Leak Site BreachForums Springs Back to Life Weeks After FBI Takedown (2024)

Leak Site BreachForums Springs Back to Life Weeks After FBI Takedown (1)

Source: ozrimoz via Shutterstock

Barely two weeks after the FBI and the US Department of Justice shut down BreachForums, the notorious data leak site appears to be back online, hawking personal and payment card data purportedly belonging to more than 500 million Live Nation/Ticketmaster customers.

Truth or Law Enforcement Bluff?

Researchers at Malwarebytes this week spotted "ShinyHunters," an administrator of the BreachForums site, posting the alleged Ticketmaster data for sale for $500,000 on one of its original domains. But they are unsure if the apparent revival of the operation is legit, or simply a lure by law enforcement to trap bad actors looking to once again buy stolen data from the forum.

"We dare conclude that this dataset's goal is to generate some attention and act as a lure to let old forum users know that BreachForums is alive and kicking," Malwarebytes researcher Pieter Arntz wrote in a blog post this week. "But who is running the show, is the question that we hope to answer soon."

BreachForums is a hacking forum and marketplace for cybercriminals to buy and sell all kinds of stolen data, including credit card data, bank account information, Social Security numbers, bank account information, hacking tools, account credentials, and personally identifying information. The forum, which boasted of having some 340,000 members earlier this year, became the go-to market for illicit data in mid-2022 following the FBI's disruption of RaidForums, another data leak site, which at the time was the biggest of its kind.

Earlier this month, the FBI and the DOJ seized control of BreachForums domains and Telegram channels belonging to two of its main admins, "Baphomet" and "ShinyHunters." The move followed the arrest in March 2023 of Conor Fitzpatrick, aka "pompompurin," the alleged creator of BreachForums. Though neither the FBI nor the DoJ have provided many details around the BreachForum domain takedown, ShinyHunters has claimed that the FBI has arrested Baphomet as well, Flashpoint said in a report this week.

"An Avatar and a Handle are Easily Copied"

According to Malwarebytes, the reappearance of BreachForums just two weeks after law enforcement seized its domains is suspicious for several reasons. For one thing, the same data that ShinyHunters has posted for sale on BreachForums is also for sale from an individual using the handle SpidermanData on another Dark Web site. The dataset itself — allegedly containing data belonging to 560 million customers — seems suspiciously large and therefore likely not what it purports to be. The revived BreachForums site also requires users to register if they want to see the content that is available for sale on it.

"An avatar and a handle are easily copied, and there are a few things that raised our spidey-senses that something is up," Arntz wrote in the Malwarebytes blog post.

In separate comments to Dark Reading, Arntz says this wouldn't be the first time that law enforcement has used similar lures to try and trap cybercriminals. He points to a 2018 sting operation that resulted in the takedown of Dark Web drug site Hansa Market and the takedown of an encrypted device company called ANOM as two examples.

Consistent With Previous Takedowns

However, if the BreachForums revival is indeed genuine, that too would be consistent with previous trends, Arntz notes. "Criminals like to keep doing what they know works," he says. "So dealing with the same administrators and especially the trusted escrow service beats having to find a new one that they don't know yet. So existing users will be likely to return."

Ian Gray, VP of intelligence at Flashpoint, says evidence suggests BreachForums is operational. Dark Web chatter points to the main BreachForums domain being transferred elsewhere after the law enforcement seizure. "Shortly after the seizure, the site included a link to 'Jacuzzi 2.0,' a Telegram chat for BreachForums," Gray says. "Today, the landing page for the site includes a link to N.W.A.'s "F*** Tha Police," he says, referring to American hiphop group N.W.A.s protest song.

ShinyHunters, the administrator of the shuttered BreachForums, claims to have regained control of the domain seized from the FBI, he notes.

More chatter suggests that another BreachForums member "USDoD" will launch a similar leak site on July 4 that is not associated with the current iteration of BreachForums, Gray notes. The new forum's domain is planned to be either breachnation.io or databreached.io, he says.

Unfortunately, the BreachForums of the world are poised to metastasize, says Patrick Harr, CEO of SlashNext, an email security vendor. "They are never fully eradicated despite treatment or in this case a takedown," he says. "The group, like cancer, still lurks in the background, waiting to re-emerge, sometimes in different name or form but with the same purpose."

Leak Site BreachForums Springs Back to Life Weeks After FBI Takedown (2024)

FAQs

Leak Site BreachForums Springs Back to Life Weeks After FBI Takedown? ›

Barely two weeks after the FBI and the US Department of Justice shut down BreachForums, the notorious data leak site appears to be back online, hawking personal and payment card data purportedly belonging to more than 500 million Live Nation/Ticketmaster customers.

What replaced BreachForums? ›

On May 16, 2024, threat actor USDoD announced on X their intent to launch a new, open-source data breach forum named Breach Nation. USDoD claimed that Breach Nation will use two separate domains, breachnation[.] io and databreached[.] io, with a planned launch date of July 4, 2024.

Is BreachForums safe? ›

These resources are sourced in illegal markets hosted on clear web forums, Tor hidden services, Telegram channels and through private chats. BreachForums is one such cybercrime forum that allows threat actors to sell these tools, services, stolen databases, access credentials, personal data, financial data and more.

Is breachforum seized? ›

BreachForums—probably the largest dark web marketplace for stolen data to be leaked and sold—has been seized by law enforcement.

Is BreachForums closed? ›

BreachForums, sometimes referred to as Breached, is an English-language black hat–hacking crime forum. The website acted as an alternative and successor to RaidForums following its shutdown and seizure in 2022.

Where are ShinyHunters from? ›

ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide range of targets, including businesses, organizations, and government agencies.

Has FBI ever been hacked? ›

On November 13, 2021, a hacker named Conor Brian Fitzpatrick, going by his alias "Pompompurin", compromised the FBI's external email system, sending thousands of messages warning of a cyberattack by cybersecurity CEO Vinny Troia who was falsely suggested to have been identified as part of The Dark Overlord hacking ...

Is BreachForums under the control of the FBI? ›

Earlier this month, the FBI and the DOJ seized control of BreachForums domains and Telegram channels belonging to two of its main admins, "Baphomet" and "ShinyHunters." The move followed the arrest in March 2023 of Conor Fitzpatrick, aka "pompompurin," the alleged creator of BreachForums.

What is the use of BreachForums? ›

History of BreachForums

Threat actors would upload data relating to companies which was usually stolen through hacking activity but also though scraping and unintentional open access. The site was also used to sell access to others, with initial access brokers selling access to corporations for large volumes of money.

What was leaked from Ticketmaster? ›

Summary. Over 560 million Ticketmaster users' personal and payment details were exposed on May 28, 2024. ShinyHunters stole 1.3TB of data, selling it on Breach Forums for $500,000. A hijacked Snowflake cloud account led to the breach, also affecting Santander, and highlighting third-party security risks.

What happens to money that has been seized? ›

Property seized from crime is sold at public auction by Asset Confiscation Operations and funds generated from the sale are placed into a consolidated fund.

Under what conditions is a person considered to be seized? ›

Two elements must be present to constitute a seizure of a person: First, there must be a show of authority by the police officer. The presence of handcuffs or weapons, the use of forceful language, and physical contact are each strong indicators of authority.

What is a seized package? ›

A seizure of a shipping package may be due to any of the following reasons: The package contains illegally obtained items and profits; The package includes evidence of an offense; The package includes items that are processed unlawfully or contraband; The package contains properties used in criminal activity.

Has Ticketmaster been hacked? ›

The personal details of 560 million Ticketmaster customers worldwide were stolen in the hack - with cyber criminals then attempting to sell that information online.

Is BreachForums.st safe? ›

FBI Seizes BreachForums Again, Urges Users to Report Criminal Activity. Law enforcement agencies have officially seized control of the notorious BreachForums platform, an online bazaar known for peddling stolen data, for the second time within a year. The website ("breachforums[.]

What happens when an item is seized? ›

You should tell the seizing officer about any property you are unable to take so they can record it. Smaller items will be placed in a sealed bag. You'll not be allowed to take any seized things or items of property that are being held as evidence of any criminal proceedings.

What does it mean when a product is seized? ›

Seizure of goods means withholding the goods temporarily while waiting for the results of legal proceedings.

What does it mean when a weapon is seized? ›

Law enforcement officers may take and remove (seize) firearms from any individual whom the law enforcement officer believes to be dangerous without getting permission from a judge in a warrant.

References

Top Articles
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 5623

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.