Jimbzo
Record ID: ACT-0001
Handle(s): Jimbzo; @Jimbzo_2; pw2h
Status: Active
First Observed: 2023-06-23
Summary
Jimbzo is an online cyber-community actor documented across Telegram spaces focused on breach forums, OSINT, leaked databases, stealer-log ecosystems, and breach-lookup services. The earliest preserved activity shows interest in stealer logs and log-parsing tooling, while later logs show him discussing database cleaning, indexing, search services, forum history, and moderation activity. He explicitly identifies as Jimbzo in multiple 2025 and 2026 entries, including cases where he corrects others who appear to confuse him with another actor.
The available evidence supports a profile closer to data collector, indexer, breach-community moderator, and loud technical commentator than confirmed elite intrusion operator. He presents himself as building or operating breach-lookup infrastructure, speaks repeatedly about parsing and indexing large datasets, compares competing OSINT and breach-lookup providers, and discusses his own service plans, pricing, API access, and search speed. These claims are self-reported and should not be treated as independently verified.
His strongest documented qualities are persistence, practical knowledge of leaked-data ecosystems, skepticism toward fake breach claims, attention to data quality, and awareness of infrastructure constraints such as storage, indexing, search speed, and bandwidth. He is often direct to the point of being useful: he challenges inflated record counts, questions whether samples exist, distinguishes public scraping from real access, and asks others to test his own site for vulnerabilities.
Aliases
Jimbzo— primary handle; self-identified in multiple logs.@Jimbzo_2— Telegram-style handle referenced in NoSINT-related activity.pw2h— described by Jimbzo as a BreachForums alias; later appears in the phrase “pw2h aka Jimbzo mc leak.” Context is incomplete, but the association is directly present in the logs.
Affiliations
- BreachForums — frequent activity, including apparent moderation commands and breach-community discussion.
- Database World ROC — repeated database, breach-lookup, and OSINT discussion.
- BF Repo V3 Chat — breach-repository and leaked-data discussion.
- ANTILARP CHAT FFS — observed discussion, site testing, and API/custom-request context.
- idleakcheck — breach / people-search project that Jimbzo presents as his own or under his control.
Timeline
2023-06-23— First preserved activity: requests stealer logs in a Telegram chat. [1]2023-06-29— Asks for a log parser without a RAT or backdoor, showing early concern with processing stealer-log material while avoiding obviously malicious tooling. [1]2024-05-02— Offers Minecraft player lookup by UUID, username, or IP, and disputes claims that certain Minecraft server databases were leaked. [2]2024-05-23— Discusses cookie/session replication in the context of stealer-log style access, indicating familiarity with account-session abuse concepts. [3]2025-04-18— States that he does not use the same alias everywhere and identifies his BF alias aspw2h. [4]2025-04-25— Claims to have private email-password data, describes plans for a breach-lookup service, and outlines pricing and lookup-speed goals. These are self-reported claims, not independent measurements. [5]2025-04-28— Posts a comparison list of breach-lookup services and states that his own service is not listed, showing active tracking of the OSINT / breach-lookup market. [6]2025-05-06— Says he is indexing his own data rather than relying on other services or APIs, and discusses cleaning, merging, indexing, and selling API access. [7]2025-05-22— Discusses Minecraft database work, including “800 mc databases,” a BF-posted collection, months of parsing and cleaning, and the phrase “pw2h aka Jimbzo mc leak.” [8]2025-08-23— Shares a search endpoint foridleakcheck, claims fast search responses, and says he has a full dataset plus free search for it. [10]2025-08-25— Requests pentesting ofidleakcheck, enables free searches for new accounts, and offers search access in return for vulnerability notes. [11]2025-09-05— Claims to be at “4 billion unique rows” and discusses custom API requests. Again, this is self-reported. [12]2026-02-04— Critiques an OSINT article at length, pushing back on weak claims about VPN detection, DNS logs, fingerprints, and browser hygiene. [13]2026-03-09— Self-identifies as Jimbzo in BreachForums chat and discusses storage needs for long-term data handling. [15]2026-04-12— Denies being “Trapalot” and states “i am JIMBZO,” reinforcing the handle association. [16]2026-04-14— Says he found USA data and is indexing it intoidleakcheck.2026-05-06— Issues a ban for targeting medical institutions and states opposition to hospital targeting, one of the clearer ethical boundaries in the logs. [17]2026-05-11— Discusses a ComWiki profile, AI-written profile concerns, and loss of an account that had access to many stealer-log and database-related channels. [19]2026-05-14— Last documented activity in the provided logs: issues “/dban no selling” and participates in discussion about ComWiki, Doxbin history, court documents, and breach-community documentation. [20]
