{"id":7966,"date":"2025-10-27T10:03:27","date_gmt":"2025-10-27T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/27\/infamous-cybercriminal-forum-breachforums-is-back-again-with-a-new-clear-net-domain\/"},"modified":"2025-10-27T10:03:27","modified_gmt":"2025-10-27T10:03:27","slug":"infamous-cybercriminal-forum-breachforums-is-back-again-with-a-new-clear-net-domain","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/27\/infamous-cybercriminal-forum-breachforums-is-back-again-with-a-new-clear-net-domain\/","title":{"rendered":"Infamous Cybercriminal Forum BreachForums Is Back Again With a New Clear Net Domain"},"content":{"rendered":"<p>    Infamous Cybercriminal Forum BreachForums Is Back Again With a New Clear Net Domain<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The notorious cybercrime forum BreachForums has resurfaced online, this time on a clearnet domain accessible without specialized tools like Tor.<\/p>\n<p>The platform, long a hub for data leaks, <a href=\"https:\/\/cybersecuritynews.com\/category\/hacking-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">hacking tools<\/a>, and illicit trades, went dark earlier this year following a series of law enforcement takedowns and internal disruptions.<\/p>\n<p>Now, just months later, it\u2019s operational again, drawing both excitement from underground actors and suspicion from security experts.<\/p>\n<p>The forum\u2019s return was announced by its administrator, known only as \u201ckoko,\u201d who claimed in a pinned post that core functionality has been fully restored from a recent backup. <\/p>\n<p>Users can once again browse sections dedicated to stolen credentials, <a href=\"https:\/\/cybersecuritynews.com\/tag\/lockbit-ransomware-gang\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware discussions<\/a>, and zero-day exploits. Koko emphasized that the site is \u201cstronger than ever,\u201d with enhanced anonymity features to evade detection.<\/p>\n<p>However, the revival comes amid whispers of compromise, specifically, the old escrow system, which handled cryptocurrency transactions for illicit deals, was hacked, leading to significant losses for vendors and buyers alike.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-breachforums-is-back-again\"><strong>BreachForums Is Back Again?<\/strong><\/h2>\n<p>BreachForums isn\u2019t starting over entirely; koko detailed that the team is rebuilding the escrow service from scratch to address the vulnerabilities exposed in the breach. <\/p>\n<p>\u201cWe\u2019ve learned from the mistakes,\u201d Koko wrote, promising improved encryption and multi-signature wallets to prevent future thefts.<\/p>\n<p>This follows a pattern for the forum, which has bounced back multiple times since its inception in 2022 as a successor to the shuttered RaidForums. <\/p>\n<p>Past iterations have been hit by FBI seizures and arrests, including the 2023 takedown of its founder, Conor Fitzpatrick, aka \u201cPompompurin.\u201d<\/p>\n<p>Yet, the clearnet pivot marks a bold shift. By ditching the dark web, <a href=\"https:\/\/cybersecuritynews.com\/tag\/breachforums\/\" target=\"_blank\" rel=\"noreferrer noopener\">BreachForums<\/a> aims to attract a broader audience, including less tech-savvy criminals who avoid Tor\u2019s complexities.<\/p>\n<p>Despite the optimism from koko, skepticism abounds in the cyber underground. Many forum veterans suspect this iteration could be a honeypot operated by law enforcement. <\/p>\n<p>\u201cIt\u2019s too clean, too quick,\u201d one anonymous poster commented, echoing concerns that U.S. agencies like the FBI or Secret Service might be monitoring activity to build cases. <\/p>\n<p>Cybersecurity firms such as Recorded Future have issued warnings, noting that clearnet domains are easier for authorities to track via IP logs and hosting providers.<\/p>\n<p>Experts urge caution for anyone encountering the site. \u201c<a href=\"https:\/\/cybersecuritynews.com\/tag\/breachforums\/\" target=\"_blank\" rel=\"noreferrer noopener\">BreachForums<\/a> has always been a double-edged sword, valuable intel for researchers, but a magnet for real threats,\u201d said John Doe, a threat analyst at a leading security firm.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/breachforums-back-again\/\">Infamous Cybercriminal Forum BreachForums Is Back Again With a New Clear Net Domain<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/breachforums-back-again\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infamous Cybercriminal Forum BreachForums Is Back Again With a New Clear Net Domain The notorious cybercrime forum BreachForums has resurfaced online, this time on a clearnet domain accessible without specialized tools like Tor. The platform, long a hub for data leaks, hacking tools, and illicit trades, went dark earlier this year following a series of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-7966","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7966"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7966"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7966\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7966"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7966"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7966"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}