onlinesyscfg.research
utc
syscfg://research
home/research/opsec-hall-of-shame
PublishedThreat History

OPSEC Hall of Shame: The Mistakes That Ended Careers

2026-06-20-17 min read
#opsec#arrested#mistakes#sabu#pompompurin#intelbroker#cybercrime

Every arrest has a story. Almost every story has the same shape: years of careful work, consistent tradecraft, maintained separation between identities - and then one moment. One forum post. One unmasked connection. One email address used across two contexts. The pattern repeats so reliably that it functions less like a series of individual mistakes and more like a structural feature of how people get caught.

This is a catalogue of documented operational security failures - cases where the mistake is on record, verified by court documents, journalist investigation, or forensic disclosure. No speculation. These are the actual mistakes that made the arrests possible.

◈ interactive artifact
OPSEC Case Files - Evidence Board
Click-through case files for each documented failure. Sabu, DPR, Alpha02, Pompompurin, IntelBroker, GOllumfun - the mistake, the context, and what followed.

//Hector Monsegur (Sabu) - LulzSec / Anonymous

Sabu was the most important figure in Anonymous and LulzSec during their most active period: the de facto leader of the group that hacked HBGary Federal, the CIA, Fox News, and Sony, and the coordinator of the broader AntiSec operation with Anonymous. He was cautious. He ran everything through Tor. He never revealed his real name. He was the kind of operator who understood exactly what opsec required.

In June 2011, at home, with something apparently on his mind, he logged into an IRC channel without routing through Tor first. His real IP address appeared in the connection metadata. One unmasked session. The IP resolved to an apartment in Manhattan's Lower East Side, registered to a 28-year-old named Hector Xavier Monsegur.

The FBI didn't arrest him immediately. They surveilled him, confirmed the identity, and then knocked on his door - confronting him with evidence they said was enough for a 124-year sentence. Monsegur flipped. For the next ten months, while still publicly operating as Sabu, he fed the FBI information on every member of LulzSec and associated Anonymous cells. The mass arrests of March 2012 - which took down LulzSec's entire core - were the result.

[IOC]
Mistake: Single unmasked IRC session - real IP in connection metadata Consequence: Identity confirmed, apartment located, arrest FBI leverage: 124-year sentence exposure Outcome: 10 months as informant, mass arrests of LulzSec core Sentence: Time served + 1 year, 2014 (credited for cooperation)

//Ross Ulbricht (Dread Pirate Roberts) - Silk Road

Covered separately in depth elsewhere on this site - but the OPSEC failure belongs in any catalogue. In March 2012, while building the hidden service infrastructure for Silk Road, Ulbricht asked a PHP-cURL programming question on Stack Overflow under his real name and Gmail address: [email protected]. He edited the post within a minute, changing the username to "frosty." The edit was too slow. Stack Overflow preserves history.

Months later, when FBI investigators examined the Silk Road servers, the admin handle was "frosty." The same handle he had used on Stack Overflow after hastily changing his real name. The convergence was documented in the indictment.

The compounding factor: he kept a detailed personal diary on the server. Not encrypted. Accessible to anyone with administrative access. The diary discussed hiring a hitman, the daily operations of the marketplace, and his personal ideology. When the server was imaged by law enforcement, they read everything.

//Alexandre Cazes (Alpha02) - AlphaBay

The founder and primary administrator of AlphaBay - for years the largest dark web marketplace in existence - used a personal Hotmail account as the sender address for AlphaBay's automated user emails: [email protected].

The address was registered to his legal name. The "91" matched his birth year. Microsoft's response to the FBI subpoena connected the email to a Canadian named Alexandre Cazes and to a registered Thai software company. The rest of the investigation - property records, financial flows, immigration records - was straightforward from there.

He also kept unencrypted text files of all administrative passwords on his laptop. When Thai police arrested him at his home in Bangkok while he was mid-session on the admin panel, they found a full asset spreadsheet listing every property, vehicle, and cryptocurrency holding. He had effectively documented his own case for the prosecution.

