Back to topic hub

Dark Web

Understanding Hacking Forums: Intelligence for Cybersecurity Teams

Share on social

August 27, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter

Hacking forums are online communities where cybercriminals communicate, exchange knowledge, advertise services and conduct business. While some operate on the dark web, others maintain a presence on the clear web or operate across both.

For cybersecurity professionals, these forums provide valuable insight into the cybercriminal ecosystem. Threat actors use them to discuss vulnerabilities, trade stolen data and access, recruit collaborators, advertise criminal services and share techniques and tools.

Because forum activity can reveal how attackers communicate and prepare for attacks, monitoring these communities can provide an important source of dark web intelligence for defenders.

What Are Hacking Forums?

Hacking forums are online communities focused on hacking, cybercrime and related activities. In many ways, they operate similarly to legitimate online forums, with user accounts, discussion threads, private messages, reputation systems and administrators.

The difference is in the activities taking place within them.

Depending on the forum, users may discuss hacking techniques, vulnerabilities, malware, fraud, stolen databases, compromised accounts, and other forms of cybercrime. Forums can also provide a marketplace for criminal services, with users advertising everything from stolen information to access to compromised organizations.

Not all hacking forums operate exclusively on the dark web. Some use clear-web infrastructure, while others maintain both clear-web and dark-web versions. The distinction is therefore less important than understanding the communities and criminal activity taking place within them.

What Happens on Hacking Forums?

Hacking forums serve several functions within the wider cybercriminal ecosystem.

Trading stolen data

Forums can be used to advertise and trade stolen databases, credentials and other compromised information. Sellers may use established communities to reach potential buyers and build a reputation.

Selling initial access

Threat actors may advertise access to compromised organizations, often obtained through vulnerabilities, stolen credentials, or compromised remote access services.

Access can be sold directly or auctioned to interested buyers, creating a secondary market around compromised organizations.

Discussing vulnerabilities and exploits

Forums provide places for threat actors to discuss vulnerabilities, share exploitation techniques and exchange tools.

This can give defenders visibility into how criminals are discussing vulnerabilities affecting technologies used by organizations.

Recruiting collaborators

Cybercrime is increasingly organized around specialist roles and partnerships. Forums can provide a place for threat actors to recruit developers, affiliates, initial access brokers and other specialists.

Ransomware operators, for example, may use forums to recruit affiliates to deploy their ransomware against victims.

Sharing knowledge and techniques

Experienced criminals can exchange advice, tools, and techniques with other members of the community. Some established forums have developed reputations as professional communities where experienced threat actors conduct business and collaborate on criminal operations.

Why Do Hacking Forums Matter to Cybersecurity?

Hacking forums provide visibility into activity that may take place before an attack reaches an organization.

An attacker does not necessarily need to compromise an organization themselves. They may purchase credentials, buy access from an Initial Access Broker, acquire tools from another criminal, or recruit a specialist through a forum.

This means that hacking forum activity can provide signals at different stages of the attack lifecycle.

For example:

  • An employee's credentials may be advertised for sale.
  • Access to an organization's network may be offered to buyers.
  • Threat actors may discuss a vulnerability affecting technology used by an organization.
  • Criminals may discuss an organization, sector, or technology as a potential target.
  • Ransomware groups may advertise affiliate opportunities or recruit collaborators.

These signals can give security teams an opportunity to investigate and act before an attack progresses.

Hacking Forums Are Part of a Wider Cybercriminal Ecosystem

Hacking forums do not operate in isolation.

A single criminal operation may involve multiple platforms and services. Credentials might be obtained through information-stealing malware, advertised on a forum, sold through a marketplace, and then used to gain access to an organization. A ransomware operator might recruit an affiliate through a forum before the affiliate uses purchased access to compromise a victim.

This interconnected ecosystem means that monitoring forums can provide context that would not be visible from an individual marketplace or leak site alone.

It also explains why hacking forums can remain valuable sources of intelligence even when individual communities disappear. Forums are frequently disrupted, seized, abandoned or replaced, but the underlying criminal ecosystem continues to evolve.

