Technical Issues

BeautifulPeople.com Hacked & Personal Data Sold

Technical Issues
  • Friday, May 27 2016 @ 09:38 am
  • Contributed by:
  • Views: 1,404
BeautifulPeople.com was Hacked

BeautifulPeople.com boasts that it offers “online dating for beautiful people only,” but it’s currently making headlines for something far from pretty. The site was recently attacked by hackers who put the personal info of 1.1 million members for sale on the black market.

According to security expert Troy Hunt, the data belonged to members who joined before July 2015. Information like weight, height, job, and phone number was reportedly compromised, though no passwords or financial details were included.

"The breach involves data that was provided by members prior to mid-July 2015. No more recent user data or any data relating to users who joined from mid-July 2015 onward is affected," Beautiful People said in a statement. "As far as we were aware, at that time [in December 2015], only the two security researchers who informed us of the breach had access to this data."

Chris Vickery, who originally discovered breach, told the BBC the firm acted quickly after he notified them - but it was already too late. "They published it openly to the world with no protection whatsoever," he said.

Like the Ashley Madison hack – which exposed 39 million people hoping to cheat on their partners – there’s a sense of schadenfreude to the news. A part of us enjoys seeing “bad” people (or in this case, people who have an inflated sense of their own goodness) get knocked down a peg. We call it karma, but what it really is, is a warning.

Hacking is a scary phenomenon no matter what, and doubly so when it’s done with the intention to shame. Online dating is now so commonplace that many users have grown lax about how they do it. Theoretically we know we need to protect our personal information, but how much effort do we really put into it? Our data is bought and sold constantly, whether we know it or not, both legally and illegally. Let the Beautiful People hack be a reminder to prioritize your privacy.

The good news is, the company says the leak has since been patched. But there’s no way to reclaim the data that’s now circulating. Victims of the hack must now take precautions like changing passwords and monitoring for identity theft.

Beautiful People said all affected members are being notified about the breach. You can also use Troy Hunt’s HaveIBeenPwned.com to find out what, if any, personal information about you is publically available online.

Yet Another Dating Site Which Has Been Allegedly Hacked

Technical Issues
  • Saturday, March 26 2016 @ 10:45 am
  • Contributed by:
  • Views: 2,596
Mate1

Just when you get comfortable with the Internet again, a new story about a hacking disaster makes headlines. This time, a hacker on a dark web forum called “Hell” claims to have sold the email addresses and plaintext passwords of over 27 million users of dating site Mate1.com.

Last year, Hell made headlines when a hacker posted the personal details and sexual preferences of almost 4 million users of the hookup site Adult Friend Finder. The data dump was discovered months after the hack actually happened, forcing Adult Friend Finder to fess up about the breach.

Motherboard obtained a small sample of the stolen email addresses and passwords. Out of 500 addresses, 498 were linked to accounts on Mate1.com. According to its website, Mate1 has over 36.5 million users.

“Their server was compromised and the MySQL database was dumped,” the anonymous hacker told Motherboard. “I had shell/command access to their server.” The hacker claims to have obtained 40 million accounts initially, then whittled that number down by weeding out the bot logins. “They all had a common password pattern,” they said.

The database of poached user info was offered for 20 bitcoin on Hell (around $8,700) although it’s not clear if that was the actual selling price.

How did it happen? Motherboard found that Mate1 was shockingly open to such an attack. A reporter for the site clicked “forgotten password” on the login page and was sent a full, plaintext password via email. Mate1 made no attempt to conceal the password in any way.

The threat here isn't just that users’ dating accounts may now be compromised. A second danger comes from the fact that victims may have used the same passwords across multiple websites, potentially leaving accounts on Gmail, Amazon - anything, really - now open to attack. Anyone who purchased the database could test their newly-acquired passwords on more valuable accounts, and given the high number of credentials the hacker claims to have obtained, there’s a real chance that a significant number will indeed compromise accounts on other websites.  

The first step, if you have an account with Mate1.com, is to change your password there. You’ll also want to update any accounts that share the same password and check to make sure they haven’t been tampered with.  

This hack won’t make news the way the Ashley Madison hack did (catch up here, here, and here if you missed that story), but it serves as yet another reminder that digital security is a subject to be taken seriously.

For more information on this dating service you can read our full review of Mate1.

