DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

The BreachForums case: The HHS-OIG did WHAT?!? Why?

Posted on March 25, 2023 by Dissent

Revelations contained in an affidavit by an FBI agent and a press release by the Department of Justice about the arrest of the owner of a popular hacking forum raise a few questions about the role of the U.S. Department of Health and Human Services Office of the Inspector General (HHS-OIG).

An affidavit by FBI Special Agent John Longmire in support of the criminal complaint against Conor Fitzpatrick, aka “Pompompurin” (Pom), the owner of BreachForums, states that since “on or around March 2022,”  HHS-OIG investigated an administrator and certain members of  BreachForums. The affidavit does not explain why HHS-OIG started investigating Pom or some of the new forum’s members. There had never been any public statement suggesting that HHS-OIG had been involved in investigating or seizing RaidForums, BreachForum’s predecessor, which had been seized in February. So why did HHS-OIG start investigating Pom and some BreachForum members in March 2022?

More intriguingly, the Department of Justice’s press release credits HHS-OIG for participating in a “disruption activity” that “caused BreachForums to go offline.” The DOJ press release does not explain why HHS-OIG got involved in that.

Because HHS-OIG has not issued any press release or statement explaining its actions, DataBreaches sent the agency an email with questions, including:

  1. Was this the first time HHS-OIG engaged in any “disruption” activity?
  2. Was the arrest of Fitzpatrick a bit rushed to prevent leakage of more data from DC Health Links? On March 9, forum user “Denfur” had re-listed the data previously posted for sale by “IntelBroker.” On March 13, Denfur added a post indicating that there was more data and that it would be leaked at some point. Two days later, a complaint was filed against Fitzpatrick, a search warrant was executed, and he was arrested. Correlation or causation?
  3. Was HHS-OIG’s participation in a disruption activity intended to get BreachForums down so that more DC Health Links data could not be leaked on the popular forum where it would be more likely to be noticed and downloaded?
  4. Did HHS-OIG’s disruption activity include brute force attempts on IntelBroker’s forum account? Those attacks had been reported to DataBreaches by a self-described friend of IntelBroker. The same friend claims that the brute force attacks were why IntelBroker self-banned (brute force attacks do not work against suspended accounts).
  5. Did HHS-OIG’s disruption activity include accessing a server with the intention that the access would be noticed by the new administrator, who would then be less likely to put the forum back up? In other words: did Baphomet see the access he was intended to see and respond as any security-conscious administrator would respond by not putting the forum back up?
  6. Can HHS-OIG explain what statute, law, or regulation gives HHS-OIG the authority to engage in any disruptive activities targeting cybercrime websites or individuals?

Those were DataBreaches’ questions. You may have others.

If this site gets any answers, this post will be updated, but a reply to the email has not been received.

Update of March 28: A reply from HHS-OIG today reads, “Thank you for contacting HHS-OIG. We are not able to provide further information regarding this case.”

Category: Commentaries and AnalysesFederalHealth DataLegislationOf Note

Post navigation

← Cyber breach affects eastern NC postal service
Hackers attack Wisconsin court system computer network →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks
  • Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • $28 million in Texas’ cybersecurity funding for schools left unspent
  • Cybersecurity incident at Central Point School District 6

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025
  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
  • FTC dismisses privacy concerns in Google breakup

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.