Cybercrime DB

BreachForums and Stolen Data Market Prosecutions

Shutting down stolen data markets doesn't stop the trade—it just changes hands.

Senior Writer · · 11 min read
Cover illustration for “BreachForums and Stolen Data Market Prosecutions”
dark web markets and forums · September 21, 2026 · 11 min read · 2,454 words

BreachForums ran through three eras, three owners, and one very predictable ending. Each version got seized, its owner got unmasked, and the data kept moving anyway. That pattern, not any single arrest, is the story that explains what a takedown actually buys you.

Conor Brian Fitzpatrick started the site in March 2022 under the handle "Pompompurin," building it as a direct replacement the moment law enforcement shut down RaidForums. Despite the "dark web" label everyone slaps on it, BreachForums ran on the regular internet as well as Tor. The "dark web" part was never about hosting, it described what happened there: a mix of community forum and open marketplace, where reputation scores sat right next to live listings for stolen databases, breached credentials, and hands-on access to hacked networks.

Courts and the DOJ put a number on version one of the platform: more than 330,000 members, access to at least 888 stolen datasets, and over 14 billion individual records containing names, dates of birth, Social Security numbers, employment information, and health insurance information. Fitzpatrick personally pocketed $698,714 working as the middleman between sellers and buyers, his own sentencing records show. Benoît Grunenwald at ESET called it "the historic crossroads between those who attack companies and those looking to buy fresh data," which is about as clean a description of the site's actual function as you'll find. Those figures belong to v1 only. Later versions carried the same name under different owners, different infrastructure, and different scale.

How the criminal supply chain around stolen data works

Strip away the drama and BreachForums looked a lot like any B2B marketplace, staffed by people who'd get arrested for a profile on a professional networking site. Phishing crews, infostealer operators, and ransomware groups collect the raw material. Initial access brokers package it. Marketplace operators list and move it. Fraud rings, ransomware affiliates, and occasionally a nation-state buyer pay for it. Everyone specializes, nobody talks to the tax authority about it.

The raw material isn't scarce. Verizon's 2025 Data Breach Investigations Report found credential theft involved in 22% of breaches, 20% of exploited vulnerabilities, and 16% of phishing incidents. Flashpoint's 2025 Global Threat Intelligence Report tracked more than 23 million infostealer-infected hosts, which produced 2.1 billion harvested credentials. KELA's State of Cybercrime 2026 report counted 2.86 billion compromised credentials moving across criminal markets in 2025 alone. That's not a leak; that's a firehose.

Pricing runs on logic you'd recognize from any secondhand market: freshness, completeness, whether it still works, which country it's from. U.S. credit cards with a CVV code go for $10 to $40. A card with a verified $5,000 balance sitting behind it jumps to $110 to $120. Healthcare records sell for $500 or more per record, and unlike a credit card number, you can't just call the bank and cancel a stolen diagnosis. Check Point's IAB report puts corporate network access mostly at $500 to $3,000, with domain admin credentials pulling in far more. FBI's Internet Crime Complaint Center put total cybercrime losses at $20.9 billion in 2025, up 26% from the year before. That's the downstream bill for what gets traded upstream.

Payment channels vary by transaction type, with privacy coins preferred for marketplace trades, though Chainalysis's 2025 Crypto Crime Report found stablecoins, mainly USDT, now account for 63% of illicit crypto volume. And none of this data has an expiration date. A record stolen once can get resold, repackaged, and reused for years after the original breach, which is the detail that makes "we took down the marketplace" a much smaller victory than it sounds.

Fitzpatrick's arrest, guilty plea, and the sentencing reversal that recalibrated deterrence

Fitzpatrick got arrested in March 2023 and pleaded guilty that July to three federal counts: two tied to access device fraud, one for possessing child sexual abuse material. His original sentence landed like a punchline nobody asked for: time served, which came out to 17 days, plus 20 years of supervised release. The defense leaned on his autism diagnosis, arguing prison offered no correctional value. Seventeen days. For a site that moved 14 billion records.

The Fourth Circuit Court of Appeals wasn't buying it either. On January 21, 2025, the appeals court vacated the sentence as substantively unreasonable, pointing to the seriousness of the crimes and the need for actual deterrence. Prosecutors had originally asked for at least 188 months. When Judge Leonie Brinkema resentenced Fitzpatrick on September 16, 2025, he got three years in prison plus the same 20 years of supervised release.

That reversal matters beyond Fitzpatrick's own case. An appeals court stepping in specifically to correct leniency toward a forum operator signals that courts now treat this as its own category of crime, distinct from a lone hacker breaking into one company. For security teams watching this from the outside, the deterrence language the Fourth Circuit used is the tell: prosecutors and judges are starting to price in the scale of harm these platforms enable, not just the individual act of running a website.

