📈 Get daily crypto insights that make you smarter about your money

FBI Seizes BreachForums in Global Cybercrime Crackdown: What Crypto Users Must Know

The Federal Bureau of Investigation, in coordination with French authorities and law enforcement agencies across 14 countries, has seized the domains of BreachForums — one of the world’s largest online forums for cybercriminals to buy and sell stolen data. The operation, which took place on October 10 and saw seizure banners posted across the forum’s domains by October 13, 2025, represents one of the most significant law enforcement actions against cybercrime infrastructure in recent years.

The Exploit Mechanics

BreachForums operated as an open-web marketplace where over 142,000 members exchanged more than 215,000 messages facilitating the trade of stolen databases, credit card numbers, banking credentials, and personally identifiable information. The forum maintained an enormous and continuously updated archive of hacked databases, including hundreds of millions of account credentials from high-profile attacks targeting major corporations worldwide.

The platform functioned as a successor to RaidForums, which was seized by the DOJ in April 2022. After BreachForums’ initial disruption in 2023, it reconstituted and continued operations, becoming a central hub for groups like ShinyHunters, Baphomet, and IntelBroker. These threat actors used the forum to monetize stolen data from breaches across industries — including cryptocurrency exchanges, DeFi protocols, and wallet providers.

Affected Systems

The seizure directly impacts the cybercrime supply chain that fuels account takeovers against cryptocurrency users. BreachForums served as a primary distribution channel for stolen credentials that attackers would later use in credential-stuffing attacks against exchange accounts, hot wallets, and DeFi platforms. With Bitcoin trading at approximately $115,271 and Ethereum at $4,245 on the day of the seizure, the potential damage from credential-based attacks remained substantial.

Notably, the hacking collective Scattered LAPSUS$ Hunters had been using BreachForums to threaten the release of one billion records allegedly stolen from Salesforce customers. Listed victims included Adidas, Cartier, Chanel, Cisco, FedEx, IKEA, McDonald’s, Toyota, and Walgreens. Salesforce confirmed it would not pay a ransom demand.

The Mitigation Strategy

Law enforcement agents in the United States, Australia, Belgium, Poland, Portugal, Romania, Spain, and the United Kingdom executed synchronized search warrants, arrests, and interviews. The FBI’s Internet Crime Complaint Center (IC3) posted seizure banners on the forum’s domains, redirecting visitors to a portal where victims and former members could submit information to assist in ongoing investigations.

However, security researchers noted that the forum’s Tor-based dark web presence remained active following the domain seizure. A clone site reportedly appeared as early as October 13 at a new domain, underscoring the persistent challenge of permanently dismantling such platforms.

Lessons Learned

The BreachForums takedown reinforces several critical lessons for the cryptocurrency community. First, law enforcement agencies are increasingly capable of coordinating multinational operations against cybercrime infrastructure. Second, the data seized — including IP logs, private messages, and backup databases — will likely fuel additional investigations and arrests in the months ahead.

For crypto users specifically, the breach data circulating on these forums poses a direct threat. Credentials stolen from non-crypto services are routinely tested against exchange accounts in automated attacks. Using unique passwords, hardware two-factor authentication, and monitoring breach notification services remains essential.

User Action Required

Cryptocurrency users should take immediate steps to secure their accounts in the wake of this seizure. Enable hardware-based 2FA on all exchange accounts, rotate passwords that may have been reused across services, and review recent login activity for suspicious access. Users who held accounts on any platform listed in the Salesforce-related breach disclosures should be especially vigilant. The authorities have established a portal at the IC3 website where individuals can report relevant information about BreachForums activity.

