BreachForums, an online bazaar for stolen data, seized by FBI

BUSTED —

An earlier iteration of the site was taken down last year; now its reincarnation is gone.

The front page of BreachForums.

Enlarge / The front page of BreachForums.

The FBI and law enforcement partners worldwide have seized BreachForums, a website that openly trafficked malware and data stolen in hacks.

The site has operated for years as an online trading post where criminals could buy and sell all kinds of compromised data, including passwords, customer records, and other often-times sensitive data. Last week, a site user advertised the sale of Dell customer data that was obtained from a support portal, forcing the computer maker to issue a vague warning to those affected. Also last week, Europol confirmed to Bleeping Computer that some of its data had been exposed in a breach of one of its portals. The data was put up for sale on BreachForums, Bleeping Computer reported.

On Wednesday, the normal BreachForums front page was replaced with one that proclaimed: “This website has been taken down by the FBI and DOJ with assistance from international partners.” It went on to say agents are analyzing the backend data and invited those with information about the site to contact them. A graphic shown prominently at the top showed the forum profile images of the site’s two administrators, Baphomet and ShinyHunters, positioned behind prison bars.

The FBI also created a dedicated subdomain on its IC3.gov domain that said: “From June 2023 until May 2024, BreachForums (hosted at breachforums.st/.cx/.is/.vc and run by ShinyHunters) was operating as a clear-net marketplace for cybercriminals to buy, sell, and trade contraband, including stolen access devices, means of identification, hacking tools, breached databases, and other illegal services.” The page provided a form that visitors could fill out to provide tips. At the time this post went live, breachforums.ic3.gov was not available.

The FBI and the Department of Justice declined to comment.

The action on Wednesday is the second time within a year that the online data bazaar has been taken down by law enforcement. Last June, a different domain used to host the site was seized three months after the FBI arrested its alleged founder and operator. Conor Brian Fitzpatrick, then 21 years old, pleaded guilty to multiple charges. In January, he was sentenced to 20 years of supervised release. Prosecutors said that under Fitzpatrick, BreachForums had provided access to the personal information of millions of US citizens.

Shortly after the June takedown of the site, a new individual stepped forward and revived the forum by hosting it on a new domain, which the FBI said had changed three times. This time around, the FBI also seized the official BreachForums Telegram channel and a second one belonging to Baphomet. Both channels displayed the same graphic appearing on the newly seized BreachForums site. It’s not clear how authorities took control of the Telegram channels.

The claim that authorities have access to the BreachForums’ backend data raises the possibility that they are now in possession of email addresses, IP addresses, and other data that could be used to prosecute site users.

In 2022, the FBI seized RaidForums, another site for buying and selling malware and compromised data.

Listing image by Shutterstock

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Think ‘Adaptive, Creative, and Resilient’ to Drive Growth thumbnail

Think ‘Adaptive, Creative, and Resilient’ to Drive Growth

For years, we have heard the story that tech investments drive productivity. But when we further explored this topic, we found that the productivity of tech investments has been steadily falling for the past 20 years thanks to disconnected digital investments and stakeholders, rising technical debt, and pervasive digital sameness. Now, as we start to…
Read More
MobileCoin reveals Signal-integrated cryptocurrency payments feature has quietly rolled out to international markets thumbnail

MobileCoin reveals Signal-integrated cryptocurrency payments feature has quietly rolled out to international markets

2021 年春,加密通信应用 Signal 宣布将在英国开测支付功能,并且集成对 MobileCoin 的支持。作为一款相对新颖的加密货币,Signal 宣称 MobileCoin 更加注重隐私体验。自去年 11 月中旬以来,该公司已悄然开启更广泛的阶段性测试,让数以百万计的移动设备用户具备了数字支付的能力。 最新消息是,MobileCoind 创始人 Josh Goldbard 已确认正式向国际市场推送 Signal 新支付功能的时间。参考 Signal 的总下载量报告,当前已有上亿台设备能够打开 MobileCoin,并在五秒(或更短的时间)内实现端到端的加密支付。据说当前每日交易量已达数千笔,相比之下,测试阶段的日交易量只有数十笔。即便如此,Signal 的支付功能,用起来还不够便捷。大部分市场区域的 Signal 用户,都可通过点击 + 图标、然后选择‘支付’,以访问他们的 MobileCoin 钱包。除了要等待加密货币钱包的加载,这款加密货币也仅在少数几个规模较小的交易所挂牌(比如 BitFinex 和 FTX),其中没有任何一家是面向美国市场的。与此同时,Signal 方面没有回应外媒的置评请求。不过去年 4 月,Moxie Marlinspike 曾接受过《连线》的采访,期间有解释其希望为 Signal 这款加密视频通话 / 消息应用引入支付功能。显然,此举是为了让 Signal 可在功能上与 WhatsApp 和 Facebook Messenger 等展开直接的竞争,同时让用户享有这款应用广受赞誉的隐私保护特性。
Read More
Index Of News
Total
0
Share