How the FBI Caught Hacker Pompompurin

Seytonic
26 Mar 202308:09

Summary

TLDRPompompurin, the notorious hacker and owner of BreachForums, was arrested by the FBI after a series of opsec failures. Known for his high-profile cybercrimes and clashes with security researchers, his downfall came from mixing his real and online identities. The FBI traced him through a leaked database, his email, and IP addresses linked to his home. Now facing up to 20 years in prison, the future of BreachForums is uncertain as its second-in-command, 'Baphomet', struggles to maintain the site amidst fears of FBI infiltration.

Takeaways

  • 😎 Pompompurin, known for using a Hello Kitty character, became a notorious figure in the cybercriminal world by running breachforums, a major English-speaking blackhat forum.
  • 🔍 The FBI tracked down Pompompurin through a slip-up in a private message on a seized forum, where he mentioned an email address that contained his real name, Conor Fitzpatrick.
  • 📧 The FBI linked Pompompurin's real identity to a Google Pay account, which was connected to an IP address used for a Zoom account registered to an email address that Pompompurin used to log into breachforums.
  • 🏠 Google Pay accounts were linked to Pompompurin's home address, making it easy for the FBI to locate him.
  • đŸ‘źâ€â™‚ïž After his arrest, Conor Fitzpatrick, also known as Pompompurin, admitted to being the owner and admin of BreachForums and was charged with conspiracy to solicit the selling of unauthorized access devices.
  • 💰 Pompompurin's bail was set at $300,000, paid by his parents, and he could face up to 20 years in prison according to sentencing guidelines.
  • 🛑 Following Pompompurin's arrest, the second in command of BreachForums, 'Baphomet', restricted and eventually banned Pompompurin's access to the forum due to security concerns.
  • 🚹 Baphomet feared that the FBI could exploit Pompompurin's access to de-anonymize BreachForums' users, leading to the decision to shut down the forum.
  • 🔄 Baphomet considered migrating to new infrastructure to keep the forum alive but later decided to shut down BreachForums completely due to evidence of FBI access to the forum's infrastructure.
  • 🌐 The shutdown of BreachForums left its large user base without a platform, and Baphomet is in discussions to potentially build a new community with other forum admins.
  • 🔄 The script highlights the cyclical nature of such forums, with the downfall of one often leading to the rise of another, as seen with the transition from raidforums to BreachForums.

Q & A

  • Who is Pompompurin and what is his connection to the cyber criminal underworld?

    -Pompompurin, also known as Conor Fitzpatrick, is a notorious hacker who rose to fame as the owner of BreachForums, one of the largest English-speaking blackhat forums on the internet, known for facilitating the sale of countless data breaches.

  • What is the significance of BreachForums in the context of cybercrime?

    -BreachForums is significant as it has become one of the largest platforms for English-speaking cyber criminals, particularly for the sale and distribution of data breaches through its 'leaks market'.

  • How did Pompompurin's rivalry with NightLion Security's Vinny Troia escalate?

    -The rivalry escalated through public clashes and a multi-year troll campaign initiated by Pompompurin, including hacking Vinny's Twitter account and falsely accusing him of being a pedophile by breaching the National Center for Missing and Exploited Children's database.

  • What was the turning point that led to Pompompurin's arrest?

    -The turning point was Pompompurin's slip-up in a private message to 'Omnipotent' on raidforums, where he mentioned an email address that the FBI later linked to his real identity, Conor Fitzpatrick.

  • How did the FBI identify Pompompurin's real identity?

    -The FBI identified Pompompurin's real identity by analyzing a private message on raidforums where he mentioned an email address that contained his real name, Conor Fitzpatrick. Further investigation linked this email to a Google Pay account and IP addresses associated with his online activities.

  • What was Pompompurin's reaction when he was arrested?

    -Upon his arrest, Pompompurin, also known as Conor Brian Fitzpatrick, quickly accepted that the game was over and admitted to the FBI that he was Pompompurin and the owner and admin of BreachForums.

