Exploring crypto’s most infamous darkish net cybercrime discussion board

Exploring crypto’s most infamous darkish net cybercrime discussion board

We gained entry to BreachForums, a closed on-line discussion board with a thriving cybercrime neighborhood, to get a way of the services and products being bought on the digital black market of the darkish net.

Right here’s what we discovered.

This text is written for instructional functions, and doesn’t encourage using the darkweb.

What’s the darkish net?

As a fast little bit of background data, let’s make clear what we imply by the darkish net and cybercrime boards. The darkish net is a hidden a part of the web, accessible solely by means of particular searching software program like Tor, that focuses on consumer anonymity.

The darkish net serves as a hub for each authentic makes use of, corresponding to privacy-conscious searching, and unlawful actions, together with the sale of stolen knowledge, medicine, weapons, providers, and different contraband.

Cybercrime boards on the darkish net are communities the place hackers, fraudsters, and different criminals change data, instruments, and providers, usually involving cryptocurrencies to facilitate nameless transactions.

What’s BreachForums?

BreachForums was launched as RaidForums in 2015 by Portuguese hacker Diogo Santos Coelho. RaidForums was began as a neighborhood targeted on ‘raiding’ web sites and on-line areas as a type of pranking, trolling, or on-line disruption.

Nonetheless, as hackers on the location started breaching social media platforms and web sites and stealing tens of millions of consumer credentials, they began to promote these credentials to the very best bidder. RaidForums shortly developed into one of the crucial refined and well-established hubs of organized prison exercise on the darkish net.

When Binance was breached in February 2024, BreachedForums was the primary place that the consumer KYC particulars popped up on the market, and the identical was true of the leaked Bitcoin ATM code used within the state of El Salvador, which appeared on the market on BreachForums in April of the identical yr.

The location began to draw cybercriminals seeking to purchase delicate data from company safety breaches and even leaked authorities paperwork, inflicting it to be the main target of worldwide regulation enforcement efforts.

In 2022, Europol and U.S. intelligence companies collaborated to grab the web site and establish and arrest founder Diogo Santos Coelho who’s now in UK custody awaiting extradition to the US for expenses of cybercrime.

FBI banner positioned on BreachForums following 2022 seizure

RaidForums was shortly re-established as BreachForums by a consumer known as PomPomPurin who was arrested by the FBI in 2023, and the location was taken over by one other consumer known as Baphomet. BreachForums was seized by the FBI in Could 2024, though cloned variations of the location have since popped up as soon as extra.

Whereas the location nonetheless boasts sturdy exercise, as we’re about to point out, many on-line customers have speculated that the web site could also be a ‘honeypot’ or entice arrange by the FBI to watch cybercriminals and expose them for prosecution.

What we discovered on the darkish net crime hub BreachForums

Coming into BreachForums, we had been instantly confronted with a barrage of proposed criminality. Whereas some cybercrime boards undertake a extra delicate strategy of masquerading as communities of IT and cybersecurity lovers, BreachForums has by no means made any such efforts to cover its true nature, and the house web page on the time of our login confirmed customers providing the violent providers of the MS13 or La Mara Salvatruca gang for $10,000.

Like all darkish net postings involving violence, that is extra more likely to be a rip-off than a real supply, however the criminality didn’t cease there. The scrolling chatbox of the web site additionally displayed customers discussing, in real-time, the sale of The discussion board’s market, which is buzzing with sellers providing unlawful merchandise corresponding to stolen knowledge, tutorials on financial institution fraud and bank card fraud, IP monitoring, and rather more.

There was additionally, in fact, a thread of Anime and Manga appreciation as a result of even cybercriminals have hobbies.

Exploring crypto’s most notorious dark web cybercrime forum - 2
Anime thread | supply: BreachForums

The entire posts proven on this article had been posted inside hours of our preliminary login, demonstrating sturdy exercise in a web-based neighborhood that’s nonetheless very lively, though one presumes beneath heavy commentary from regulation enforcement.

