{"id":15309,"date":"2023-06-15T11:10:18","date_gmt":"2023-06-15T11:10:18","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=15309"},"modified":"2023-06-15T11:17:28","modified_gmt":"2023-06-15T11:17:28","slug":"breachforums-is-back-online-shinyhunters","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/breachforums-is-back-online-shinyhunters\/","title":{"rendered":"BreachForums Is Back Online, Led by ShinyHunters"},"content":{"rendered":"<p>BreachForums, an infamous Darknet forum that was shut down in late March 2023, <strong>is back online since approx. June 13 2023<\/strong>. After 3 months offline, it is revived by a hacker group called ShinyHunters. <strong>But will Breached be as successful as they used to be?<\/strong><\/p>\n<h2>What is BreachForums?<\/h2>\n<p>Breached Forums used to be a massive Darknet forum that was acting <strong>not only as a communication platform but also as a black market<\/strong>. Hackers from all over the world were selling databases of leaked credentials, banking cards, data stolen from corporations and so forth. Its popularity peaked in early summer 2022, after the FBI <a href=\"https:\/\/gridinsoft.com\/blogs\/raid-forums-shutdown\/\">closed another Darknet forum<\/a> \u2013 RaidForums \u2013 and detained its administrator.<\/p>\n<p>Though, the same but different fate was against BreachForums. One day, Conor Brian Fitzpatrick a.k.a. Pompompurin made a mistake that cost him his freedom \u2013 logged into his account <a href=\"https:\/\/gridinsoft.com\/vpn\">without using VPN<\/a>. That immediately revealed his IP address, and just in a couple of days, pleasant men in uniform were at his doorstep. Despite the servers not being accessed by the law enforcement directly, <strong>the other admin of BreachForums decided to shut off the forum<\/strong>, as there was a risk that law enforcement would find him as well.<\/p>\n<figure id=\"attachment_13885\" aria-describedby=\"caption-attachment-13885\" style=\"width: 1401px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim.png\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim.png\" alt=\"Baphomet Finalstatement\" width=\"1401\" height=\"755\" class=\"size-full wp-image-13885\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim.png 1401w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim-300x162.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim-1024x552.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/03\/baph-last-claim-768x414.png 768w\" sizes=\"auto, (max-width: 1401px) 100vw, 1401px\" \/><\/a><figcaption id=\"caption-attachment-13885\" class=\"wp-caption-text\">The second admin&#8217;s statement regarding BreachForums shutdown<\/figcaption><\/figure>\n<p>But, as it turns out, there could be life after death. In late May 2023, <a href=\"https:\/\/twitter.com\/vxunderground\/status\/1664676220628357120\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">several places posted information<\/a> regarding the Breach revival by ShinyHunters. This infamous gang states they <strong>will take over the Breached Forums and run it despite the hazards<\/strong> from the enforcement agencies. And now it is confirmed &#8211; BreachForums is back online.<\/p>\n<h2>BreachForums Are Revived by ShinyHunters<\/h2>\n<p>Probably, the most obvious sign of recognition for the cybercrime gang is the article on Wikipedia. Black hat hackers from ShinyHunters <a href=\"https:\/\/intel471.com\/blog\/shinyhunters-data-breach-mitre-attack\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">are known for hacking into Microsoft<\/a>, Bonobos, NitroPDF and many others \u2013 enough to get an ill fame. Being active since 2020, they quickly gained a considerable number of victims, especially for peaky guys that are not attacking everyone they see. Despite the detainment of one of their crew members in Morocco, <strong>the gang keeps going and, what\u2019s more important, expanding their activities<\/strong>.<\/p>\n<figure id=\"attachment_15310\" aria-describedby=\"caption-attachment-15310\" style=\"width: 887px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/breached-welcome.webp\" alt=\"BreachForums Back Online\" width=\"887\" height=\"482\" class=\"size-full wp-image-15310\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/breached-welcome.webp 887w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/breached-welcome-300x163.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/breached-welcome-768x417.webp 768w\" sizes=\"auto, (max-width: 887px) 100vw, 887px\" \/><\/a><figcaption id=\"caption-attachment-15310\" class=\"wp-caption-text\">First message on the recovered BreachForums site<\/figcaption><\/figure>\n<p>The \u201ctakeover\u201d of BreachForums is probably the new vector of cybercrime gang development \u2013 in all senses. It is <strong>probably the first time when a full-fledged cybercrime gang will have an entire forum<\/strong> under their control. Such a behaviour is also a definite sign of <a href=\"https:\/\/gridinsoft.com\/hacker\">hackers having no fairness<\/a> before law enforcement. This forum was \u2013 and still is \u2013 a subject of FBI investigation, thus claiming its possession is dangerous to say the least. Possibly, Baphometh, the second admin of Breached, joined or sold all the assets related to this forum to the gang.