The notorious crime forum BreachForums has suffered a new and potentially fatal blow to its reputation, after it was revealed that a database of thousands of criminal users was stolen months ago.

News of the breach became public on January 9th, when a zip file containing a MySQL database , with 323,986 BreachForums users, appeared on shinyhunte[.]rs, a domain reportedly unrelated to the notorious extortion group of the same name.
According to Have I Been Pwned, the data breach occurred last August, two months before the police took down BreachForums. The police operation came after threats by Scattered Lapsus$ Hunters that they would use the extortion site to publish a billion files stolen from customers Salesforce. That matches the August 11 date on the database that was leaked last week.
See also: Protecting digital assets: Crypto security
That day, its administrators reportedly announced that the site was being shut down over fears it had been hacked by authorities . Have I Been Pwned reported that the stolen data also included hashed passwords, private messages , and forum posts . However, according to security intelligence firm Resecurity , the January leak contains two new items: a password-protected PGP private key file and a grandiose, bizarre 4,400-word manifesto titled “ Doomsday ” by a writer using the name “James,” who claims to be behind the leak.

The PGP key, leaked a day later on January 10, was likely used to sign messages from BreachForums administrators, Resecurity reported.
BreachForums: One collapse after another
This leak is just the latest in a series of problems, arrests and takedowns affecting what was once one of the largest English-language crime forums. The successor to RaidForums, seized by US authorities in 2022, billed itself as a place to discuss topics including data breaches, illegal sexual content, ransomware and hacking tools.
See also: HawkSec: Discord data is for sale
In 2023, the site's alleged founder and administrator , Conor Brian Fitzpatrick , was arrested and the clearnet domains were seized three months later. Fitzpatrick was later sentenced to three years in prison by a US court.
In 2024, a replacement administrator, Baphomet, was also reportedly arrested , and in 2025, five more people accused of being connected to the site were arrested. Finally, last October, the blackmail site on the dark web came crashing down. The forum later revived under a new domain.
The immediate question is whether the leaked database will be useful to police, assuming they don't already have access to it. It contains email addresses and IP data that will likely point to proxies or anonymization services. An analysis has shown that many of the IP addresses are simply loopbacks. However, the most popular email service used to register on BreachForums is Gmail, which can provide a forensic link to anyone who was careless and didn't cover their tracks.

A data integrity issue
Experts had mixed reactions to the news of the database leak. “The breach significantly undermines trust in the platform itself, which is critical for any cybercrime forum,” said Michael Jepson, director of penetration testing at consulting firm CybaVerse. “The report damages trust in BreachForums as a safe environment. As a result, more sophisticated cybercriminals are likely to move from large, well-known forums to smaller, invite-only communities,” he added.
See also: Researchers uncover service providers fueling PBaaS scams
However, Michael Tigges, senior security operations analyst at security firm Huntress, was less optimistic. “While potentially useful to authorities and security professionals investigating hostile activity, the database is ultimately of limited forensic use. While the leak may be legitimate, its integrity is questionable if it came from another cybercrime group,” he noted.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The biggest risk was that data leaks could be a cover for the distribution of disinformation. “Data leaks like these can be used to connect clusters of activity, but the reliability of the information needs to be carefully examined,” Tigges said.
