We gained entry to BreachForums, a closed on-line discussion board with a thriving cybercrime group, to get a way of the services and products being bought on the digital black market of the darkish net.
Right here’s what we discovered.
This text is written for academic functions, and doesn’t encourage the usage of the darkweb.
What’s the darkish net?
As a fast little bit of background info, let’s make clear what we imply by the darkish net and cybercrime boards. The darkish net is a hidden a part of the web, accessible solely by means of particular shopping software program like Tor, that focuses on person anonymity.
The darkish net serves as a hub for each reputable makes use of, resembling privacy-conscious shopping, and unlawful actions, together with the sale of stolen knowledge, medicine, weapons, companies, and different contraband.
Cybercrime boards on the darkish net are communities the place hackers, fraudsters, and different criminals alternate info, instruments, and companies, typically involving cryptocurrencies to facilitate nameless transactions.
What’s BreachForums?
BreachForums was launched as RaidForums in 2015 by Portuguese hacker Diogo Santos Coelho. RaidForums was began as a group centered on ‘raiding’ web sites and on-line areas as a type of pranking, trolling, or on-line disruption.
Nonetheless, as hackers on the positioning started breaching social media platforms and web sites and stealing thousands and thousands of person credentials, they began to promote these credentials to the best bidder. RaidForums rapidly developed into probably the most subtle and well-established hubs of organized prison exercise on the darkish net.
When Binance was breached in February 2024, BreachedForums was the primary place that the person KYC particulars popped up on the market, and the identical was true of the leaked Bitcoin ATM code used within the state of El Salvador, which appeared on the market on BreachForums in April of the identical yr.
The positioning began to draw cybercriminals trying to purchase delicate info from company safety breaches and even leaked authorities paperwork, inflicting it to be the main target of worldwide legislation enforcement efforts.
In 2022, Europol and U.S. intelligence businesses collaborated to grab the web site and establish and arrest founder Diogo Santos Coelho who’s now in UK custody awaiting extradition to the US for costs of cybercrime.
RaidForums was rapidly re-established as BreachForums by a person referred to as PomPomPurin who was arrested by the FBI in 2023, and the positioning was taken over by one other person referred to as Baphomet. BreachForums was seized by the FBI in Could 2024, though cloned variations of the positioning have since popped up as soon as extra.
Whereas the positioning nonetheless boasts sturdy exercise, as we’re about to indicate, many on-line customers have speculated that the web site could also be a ‘honeypot’ or lure arrange by the FBI to watch cybercriminals and expose them for prosecution.
What we discovered on the darkish net crime hub BreachForums
Coming into BreachForums, we had been instantly confronted with a barrage of proposed criminality. Whereas some cybercrime boards undertake a extra refined strategy of masquerading as communities of IT and cybersecurity fanatics, BreachForums has by no means made any such efforts to cover its true nature, and the house web page on the time of our login confirmed customers providing the violent companies of the MS13 or La Mara Salvatruca gang for $10,000.
Like all darkish net postings involving violence, that is extra prone to be a rip-off than a real provide, however the criminality didn’t cease there. The scrolling chatbox of the web site additionally displayed customers discussing, in real-time, the sale of The discussion board’s market, which is buzzing with sellers providing unlawful merchandise resembling stolen knowledge, tutorials on financial institution fraud and bank card fraud, IP monitoring, and far more.
There was additionally, in fact, a thread of Anime and Manga appreciation as a result of even cybercriminals have hobbies.
The entire posts proven on this article had been posted inside hours of our preliminary login, demonstrating sturdy exercise in a web-based group that’s nonetheless very energetic, though one presumes below heavy commentary from legislation enforcement.
The above picture exhibits customers promoting entry to every part from on-line video streaming platforms like Paramount Plus and Netflix to breached OnlyFans accounts.
Posts within the leaked knowledge subforum confirmed customers promoting knowledge leaks, together with bundles of e mail logins for C-Suite administrators of varied firms in addition to ID paperwork from the UAE, India, Qatar, and Saudi Arabia, in addition to a leak of information and pictures stolen from Saudi Arabian navy emails.
