Crime Dark Web ‘BreachForums’ Operator Charged With Computer Crime

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
(https://www.bloomberg.com/news/arti...chforums-operator-charged-with-computer-crime)
(https://archive.ph/0pUXW)

9551e85cf3b9269e8e181665211a60edcdfd46fe.png

Federal agents have arrested a Peekskill, New York, man they say ran the notorious dark web data-breach site “BreachForums” under the name “pompompurin.”

Conor Brian Fitzpatrick was arrested by a team of investigators at his home around 4:30 p.m. Wednesday, FBI Special Agent John Longmire said in a sworn statement filed in court the next day. Fitzpatrick is charged with a single count of conspiracy to commit access device fraud.

BreachForums hosted the stolen databases of almost 1,000 companies and websites. The databases often includes personal information, such as names, emails and passwords. The information is offered for sale by users of the site and can be used for fraud. Pompompurin’s profile on BreachForums describes him as “Bossman.”

Longmire, a 16-year FBI Agent who said he had led the agents in the arrest, said Fitzpatrick admitted he had used the alias “pompompurin” and was the owner and operator of BreachForums.

Fitzpatrick, who was released on bond, didn’t immediately respond to a request for comment. Benjamin Gold, a lawyer who represented him in his court appearance, declined to comment.

A local newspaper listed Fitzpatrick among the 2021 graduates of Peekskill High School. A local news station posted video of FBI and Homeland Security agents, working with local police, raiding a home in Peekskill on Wednesday and carrying bags of possible evidence from the house. The report didn’t identify Fitzpatrick as the target, but the address is the one listed in online records as the house where he lived with his parents.

Cybersecurity Investigators

Fitzpatrick had been closely scrutinized by cybersecurity investigators for more than a year, and was considered a significant player in the cybercrime ecosystem, according to multiple people familiar with the situation who asked not to be identified because the information isn’t public.

RaidFourms, the spiritual precursor to BreachForums, was sized by the Federal Bureau of Investigation in April 2022.

“Breach Forums is one of, if not the most active, hacker forums out there,” said Allan Liska, a senior intelligence analyst at cybersecurity firm Recorded Future. “They are well-known for leaking sensitive information stolen from major organizations around the world including the Robinhood trading platform and Acer Computers.”

BreachForums was founded after the shutdown of RaidForums, “specifically with the goal of carrying on the work started at Raid,” Liska said. “Pompompurin ran the forum and actively encouraged the hack and leak activities that occurred there.”

In November 2021, Pompompurin claimed responsibility for sending out fake emails that originated from an “fbi.gov” email address. Pompompurin claimed responsibility for the breach in an interview with Brian Krebs.

Details of the charges, filed in federal court in Alexandria, Virginia, have not been made public. A spokeswoman for the US Attorney in Alexandria didn’t return phone and email messages seeking comment.

Fitzpatrick was presented in federal court in White Plains, New York, and released on a $300,000 unsecured bond, signed by his parents. Fitzpatrick is required to avoid any contact with codefendant, coconspirators and witnesses in the case. He’s due to appear in court in Alexandria on March 24.

The case is US v. Fitzpatrick, 23-cr-2171, US District Court, Southern District of New York (Manhattan).
 
I assume some of these people know each other and their doings. Probably someone (or multiple someones) flipped, and now the dominos are all falling.
Exactly my thought, in Zeekills instance however it's a little bit different..

Vastaamo refused, so Ransom Man (Zeekill) shifted to extorting individual patients — sending them targeted emails threatening to publish their therapy notes unless paid a 500-euro ransom.

When Ransom Man (Zeekill) found little success extorting patients directly, they uploaded to the dark web a large compressed file containing all of the stolen Vastaamo patient records.

But as documented by KrebsOnSecurity in November 2022, security experts soon discovered Ransom Man had mistakenly included an entire copy of their home folder, where investigators found many clues pointing to Kivimäki’s involvement.
 
  • Like
Reactions: Cold Root Beer
Never do that. Even if they have irrefutable video of you committing a crime, NEVER admit anything.
These people really need to get familiar with STFU Fridays.




It's not so hard, people. Learn the gahdamn script, learn to shut the fuck up.

All your opsec and l33t h4xx0r skillz are absolutely worthless if you can't follow this simple rule. Lemme say that again: SHUT THE FUCK UP.