  • What charges did Pompompurin face after his arrest?

    -Pompompurin was charged with 'conspiracy to solicit individuals with the purpose of selling unauthorized access devices,' which refers to means of accessing accounts, such as usernames and passwords.

  • How did the arrest of Pompompurin impact the operations of BreachForums?

    -Following Pompompurin's arrest, the second in command, 'Baphomet,' restricted his access to the site and eventually banned him. Concerns about the FBI exploiting Pompompurin's access led to the decision to shut down BreachForums.

  • What was the role of 'Baphomet' in the aftermath of Pompompurin's arrest?

    -'Baphomet' assumed control of BreachForums, initially restricting and then banning Pompompurin's access to the site. He also monitored logs for any unauthorized access or modifications to the forum's infrastructure.

  • What are the implications of the FBI's access to BreachForums' database?

    -The implications are significant as it suggests that the FBI could potentially de-anonymize users of the forum, similar to what happened with raidforums, which was transformed into an FBI honeypot after its seizure.

  • What is the future of the cyber criminal community that was䟝托 on BreachForums?

    -With BreachForums shutting down, the community is left without a platform. However, it is likely that a new platform will emerge to fill the void, as the quarter of a million users seek a new home for their activities.

Outlines

00:00

🔍 The Downfall of Pompompurin: Cyber Criminal Unmasked

Pompompurin, a notorious hacker and the owner of the prominent blackhat forum BreachForums, was apprehended by the FBI. Known for his rivalry with security researcher Vinny Troia and infamous trolling campaigns, including a spam attack from an FBI email address, Pompompurin's real identity was revealed through a slip-up in a private message on a seized forum, 'raidforums'. The FBI linked an email address mentioned in the message to a Google Pay account, which was further connected to an IP address used by Pompompurin's other online activities. This led to his arrest, where he admitted to being the administrator of BreachForums and was charged with conspiracy to solicit the selling of unauthorized access devices. Despite his young age, he faces significant prison time.

05:02

đŸ’„ The Aftermath of BreachForums: A Community in Limbo

Following the arrest of its founder, Pompompurin, the future of BreachForums is uncertain. The forum was established after the shutdown of 'raidforums' and quickly became a hub for cybercriminal activities. With Pompompurin's arrest, the second-in-command, 'Baphomet', initially restricted and later banned the founder's access to the site. Concerns about the FBI's potential access to BreachForums' infrastructure and user data have led to the decision to shut down the forum. Baphomet has expressed intentions to collaborate with other forum administrators to create a new community, but the fate of the displaced users remains unclear. The incident highlights the risks of mixing real-life and online identities, as well as the vulnerability of such forums to law enforcement actions.

Mindmap

Keywords

💡Pompompurin

Pompompurin refers to a notorious hacker and the owner of breachforums, who rose to fame in the cybercriminal underworld. The character is known for using a Hello Kitty persona as a brand. In the video, Pompompurin's activities and eventual arrest are central to the narrative, illustrating the consequences of high-profile cybercrime.

💡BreachForums

BreachForums is one of the largest English-speaking blackhat forums on the internet, notorious for facilitating the sale of countless data breaches. It is a key setting in the video, highlighting the platform's role in the cybercrime ecosystem and its eventual downfall following Pompompurin's arrest.

💡Cyber Criminal

A cyber criminal is an individual who uses technology to commit crimes such as hacking, identity theft, and data breaches. The video focuses on the life and actions of Pompompurin, who is a prime example of a cyber criminal, and the impact of his activities on the digital world.

💡NightLion Security

NightLion Security is mentioned as the company owned by Vinny Troia, who had public clashes with Pompompurin. The company represents the cybersecurity industry's efforts to combat cybercrime, and the video discusses the rivalry between its owner and the hacker.

