Troy Hunt claims that Carding Mafia, a forum for stealing and trading credit cards, has been hacked, exposing emails, usernames, and passwords for ~300K hackers
Lorenzo Franceschi-Bicchierai / VICE : Tweets: @lorenzofb , @peterwsinger , @edbott , and @x0rz Tweets: Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Hackers hacked a credit card hacking forum, exposing the data of 300,000 hackers. The forum is Carding Mafia, and for now they haven't announced the breach to their users. https://www.vice.com/... Peter W. Singer / @peterwsinger : Hacker on hacker crime, ya hate to see it. “Credit Card Hacking Forum Gets Hacked, Exposing 300,000 Hackers' Accounts” https://www.vice.com/... Ed Bott / @edbott : “Hackers hacked a hacking forum...” is peak Broken Internet. https://twitter.com/... @x0rz : That is pure speculation of course, but if LE wants to win against cybercrime using ✨cyber✨, that's the only winning move. Otherwise it's an always-losing cat & mouse game. Also, if you're doing crime and that isn't in your threat model, you're going to have a bad time in jail. https://twitter.com/...
Context & Ripple Effects
The breach fits a pattern rather than standing alone: weeks before Carding Mafia was hit, three of the longest-running Russian cybercrime forums were hacked in a single month, leaking member email addresses and login metadata. The same playbook goes back further — the Cracked.to database ended up posted at rival site Raidforums in 2019, exposing IPs, emails, and DMs.
What makes this instance notable is who found it: Troy Hunt, whose Have I Been Pwned service has become the standard intake point for exactly this kind of leaked credential corpus, meaning the data can flow straight into victim notification rather than staying a curiosity inside the underground.
First-order effects
- Roughly 300,000 registered users of Carding Mafia now have their emails, usernames, and passwords exposed, while the forum itself — per VICE's reporting — has not announced the breach to its own membership.
- Defenders gain an unusual dataset: credentials belonging to active carders, which banks, researchers, and investigators can cross-reference against fraud patterns in ways a consumer breach never allows.
Second-order effects
- Members of Carding Mafia and rival carding forums face forced credential rotation and identity exposure, echoing the de-anonymization pressure the Russian forum leaks put on their user bases just weeks earlier.
- Have I Been Pwned becomes the likely public distribution point for the corpus, shifting visibility of underground breaches from closed forums to mainstream breach-notification channels.
Third-order effects
- If forum-on-forum hacking keeps recurring — Russian forums, Cracked.to, now Carding Mafia — operational security across criminal marketplaces structurally weakens, making every member list a future law-enforcement or researcher asset and eroding the trust these venues depend on.
- Breach data increasingly originates from the criminals themselves, pushing breach-notification infrastructure like Hunt's into a role of policing the underworld as much as protecting consumers.
The trend: Cybercrime forums are becoming their own richest source of breached credentials, turning underground membership lists into recurring raw material for defenders and investigators.