 
Last edited:
I'm so mad, trolling the FBI's email server is naughty but a sadistic paedophile predator and serial swatting scum Corey Ray Barnhill is allowed to wreak havoc on anyone that dares to cross him or his psychopathic company.
You just know the only reason the feds went after him was embarrassment from being toyed by a Hello Kitty character who hates paedophiles.

#FreePomp

Also, mind catching the real person who swatted MTG too? She and her family (many children) could have been killed?
Precisely zero people died from the FBI being made fun of.

He graduated high school in 2021 and they’d been watching him for over a year? Is this to make sure he definitely gets adult charges? I don’t understand US law but seems a bit sus.
Wouldn't be the first or last time some glowie was secretly stalking children.
 
There doesn't seem to be any mention of this, but where did his OPSEC give up? How were the FEDs able to find him? All these articles and videos just seem to talk about what he did and what his website was.

Sigh. Any nigger can spoof mail from anywhere else, I used to do this for shits and giggles years ago. Spoofing a send address is not a breach.
I looked into it and it seems like he hijacked some FBI email servers, not just simple spoofing.
https://krebsonsecurity.com/2021/11/hoax-email-blast-abused-poor-coding-in-fbi-website/
 
Working with the feds is like the frog and the scorpion story.
Except there’s a slight chance of buttsex and forced blowjobs in this story.

Also, a potential way to help share breach data is to use SimpleX. Create a small room, set a hard limit, once that limit is reached, the last one in makes a new SimpleX group and forwards all info over to it.

This means the attack surface is very very small and if one group gets infiltrated or monitored, even the group leader can only divulge that one other group exists. It’s just proxy-chaining but for E2EE groups that do t know about each other on the human or the technical level.
 
Last edited:
Don't click random links!
What about random Minecraft mods from Byuu?

Working with the feds is like the frog and the scorpion story.
Anyone who wants to know how shitty it can be, look into what happened with Matthew Cox the bank/mortgage fraud guy. He had multiple deals with the feds in cooperation that they basically tried to say "thanks for playing, you get nothing and no refunds." Eventually he fought them in court while in prison and had enough in writing from them that he could force them to give him time off but damn did they try to screw him.
 
I really dont understand why everyone simps for these people. Those people make your life miserable, steal your money, sell your personal info to other criminals and encrypt your data to extort bitcoin. And you praise them like heros? I dont want to sound mad, I just dont understand the level of support seen in the comments
 
I really dont understand why everyone simps for these people. Those people make your life miserable, steal your money, sell your personal info to other criminals and encrypt your data to extort bitcoin. And you praise them like heros? I dont want to sound mad, I just dont understand the level of support seen in the comments
Yes.

But the feds are worse. 1000x worse.
 
  • Like
Reactions: Cpt. Stud Beefpile
There doesn't seem to be any mention of this, but where did his OPSEC give up? How were the FEDs able to find him? All these articles and videos just seem to talk about what he did and what his website was.
The fake news isn't real journalism. They're just stenographers echoing whatever the feds who own them told them to say.
I really dont understand why everyone simps for these people. Those people make your life miserable, steal your money, sell your personal info to other criminals and encrypt your data to extort bitcoin.
Lmao no they don't, because I'm not fuckin retarded.
 
Hilarious shit.

Can't wait to check out Mental Outlaw's video on the matter, that nigger's shit is unironically very informative, notwithstanding the cringe 4chin and weeb coomer memes.

Even funnier that this happened just after making some of the tryhard and edgelord cybercriminals, that are extremely common in these places, seethe in the propering grounds thread about how obviously pathetic his "legacy" and "nostalgiafagging", so to speak, are.
Moloch never closes a door without opening a window. Endless praise to him!
 
The fake news isn't real journalism. They're just stenographers echoing whatever the feds who own them told them to say.

Lmao no they don't, because I'm not fuckin retarded.
As always, An0malous. You're the exception, not the rule.

Yes.

But the feds are worse. 1000x worse.
Terry a davis did it better, get new material.

I really dont understand why everyone simps for these people. Those people make your life miserable, steal your money, sell your personal info to other criminals and encrypt your data to extort bitcoin. And you praise them like heros? I dont want to sound mad, I just dont understand the level of support seen in the comments
Because most people want to suffer, they beg me to make them suffer, and yours truly is happy to provide.

Why are these retards calling it "dark web" when the forum was always a completely normal clear site.

The media are lying assholes.
The real question is: Why are you so mad about labels?
 