The above picture reveals customers promoting entry to every part from on-line video streaming platforms like Paramount Plus and Netflix to breached OnlyFans accounts.

Posts within the leaked knowledge subforum confirmed customers promoting knowledge leaks, together with bundles of electronic mail logins for C-Suite administrators of assorted corporations in addition to ID paperwork from the UAE, India, Qatar, and Saudi Arabia, in addition to a leak of information and pictures stolen from Saudi Arabian navy emails.

This final leak that includes navy paperwork seems real based on our preliminary investigation however was additionally proven to be from 2016, indicating that this consumer is making an attempt to move off previous leaked data as recent, considered one of many examples of the varieties of scams that happen even amongst cybercriminals on-line.

One consumer claimed to have unique entry to an Australian medical health insurance MedBank leak, and Australia’s MedBank was certainly breached by Russian cybercriminals in 2022 when the non-public data of 9.7m Australians was stolen.

Exploring crypto’s most notorious dark web cybercrime forum - 3
Database leaks subforum | supply: BreachForums

Not like the hitman-for-hire kind posts that the darkish net is known for, these doc and identification leaks are sadly very believable, as the primary function of BreachForums is certainly to promote stolen knowledge of this nature, and enterprise has been booming for years.

Nonetheless, with the repeated seizures and arrests by regulation enforcement, it’s attainable that a few of these posts are additionally traps by the FBI or different companies in search of to catch criminals within the act.

Companies discovered on BreachForums

In addition to stolen knowledge, industrious cybercriminals additionally supply varied providers for rent on the darkish net, invariably taking cryptocurrency as cost.

On BreachForums, we instantly discovered customers purporting to supply DDoS providers, entry to a distributed denial of service assault the place criminals leverage a botnet to close down a web site’s operations to both extort cash from the sufferer, goal competing companies or just spite an enemy.

Exploring crypto’s most notorious dark web cybercrime forum - 4
Companies subforum | supply: BreachForums

One on-line group of cybercriminal builders had an commercial for HNVC or Hidden Digital Community Computing providers that can be utilized to realize distant entry to a sufferer’s laptop.

It was attention-grabbing to notice that very similar to an advert for authorized on-line providers, the put up had an in depth listing of options and pricing choices out there and provided buyer help in each Russian and English.

Exploring crypto’s most notorious dark web cybercrime forum - 5
Companies subforum | supply: BreachForums

Different providers included providers to supply cellphone numbers permitting criminals to obtain login codes to activate on-line accounts with out figuring out themselves or their very own cellphone quantity.

We discovered bulk electronic mail senders used for unlawful mass-marketing campaigns for merchandise, phishing scams, or different malware, and in addition noticed ads for electronic mail flooders used to clog up the e-mail inbox of an enemy in an effort to make the e-mail unusable or to cover malicious actions corresponding to warnings of tried logins.

One electronic mail flooder went to the difficulty of making what seems to be an AI-generated banner advert and brand for his or her service, the identify of which we have now censored in order to not promote their providers.

Exploring crypto’s most notorious dark web cybercrime forum - 6
AI-generated advert for darkish net electronic mail flooder | Supply: BreachForums

We noticed whole threads devoted to providers promoting entry to distant on-line servers, programming providers for net growth, and even graphic design providers, all of which might be used to create refined scams corresponding to fraudulent touchdown pages to steal sufferer’s consumer knowledge.

In fact, whereas a few of these providers could also be authentic, lots of them are seemingly faux, and because of the web site being seized and reopened a number of instances, the accounts listed below are all beneath two years previous.

Cybercrime boards usually function on an escrow foundation, or on the idea of belief the place a consumer has a confirmed observe file of ‘honest’ gross sales, whereas this new web site has few measures in place to safeguard in opposition to scams.

We did see a number of providers promoting that they settle for escrow funds, that means a vetted third celebration holds funds till each events are happy with cost, as with this developer providing pre-made phishing web sites and touchdown pages.