Disclaimer: This article is for informational purposes only and does not constitute financial or legal advice. Always conduct your own research before making security decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “FBI Seizes BreachForums in Global Cybercrime Crackdown: What Crypto Users Must Know”

  1. 142K members and 215K messages facilitating stolen data trades. the forum was basically Amazon for cybercrime. good riddance even if its temporary

    1. Zara Okonkwo 142K members trading stolen data on clearnet. centralized darknet markets for stolen data are basically honeypots waiting to happen

    1. Scattered Spider using BreachForums to monetize MFA bypass creds is the real story here. the forum wasnt just data trading, it was an operations hub

      1. Scattered Spider using the forum to sell MFA bypass creds means this wasnt just data trading. it was an active operations hub for live attacks

      2. Yuki Endo Scattered Spider selling MFA bypass creds on a public forum tells you how brazen these groups got. they treated BreachForums like a B2B storefront

        1. scattered spider treating breachforums like a B2B store for MFA bypass creds is wild. 14 countries coordinated and theres already a successor site brewing

        2. scattered spider selling MFA bypass like saas on a clearnet forum. 14 countries coordinated and theres already a telegram replacement running

      3. Scattered Spider using BreachForums as a B2B storefront for MFA bypass creds tells you how professionalized cybercrime got

    1. threat_intel_junkie

      142K members and nobody thought to move to a dark web forum sooner? centralized clearnet markets for stolen data always end the same way

  2. 142K members and 215K messages trading stolen data on an open web forum. the operational security of cybercriminals is genuinely baffling sometimes

  3. 14 countries coordinated and the site was still up for 3 days after seizure banners went live. operational security on the law enforcement side wasnt great either

  4. BreachForums was the third iteration after RaidForums got seized. they keep rebuilding the same model on new domains and it keeps working. whack a mole at this point

    1. pwn_diary_ exactly. RaidForums got seized and BreachForums replaced it. now BreachForums is seized and something else will pop up. whack-a-mole doesnt work

      1. forum_refugee RaidForums to BreachForums to whatever comes next. the user base doesnt disappear, it just migrates domains. whack-a-mole

        1. opsec_ghost_ the whack-a-mole problem is structural. clearnet forums get seized because they need DNS and hosting. darknet markets last longer but have their own exit scam issues

          1. clearnet_honeypot_

            142k members trading stolen data on clearnet. iris_table is right, the whack-a-mole is structural. DNS and hosting are the weak links

    2. raidforums to breachforums to whatever comes next. each iteration the user count doubles. supply and demand for stolen data is the actual problem

      1. Pavel G. user count doubling each iteration is the scariest part. RaidForums had maybe 50k, BreachForums hit 142k. whatever replaces it will be bigger again

    3. darknet_pivot_

      pwn_diary_ exactly. they seized RaidForums in 2022 and BreachForums replaced it within weeks. the demand side doesnt go away

  5. 142K members on a clearnet forum selling stolen credentials. the opsec on these buyers is already compromised by definition, which is why takedowns actually work here

  6. 142K members selling stolen creds on a clearnet forum. the opsec was non-existent which is exactly why this seizure actually landed

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,015.00-1.6%ETH$1,877.01-2.2%SOL$76.23-1.1%BNB$600.09-1.2%XRP$1.02-2.1%ADA$0.1938-1.8%DOGE$0.0699-0.7%DOT$0.8051-0.3%AVAX$6.46-1.5%LINK$8.28-0.4%UNI$3.96-2.8%ATOM$1.41+1.8%LTC$45.09-2.2%ARB$0.0804+1.8%NEAR$1.60-1.7%FIL$0.7053-0.9%SUI$0.6923-0.6%BTC$64,015.00-1.6%ETH$1,877.01-2.2%SOL$76.23-1.1%BNB$600.09-1.2%XRP$1.02-2.1%ADA$0.1938-1.8%DOGE$0.0699-0.7%DOT$0.8051-0.3%AVAX$6.46-1.5%LINK$8.28-0.4%UNI$3.96-2.8%ATOM$1.41+1.8%LTC$45.09-2.2%ARB$0.0804+1.8%NEAR$1.60-1.7%FIL$0.7053-0.9%SUI$0.6923-0.6%
Scroll to Top