//Conor Fitzpatrick (Pompompurin) - BreachForums

BreachForums was the successor to RaidForums after its seizure in 2022 - a major English-language cybercrime forum that hosted leaked database sales, access credential marketplaces, and tool discussion. Its administrator, operating as "pompompurin," was one of the most recognised handles in the breach community.

In a public discussion thread, pompompurin mentioned that a particular data breach being discussed did not include an email address that matched his personal account. He typed: "this email seems to have the same case as mine" - and then, apparently demonstrating what he meant, typed what he described as a similar format:[email protected]. He added, almost immediately, that he didn't want to share his "actual email for obvious reasons."

The email he had just typed was his actual email. The FBI confirmed this by cross-referencing it against login logs from a separate forum - Raid Forums - where nine IP addresses used by pompompurin were connected to mobile devices registered to a Verizon number belonging to Conor Brian Fitzpatrick of Peekskill, New York.

He was 21 when arrested. The FBI agent who knocked on his door reported that Fitzpatrick identified himself immediately and admitted he was pompompurin in the first conversation.

[IOC]
Mistake: Typed his own email address while ostensibly demonstrating he wasn't sharing it Forum: BreachForums admin thread, March 2023 Supporting evidence: 9 IPs tied to his Verizon number across Raid Forums login logs Arrest location: Peekskill, New York Identified himself: Within minutes of FBI contact

//Arion Kurtaj (WhiteDoxbin) - Lapsus$

Arion Kurtaj was 16 when he purchased Doxbin - the internet's most notorious personal information repository, active since 2011 - apparently because he could. He ran it for a period, then in January 2022 grew frustrated with the community and leaked the entire Doxbin user database to Telegram. This included credentials, posts, and the personal information that members had contributed to the site.

The community's response was immediate: they posted a comprehensive dox of WhiteDoxbin (Kurtaj's handle) on the very site he had just leaked, including his real name, home address in Oxford, UK, photos, and videos filmed outside his home. The information reached law enforcement. UK police began surveillance.

By the time Kurtaj was arrested, he was deeply embedded in Lapsus$ - the group that had compromised Nvidia, Samsung, Microsoft, Ubisoft, and Okta. He had also hacked Uber and leaked Grand Theft Auto VI footage from within Rockstar Games' internal systems - reportedly from inside a Travelodge hotel while on bail for previous offences, using a Fire Stick, a phone, and a hotel TV.

He was found not criminally responsible due to severe autism and sentenced to an indefinite hospital order. His co-defendant, who was 17 at the time of the offences, was convicted of multiple counts of computer misuse.

//The Pattern

Across every case, the mechanics of the failure are different but the structure is identical:

  • A long period of careful, consistent behaviour
  • A single anomalous event - a moment of distraction, impatience, or carelessness
  • A mistake that, in isolation, might not be fatal
  • Existing investigative threads that provide the context to make the mistake fatal

Sabu's unmasked session would have meant nothing if law enforcement hadn't already been interested in Anonymous. Ulbricht's Stack Overflow post would have meant nothing without Gary Alford's separate investigation into early Silk Road forum activity. Pompompurin's email slip would have meant nothing without the pre-existing IP correlation data from Raid Forums.

Operational security doesn't need to fail completely to fail fatally. It needs to fail at the exact moment when the failure is meaningful - when the adversary is already watching, already interested, already building a case. The mistake that ends everything is rarely the first mistake. It's the last one that gets noticed.

The practical implication: there is no opsec regime that survives indefinite exposure to a motivated, resourced investigative team. The goal of opsec is to raise the cost of attribution high enough that it isn't worth pursuing. When the cost ceiling is "federal prison," investigators are quite motivated.

[TECHNICAL NOTE]
Law enforcement has documented a recurring theme in post-arrest interviews: suspects describe their opsec as "better than anyone else's" or "too careful to get caught." The belief that personal opsec is exceptional is itself a risk factor - it leads to the kind of relaxed vigilance that produces unmasked IRC sessions and personal email addresses in admin notification systems. The most dangerous moment is when you believe you've become too careful to make mistakes.