Jackie Singh (Active) Profile picture
Jul 10, 2024 18 tweets 6 min read Read on X
I am reviewing this alleged hack of The Heritage Foundation.

I have identified very embarrassing data within this dataset. Why so many Chinese IP addresses? 🤔
The zipped file contains one single file:

"daily-signal_dev_database_new.sql"

This appears to be a combined set of exports from a SQL database. Here are the first lines Image
Because this is a combined export (likely from the command line) of various tables, the file is not readable by a typical SQL editor, and needs to be split into pieces to make it so.

I'd rather just turn it into CSV chunks to start cleaning up the dataset for further analysis
There are 215,000 lines or so in the WordPress Comments table. As you can see, comment_author_IP is available, which is broadly useful to get a sense of where people posting replies to the Heritage blog are coming from in the world.

Earliest date: 2008-01-04. Newest: 2022-11-09 Image
After creating a CSV chunk with only the WP comments table, now I can view columns and extract their content as needed. After extracting IP addresses from the author column, I can eliminate duplicates and work on analyzing their presumed geo origin, which is of interest to me Image
Dataset was a little dirty and a hassle to clean up.

Here are the 60K extracted IPs from the WP Comments table:

#HeritageFoundation defuse.ca/b/PTrmvlbs
Image
Sample geolocations from the first 100 IPs (these are sorted 'low to high', and many Asia-based netblocks start with the number 1) Image
Here are the 69.5K email addresses present within the complete dataset:



🤔 235 .mil and .gov email addresses
🤔 95 .ru and .cn email addresses

#HeritageFoundationdefuse.ca/b/mLXCi0iXsGFj…
Linked below is a statistical breakdown of the domain names associated with all email addresses in the dataset.

Stacking and counting are basic analytical tools which can help analysts identify outliers.

defuse.ca/b/GMCj2uAfvELn…
Image
I have a script running to grab geolocation information and will tweet when it finishes.

Those working at big companies with access to certain commercial tools can do this more quickly than I can.
Because the original host took the file down, you can now find it here:

This is a 368 MB .zip file which uncompresses to a single 1.94 GB flat file.

SHA256: 3dcc258331d9139a654402d20b756b57ca17228aa9e2f80a4b6451b96c8eac70tan-medieval-hornet-252.mypinata.cloud/ipfs/QmVwiYsr4…
The hacker group claiming responsibility for this action has released new information on their Telegram channel. Image
Here is the list of Administrators.

defuse.ca/b/ely6s7iwqpLF…
BREAKING: SiegedSec claims to have officially disbanded.

#HeritageFoundation
Image
Image
@CloudsEdgeArt1 I am the first person covering this.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Jackie Singh (Active)

Jackie Singh (Active) Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @HackingButLegal

Feb 5
THREAD 🧵

1/ This breaking exclusive story from Reuters (sourced from her office) looks like an effort to retroactively justify and normalize Tulsi Gabbard's presence at the recent Georgia raid by framing it as part of a broader ODNI election security mission. I can explain:
2/ Between Feb 1–4, Gabbard told Congress her Georgia role falls under ODNI's election security authority and is tied to a long running assessment of electronic voting systems.
3/ At the same time, this newly-public Puerto Rico operation is now being highlighted as proof of that "long running" work, with ODNI emphasizing vulnerabilities and alleged foreign‑interference risks to make Georgia look like one more node in an existing program.
Read 10 tweets
Jan 31
"Most of them"? Technically true—I suppose @EoinHiggins_ must missed this email from Soon Yi

#EpsteinFiles #WoodyAllen Image
Image
Image
*must have missed this email 😉
Here is Soon Yi forwarding content to Epstein which reads, "Just as the MeToo movement has gone too far so has Botox" Image
Read 4 tweets
Jan 31
Tyler Shears is in the #EpsteinFiles because he directly worked PR for Epstein. He was also the CTO (and responsible for "deep dive due diligence on all new investments and company projects") at The Ingersoll Group during the time when Keith Ingersoll was committing crimes there. Image
Keith Ingersoll is an associate of Matt Gaetz.

justice.gov/usao-mdfl/pr/o…
Ingersoll wound up in prison for fraud because it was probably easier to prove than other crimes.

abcnews.go.com/Politics/gaetz…
Read 4 tweets
Jan 26
Me in 2023: "If Millennials think we're having a hard time now, the madness & the chaos that would be unleashed in a 2nd Trump presidency would be unmatched by any other point in American history, & I think that none of us want to live through that"

You can see my eye twitching.
Anthony Davis: He knows he's 'Above the Law' and he kind of is.

Me: He kind of is. He kind of is. I mean, when you think about an equivalent, you could think about someone like Elon Musk.
Read 13 tweets
Jan 22
Some stories wound me in the writing. The toll is a stress that burrows deep during research. When the weight grows unbearable, when it overwhelms, I step back, breathe, think. But I will not be ruled by fear. My allegiance is to democracy, and the stakes could not be higher.
The cunning of fear is that it needs no chains. It merely suggests that tomorrow is soon enough, that someone else will speak, and that the risk outweighs the duty. Fear stops the hand before it writes, and closes the throat before it speaks.
Fear is a thief of motion. It wins not by persuasion, but by paralysis. It whispers in our ear that stillness is safety, that silence protects. It makes cowards feel wise, inaction feel reasonable, retreat feel like strategy. So nothing moves. The moment passes, and passes again.
Read 8 tweets
Jan 20
For Your Consideration. Image
Image
Note the date and time. lavanguardia.com/politica/20260…
The recent train derailment occurred in Spain's Córdoba province on January 18, 2026 at around 7:45 p.m. local time (6:45 p.m. GMT).

Do your own math. I've ridden on high speed Spanish trains. They are incredibly efficient and well run systems.

A pride of their nation.
Read 10 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(