Ransomware victim disclosure
← All victimsBreachForums
listed as BreachForums version 5 · Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 26, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Listed on leak site
- Mar 26, 2026
About the victim
AI dossier — public-source company profileBreachForums is a well-known underground hacking and data-breach forum that has operated under multiple administrators following repeated law enforcement seizures, including an FBI takedown. It facilitates the buying, selling, and sharing of stolen data and hacking tools. The forum has gone through numerous iterations and domain changes across its history.
- Industry
- Cybercrime & Hacking Forum
Attack summary
Severity: high — The threatened data includes PII such as IP addresses and email addresses of forum members at scale, along with private communications. Full exposure of this data would de-anonymise a large number of individuals, many of whom may be threat actors or victims themselves, representing significant downstream harm.ShinyHunters claims to hold full backups of BreachForums obtained after the FBI seizure on 10 Oct 2025, and threatens to publish all private messages, email addresses, IP addresses, and posts if impostor forums continue operating. The group is leveraging possession of the data as coercion rather than a traditional ransomware demand.
Data the group says was taken
AI dossier — extracted from the leak post- Private messages
- Email addresses
- IP addresses
- Forum posts
- Full site database backups
What the group claims
BreachForums has been run by many fakes, but by us, following the FBI seizure on 10 Oct 2025. Maintaining such an ecosystem is a waste of our time. There was an unauthorised leak on 9 Jan 2026. Ever since then, false personas going by “N/A“ and “Indra“ were successfully able to restore a similar-looking “legitimate“ forum. All the current forums are fake [ .sb, .ac, .fi, .bf, .us, ect.]. If they continue to exist, we'll leak all the BF backups, including every private message, emails, IP addresses, posts, ect. We have exploits for all 1.8 versions of MyBB.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