💡FBI

The FBI, or Federal Bureau of Investigation, is the principal federal investigative agency in the United States. In the context of the video, the FBI plays a critical role in tracking down and arresting Pompompurin, showcasing the efforts of law enforcement in cybercrime investigations.

💡RaidForums

RaidForums was a blackhat site similar to BreachForums that was shut down by the FBI. The video discusses the site's history and its connection to Pompompurin, who was a regular user before it was seized, and how its closure led to the creation of BreachForums.

💡Data Breach

A data breach refers to an incident where unauthorized individuals gain access to confidential information. The video script mentions data breaches as a common occurrence facilitated by forums like BreachForums, emphasizing the severity of the cyber threats discussed.

💡Ego

Ego, in the context of the video, refers to the overconfidence and self-importance that can lead to mistakes. Pompompurin's ego is highlighted as a factor in his downfall, as it made him a target for the FBI and contributed to operational security (opsec) failures.

💡Operational Security (OpSec)

Operational security involves measures taken to protect sensitive information from being accessed by unauthorized parties. The video points out Pompompurin's opsec mistakes, such as mixing his real-life and online identities, which ultimately led to his identification and arrest.

💡Google Pay

Google Pay is a digital wallet platform and online payment system. In the video, it is mentioned as a service linked to the email address that helped the FBI trace Pompompurin's real identity, illustrating how digital footprints can be used in cyber investigations.

💡Conspiracy

In legal terms, conspiracy refers to an agreement between two or more persons to commit a crime. The video mentions that Pompompurin was charged with conspiracy to solicit individuals for selling unauthorized access devices, underscoring the legal implications of his actions.

💡Honeypot

A honeypot in cybersecurity is a decoy system set up to attract and trap attackers. The video discusses how raidforums was transformed into an FBI honeypot after its seizure, highlighting the tactics used by law enforcement to capture cybercriminals.

Highlights

Pompompurin, the hacker and owner of breachforums, was arrested by the FBI.

Pompompurin's rise to fame in the cybercriminal underworld through breachforums.

The leaks market on breachforums as a major source of data breaches.

Pompompurin's public rivalries with security researchers, particularly with Vinny Troia.

Pompompurin's multi-year troll campaign against Vinny Troia, including hacking his Twitter account.

The misuse of an FBI website vulnerability to send spam emails warning of fake cyberattacks by Vinny.

Pompompurin's downfall due to his ego and the attention it drew from the FBI.

The FBI's discovery of Pompompurin's real identity through a private message on raidforums.

The revelation of Pompompurin's real email address in a conversation with raidforum's owner 'Omnipotent'.

The FBI's use of Google warrants to link the email address to a Google Pay account and further to Pompompurin's identity.

Pompompurin's arrest and admission to the FBI that he was the owner of BreachForums.

The charge against Pompompurin for conspiracy to solicit individuals to sell unauthorized access devices.

The bail set for Pompompurin and its payment by his parents, revealing his age as 20.

The immediate actions taken by BreachForums' second in command 'Baphomet' after Pompompurin's arrest.

The decision to shut down BreachForums due to the potential FBI access to its infrastructure.

The transformation of raidforums into an FBI honeypot post-seizure.

Baphomet's plans to build a new community with the help of competitor forum admins.

The future uncertainty for the 250,000 users of BreachForums as they become 'internet refugees'.

Transcripts

play00:00

Pompompurin, the infamous hacker and owner  of breachforums was recently arrested,  

play00:05

and the FBI has just revealed exactly how they  tracked him down. But, before we get to that  

play00:10

how did this guy, who brands himself using a  hellokitty character rise to become one of the  

play00:15

most famous personalities in the cyber criminal  underworld? Well - owning breachforums certainly  

play00:20

played a part, it’s become one of the largest  English speaking blackhat forums on the internet 

play00:25

the most famous section being the leaks  market which has facilitated the sale of  

play00:29

countless data breaches I’d say maybe even most  of the leaks we’ve looked at on this channel  

