OPSEC Hall of Shame: The Mistakes That Ended Careers
Every arrest has a story. Almost every story has the same shape: years of careful work, consistent tradecraft, maintained separation between identities - and then one moment. One forum post. One unmasked connection. One email address used across two contexts. The pattern repeats so reliably that it functions less like a series of individual mistakes and more like a structural feature of how people get caught.
This is a catalogue of documented operational security failures - cases where the mistake is on record, verified by court documents, journalist investigation, or forensic disclosure. No speculation. These are the actual mistakes that made the arrests possible.
//Hector Monsegur (Sabu) - LulzSec / Anonymous
Sabu was the most important figure in Anonymous and LulzSec during their most active period: the de facto leader of the group that hacked HBGary Federal, the CIA, Fox News, and Sony, and the coordinator of the broader AntiSec operation with Anonymous. He was cautious. He ran everything through Tor. He never revealed his real name. He was the kind of operator who understood exactly what opsec required.
In June 2011, at home, with something apparently on his mind, he logged into an IRC channel without routing through Tor first. His real IP address appeared in the connection metadata. One unmasked session. The IP resolved to an apartment in Manhattan's Lower East Side, registered to a 28-year-old named Hector Xavier Monsegur.
The FBI didn't arrest him immediately. They surveilled him, confirmed the identity, and then knocked on his door - confronting him with evidence they said was enough for a 124-year sentence. Monsegur flipped. For the next ten months, while still publicly operating as Sabu, he fed the FBI information on every member of LulzSec and associated Anonymous cells. The mass arrests of March 2012 - which took down LulzSec's entire core - were the result.
//Ross Ulbricht (Dread Pirate Roberts) - Silk Road
Covered separately in depth elsewhere on this site - but the OPSEC failure belongs in any catalogue. In March 2012, while building the hidden service infrastructure for Silk Road, Ulbricht asked a PHP-cURL programming question on Stack Overflow under his real name and Gmail address: [email protected]. He edited the post within a minute, changing the username to "frosty." The edit was too slow. Stack Overflow preserves history.
Months later, when FBI investigators examined the Silk Road servers, the admin handle was "frosty." The same handle he had used on Stack Overflow after hastily changing his real name. The convergence was documented in the indictment.
The compounding factor: he kept a detailed personal diary on the server. Not encrypted. Accessible to anyone with administrative access. The diary discussed hiring a hitman, the daily operations of the marketplace, and his personal ideology. When the server was imaged by law enforcement, they read everything.
//Alexandre Cazes (Alpha02) - AlphaBay
The founder and primary administrator of AlphaBay - for years the largest dark web marketplace in existence - used a personal Hotmail account as the sender address for AlphaBay's automated user emails: [email protected].
The address was registered to his legal name. The "91" matched his birth year. Microsoft's response to the FBI subpoena connected the email to a Canadian named Alexandre Cazes and to a registered Thai software company. The rest of the investigation - property records, financial flows, immigration records - was straightforward from there.
He also kept unencrypted text files of all administrative passwords on his laptop. When Thai police arrested him at his home in Bangkok while he was mid-session on the admin panel, they found a full asset spreadsheet listing every property, vehicle, and cryptocurrency holding. He had effectively documented his own case for the prosecution.
//Conor Fitzpatrick (Pompompurin) - BreachForums
BreachForums was the successor to RaidForums after its seizure in 2022 - a major English-language cybercrime forum that hosted leaked database sales, access credential marketplaces, and tool discussion. Its administrator, operating as "pompompurin," was one of the most recognised handles in the breach community.
In a public discussion thread, pompompurin mentioned that a particular data breach being discussed did not include an email address that matched his personal account. He typed: "this email seems to have the same case as mine" - and then, apparently demonstrating what he meant, typed what he described as a similar format:[email protected]. He added, almost immediately, that he didn't want to share his "actual email for obvious reasons."
The email he had just typed was his actual email. The FBI confirmed this by cross-referencing it against login logs from a separate forum - Raid Forums - where nine IP addresses used by pompompurin were connected to mobile devices registered to a Verizon number belonging to Conor Brian Fitzpatrick of Peekskill, New York.
He was 21 when arrested. The FBI agent who knocked on his door reported that Fitzpatrick identified himself immediately and admitted he was pompompurin in the first conversation.
//Arion Kurtaj (WhiteDoxbin) - Lapsus$
Arion Kurtaj was 16 when he purchased Doxbin - the internet's most notorious personal information repository, active since 2011 - apparently because he could. He ran it for a period, then in January 2022 grew frustrated with the community and leaked the entire Doxbin user database to Telegram. This included credentials, posts, and the personal information that members had contributed to the site.
The community's response was immediate: they posted a comprehensive dox of WhiteDoxbin (Kurtaj's handle) on the very site he had just leaked, including his real name, home address in Oxford, UK, photos, and videos filmed outside his home. The information reached law enforcement. UK police began surveillance.
By the time Kurtaj was arrested, he was deeply embedded in Lapsus$ - the group that had compromised Nvidia, Samsung, Microsoft, Ubisoft, and Okta. He had also hacked Uber and leaked Grand Theft Auto VI footage from within Rockstar Games' internal systems - reportedly from inside a Travelodge hotel while on bail for previous offences, using a Fire Stick, a phone, and a hotel TV.
He was found not criminally responsible due to severe autism and sentenced to an indefinite hospital order. His co-defendant, who was 17 at the time of the offences, was convicted of multiple counts of computer misuse.
//The Pattern
Across every case, the mechanics of the failure are different but the structure is identical:
- A long period of careful, consistent behaviour
- A single anomalous event - a moment of distraction, impatience, or carelessness
- A mistake that, in isolation, might not be fatal
- Existing investigative threads that provide the context to make the mistake fatal
Sabu's unmasked session would have meant nothing if law enforcement hadn't already been interested in Anonymous. Ulbricht's Stack Overflow post would have meant nothing without Gary Alford's separate investigation into early Silk Road forum activity. Pompompurin's email slip would have meant nothing without the pre-existing IP correlation data from Raid Forums.
Operational security doesn't need to fail completely to fail fatally. It needs to fail at the exact moment when the failure is meaningful - when the adversary is already watching, already interested, already building a case. The mistake that ends everything is rarely the first mistake. It's the last one that gets noticed.
The practical implication: there is no opsec regime that survives indefinite exposure to a motivated, resourced investigative team. The goal of opsec is to raise the cost of attribution high enough that it isn't worth pursuing. When the cost ceiling is "federal prison," investigators are quite motivated.