I just dont understand the level of support seen in the comments
Well helped expose that chomo Corey Barnhill and Pompompurin to me seems like a nice guy. He is a black hat hacker for sure but definitely not the blackest one. He could've done some real damage during his FBI email hack, but he didn't do it. To quote him directly from an interview after that incident.
“I could’ve 1000% used this to send more legit looking emails, trick companies into handing over data etc.,” Pompompurin said. “And this would’ve never been found by anyone who would responsibly disclose, due to the notice the feds have on their website.”
 
  • Agree
Reactions: Markass the Worst
The "lost" final update message btw:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hello Everyone.

This will be my final update on Breached, as I've decided to shut it down. I'm aware this news will not please anyone, but it's the only safe decision now that I've confirmed that the glowies likely have access to Poms machine.

As I said early on in all of this, anything related to production Breached infrastructure was locked down immediately - however I was kind enough to leave a few old, non-essential servers completely unchanged. One of those servers I left unchanged is an old CDN from months ago that no longer hosts any CDN files or configs but rather was used to just download large files from time to time.

Throughout the migration I checked to see if anything was going on that would cause concern during the migration. One of the servers checked, was the old CDN server described above. It seems someone logged in on Mar 19, 1:34 EST prior to me logging into the server. Unfortunately this likely leads to the conclusion that someone has access to Poms machine. Any servers we use are never shared with anyone else, so someone would have to know the credentials to that server to be able to login. I now feel like I'm put into a position where nothing can be assumed safe, whether its our configs, source code, or information about our users - the list is endless. This means that I can't confirm the forum is safe, which has been a major goal from the start of this shitshow.

As for what this means now, It's complicated. Unlike when other communities go down and everyone scatters, stupidly I will still be around. I will redirect all the Breached domains to my baph.is domain. The Telegram group and channel will remain up for now, but I will make a new Telegram group for those interested in seeing what I have planned next. I will always be willing to sign a message to prove my identity to the community.

While the community of Breached will die, I'm going to continue conversations with some of the competitor forum admins and various service operators who reached out to me over the past few days. I'm hoping to work with some of those people to build a new community, that will have the best features of Breached, while reducing the attack surfaces we never properly addressed. As with things like this, I have no doubt our userbase may be absorbed by another community but if there is patience then I hope to bring something back that will rival any other community that can take our place.

I'll be taking 24 hours from the sharing of this message to just rest and think. I'll be back online to talk with everyone, and we'll go from there. The domains for the time being shouldn't be seized, but I'll let the community know if any of that happens.

For now - see you space cowboy.

- - Baphomet
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEwjntiyso/csN4SiV9wumY4m0ToYFAmQZTG0ACgkQ9wumY4m0
ToYtQw/+MoP3mciQmLH0lWcWLZwU1DW5OkyLMVYCOx44Hx49rWSqa/Q28+aTTjKf
Q5q33zLvlHHfB9+4jchCVdi8+D9Y0QvU2t4sc9zzF2vv2iQPUL2vg6xOThwTQeXW
cBye7zFZM0BLjkkjNqDPJffXvXfvXvZ+IuLGH8ddmzpWKbFEnx3FWmUKxBMR2JcE
53PHkiNtYfMi2qng98Xxu17stsP5Ow2rayLAWawbV0o2VULrgLJUpTwoxOZZ+qqL
YB6fF/mfSILjS3AJNOvAf8WrO4vfF/X//px7vhLdyJkMMBfoPO9wLJTVjXxadvOn
K5VrCE/vSpOGRaL0d8E6JJQ+8h/AOMMxdyGqztm1YQw0/wOlB6JqnQBS+LL+IpuR
jz5hMqVr97yuSkfyeOlO6uWT4jq5j2SdVO/SRV7MxctVQ1tMNkGElclS1/rJV1aj
IS8Ke/EVuiUTmMjRC7+k92xf8mZcCzOwqeOBatZUiFT5gbt/TrhO7BIf8+12ULO1
LDCR3lGQv6MZIy8+b3trRvt2tuMmP6oLoBo4CGXyvo8dh/oOfTLHeb0OXFe5JeZ7
LM9aQgtPuaBQ79fGBqv0u++WEyGBVb6DlKAxQ5MuAtvM9VnY6wt3vy+/2YiE0GHZ
z5kf7m4HlIUguJ0qbdfVlZjw2Qzrg+4oDI8IdwyclVcw6yNBHLI=
=kr1F
-----END PGP SIGNATURE-----

From here
 
Back