play00:34

over the past year, came from breachforums. Aside from being a cyber criminal King Pin,  

play00:39

Pompompurin also gained notoriety and became  a bit of a celebrity for his rivalries with  

play00:45

security researchers, the most notable being his  frequent and very public clashes with the owner of  

play00:50

NightLion security, Vinny Troia, which stems  from Vinny’s unsuccessful attempts to unmask  

play00:56

Purin’s real identity. Purin wasn’t too happy  with these attempts and responded by unleashing  

play01:01

a multi-year long troll campaign against Vinny,  which included hacking his Twitter account, as  

play01:06

well as breaching the National Center for Missing  and Exploited children, all in an effort to put  

play01:11

out an alert claiming Vinny is a Pedo. But by far  his biggest troll was utilising a vulnerability in  

play01:17

the FBI website itself to send thousands of spam  emails from a legit FBI email address, warning of  

play01:24

fake cyberattacks being perpetrated by Vinny. But arguably Pompom’s biggest enemy was his  

play01:29

ego - which is by no means unique among cyber  criminals. Whilst attracting so much attention  

play01:34

made him a celebrity amongst his peers, it painted  a large target on his back in the eyes of the FBI,  

play01:40

which has just revealed exactly how they hunted  him down. For this story we have to go back to the  

play01:45

days of raidforums, a now seized blackhat site  that Purin was a regular user of. When the FBI  

play01:51

shut the site down last year they obtained its  database which included the private messages of  

play01:56

all the forums’ members. One such conversation  between Pompompurin and raidforum’s owner  

play02:01

“Omnipotent”, is of particular interest. They were  discussing a data leak pertaining to the keyboard  

play02:06

app AI.type, over 30 million user’s details were  leaked, and the database was of course posted on  

play02:12

raidforums - the database was said to include  all the app’s users. However Purin messaged  

play02:18

Omnipotent, saying the leaked database could not  have contained all the app’s users, because his  

play02:23

email wasn’t included in the dump. He says “Not  messaging to ask for credits back or anything,  

play02:28

because I wanted it anyways, I just wanted to  let you know that it doesn’t seem to be the  

play02:32

full amount of data" Omnipotent responds “What  email did you look up and how?” “I don’t want  

play02:37

to share my actual email for obvious reasons, but  this email seems to have the same case as mine):”  

play02:43

“[email protected]”. Pompompurin  no doubt thought he was being real smart when  

play02:50

he told Omnipotent this wasn’t his email, but  not only was it his real email, but it contains  

play02:55

Purin’s real name “Conor Fitzpatrick” - Whilst  Omnipotent didn’t figure this out - the FBI did. 

play03:01

After the FBI served Google warrants, they  found that this email was linked to a google pay  

play03:07

account, which another gmail account shared the  same details to. The FBI investigated this second  

play03:12

email and found it was accessed using the same IP  address as a zoom account which was registered to  

play03:18

the email address “[email protected]” - which  is the exact same email that Purin used to log  

play03:24

into raidforums. Regardless of whether Purin used  VPNs or TOR, he had committed the deadly sin of  

play03:31

mixing his irl and online identities, firstly  when he sent Omnipotent that fateful message,  

play03:37

and secondly when he mixed the IPs he was using  for his irl and Pompompurin identities. Oh and  

play03:43

those Google pay accounts, were linked to Pompom’s  home address, so tracking him down was simple. 

play03:49

Court documents show that when Pompompurin, also  known by his much less catchy name “Conor Brian  

play03:55

Fitzpatrick” was arrested he quickly accepted  the game was over, admitting to the FBI that  

play04:00

he was Pompompurin and “the owner and admin of  BreachForums”. Conor was charged with “conspiracy  

play04:06

to solicit individuals with the purpose of selling  unauthorized access devices”. “Access devices”  

play04:11

simply being a fancy term for a means of accessing  an account, like usernames and passwords.  

