{"id":3802,"date":"2024-05-29T16:32:32","date_gmt":"2024-05-29T21:32:32","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown"},"modified":"2024-05-29T16:32:32","modified_gmt":"2024-05-29T21:32:32","slug":"leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/29\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown\/","title":{"rendered":"Leak Site BreachForums Springs Back to Life Weeks After FBI Takedown"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt685c6c9be957edeb\/665793b6f422034dd212a212\/darkweb_ozrimoz_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Barely two weeks after the FBI and the US Department of Justice shut down BreachForums, the notorious data leak site appears to be back online, hawking personal and payment card data purportedly belonging to more than 500 million Live Nation\/TicketMaster customers.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Truth or Law Enforcement Bluff?\">Truth or Law Enforcement Bluff?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers at Malwarebytes this week spotted &#8220;ShinyHunters,&#8221; an administrator of the BreachForums site, posting the alleged TicketMaster data for sale for $500,000 on one of its original domains. But they are unsure if the apparent revival of the operation is legit, or simply a lure by law enforcement to trap bad actors looking to once again buy stolen data from the forum.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We dare conclude that this dataset&#8217;s goal is to generate some attention and act as a lure to let old forum users know that BreachForums is alive and kicking,&#8221; Malwarebytes researcher <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/05\/data-leak-site-breachforums-is-back-boasting-live-nation-ticketmaster-user-data-but-is-it-a-trap\" rel=\"noopener\">Pieter Arntz wrote in a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> this week. &#8220;But who is running the show, is the question that we hope to answer soon.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BreachForums is a hacking forum and marketplace for cybercriminals to buy and sell all kinds of stolen data, including credit card data, bank account information, Social Security numbers, bank account information, hacking tools, account credentials, and personally identifying information. The forum, which boasted of having some 340,000 members earlier this year, became the go-to market for illicit data in mid-2022 following the FBI&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/united-states-leads-seizure-of-one-of-the-world-s-largest-hacker-forums-and-arrests-administrator\" rel=\"noopener\">disruption of RaidForums<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, another data leak site, which at the time was the biggest of its kind.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Earlier this month, the FBI and the DOJ <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/fbi-doj-shut-down-breachforums-launch-investigation\" rel=\"noopener\">seized control of BreachForums<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> domains and Telegram channels belonging to two of its main admins, &#8220;Baphomet&#8221; and &#8220;ShinyHunters.&#8221; The move followed the arrest in March 2023 of Conor Fitzpatrick, aka &#8220;pompompurin,&#8221; the alleged creator of BreachForums. Though neither the FBI nor the DoJ have provided many details around the BreachForum domain takedown, ShinyHunters has claimed that the FBI has arrested Baphomet as well, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/flashpoint.io\/intelligence-101\/breach-forums\/\" rel=\"noopener\">Flashpoint<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> said in a report this week.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"&quot;An Avatar and a Handle are Easily Copied&quot;\">&#8220;An Avatar and a Handle are Easily Copied&#8221;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;According to Malwarebytes, the reappearance of BreachForums just two weeks after law enforcement seized its domains is suspicious for several reasons. For one thing, the same data that ShinyHunters has posted for sale on BreachForums is also for sale from an individual using the handle SpidermanData on another Dark Web site. The dataset itself \u2014 allegedly containing data belonging to 560 million customers \u2014 seems suspiciously large and therefore likely not what it purports to be. The revived BreachForums site also requires users to register if they want to see the content that is available for sale on it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;An avatar and a handle are easily copied, and there are a few things that raised our spidey-senses that something is up,&#8221; Arntz wrote in the Malwarebytes blog post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In separate comments to Dark Reading, Arntz says this wouldn&#8217;t be the first time that law enforcement has used similar lures to try and trap cybercriminals. He points to a 2018 sting operation that resulted in the takedown of Dark Web drug site <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/dark-web-marketplaces-dissolve-post-alphabay-hansa-takedown\" rel=\"noopener\">Hansa Market<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and the takedown of an encrypted device company called <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/800-criminals-arrested-in-biggest-ever-law-enforcement-operation-against-encrypted-communication\" rel=\"noopener\">ANOM<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as two examples.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Consistent With Previous Takedowns\">Consistent With Previous Takedowns<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, if the BreachForums revival is indeed genuine, that too would be consistent with previous trends, Arntz notes. &#8220;Criminals like to keep doing what they know works,&#8221; he says. &#8220;So dealing with the same administrators and especially the trusted escrow service beats having to find a new one that they don&#8217;t know yet. So existing users will be likely to return.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ian Gray, VP of intelligence at<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\"> <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Flashpoint, says evidence suggests BreachForums is operational. Dark Web chatter points to the main BreachForums domain being transferred elsewhere after the law enforcement seizure. &#8220;Shortly after the seizure, the site included a link to &#8216;Jacuzzi 2.0,&#8217; a Telegram chat for BreachForums,&#8221; Gray says. &#8220;Today, the landing page for the site includes a link to N.W.A.&#8217;s &#8220;F*** Tha Police,&#8221; he says, referring to American hiphop group N.W.A.s protest song.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ShinyHunters, the administrator of the shuttered BreachForums, claims to have regained control of the domain seized from the FBI, he notes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More chatter suggests that another BreachForums member &#8220;USDoD&#8221; will launch a similar leak site on July 4 that is not associated with the current iteration of BreachForums, Gray notes. The new forum&#8217;s domain is planned to be either breachnation.io or databreached.io, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unfortunately, the BreachForums of the world are poised to metastasize, says Patrick Harr, CEO of SlashNext, an email security vendor. &#8220;They are <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/blackcat-unseizes-sites-fbi-revenge-attacks\" rel=\"noopener\">never fully eradicated<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> despite treatment or in this case a takedown,&#8221; he says. &#8220;The group, like cancer, still lurks in the background, waiting to re-emerge, sometimes in different name or form but with the same purpose.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Barely two weeks after the FBI and the US Department<\/p>\n","protected":false},"author":12,"featured_media":3803,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3802","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=1000%2C573&ssl=1",1000,573,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=300%2C172&ssl=1",300,172,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=640%2C367&ssl=1",640,367,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=640%2C367&ssl=1",640,367,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=1000%2C573&ssl=1",1000,573,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=1000%2C573&ssl=1",1000,573,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=1000%2C573&ssl=1",1000,573,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?resize=825%2C573&ssl=1",825,573,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/leak-site-breachforums-springs-back-to-life-weeks-after-fbi-takedown.jpg?fit=1000%2C573&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3802","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3802"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3802\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3803"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3802"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3802"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3802"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}