Domains used by notorious hacking group ShinyHunters for Salesforce hacks disrupted in FBI takedown

  • Law enforcement seizes domains used by Scattered Lapsus$ Hunters
  • Files from Salesloft/Salesforce breach were leaked
  • The group stated “the era of forums is over”

The domains used by Scattered Lapsus$ Hunters to host data leak websites were reportedly seized by law enforcement just as the group was about to leak files stolen in the Salesloft/Salesforce breach. It didn’t stop the leaks, though.

The clearnet domain breachforums.hn was defaced, showing the usual FBI placeholder – “this domain has been seized”. This domain was previously used to reestablish BreachForums, an infamous underground website where cybercriminals exchanged knowledge, tools, and stolen goods, but after the forum was taken down by the FBI for the second time, it was propped back up by Scattered Lapsus$ Hunters, to be used as a data leak and extortion site.

Just days before the latest takedown, Scattered Lapsus$ Hunters announced they would start leaking the data stolen in the Salesloft/Salesforce breach, and even shared the exact moment when the files would go online. In an obvious attempt to thwart the leaks, the FBI, together with French authorities, took down not just breachforums.hn, but also the Tor site. However, this one was restored rather quickly, and files belonging to multiple companies were leaked.

Forums are dead

Among the victims were Qantas, Gap, Vietnam Airlines, Toyota, Disney, McDonald’s, Ikea, and Adidas. Files belonging to more than 40 companies were leaked.

Unfortunately, no arrests were made, meaning Scattered Lapsus$ Hunters can just prop the forum back up and pick up where they left off. However, according to BleepingComputer, the group has no intention of resurrecting the famous forum, reportedly saying: “The era of forums is over”.

It seems Telegram groups will be taking over, serving as improvised forums with a little more resilience to them.

Another reason for the pivot away from forums, according to CyberInsider, is the fact that the FBI “destroyed” database backups dating back to 2023, along with all escrow databases.

The hackers also apparently said that all hacking forums that emerge after BreachForums should be considered honeypots propped up by cybersecurity researchers and law enforcement, and as such, should be avoided.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

Google pulls AI model after senator says it fabricated assault allegation

Google says it has pulled AI model Gemma from its AI Studio platform after a Republican senator complained the model, designed for developers, “fabricated...

How to watch College Basketball 2025/26: free NCAA live streams, TV channels, preview

Watch College Basketball 2025/26 live streams as the Florida Gators look to go back-to-back. Below we have all the info on how to watch...

I’ve tested over a dozen coffee makers this year, and these are the 3 top bean-to-cup machines I recommend

If you love fresh coffee but don't have the time or inclination to use a manual espresso machine, you need a bean-to-cup coffee machine....

Internxt is my favorite secure cloud storage provider – and there’s a giant Black Friday sale

This Black Friday, deals are starting early. Cloud storage is an ever growing part of not just businesses, but normal life - with most...

Workers are increasingly burnt out – and AI nagging and notification pings aren’t helping

UK workers are 11% more overwhelmed by notifications than the global average, Atlassian study findsWorkers want flexibility to choose their hours, including focus time‘Asynchronous’...

Battlefield 6 gets temporary XP adjustments in the midst of a baffling Strikepoint exploit

An alleged Strikepoint exploit in Battlefield 6 has been discoveredIt supposedly lets players earn millions in XP without engaging with the gameBattlefield Studios has...

Nearly all creators admit they use AI tools for work – so is this the end of true creativity?

Adobe finds 86% of creators use GenAI in their workflowsMany are preparing for agentic AI, but are still worried about AI models using their...

Thousands fall victim to ransomware as European attacks reach record highs – here’s why they’re so at risk

European companies are being targeted more and more by ransomware attacksHigh income and strict regulations make them lucrative targets, Crowdstrike findsGeopolitics also plays a...

Fitbit’s new AI-powered personal coach app is now rolling out to some – here’s what’s new

A new AI coach is heading to Fitbit Premium usersSome US users on Android are now seeing the updateThe extra AI features offer insights,...

Welcome Fortnite’s new alien overlords with this Kang and Kodos Glider, available to MyDisney account holders until February

Fortnite x The Simpsons has launchedYou can earn in-game items like the Kang and Kodos Glider by linking various accountsThe Simpsons Discord Avatar and...