None of this ended the platform, though. Fitzpatrick's arrest in March 2023 kicked off a leadership handoff, first to an operator known as Baphomet, then to ShinyHunters, and eventually to IntelBroker. His case turned out to be chapter one of a longer story, not the finale.

IntelBroker's career as BreachForums owner and how FBI tradecraft unmasked him

IntelBroker turned out to be Kai West, a 25-year-old British national who ran BreachForums from August 2024 to January 2025. French authorities arrested him in February 2025, and federal prosecutors followed. charges got unsealed alongside the broader French sweep that June.

The scale of what he's accused of is genuinely startling. Prosecutors say West breached more than 40 organizations between 2023 and 2025, offering stolen data for sale at least 41 times and giving it away or trading it for site credits roughly 117 more. He allegedly sought over $2 million in payment and caused at least $25 million in victim losses. The named victims read like a corporate directory: an international police agency, General Electric, AMD, HPE, Nokia, Cisco, and DC Health Link, the last of which is notable because it exposed the health care plan data of federal lawmakers. House members and staff.

He's facing a four-count federal indictment: conspiracy to commit computer intrusions, conspiracy to commit wire fraud, unauthorized access to a protected computer, and wire fraud. The charges each carry maximum sentences ranging from five to twenty years in prison.

The unmasking itself deserves close attention. FBI investigators used open-source research and undercover purchases, buying stolen data directly from West posing as regular criminal customers. An email account tied back to him held invoices and identifying records, which is how agents connected the real person to the IntelBroker persona. It's the same playbook threat intelligence teams use to track personas across forums: correlate usernames, cross-reference metadata, follow the money trail. The difference is the FBI got to make an arrest at the end of it. West remains in French custody, and the case hasn't resolved as of this writing.

The June 2025 French sweep that dismantled the successor administration

On June 23, 2025, France's cybercrime unit, the Brigade de lutte contre la cybercriminalité (BL2C), arrested four people operating under the aliases ShinyHunters, Hollow, Noct, and Depressed. The arrests, made public on June 25, hit metropolitan France and La Réunion simultaneously, spanning Hauts-de-Seine near Paris, Seine-Maritime in Normandy, and Réunion itself. That's not a lucky raid, that's coordinated intelligence work pointing investigators at multiple locations at once.

French charges center on domestic victims: telecom provider SFR, the French Football Federation, the national employment agency France Travail, and electronics retailer Boulanger. The France Travail breach alone reportedly exposed data on an estimated 43 million people, which puts it in the same conversation as some of the largest breaches on record anywhere.

The ShinyHunters name carries a longer resume than just the French cases, though. It's linked to breaches at Salesforce, PowerSchool, and the Snowflake-connected attacks that hit Santander, Ticketmaster, AT&T, Advance Auto Parts, Neiman Marcus, and Cylance. Grunenwald's read on the arrested operators was blunt: "technically sophisticated, it takes proven skill to administer a site like BreachForums in a community built on trust and anonymity." Matching that sophistication took real investigative work.

One detail flips the script on assumptions here. French police initially suspected Russian nationals, a common assumption in this space. Instead, investigators found French nationals in their twenties. Attribution built on demographic habit, rather than evidence, is a bet that doesn't always pay off. The timing cuts against the "enforcement is winning" narrative too: data breach posts on underground forums rose 43% in 2024, meaning this sweep landed while the market was expanding. The arrests mark a significant disruption to the succession chain: founder arrested in 2023, successor leadership dismantled in 2025.

The enforcement pattern across BreachForums, Genesis Market, and LockBit operations

The DOJ doesn't treat these cases as isolated. Its own framing links BreachForums directly to the 2022 RaidForums shutdown and the 2023 Genesis Market takedown, describing a deliberate, sequenced pressure campaign against the stolen data ecosystem as a whole.

Operation Cookie Monster, in April 2023, took down Genesis Market, a site that sold browser fingerprints, cookies, and session data harvested from 1.5 million compromised machines. That operation produced 119 arrests across 17 countries. Operation Cronos, in February 2024, hit LockBit: the NCA, FBI, and Europol seized 34 servers, shut down the group's leak site, and froze 200 cryptocurrency accounts. A follow-up phase unmasked LockBit's alleged administrator, Khoroshev, though he remains in a country that won't extradite him, untouchable despite a $10 million reward from the State Department. State Department. Operation RapTor, in 2025, brought a crackdown led by an international police agency across multiple dark web platforms, resulting in 270 arrests across 10 countries.

