{"id":9782,"date":"2026-01-10T10:03:46","date_gmt":"2026-01-10T10:03:46","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/10\/breachforums-hack-hackers-expose-all-user-records-from-popular-dark-web-forum\/"},"modified":"2026-01-10T10:03:46","modified_gmt":"2026-01-10T10:03:46","slug":"breachforums-hack-hackers-expose-all-user-records-from-popular-dark-web-forum","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/10\/breachforums-hack-hackers-expose-all-user-records-from-popular-dark-web-forum\/","title":{"rendered":"BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum"},"content":{"rendered":"<p>    BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In a dramatic turn for the cybercrime underworld, a mysterious hacker known as \u201cJames\u201d has leaked the complete user database of BreachForums, a notorious Dark Web forum serving as a hub for stolen data trading and hacking discussions.<\/p>\n<p>The breach, announced on January 9, 2026, via the site <em>shinyhunte.rs<\/em>, exposes metadata for over 323,986 users, including admins, moderators, and regular members, potentially dooming many to law enforcement scrutiny.<\/p>\n<p>This incident underscores the irony of cybercriminals falling victim to their own vulnerabilities.paste.txt\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"breachforums-turbulent-history\"><strong>BreachForums Data Breach<\/strong><\/h2>\n<p>BreachForums emerged in 2022 as the successor to RaidForums, which U.S. authorities seized amid investigations into data trafficking.<\/p>\n<p>The forum, powered by <a href=\"https:\/\/cybersecuritynews.com\/breachforums-mybb-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">MyBB software<\/a>, facilitated sales of breached datasets, hacking tools, and illicit services, often hosted via DDoS-Guard and Tor mirrors despite repeated takedowns.<\/p>\n<p>Key disruptions included the 2023 arrest of founder Conor Fitzpatrick, who received a 20-year supervised release sentence, and a 2024 domain seizure swiftly reclaimed by operators <a href=\"https:\/\/cybersecuritynews.com\/shinyhunters-possibly-collaborates-with-scattered-spider\/\" target=\"_blank\" rel=\"noreferrer noopener\">ShinyHunters<\/a>.<\/p>\n<p>ShinyHunters, linked to groups like Scattered LAPSUS Hunters, relaunched the site multiple times, surviving French arrests in June 2025 and FBI seizures of extortion portals. The forum\u2019s resilience relied on frequent domain switches and Dark Web presence, but underlying MyBB flaws proved fatal.<\/p>\n<p>The dumped MySQL database, from table \u201chcclmafd2jnkwmfufmybbusers,\u201d reveals usernames, hashed passwords (Argon2), emails, IP addresses, registration dates, and PGP keys for high-profile accounts like ShinyHunters, Hollow, and IntelBroker.<\/p>\n<p>Analysis shows admins (4), super moderators (3), and mods (6), with user origins spanning the U.S. (largest share), Germany, Netherlands, France, Turkey, UK, and MENA regions like Morocco and Egypt.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgWOP42Nhen0ZhYGZGcvopUE7peCmyVTYZNXGpkZmoZvk7bQocVdrHKAuUSMF-1bPbe5QYq0LoBBsW23VUHxD23oCgPRrGPYJdytgXLotvKG0YAjCx_3UVoO4VhpKYSQi2AI3wtJ5pjnPuDzUmGzqnvu2efSDG-gwlrCcLRSVzmcDXBtt3e7vbnsDbntqwp\/s16000\/BreachForums%2520Hack1.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>Screenshots from attached images depict the shinyhunte.rs page with \u201cDOOMSDAY: The Story of James\u201d manifesto and a pie chart visualizing user countries, highlighting U.S. dominance. James claims the breach stemmed from a web app vulnerability or misconfiguration, turning the criminals\u2019 haven into a liability.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjn19Ak2N6tZOJ7B5dxXfKoDCAxC2FqpSzVBNpZFRMUqtS7heY55Cqd6A-XfdsPkG4mRUpluY0Qt7kaTqdDqdBG-J4Nq3s9Ztnsmc-Y1-uPVMw6Zto5HdHI3YaPa1RXYZ47LXY0b4uCMfGKDrY_sHfGiKl1m08Ou1XwgzGOWu4obOMlRXycgXY_p6EGWF2u\/w640-h418\/BreachForums%2520Hack.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>Under the banner \u201cDoomsday,\u201d James portrays himself as a \u201cpredator\u201d transcending generations, boasting infiltrations of Google, Microsoft, the FBI, the NSA, and more.<\/p>\n<p>He names alleged operators like Dorian Dali (Kams), Nahyl Ojeda (INDRA), Ali Aboussi (Kernel), and founders Prosox\/Kuroish, vowing their downfall for betraying a higher purpose. Addressing French readers, James positions himself as a protector against these \u201cchildren\u201d he once mentored, linking to anti-France activities.<\/p>\n<p>The text blends hacker lore with philosophical rants on power, evil, and redemption, echoing past underground manifestos.<\/p>\n<p>This self-inflicted wound exposes plaintext risks even on Dark Web sites, amplifying arrest threats amid global crackdowns. Victims face doxxing, while law enforcement gains leads on ShinyHunters derivatives within \u201cThe Com\u201d network. Resecurity, <a href=\"https:\/\/www.resecurity.com\/blog\/article\/doomsday-for-cybercriminals-data-breach-of-major-dark-web-foru\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">sharing<\/a> the dump for analysis, warns of broader disruptions to extortion rackets targeting firms like Salesforce.<\/p>\n<p>As James declares \u201cno place to hide,\u201d the BreachForums saga illustrates cybercrime\u2019s fragility, predators devoured by a greater one.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/breachforums-hack\/\">BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/breachforums-hack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum In a dramatic turn for the cybercrime underworld, a mysterious hacker known as \u201cJames\u201d has leaked the complete user database of BreachForums, a notorious Dark Web forum serving as a hub for stolen data trading and hacking discussions. The breach, announced on January [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-9782","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9782"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9782"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9782\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}