PwnForums protège-t-il délibérément la Russie ?
A PwnForums administrator swiftly removed an announcement about Getmeback.ru, a Russian service offering payment solutions, citing a strict policy prohibiting Russian databases and data from several surrounding countries, including Ukraine. This action, alongside the forum's selective enforcement of its rules – banning Russian data while allowing leaks from other nations – raises questions about the forum's true political alignment and suggests a deliberate strategy to both protect Russian data and potentially lure in members operating from restricted regions. The incident highlights that a forum's internal rules and moderation practices can be valuable intelligence sources, revealing not just what is published, but also what is actively suppressed.
A PwnForums administrator swiftly removed an announcement about Getmeback.ru, a Russian service offering payment solutions, citing a strict policy prohibiting Russian databases and data from several surrounding countries, including Ukraine. This action, alongside the forum's selective enforcement of its rules – banning Russian data while allowing leaks from other nations – raises questions about the forum's true political alignment and suggests a deliberate strategy to both protect Russian data and potentially lure in members operating from restricted regions.
According to ZATAZ’s observations, PwnForums has over 850,000 messages, 82,000 discussions, and 366,000 members. The forum has been a prominent hub within the cybercrime ecosystem, with recent announcements revealing data breaches targeting France, alongside leaks from other countries.
Recently, a member using the pseudonym 3p published an announcement about Getmeback.ru, a Russian service. Immediately after, the administrator intervened, deleting the post and stating that “Russian databases are not allowed here.” The administrator then linked to an internal document titled “Statement Regarding Russian Data(CIS),” dated May 15, 2026, which explicitly prohibits activities involving Russian data and data from several post-Soviet states, including Ukraine, Belarus, Kazakhstan, Azerbaijan, Armenia, Kirghizstan, Tajikistan, Turkmenistan, Moldova, and Georgia. The document also notes that Ukraine is not a member of the Commonwealth of Independent States (CIS) but has never ratified its charter, and the other countries listed have varying degrees of association with the CIS.
This action follows a similar incident three years prior, where a post about Gemotest.ru, a Russian laboratory, was removed after offering access to compromised data from 3.04 million people, including names, birthdates, genders, phone numbers, email addresses, physical addresses, insurance numbers, and passports. The data was offered for sale, and the forum had become increasingly pro-Russian since May 2026.
ZATAZ’s analysis indicates that the forum’s selective enforcement – banning Russian data while allowing leaks from other nations – is a deliberate strategy. The rapid deletion of posts about Russian data, combined with the presence of leaks from countries outside the banned list, suggests a calculated effort to protect Russian data while potentially luring in members operating from restricted regions. The forum’s actions are not simply a matter of enforcing rules; they are a form of intelligence gathering, revealing what is being protected and what is being encouraged. The rapid deletion of posts and the consistent presence of leaks from outside the banned list are valuable indicators of the forum's operations and potential targets. The case of LeakBase and its administrator, apprehended by local authorities, demonstrates that internal forum rules are not a guarantee of impunity and that the forum's internal policies are a valuable source of intelligence.
