Saturday, March 18, 2023
HomeCyber SecurityFeds Cost NY Man as BreachForums Boss “Pompompurin” – Krebs on Safety

Feds Cost NY Man as BreachForums Boss “Pompompurin” – Krebs on Safety


The U.S. Federal Bureau of Investigation (FBI) this week arrested a New York man on suspicion of working BreachForums, a well-liked English-language cybercrime discussion board the place a number of the world greatest hacked databases routinely first present up on the market. The discussion board’s administrator “Pompompurin” has been a thorn within the aspect of the FBI for years, and BreachForums is extensively thought-about a reincarnation of RaidForums, a remarkably comparable crime discussion board that the FBI infiltrated and dismantled in 2022.

FBI brokers carting gadgets out of Fitzpatrick’s dwelling on March 15. Picture: Information 12 Westchester.

In an affidavit filed with the District Court docket for the Southern District of New York, FBI Particular Agent John Langmire mentioned that at round 4:30 p.m. on March 15, 2023, he led a workforce of legislation enforcement brokers that made a possible trigger arrest of a Conor Brian Fitzpatrick in Peekskill, NY.

“Once I arrested the defendant on March 15, 2023, he acknowledged to me in substance and partly that: a) his title was Conor Brian Fitzpatrick; b) he used the alias ‘pompompurin/’ and c) he was the proprietor and administrator of ‘BreachForums the information breach web site referenced within the Grievance,” Langmire wrote.

Pompompurin has been one thing of a nemesis to the FBI for a number of years. In November 2021, KrebsOnSecurity broke the information that 1000’s of faux emails a couple of cybercrime investigation had been blasted out from the FBI’s e mail techniques and Web addresses.

Pompompurin took credit score for that stunt, and mentioned he was capable of ship the FBI e mail blast by exploiting a flaw in an FBI portal designed to share info with state and native legislation enforcement authorities. The FBI later acknowledged {that a} software program misconfiguration allowed somebody to ship the pretend emails.

In December, 2022, KrebsOnSecurity broke the information that hackers energetic on BreachForums had infiltrated the FBI’s InfraGard program, a vetted FBI program designed to construct cyber and bodily risk info sharing partnerships with specialists within the non-public sector. The hackers impersonated the CEO of a significant monetary firm, utilized for InfraGard membership within the CEO’s title, and had been granted admission to the group.

From there, the hackers plundered the InfraGard member database, and proceeded to promote contact info on greater than 80,000 InfraGard members in an public sale on BreachForums. The FBI responded by disabling the portal for a while, earlier than finally forcing all InfraGard members to re-apply for membership.

Extra lately, BreachForums was the gross sales discussion board for knowledge stolen from DC Well being Hyperlink, a medical insurance trade primarily based in Washington, D.C. that suffered a knowledge breach this month. The gross sales thread initially mentioned the information included the names, Social Safety numbers, dates of delivery, well being plan and enrollee info and extra on 170,000 people, though the official discover concerning the breach says 56,415 individuals had been affected within the DC Well being Hyperlink breach.

In April 2022, U.S. Justice Division seized the servers and domains for RaidForums, a particularly common English-language cybercrime discussion board that bought entry to greater than 10 billion shopper information stolen in a number of the world’s largest knowledge breaches since 2015. As a part of that operation, the feds additionally charged the alleged administrator, 21-year-old Diogo Santos Coelho of Portugal, with six prison counts.

Coelho was arrested in the UK on Jan. 31, 2022. By that point, the brand new BreachForums had been dwell for just below per week, however with a well-known look.

BreachForums stays accessible on-line, and from reviewing the dwell chat stream on the location’s dwelling web page it seems the discussion board’s energetic customers are solely simply turning into conscious that their administrator — and the location’s database — is probably going now in FBI palms:

Members of BreachForums focus on the arrest of the discussion board’s alleged proprietor.

“Wait in the event that they arrested pom then doesn’t the FBI have all of our particulars we’ve registered with?” requested one frightened BreachForums member.

“However all of us have good VPNs I suppose, proper…proper guys?” one other denizen provided.

“Like pom would probably do a plea discount and cooperate with the feds as a lot as doable,” replied one other.

Fitzpatrick couldn’t be instantly reached for remark. The FBI declined to remark for this story.

There is just one web page to the prison grievance towards Fitzpatrick (PDF), which costs him with one rely of conspiracy to commit entry gadget fraud. The affidavit on his arrest is on the market right here (PDF).

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments