

In March 2023, the FBI arrested Connor Brian Fitzpatrick, the 20-year-old who operated BreachForums under the alias "Pompompurin." Within days, the forum's community had begun migrating to alternatives, and within weeks, ShinyHunters had relaunched BreachForums under new management. When the FBI and Europol seized that version in May 2024, a new iteration appeared within days. This pattern, disruption followed by rapid reconstitution, characterises the underground forum ecosystem and explains why monitoring it cannot be a periodic activity. Forums close, rebrand, and reopen, but the community of threat actors they serve is continuous, and the intelligence they generate is ongoing.
For security teams, underground forums are not simply places where criminals transact; they are intelligence environments where threat actor capabilities, targeting intentions, and operational techniques are discussed and demonstrated before they are deployed against real targets. A security team that monitors these forums gains access to intelligence that cannot be obtained from any other source: advance warning of campaigns, early visibility into new techniques, and real-time information about data already stolen from their organisation or supply chain.
The underground forum ecosystem is neither monolithic nor static. Different forums serve different communities with different specialisations, and the most valuable intelligence for any given organisation depends on which forums are most relevant to the threat actors most likely to target it. BreachForums positioned itself as the primary market for stolen data: database dumps, credential lists, and logs from infostealer campaigns. Its audience was international, with English as the primary language and representation from criminal operators across multiple regions.
Exploit.in and XSS.is are Russian-language forums with a more technically oriented community. Exploit.in focuses on vulnerabilities, exploit techniques, and offensive tools. Discussions on Exploit.in include technical analysis of software vulnerabilities, offers of custom exploit development services, and exchanges about defensive product weaknesses. XSS.is combines a marketplace function with technical discussion and is known as a venue where ransomware groups have historically recruited affiliates and posted operational announcements.
Beyond these major forums, a long tail of smaller, more specialised communities exists: forums focused on specific types of fraud, country-specific criminal networks, and closed Telegram groups that function as invitation-only underground communities. The intelligence value of these smaller communities varies: some host highly sophisticated actors with narrow specialisations, while others are primarily populated by less experienced criminals repackaging content from larger forums.
The distinctive intelligence value of underground forum monitoring comes from the nature of the information that circulates there. Before a criminal campaign is launched, the actors preparing it may announce on forums that they are seeking access to specific sectors, sell the tools they intend to use, or discuss the defensive products that their techniques are designed to bypass. These pre-attack signals create a detection window that internal security tools, which can only observe what happens inside the organisation's perimeter, cannot provide.
Access listings from initial access brokers, posted on forums before the access is purchased by a ransomware group, represent perhaps the most directly actionable pre-attack intelligence available through forum monitoring. When an access broker posts that they have VPN access to a mid-sized financial services firm in Germany with Active Directory access included, that listing is an alert that a network has been compromised and that the access is about to be weaponised. For organisations monitoring these listings, correlation with their own infrastructure characteristics, sector, size, technology stack, can provide advance warning before a ransomware affiliate has been selected and the attack has been planned.
Technical discussions on forums like Exploit.in surface emerging techniques before they are documented in public security research. A thread discussing a new method of bypassing a specific security product is intelligence that defenders of that product can use to assess their detection coverage and develop compensating controls, potentially weeks before the technique appears in a malware campaign and months before a vendor advisory is published.
Accessing underground forums to extract intelligence presents legal and operational challenges that most organisations cannot manage independently. Registration on many criminal forums requires a vouching process from existing members, payment of entrance fees, or a demonstration of criminal capability. Analysts who join these forums as part of intelligence operations must maintain cover personas that are consistent with the community's expectations, which requires sustained investment of time and risk tolerance.
The legal environment for forum intelligence varies by jurisdiction. In some countries, accessing a criminal forum, even for intelligence purposes and without conducting any criminal transactions, may constitute participation in a criminal enterprise. Legal frameworks for authorised computer access investigations, such as the US Computer Fraud and Abuse Act and equivalent European legislation, create constraints that organisations must navigate carefully. Security teams should obtain legal advice before establishing any direct presence on criminal forums and should document their intelligence objectives and operational boundaries.
The risk of attribution is also real: forum communities are suspicious of newcomers and maintain systems for identifying and exposing individuals who appear to be conducting intelligence operations. An analyst who is identified as a law enforcement or corporate intelligence operative faces not only the loss of their access but potential targeting for harassment, doxxing, or retaliatory attacks.
Not all forum intelligence is reliable. Criminal forums host a mixture of genuine actors with legitimate capabilities and fraudsters who fabricate or repackage data to collect payment from buyers who cannot verify authenticity. Assessing the credibility of a forum source requires evaluating the operator's reputation within the community, the verifiability of their claims based on available samples, and the consistency of their operational history with claimed capabilities.
