Conor Brian Fitzpatrick, the 22-year-old former administrator of cybercrime marketplace BreachForums, will forfeit nearly $700,000 to settle a civil lawsuit related to a healthcare data breach.
This is a rare instance of a threat actor directly facing financial penalties for facilitating the sale of stolen data on their platform.
Fitzpatrick launched BreachForums in March 2022 as a successor to RaidForums, which the FBI had shut down.
As an administrator, he personally vetted databases for sale and offered escrow services to facilitate transactions.
Under his administration, BreachForums accumulated over 300,000 users and facilitated the sale of databases containing over 14 billion individual records.
Despite multiple law enforcement takedowns, including the most recent in April 2025, variations of BreachForums have repeatedly resurfaced online, demonstrating the persistent challenge of permanently disrupting cybercriminal marketplaces.
Fitzpatrick, known online as “Pompompurin,” was implicated after sensitive personal information from Nonstop Health, a California-based insurance provider, appeared for sale on BreachForums in January 2023.
The data breach exposed tens of thousands of records containing Social Security numbers, birthdates, addresses, and phone numbers of Nonstop Health customers.
In an unprecedented legal strategy, Nonstop Health’s attorneys added Fitzpatrick as a third-party defendant to their class action litigation in November 2023, following his arrest by the FBI on criminal charges of conspiracy to commit access device fraud under 18 U.S.C. § 1029 and possession of child sexual abuse material.
“This is the first and only case where a cybercriminal or anyone related to the security incident was actually named in civil litigation,” said Jill Fertel, a former prosecutor who leads the cyber litigation practice at Cipriani & Werner, representing Nonstop Health.
KrebsOnSecurity reports that the settlement represents a significant shift in how threat actors may be held accountable through civil channels.
Mark Rasch, a former federal prosecutor now with cybersecurity firm Unit 221B, highlighted the rarity of such outcomes.
“It is rare in these civil cases that you know the threat actor involved in the breach, and it’s also rare that you catch them with sufficient resources to be able to pay a claim,” Rasch explained.
The $700,000 from Fitzpatrick will become part of the broader $1.6 million class action settlement that Nonstop Health agreed to in January 2025.
Class members can receive reimbursement for out-of-pocket losses up to $5,000 for unreimbursed fraud, identity theft, and related costs.
Fitzpatrick’s legal troubles extend beyond civil liability. Despite pleading guilty to serious charges, including possession of over 600 CSAM images, he initially received a relatively lenient sentence in January 2024 – time served plus 20 years of supervised release.
Federal prosecutors appealed this sentence, arguing it failed to reflect the severity of his crimes.
Their case strengthened when Fitzpatrick violated his release conditions by accessing unauthorized computer systems via virtual private networks (VPNs) and professing innocence on Discord despite his guilty plea.
In January 2025, the U.S. Court of Appeals vacated his original sentence and ordered resentencing for June 3, 2025.
Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…