Hacker/Cybercrime Community / Script Kiddies / Skids / Skid Hunters / Hacker Forums / Darknet Marketplaces - Skids and manchildren that hunt them

  • 🔧 At about Midnight EST I am going to completely fuck up the site trying to fix something.
> kiwifarms.is is very turbo dangerous and gets aborted by the gigachad free-speech icelandic registrar
> xss.is is fine, then seized by europol

interesting priorities.
I had reported multiple crime websites to cloudflare, always got the same spiel about them not being responsible for the content and only being a proxy yadda yadda.
 
Law enforcement has seized the dark web extortion sites of the BlackSuit ransomware operation.
https://archive.is/TzH5T (original: https://www.bleepingcomputer.com/ne...ement-seizes-blacksuit-ransomware-leak-sites/)
Seizure notice:
1753413520523.webp
 
BreachForums is back on its original Tor url http://breached26tezcofqla4adzyn22notfqwcac7gpbrleg4usehljwkgqd.onion
With all the data, accounts etc. in tact. It is most likely a fed honeypot now.

1753485771603.webp


Canary & mirrors:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Next update by 08-25-2025.

Current:
breachforums.hn
breached26tezcofqla4adzyn22notfqwcac7gpbrleg4usehljwkgqd.onion

Mirrors:
breached4lhlibrqmzj7h2n4unu7wdzkg7gczcggufbqufwmmdraiyqd.onion
breachedetbw6gnud64wvuld3xkyrrbz5eijhvjbbix72izpegjdvcyd.onion
breachedhr2hxxranvbogkth63cpxwdcelsetui4uqavejvsqes4thid.onion
breachedm6qqmtc2ksrdhhtdr6o4erzudgx4blvkcxhyeruudtibizqd.onion

PGP Key: http://breached26tezcofqla4adzyn22notfqwcac7gpbrleg4usehljwkgqd.onion/pgp.txt

Fingerprint: E80C 1308 A09E C1AD C418 C3F0 2578 988F 69BC A3FC

BTC Block Hash: 000000000000000000008d76de49dfc041b45c72f69b9240ad14d30cc6756b30
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCAAdFiEE6AwTCKCewa3EGMPwJXiYj2m8o/wFAmiDnV8ACgkQJXiYj2m8
o/y5ywv9FlLlhuEI5RsKc2oS5nk13lGm8UM2l0wyWNrj1Pwyfj9E69bsFUcE4JD1
ispoN5f8T1Cs4vd8kT2ce8oWfvOo1+CPFTMDc8dkot1M1LC0tuMMDFLc9UTDnsJU
gvEeli28Cu7csz8lcpUaRdcDX2nYEzOtHrYuyVWnC4ywyctnj0SL3n4OPditIzjG
ht+Z6v4lyKSd4CJa64QRbdt8MoM5/MnB7Rl01F1Z6hnuzRWe6aghttfktdyylQI8
moarbCHKkDc+Uej0I5rS86M4l7xYfTgXLQ2l+y4A93Fh8JoKZze7eLDG8tCM0dHe
ukRQR5SfunwtP4IfFu4YBgYbYkf4ZVqXcDJrZ+ywFC6hEhnaQcEYHdjFJeM1XLv5
hF8T5/eAshmWSLBxHwgTpZF180cunnA9md4YTgOFsDTvMnHuag8MotvSv+4V0Mx0
krRPhTkc406hcPrBU5U4hIlzv5k/VaVN5ONXbckz6cPR9WEkV0xeJFqDssxDK4Ja
g+GMMVGe
=16uk
-----END PGP SIGNATURE-----
 
Last edited:
Haven't looked much into it, but:
It's pretty cut and dried. They removed a key feature that protected user information (browser and OS), then blatantly lied about it. Previously, TorBrowser spoofed OS so that every user appeared to be a Windows user. Now it exposes your OS directly, so the website gets a log of whether you came in on Windows/Mac/Linux/Android.

They kept the preference setting for it so you could "turn it on" but the switch does literally nothing, it's just a fake to create the impression you actually have a choice in the matter. They, in the developer's own words, "tore out" the code.

This is probably worthy of a happenings post, not because Tor is provably broken in more than this way, but because the project will outright lie about trivially provable detrimental changes they made to the server. Would they put in a backdoor? I no longer trust them not to and would view the whole organization as compromised.
 
BreachForums is back on its original Tor url http://breached26tezcofqla4adzyn22notfqwcac7gpbrleg4usehljwkgqd.onion
With all the data, accounts etc. in tact. It is most likely a fed honeypot now.


Hello BreachForums users,

In light of recent reports regarding alleged arrests involving BreachForums operatives, let us clarify unequivocally: none of our administrators have been arrested. The individuals named by law enforcement have never been part of our administration. Furthermore, we confirm that BreachForums infrastructure, code, and data remain uncompromised. As far as we're concerned, it's business as usual.

To address specific misconceptions: IntelBroker was never the actual owner of this forum. The title was intentionally assigned to him to divert attention from us, a strategy that evidently succeeded. He never had any "Owner" or "Administrator" privileges to this forum.

As announced previously, we temporarily closed the forum in April due to an identified zero-day vulnerability in MyBB. That vulnerability has since been patched. Shortly after our initial announcement, our original domain (breachforums.st) was suspended by our registrar following a request from law enforcement. Please do not believe conspiracy theories posted online and from people spreading FUD.

[email from nic.st] We have received multiple complaints regarding the domain name breachforums.st, including reports from law enforcement authorities as well as end users (so-called “abuse” cases). These complaints indicate that the domain in question points to an online resource where unlawful activity is/was taking place. Following an internal review and taking into account the seriousness of the information provided, we have concluded that continued operation of the domain presents an unacceptable risk. Consequently, we have decided to suspend the domain name and block it from future registration.

We acknowledge that this decision may cause inconvenience, but we are no longer able to guarantee the integrity of the domain in light of the issues raised. We refer in particular to the following provisions in the domain registration agreement:

1. The statement that you made in the registration process are complete and accurate and that you will maintain and update this information as needed to keep it current, complete and accurate. ST Registry may contact account holder or domain registrant in case of any issues or news/highlights about services provided on nic.st website. You as a customer are free to cancel your account and/or service at any time.

2. To your knowledge, the registration of the domain name will not infringe upon or otherwise violate the rights of any third party according to the laws of Séo Tomé and Principe or any other applicable jurisdiction.

3. You are not registering the domain name for an unlawful purpose.

This decision is final and takes effect inmediately. Sincerely, ABUSE TEAM, NIC.ST

The recent surge of domain seizures and disruptions across similar communities, including the incident involving XSS.is, has only reinforced our resolve. This isnt the end, it's a new beginning. We've used this time to regroup, refocus, and prepare for what's next. The forum is now better positioned than ever to thrive despite the ongoing efforts by law enforcement to disrupt our ecosystem.

The forum remains exactly the same since it was closed; Your accounts, your posts, your reputation, nothing has been lost or altered.

Expect changes in the coming weeks:

- A revamped moderation system that's more transparent and fair.
- Regular updates to keep you informed about what's happening behind the scenes.
- More focus on community engagement, because this place is only as strong as the people in it.
 
  • Optimistic
Reactions: Markass the Worst
Back