Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SecurityWeek reported in March 2021 that four predominantly Russian-language cybercrime forums—Verified, Crdclub, Exploit and Maza—had faced breaches or attempted intrusions between January and March. The incidents exposed different risks, from alleged cryptocurrency theft and account-enabled fraud to a partial data leak. The report did not identify who was responsible, and some claims about what was exposed remained disputed.

Which cybercrime forums were breached?

The incidents were not all the same kind of breach. SecurityWeek’s March 5, 2021 report described them as follows:

Month and forum Reported access or incident Data or assets reportedly affected Corroboration and uncertainty
January — Verified A threat actor announced on Raid Forums that they had breached the forum and held its database. The announcement reportedly included registered-user details, private messages, posts, threads and hashed passwords. SecurityWeek said the hacker apparently transferred $150,000 worth of cryptocurrency from the forum’s wallet and offered the database for $100,000. The database contents and cryptocurrency transfer were reported claims, not independently verified losses; the asking price does not show that the data sold.
February — Crdclub The administrator account was reportedly hacked. The intruder used the account to direct customers to a fraudulent money-transfer service and divert an unknown amount of money. The report did not quantify the losses.
March — Exploit An attacker apparently gained SSH access to a proxy server used for DDoS protection and attempted to dump network traffic. Users discussed moving away from email registration. Some forum users claimed the leaked database was old or incomplete. Those claims about the database’s age or completeness were user discussion, not a verified assessment of all records.
March — Maza The invite-only forum, described as active since 2003, displayed a breach notification on March 3. An accompanying PDF contained over 3,000 rows with usernames, email addresses, other contact details and partially obfuscated password hashes. Intel 471 said some leaked data correlated with its prior research, confirming that at least some Maza databases had been breached. This did not establish that the complete database was exposed or that each row represented a unique person.

What user data was leaked from Maza?

The Maza notice came with a PDF containing over 3,000 rows of user-related information, including usernames, email addresses, other contact details and partially obfuscated password hashes. SecurityWeek reported that Intel 471 found some of the leaked data correlated with its earlier research, supporting the conclusion that at least some Maza databases had been breached.

The reported row count is not a count of confirmed affected people: the report did not establish that the file represented the full database or that every row belonged to a unique individual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who hacked the forums?

SecurityWeek said the actor’s identity was unknown and that no one appeared to have claimed responsibility. The report relayed Intel 471’s assessment that the attacks’ public nature ruled out a law-enforcement operation; that was Intel 471’s conclusion, not an independently established fact in the article.

Evidence varied by forum. Verified’s database contents and wallet transfer were described as reported claims; Exploit users disputed the age or completeness of the data; and Intel 471’s correlation of Maza data supported a breach of at least some databases, not the full scope of exposure. These distinctions matter: an intrusion attempt, an attacker’s announcement and corroborated data are not interchangeable proof.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the incidents mattered beyond the forums

These cases showed that communities trading on anonymity could still expose members to account compromise, fraud and disclosure of their identities or activity. SecurityWeek noted that the breaches could give security researchers greater visibility into who used the forums.

In 2023, Sophos described a broader effect of breaches and law-enforcement takedowns: weakened confidence in traditional cybercrime forums and marketplaces, alongside some cybercriminals using Telegram to advertise. That is dated ecosystem context, not evidence about what happened to Verified, Crdclub, Exploit or Maza after the 2021 incidents, or a measure of present-day activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.