BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum
In a recent development, a hacker identified as "James" has released the complete user database of BreachForums, a Dark Web forum involved in trading stolen data and hacking discussions.
In a recent development, a hacker identified as "James" has released the complete user database of BreachForums, a Dark Web forum involved in trading stolen data and hacking discussions.
The breach, which was disclosed on January 9, 2026, on the website shinyhunte.rs , has exposed metadata for over 323,986 users, including administrators, moderators, and regular members. This incident may have significant implications for those involved, as they could become subjects of law enforcement investigations.
BreachForums was established in 2022 following the shutdown of RaidForums by U.S. authorities. The platform, using MyBB software , was a venue for selling breached datasets, hacking tools, and illicit services. Despite repeated takedowns, it continued operations via DDoS-Guard and Tor mirrors.
Notable disruptions included the arrest of its founder, Conor Fitzpatrick, in 2023, who was sentenced to 20 years of supervised release, and a 2024 domain seizure, which was quickly recovered by the operators ShinyHunters .
This incident may have significant implications for those involved, as they could become subjects of law enforcement investigations.
ShinyHunters, associated with groups like Scattered LAPSUS Hunters, managed to relaunch the site multiple times, surviving various law enforcement actions. However, vulnerabilities in the MyBB software ultimately led to the breach.
The leaked MySQL database includes usernames, hashed passwords (Argon2), emails, IP addresses, registration dates, and PGP keys for prominent accounts. Analysis indicates that the user base consists of 4 administrators, 3 super moderators, and 6 moderators, with users primarily from the United States, Germany, Netherlands, France, Turkey, the United Kingdom, and regions such as Morocco and Egypt.
Attached images display the shinyhunte.rs page with a manifesto titled "DOOMSDAY: The Story of James" and a pie chart showing the distribution of users by country, with a significant proportion from the U.S. The breach was attributed to a web application vulnerability or configuration error.
The incident raises concerns about the security of even Dark Web sites, highlighting the risks of storing sensitive information in plaintext. The breach could lead to increased law enforcement activity against those involved in the forum's operations.
For further analysis, Resecurity has shared the data dump, noting potential impacts on extortion operations targeting firms.
Based on reporting by Cyber Security News.
