Pompompurin is the online alias of Conor Brian Fitzpatrick, a U.S.-based cybercriminal best known as the alleged administrator of BreachForums and the owner of Breached.co. The actor is associated with English-language cybercrime communities centered on the trafficking of stolen data and has been publicly linked to multiple intrusions involving theft and publication or sale of breached information. Reported victims and datasets tied to this alias include consumer and corporate data from organizations such as Robinhood, QuestionPro, Mangatoon, and ShitExpress. Operationally, Pompompurin has been associated with exploiting web application weaknesses, including SQL injection, to obtain unauthorized access and exfiltrate databases. The actor has then distributed or monetized stolen information through criminal forums rather than pursuing conventional ransomware encryption. Public reporting also links this alias to abuse of an FBI email system misconfiguration in 2021 to send fraudulent cyberattack warning messages, demonstrating spoofing and post-compromise misuse of trusted infrastructure. Pompompurin is closely tied to the broader breach-forum ecosystem and has been mentioned alongside other prominent forum-linked actors. Available reporting supports a primarily financially motivated profile focused on stolen-data acquisition, forum administration, and cybercrime enablement. Although the actor has been discussed in the context of abusive online communities, the strongest corroborated activity centers on data theft, unauthorized access, and criminal marketplace operations rather than ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Administrator of BreachForums tied to sale of hacked corporate databases, fake FBI email blasts, and infiltration of the FBI InfraGard program.
Exploited a SQL injection vulnerability in ShitExpress, dumped the customer database, and shared sample stolen data on a hacking forum. The content also describes prior data theft and sale activity involving multiple companies.
Named threat actor potentially impacted by the Doxbin user database leak (credentials, MFA codes, stealer logs, chat history), which could expose operational details and enable follow-on targeting or law-enforcement attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.