Spammers take Advantage of Ashley Madison Hack

Technical Issues
  • Wednesday, August 12 2015 @ 10:54 am
  • Contributed by:
  • Views: 1,622

By now, we’ve all heard of the latest in cyber attacks; personal information from infidelity dating website Ashley Madison was stolen by hackers who have since threatened to expose its 37 million users.

However, information about what exactly was stolen – such as credit card information or social security numbers – is still a bit hazy. Ashley Madison customer service has, according to news website Inquisitr, provided customers with conflicting information about what was subject to the hack, namely because they don’t know what was stolen and sold or given to third parties. Some customers have been told that credit card numbers weren’t hacked, but others were told that third party credit card data was indeed hacked.

A few websites have emerged to help customers see if their personal data has been leaked, including a site “Was he on Ashley Madison,” (WasHeOnAshleyMadison.com). Customers of Ashley Madison and also of hacked website Adult Friend Finder could search through emails to see if theirs were compromised. However, as of July 31, that website was put up for sale, and quickly bought by someone looking to make a statement to users of Ashley Madison and Adult Friend Finder. Hours later, what appears to be a former Ashley Madison user posted a statement lashing out against the company, including this paragraph to those who were hacked:

“You have been through enough pain and anger and anxiety about their hack without having some opportunistic scammer buy this domain and charge you money for data they do not have.

I have decided that I am going to fight the AM people so I can keep this domain. They have refused to offer any of their customers any kind of solace or at least a year of identity theft protection which is standard practice when your data is hacked. They prefer to sit in their ivory tower and hide behind their lawyers.

This is not OK with me and it should not be OK with you.”

According to Inquisitr, there have been many sites claiming to provide information for those who feel their personal information could have been hacked, but many of these sites have been nothing but spam themselves. According to an investigation by BBC, Ashley Madison users were sent emails providing links to third party websites, supposedly with information about the hack. Some included the recipient’s Ashley Madison user name, giving more credence to the email, but worrying customers that their information was indeed sold to a third party. However, when people clicked on the links, they were sent to spam sites that were booby-trapped with malware and, in some cases, graphic images and videos of adulterers ‘burning in hell.’

Now Ashley Madison users are turning to Reddit to provide current information about the hack to other users in an attempt to gain information.

One Reddit user claimed that Ashley Madison sold user information to third party sites from the beginning, because that user began getting spam emails as soon as he/she signed up on the website. While it's difficult to tell where exactly information has gone, it has been compromised. We'll see what Ashley Madison does next to address the issue.

Why The Hack Could Be The End Of Ashley Madison

Technical Issues
  • Friday, August 07 2015 @ 07:33 am
  • Contributed by:
  • Views: 1,626

Cheaters are having a bad week.

In case you're not up to speed on the latest scandal to rock the online dating world, here's the gist: a group of hackers calling themselves The Impact Team attacked Ashley Madison and gained access to the site's database of 37 million members. The hackers got hold of financial records, addresses, and other highly sensitive personal information, and have threated to publish it online unless Ashley Madison shuts down.

Avid Life Media, Ashley Madison's parent company, says it has secured its sites and is working with law enforcement agencies to find the parties responsible. Despite their efforts, files containing emails and passwords for some Ashley Madison users have started to spread online.

Some have called this the beginning of the end for Ashley Madison. It's devastating for any website to be hacked, but infinitely more so when it's designed for a philandering clientele whose top priority is privacy. Ashley Madison has failed to uphold one of its most important – perhaps the most important – promises.

And it gets worse. Avid Life Media announced earlier this year that it hopes to raise $200 million in an initial public offering in London in 2015. The brand's value is based almost completely on the service's ability to protect its members' privacy. Without that, is the Ashley Madison worth anything in the first place?

“If a password manager such as LastPass was hacked,” writes Christina Warren for Mashable, “the service would be dead in the water. After all, the whole point of a password management service is to secure and protect your passwords.”

The same principle applies here. Ashley Madison's adulterous target audience is likely to be wary of a site with a history of being hacked. New customers will think twice before joining. Current customers will jump ship. And the IPO? If the hack doesn't squash it completely, it will at least significantly reduce the value of the company.

A renaissance isn't impossible. Other companies have endured disasters, rebranded, and risen from the ashes. It's possible that Ashley Madison could update its security practices, change its name, and come back to reclaim its place in the online dating market.

But should it? Will anyone buy into the narrative that Ashley Madison has seen the error of its ways and reformed? Will cheaters, who require privacy more than anything else, take a chance on a service with such a shoddy track record? The damage may already be irreversible.

