Blog

BreachForums hacking forum admin resentenced to three years in prison

Conor Brian Fitzpatrick, the 22-year-old behind the notorious BreachForums hacking forum, was resentenced today to three years in prison after a federal appeals court overturned his prior sentence of time served and 20 years of supervised release.

Fitzpatrick, of New York, operated under the alias “Pompompurin” and created the BreachForums hacking forum in 2022 after the FBI took down RaidForums.

Fitzpatrick was arrested on March 15, 2023, and charged with conspiracy to solicit individuals to sell unauthorized access devices. At the time of his arrest, he admitted to FBI agents that he was Pompompurin and the administrator of BreachForums.

In July 2023, Fitzpatrick pleaded guilty to Conspiracy to Commit Access Device Fraud, Solicitation for the Purpose of Offering Access, and Possession of Child Pornography.

The Department of Justice says Fitzpatrick violated his pretrial release conditions by using the internet on unmonitored devices.

“After he entered his guilty pleas, the defendant used VPN services to conceal his use of the Internet and repeatedly utilized an unauthorized and unmonitored electronic device (or devices) to avoid detection by pretrial services,” reads court documents regarding the resentencing.

“Even now, the defendant has not provided pretrial services or the government with this unmonitored device (or devices).”

Despite prosecutors seeking more than 15 years in prison, Fitzpatrick was sentenced in January 2024, to time served, which included 17 days in jail, and 20 years of supervised release.

Under that sentence, he was placed on home confinement with GPS monitoring for two years, barred from internet access during his first year of release, required to install monitoring software on his devices, and required to undergo mental health treatment.

See also  Fake Mac fixes trick users into installing new Shamos infostealer

After an appeal by the Department of Justice, the U.S. Court of Appeals for the Fourth Circuit vacated the sentence in January 2025, finding it insufficient, and remanded the case for resentencing.

Today, Fitzpatrick was given a three-year prison term on three counts: conspiracy to commit access device fraud, solicitation for the purpose of offering access devices, and possession of CSAM.

BreachForums

BreachForums was a hacking forum used to trade, sell, and leak stolen data, as well as sell access to corporate networks and other illegal cybercrime services. BreachForums rapidly grew into one of the largest English-language hacking forums, boasting more than 330,000 members.

The site became notorious for the selling and trading of stolen data from telecom providers, social networks, healthcare companies, investment firms, and government agencies. 

However, it faced increasing pressure by the US government after a threat actor breached D.C. Health Link, a healthcare provider for U.S. House members, their staff, and their families, and began using the forum to sell and leak stolen data.

It was soon after this breach, that the FBI seized BreachForums and arrested Fitzpatrick.

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.


Source link

Back to top button
close