.___ .___ ___. __ __ __ __| _/_______ ___ ____ __| _/ \_ |__ ___.__. ____ _____ _____| | __ _____/ |__/ |_ / __ |/ _ \ \/ // __ \ / __ | | __ < | | _/ ___\\__ \ / ___/ |/ // __ \ __\ __\ / /_/ ( <_> > <\ ___// /_/ | | \_\ \___ | \ \___ / __ \_\___ \| <\ ___/| | | | \____ |\____/__/\_ \\___ >____ | |___ / ____| \___ >____ /____ >__|_ \\___ >__| |__| \/ \/ \/ \/ \/\/ \/ \/ \/ \/ \/ >< quick and small intro: On breached.to a user by the name of "AgainstTheWest" was created March 18, 2022 The User claimed to have databreaches that actually werent real such as TikTok and WeChat Shortly after that he got banned. Archive: https://web.archive.org/web/20220905055353/https://breached.to/user-AgainstTheWest Apart from him having a very similiar writing style like IntelBroker and humour and tendency to put random profile pictures. In the description of AgainstTheWest's profile you can see a XMR Address If you go to a certain snapshot of IntelBrokers profile you can see the same XMR address put up for donations on his profile... Coincidence I think not Archive: https://web.archive.org/web/20230104201005/https://breached.vc/User-Intelbroker He removed that XMR Address shortly after This confirms that the old alias of Intelbroker is AgainstTheWest -= AgainstTheWest =- Twitter: https://twitter.com/AggressiveCurl [ SUSPENDED ] XMR: 48ij9MUxTKjW1xx2kGopvqAzbAWd9pxWQFsVW6C3KRmACzLYSnD9f6iAQx2LHPFv5FJYRv9H5k8BH9P3RPViA3EU9GzB1pU Email: rigo@mortis.com From a snapshot of his twitter we can see that he is located in Europe We can also tell by IntelBrokers accent in a video from "DuperTrooper" that his accent is Macedonian or Russian ***( ATTENTION )*** this is simply a starter-dox I have nothing against intelbroker intelbroker for contact text me on signal user: hidden ________________________________________________ / \ | _________________________________________ | | | | | | | C:\> u got doxed by caskett | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |_________________________________________| | | | \_________________________________________________/ \___________________________________/ ___________________________________________ _-' .-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-. --- `-_ _-'.-.-. .---.-.-.-.-.-.-.-.-.-.-.-.-.-.-.--. .-.-.`-_ _-'.-.-.-. .---.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-`__`. .-.-.-.`-_ _-'.-.-.-.-. .-----.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-----. .-.-.-.-.`-_ _-'.-.-.-.-.-. .---.-. .-------------------------. .-.---. .---.-.-.-.`-_ :-------------------------------------------------------------------------: `---._.-------------------------------------------------------------._.---' dads info allegedly: Address: 725 diandrea dr FullName: adam phlee DOB: 9/29/1965 Phone: 330-712-5011 possible intels personal data: addy: Raleigh NC27607 aliases of target: IntelbrokerBF intelbroker AgainstThewest letsend —- Social Media ———————————————- Github: https://github.com/IntelBroker Keybase: https://keybase.io/intelbroker Breachforums: https://breachforums.st/User-IntelBroker PGP: https://pastebin.com/7KMtLZu5 [ miggerkiller44@cock.li ] -= Crypto =- ETH: 0x0cD1FD1191aeC66F555C0893D29E7c36AeEeb6ab Bitcoin: bc1q6uzzurelqx348t6cr775yv9v4x43m88x7djqkf bc1qj52d3d4p6d9d72jls6w0zyqrrt0gye69jrctvq --- old emails --- cvn68@riseup.net User: letsend ---- f17@riseup.net User: againstthewest ---- --- current emails --- User: IntelBroker email: 17intelbroker@proton.me lastip: 89.36.78.126 regip: 45.134.140.181 ---- dollaria@proton.me User: IntelBroker ---- intelbroker@national.shitposting.agency ---- intelbroker@cock.li ---- 19intelbroker@proton.me [ MAYBE ] intelbroker@national.shitposting.agency - https:/cock.li Twitter Keybase Skype Microsoft - Sweden [ VPN ] following breaches per email: 1. rigo@mortis.com: https://files.catbox.moe/dwv1ri.json 2. cvn68@riseup.net: https://files.catbox.moe/ep01mj.json [ledsend] 'lastip': '89.38.224.102 'regip': '89.38.224.102' 3. f17@riseup.net: {NO DATA FOUND} [User: againstthewest] 4. 