en
Feedback
Intelligence X

Intelligence X

Open in Telegram

intelx.io - search engine & data archive

Show more
The country is not specifiedTechnologies & Applications15 181
7 004
Subscribers
No data24 hours
+57 days
+8830 days
Posts Archive
There are related hacks in which defendant has not yet been charged. One is the Twitter hack Conor Brian Fitzpatrick admitted: https://bleepingcomputer.com/news/security/54-million-twitter-users-stolen-data-leaked-online-more-shared-privately/ The forum screenshot is dated 07.07.2022.

+1
image_2023-03-26_12-36-42.png1.40 KB

+2
image_2023-03-26_12-35-30.png2.86 KB

Here is an archived interview of Conor Brian Fitzpatrick about his criminal enterprise from Mar 16, 2022: https://web.archive.org/web/20220317205735/https://dataknight.org/exclusive-interview-with-pompompurin/ This interview shows his state of mind (mens rea) at the time. He expected a takedown, and prepared for it. "If I get arrested one day it also wouldn't surprise me"

Defendant kept abusing our free service in 2021, hijacking .edu email accounts to scrape our API, which forced us to restrict the free version. Instead of appreciating our free tier, he abused it & kept mocking our service: https://twitter.com/pompompur_in/status/1422829712498376706 (suspended) It then quickly escalated in 2022 to death threats, rape threats, swatting threats, doxxing including family members of our employees, copyright infringement, trademark infringement, hacking, bomb & terrorism threats, Czech police had to get involved, lawyers hired, etc. The actions of Conor Brian Fitzpatrick, Moeen Malik, and other defendants caused a lot of real damage to real people. We will hold them accountable. More criminal & civil complaints are being prepared. Defendant's log reveal he even searched for the email address "mccarrafitz@hotmail.com", as well as conorfitz_1@icloud.com, and conorfitz@optimum.net - from hijacked edu email accounts which he used under his 'pompompurin' persona. We wouldn't have been aware of his accounts, and the miuse of the .edu accounts, if it wasn't for his consistent and constant bragging and mockery and attacks.

On August 5, 2021, we already knew about defendants real identity without fully realizing it. Our internal assessment was at the time: "conorfitzpatrick" was "probably one of his aliases".

This gem is worth mentioning extra: "records obtained from the SQL database of forum activity on BreachForums" This means anyone who logged in via breached[.]co/to/vc might be in trouble. 🚔 The FBI is now in possession of the SQL database of RaidForums and BreachForums.

+2
image_2023-03-24_16-23-00.png1.09 KB

Defendant had almost no OPSEC. He logged into his RaidForums account from his real Verizon IP. He logged into many real personal accounts and hacker accounts from the same IP, multiple times. He used his personal Gmail addresses conorfitzpatrick02@gmail.com and conorfitzpatrick2002@gmail.com in a variety activities that are connected to his pompompurin persona.

31-page affidavit on pompompurin, his missing OPSEC, and his crimes.

+2
image_2023-03-24_09-41-09.png2.25 KB

How the forum started: Defendant Conor Brian Fitzpatrick tagged the FBI in his tweet announcing the forum. Here are all tweets from Conor Brian Fitzpatrick Twitter account "@xml" are archived and searchable: https://intelx.io/?did=8630eb0d-be98-4ec5-902a-f1e107baeccc 🔓

+1
image_2023-03-24_09-38-26.png0.65 KB

The second admin of BreachForums "Baphomet" initially claimed to move the forum to a new server, then decided to shut it down. According to him "someone logged in" to the CDN server.

+3
image_2023-03-24_09-35-24.png1.80 KB

Update to this story: Conor Brian Fitzpatrick, alias pompompurin, has been arrested on March 15, 2023 in Peekskill, New York. He has been charged "with one count of conspiracy to solicit individuals with the purpose of selling unauthorized access devices, in violation of Title 18, United States Code, Section 1029 (b)(2)". It appears that our assessment at the time was correct. The IP address we published shows New York as geo-location. The court records United States v. Fitzpatrick (7:23-cr-02171) appear to be sealed at the moment. According to the docket, today the "Defendant to appear in the Eastern District of Virginia on March 24, 2023 at 12 pm. " Court documents and other relevant public sources are indexed here: https://intelx.io/?s=9e8c95de-c08e-401a-b2dd-c101463b7318 🔓 Some of the news coverage: * https://krebsonsecurity.com/2023/03/feds-charge-ny-man-as-breachforums-boss-pompompurin/ * https://www.bleepingcomputer.com/news/security/alleged-breachforums-owner-pompompurin-arrested-on-cybercrime-charges/ * https://thehackernews.com/2023/03/pompompurin-unmasked-infamous.html * Local news report: https://peekskillherald.com/7107/news/fbi-arrests-alleged-cybercriminal-in-peekskill/ * https://blog.cyble.com/2023/03/20/wave-of-arrests-hits-cybercriminals/

+2
image_2023-01-08_00-07-22.png1.05 KB

Some of the bad actors got terrible OPSEC. One moderator "lain" of a forum got apparently raided in Chile due to credit card fraud. According to chat logs from 03.07.2022 (third attached screenshot), he previously ddosed the Chilean government. We will reach out to Chilean authorities.

Threat actor pompompurin bragged about how he registered an account on our site (he used the email badhou3a@protonmail.com), so we'll send all his details straight to the FBI to help in their investigation. The threat actor still uses his emails pom@pompur.in and pompompurin@riseup.net,