In the world of cybercrime, where anonymity is the rule and trust is a rare commodity, a new and disturbing trend is emerging: hackers are targeting each other. The phenomenon, known as doxxing, refers to the publication of cybercriminals' personal information by other hackers, whether for revenge or for financial or competitive gain.

What was once a weapon of activists and journalists against criminals has now turned into an internal war within the underground forums themselves. The dark web is no longer just a place of collaboration – it is also a field of conflict.
Cybercriminals expose their own
This new form of “doxxing” does not target random users. Instead, it targets key members of organized cybercrime groups: ransomware, infostealer developers, C2 server administrators, and payment intermediaries.
In many cases, the attacks are accompanied by the disclosure of identity information, bank accounts, email addresses, and even photographs. This data is leaked to specialized forums, which often bear ironic names such as “Leaker's Hub” or “Rats Exposure”, acting as “boards of shame” for the cybercriminals themselves.
See also: Doxxing campaign targeted Lumma Stealer operators
A Trend Micro source says it's a new form of "cyberjustice," where communities themselves impose punishments on their members. The reasons? Betrayal, fraud, internal disagreements, or simply competition for dominance in the malware market.
The economy of intimidation
Doxxing is not just an act of revenge; it is also a financial tool of pressure. Rival groups use data leaks to damage the credibility of their competitors and attract their customers.

Some reports indicate that personal information hackers' are accompanied by threats to destroy servers or expose their clients. On some underground forums, users are even paying "bounty fees" for information about the real identities of known hackers.
This “cyber extortion” has created a new kind of parallel information market, where selling hacker data can bring in big profits. The irony is obvious: those who make a living from selling data now become the products themselves.
From Telegram to Darknet: The new battlefield
Most doxxing operations start in Telegram channels, where groups of hackers exchange information and evidence for their revelations. The data is then transferred to darknet forums, where administrators confirm the validity of the leaks.
See also: WhatsApp warns of screen sharing scams
There, attacks take on an almost ritualistic character: screenshots, code evidence, and even IP logs are published. The most famous cases have led to the disbandment of entire malware groups, after the disclosure of the identities of their members caused panic and a loss of trust among accomplices.
When hackers are afraid to... hack
The consequence of the phenomenon is clear: fear and suspicion are growing even among cybercrime professionals. Groups now require authentication for new members, while communications are being moved to more secure platforms or custom encrypted chat servers.
This situation, according to experts, can also have positive consequences for cybersecurity. The internal “civil war” between groups reduces cooperation and makes it difficult to distribute malware on a large scale.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
However, it also creates new risks: hackers who feel betrayed turn to revenge attacks, targeting not only competitors but also unsuspecting users.

Ethical dilemmas and the future of Doxxing
Doxxing opens up an ethical and legal vacuum. Although the targets are criminals, publishing personal data remains illegal and can put others at risk. Cybersecurity authorities now face a dilemma: is the “self-cleaning” of the dark web a necessary evil or a new form of chaos?
See also: Salt Typhoon breached a European Telecom Network with Snappybee malware
The only thing that is certain is that the phenomenon is not going to stop anytime soon. As hackers continue to compete for money, fame and influence, the dark web will be filled with more faces, more names and more betrayals.