17intelbroker@proton.me: https://files.catbox.moe/wl53p0.json lastip: 89.36.78.126 regip: 45.134.140.181 'NickName': 'IntelBroker' 'Points': '764', 'PostsCount': '276 5. dollaria@proton.me: Leak from breached.vc username: intelbroker regip: 185.238.231.32 lastip: 185.192.69.235 6. intelbroker@national.shitposting.agency: {NO RESULTS FOUND} 7. intelbroker@cock.li: {NO RESULTS FOUND} 8. 19intelbroker@proton.me [ NON-CONFIRMED ]: 'NickName': 'intelbroker2' LastIP': '212.83.144.108 9. asleep@gmxx.dee: https://files.catbox.moe/qf8grg.json Leak from 1671_FLIPD_GG_529K_HACKING_072022 10. nclsduigdbdkudekxj@twzhhq.com: https://files.catbox.moe/j89ygx.json 11. Mr_croissant0x@protonmail.com: https://files.catbox.moe/h7j14k.json 12. zaxscd@er83.hui: https://files.catbox.moe/c1opgd.json 13. aphlee@yahoo.com: https://files.catbox.moe/5zd3jq.json 14. xfghjkdgbnjmklfsjklmh@gmail.com: https://files.catbox.moe/6xt6c0.json (NON CONFIRMED YET) 15. fsdgsdgs@gmail.com: https://files.catbox.moe/jopec4.json (NON CONFIRMED YET) long story short I was doing my research and found an ip that wasn't a vpn it was being used by intelbroker. found it in a breach i confirmed its his ip but I then went and looked up the ip and I found a yahoo mail and 2 gmails… I searched the yahoo mail and struck gold: this might be his dad info tho with info like phone number,addy,full name and way more ============================================================================================ [list of ips] 89.38.224.102 - vpn 137.119.17.17 - no vpn/clean info on clean ip: ISP: The Hancock Telephone Company country: US city: Hancock Region: NY 89.36.78.126 - mullvad vpn 45.134.140.181 - ProtonVPN 185.192.69.235 - ExpressVPN 185.238.231.32 - ExpressVPN 212.83.144.108 - TunnelBear VPN 89.38.224.103 - VPN IP Address VPN Detected 89.46.62.77 - Mullvad VPN ============================================================================================ [BREACHES FROM THE IP'S IN ORDER (from top to bottom)] 1. https://files.catbox.moe/0kro95.json 2. https://files.catbox.moe/0uzy9c.json *(FOUND EMAIL/YAHOO MAIL WITH IP ATTACHED)* also this ip was used by intelbroker without being an vpn 3. https://files.catbox.moe/c0qr3s.json number 3 also has an og users leak an the acc used a google mail to sign up with. Leak from: "0945_OGUSERS_COM_331K_HACKING_042021" the ip at number 3 is an ip intel used alot 4. https://files.catbox.moe/vjt5sr.json 5. https://files.catbox.moe/739zc2.json 6. https://files.catbox.moe/yzved0.json 7. https://files.catbox.moe/um7ib2.json 8. https://files.catbox.moe/690a72.json 9. https://files.catbox.moe/uvposi.json ============================================================================================ so while looking through the data that I got from searching the emails I found 2 more mails and some ips starting with this one: 89.38.224.102 however this is sadly a vpn: IP Address 89.38.224.102 VPN Detection VPN IP Address VPN Detected This IP address is a VPN Connection. Risk Status 65% - Suspicious IP ISP M247 Europe Country RS RS City Belgrade CIDR IP Address Subnet 89.38.224.0/24 while I looked up that ip I found the 3 emails and 1 more ip: asleep@gmxx.dee nclsduigdbdkudekxj@twzhhq.com Mr_croissant0x@protonmail.com this 1 had the vpn as last ip but a diff ip address as its regip the ip was as followed: IP Address 137.119.17.17 VPN Detection Clean IP - Not A Proxy/VPN Clean IP - Not A VPN Connection ISP The Hancock Telephone Company Country US US City Hancock ============================================================================================