Cyber Security News

BreachForums Admin to Pay $700,000 in Health Care Data Breach

Conor Brian Fitzpatrick, the 22-year-old former administrator of cybercrime marketplace BreachForums, will forfeit nearly $700,000 to settle a civil lawsuit related to a healthcare data breach. 

This is a rare instance of a threat actor directly facing financial penalties for facilitating the sale of stolen data on their platform.

Fitzpatrick launched BreachForums in March 2022 as a successor to RaidForums, which the FBI had shut down. 

As an administrator, he personally vetted databases for sale and offered escrow services to facilitate transactions.

Under his administration, BreachForums accumulated over 300,000 users and facilitated the sale of databases containing over 14 billion individual records. 

Despite multiple law enforcement takedowns, including the most recent in April 2025, variations of BreachForums have repeatedly resurfaced online, demonstrating the persistent challenge of permanently disrupting cybercriminal marketplaces.

New Cybercrime Lawsuit Approach

Fitzpatrick, known online as “Pompompurin,” was implicated after sensitive personal information from Nonstop Health, a California-based insurance provider, appeared for sale on BreachForums in January 2023. 

The data breach exposed tens of thousands of records containing Social Security numbers, birthdates, addresses, and phone numbers of Nonstop Health customers.

In an unprecedented legal strategy, Nonstop Health’s attorneys added Fitzpatrick as a third-party defendant to their class action litigation in November 2023, following his arrest by the FBI on criminal charges of conspiracy to commit access device fraud under 18 U.S.C. § 1029 and possession of child sexual abuse material.

“This is the first and only case where a cybercriminal or anyone related to the security incident was actually named in civil litigation,” said Jill Fertel, a former prosecutor who leads the cyber litigation practice at Cipriani & Werner, representing Nonstop Health.

“Pompompurin” Settlement

KrebsOnSecurity reports that the settlement represents a significant shift in how threat actors may be held accountable through civil channels. 

Mark Rasch, a former federal prosecutor now with cybersecurity firm Unit 221B, highlighted the rarity of such outcomes.

“It is rare in these civil cases that you know the threat actor involved in the breach, and it’s also rare that you catch them with sufficient resources to be able to pay a claim,” Rasch explained.

The $700,000 from Fitzpatrick will become part of the broader $1.6 million class action settlement that Nonstop Health agreed to in January 2025. 

Class members can receive reimbursement for out-of-pocket losses up to $5,000 for unreimbursed fraud, identity theft, and related costs.

Fitzpatrick’s legal troubles extend beyond civil liability. Despite pleading guilty to serious charges, including possession of over 600 CSAM images, he initially received a relatively lenient sentence in January 2024 – time served plus 20 years of supervised release.

Federal prosecutors appealed this sentence, arguing it failed to reflect the severity of his crimes. 

Their case strengthened when Fitzpatrick violated his release conditions by accessing unauthorized computer systems via virtual private networks (VPNs) and professing innocence on Discord despite his guilty plea.

In January 2025, the U.S. Court of Appeals vacated his original sentence and ordered resentencing for June 3, 2025.

Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago