Jackie Singh (Inactive) Profile picture
Jul 10, 2024 18 tweets 6 min read Read on X
I am reviewing this alleged hack of The Heritage Foundation.

I have identified very embarrassing data within this dataset. Why so many Chinese IP addresses? 🤔
The zipped file contains one single file:

"daily-signal_dev_database_new.sql"

This appears to be a combined set of exports from a SQL database. Here are the first lines Image
Because this is a combined export (likely from the command line) of various tables, the file is not readable by a typical SQL editor, and needs to be split into pieces to make it so.

I'd rather just turn it into CSV chunks to start cleaning up the dataset for further analysis
There are 215,000 lines or so in the WordPress Comments table. As you can see, comment_author_IP is available, which is broadly useful to get a sense of where people posting replies to the Heritage blog are coming from in the world.

Earliest date: 2008-01-04. Newest: 2022-11-09 Image
After creating a CSV chunk with only the WP comments table, now I can view columns and extract their content as needed. After extracting IP addresses from the author column, I can eliminate duplicates and work on analyzing their presumed geo origin, which is of interest to me Image
Dataset was a little dirty and a hassle to clean up.

Here are the 60K extracted IPs from the WP Comments table:

#HeritageFoundation defuse.ca/b/PTrmvlbs
Image
Sample geolocations from the first 100 IPs (these are sorted 'low to high', and many Asia-based netblocks start with the number 1) Image
Here are the 69.5K email addresses present within the complete dataset:



🤔 235 .mil and .gov email addresses
🤔 95 .ru and .cn email addresses

#HeritageFoundationdefuse.ca/b/mLXCi0iXsGFj…
Linked below is a statistical breakdown of the domain names associated with all email addresses in the dataset.

Stacking and counting are basic analytical tools which can help analysts identify outliers.

defuse.ca/b/GMCj2uAfvELn…
Image
I have a script running to grab geolocation information and will tweet when it finishes.

Those working at big companies with access to certain commercial tools can do this more quickly than I can.
Because the original host took the file down, you can now find it here:

This is a 368 MB .zip file which uncompresses to a single 1.94 GB flat file.

SHA256: 3dcc258331d9139a654402d20b756b57ca17228aa9e2f80a4b6451b96c8eac70tan-medieval-hornet-252.mypinata.cloud/ipfs/QmVwiYsr4…
The hacker group claiming responsibility for this action has released new information on their Telegram channel. Image
Here is the list of Administrators.

defuse.ca/b/ely6s7iwqpLF…
BREAKING: SiegedSec claims to have officially disbanded.

#HeritageFoundation
Image
Image
@CloudsEdgeArt1 I am the first person covering this.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Jackie Singh (Inactive)

Jackie Singh (Inactive) Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @HackingButLegal

Dec 24
FACT: Sanctions are the most important method of global financial moderation to help keep us safe from the world's worst terrorists.

This key defensive tool is now converted to a weapon of state repression and censorship by Trump admin under false guise of defending free speech.
We're not just talking the regular ol' domestic state repression, either.

The sanctions list has just become a global cleaver to financially terminate Trump's political enemies who are not U.S. citizens nor residents. He seeks to antagonize his targets and send a public message.
The clear message being broadcasted is that opposing Trump or engaging in advocacy which runs counter to the ideology this administration is installing in the U.S. is likely to result in significant consequences.

The admin repeats this message of fear via every channel, daily.
Read 8 tweets
Dec 15
🧵 Authoritarians follow a predictable playbook, and you can often spot it before it is too late. THREAD of core behaviors of dictators who want to hold power at any cost
1. Aggressively centralize power.

They weaken parliaments, courts, and watchdogs, often by using "emergencies" or legal tweaks to concentrate authority in the executive while claiming to respect the rule of law.

nytimes.com/2025/03/20/us/…
2. Rig the game instead of canceling it.

Elections keep their veneer of legitimacy, but rules, districts, oversight bodies, and term limits are quietly manipulated to make losing nearly impossible.

aclu.org/news/voting-ri…
Read 19 tweets
Dec 4
1/ Stockton’s mayor called this a gang-related incident.

WRONG! A lone gunman, not multiple as initially reported. Sheriff bungled initial response by wrongly assuming contours of the crime before arrival on scene, then failed to enter. Chased down victims while others bled out.
2/ Bc they’re habituated to community violence, not lone gunmen in mass shooter scenarios, they arrived fast yet unequipped, then failed to properly assess/secure the scene and find the gunman. The key witness who saw the shooter exited to seek a paramedic to help his dying son.
3/ Amari Peterson, 14, may have coded before he was loaded into the ambulance. The paramedics forced Dad to ride upfront, then drove slowly, and never told him his son had died. At the hospital, he was stonewalled by hospital staff as to status at the Sheriff’s behest for 7 hours
Read 4 tweets
Nov 26
1/ Yesterday, Press Sec Karoline Leavitt appeared at the 78th annual National Thanksgiving Turkey Pardon wearing what can only be described as pilgrim cosplay 💀🦃

This wasn't an accident. A thread on political fashion as ideological theater. 🧵
2/ The outfit immediately drew comparisons to 17th-century Puritan dress, specifically the clothing women may have worn at the mythologized "First Thanksgiving" in 1621. Media called it "full cosplay" and "pilgrim-core." But dismissing it as a fashion miss understates the matter
3/ The "First Thanksgiving" narrative is one of America's most contested origin myths. Historians have spent decades unpacking how this story sanitizes colonization, erases Indigenous perspectives, & constructs European Christian settlers as top protagonists of American identity.
Read 11 tweets
Nov 21
I can tell you how they did it, because they tried to do it to me—

Be very careful with anyone new being joined to your Signal chats; be cautious with what you say in group chats where you don't explicitly know (IRL) and trust every member.

Most of all, beware group invites. 1/ Image
2/ They may try to use people of color to lure you in, or use some other commonality between you and their surveillance persona. They may appear on the surface to be genuine activists. Ask a lot of questions, act legally in your dealings, and follow your gut.
3/ I am not a lawyer. I suggest folks seek legal advice from a competent professional. But it stands to reason that if you follow the law, and distance yourself from those who don't intend to, you can keep your nose clean enough to avoid this type of risk

Read 4 tweets
Nov 20
🚨 THREAD: NEW preprint paper by Cornell University researchers found that @elonmusk's @Grokipedia cited the white nationalist site VDare 107 times, the neo-Nazi site Stormfront 42 times, and the conspiracy site Infowars 34 times. 👀👇 1/🧵

#AdversarialML #AIethics Image
2/ Their analysis of over 880K articles revealed 12,522 citations to sources deemed low-credibility by academic research (3x higher than Wikipedia). They found ~5.5% of Grokipedia articles have citations to sources strictly blacklisted by the Wiki community for unreliability. Image
3/ Unlike Wikipedia's volunteer-based system, Grokipedia centralizes control through Elon Musk’s xAI.

Researchers identified 1,050 instances where Grokipedia cited AI conversations with the Grok chatbot as authoritative sources. Image
Read 7 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(