play04:17

His bail was set at $300 thousand dollars, which  was promptly paid by his parents - because the  

play04:22

guy is apparently only 20 years old - and  under sentencing guidelines he could be  

play04:27

facing the next 20 years of his life in prison. BreachForums’ second in command, an admin going  

play04:32

by ‘Baphomet’ posted an announcement in the  early hours of Purin’s arrest. Saying he  

play04:36

assumed the worst after just 24 hours of Purin  being afk - which really puts into perspective  

play04:42

just how glued Purin was to his criminal  enterprise. During this initial 24 hours,  

play04:47

Baphomet “[removed] his access to all important  infrastructure and restricted his forum account  

play04:52

[so he could] still login but not carry out any  administrator actions.”. He’s also been monitoring  

play04:57

“[logs] to see [if there’s been] any access or  modifications to [Breachforums infrastructure]”.  

play05:02

Which brings us to the next act in this saga,  the future, or lack thereof, of breachforums. 

play05:07

Breachforums was born out of the downfall  of raidforums, an almost identical site,  

play05:13

hosting a community dedicated to cyber  crime, with sales of hacking tools,  

play05:16

a leaks market, and so on. After 8 years  on the internet, raidforums was - well,  

play05:21

raided themselves by the FBI, with  its owner “Omnipotent” arrested - to  

play05:26

this day the 21 year old behind it is  still fighting extradition to the US. 

play05:31

The shutdown of raidforums left its half  a million registered users homeless,  

play05:35

but Pompompurin, a user of the site with a good  reputation soon stepped in to fill the void,  

play05:41

creating breachforums. The new site was pretty  much a continuation of raidforums, just under new  

play05:47

management, so much so that Purin even let users  keep the ranks they had gained on raidforums. 

play05:52

However barely 12 months after breach was  set up, with Purin now sitting in a jail  

play05:57

cell. Admin Baphomet has been forced to not only  restrict Purin’s access to the site he founded,  

play06:02

but ban him altogether, after all it’s clear  at this point he just ain’t coming back,  

play06:07

and fear runs high that the FBI could  in some way exploit Purin’s access to  

play06:11

breachforums in order to deanonymise it’s users. Let’s not forget, after raidforums’ seizure,  

play06:17

it was transformed into an FBI honeypot, every  page on the site redirected to a login page that  

play06:22

law enforcement was using in order to grab user  credentials. After banning Purin, Admin Baphomet  

play06:28

vowed to takeover the site and keep it alive  long term by migrating to new infrastructure. 

play06:34

However this pledge didn’t last long, he soon  released an update saying he was going to shut  

play06:38

down breachforums for good - reason being that  logs showed someone (presumably the FBI) had  

play06:44

exploited Purin’s credentials to access breached  infrastructure shortly after his arrest, meaning  

play06:49

in his words “nothing can be assumed safe, whether  its our configs, source code, or information about  

play06:54

our users - the list is endless. This means  that I can't confirm the forum is safe”, 

play07:00

His fears were confirmed in the last day or so,  when newly published court documents revealed  

play07:04

Pompompurin’s other opsec mistakes. Like the  time he forgot to use a VPN when logging into  

play07:10

breachforums, but rather using an IP registered to  his real home address. The fact the FBI even know  

play07:16

this confirms they have access to breachforum’s  database, just as they did with raidforums. 

play07:22

What happens now? Well - Baphomet says he’s  having conversations with competitor forum admins,  

play07:27

“hoping to work with some of those people to build  a new community”. Whether that happens or not, the  

play07:32

void will be filled one way or another, with its  quarter of a million users now internet refugees. 

play08:04

As always thanks for watching, and I’ll  see you in the next video, have a good one!

Rate This
★
★
★
★
★

5.0 / 5 (0 votes)

Ähnliche Tags
CybercrimeHackingForumsFBIArrestIdentityLeakSecurityUnderworldControversy
Benötigen Sie eine Zusammenfassung auf Englisch?