Updating: Two Telegram channels and two accounts banned, one bounty offered, and BreachForums goes down - DataBreaches.Net Published: 2025-08-12 · Archived: 2026-04-09 02:18:10 UTC If you were glued to a Telegram channel the other day watching people associated with ShinyHunters, Scattered Spider, and Lapsu$ leak data and rant about Mandiant, the NCA, the FBI, and demand that some arrested folks be set free, then you might want to think of yesterday and today as the next episode to the daytime drama. But first: it looks like FalconFeeds.io has a detailed timeline of the Telegram channel in question. I am unabashedly jealous of people who have the time and resources to produce detailed and documented reports that take 18 minutes to read. View the following as a TL;DR version of developments since this site’s previous post about the Telegram channel that appeared on August 8. By yesterday morning, the channel that had been  leaking hacked data, offering data for sale, and making threats against Mandiant had been banned, as was the account recently used by “Shiny” (the individual and seeming leader of ShinyHunters).  A backup channel for the group’s main channel was now being used, but it seemed that users who had been so active previously (including ShinyCorp, Yuka, UNC3944, UNC5537, Rey, zzz, Famous PORNSTAR, and others)  were now pretty quiet. There was no flood of leaks or much of anything yesterday morning, but maybe everyone was just re-grouping after losing the main channel and were getting ready to become active again. If so, their plans were derailed in the afternoon. A Bounty Offered on Yukari Somewhat surprisingly (to DataBreaches, anyway),  yesterday afternoon an announcement appeared on BreachForums offering a $500,000.00 bounty, payable in XMR, for information on the individual known as “Yukari.”  DataBreaches was surprised because the individual known as Yukari is a long-time friend and ally of ShinyHunters. That a bounty would be posted on BreachForums made this blogger wonder if there had suddenly been a serious falling out between friends, or if ShinyHunters was just trolling with the reward announcement, or if there was some other explanation. The reward offer pointed people to a Telegram account set up specifically for information on Yukari. That account does not appear to have been banned or deleted. Compromised About 30 minutes after someone posted, “We are back,”  Shiny posted, “Hey, it’s me Shiny again, tonight I’m here to share some really bad news I found out while being banned.” What followed was a pgp-signed message, a copy of which was also uploaded to Pastebin. The gist of the message was that BreachForums was compromised and is allegedly under the control of law enforcement in France and https://databreaches.net/2025/08/12/updating-two-telegram-channels-and-two-accounts-banned-one-bounty-offered-and-breachforums-goes-down/ Page 1 of 2 U.S. law enforcement. The BreachForums accounts of “ShinyHunters” and “Hollow” had been compromised, Shiny claimed, and the new founder, “N/A,” was allegedly “a fed.” [DataBreaches is reporting the claims, but has no way of verifying or refuting any of them. DataBreaches is reporting them simply because they help explain what happened next.] Shiny also claimed that the bounty post that had been posted by the ShinyHunters account on BreachForums was not by ShinyHunters and was a result of the compromise. Shortly after Shiny posted on Telegram, BreachForums went down and is still down. Who took it down has not been confirmed, and whether it will stay down and whether a seizure notice will appear is unknown at this time. A check of the nameservers for the forum does not indicate any change to nameservers owned by the government as of this publication. Playing Whack-A-Mole Compared to the weekend’s frenzied posting on the main Telegram channel, the backup/discussion Telegram channel was relatively quiet. Then someone posted  a few redacted screenshots that appear to be redacted requests from U.S. Interpol (NCB) to France in June 2024 concerning ShinyHunters. And then they also  threatened FalconFeeds with a DDoS attack because their reporting cited content that angered the posters. Since everyone and their grandmother had to know that everybody in law enforcement and every intel firm would be scraping everything in the channel, it seems a tad unreasonable for posters to blame FalconFeeds or anyone else for reporting or re-posting what they themselves had posted. And then, of course, there was also the fact that they threatened a DDoS attack. Hours later, the backup channel was banned too. Whether it was banned because of the redacted NCB images or because of DDoS threat or for some other other reason is not known to DataBreaches. By publication time, though, another channel had been opened. In messages that appear to be written by Shiny, we read: After I leaked that BF was compromised by law enforcement a few hours later they took the site down and they just got the Telegram channel @sp1d3rlapsushunters banned. We are in literal war. I don’t know what they don’t understand but they aren’t winning this at all lol At this point, I think they may have lost sight of a bigger picture. What were they trying to accomplish with this channel and activity? And what impression have they really created for future targets? Source: https://databreaches.net/2025/08/12/updating-two-telegram-channels-and-two-accounts-banned-one-bounty-offered-and-breachforums -goes-down/ https://databreaches.net/2025/08/12/updating-two-telegram-channels-and-two-accounts-banned-one-bounty-offered-and-breachforums-goes-down/ Page 2 of 2