Intelligence X
Open in Telegram
intelx.io - search engine & data archive
Show moreThe country is not specifiedTechnologies & Applications15 181
7 004
Subscribers
No data24 hours
+57 days
+8830 days
Posts Archive
7 004
There are related hacks in which defendant has not yet been charged. One is the Twitter hack Conor Brian Fitzpatrick admitted:
https://bleepingcomputer.com/news/security/54-million-twitter-users-stolen-data-leaked-online-more-shared-privately/
The forum screenshot is dated 07.07.2022.
7 004
The official DOJ announcement about the arrest of Conor Brian Fitzpatrick:
https://www.justice.gov/opa/pr/justice-department-announces-arrest-founder-one-world-s-largest-hacker-forums-and-disruption
7 004
Here is an archived interview of Conor Brian Fitzpatrick about his criminal enterprise from Mar 16, 2022:
https://web.archive.org/web/20220317205735/https://dataknight.org/exclusive-interview-with-pompompurin/
This interview shows his state of mind (mens rea) at the time. He expected a takedown, and prepared for it.
"If I get arrested one day it also wouldn't surprise me"
7 004
Defendant kept abusing our free service in 2021, hijacking .edu email accounts to scrape our API, which forced us to restrict the free version.
Instead of appreciating our free tier, he abused it & kept mocking our service:
https://twitter.com/pompompur_in/status/1422829712498376706 (suspended)
It then quickly escalated in 2022 to death threats, rape threats, swatting threats, doxxing including family members of our employees, copyright infringement, trademark infringement, hacking, bomb & terrorism threats, Czech police had to get involved, lawyers hired, etc.
The actions of Conor Brian Fitzpatrick, Moeen Malik, and other defendants caused a lot of real damage to real people. We will hold them accountable. More criminal & civil complaints are being prepared.
Defendant's log reveal he even searched for the email address "mccarrafitz@hotmail.com", as well as conorfitz_1@icloud.com, and conorfitz@optimum.net - from hijacked edu email accounts which he used under his 'pompompurin' persona.
We wouldn't have been aware of his accounts, and the miuse of the .edu accounts, if it wasn't for his consistent and constant bragging and mockery and attacks.
7 004
On August 5, 2021, we already knew about defendants real identity without fully realizing it.
Our internal assessment was at the time: "conorfitzpatrick" was "probably one of his aliases".
7 004
This gem is worth mentioning extra: "records obtained from the SQL database of forum activity on BreachForums"
This means anyone who logged in via breached[.]co/to/vc might be in trouble. 🚔
The FBI is now in possession of the SQL database of RaidForums and BreachForums.
7 004
Defendant had almost no OPSEC. He logged into his RaidForums account from his real Verizon IP.
He logged into many real personal accounts and hacker accounts from the same IP, multiple times. He used his personal Gmail addresses conorfitzpatrick02@gmail.com and conorfitzpatrick2002@gmail.com in a variety activities that are connected to his pompompurin persona.
7 004
How the forum started: Defendant Conor Brian Fitzpatrick tagged the FBI in his tweet announcing the forum.
Here are all tweets from Conor Brian Fitzpatrick Twitter account "@xml" are archived and searchable:
https://intelx.io/?did=8630eb0d-be98-4ec5-902a-f1e107baeccc 🔓
7 004
The second admin of BreachForums "Baphomet" initially claimed to move the forum to a new server, then decided to shut it down. According to him "someone logged in" to the CDN server.
7 004
Update to this story: Conor Brian Fitzpatrick, alias pompompurin, has been arrested on March 15, 2023 in Peekskill, New York.
He has been charged "with one count of conspiracy to solicit individuals with the purpose of selling unauthorized access devices, in violation of Title 18, United States Code, Section 1029 (b)(2)".
It appears that our assessment at the time was correct. The IP address we published shows New York as geo-location.
The court records United States v. Fitzpatrick (7:23-cr-02171) appear to be sealed at the moment. According to the docket, today the "Defendant to appear in the Eastern District of Virginia on March 24, 2023 at 12 pm. "
Court documents and other relevant public sources are indexed here:
https://intelx.io/?s=9e8c95de-c08e-401a-b2dd-c101463b7318 🔓
Some of the news coverage:
* https://krebsonsecurity.com/2023/03/feds-charge-ny-man-as-breachforums-boss-pompompurin/
* https://www.bleepingcomputer.com/news/security/alleged-breachforums-owner-pompompurin-arrested-on-cybercrime-charges/
* https://thehackernews.com/2023/03/pompompurin-unmasked-infamous.html
* Local news report: https://peekskillherald.com/7107/news/fbi-arrests-alleged-cybercriminal-in-peekskill/
* https://blog.cyble.com/2023/03/20/wave-of-arrests-hits-cybercriminals/
7 004
Some of the bad actors got terrible OPSEC. One moderator "lain" of a forum got apparently raided in Chile due to credit card fraud.
According to chat logs from 03.07.2022 (third attached screenshot), he previously ddosed the Chilean government. We will reach out to Chilean authorities.
7 004
Threat actor pompompurin bragged about how he registered an account on our site (he used the email badhou3a@protonmail.com), so we'll send all his details straight to the FBI to help in their investigation.
The threat actor still uses his emails pom@pompur.in and pompompurin@riseup.net,