Hackers Threaten To Expose Millions Of Ashley Madison Cheaters

Technical Issues
  • Tuesday, July 21 2015 @ 08:27 am
  • Contributed by:
  • Views: 1,746

Life's short. Have an affair. Get hacked.

It's not Ashley Madison's new slogan, but it could be.

The biggest story in the online dating world right now is the news that the infamous dating site for adulterers has been attacked by hackers. A group calling themselves The Impact Team claims to have complete access to Ashley Madison’s database of more than 37 million members. They say they're in possession of financial records, addresses, and other personal information, and are threatening to publish it online unless the site closes.

In addition to Ashley Madison, the same group has compromised two other dating sites, Cougar Life and Established Men. All three are owned by the same parent company, Avid Life Media (ALM).

The hackers said in a statement: “Avid Life Media has been instructed to take Ashley Madison and Established Men offline permanently in all forms, or we will release all customer records, including profiles with all the customers’ secret sexual fantasies and matching credit card transactions, real names and addresses, and employee documents and emails. The other websites may stay online.”

The issue that prompted the attack appears to be the leavers’ fee that Ashley Madison charges users. Should a member choose to leave the service permanently, Ashley Madison offers a “full delete” of their profile and all associated data for a $19 fee.

However, The Impact Team claims no data is ever deleted. "Full Delete netted [Avid Life Media] $1.7 million in revenue in 2014. It's also a complete lie," the hackers said in their statement. "Users almost always pay with credit card; their purchase details are not removed as promised, and include real names and address, which is of course the most important information the users want removed."

So far Avid Life Media has defended the service and offered to stop charging for it in the future. Their own statement says: “We apologise for this unprovoked and criminal intrusion into our customers’ information. The current business world has proven to be one in which no company’s online assets are safe from cyber-vandalism, with Avid Life Media being only the latest among many companies to have been attacked, despite investing in the latest privacy and security technologies.”

For now, ALM has positive words for concerned users. “At this time,” reads the statement, “we have been able to secure our sites, and close the unauthorised access points.” The company is working with law enforcement agencies to investigate the hack and plans to prosecute all parties responsible for what they're calling “an act of cyber-terrorism.”

For more on this developing story you can check out CNN.

AdultFriendFinder's Database Hacked, Data On Sale For $17K

Technical Issues
  • Monday, June 08 2015 @ 06:45 am
  • Contributed by:
  • Views: 2,216

Looking for a morally suspect way to blow $17,000? Here's an idea: purchase the private info stolen from an adult dating website.

According to multiple reports, a massive database of user data was swiped from casual hookup site AdultFriendFinder. It's now going for 70 bitcoins — the equivalent of nearly $17,000 — on the Dark Web.

Adult FriendFinder boasts 63 million users worldwide, billing itself as a "thriving sex community.” Up to 4 million members who shared sensitive sexual information with the site have been affected by the hack.

Allegedly the unredacted data for sale includes personal details like names, email addresses, and postal codes, as well as information about sexual habits and orientation. In addition to your garden variety identity fraud and spam, a breach of this nature could put users at risk of extortion and blackmail.

Interest in the poached info appears to be high. ROR[RG], the moniker used by the hacker who claims to have breached the site, wrote "I have had so many people ask me to buy the db today" in an underground forum on Saturday. ROR[RG] is also offering to break into any company or website for 750 bitcoins (about $170,000).

Within hours of the data being leaked, hackers on the forum declared their intentions to hit victims with spam emails. After sending out virused emails, they can trawl through the data for potential blackmail targets. So far there have been confirmed reports of users receiving spam with malware or trojans.

FriendFinder Networks, the Silicon Valley company that operates the service, says “there is no evidence that any financial information or passwords were compromised.” The company has hired the Mandiant response division of cyber-security company FireEye, which has previously investigated a number of high-profile breaches, to investigate.

In the meantime members are urged to update their user names and passwords. AdultFriendFinder is also temporarily blocking attempts to search for user profiles by any users who are suspected of being affected by the security issue.

"As is common with similar cyber attack events, until the investigation is completed, it will be difficult to confirm the full scope of the incident, but we will continue to work vigilantly to address this potential issue and will provide updates on this site as we learn more from our investigation," said Adult FriendFinder in a statement. "Protecting our members' information is our top priority and we will continue to take the appropriate steps needed to protect our members and their information."

Page navigation