{"id":13860,"date":"2023-03-20T16:25:06","date_gmt":"2023-03-20T16:25:06","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=13860"},"modified":"2023-03-22T03:10:53","modified_gmt":"2023-03-22T03:10:53","slug":"breachforums-shutdown","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/breachforums-shutdown\/","title":{"rendered":"BreachForums is down. Things got worse?"},"content":{"rendered":"<p>Recently, one of BreachForums administrators nicknamed PomPomPurin was arrested by the FBI. That event took place <strong>on March 17, 2023<\/strong>, and since then, another administrator of that forum assured that BreachForums activity will not be interrupted or influenced. However, <strong>since 19:00 GMT of March 19, the page is not available<\/strong>.<\/p>\n<h2>What is BreachForums and who is PomPomPurin?<\/h2>\n<p>BreachForums is one of the biggest online communities dedicated to hacking, data leaks, malware and so forth. It goes deeply beyond the boundaries of legitimacy and is considered <a href=\"https:\/\/gridinsoft.com\/darknet\">one of the Darknet markets<\/a>. It contains <strong>numerous offers of leaked data for sale \u2013 mainly from corporations and government organisations<\/strong>. BreachForums also was a place to post bids for access to corporate networks and databases with data of specific groups of people. Despite such illegal content, it was available from the surface Web, yet <a href=\"https:\/\/gridinsoft.com\/blogs\/access-dark-web-darknet-safely\/\">some sections were Darknet-only<\/a>. The fact that the FBI is interested in stirring this snake ball is estimated.<\/p>\n<p>On March 17, 2023, one of the administrators of BreachForums, <strong>PomPomPurin a.k.a Conor Brian Fitzpatrick was detained<\/strong>. The FBI <a href=\"https:\/\/loaris.app\/blogs\/breachforums-administrator-is-detained\/\" target=\"_blank\" rel=\"noopener nofollow\">arrested him in his house<\/a> in Peekskill, NY. That fact was approved by another \u201cchief\u201d of the forum, nicknamed Baphomet. He noticed that Pom did not appear online for over a day without any warning. After that, he banned both the forum account and server infrastructure access of the detainee. <strong>Baphomet additionally pointed out that BreachForums&#8217; work will not be interrupted<\/strong>, as he has enough access to maintain the servers. As it turned out, something went wrong.<\/p>\n<figure id=\"attachment_13862\" aria-describedby=\"caption-attachment-13862\" style=\"width: 1280px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/banned-pom.jpg\" alt=\"PomPomPurin account banned\" width=\"1280\" height=\"679\" class=\"size-full wp-image-13862\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/banned-pom.jpg 1280w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/banned-pom-300x159.jpg 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/banned-pom-1024x543.jpg 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/banned-pom-768x407.jpg 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><figcaption id=\"caption-attachment-13862\" class=\"wp-caption-text\">Blocked account that belonged to PomPomPurin<\/figcaption><\/figure>\n<h2>BreachForums website is not available<\/h2>\n<p>On March 19, 2023, users noticed that BreachForums is not accessible. When trying to access the surface Web version, the server returns 502 error code. It also says <strong>\u201cLooks like we have got an invalid response from the upstream server. That\u2019s all we know\u201d<\/strong>. The Darknet version shows an <strong>Onionsite Not Found<\/strong> error, which generally stands for the situation when <a href=\"https:\/\/gridinsoft.com\/blogs\/ddos-attacks-6-tried-and-tested-methods-how-to-prevent-it\/\">servers that were holding the website<\/a> are not operating. At a glance, it looks like the FBI proceeded from PomPomPurin detainment to seizing the servers.<\/p>\n<figure id=\"attachment_13863\" aria-describedby=\"caption-attachment-13863\" style=\"width: 1009px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breached-tor.png\" alt=\"Breached Forums Onionsite\" width=\"1009\" height=\"729\" class=\"size-full wp-image-13863\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breached-tor.png 1009w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breached-tor-300x217.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breached-tor-768x555.png 768w\" sizes=\"auto, (max-width: 1009px) 100vw, 1009px\" \/><figcaption id=\"caption-attachment-13863\" class=\"wp-caption-text\">Error returned by the Onion version of BreachForums<\/figcaption><\/figure>\n<p>Baphomet claimed that there is no danger of the FBI taking over the infrastructure, both physically and technically. Nonetheless, after the BreachForums shutdown, he reappeared with another message. It says that currently <strong>Baph does his best to migrate the servers and reconfigure everything<\/strong> as quickly as possible. He also tries to give no chance for law enforcement to reveal it.<\/p>\n<figure id=\"attachment_13865\" aria-describedby=\"caption-attachment-13865\" style=\"width: 822px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breachforums-migration.png\" alt=\"BreachForums migration\" width=\"822\" height=\"696\" class=\"size-full wp-image-13865\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breachforums-migration.png 822w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breachforums-migration-300x254.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breachforums-migration-768x650.png 768w\" sizes=\"auto, (max-width: 822px) 100vw, 822px\" \/><figcaption id=\"caption-attachment-13865\" class=\"wp-caption-text\">Baphomet message regarding ongoing works<\/figcaption><\/figure>\n<p>That contrasts with his claims in the forum post, where he says about doing constant monitoring of logs to uncover anything that may be a sign of infrastructure compromise. If he suddenly decided to migrate the infrastructure \u2013 <strong>probably the FBI found a way to access it despite the blocks deployed by Baphomet<\/strong>. Another possible cause is that Pompompurin was pretty talkative, especially considering the possible softening of punishment for cooperation.<\/p>\n<figure id=\"attachment_13866\" aria-describedby=\"caption-attachment-13866\" style=\"width: 1660px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-claim.png\" alt=\"Baphomet claim day1\" width=\"1660\" height=\"425\" class=\"size-full wp-image-13866\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-claim.png 1660w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-claim-300x77.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-claim-1024x262.