This study introduces a supervised machine learning method for predicting private messages in underground forums, a key to understanding the cybercriminal ecosystem. Since private messages are rarely available to analysts, the method leverages partial leaks to predict which public threads will generate private interactions. The approach includes an automated post-labeling method to reduce costs and can be tuned to focus on either users likely to receive private messages or threads likely to trigger them. Evaluations using data from three real forum leaks demonstrate that public information can predict private activity, though models are not universally applicable across forums, and NLP features are crucial for prediction accuracy.