This final leak that includes navy paperwork seems real in response to our preliminary investigation however was additionally proven to be from 2016, indicating that this person is making an attempt to go off outdated leaked info as recent, certainly one of many examples of the sorts of scams that happen even amongst cybercriminals on-line.
One person claimed to have unique entry to an Australian medical insurance MedBank leak, and Australia’s MedBank was certainly breached by Russian cybercriminals in 2022 when the private info of 9.7m Australians was stolen.
Not like the hitman-for-hire kind posts that the darkish net is legendary for, these doc and id leaks are sadly very believable, as the primary function of BreachForums is certainly to promote stolen knowledge of this nature, and enterprise has been booming for years.
Nonetheless, with the repeated seizures and arrests by legislation enforcement, it’s potential that a few of these posts are additionally traps by the FBI or different businesses in search of to catch criminals within the act.
Providers discovered on BreachForums
In addition to stolen knowledge, industrious cybercriminals additionally provide numerous companies for rent on the darkish net, invariably taking cryptocurrency as cost.
On BreachForums, we instantly discovered customers purporting to supply DDoS companies, entry to a distributed denial of service assault the place criminals leverage a botnet to close down an internet site’s operations to both extort cash from the sufferer, goal competing companies or just spite an enemy.
One on-line group of cybercriminal builders had an commercial for HNVC or Hidden Digital Community Computing companies that can be utilized to realize distant entry to a sufferer’s laptop.
It was attention-grabbing to notice that very similar to an advert for authorized on-line companies, the publish had an in depth checklist of options and pricing choices obtainable and supplied buyer assist in each Russian and English.
Different companies included companies to offer cellphone numbers permitting criminals to obtain login codes to activate on-line accounts with out figuring out themselves or their very own cellphone quantity.
We discovered bulk e mail senders used for unlawful mass-marketing campaigns for merchandise, phishing scams, or different malware, and in addition noticed ads for e mail flooders used to clog up the e-mail inbox of an enemy in an effort to make the e-mail unusable or to cover malicious actions resembling warnings of tried logins.
One e mail flooder went to the difficulty of making what seems to be an AI-generated banner advert and brand for his or her service, the title of which we have now censored in order to not promote their companies.
We noticed complete threads devoted to companies promoting entry to distant on-line servers, programming companies for net growth, and even graphic design companies, all of which may very well be used to create subtle scams resembling fraudulent touchdown pages to steal sufferer’s person knowledge.
After all, whereas a few of these companies could also be reputable, a lot of them are possible faux, and as a result of web site being seized and reopened a number of instances, the accounts listed below are all below two years outdated.
Cybercrime boards typically function on an escrow foundation, or on the idea of belief the place a person has a confirmed observe file of ‘sincere’ gross sales, whereas this new web site has few measures in place to safeguard in opposition to scams.
We did see a number of companies promoting that they settle for escrow funds, which means a vetted third social gathering holds funds till each events are happy with cost, as with this developer providing pre-made phishing web sites and touchdown pages.
The willingness to simply accept escrow signifies that this person could certainly be promoting what they declare to promote, though there are possible many scams involving escrow funds on this web site as nicely.
In reality, the positioning has a complete rip-off thread on the positioning that exhibits a log of customers reporting on-site scams.
Person uuu732 studies that their efforts to rip-off others on-line backfired attributable to falling prey to a rip-off on BreachForums themselves. They paid person PennyTrate-x $300 for software program that might enable them to bypass malware detection softwares and ship malware-infected PDFs to their unsuspecting victims.

The vendor didn’t present the products, and when the moderator requested them for a proof, they declined to reply, resulting in their account getting banned.
One other person reported a dispute with a special vendor. On this case, the person spent $500 making an attempt to buy database of person credentials breached from a Swiss insurance coverage firm and an extra $1,300 making an attempt to buy the database of a Swiss retail outlet. They reported that they didn’t obtain their illicit knowledge in both transaction.