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-claim-768x197.png 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-claim-1536x393.png 1536w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-claim-1568x401.png 1568w\" sizes=\"auto, (max-width: 1660px) 100vw, 1660px\" \/><figcaption id=\"caption-attachment-13866\" class=\"wp-caption-text\">Message that Baphomet posted as soon as the information about the detainment appeared<\/figcaption><\/figure>\n<p>This or another way, BreachForums is likely entering troubled times. Even if the migration ends up successful, law enforcement may still be on the trail. <strong>Possibly, Baphomet is the next to face nice men in uniform<\/strong> \u2013 just because of his decision to take over the forum controls. Still, nothing points to the impossibility of the Breached Forums returning and running in a usual manner \u2013 as if nothing happened.<\/p>\n<h2>Update for 21.03.2023<\/h2>\n<p>A message in the BreachForums Telegram channel appeared, <strong>claiming that Breached Forums will not be continued<\/strong>. The channel that most likely belongs to the aforementioned Baphomet, posted the following message:<\/p>\n<figure id=\"attachment_13884\" aria-describedby=\"caption-attachment-13884\" style=\"width: 486px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/tg-community.png\" alt=\"Baphomet TG post\" width=\"486\" height=\"441\" class=\"size-full wp-image-13884\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/tg-community.png 486w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/tg-community-300x272.png 300w\" sizes=\"auto, (max-width: 486px) 100vw, 486px\" \/><figcaption id=\"caption-attachment-13884\" class=\"wp-caption-text\">Baphomet&#8217;s post in Telegram community<\/figcaption><\/figure>\n<p><strong>&#8220;I will be taking down the forum, as I believe we can assume that nothing is safe anymore&#8221;<\/strong>. That already says a lot regarding what happened to Breached Forums after the PomPompurin detainment. Though Baphomet still has a bit of hope, saying that he will establish another Telegram group, where he will notify about possible betterment.<\/p>\n<p>Even more interesting details appear in the text file that Baph offers to download. It finally sheds light on the FBI\u2019s part in this action. It says that Baph <strong>detected login activity on one of the non-essential servers on March 19, 2023<\/strong> \u2013 two days after Pom\u2019s arrest. Thus it is logical to assume that law enforcement succeeded at taking over PomPomPurin&#8217;s computer and accessing it. The server contained enough information to <strong>compromise source code, user information, configurations and other things<\/strong>.<\/p>\n<figure id=\"attachment_13885\" aria-describedby=\"caption-attachment-13885\" style=\"width: 1401px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim.png\" alt=\"Baphomet Finalstatement\" width=\"1401\" height=\"755\" class=\"size-full wp-image-13885\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim.png 1401w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim-300x162.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim-1024x552.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim-768x414.png 768w\" sizes=\"auto, (max-width: 1401px) 100vw, 1401px\" \/><figcaption id=\"caption-attachment-13885\" class=\"wp-caption-text\">Baphomet&#8217;s final statement regarding BreachForums<\/figcaption><\/figure>\n<h2>BreachForums epitaph<\/h2>\n<p>It is not completely clear whether Baphomet will use assets from BreachForums or not. He states that a number of other hacker forums\u2019 admins and representatives contacted him, offering certain deals. Baph promises \u201cto build a new community that will have the best features of Breached\u201d. Yet, by these words, <strong>the actor confirms that BreachForums are completely ceased, with no chance to return<\/strong>.<\/p>\n<p>Breached Forums saw their major boost after the RaidForums shutdown back in April 2022. A huge community of hackers was seeking another place to communicate, and exchange experiences and stolen data. <strong>Pom\u2019s brainchild was first on hand<\/strong>. Moreover, he was brave enough to post an offer to join his forum right under the FBI\u2019s Twitter post regarding the RaidForums shutdown.<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/pom-fbi.png\" alt=\"Pompompurin FBI raidforums\" width=\"541\" height=\"802\" class=\"aligncenter size-full wp-image-13886\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/pom-fbi.png 541w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/pom-fbi-202x300.png 202w\" sizes=\"auto, (max-width: 541px) 100vw, 541px\" \/><\/p>\n<p>Will the hacker community suffer because of such a loss? Most probably, other hacker sites will witness a spike in activity \u2013 <strong>nature always abhors a vacuum<\/strong>. Another edge of the &#8220;problem&#8221; is a slowdown in hacker operations: there is no usual place to sell the stolen and buy the needed access or applications. Nonetheless, they will definitely adapt to the situation, and we will see the outcome in the near future.<\/p>\n<p style=\"padding-top:15px;padding-bottom:15px;\"><a href=\"\/download\/antimalware\" rel=\"nofollow\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"\/blogs\/wp-content\/uploads\/2022\/07\/env01.webp\" alt=\"BreachForums is down. Things got worse?\" width=\"798\" height=\"336\" class=\"aligncenter size-full\" title=\"\"><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently, one of BreachForums administrators nicknamed PomPomPurin was arrested by the FBI. That event took place on March 17, 2023, and since then, another administrator of that forum assured that BreachForums activity will not be interrupted or influenced. However, since 19:00 GMT of March 19, the page is not available. What is BreachForums and who [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":13861,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[15],"tags":[1221,619,416,123],"class_list":{"0":"post-13860","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-news","8":"tag-breachforums","9":"tag-cybersecurity","10":"tag-darknet","11":"tag-fbi"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/breachedforums-shutdown.webp","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/13860","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=13860"}],"version-history":[{"count":6,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/13860\/revisions"}],"predecessor-version":[{"id":13889,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/13860\/revisions\/13889"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/13861"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=13860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=13860"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=13860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}