BreachForums Hacked — 325,000 Cybercriminal Accounts Exposed
On January 10, 2026, the BreachForums cybercrime bazaar suffered its own data breach: 324,000 user accounts with IP addresses, display names, and the forum’s official PGP key were published online. The leak is a goldmine for law enforcement and an operational catastrophe for members whose anonymity collapsed overnight.
May 2024. The FBI seizes the domains of BreachForums, the largest stolen-data marketplace on the dark web. Administrator Conor Fitzpatrick, aka \u201cPompompurin,\u201d is arrested. The forum is back under a new domain within weeks.
June 2025. Five operators of the latest iteration are arrested in France. The breachforums[.]hn domain shuts down on August 11, 2025. That same day, a ShinyHunters member publicly accuses the forum of being a law-enforcement honeypot.
January 10, 2026. A user named \u201cJames\u201d posts a 7 GB archive on a website linked to ShinyHunters. Inside: the complete BreachForums user database. 323,988 accounts exposed. The forum\u2019s official PGP key. Public IP addresses for 70,000 members.
The forum where stolen data was traded just gave up its own. No ransom demand. No negotiation. No adversary to blame. Just an unsecured folder on a server.
What Leaked
The archive, breachedforum.7z, contains three files.
databoose.sql: the mybb_users table from the MyBB forum engine, holding 323,988 records. Each entry carries a display name, registration date, email address, and IP address. The last account registered on August 11, 2025\u2014the very day the .hn domain closed.
breachedforum-pgp-key.txt.asc: the PGP private key created on July 25, 2023 and used by administrators to sign official announcements. It was passphrase-protected, but the password was discovered and verified the same day by Resecurity. Anyone can now sign messages impersonating BreachForums administrators.
shinyhunte.rs-the-story-of-james.txt: a manifesto signed by \u201cJames,\u201d the person behind the leak.
BleepingComputer\u2019s analysis revealed a critical detail. Most IP addresses in the database point to 127.0.0.9, a loopback address likely generated by an application-layer proxy meant to shield users\u2019 real locations.
But 70,296 records do not contain this ghost address. Those are public IPs, verified individually by researchers. For 70,000 members, anonymity disappeared the moment the archive went live.
That ratio\u201422% exposed\u2014suggests a failure in the anonymization mechanism at some point in the forum\u2019s history. Either the proxy was disabled for a period, or certain access paths bypassed the protection entirely.
The Stolen-Data Bazaar Gets Its Own Data Stolen
BreachForums was never an ordinary forum. The successor to RaidForums\u2014seized in 2022\u2014it was the gravitational center of the cybercriminal ecosystem. Ransomware groups, initial-access brokers, database resellers: everyone had an account.
The volume of data that transited through it is hard to quantify. Hundreds of terabytes of corporate records\u2014Salesforce, Accenture, Ernst & Young\u2014were listed for sale. Medical records. Government databases. Network access priced by the victim\u2019s annual revenue.
The forum survived three FBI seizures. The arrest of founder Pompompurin in March 2023. A French law-enforcement operation in June 2025. Each time, it resurfaced under a new domain with a fresh crew.
In 2025, the ShinyHunters extortion group\u2014known for the widespread Salesforce customer attacks\u2014took control of the latest iteration. The forum doubled as a storefront for their own operations. The breachforums[.]hn domain was seized by the FBI in October 2025.
Then came January 10, 2026. And this time, BreachForums wasn\u2019t seized by law enforcement. It was hacked. The line between predator and prey just vanished.
The Mechanics of a Fatal Mistake
The current administrator, known as \u201cN/A,\u201d acknowledged the leak in a post on the forum itself\u2014the only platform left for him to address his community.
According to his account, a backup of the users table was temporarily stored in an unsecured folder on the server during the forum\u2019s restoration from the .hn domain migration in August 2025. The folder was downloaded \u201conly once\u201d during that exposure window.
The administrator reminded members that disposable email addresses had been recommended and that most IPs mapped to the local proxy address.
Those caveats change nothing. 70,000 public IPs are in the wild. The PGP key is compromised\u2014password included. The database is downloadable by anyone with the link.
One configuration mistake. One forgotten folder. That\u2019s all it took.
A Goldmine for Law Enforcement
For investigators, this leak is a force multiplier that years of conventional investigation could never have delivered.
Every public IP address can be cross-referenced with:
- Connection logs from previously seized services\u2014VPNs, encrypted messengers, cryptocurrency exchanges.
- Ongoing investigations into ransomware campaigns, intrusions, or data sales where the same pseudonym appears.
- ISP records and geolocation data, turning an IP address into a physical identity.
The presence of 70,000 public IPs is especially valuable because it contradicts the forum\u2019s implicit promise. BreachForums members operated under the assumption that their real addresses were protected. That betrayed trust is the leak\u2019s true treasure.
Resecurity also confirmed that the PGP key\u2019s password, initially absent from the archive, was added to the leak site hours after the initial publication. That update transformed an unusable key into a full impersonation tool.
The pattern isn\u2019t new. In 2017, Dutch police operated the Hansa dark market for an entire month before shutting it down, harvesting identifiers from thousands of users. In 2023, the FBI\u2019s Operation Cookie Monster dismantled Genesis Market using the same logic: hit the marketplace to reach all its customers at once.
This time, investigators didn\u2019t even have to seize the forum. A misconfigured folder did the job for them.
The Verdict
BreachForums just delivered, despite itself, the most vivid demonstration of a principle every security professional knows but few act on: compromise is not a question of skill. It\u2019s a question of attack surface.
The forum\u2019s administrators were seasoned operators, aware of the stakes, targeted by the FBI and French authorities. They ran infrastructure that survived three international seizures. And they left a SQL dump in an accessible directory.
The lesson extends far beyond the dark web. If the BreachForums team can make this mistake, so can yours. Your open S3 bucket, your API token in a Git repository, your unencrypted backup on a network share aren\u2019t any safer. Infrastructure security isn\u2019t measured by the sophistication of your defenses, but by the number of unverified human decisions that pass through it every day.
For the BreachForums members whose IP is in that file, there is no patch. The information is out. It\u2019s indexed, shared, cross-referenced. The only question is who will use it first\u2014investigators or rivals.
References
- BreachForums hacking forum database leaked, exposing 324,000 accounts, BleepingComputer, Lawrence Abrams, January 10, 2026.
- FBI takes down BreachForums portal used for Salesforce extortion, BleepingComputer, Bill Toulas, October 10, 2025.
- BreachForums hacking forum operators reportedly arrested in France, BleepingComputer, Bill Toulas, June 25, 2025.
- FBI seizes BreachForums after arresting its owner Pompompurin, BleepingComputer, Lawrence Abrams, 2024.