What do darkish net criminals do with stolen person knowledge?
Cybercriminals purchase login knowledge and person knowledge in an effort to hack e mail and social media accounts to both achieve entry to a person’s funds and rob them, or to realize entry to delicate info that they’ll additional exploit.
For instance, a darkish internet prison may entry a person’s PayPal account and attempt to make unauthorized purchases or switch funds straight to a different account, or commit id theft by making use of for loans in another person’s title utilizing their passport info.
This info can also be generally used for extortion and blackmail functions when criminals discover delicate info by logging into their sufferer’s accounts.
How you can keep secure on-line
As we will see, the darkish net is a harmful subsection of the web for a lot of causes. Even on this web site that has been seized and reopened a number of instances, we discover an open-air bazaar of prison exercise starting from unlawful companies and merchandise to scams being perpetrated in opposition to different members of the discussion board.
On the clearnet, customers can keep secure by implementing two-factor authentication on their gadgets and on-line accounts, which means a second machine like their cellphone is required to sign up to an account. This may also help stop hacking and phishing assaults. Likewise, taking care to confirm URLs on-line to make sure that they’re right and never mispelled or fraudulent may also help stop falling prey to an assault.
Unsuspecting customers visiting the darkish net, even purely out of private curiosity, will discover themselves rubbing shoulders with seasoned scammers and hackers probing for any weak point they’ll discover. Customers visiting the darkish net ought to keep away from clicking on any unfamiliar hyperlinks or downloading any information, and whereas it ought to go with out saying, making a purchase order of any variety can open you as much as every kind of hassle from each authorized and non-legal actors.
In reality, the easiest way to remain secure from the darkish net is solely to not go to it within the first place! Allow us to try this for you. We goal to go to different corners of the darkish net frequently and provides common updates on our findings, preserving you updated on the underbelly of the worldwide web.
How you can get to the darkish net on a Chromebook?
Folks ask this on a regular basis, and the reply is a little bit sophisticated. Firstly, we don’t advocate that anybody accesses the darkish net! Whereas the area is attention-grabbing to discover from a journalistic standpoint, it’s additionally stuffed with scammers and different sorts of criminals that may be harmful to come back throughout. To get to the darkish net on a Chromebook, folks sometimes set up Linux by way of the Crostini app and easily add the Tor browser repository to realize entry to Tor’s hidden serices, AKA the darkish net. Nonetheless, as soon as once more, this isn’t advisable except carried out for analysis or journalism functions.
Why is the darkish net so creepy?
The darkish net has a popularity for being ‘creepy’ partly as a result of prevalence of in style YouTube movies which confirmed YouTubers claiming to open ‘thriller containers’ from the darkish net, in addition to the recognition of brief tales and ‘creepypastas’ which featured the darkish net in horror fiction.
In actuality, these movies are sometimes staged, and the darkish net is commonly extra businesslike. Folks often entry it both to share info with out being censored or persecuted, resembling political whistleblowers, or, in fact, to perpetrate cybercrime and deal in contraband.
How you can test my if my e mail is on darkish net?
Whereas breached e mail addresses are bought on web sites like Nulled, you don’t must entry the darkish net to see in case your e mail is there. To test in case your e mail is on the darkish net, you should use the Have I Been PWNed device on the clear internet as an alternative.
Is the darkish net actual?
Sure, the darkish net may be very actual! Massive sums of cash are exchanged within the sale of narcotics, breached on-line accounts, malware, weapons, hacking companies for rent, and different types of contraband.
What to do if e mail is on darkish net?
In case your e mail is discovered to be on the darkish net, you need to change your password instantly and establishing two-factor authentication (2FA). Should you’re discovering that individuals are nonetheless making an attempt to entry your account, resembling with emails in your inbox asking you to substantiate logins, you may need to contemplate altering your e mail deal with altogether.