Why Monitor Hacking Forums?

For defenders, the value of monitoring hacking forums is not simply knowing what criminals are discussing. It is identifying information that could have a direct impact on an organization's security.

Monitoring can help organizations:

  • Identify compromised credentials and stolen data
  • Discover access to corporate systems being advertised
  • Identify discussions relating to vulnerabilities and exploits
  • Detect potential targeting
  • Understand emerging criminal techniques and services
  • Identify ransomware recruitment and activity
  • Investigate relationships between threat actors and criminal communities

The earlier relevant activity is identified, the more time security teams have to investigate, remediate exposure and strengthen their defenses.

The Hacking Forums to Watch

The cybercriminal forum landscape changes constantly. Established communities can disappear following law enforcement action, technical disruption or internal disputes, while new forums can emerge to attract users from disrupted communities.

The following list provides an overview of some of the most significant hacking forums currently relevant to cybersecurity professionals, including information on their history, activity, focus and role within the wider cybercriminal ecosystem.

BreachForums

Active Since: March 2022

Dark Web and Clear Web

Predominant Languages: English

Known Aliases of Admins or Staff: @Baphomet, ShinyHunters, Manitoba, Dedale

BreachForums launched in March 2022 as the successor to RaidForums, operating on both the clear and dark web to trade leaked databases and cybercrime tools. It first shut down in March 2023 after the arrest of administrator "pompompurin," but quickly reemerged in June 2023 under veterans like "Baphomet" and the hacking collective "ShinyHunters."

Despite an FBI seizure in May 2024, the forum returned just two weeks later, highlighted by a massive Ticketmaster database leak. Management underwent rocky changes in July 2024 when ShinyHunters stepped down for a poorly received new owner, Anastasia. By April 2025, the forum mysteriously shut down again.

After several failed revival attempts, the site briefly returned in December 2025 by restoring an old database backup. However, this latest iteration was short-lived; by June 2026, it shuttered its operations entirely, with its administrators confessing they were "just another clone" impersonating the original ShinyHunters.

Cracked

Active Since: April 2018

Clear Web

Predominant Languages: English

Known Aliases of Admins or Staff:KSZ, Barry, Darkness, Liars, Ping

Cracked is a clear web hacking forum that takes its name from the act of “cracking”, slang for breaking into accounts or software (usually with the intention of circumventing payment).

Users trade in tools, configs, tutorials, and other resources to achieve this end, such as leaked credential combo lists and SOCKS proxies, as well as discussing how to monetize their illicit activities.

Cracked was seized in January 2025 in Operation Talent, a German-led law enforcement operation that also disrupted Nulled forum. Cracked has since returned virtually unchanged from its pre-seizure form.

DamageLib

Active Since: July 2025

Dark Web and Clear Web

DamageLib is a predominantly Russian-speaking hacking forum, which sprung up in the wake of the arrest of XSS forum’s alleged administrator in July 2025.

Taking its name from XSS’s former title DamageLab, its staff team is believed to include several former XSS moderators. Unlike many other hacking forums, DamageLib ostensibly bans the sale of goods and services on its platform.

DarkForums

Active Since: November 2022

A spiritual successor to the RaidForums/BreachForums lineage, DarkForums has grown to become the top destination for selling and sharing stolen databases, at least in the English-speaking cybercrime sphere. Originally launched in 2022 as a spin-off of Indian hacking forum D4RK4RMY, DarkForums gained more and more users as the continuous seizures of BreachForums iterations took their toll on the brand’s perceived reliability.

Dread

Active Since: February 2018

Dark Web

Predominant Languages: English

Known Aliases of  Admins or Staff: mHugBunter, Paris, Syntax, Shakybeats, Solar

Dread is a dark web forum that was born out of Reddit’s clampdown on discussions around dark web markets and scamming techniques.

Almost since its inception it has been plagued by denial-of-service (DDoS) attacks that have at times left it virtually unusable. According to chief administrator HugBunter, the downtime is the result of a persistent adversary targeting the hidden service with the objective of extorting dark web markets that use Dread to communicate with their users. This downtime has led many users to migrate to Dread’s I2P mirror to access the dark web forum.

