitive information stolen from major organizations around the world including the Robinhood trading platform and Acer Computers.”But we all have good VPNs I guess, right…right guys?
- "Anonymous" BreachForums user.
So for your information, Pom was using Mullvad for all we know. However I think what got him arrested was the large spread he had on him and kinda weird opsec. Check his Twitter. He wasn't as active as he use to be, but twitter.com/xml/status/1593187931073961985#m a phone? why? and theres much more slipps the guy was doing. Of course, a phone is just a phone for all we know, if used properly, fingerprint may be pretty useless, but still it accumulates. I still think he was a real G. Just really unclear to me why he was flexing so fucking hard. @xml or his domains like "a.sc" what the fuck