Landmark Penalty in Cybercrime Marketplace Case
Conor Brian Fitzpatrick, a 22-year-old cybercrime figure once at the helm of the notorious BreachForums, has agreed to surrender nearly $700,000 to resolve a civil case tied to a major breach of healthcare data.
This marks a rare and consequential move in the fight against online data trafficking—where a platform operator is being held financially accountable for enabling the trade of stolen information.
BreachForums, which Fitzpatrick launched in March 2022 as a follow-up to the shuttered RaidForums, quickly became a central hub for illicit data sales. Unlike many forum operators who remain anonymous or hands-off, Fitzpatrick took a direct role: personally verifying leaked databases and offering middleman services to ensure transactions went through.
Under his control, the forum drew more than 300,000 members and became a marketplace for over 14 billion compromised records.
Even after multiple crackdowns by global law enforcement, including the latest takedown in April 2025, versions of BreachForums continue to reappear, illustrating the resilience of cybercriminal infrastructure and the challenges in dismantling it for good.
The case against Fitzpatrick—who operated under the alias “Pompompurin”—emerged after stolen records from California insurer Nonstop Health were spotted for sale on the forum in early 2023. The civil suit reflects a growing trend: targeting enablers of cybercrime not just with criminal charges, but with substantial financial consequences.

New Legal Frontier: Cybercrime Admin Held Liable in Health Data Breach Settlement
A high-profile data breach involving California-based insurance firm Nonstop Health has led to the exposure of tens of thousands of sensitive customer records—including Social Security numbers, full birthdates, physical addresses, and phone numbers—marking a major breach of personal privacy.
But what followed may be even more unprecedented.
In a bold legal maneuver with no prior equivalent, Nonstop Health’s legal team took the unusual step of naming Conor Brian Fitzpatrick—a known cybercrime forum operator—as a third-party defendant in their ongoing class action suit. The move came just months after Fitzpatrick’s arrest on federal charges, including access device fraud and possession of child sexual abuse material.
“This marks a first in civil cyber litigation,” said Jill Fertel, head of cyber litigation at Cipriani & Werner and former prosecutor. “It’s the only case on record where a figure associated with the breach itself has been pulled into a civil suit.”
Fitzpatrick, known online as “Pompompurin,” had run BreachForums, a darknet marketplace infamous for brokering stolen data. Legal experts say the decision to pursue him for financial damages sets a new tone in how victims—and their attorneys—are seeking justice.
Cyber Laws Meet Civil Liability
The case adds momentum to a growing trend of targeting individual cyber actors through civil court—something rarely seen in the legal world.
“This kind of accountability is rare,” said Mark Rasch, a veteran federal prosecutor now advising cybersecurity firm Unit 221B. “You almost never get the name, let alone the resources, of the threat actor. This was a unicorn scenario.”
Fitzpatrick’s $700,000 payout is now folded into Nonstop Health’s total $1.6 million class action settlement finalized in early 2025. Affected customers will be eligible for up to $5,000 in compensation for direct losses stemming from identity theft, fraud, and related expenses.
Ongoing Criminal Fallout
While the civil suit may be winding down, Fitzpatrick’s criminal proceedings remain very much active.
Despite pleading guilty to possessing more than 600 illicit images of child sexual abuse material, he was initially sentenced to time served and 20 years of supervised release in early 2024. That ruling was met with outrage—and a successful appeal from federal prosecutors, who argued the punishment failed to reflect the scope of the crimes.
Their case was bolstered when Fitzpatrick allegedly defied his supervised release by reengaging in prohibited online activity, including using VPNs to access restricted systems and publicly denying responsibility on Discord.
In response, the U.S. Court of Appeals nullified his original sentence in January 2025. A new sentencing hearing is scheduled for June 3, 2025.




