Epik data breach impacts 15 million users, including non-customers


Epik has now confirmed that an “unauthorized intrusion” did in reality happen into its programs. The announcement follows final week’s incident of hacktivist collective Anonymous leaking 180 GB of data stolen from on-line service supplier Epik. To mock the corporate’s preliminary response to the data breach claims, Anonymous had altered Epik’s official knowledge base, as reported by Ars.

Epik is a website registrar and net providers supplier identified to serve right-wing shoppers, a few of which have been turned down by extra mainstream IT suppliers as a result of objectionable and typically illicit content material hosted by the shoppers. Epik’s shoppers have included the Texas GOP, Parler, Gab, and 8chan, amongst others.

Epik hack impacts thousands and thousands of non-customers, too

Turns out, the leaked data dump comprises 15,003,961 electronic mail addresses belonging to each Epik’s prospects and non-customers, and never everyone seems to be happy with the news. This occurred as Epik had scraped WHOIS data of domains, even these not owned by the corporate, and saved these data. In doing so, the contact data of those that have by no means transacted with Epik straight was additionally retained in Epik’s programs.

Data breach monitoring service HaveIBeenPwned has now begun sending out alerts to thousands and thousands of electronic mail addresses uncovered within the Epik hack. The service’s founder, Troy Hunt, is among the many impacted by the data breach however who “had absolutely nothing to do with Epik.”

In a ballot final week, Hunt had requested if affected customers who weren’t Epik prospects most well-liked receiving breach alerts as properly. The majority of customers responded affirmatively to the query.

“The breach exposed a huge volume of data not just of Epik customers, but also scraped WHOIS records belonging to individuals and organisations who were not Epik customers,” states HaveIBeenPwned. “The data included over 15 million unique email addresses (including anonymised versions for domain privacy), names, phone numbers, physical addresses, purchases and passwords stored in various formats.”

Ars has seen part of the leaked whois.sql data set file, roughly 16 GB in measurement, with emails, IP addresses, domains, bodily addresses, and cellphone numbers of the customers. We observed WHOIS data for some domains have been dated and contained incorrect details about area homeowners—individuals who now not personal these property.

Epik's WHOIS database, part of the 180 GB leak.
Enlarge / Epik’s WHOIS database, a part of the 180 GB leak.

Ax Sharma

Prior to registering domains, area registrars require customers to supply their “WHOIS” contact data, resembling electronic mail deal with, bodily deal with, and cellphone quantity. This data turns into part of the general public WHOIS listing and is searchable by anybody for contacting the area proprietor. Being public data, WHOIS data could also be seen or scraped by anybody. Those preferring to not disclose their private data straight on a WHOIS listing usually depend on an organization or a private WHOIS provider to behave on their behalf. However, what has gotten the customers involved on this case is that the presence of their contact data in Epik’s data set might falsely painting them as having a connection to Epik when there was none.

“Wonder if there is any legal recourse once can take against [Epik] for harvesting data, and keeping it longer than expected in a cache for individuals who are NOT clients, and have had 0 business dealings with them? Is there a precedent for this?” asked TapEnvy.US, a Texas-based app growth store.

Epik confirms data breach, emails impacted folks

Epik has confirmed the breach and can be emailing the impacted events about an “unauthorized intrusion,” in accordance with screenshots shared by data scientist Emily Gorcenski and cybersecurity professional Adam Sculthorpe:

Epik begins emailing data breach notice to customers.
Enlarge / Epik begins emailing data breach discover to prospects.

“As we work to confirm all related details, we are taking an approach toward maximum caution and urging customers to remain alert for any unusual activity they may observe regarding their information used for our services – this may include payment information including credit card numbers, registered names, usernames, emails, and passwords,” reads Epik’s electronic mail discover.

Although the corporate has not confirmed right now if bank card data was additionally compromised, as a warning, customers are inspired to “contact any credit card companies that you used to transact with Epik and notify them of a potential data compromise to discuss your options with them directly.”

Previously, an Epik spokesperson had advised Ars that the corporate was not conscious of any breach and was investigating the claims.

Users can verify if their data has been uncovered as part of this hack at HaveIBeenPwned.com. Those whose contact data was uncovered ought to preserve a watch out for any phishing emails and on-line banking scams.

Source link