Related Incidents
Evidence
| Ref | Source | Date | Notes |
|---|---|---|---|
| [0] | Template / tasking file | 2026-05-14 | Establishes the requested ComWiki structure, evidence standard, and balancing requirements for this record. |
| [1] | Uploaded Telegram log: user-1219191310 | 2023-06-23 to 2024-03-15 | Earliest preserved activity, including requests for stealer logs and a log parser. |
| [2] | Uploaded Telegram log: user-1219191310 | 2024-05-02 to 2024-05-16 | Minecraft database / player lookup discussion and denial of certain server-database leak claims. |
| [3] | Uploaded Telegram log: user-1219191310 | 2024-05-21 to 2024-06-17 | Discussion of stealer-log material, cookie/session replication, and Minecraft database access. |
| [4] | Uploaded Telegram log: user-1219191310 | 2025-04-18 | Jimbzo says he does not use the same alias and identifies his BF alias as pw2h. |
| [5] | Uploaded Telegram log: user-1219191310 | 2025-04-25 | Self-reported breach-lookup plans, private email-password dataset claims, pricing, and lookup-speed goals. |
| [6] | Uploaded Telegram log: user-1219191310 | 2025-04-28 | Comparison list of breach-lookup services; shows market awareness and record-count tracking. |
| [7] | Uploaded Telegram log: user-1219191310 | 2025-05-06 | States that he is indexing his own data and discusses cleaning, merging, indexing, and API resale. |
| [8] | Uploaded Telegram log: user-1219191310 | 2025-05-22 | Minecraft database history, manual cleaning/parsing claims, lost datasets, and “pw2h aka Jimbzo mc leak.” |
| [9] | Uploaded Telegram log: user-1219191310 | 2025-08-04 | Self-identification as Jimbzo after apparent confusion with another person. |
| [10] | Uploaded Telegram log: user-1219191310 | 2025-08-23 | Shares and discusses idleakcheck, including search response claims and dataset indexing. |
| [11] | Uploaded Telegram log: user-1219191310 | 2025-08-25 | Requests pentesting of idleakcheck and offers search access in return for vulnerability notes. |
| [12] | Uploaded Telegram log: user-1219191310 | 2025-09-05 to 2025-09-07 | Claims multi-billion-row scale and discusses API/custom-request work. |
| [13] | Uploaded Telegram log: user-8568177442 | 2026-02-04 | Detailed critique of an OSINT article, showing technical skepticism and attention to weak inference. |
| [14] | Uploaded Telegram log: user-8568177442 | 2026-03-24 | Critiques an alleged large breach claim using storage, bandwidth, file-tree, and infrastructure reasoning. |
| [15] | Uploaded Telegram log: user-8568177442 | 2026-03-09 | Self-identification as Jimbzo and discussion of storage needs for long-term data. |
| [16] | Uploaded Telegram log: user-8568177442 | 2026-04-12 | Denies being Trapalot and reasserts Jimbzo identity. |
| [17] | Uploaded Telegram log: user-8568177442 | 2026-05-06 to 2026-05-07 | Moderation against targeting medical institutions; also shows blunt opposition to hospital attacks. |
| [18] | Uploaded Telegram log: user-8568177442 | 2026-05-08 to 2026-05-10 | Moderation commands, “no selling” enforcement, abrasive ban language, and routine chat behavior. |
| [19] | Uploaded Telegram log: user-8568177442 | 2026-05-11 | ComWiki profile discussion, AI-writing concern, and mention of an account with many stealer-log/database channels. |
| [20] | Uploaded Telegram log: user-8568177442 | 2026-05-14 | Latest preserved activity; includes “/dban no selling” and discussion of Doxbin/court-document research. |
Notes
The strongest supported description is not “elite hacker” but “breach-data ecosystem operator/commentator.” He shows recurring interest in collection, parsing, cleaning, indexing, lookup tooling, service comparison, and API access. He also presents himself as building or operating idleakcheck, but the logs alone do not independently verify the scale, quality, legality, or business status of that service.
The record shows technical competence in practical data-community terms: he understands duplicates, search performance, dataset sourcing, public-vs-private claims, infrastructure costs, and why large breach claims can collapse under bandwidth or storage math. He is also capable of useful skepticism, especially when confronting exaggerated breach claims or weak OSINT methodology.
Jimbzo’s reputation, based on these logs, should be understood as a mix of capability and mess: technically alert, persistent, often funny in the bleak house style of breach chats, but also reckless, abrasive, and comfortable operating around material that creates real harm when misused. Critics and supporters would probably both recognize him here, which is usually a sign the file has not been sanded into nonsense.
Record created: 2026-05-14.