Exploring crypto’s most notorious dark web cybercrime forum - 7
Companies subforum | supply: BreachForums

The willingness to simply accept escrow signifies that this consumer could certainly be promoting what they declare to promote, though there are seemingly many scams involving escrow funds on this website as properly.

In actual fact, the location has a whole rip-off thread on the location that reveals a log of customers reporting on-site scams.

Person uuu732 stories that their efforts to rip-off others on-line backfired on account of falling prey to a rip-off on BreachForums themselves. They paid consumer PennyTrate-x $300 for software program that may permit them to bypass malware detection softwares and ship malware-infected PDFs to their unsuspecting victims.

Exploring crypto’s most notorious dark web cybercrime forum - 8
Rip-off Experiences subforum | supply:crypto.information

The vendor didn’t present the products, and when the moderator requested them for a proof, they declined to reply, resulting in their account getting banned.

One other consumer reported a dispute with a distinct vendor. On this case, the consumer spent $500 making an attempt to buy database of consumer credentials breached from a Swiss insurance coverage firm and a further $1,300 making an attempt to buy the database of a Swiss retail outlet. They reported that they didn’t obtain their illicit knowledge in both transaction.

What do darkish net criminals do with stolen consumer knowledge?

Cybercriminals purchase login knowledge and consumer knowledge in an effort to hack electronic mail and social media accounts to both acquire entry to a consumer’s funds and rob them, or to realize entry to delicate data that they’ll additional exploit.

For instance, a darkish web prison would possibly entry a consumer’s PayPal account and attempt to make unauthorized purchases or switch funds straight to a different account, or commit identification theft by making use of for loans in another person’s identify utilizing their passport data.

This data can be generally used for extortion and blackmail functions when criminals discover delicate data by logging into their sufferer’s accounts.

The best way to keep secure on-line

As we will see, the darkish net is a harmful subsection of the web for a lot of causes. Even on this web site that has been seized and reopened a number of instances, we discover an open-air bazaar of prison exercise starting from unlawful providers and merchandise to scams being perpetrated in opposition to different members of the discussion board.

On the clearnet, customers can keep secure by implementing two-factor authentication on their units and on-line accounts, that means a second gadget like their cellphone is required to register to an account. This may help forestall hacking and phishing assaults. Likewise, taking care to confirm URLs on-line to make sure that they’re right and never mispelled or fraudulent may help forestall falling prey to an assault.

Unsuspecting customers visiting the darkish net, even purely out of non-public curiosity, will discover themselves rubbing shoulders with seasoned scammers and hackers probing for any weak point they’ll discover. Customers visiting the darkish net ought to keep away from clicking on any unfamiliar hyperlinks or downloading any information, and whereas it ought to go with out saying, making a purchase order of any sort can open you as much as every kind of hassle from each authorized and non-legal actors.

In actual fact, the easiest way to remain secure from the darkish net is solely to not go to it within the first place! Allow us to try this for you. We intention to go to different corners of the darkish net frequently and provides common updates on our findings, holding you updated on the underbelly of the worldwide web.

The best way to get to the darkish net on a Chromebook?

Individuals ask this on a regular basis, and the reply is a bit difficult. Firstly, we don’t advocate that anybody accesses the darkish net! Whereas the area is attention-grabbing to discover from a journalistic viewpoint, it’s additionally filled with scammers and different varieties of criminals that may be harmful to return throughout. To get to the darkish net on a Chromebook, individuals usually set up Linux through the Crostini app and easily add the Tor browser repository to realize entry to Tor’s hidden serices, AKA the darkish net. Nonetheless, as soon as once more, this isn’t really useful until carried out for analysis or journalism functions.

Why is the darkish net so creepy?

The darkish net has a fame for being ‘creepy’ partly because of the prevalence of standard YouTube movies which confirmed YouTubers claiming to open ‘mystery boxes’ from the darkish net, in addition to the recognition of quick tales and ‘creepypastas’ which featured the darkish net in horror fiction.

In actuality, these movies are usually staged, and the darkish net is commonly extra businesslike. Individuals normally entry it both to share data with out being censored or persecuted, corresponding to political whistleblowers, or, in fact, to perpetrate cybercrime and deal in contraband.

The best way to examine my if my electronic mail is on darkish net?

Whereas breached electronic mail addresses are bought on web sites like Nulled, you don’t have to entry the darkish net to see in case your electronic mail is there. To examine in case your electronic mail is on the darkish net, you should utilize the Have I Been PWNed device on the clear web as a substitute.

Is the darkish net actual?

Sure, the darkish net may be very actual! Giant sums of cash are exchanged within the sale of narcotics, breached on-line accounts, malware, weapons, hacking providers for rent, and different types of contraband.

What to do if electronic mail is on darkish net?

In case your electronic mail is discovered to be on the darkish net, you must change your password instantly and establishing two-factor authentication (2FA). In the event you’re discovering that individuals are nonetheless making an attempt to entry your account, corresponding to with emails in your inbox asking you to verify logins, you would possibly wish to think about altering your electronic mail tackle altogether.

Supply hyperlink

bitcoin
Bitcoin (BTC) $ 84,228.57 0.14%
ethereum
Ethereum (ETH) $ 1,995.45 1.18%
tether
Tether (USDT) $ 1.00 0.03%
xrp
XRP (XRP) $ 2.38 0.88%
bnb
BNB (BNB) $ 625.95 1.65%
solana
Solana (SOL) $ 129.79 1.28%
usd-coin
USDC (USDC) $ 1.00 0.00%
cardano
Cardano (ADA) $ 0.707467 0.94%
dogecoin
Dogecoin (DOGE) $ 0.169171 0.50%
tron
TRON (TRX) $ 0.235678 0.54%
staked-ether
Lido Staked Ether (STETH) $ 1,996.14 1.41%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 84,097.53 0.12%
chainlink
Chainlink (LINK) $ 14.42 2.85%
leo-token
LEO Token (LEO) $ 9.79 0.66%
the-open-network
Toncoin (TON) $ 3.63 0.02%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,379.84 0.78%
stellar
Stellar (XLM) $ 0.278718 0.20%
avalanche-2
Avalanche (AVAX) $ 19.61 4.11%
usds
USDS (USDS) $ 1.00 0.01%
hedera-hashgraph
Hedera (HBAR) $ 0.184665 0.75%
shiba-inu
Shiba Inu (SHIB) $ 0.000013 1.92%
sui
Sui (SUI) $ 2.29 0.71%
litecoin
Litecoin (LTC) $ 91.87 0.87%
polkadot
Polkadot (DOT) $ 4.52 0.47%
pi-network
Pi Network (PI) $ 0.998931 8.82%
bitcoin-cash
Bitcoin Cash (BCH) $ 325.31 0.88%
mantra-dao
MANTRA (OM) $ 6.36 0.71%
bitget-token
Bitget Token (BGB) $ 4.70 1.81%
weth
WETH (WETH) $ 1,995.99 1.18%
ethena-usde
Ethena USDe (USDE) $ 0.999808 0.08%
hyperliquid
Hyperliquid (HYPE) $ 15.90 4.39%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.03%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,121.26 1.28%
whitebit
WhiteBIT Coin (WBT) $ 28.78 0.99%
uniswap
Uniswap (UNI) $ 6.84 0.86%
monero
Monero (XMR) $ 214.27 0.96%
