NEW: The hack of web hosting company Epik has revealed the names behind some of the most notorious far-right sites.

A cybersecurity expert I analyzed the data with said Epik was “fully compromised.”

“Maybe the worst I’ve ever seen in my 20-year career.” dailydot.com/debug/epik-hac…
As first revealed on Monday by @stevanzetti, the hacking collective Anonymous announced that it had hacked Epik, whose customers have included Parler, Gab, and forums such as TheDonald. dailydot.com/debug/epik-hac…
As I noted yesterday, the breach includes the email inbox of an Epik employee that regularly spoke with CEO Robert Monster.

I attempted to speak over the phone with Monster by calling him on the personal cell number listed in his email signature but did not receive a reply.
The massive data trove includes, among other things, the names, addresses, phone numbers, and email addresses of those who registered web domains with Epik.

dailydot.com/debug/epik-hac…
I was able to verify the data by calling numerous people, including the individual who registered the domain patriots.win–home to the massive pro-Trump forum known as TheDonald.

dailydot.com/debug/epik-hac…
A database titled “intrust.sql”–which appears related to Epik’s 2011 purchase of domain name registrar IntrustDomains–even included credit card numbers stored in plaintext (although the cards appear expired).

Even some passwords were stored in plaintext.dailydot.com/debug/epik-hac…
Update: There are also *current* credit card numbers stored in plain text in the data breach.

dailydot.com/debug/epik-hac…
Although the press release from Anonymous claimed no credit card data was present, I can confirm that there are credit card numbers stored in plaintext.

The cybersecurity expert who analyzed the data with me summed up the breach as so: dailydot.com/debug/epik-hac…
Just to point out, even though Epik has a service to anonymize registrar information (so that people can't see who registered a certain domain), there is an entire database that lists the personal information of all the 'anonymized' users. dailydot.com/debug/epik-hac…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mikael Thalen

Mikael Thalen Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @MikaelThalen

30 Jul
Exclusive: Leaked chats reveal how the former lead psychologist for Cambridge Analytica is secretly working behind the scenes to influence anti-vaccine efforts.

dailydot.com/debug/leaked-c…
Patrick Fagan, who has worked for Cambridge Analytica, the tobacco and gambling industries, as well as on voter deterrence campaigns, is secretly aiding the UK-based organization known as HART.

dailydot.com/debug/leaked-c…
HART is a self-described group of 'highly qualified UK doctors, scientists, economists, psychologists and other academic experts.'

But their private chats reveal a group inundated with QAnon-type conspiracy theories.

dailydot.com/debug/leaked-c…
Read 7 tweets
8 Jul
New: Twitter was flooded with identical pro-lockdown tweets this week, leading many to blame a 'bot campaign' on behalf of a foreign government.

But it looks like the tweets were just part of a 'copypasta' effort from internet trolls.

dailydot.com/debug/twitter-…
Several high-profile accounts alleged that a 'bot army' had been deployed after dozens of tweets shared identical criticisms of the UK government's plan to ease lockdown restrictions.

dailydot.com/debug/twitter-…
I was able to track down the original tweet to a woman in the UK who was confused at why so many people were copying her tweet.

"I think the accounts were doing it to make the story of my brother look false," she said.

dailydot.com/debug/twitter-…
Read 6 tweets
4 Jun
Microsoft's Bing search engine appears to be censoring image results for "tank man"—a reference to the lone protester who stood in front of Chinese tanks—on the 32nd anniversary of the Tiananmen Square Massacre vice.com/en/article/qj8…
Meanwhile, a search for "tank man" on Google images displays what you would expect. Both the search on Google and Bing were made from the US, not China.
To be clear, searching "tank man" on either Google or Bing does return the relevant web results.

It's the image results on Bing that don't return any results. This could be a simple glitch at the end of the day. I reached out to Microsoft to ask.
Read 8 tweets
14 May
The preliminary hearing for this case was today and police never presented the so-called deepfake to the court.

Because, as I exclusively revealed in April, the cops never even had the video. The lawyer for the alleged deepfake mom has told me that the vaping video was real.
The district attorney in the case against the Pennsylvania mom accused of making deepfakes has now said that the videos in the case many not be deepfakes at all.

buckscountycouriertimes.com/story/news/202…
Prosecutors, who backtracked on their claims Friday that a Pennsylvania mom created deepfakes to harass her daughter's cheerleading rivals, are still taking the case to trial.

inquirer.com/news/rafaella-…
Read 5 tweets
14 May
Scoop: Document reveals Trump's D.C. hotel purposely spiked prices to keep out QAnon supporters. dailydot.com/debug/trump-ho…
In February, Forbes reported that the price of hotel rooms had increased from around $476 to $1,331 per night for March 3 & 4.

The hotel wouldn't confirm whether the price surge was related to the belief among QAnon supporters that Trump would be inaugurated on March 4.
An intelligence briefing leaked onto the dark web by a ransomware gang this week shows that D.C. police contacted Trump Hotel.

The hotel said it spiked prices as a "security tactic" in order to keep potential protesters from booking rooms.
Read 4 tweets
24 Nov 20
While there is an unconfirmed report of Parler being hacked, the screenshot circulating of a Parler database password is old.

I looked into the database leak in July and confirmed thanks to @WhiskeyNeon that it was for a site not held on the same infrastructure as the main site.
As you can see in an archived version of the configuration file, the page was discovered as early as July of this year.

This isn't to deny that a hack may have taken place, but that this screenshot is almost certainly unrelated. archive.ph/Mll5H
The leaked database was linked to a WordPress page that Parler seemingly used for blog posts and announcements. It would not have hosted user data.

The main Parler site is not based on WordPress.
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(