On March 17, 2022, the FBI seized RaidForums - the dominant English-language cybercrime forum for the previous five years. Its founder, Diogo Santos Coelho ("Omnipotent"), was arrested in the UK. The seizure was widely reported as a major law enforcement win. By the end of that same week, a new forum had registered its domain and begun recruiting former RaidForums members. Within three months, BreachForums had more active users than RaidForums ever had.
This is the story of how data breach trading works, why forums like BreachForums keep coming back, and what the data sold there actually means in practice.
The BreachForums Timeline
BreachForums was founded in early 2022 by a user known as "Pompompurin." The name was a reference to a Sanrio character - an ironic choice for someone who would go on to become one of the most prolific data brokers in cybercrime history. Pompompurin's real identity, Conor Brian Fitzpatrick, was 20 years old when he founded the forum.
The forum rapidly established itself as the premier destination for English-language data trading. Unlike its predecessors, BreachForums explicitly positioned itself around leaked databases rather than carding or malware - a deliberate niche that avoided some law enforcement triggers while building a dedicated membership. Within a year, it hosted hundreds of millions of stolen records spanning corporate breaches, government data, and combolists assembled from years of prior incidents.
Fitzpatrick was arrested in March 2023 after the FBI traced him through his IP address - he had logged into the forum without a VPN on a specific occasion that investigators were watching. He pleaded guilty to operating the forum and was sentenced in January 2024. By that point, a new operator had already taken over.
ShinyHunters, a threat actor group responsible for dozens of major corporate breaches, took over forum operations in 2023. The second iteration of BreachForums ran until May 2024, when the FBI seized it again - this time also taking down the associated Telegram channels. The seizure page announced that the site had been running under FBI observation for a period before the takedown.
A third iteration appeared within weeks. By mid-2024, BreachForums had become something like a brand rather than a single platform - the domain and forum software kept getting seized, but the community, the threat actors, and the data market simply reconstituted on the next iteration.
The Economy of a Breach Forum
BreachForums operates as a tiered marketplace. At the bottom end, members share free data - often scraped datasets, old breaches, or partial dumps - to build reputation and demonstrate access. At the top, verified vendors sell fresh corporate breaches before they become public knowledge. The value of a breach degrades rapidly once it becomes widely known, so timing is critical.
The forum uses a credits system alongside direct sales. Credits can be earned by contributing data or purchased, and they gate access to some downloads. This creates an incentive structure where frequent contributors gain more access, which in turn helps them contribute more. Reputation is everything - established names can command premium prices while new accounts get minimal trust.
Categories and What They Mean
The databases section contains the raw material: email addresses, passwords (hashed or plain), names, phone numbers, physical addresses, Social Security numbers. The most valuable databases are fresh - breached within weeks - and include credentials that haven't yet been incorporated into existing combolists. Old databases retain value because they enable correlation: matching an email from a 2018 breach against a 2024 breach to build a more complete profile.
Combolists are pre-processed combinations of email addresses and passwords, formatted specifically for credential stuffing tools like OpenBullet. The key metric is the hit rate - the percentage of credentials that still work against a target service. A combolist with a 30% hit rate against a major retailer is worth substantially more than one with a 5% hit rate, even if the latter is larger. Stealer logs, captured by information-stealing malware from infected computers, are particularly valuable because they include session cookies and autofill data in addition to passwords.
The exploits section operates differently. Zero-day vulnerabilities - flaws unknown to the vendor - can command tens or hundreds of thousands of dollars. BreachForums is not the primary market for top-tier zero-days (specialized brokers and intelligence agencies pay more) but it does see the lower end of the market: n-day exploits for recently patched vulnerabilities, proof-of-concept code, and occasionally legitimate zero-days from sellers who couldn't find a premium buyer elsewhere.
Malware source code and builder sales represent the infrastructure layer. An information stealer sold on BreachForums generates more data to sell on BreachForums. The ecosystem is vertically integrated in ways that law enforcement finds genuinely difficult to disrupt from any single point.
Key Threat Actors
IntelBroker is one of the most consistent presences in the BreachForums ecosystem. Active since at least 2022, the actor posts high-profile government and corporate breaches - sometimes for sale, sometimes for free as reputation demonstrations. Attributed breaches include data from Europol, DC Health Link, T-Mobile vendor systems, AMD, and multiple US federal agencies. IntelBroker claims to operate from Eastern Europe and has shown consistent OPSEC discipline, with no confirmed identity as of mid-2025.
ShinyHunters predate BreachForums - they were responsible for major breaches at Tokopedia, Mashable, Wattpad, and others during 2020-2021, selling data through earlier forums. Their takeover of BreachForums gave them both a revenue stream and a platform for continued operations. French authorities arrested several members in 2024, but the forum continued operating, suggesting the group has more members than those charged.
USDoD, the actor behind the National Public Data breach disclosed in 2024 - a database containing Social Security numbers for approximately 2.7 billion records - exemplifies a pattern increasingly common on BreachForums: actors who aggregate and reformat existing leaked data rather than conducting fresh intrusions. The NPD breach drew significant media attention not because it was technically sophisticated but because of its scale and the sensitivity of the data.
The National Public Data Breach (2024)
The National Public Data breach deserves a separate note because it illustrates how breach data accumulates and compounds over time. The dataset sold by USDoD on BreachForums in April 2024 was not a single intrusion - it was an aggregation of records from multiple prior breaches, data broker purchases, and public records, combined into a unified format and sold as a comprehensive US identity dataset.
The 2.7 billion record count is misleading in the way that most breach counts are misleading: many records are duplicates, many are incomplete, and many are outdated. But the dataset did contain accurate Social Security numbers matched to names and addresses for a substantial fraction of the US population, drawn from various prior incidents. It was the data broker model - collecting as much as possible and reselling in aggregated form - applied to stolen data.
National Public Data filed for bankruptcy in October 2024 after the breach became public and multiple class action lawsuits were filed. The company had been aggregating and selling personal data for background checks and people-search services, and had apparently been breached long before the data appeared on BreachForums.
Why Takedowns Don't Work
The recurring seizures of BreachForums illustrate a fundamental problem with forum-focused enforcement. The data is distributed. Once a breach is posted, it proliferates across Telegram channels, Discord servers, private mirrors, and individual copies. Seizing the forum removes the marketplace but not the goods.
The community is persistent. Forum members move to the next platform, bring their reputation with them, and reconstitute. The BreachForums brand itself has become a trust signal - new iterations attract the old community precisely because they inherit the name.
The operators are distributed. ShinyHunters demonstrated that a forum can operate without a single identifiable administrator. After Pompompurin's arrest, the group structure that took over was geographically dispersed and operationally segmented.
Downstream Impact
Breach forums exist at the top of a supply chain. The data sold on BreachForums is used to run credential stuffing campaigns against banks and retailers, to build spear-phishing target lists, to enable SIM swap fraud, to file fraudulent tax returns and insurance claims, and to conduct account takeover at scale. A single database breach cycles through the ecosystem for years: it appears on BreachForums first as a premium sale, then as a free release, then gets incorporated into combolists, then gets used in credential stuffing, and finally gets absorbed into identity fraud datasets.
The individuals whose data appears in these databases have essentially no recourse. Breach notification laws require disclosure but don't prevent the data from being used. Credit monitoring services detect identity theft after it occurs. The data, once released, circulates indefinitely - the 2018 Collection #1 dump of 773 million records is still actively used in credential stuffing campaigns in 2026.
The demo above simulates the BreachForums interface as it appeared in 2024 - the forum layout, category structure, sample thread types, and the kind of content posted in each section. Toggle analyst mode to see context on what each category represents operationally.