The United States Department of Justice just announced on Friday that a 20-year-old man from Illinois has been charged for allegedly running the notorious hacker site “Breachforums.” The website was a marketplace for stolen data, including login credentials, credit card information, and personal identification.
The accused, a resident of Illinois, is alleged to have operated the site and collected fees from the site’s users in exchange for providing them access to the stolen data. The site was active between 2016 and 2020, during which time it amassed over 200,000 members and facilitated the sale of approximately 4 million stolen login credentials.
The Department of Justice has charged the accused with conspiracy to commit computer fraud and abuse, conspiracy to commit wire fraud, and conspiracy to commit identity theft. If convicted, he faces up to 20 years in prison.
The takedown of Breachforums is a significant blow to the underground cybercrime ecosystem. The site was one of the largest marketplaces for stolen data, and its shutdown is expected to significantly impact the sale of stolen data on the dark web. It also serves as a warning to others operating similar sites that they will not go undetected and that there are consequences for their actions.
This case highlights the importance of cybersecurity and the need for individuals and organizations to take proactive steps to protect their data. Employing strong passwords, two-factor authentication, and other security measures is critical to prevent data breaches. Additionally, monitoring credit reports and bank accounts regularly for any signs of unauthorized activity is crucial.
Overall, this case emphasizes the importance of cooperation between law enforcement and cybersecurity experts in identifying and prosecuting cybercriminals. The takedown of Breachforums is a significant victory in the ongoing battle against cybercrime. However, there is still work to be done to protect individuals and organizations from the harm caused by these criminals.
Reading an older article? Use the brief to stay current.
Get the 5-Minute Weekday Cyber Brief
The cyber stories worth paying attention to, filtered from 100+ trusted sources and explained fast.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day
CVE-2026-19490 is a CVSS 9.3 NetScaler Gateway/AAA auth bypass. A public PoC on Sept 2 was followed by live probes within a...
PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Confirm Emergency Patch Release 2, restrict admin exposure, and hunt like...
JFrog Artifactory CVE-2026-82329: Empty Join Key, Full Admin Token, Busy Scanners
CVE-2026-82329 lets attackers forge Artifactory admin tokens via a deterministic empty join key. Mass scanning peaked near 406,000 attempts; patch fixed builds...
The 5-Minute Cyber Brief: September 14, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.