Article Details
Scrape Timestamp (UTC): 2026-01-10 18:19:09.170
Original Article Text
Click to Toggle View
BreachForums hacking forum database leaked, exposing 324,000 accounts. The latest incarnation of the notorious BreachForums hacking forum has suffered a data breach, with its user database table leaked online. BreachForums is the name of a series of hacking forums used to trade, sell, and leak stolen data, as well as sell access to corporate networks and other illegal cybercrime services. The site was launched after the first of these forums, RaidForums, was seized by law enforcement, with the owner, "Omnipotent", arrested. While BreachForums has suffered data breaches and police actions in the past, it has been repeatedly relaunched under new domains, with some accusing it of now being a honeypot for law enforcement. Yesterday, a website named after the ShinyHunters extortion gang released a 7Zip archive named breachedforum.7z. This archive contains three files named: A representative of the ShinyHunters extortion gang told BleepingComputer they are not affiliated with the site that distributed this archive. The archive's 'breachedforum-pgp-key.txt.asc' file is the PGP private key created on July 25, 2023, and used by BreachForums to sign official messages from the administrators. While the key has been leaked, it is passphrase-protected, and without the password, it can't be abused to sign messages. The "databoose.sql" file is a MyBB users database table (mybb_users) containing 323,988 member records that include member display names, registration dates, IP addresses, and other internal information. BleepingComputer's analysis of the table shows that most of the IP addresses map back to a local loopback IP address (0x7F000009/127.0.0.9), so they are not of much use. However, 70,296 records do not contain the 127.0.0.9 IP address, and the records we tested map to a public IP address. These public IP addresses could be an OPSEC concern for those people and valuable to law enforcement and cybersecurity researchers. The last registration date in the newly leaked user database is from August 11, 2025, which is the same day that the previous BreachForums at breachforums[.]hn was closed. This shutdown followed the arrest of some of its alleged operators. That same day, a member of the ShinyHunters extortion gang posted a message on the "Scattered Lapsus$ Hunters" Telegram channel, claiming the forum was a law-enforcement honeypot. The BreachForums administrators subsequently denied these allegations. The breachforums[.]hn domain was later seized by law enforcement in October 2025 after it was repurposed to extort companies impacted by the widespread Salesforce data theft attacks conducted by the ShinyHunters extortion group. The current BreachForums administrator, known as "N/A," has acknowledged the new breach, stating that a backup of the MyBB user database table was temporarily exposed in an unsecured folder and downloaded only once. "We want to address recent discussions regarding an alleged database leak and clearly explain what happened," N/A wrote on BreachForums. "First of all, this is not a recent incident. The data in question originates from an old users-table leak dating back to August 2025, during the period when BreachForums was being restored/recovered from the .hn domain." "During the restoration process, the users table and the forum PGP key were temporarily stored in an unsecured folder for a very short period of time. Our investigation shows that the folder was downloaded only once during that window," continued the administrator. While the administrator said that BreachForums members should use disposable email addresses to reduce risk and that most IP addresses mapped to local IPs, the database still contains information that could be of interest to law enforcement. The 2026 CISO Budget Benchmark It's budget season! Over 300 CISOs and security leaders have shared how they're planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026. Learn how top leaders are turning investment into measurable impact.
Daily Brief Summary
BreachForums, a hacking forum, experienced a data breach, leaking a user database with 324,000 accounts, including display names, registration dates, and IP addresses.
The breach involved a MyBB users database table, with 70,296 records containing public IP addresses, posing potential operational security risks for users.
The leaked data was temporarily exposed in an unsecured folder during a restoration process, according to the forum's current administrator.
The breach has raised concerns about the forum being a potential law enforcement honeypot, although administrators have denied these claims.
Law enforcement seized the breachforums[.]hn domain in October 2025, following its use in extortion activities related to Salesforce data thefts.
The exposed PGP key used by BreachForums is passphrase-protected, limiting its immediate misuse for signing messages.
BreachForums advises users to employ disposable email addresses to mitigate risks, but the breach remains a significant concern for user privacy and security.