World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison

World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison

Conor Brian Fitzpatrick, the 22-year-old founder of BreachForums, has been resentenced to three years in federal prison for operating one of the world’s largest cybercriminal marketplaces. 

The New York resident was sentenced on September 16, 2025, for creating and administering a platform that facilitated the sale of stolen data and harbored child sexual abuse material (CSAM).

Key Takeaways
1. Conor Fitzpatrick received three years for running BreachForums.
2. The forum amassed 330 K users and 14 B stolen records.
3. He forfeited domains, devices, and crypto amid the DOJ crackdown.

The resentencing follows a U.S. Court of Appeals for the Fourth Circuit decision on January 21, 2025, which vacated Fitzpatrick’s original lenient sentence of 17 days served and ordered a new sentencing hearing. 

Google News

Fitzpatrick pleaded guilty to access device conspiracy (18 U.S.C. § 1029), access device solicitation, and possession of CSAM under federal statutes.

BreachForums: The Global Hub for Stolen Data

BreachForums emerged in March 2022 as the successor to RaidForums, which law enforcement seized in February 2022. 

The platform rapidly expanded to over 330,000 registered users, establishing itself as the premier English-language hacking forum globally. 

The marketplace specialized in trafficking personally identifiable information (PII), including Social Security numbers, bank account credentials, and authentication tokens from major data breaches.

The Department of Justice stated that the forum maintained access to 888 datasets containing over 14 billion individual records of stolen information. 

Notable breaches included a database with contact information for approximately 200 million users of a major U.S. social networking platform and sensitive details of 87,760 InfraGard members—a critical infrastructure protection partnership between the FBI and private sector entities. 

The platform also trafficked credentials from telecommunications providers, healthcare services, and internet service providers.

As part of his plea agreement, Fitzpatrick forfeited over 100 domain names associated with BreachForums’ infrastructure, more than a dozen electronic devices used in the criminal enterprise, and cryptocurrency proceeds generated from the illegal marketplace. 

The Computer Crime and Intellectual Property Section (CCIPS) led the prosecution, which has secured convictions of over 180 cybercriminals since 2020 and facilitated the return of over $350 million to victims.

Acting Assistant Attorney General Matthew R. Galeotti emphasized the Justice Department’s commitment to dismantling cybercriminal infrastructure, stating that operators of similar forums should expect relentless investigation and prosecution. 

The FBI’s Washington Field Office conducted the investigation under its Cyber Division’s ongoing efforts to combat dark web marketplaces that enable data theft, fraud, and other cybercrimes targeting critical infrastructure and private citizens.

Free live webinar on new malware tactics from our analysts! Learn advanced detection techniques -> Register for Free


Source link

About Cybernoz

Security researcher and threat analyst with expertise in malware analysis and incident response.