Skip to content

Ramp4u Cybercrime Forum Allegedly Breached, 340,000 IP Logs and Private Messages Published

Breach Report Jurisdiction Unclear Cybercrime Forum Free Download

Ramp4u Cybercrime Forum Allegedly Breached, 340,000 IP Logs and Private Messages Published

A forum user posting as kitta has published what they describe as the database of Ramp4u, a Russian-language cybercrime and dark web forum. The breach is dated to March 2024 and claimed to cover 7,709 users. Beyond usernames, email addresses, and credential hashes, the release includes the forum's private message table, its posts and threads, and 340,333 IP log entries. In this case the exposed population is the forum's own membership, which inverts the usual reading: the harm to the public is limited, while the value to investigators is not. The claim is unverified.

IP logs340,333
Users7,709
Private messages3,875
Actorkitta

Post details

TargetRamp4u
JurisdictionNot established
SectorCybercrime forum
ListingFree — reply to unlock
Users7,709
Content7,784 posts / 1,732 threads
Breach datedMarch 2024
Actorkitta

!Allegedly included

  • Usernames
  • Email addresses
  • Password hashes & salts
  • IP address logs
  • Private messages
  • Posts & threads
  • Registration timestamps
  • Last visit timestamps
  • Timezone settings
  • Account status flags

Screenshot

Potential impact

The IP log table is the significant asset, not the user count. Forum members typically connect through VPNs or Tor, but across 340,000 log entries a single lapse is statistically likely, and one unprotected login is enough to tie a handle to a person. Attribution value does not decay the way operational data does, so the March 2024 date matters little. The private messages compound this, since operational negotiation tends to be franker than public posting. Reused email addresses allow correlation against other datasets. Sample usernames reference known ransomware brands, though a chosen handle evidences nothing about identity.

iStatus

Unverified

The sample shows a standard forum software user table, consistent with a database export rather than an assembled list. The data is roughly two and a half years old and may already have circulated privately before this release. The same account published two unrelated databases within the past fortnight. Nothing has been independently corroborated, and the forum's operators are in no position to confirm or deny. The claim is unverified.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest