BreachForums is an English-language cybercrime forum that functions as a marketplace and community for trading stolen data, compromised access, and cybercriminal services and tools. It became widely known as a successor venue for data-breach trading and has been closely associated with prominent financially motivated cybercrime actors, including figures linked to ShinyHunters and other forum administrators and moderators. Public reporting has tied the forum’s administration at different times to aliases including Pompompurin, ShinyHunters, Hollow, Noct, Depressed, and IntelBroker. The forum has repeatedly appeared in connection with the public sale, advertisement, or discussion of hacked corporate and institutional databases. It has also served as a platform where threat actors claim responsibility for intrusions, publish extortion demands, and threaten disclosure of allegedly stolen information. Reported incidents linked to claims posted on the forum include breaches affecting government entities and international organizations, including the European Space Agency and France’s Ministry of the Interior. Law-enforcement actions have significantly disrupted the forum but have not prevented its reappearance. Conor Brian Fitzpatrick, known as Pompompurin, was arrested in 2023 as the alleged administrator. In 2025, French authorities arrested five high-ranking members or administrators associated with the forum, including individuals identified under the aliases ShinyHunters and IntelBroker. Around the same period, the forum was reportedly relaunched, and an administrator publicly framed at least one government intrusion as retaliation for those arrests. BreachForums is best understood as a cybercriminal platform and loose actor ecosystem rather than a single tightly controlled intrusion set. Its observed role centers on monetization and dissemination of stolen data, support for extortion activity, and facilitation of post-compromise criminal trade. High-confidence reporting supports its use for advertising breached datasets, enabling exfiltration-driven monetization, and supporting financially motivated cybercrime operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BreachForums is a well-known hacking forum where threat actors often claim responsibility for breaches and leak stolen data. In this case, a threat actor on BreachForums claimed to have breached European Space Agency servers.
BreachForums is known for facilitating and conducting cyberattacks, data breaches, and extortion campaigns. In this incident, they claimed responsibility for breaching France's Ministry of the Interior, allegedly stealing data on over 16 million people and threatening to release it unless the government negotiates.
BreachForums is an underground forum used by cybercriminals, including groups like ShinyHunters, to trade and sell stolen data.
BreachForums is an online cybercriminal marketplace for selling stolen data and hacking tools, operated by several high-profile individuals.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.