How the FBI caught the BreachForums admin

on Friday, The U.S. Department of Justice has announced that the now-arrested purported administrator of the notorious hacking forum BreachForums has targeted “millions of U.S. citizens and hundreds of U.S. and foreign companies, organizations, and government agencies.” announced that it facilitated the sale of personal information belonging to it.

In a statement, prosecutors confirmed the arrest of Connor Fitzpatrick, 20, aka Pompompurin, of Peekskill, N.Y. Fitzpatrick faces up to five years in prison if convicted. has been charged with one count of conspiracy to commit access device fraud.

To prove that BreachForums facilitated the buying and selling of stolen and hacked data, an undercover FBI agent purchased five sets of data. Usernames, password hashes, email addresses for approximately 8,000 customers, and payment card information for 1,900 of his customers. Another data set stolen from an unnamed US-based investment firm contains at least 5 million email addresses. Contain personal information of “many Americans,” such as names, email addresses, phone numbers, home addresses, dates of birth, social security numbers, driver’s license numbers, bank names, routing numbers, account numbers; . Another one from the same seller that contained the personal and bank account information of about 15 million Americans. One more he data was obtained from a US healthcare company.

The Federal Bureau of Investigation gathered some evidence to catch Pompompurin. First, they obtained the IP address his Pompompurin used to access RaidForums, the predecessor of BreachForums, which he seized by the FBI in April 2022. Nine of those IP addresses were associated with Fitzpatrick, according to his internet service provider Verizon as an FBI special agent. John Longmire wrote in his March 15 affidavit two days before Fitzpatrick was arrested:

In a nice snafu on the part of the hackers, Longmire writes that the second piece of evidence came from Pompompurin himself. In a chat with RaidForums’ admins, Pompompurin noticed that none of the data breaches posted on the site included “My old email he had one”, and he said that he had made a claim to the legitimate data breach notification site Have I Been. You said you looked it up on Pwned.

Pompompurin then said, “(I don’t want to share the actual email for obvious reasons, but this email seems to be the same case as mine): conorfitzpatrick02@gmail.com” The address that wrote the email in the affidavit was indeed Pompompurin. Because the FBI got records from her Google showing that Fitzpatrick registered the address months before the chat. According to the affidavit, the alleged hacker also had a Google Pay account linked to both his email address and the new address “conorfitzpatrick2002@gmail.com”, both owned by his Fitzpatrick. linked to the number.

Additionally, the agent writes that it has obtained more records from Google. This shows that conorfitzpatrick2002@gmail.com had her address funmc59tm@gmail.com a recovery email linked to her IP address registered to someone with the last name Fitzpatrick and a different phone number. was Agents said they believed it belonged to Fitzpatrick’s father.

Pompompurin then used several VPNs to connect to his Gmail account, some of which overlapped with his activity elsewhere on the Internet, according to the affidavit.

The agent also said the FBI obtained records from cryptocurrency exchange Purse.io. It was also used to connect to a Gmail account and Pompompurin’s RaidForums account. Additionally, that his Purse.io account was registered under his name Conor Fitzpatrick and his email address “conorfitzpatrick2002@gmail.com,” the affidavit states.

According to the agent, these four IP addresses are owned by a VPN provider and were also used by Pompompurin to connect to the ‘conorfitzpatrick2002@gmail.com’ account.

According to the affidavit, another VPN IP address was also used to log into the Zoom account under the name “pompompurin” associated with the Riseup email address that was also used to register the RaidForums account.

Purse.io records also show that Fitzpatrick’s account purchased “several items” and shipped them to an address that had already established that Fitzpatrick’s phone number was Fitzpatrick’s. Also, seven of his nine IP addresses used to connect to Purse.io were also used to connect to his Pompompurin account on RaidForums. Finally, according to the affidavit, the Purse.io account was “exclusively funded by his Bitcoin address, which Pompompurin discussed in his RaidForums post.”

The evidence doesn’t stop there. According to the affidavit, in a database of activity on the RaidForums forums, federal authorities found that Pompompurin had been identified from his IP address registered with Fitzpatrick’s father at the same home address previously identified by authorities. We have confirmed that you have accessed your account.

The same IP address was used to access the iCloud account associated with Fitzpatrick, Longmire wrote in the affidavit.

Additionally, as Pompompurin wrote in his BreachForums post, Longmire pointed out that the RaidForums and BreachForums accounts with the handle Pompompurin are most likely owned by the same person. A user there,” and his new Pompompurin account on BreachForums, “alludes to past activity by the pompompurin account on RaidForums.”

Finally, Longmire writes that the FBI obtained a warrant from Verizon to obtain Fitzpatrick’s real-time cell phone GPS location, and that investigators found Pompompurin logged into BreachForums while his cell phone It was possible to observe that the position of the was indicated to be at his home.

The Federal Bureau of Investigation also monitored Fitzpatrick’s home, and agents noticed Pompompurin’s account was active on the forum.

This pile of evidence allowed law enforcement to obtain a warrant to search Fitzpatrick’s home. Fitzpatrick agreed to speak with the agent, “acknowledging that he is a Pompompurin user of his account,” and that “he owns and manages Bleach Forums and was formerly a RaidForums Pompompurin account.

The FBI did not immediately respond to a request for comment. Fitzpatrick’s attorneys also did not respond to a request for comment.

Ironically, Fitzpatrick may have thought this day would come when he launched BreachForum. In an interview on his website for Data Knight, an interviewer asked him:Why would you want it back knowing you could face the same fate [may be]? “

Pom Pom Purin said, “I don’t really care. I wouldn’t be surprised if I get arrested one day, but like I said, someone I trust who has full access to everything they need to reboot without me. There is

In a statement Friday, the Justice Department also said it “performed a disruptive operation that caused BreachForums to be taken offline.” When asked for comment, DOJ spokesperson Joshua Stueve declined to provide details. At the time of publication, BreachForums was inaccessible and displayed a “bad gateway” error, but the domain still appeared to be under the control of the site’s current administrator.

After the Department of Justice announced Fitzpatrick’s arrest, his successor, known as Baphomet, announced that the forum would be closed.

On Friday, after the affidavit was circulated online, Baphomet wrote a message to his telegram channel, saying, “The most important thing for our community right now is that the FBI has access to the compromised database. It is to recognize that the has been confirmed.” “At this point, the entire document clearly states what I said during my entire time at Breached and that I should never trust anyone to handle my OPSEC. I never made this assumption, and no one else should.”

As such, Baphomet added, “Simply putting everyone back in the same community without figuring out how to move forward safely and properly is basically a death trap.”


Any info on the bleach forums? We’d love to hear from you. From any non-work device, you can securely contact Lorenzo Franceschi-Bicchierai at Signal (+1 917 257 1382). You can also contact TechCrunch via SecureDrop.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *