Researcher Linked Early Cybercrime Forum to Modern Actors

A new analysis tracked 205 handles from the Exploit.in database that remain active in today's cybercrime ecosystem.

Updated on Sept. 26, 2026 in Cybersecurity

Isometric editorial illustration of an abandoned server rack with tangled fiber-optic cables, representing historical persistence in cybercrime.
Researcher Dancho Danchev identified 205 user handles that transitioned from the early-2000s Exploit.in forum to current cybercrime ecosystems, revealing a nearly two-decade persistence. AI Illustration. Upload story photo >

Live Poll

Do you trust that current cybersecurity measures are effective against long-term criminal networks?

Researcher Dancho Danchev released a study analyzing the Exploit.in forum, which operated from 2005 to 2008. The investigation identified 205 user handles that were active on the site and remain present in modern cybercrime forums.

Why it matters

The findings demonstrate the long-term persistence of certain actors within the cybercrime landscape, highlighting a continuous presence that spans nearly two decades. This persistence offers insight into how early forum trust models have evolved into the complex structures seen today.

The Exploit.in database featured 80,891 posts across 13,925 threads, with the top 1% of members authoring 52.6% of all content. Data also shows that 60.6% of registered members never contributed a post, while only 82 accounts exceeded 200 posts.

The players

Dancho Danchev

He is a security researcher who conducted the analysis of historical cybercrime forum data.

The details

The analysis cross-referenced member lists from the 2005 to 2008 period with private message archives from five contemporary cybercrime forums. Activity on the original platform typically peaked at 10 at night Moscow time, with a notable decline in participation during weekends.

Timeline

  1. February 2005: Recording of the Exploit.in forum database began.

  2. May 2008: Recording of the Exploit.in forum database concluded.

  3. September 26, 2026: Research findings regarding the database were published.

The Tech Race

This study maps the evolution of the historical reputation-based trust model used by early cybercrime forums into today's sophisticated criminal networks. It tracks how early organizational structures have matured and persists alongside modern advancements in secure trade.

The findings underscore that digital security threats often involve long-standing entities that adapt their tactics over decades rather than disappearing. Understanding these persistent patterns helps security professionals better identify and anticipate long-term risks in the digital landscape.

The takeaway

Cybercrime forums rely on a small core of highly active contributors, as evidenced by the 52.6% post volume from only 1% of the membership. Users should note that these platforms utilize tiered access and escrow services, such as those found on RAMP and XSS, to facilitate illicit operations.

Further reading

For more on evolving digital threats, visit the Cybersecurity section.

Source note: This article includes information reported by Security Affairs.

Live Poll

Do you trust that current cybersecurity measures are effective against long-term criminal networks?