<\/p>\n<h2>Conflict with other forums<\/h2>\n<p>Obviously, after the Breached shutdown in late March, <strong>its numerous alternatives popped out<\/strong>. Though fellow hackers did not haste using them, because of fears these platforms <a href=\"https:\/\/gridinsoft.com\/honeypot\">may be controlled by the FBI<\/a> or other law enforcement. To bait people, these forums were claiming \u201ccooperation with Breached\u201d, which forced Baphometh to publicly reject any relations. Though some black markets, like Exposed Forum, went further, putting to use incriminating banners like the one they currently have.<\/p>\n<figure id=\"attachment_15323\" aria-describedby=\"caption-attachment-15323\" style=\"width: 632px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/exposed-message.webp\" alt=\"Exposed forums rant\" width=\"632\" height=\"378\" class=\"size-full wp-image-15323\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/exposed-message.webp 632w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/exposed-message-300x179.webp 300w\" sizes=\"auto, (max-width: 632px) 100vw, 632px\" \/><\/a><figcaption id=\"caption-attachment-15323\" class=\"wp-caption-text\">Banner by the ex-ExposedForum URL that incriminates BreachForums admins of bad OPSEC<\/figcaption><\/figure>\n<p>Possibly, such a decision and reaction from Exposed admin(s) is dictated by the Breached resurgence. Having to compete with such a large and widely-known brand is pretty tough, thus selling off is an obvious decision. But for me, it <a href=\"https:\/\/gridinsoft.com\/deception-technology\">looks like shutting down the honeypot<\/a> which will not be able to attract enough crooks after the rebirth of Breached. This guess is complemented with what appears to be the IP address and hosting name of the Breached back-end server. It is known that the FBI accessed (part of) the network infrastructure of BreachedForums \u2013 that\u2019s why, exactly, it was disabled. <strong>And I doubt feds are generous enough to allow some hackers to mess around<\/strong> this information.<\/p>\n<h2>What then?<\/h2>\n<p>It will be pretty interesting to see the fate of such an ambitious step. As I said, after the Breached Forums shutdown, <strong>a lot of its alternatives appeared<\/strong>. Some even provided themselves with \u201cpromotion\u201d \u2013 like Exposed forum, that <a href=\"https:\/\/gridinsoft.com\/blogs\/raidforums-data-breach\/\">posted the leaked database of RaidForums<\/a>. Two months of shutdown never was a pleasant thing for popularity \u2013 thus the only thing we can do is simply spectate.<\/p>\n<p>For now, <strong>I can warn you about using all such forums<\/strong>. Being a cybercriminal\u2019s nest, any Darknet forum accumulates tons of illegal stuff. Touching it, even if it is a database leaked a couple of years ago, may be the reason for law enforcement to pay a visit to your settlement. Moreover, such places commonly swirl with pitfalls where you can be tricked to install malware. And it is good to remember that all such places are thoroughly controlled by the FBI and other enforcement agencies. <strong>Everything you say can and will be used against you!<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BreachForums, an infamous Darknet forum that was shut down in late March 2023, is back online since approx. June 13 2023. After 3 months offline, it is revived by a hacker group called ShinyHunters. But will Breached be as successful as they used to be? What is BreachForums? Breached Forums used to be a massive [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":15313,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[15],"tags":[1221,619,416,29],"class_list":{"0":"post-15309","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-news","8":"tag-breachforums","9":"tag-cybersecurity","10":"tag-darknet","11":"tag-hackers"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2023\/06\/breached-featured.webp","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/15309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=15309"}],"version-history":[{"count":6,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/15309\/revisions"}],"predecessor-version":[{"id":15324,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/15309\/revisions\/15324"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/15313"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=15309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=15309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=15309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}