When forum intelligence indicates that an organisation's data may have been stolen, the intelligence team must verify whether the claim is credible before escalating to incident response. Checks include comparing claimed data characteristics against known internal data formats, contacting relevant system owners to look for anomalies in access logs around the claimed breach date, and assessing whether the forum operator has a history of posting genuine breaches or repackaged old data.
Verified forum intelligence feeds into multiple downstream processes: incident response if a genuine breach is confirmed, dark web monitoring alerts for ongoing exposure tracking, and threat intelligence updates that inform detection engineering and hunting priorities. The value of this intelligence is proportional to the speed with which it can be assessed and acted upon, making the triage process a critical capability for any organisation that relies on forum monitoring as part of its threat intelligence programme.
Underground forum intelligence reaches its full value when it is integrated with internal security operations rather than existing as a separate intelligence function. When forum intelligence indicates that a specific initial access technique is being discussed as effective against a particular type of security control that the organisation uses, the detection engineering team should validate their current detection logic against that technique and develop additional rules if gaps are identified.
Forum-sourced IOCs, including domain names, IP addresses, and malware hashes extracted from forum posts and discussions, should flow into SIEM rules and threat intelligence platforms alongside IOCs from other sources. The timeliness advantage of forum intelligence, often surfacing indicators before they appear in formal intelligence feeds, is most valuable when the integration pipeline from forum collection to SIEM deployment is fast enough to provide a meaningful detection lead time.
For security leadership, forum intelligence also provides strategic value: understanding which threat actor groups are actively seeking capabilities relevant to your organisation's technology stack, which sectors are being targeted in current criminal campaigns, and what the going rate for access to organisations of your size and sector reveals about the criminal market's perception of your security posture. This strategic intelligence informs investment decisions and priority-setting in ways that operational indicators cannot.
The terms "dark web" and "underground forums" are often used interchangeably, but they describe different phenomena with different intelligence implications. The dark web refers specifically to networks and services accessible only through anonymising networks like Tor, including .onion sites that are not indexed by standard search engines. Underground forums, by contrast, include both Tor-hosted sites and forums that are accessible on the regular internet but require registration and may have moderation barriers.
Many of the most active criminal forums in 2026 operate on the regular internet rather than on Tor, because Tor's performance limitations make the browsing experience uncomfortable for communities conducting high-volume transactions. BreachForums operated as a regular website (with Tor mirrors). Telegram channels are accessible without any anonymisation tool. This shift from Tor-hosted forums to clearnet and messaging platform communities has significant implications for monitoring: intelligence collection no longer requires Tor browser capability, but it does require access to registration-gated platforms.
For defenders, this means that "dark web monitoring" as a product or service description may or may not include monitoring of the clearnet criminal forums and Telegram channels where significant criminal activity now occurs. When evaluating dark web monitoring services, the relevant question is not whether the service monitors Tor-hosted sites but whether it covers the full range of criminal communication channels where intelligence relevant to the organisation can be found, including clearnet forums, Telegram, and other messaging platforms that criminal operators have adopted. A monitoring programme that covers only Tor-hosted sites misses a substantial fraction of the intelligence available from criminal community surveillance.
Defendis monitors criminal intelligence sources across Tor-hosted sites, clearnet forums, and Telegram channels, providing coverage of the full criminal communication landscape rather than a subset defined by the technology layer on which it operates. This full coverage is what enables early warning of threats that exist in the portions of the criminal ecosystem that a narrow "dark web" definition would exclude.
Analysts who monitor criminal underground forums face operational security considerations that are distinct from those of standard threat intelligence collection. Accessing criminal forums requires accounts, and in many cases, criminal forum accounts require a vouching process, payment for membership, or a demonstrated track record of participation in criminal activities that no legitimate security professional should engage in. The line between passive monitoring and active participation in criminal communities is one that threat intelligence professionals must navigate carefully, with legal and ethical implications that vary by jurisdiction.
Most legitimate threat intelligence providers handle the access problem by maintaining established presences in criminal communities that are built and maintained by specialists with deep expertise in criminal forum culture and operational security. The intelligence produced by these specialists is then delivered to clients as finished intelligence or enriched IOC feeds, without requiring clients to establish their own forum presences. For organisations considering whether to build in-house forum monitoring capability, the practical barriers of access, the legal risks of misunderstanding participation rules, and the cultural expertise required to correctly interpret forum content all argue for a careful assessment of whether the investment in building this capability genuinely offers advantages over purchasing finished intelligence from a specialist provider.