Nevertheless, it remains a popular hub for dark web netizens involved in the market scene, as well as those interested in broader cybercrime. Conversations on Dread are mainly focused on market and vendor reviews (with many dark web users relying on Dread as a source of information) but it also has popular subs on fraud techniques such as carding, hacking, and cybercrime job recruitment.

Exploit

Active Since: February 2005

Dark Web and Clear Web

Predominant Languages: Russian

Known Aliases of Admins or Staff: Admin, Support, Garant, Adv, BigBear, L.Luciano, Mr.Burns, Pixe1, JohnRipper, Oxygen, Quake3, Weaver

Exploit is an extremely long-running Russian cybercrime forum that has been active since at least 2005.

Exploit and other Russian forums tend to view themselves as more professional than other dark web communities, often shunning non-Russian speakers and those perceived as unskilled or inexperienced.

As such, the site acts as something of a network for career cybercriminals to connect with potential collaborators on illegal business ventures, be it hacking, scamming, or working on Ransomware-as-a-Service (RaaS) schemes. At times the ransomware aspect has been tempered – for example, during the unwanted attention Exploit received in the wake of the 2021 Colonial Pipeline attack.

In this vein, we regularly witness threat actors auctioning initial access to organizations, usually through VPN or other remote access software. The posts typically have a "start" price to kick off the auction, a "step" price that indicates the increments of bidding, and a "blitz" price if a bidder wants to buy the access outright.

LeakBase [OFFLINE]

Active Since: June 2021

Clear Web

Predominant Languages: English

Known Aliases of Admins or Staff: Chucky, BloodyMery, OrderCheck, TSR


LeakBase is a relative newcomer that gained popularity during the period of BREACHFORUMS disruption as an alternative source of hacked or leaked databases. The forum is suspected to be of Russian origin due to its rule against sharing any “data related to Russia”.

March 2026 Update: LeakBase was shut down in March 2026, in an international law enforcement action known as Operation Leak coordinated by Europol.

NotBreachForums

Active Since: July 2026

Dark Web and Clear Web

NotBreachForums emerged out of the instability of BreachForums and has been actively combative towards its predecessor, even compromising the site and stealing its database.

Focused on the buying, selling and sharing of breached databases, NotBreachForums is notable for its collaborations with other cybercrime entities, such as Vect ransomware and TeamPCP (the threat actor responsible for a wave of npm supply chain attacks). You can read more about the rise of NotBreachForums here: The 2026 ‘Forum Wars’: Deconstructing the BreachForums Drama

OmniForums [OFFLINE]

Active Since: February 2023

Dark Web

Predominant Languages: English

Known Aliases of Admins or Staff: dkkota, prince97

OnniForums caught the criminal underground’s attention when its admin dkkota leaked the user database of BreachForums.

OnniForums was launched in early 2023 and claims to already have 10,000 members. The forum is aimed at database leakers, malware developers, and drug users.

January 2025 update: Onniforums went offline in January 2025, after an unsuccessful attempt to sell the platform.

PwnForums

Active Since: March 2026

Dark Web and Clear Web

PwnForums is a successor-of-sorts to BreachForums, with its founding team alleged to comprise ex-moderators of the most recent iteration which fell in the 2026 Forum Wars.

Strengthening this claim of legitimacy is the fact PwnForums was able to migrate accounts, credits and user ranks from the old BreachForums domain. PwnForums focuses, unsurprisingly, on data leaks, but interestingly bans the targeting of CIS countries, which is unusual for a primarily English-speaking forum.

RAMP [OFFLINE]

Active Since: July 2021

Dark Web

Predominant Languages: Russian

Known Admins / Moderators: Admin, Nowheretogo, chaindel, vAz

The RAMP cybercrime forum is also considered “friendly” to Exploit and XSS, with one key differentiating factor: the forum widely accepts discussions about ransomware.

As a result, it is common to see threat actors launching new Ransomware-as-a-Service ventures and attempting to recruit affiliates here.

