DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

The BreachForums case: The HHS-OIG did WHAT?!? Why?

Posted on March 25, 2023 by Dissent

Revelations contained in an affidavit by an FBI agent and a press release by the Department of Justice about the arrest of the owner of a popular hacking forum raise a few questions about the role of the U.S. Department of Health and Human Services Office of the Inspector General (HHS-OIG).

An affidavit by FBI Special Agent John Longmire in support of the criminal complaint against Conor Fitzpatrick, aka “Pompompurin” (Pom), the owner of BreachForums, states that since “on or around March 2022,”  HHS-OIG investigated an administrator and certain members of  BreachForums. The affidavit does not explain why HHS-OIG started investigating Pom or some of the new forum’s members. There had never been any public statement suggesting that HHS-OIG had been involved in investigating or seizing RaidForums, BreachForum’s predecessor, which had been seized in February. So why did HHS-OIG start investigating Pom and some BreachForum members in March 2022?

More intriguingly, the Department of Justice’s press release credits HHS-OIG for participating in a “disruption activity” that “caused BreachForums to go offline.” The DOJ press release does not explain why HHS-OIG got involved in that.

Because HHS-OIG has not issued any press release or statement explaining its actions, DataBreaches sent the agency an email with questions, including:

  1. Was this the first time HHS-OIG engaged in any “disruption” activity?
  2. Was the arrest of Fitzpatrick a bit rushed to prevent leakage of more data from DC Health Links? On March 9, forum user “Denfur” had re-listed the data previously posted for sale by “IntelBroker.” On March 13, Denfur added a post indicating that there was more data and that it would be leaked at some point. Two days later, a complaint was filed against Fitzpatrick, a search warrant was executed, and he was arrested. Correlation or causation?
  3. Was HHS-OIG’s participation in a disruption activity intended to get BreachForums down so that more DC Health Links data could not be leaked on the popular forum where it would be more likely to be noticed and downloaded?
  4. Did HHS-OIG’s disruption activity include brute force attempts on IntelBroker’s forum account? Those attacks had been reported to DataBreaches by a self-described friend of IntelBroker. The same friend claims that the brute force attacks were why IntelBroker self-banned (brute force attacks do not work against suspended accounts).
  5. Did HHS-OIG’s disruption activity include accessing a server with the intention that the access would be noticed by the new administrator, who would then be less likely to put the forum back up? In other words: did Baphomet see the access he was intended to see and respond as any security-conscious administrator would respond by not putting the forum back up?
  6. Can HHS-OIG explain what statute, law, or regulation gives HHS-OIG the authority to engage in any disruptive activities targeting cybercrime websites or individuals?

Those were DataBreaches’ questions. You may have others.

If this site gets any answers, this post will be updated, but a reply to the email has not been received.

Update of March 28: A reply from HHS-OIG today reads, “Thank you for contacting HHS-OIG. We are not able to provide further information regarding this case.”

Related posts:

  • Was there a rush to arrest Pompompurin, the owner of BreachForums? If so, why?
  • Confused about the drama with the new BreachForums? Reading this will either help you or make your head spin.
  • The “reincarnation” of BreachForums: A cyberdrama in three acts
  • Justice Department Announces Arrest of “Pompompurin” and Disruption of BreachForum’s Operation
Category: Commentaries and AnalysesFederalHealth DataLegislationOf Note

Post navigation

← Cyber breach affects eastern NC postal service
Hackers attack Wisconsin court system computer network →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • McDonald’s McHire leak involving ‘123456’ admin password exposes 64 million applicant chat records
  • Qilin claims attack on Accu Reference Medical Laboratory. It wasn’t the lab’s first data breach.
  • Louis Vuitton hit by data breach in Türkiye, over 140,000 users exposed; UK customers also affected (1)
  • Infosys McCamish Systems Enters Consent Order with Vermont DFR Over Cyber Incident
  • Obligations under Canada’s data breach notification law
  • German court offers EUR 5000 compensation for data breaches caused by Meta
  • Air Force Employee Pleads Guilty to Conspiracy to Disclose Unlawfully Classified National Defense Information
  • UK police arrest four in connection with M&S, Co-op and Harrods cyberattacks (1)
  • At U.S. request, France jails Russian basketball player Daniil Kasatkin on suspicion of ransomware conspiracy
  • Avantic Medical Lab hacked; patient data leaked by Everest Group

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • DeleteMyInfo Wins 2025 Digital Privacy Excellence Award from Internet Safety Council
  • TikTok Loses First Appeal Against £12.7M ICO Fine, Faces Second Investigation by DPC
  • German court offers EUR 5000 compensation for data breaches caused by Meta
  • How to Build on Washington’s “My Health, My Data” Act
  • Department of Justice Subpoenas Doctors and Clinics Involved in Performing Transgender Medical Procedures on Children
  • Google Settles Privacy Class Action Over Period Tracking App
  • ICE Is Searching a Massive Insurance and Medical Bill Database to Find Deportation Targets

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.