aptos
Aptos (APT) $ 5.76 2.47%
near
NEAR Protocol (NEAR) $ 2.78 1.22%
susds
sUSDS (SUSDS) $ 1.05 0.05%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.16 0.11%
dai
Dai (DAI) $ 1.00 0.03%
okb
OKB (OKB) $ 51.85 0.79%
pepe
Pepe (PEPE) $ 0.000007 0.15%
gatechain-token
Gate (GT) $ 22.97 0.59%
internet-computer
Internet Computer (ICP) $ 5.80 1.55%
tokenize-xchange
Tokenize Xchange (TKX) $ 34.56 4.70%
aave
Aave (AAVE) $ 181.64 1.46%
ethereum-classic
Ethereum Classic (ETC) $ 17.91 0.90%
ondo-finance
Ondo (ONDO) $ 0.836853 1.06%
mantle
Mantle (MNT) $ 0.786002 0.13%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 84,300.59 0.21%
first-digital-usd
First Digital USD (FDUSD) $ 0.998988 0.01%
crypto-com-chain
Cronos (CRO) $ 0.081758 4.25%
cosmos
Cosmos Hub (ATOM) $ 5.01 8.43%
official-trump
Official Trump (TRUMP) $ 11.00 0.69%
vechain
VeChain (VET) $ 0.025553 0.73%
bittensor
Bittensor (TAO) $ 252.20 1.63%
kaspa
Kaspa (KAS) $ 0.079702 1.63%
filecoin
Filecoin (FIL) $ 3.03 3.16%
ethena
Ethena (ENA) $ 0.35761 0.78%
celestia
Celestia (TIA) $ 3.46 1.92%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.210378 1.55%
lombard-staked-btc
Lombard Staked BTC (LBTC) $ 84,180.55 0.13%
render-token
Render (RENDER) $ 3.35 4.23%
fasttoken
Fasttoken (FTN) $ 4.03 0.00%
arbitrum
Arbitrum (ARB) $ 0.371545 1.87%
sonic-3
Sonic (prev. FTM) (S) $ 0.515083 3.28%
algorand
Algorand (ALGO) $ 0.189774 0.38%
story-2
Story (IP) $ 6.00 3.59%
arbitrum-bridged-usdt-arbitrum
Arbitrum Bridged USDT (Arbitrum) (USDT) $ 1.00 0.06%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
jupiter-exchange-solana
Jupiter (JUP) $ 0.530399 1.98%
optimism
Optimism (OP) $ 0.87146 1.80%
kucoin-shares
KuCoin (KCS) $ 11.29 0.73%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 0.523055 2.91%
solv-btc
Solv Protocol SolvBTC (SOLVBTC) $ 84,099.53 0.06%
binance-peg-weth
Binance-Peg WETH (WETH) $ 1,996.02 1.21%
xdce-crowd-sale
XDC Network (XDC) $ 0.07311 1.29%
nexo
NEXO (NEXO) $ 1.14 0.53%
quant-network
Quant (QNT) $ 77.26 1.61%
kelp-dao-restaked-eth
Kelp DAO Restaked ETH (RSETH) $ 2,074.27 1.28%
entangle
Entangle (NTGL) $ 0.001861 10.47%
immutable-x
Immutable (IMX) $ 0.610165 13.88%
movement
Movement (MOVE) $ 0.437856 3.29%
maker
Maker (MKR) $ 1,252.18 1.61%
dexe
DeXe (DEXE) $ 17.83 6.15%
worldcoin-wld
Worldcoin (WLD) $ 0.838274 1.48%
rocket-pool-eth
Rocket Pool ETH (RETH) $ 2,255.34 1.23%
injective-protocol
Injective (INJ) $ 10.02 3.44%
binance-staked-sol
Binance Staked SOL (BNSOL) $ 135.46 1.41%
bonk
Bonk (BONK) $ 0.000012 5.38%
blockstack
Stacks (STX) $ 0.631521 1.60%
usual-usd
Usual USD (USD0) $ 0.997835 0.04%
sei-network
Sei (SEI) $ 0.19387 1.66%
theta-token
Theta Network (THETA) $ 0.943326 2.75%
the-graph
The Graph (GRT) $ 0.097151 2.61%
lido-dao
Lido DAO (LDO) $ 1.03 3.40%
flare-networks
Flare (FLR) $ 0.014741 0.23%
paypal-usd
PayPal USD (PYUSD) $ 1.00 0.04%
eos
EOS (EOS) $ 0.555249 0.91%
Scroll to Top