RAMP also seeks to welcome actors speaking languages other than English and Russian, and has been making an effort to translate key components into Mandarin to attract Chinese threat actors, though their presence remains limited so far. The forum sees less activity than XSS and Exploit, likely in part due to the cost of obtaining an account.

OFFLINE UPDATE JANUARY 2026: RAMP was seized by US law enforcement on January 28th, 2026, taking down both its Tor and clearweb domains. A suspected administrator of the site stated they do not intend to build a new forum “from scratch” to replace it.

RehubCom

Active Since: July 2025

Dark Web and Clear Web

RehubCom is a predominantly Russian-speaking hacking forum, which sprung up in the wake of the arrest of XSS forum’s alleged administrator in July 2025.

Launched by former XSS moderator Rehub, the forum covers topics such as vulnerability exploitation, malware, carding, spamming and social engineering. RehubCom also has a marketplace section, which hosts advertisements for ransomware affiliate programs, initial access to corporate networks, paid work and more.

RuTor

Active Since: October 2014

Dark Web and Clear Web

Predominant Languages: Russian

Known Aliases of  Admins or Staff: Senior Berlin, Screaming Eagle, Darkless, Viktor Palych

RuTor has been a prominent forum in the Russian dark web scene since 2015, with threads that span multiple pages—and years—on topics ranging from drugs, fraud, computer programming, and current affairs.

It is known for hosting region/city-specific “smoking rooms,” which acted as assembly points for dispossessed vendors and buyers following the takedown of drug market giant Hydra in April 2022.

Hydra’s demise, coupled with the Russian invasion of Ukraine, triggered a civil war of sorts in the Russian cybercrime community. RuTor suffered a hack at the hands of pseudo-hacktivist collective Killnet, before launching its own attack against rival forum WayAway.

Spear

Active Since: October 2025

Dark Web and Clear Web

Spear first surfaced in late 2025, but activity on the forum didn’t pick up until the following January.

Since then it has continued to grow, and while significantly smaller than its competitors – totalling around 15,000 posts and 7000 members at time of writing – it still serves as a popular hub for the sale of stolen data, infostealer logs and various cybercrime utilities.

T1erOne

Active Since: February 2026

Dark Web and Clear Web

T1erOne launched in February 2026, shortly after the law enforcement takedown of RAMP.

Viewed as a spiritual successor to RAMP, T1erOne is focused on ransomware scheme advertisement and recruitment, and requires a fee of $450 to access the forum.

XSS

Active Since: November 2004

Dark Web and Clear Web

Predominant Languages: Russian

Known Aliases of Admins or Staff: Admin, Guron_18, Haunt, IIIIXX, Kerberos, Marcus52, Pernat1y, Quake3, R_as, Weaver

Originally known as DaMaGeLaB, XSS is one of the longest-running dark web forums.

The site rebranded from DaMaGeLaB to XSS around 2018, potentially due to the arrest of one of its administrators a year prior for their involvement in operating the Andromeda botnet. Its new name is a reference to the well-known cross-site scripting web app vulnerability.

As with Exploit, XSS is very business-oriented, with sections on hacking, corporate access, database leaks, and even competitive intelligence.

XSS had previously acted as a recruitment and PR tool for Ransomware-as-a-Service (RaaS) schemes, although this content has been “banned” at certain times, presumably so the forum doesn’t attract too much unwanted attention from law enforcement.

In 2023, the forum appeared to trial an "XSSBot," a forum chatbot that we suspect used ChatGPT to power its responses. Forum users asked the XSSBot for information about different malware strains, for tips on how to obfuscate code, and to write a rap—among other things.

The suspected administrator of Xss was arrested in Ukraine in July 2025, in a French-led law enforcement operation. This led to several splinter forums being created, though Xss itself does continue to operate.

Tom Duncan

Author

Tom Duncan

Head of Content and Communications in Marketing

Related content

Dark Web

View Article

August 27, 2026

Dark Web Marketplaces: Intelligence for Cybersecurity and Law Enforcement

Dark Web

View Article

August 27, 2026

Ransomware Leak Sites: What Defenders Need to Know

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient