ZeroFox Intelligence Flash Report - Dark Web Discussion Centers on BreachForums Outage
|by Alpha Team

ZeroFox Intelligence Flash Report - Dark Web Discussion Centers on BreachForums Outage
Product Serial: F-2025-04-17a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the recent outage of the popular deep web hacking forum BreachForums, as well as speculation surrounding the alleged arrest of notorious threat actor IntelBroker.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On April 15, 2025, ZeroFox observed that the popular deep web hacking forum BreachForums was no longer online, with the domain breachforums[.]st displaying an error code which remains as of the writing of this report.
- On the same day, the hacking collective “Dark Storm” posted to its Telegram channel seemingly claiming responsibility and providing a check-host URL which confirmed the forum's outage.
- Conflicting information has also been circulating amongst threat actors, with many instead claiming that the Federal Bureau of Investigation (FBI) is behind BreachForums’ closure.
- ZeroFox observed discussions taking place in deep and dark web (DDW) forums and Telegram channels surrounding the alleged arrest of notorious threat actor “IntelBroker”, who is known for publishing prominent data leaks and previously fulfilling an administrator role within BreachForums.
- As of the writing of this report, it is unclear whether a law enforcement (LE) operation or a hacktivist group such as Dark Storm (who has not indicated any specific motive) is responsible for the BreachForums outage.
Tags: tlp:clear, dark web, threat actor