For analysts with legitimate forum access through established providers or information sharing communities, the operational security of their monitoring activity is a genuine concern. Forum administrators actively monitor for behaviour patterns that suggest law enforcement or threat intelligence monitoring activity: accounts that only consume without contributing, accounts that ask unusual questions about pricing or logistics, and accounts whose activity patterns suggest systematic intelligence collection rather than criminal participation. Maintaining an effective monitoring presence requires understanding and adapting to these detection patterns, which is itself a specialist skill set that benefits from dedicated training and community of practice within the threat intelligence profession. This is one dimension of forum intelligence where the specialist expertise of established threat intelligence providers provides genuine value over ad-hoc in-house efforts.
The legal status of accessing criminal underground forums varies by jurisdiction and the nature of the access. Passively reading publicly accessible content on forums that can be accessed without special software or accounts is generally legal in most jurisdictions. Accessing content that requires account registration on a platform dedicated to criminal activities, using Tor to access Tor-only criminal platforms, or interacting with criminal actors may raise legal concerns that vary by jurisdiction. Many organisations address this by using specialist threat intelligence providers with established legal frameworks for their monitoring activities, rather than building in-house capabilities that might expose them to legal risk in jurisdictions with broad computer access laws.
Reputation in criminal underground forums is built through a combination of vouching (existing trusted members endorsing new members), deposit escrow (posting a financial bond that is forfeited if the member commits fraud), and track record (completing transactions successfully and receiving positive reviews from counterparties). New members with no reputation must either go through a vouching process or accept that they can only transact at lower value levels until they build a history. This reputation system, while imperfect, provides enough accountability to make established criminal forums function as marketplaces, and it is the mechanism that threat intelligence analysts must understand to interpret the credibility signals in forum content.
The translation speed from forum intelligence signal to attack depends on the type of signal. An Initial Access Broker listing for a specific organisation can be purchased and exploited within hours of posting. A discussion of a new phishing technique may take days to weeks before it is refined into a deployable campaign. Recruitment discussions for a planned operation indicate a longer timeline of preparation. Intelligence consumers who can assess the stage in the attack preparation lifecycle that a forum signal represents can better estimate response urgency and prioritise accordingly, which is one of the value-added analytical capabilities that experienced threat intelligence analysts provide on top of raw forum monitoring.
No. The major English-language forums (BreachForums, Exploit.in, XSS.is, RAMP) are the most visible to Western researchers, but significant criminal forum activity occurs in Russian, Chinese, Arabic, Portuguese, and other languages. Russian-language forums have historically been significant sources of ransomware and cybercriminal infrastructure. Chinese-language forums focus heavily on data markets and credential trading for Asian targets. Arabic-language forums include activity from actors targeting financial institutions in Middle Eastern and North African markets. Effective underground forum intelligence requires multilingual coverage that most in-house teams cannot provide, which is a key advantage of specialist providers with genuine multi-language coverage of the criminal underground.
Extracting intelligence from underground forums requires more than identifying relevant keywords and collecting matching posts. The meaning of forum content is heavily context-dependent: the same phrasing can mean different things depending on the reputation of the author, the forum section where it appears, the current events in the criminal community, and the implicit conventions of the specific forum culture. Analysts who lack this contextual understanding risk misinterpreting forum content in ways that generate either false alarms or missed threats.
Community dynamics within forums provide a layer of intelligence about the reliability and significance of specific actors' claims. An established forum member with hundreds of positive reviews announcing a new access offering is a fundamentally different intelligence signal from a recently registered account making the same claim. The former is almost certainly advertising genuine access; the latter may be attempting a scam or may have obtained stolen access that will not deliver as promised. Distinguishing between high-reputation actors and opportunistic fraudsters requires knowledge of the specific forum's reputation systems and the community's assessment of individual actors.
The language and terminology used in underground forums evolves rapidly in response to law enforcement interest, forum disruptions, and operational security concerns. Community members develop codewords and circumlocutions for sensitive topics that anyone reading forums without this contextual knowledge might miss or misinterpret. Understanding this evolving vocabulary is an ongoing analytical task that requires continuous engagement with forum content rather than periodic reviews. Specialist threat intelligence providers invest in the cultural expertise and continuous monitoring that makes this contextual understanding possible, which is one of the core advantages they offer over generic keyword monitoring approaches. Defendis maintains continuous engagement with underground forum communities to ensure that intelligence is contextually accurate and operationally relevant.
Underground forums and criminal marketplaces reveal threat actor capabilities, active campaigns, and stolen data before attacks reach their targets. Defendis monitors criminal forums, marketplaces, and supply chain intelligence sources continuously, alerting your organisation when your name, data, infrastructure, or vendor relationships appear in criminal discussions. When a threat actor announces targeting of your sector, or when data associated with your supply chain appears in a criminal forum listing, Defendis surfaces the intelligence with enough context to act before the attack materialises.
Request a demo to see how Defendis surfaces underground forum intelligence and supply chain exposure relevant to your organisation.