Executive Summary
In September 2025, the U.S. Department of Justice resentenced Conor Brian Fitzpatrick—known online as Pompompurin and the former administrator of the notorious BreachForums cybercrime marketplace—to three years in prison. Fitzpatrick pleaded guilty after orchestrating access device fraud and facilitating the sale of stolen data, in addition to possessing child sexual abuse material (CSAM). BreachForums had become a major platform for trading compromised credentials, payment card information, and illicit content before law enforcement seized the site and apprehended its leader. The takedown disrupted a key meeting ground for cybercriminals involved in massive data breaches and identity theft operations.
This incident underlines heightened law enforcement focus on cybercrime forums as hubs for illegal commerce, reflecting rising pressure on both administrators and users. The prosecution of BreachForums’ founder highlights regulatory and investigative trends aimed at deterring similar platforms and enforcing accountability for cyber-enabled offenses.
Why This Matters Now
This case exemplifies increasing efforts to dismantle the infrastructure of cybercrime marketplaces and hold ringleaders accountable. With sensitive data continuously exposed and traded on such forums, timely legal actions are crucial for disrupting supply chains of identity theft, fraud, and further criminal activity.
Attack Path Analysis
The adversary initially gained access by leveraging exposed credentials or insecure administrative interfaces, likely via compromised accounts associated with the cybercrime forum. They escalated privileges through manipulation or abuse of forum permissions to access backend infrastructure. Lateral movement occurred as the attacker pivoted to databases and other services supporting the forum, increasing their reach within the cloud environment. They established command and control channels, maintaining persistence and coordination over the environment using encrypted or covert channels. Sensitive data, including user records and illicit material, was exfiltrated through outbound traffic to attacker-controlled destinations. Ultimately, the attack resulted in the unauthorized distribution of data, service disruption, and legal consequences for operators.
Kill Chain Progression
Initial Compromise
Description
Attacker obtained initial access via compromised credentials or exposed administrative interfaces of the cloud-hosted cybercrime forum.
MITRE ATT&CK® Techniques
Acquire Infrastructure: Domains
Compromise Infrastructure: Domains
Develop Capabilities: Malware
Develop Capabilities: Exploits
Valid Accounts
Phishing: Spearphishing Attachment
Gather Victim Identity Information: Email Addresses
Gather Victim Identity Information: Credentials
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Identification and Authentication
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – Information and ICT Systems Security
Control ID: Article 8
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Continuous Authentication and Authorization
Control ID: Identity Pillar: Authentication & Access Control
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
BreachForums facilitated access device fraud and credential theft targeting banking systems, requiring enhanced east-west traffic security and zero trust segmentation.
Banking/Mortgage
Cybercrime forum's access device conspiracy directly threatens payment processing infrastructure, demanding strengthened egress security and threat detection capabilities.
Computer/Network Security
Security vendors face reputational risks from forum-facilitated breaches, necessitating improved multicloud visibility and anomaly detection for client protection.
Law Enforcement
DOJ resentencing highlights ongoing challenges in cybercrime prosecution, requiring enhanced encrypted traffic analysis and threat intelligence capabilities for investigations.
Sources
- DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAMhttps://thehackernews.com/2025/09/doj-resentences-breachforums-founder-to.htmlVerified
- Founder of One of World’s Largest Hacker Forums Resentenced to Three Years in Prisonhttps://www.justice.gov/opa/pr/founder-one-worlds-largest-hacker-forums-resentenced-three-years-prisonVerified
- BreachForums founder resentenced to 3 years prison, former freebie deal revoked by US courtshttps://cybernews.com/news/breachforums-founder-fitzpatrick-resentenced-three-years-prison/Verified
- BreachForums founder caged after soft sentence overturnedhttps://www.theregister.com/2025/09/17/breachforums_founder_prison/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic control, egress filtering, encryption of data in transit, and continuous threat detection would substantially disrupt or prevent each stage of this attack. Applying CNSF capabilities limits attacker access, restricts lateral movement, enforces policy on outbound transfers, and rapidly detects anomalies.
Control: Zero Trust Segmentation
Mitigation: Limits exposure of critical services by enforcing least privilege network access.
Control: Multicloud Visibility & Control
Mitigation: Detects abnormal privilege assignments and access patterns across workloads.
Control: East-West Traffic Security
Mitigation: Blocks or logs unauthorized internal service-to-service communications.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks known command and control traffic patterns, even if encrypted.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unsanctioned outbound data exfiltration attempts.
Rapidly detects indicators of impact or disruptive behaviors for timely incident response.
Impact at a Glance
Affected Business Functions
- Data Security
- Customer Privacy
- Regulatory Compliance
Estimated downtime: N/A
Estimated loss: N/A
BreachForums facilitated the sale of over 14 billion records of personal and commercial information, including sensitive data such as bank account details and social security numbers, leading to significant privacy violations and potential financial fraud.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation to isolate admin interfaces and sensitive workloads from unnecessary network exposure.
- • Implement granular east-west traffic controls to prevent lateral movement within cloud environments.
- • Apply strong egress filtering and encryption inspection to block unauthorized outbound data transfers.
- • Continuously monitor for anomalous traffic patterns and privilege changes using centralized visibility tools.
- • Conduct regular policy audits and simulate breach scenarios to validate effectiveness of CNSF and Zero Trust controls.



