DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

The BreachForums case: The HHS-OIG did WHAT?!? Why?

Posted on March 25, 2023 by Dissent

Revelations contained in an affidavit by an FBI agent and a press release by the Department of Justice about the arrest of the owner of a popular hacking forum raise a few questions about the role of the U.S. Department of Health and Human Services Office of the Inspector General (HHS-OIG).

An affidavit by FBI Special Agent John Longmire in support of the criminal complaint against Conor Fitzpatrick, aka “Pompompurin” (Pom), the owner of BreachForums, states that since “on or around March 2022,”  HHS-OIG investigated an administrator and certain members of  BreachForums. The affidavit does not explain why HHS-OIG started investigating Pom or some of the new forum’s members. There had never been any public statement suggesting that HHS-OIG had been involved in investigating or seizing RaidForums, BreachForum’s predecessor, which had been seized in February. So why did HHS-OIG start investigating Pom and some BreachForum members in March 2022?

More intriguingly, the Department of Justice’s press release credits HHS-OIG for participating in a “disruption activity” that “caused BreachForums to go offline.” The DOJ press release does not explain why HHS-OIG got involved in that.

Because HHS-OIG has not issued any press release or statement explaining its actions, DataBreaches sent the agency an email with questions, including:

  1. Was this the first time HHS-OIG engaged in any “disruption” activity?
  2. Was the arrest of Fitzpatrick a bit rushed to prevent leakage of more data from DC Health Links? On March 9, forum user “Denfur” had re-listed the data previously posted for sale by “IntelBroker.” On March 13, Denfur added a post indicating that there was more data and that it would be leaked at some point. Two days later, a complaint was filed against Fitzpatrick, a search warrant was executed, and he was arrested. Correlation or causation?
  3. Was HHS-OIG’s participation in a disruption activity intended to get BreachForums down so that more DC Health Links data could not be leaked on the popular forum where it would be more likely to be noticed and downloaded?
  4. Did HHS-OIG’s disruption activity include brute force attempts on IntelBroker’s forum account? Those attacks had been reported to DataBreaches by a self-described friend of IntelBroker. The same friend claims that the brute force attacks were why IntelBroker self-banned (brute force attacks do not work against suspended accounts).
  5. Did HHS-OIG’s disruption activity include accessing a server with the intention that the access would be noticed by the new administrator, who would then be less likely to put the forum back up? In other words: did Baphomet see the access he was intended to see and respond as any security-conscious administrator would respond by not putting the forum back up?
  6. Can HHS-OIG explain what statute, law, or regulation gives HHS-OIG the authority to engage in any disruptive activities targeting cybercrime websites or individuals?

Those were DataBreaches’ questions. You may have others.

If this site gets any answers, this post will be updated, but a reply to the email has not been received.

Update of March 28: A reply from HHS-OIG today reads, “Thank you for contacting HHS-OIG. We are not able to provide further information regarding this case.”

Category: Commentaries and AnalysesFederalHealth DataLegislationOf Note

Post navigation

← Cyber breach affects eastern NC postal service
Hackers attack Wisconsin court system computer network →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup
  • Montana Attorney General launches investigation into Lee Enterprises data breach
  • AT&T gets preliminary approval for $177 million data breach settlement
  • Aflac notifies SEC of breach suspected to be work of Scattered Spider
  • Former JBLM soldier pleads guilty to attempting to share military secrets with China
  • No, the 16 billion credentials leak is not a new data breach — a wake-up call about fake news (Updated)
  • Tonga’s health system hit by cyberattack (1)
  • Russia Expert Falls Prey to Elite Hackers Disguised as US Officials
  • Proposed class action settlement in In re Netgain Technology litigation
  • Qilin Offers “Call a lawyer” Button For Affiliates Attempting To Extort Ransoms From Victims Who Won’t Pay

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data
  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.
Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report