BreachForums, a cybercrime forum widely used to trade and leak stolen data, faced repeated disruption after administrators said they would shut it down over fears of law-enforcement infiltration. The closure concerns emerged after pressure on the forum's operators, underscoring growing operational risk for one of the most prominent marketplaces tied to breached databases and criminal data sales.
Authorities later escalated that pressure by seizing BreachForums infrastructure in an FBI-led action, and subsequent reporting said French police arrested five alleged administrators linked to the site. The combined actions marked a sustained international crackdown on the forum's operators and supporting infrastructure, disrupting a major venue used by threat actors to advertise, sell, and publish compromised information.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
French police reportedly detained five people described as BreachForums administrators. The arrests represented a further law enforcement action targeting the forum's operators after the earlier seizure.
Law enforcement seized BreachForums and replaced the site with a seizure banner, identifying the FBI and international partners as involved. The action disrupted a major cybercrime forum used to trade and leak stolen data.
Following the founder's arrest, BreachForums administrators said they would shut down the forum, citing fear of law enforcement infiltration. The decision marked the apparent end of the site in its original form.
U.S. authorities arrested BreachForums founder Conor Brian Fitzpatrick, known online as 'Pompompurin,' in New York. The arrest triggered uncertainty about the forum's future and concerns among members about law enforcement access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourceweb.archive.org
Open sourcebleepingcomputer.com
Open sourceweb.archive.org
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.