BreachForums is Down, Admins Posted a PGP-Signed Message

Stephanie Adlam
6 Min Read
BreachForums is Down, Forum Admins Published a PGP-Signed Message
BreachForums is temporarily offline, and its admins aired the official explanation for what is happening

BreachForums, an infamous Darknet forum, has gone offline recently, only to get back up with a worrying message on its main page. The administration posted a notice, signed with PGP for authenticity, stating they took the site offline after learning of a MyBB 0day exploit by law enforcement.

BreachForums Administration Posted a PGP-Signed Message

BreachForums, a well-known English-language marketplace for stolen data and hacking tools, has a documented history of disruptions by law enforcement, followed by periods of resurgence. The latest outage, beginning around April 15, 2025, triggered widespread speculation about its cause, ranging from Distributed Denial-of-Service (DDoS) attacks to law enforcement actions.

However, on April 28, 2025, the administration posted a PGP-signed message on the forum’s landing page, providing clarification. The message from BreachForums administration appears authentic, and explains a voluntary shutdown due to a suspected MyBB 0day exploit by law enforcement, with no infrastructure compromise or data infiltration.

BreachForums mainpage
BreachForums mainpage on April 30, 2025

What do they say & is it true?

Let’s analyze the message to shed some light on what’s going on. The message, signed with PGP using SHA512 for hashing and including a signature block. It states that around April 15, 2025, confirmation was received about a MyBB 0day vulnerability that had been suspected since the forum’s launch, based on information from trusted contacts. In response, the infrastructure was immediately shut down and incident response procedures were initiated. No compromise or data breach was found.

The exploit was identified in the PHP code of the MyBB source, and a full backend rewrite is currently in progress. An apology is offered for the lack of earlier communication, explaining that the focus was on ensuring the safety of the infrastructure, the staff, and the community. The message denies any arrests of team members and reassures that the infrastructure is secure. It also warns users not to engage with BreachForums clones, calling them likely honeypots. So, given the PGP signature and corroboration, the message appears authentic.

What were the risks for BreachForums?

BreachForums faced serious risks that could have led to its shutdown, loss of user trust, or legal consequences for its operators. Law enforcement may have exploited a critical vulnerability in the forum’s software to gain covert access, possibly identifying users or collecting evidence. Admin accounts were compromised, and some moderators went silent, hinting at arrests or infiltration. On top of that, the 0day exploit exposed the backend, creating a high risk of surveillance or data leaks.

Fake clones of the forum appeared, likely set up to trick users into revealing sensitive info – classic honeypot strategy. Finally, past data breaches show that user info like IPs and emails could easily be exposed if the forum’s security fails again. In short, the main risk is getting access to the forum backend by law enforcement agencies, with subsequent deanonymization of both users and admins.

By the way, about the admins and their hasty reaction. The admins’ paranoia isn’t just a vibe – it’s survival instinct. One of the original founders was arrested in March 2023 and even did time in jail (even though it was just 17 days). Then in May 2024, the forum got seized again after an Europol-related leak. So yeah, they’ve got a bit of trauma.

BreachForum FBI banner
FBI banner, that once toppled BreachForums’ main page

April 2025, an admin’s Telegram account suddenly redirects to an FBI channel, and two mods vanish into thin air – one deletes their account, the other goes invisible. But the admins later confirmed that law enforcement had been exploiting a MyBB 0day vulnerability, which led to the forum being shut down voluntarily.

There’s also a deep distrust in the community. After the 2024 takedown, no user data was restored, and features like the shoutbox were disabled to reduce attack surfaces. Add in legal risks, constant pressure from law enforcement, and the fact that they’re running an underground operation – that explains a lot.

Current Status

The outage began around April 15, 2025, with initial claims of a DDoS attack by the Dark Storm Team, a pro-Palestinian hacktivist group. Another analysis suggests law enforcement action is more probable. However, given the lack of typical seizure indicators like FBI banners, the latter is unlikely. In addition, DNS records remained with DDoS-Guard, not Cloudflare, typical for FBI seizures.

As of April 30, 2025, no significant updates post the April 28 message, with the forum offline. BreachForums Displays Message About Shutdown, focusing on the message, suggesting ongoing efforts but no return yet.

TAGGED:
Share This Article
Follow:
I write about how to make your Internet browsing comfortable and safe. The modern digital world is worth being a part of, and I want to show you how to do it properly.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?