When these three are lined up, the pattern repeats almost exactly: multi-agency coordination, infrastructure seizure, unmasking through OSINT and undercover buys, arrest in a jurisdiction willing to cooperate, extradition pressure, and a sentence built to send a message. But that pattern has a ceiling, and Khoroshev sits right on top of it. The same machinery that put Fitzpatrick in prison and got West arrested produces exactly nothing when the target is sitting in a country that won't extradite him. Enforcement against English-language, Western-operated forums has become systematic and repeatable. Operators running from jurisdictions that don't extradite are, for now, mostly watching from the sidelines.

What platform collapse does, and does not do, to data already in circulation

Records don't have a shelf life that matches a marketplace's uptime. Stolen data gets aggregated, repackaged, resold, and reused for years past the breach that produced it, so a market's collapse doesn't touch what's already out there circulating.

BreachForums even managed to breach itself on the way out. On January 9, 2026, a database with information on 323,986 BreachForums user accounts got posted publicly through a site tied to ShinyHunters. The forum built to trade other people's stolen data ended up leaking its own.

The mechanics of the collapse read like a slow-motion collapse rather than a single event. BreachForums v2 went offline in April 2025 after administrators blamed a MyBB zero-day vulnerability, though law enforcement is alleged to have had covert access before that point. By August 2025, ShinyHunters was claiming international law enforcement had compromised the site. Investigators appear to have been inside the platform well before the public takedown ever happened.

After the October 2025 disruption, no single successor site managed to consolidate the old userbase. Traffic scattered across PwnForums, Breached.st, and DoxByte, with no single operator consolidating control. KELA recorded a 600% jump in activity on DarkForums between April and June 2025. That's not demand disappearing, that's demand finding a new address.

Some of that traffic never went to a forum. Threat actors increasingly split operations between Tor-based forums, used for reputation-building and high-value deals, and private Telegram channels, used for fast, high-volume data distribution. Enforcement aimed at forum infrastructure doesn't touch the Telegram side of that split. Layered on top of it, a data-as-a-service model has taken hold: stolen data packaged, hosted, and sold on something closer to a subscription, which is more stable and much harder to track than a single forum with a login page.

A BreachForums post is a lead, not proof, for defenders, and DeepStrike's framing is the one worth keeping close. It's not confirmation of a breach, not confirmation of who did it, and not confirmation the forum even still belongs to whoever claims it. Reposted and recycled "leaks" appear on the forum constantly. Treat any forum post as an unverified claim until something backs it up independently.

Reading enforcement signals as an early-warning input for security teams

Enforcement doesn't arrive without warning shots. Administrative churn is one: IntelBroker's departure from BreachForums in early 2025 came before his arrest, a signal thatks. PGP-signed statements about compromised infrastructure are another, like the April 2025 announcement blaming a MyBB zero-day, or the March 2026 statement where ShinyHunters publicly disavowed the successor sites claiming its name. Sudden, unexplained outages round out the list. None of these guarantee an arrest is coming, but they've reliably shown up right before one.

The window right around a takedown is when exposure risk spikes, not drops. Operators under pressure tend to dump inventory fast, leak rival databases (the January 2026 user data release fits this pattern), or post data they'd been sitting on, all trying to extract value before the lights go out. That's a short, high-velocity period when previously unseen data can surface all at once.

Succession disputes are also worth watching. On March 26, 2026, ShinyHunters issued a PGP-signed statement calling every current BreachForums site fraudulent. Pwnforums emerged the following month as a moderator-led alternative, born out of an exit-scam scandal. Tracking who claims legitimacy after a collapse tells you where the next wave of activity is likely to land.

The IntelBroker case doubles as a lesson in method: investigators tied a persona to a real identity using email metadata, university records, and a photo of an ID card, the same OSINT discipline that threat intelligence teams use to track personas across forums. But prosecution remains rare, not routine. Most operators still work from jurisdictions with no extradition treaty covering this kind of crime, and reading enforcement signals well should sharpen response timelines, not create the false sense that a takedown makes the risk go away.

The practical move is to treat any visible enforcement activity as a trigger. Ramp up credential monitoring, run dark web scans, and check whether organizational data has turned up in any newly surfaced dataset. Disruption raises short-term exposure velocity, and the data proves it: a market getting seized doesn't mean the records inside it went anywhere.

Sources

  1. Data after the breach: Economics of the dark web | TechTarget
  2. Five Hackers Behind Notorious Data Selling Platform BreachForums Arrested
  3. BreachForums Explained: From Launch to Fragmentation
  4. BreachForums hacking forum operators reportedly arrested in France
  5. BreachForums broken up? French police arrest five members of notorious cybercrime site
  6. securityaffairs.com
  7. The Rise and Fall of BreachForums: A Cybercrime Empire Collapses - ThreatMon
  8. BreachForums - Wikipedia

More in dark web markets and forums