FBI takes down BreachForums portal used for Salesforce extortion
by V8Virus - 15-10-25, 10:48 PM
#1
The FBI seized a BreachForums domain used by the ShinyHunters group as a data leak extortion site for the widespread Salesforce attacks, with the threat actor stating that law enforcement also stole database backups for the notorious hacking forum.
In October, the domain was converted into a Salesforce data leak site by Scattered Lapsus$ Hunters, a gang claiming to consist of members linked to the Shiny Hunters, Scattered Spider, and Lapsus$ extortion groups, to extort companies impacted by the Salesforce data theft attacks.
On Tuesday, both the clearnet breachforums.hn data leak site and its Tor counterpart went offline. While the Tor site was quickly restored, the breachforums domain remained inaccessible, with its domains switched to Cloudflare nameservers previously used for domains seized by the U.S. government.
In addition to taking down the data leak site, ShinyHunters confirmed that law enforcement gained access to archived databases for previous incarnations of the BreachForums hacking forum.
The ShinyHunters team stated that no one in the core admin team has been arrested, but they will not launch another BreachForums, noting that such sites should be viewed as honeypots from now on.
Catgun
Reply
#2
what is onion url of them?
Reply
#3
(16-10-25, 09:00 AM)JohnyVeber Wrote: what is onion url of them?

This is what I found
Reply
#4
The onion URL is currently inaccessible as well.
Reply
#5
I heard about this, and their is a possibility somebody snitched and cooperated with the FBI to probably get a lenient sentence.
Reply
#6
So BF is gone because they hurt US so badly?
Reply
#7
Anyone have the data? PM, don't say anything here
Reply
#8
BreachForums is live!

Announcement: https://breached.sh/Thread-IMPORTANT-REA...Reinstated

Onion: http://ujdswnhjybusy2i4vcsfpkezrtg27glkx...Reinstated
Ban reason: scamming (Permanent)
Reply
#9
Just tried both .onion sites listed on this thread.... both seem "out of order".... first was a seized domain, and the other (http://ujdswnhjybusy2i4vcsfpkezrtg27glkx...kbyd.onion) didn't respond.

So, I guess no one else appears to have the salesforce breach data, huh?
Reply


Forum Jump:


 Users browsing this thread: 1 Guest(s)