BreachForums went offline after the FBI reportedly arrested its alleged founder and administrator, known as “pompompurin,” on March 15, 2023, and charged him with conspiracy to commit access device fraud. All forum mirrors were inaccessible by March 20. In a March 21 update, replacement administrator Baphomet announced the forum’s closure over suspicions that law enforcement had compromised it; that suspected compromise was not independently confirmed. The prominent English-language cybercriminal forum had emerged after the takedown of RaidForums, which Europol announced in April 2022.
Baphomet proposed creating another Telegram group and working with competing forum administrators to establish a replacement community. ReliaQuest assessed that the shutdown would displace rather than eliminate cybercriminal activity, with users potentially moving to Russian-language forums and other channels to distribute stolen data. For defenders, the disruption does not establish that previously stolen information is contained: monitoring for exposed credentials and organizational data should extend beyond BreachForums to replacement communities and alternative distribution channels.

See the reporting duties and controls this puts on the clock.
10 events from the most recent confirmed update back to the earliest known activity.
BreachForums was inaccessible through all its mirrors as of March 20. The report linked the downtime to pompompurin’s arrest as a likely explanation but did not confirm an FBI seizure of the infrastructure.
Security researchers began reporting that the FBI had arrested the suspected founder and administrator of BreachForums.
The FBI reportedly arrested a 21-year-old New York man identified in an agent’s affidavit as pompompurin, BreachForums’ owner and administrator. The criminal complaint charged him with one count of conspiracy to commit access device fraud.
Pompompurin launched BreachForums to replicate RaidForums’ functionality and appearance. The new forum attracted many former RaidForums users.
Authorities arrested RaidForums’ founder and chief administrator. The arrest preceded the seizure of the forum’s infrastructure.
Pompompurin exploited a vulnerability in an FBI-owned email server to send thousands of fake emails concerning a cybercrime investigation.
RaidForums launched as a community that supported trading in account credentials, databases, and network access. It later became the predecessor to BreachForums.
Replacement administrator Baphomet announced that BreachForums was being shut down because they believed law enforcement had compromised it; the report did not independently confirm that claim. Baphomet also proposed another Telegram group and collaboration with competing forum administrators to build a replacement community.
Before the shutdown announcement, administrators said on Russian-language forums that they were migrating infrastructure and intended to restore BreachForums. One administrator attributed the downtime to precautions against internet scanning that could expose the actual hosts.
RaidForums’ infrastructure was seized through Operation TOURNIQUET following its founder’s arrest. Europol coordinated support for investigations involving the United States, United Kingdom, Sweden, Portugal, and Romania.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.