The FBI seized a BreachForums domain used by the ShinyHunters group as a data leak extortion site for the widespread Salesforce attacks, with the threat actor stating that law enforcement also stole database backups for the notorious hacking forum. The domain, Breachforums.hn, was previously used to relaunch the hacking forum this summer, but the site was soon taken offline again after some of its alleged operators were arresteds. In October, the domain was converted into a Salesforce data leak site by Scattered Lapsus$ Hunters, a gang claiming to consist of members linked to the Shiny Hunters, Scattered Spider, and Lapsus$ extortion groups, to extort companies impacted by the Salesforce data theft attacks. On Tuesday, both the clearnet breachforums.hn data leak site and its Tor counterpart went offline. While the Tor site was quickly restored, the breachforums domain remained inaccessible, with its domains switched to Cloudflare nameservers previously used for domains seized by the U.S. government. Last night, the FBI completed the action, adding a seizure banner to the site and switching the domain's name servers to ns1.fbi.seized.gov and ns2.fbi.seized.gov. According to the seizure message, law enforcement authorities in the U.S. and France collaborated to take control of the BreachForums web infrastructure before the Scattered Lapsus$ Hunters hacker began leaking data from Salesforce breaches. However, with the Tor dark web site still accessible, the threat actors claim ...
FBI takes down BreachForums portal used for Salesforce extortion
BleepingComputer
·Bill Toulas
·Published Oct 10, 2025
·Updated
Affected Software
1 affected component
Salesforce Salesforce
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the FBI's takedown of the BreachForums portal used for extortion related to Salesforce data breaches.
2
What security implications are discussed?
The article highlights the implications of data leaks and extortion tactics employed by threat actors such as the ShinyHunters group.
3
What group was responsible for the extortion mentioned in the article?
The ShinyHunters group was identified as the threat actor involved in the Salesforce extortion scheme.
4
What products or software are affected by the breach?
Salesforce is the primary software affected by the data breach and extortion activities discussed in the article.
5
What action was taken by law enforcement regarding the BreachForums site?
The FBI seized a domain associated with BreachForums to disrupt extortion activities linked to Salesforce attacks.