2021 Epik Data Breach
   HOME

TheInfoList



OR:

The Epik data breach occurred in 2021 and targeted the American
domain registrar A domain name registrar is a company that manages the reservation of Internet domain names. A domain name registrar must be accredited by a generic top-level domain (gTLD) registry or a country code top-level domain (ccTLD) registry. A registrar ...
and web hosting company
Epik Epik is a right-wing American domain registrar and web hosting company known for providing services to alt-tech websites that host far-right, neo-Nazi, and other extremist materials. It has been described as a haven for the far-right because of i ...
. The
breach Breach, Breached, or The Breach may refer to: Places * Breach, Kent, United Kingdom * Breach, West Sussex, United Kingdom * ''The Breach'', Great South Bay in the State of New York People * Breach (DJ), an Electronic/House music act * Miroslava ...
exposed a wide range of information including personal information of customers, domain history and purchase records, credit card information, internal company emails, and records from the company's WHOIS privacy service. More than 15million unique email addresses were exposed, belonging to customers and to non-customers whose information had been scraped. The attackers responsible for the breach identified themselves as members of the
hacktivist In Internet activism, hacktivism, or hactivism (a portmanteau of '' hack'' and '' activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in h ...
collective
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
. The attackers released an initial 180
gigabyte The gigabyte () is a multiple of the unit byte for digital information. The prefix ''giga'' means 109 in the International System of Units (SI). Therefore, one gigabyte is one billion bytes. The unit symbol for the gigabyte is GB. This defini ...
dataset on September 13, 2021, though the data appeared to have been exfiltrated in late February of the same year. A second release, this time containing bootable disk images, was made on September 29. A third release on October 4 reportedly contained more bootable disk images and documents belonging to the
Texas Republican Party The Republican Party of Texas (RPT) is the affiliate of the United States Republican Party in the state of Texas. It is currently chaired by Matt Rinaldi, succeeding Allen West who resigned prior to the expiration of his term to run for governo ...
, a customer of Epik's. Epik is known for providing services to websites that host
far-right Far-right politics, also referred to as the extreme right or right-wing extremism, are political beliefs and actions further to the right of the left–right political spectrum than the standard political right, particularly in terms of being ...
,
neo-Nazi Neo-Nazism comprises the post–World War II militant, social, and political movements that seek to revive and reinstate Nazism, Nazi ideology. Neo-Nazis employ their ideology to promote hatred and Supremacism#Racial, racial supremacy (ofte ...
, and other
extremist Extremism is "the quality or state of being extreme" or "the advocacy of extreme measures or views". The term is primarily used in a political or religious sense to refer to an ideology that is considered (by the speaker or by some implied shar ...
content. Past and present Epik customers include Gab,
Parler Parler () is an American alt-tech social networking service associated with conservatives. Journalists have described Parler as an alt-tech alternative to Twitter, and users include those banned from mainstream social networks or who oppose ...
,
8chan 8kun, previously called 8chan, Infinitechan or Infinitychan (stylized as ∞chan), is an imageboard website composed of user-created message boards. An owner moderates each board, with minimal interaction from site administration. The site ha ...
, the
Oath Keepers Oath Keepers is an American far-right anti-government militia whose leaders have been convicted of violently opposing the government of the United States, including the transfer of Presidential power as prescribed by the US Constitution. ...
, and the
Proud Boys The Proud Boys is an American far-right, neo-fascist, and exclusively male organization that promotes and engages in political violence in the United States.Far-right: * * Fascist: * * * * * Men only: * * * Political violence: * * * It has ...
. The hack was described as "a
Rosetta Stone The Rosetta Stone is a stele composed of granodiorite inscribed with three versions of a Rosetta Stone decree, decree issued in Memphis, Egypt, in 196 BC during the Ptolemaic dynasty on behalf of King Ptolemy V Epiphanes. The top and middle te ...
to the far-right" because it has allowed researchers and journalists to discover links between far-right websites, groups, and individuals.
Distributed Denial of Secrets Distributed Denial of Secrets, abbreviated DDoSecrets, is a non-profit whistleblower site for news leaks founded in 2018. Sometimes referred to as a successor to WikiLeaks, it is best known for its June 2020 publication of a large collection of ...
(DDoSecrets) co-founder Emma Best said researchers had been describing the breach as "the
Panama Papers The Panama Papers ( es, Papeles de Panamá) are 11.5 million leaked documents (or 2.6 terabytes of data) that were published beginning on April 3, 2016. The papers detail financial and attorney–client information for more than 214,488 ...
of hate groups". Epik was subsequently criticized for lax
data security Data security means protecting digital data, such as those in a database, from destructive forces and from the unwanted actions of unauthorized users, such as a cyberattack or a data breach. Technologies Disk encryption Disk encryption refe ...
practices, in particular failing to properly
encrypt In cryptography, encryption is the process of encoding information. This process converts the original representation of the information, known as plaintext, into an alternative form known as ciphertext. Ideally, only authorized parties can decip ...
sensitive customer data.


Background

Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
is a
decentralized Decentralization or decentralisation is the process by which the activities of an organization, particularly those regarding planning and decision making, are distributed or delegated away from a central, authoritative location or group. Conce ...
international
hacktivist In Internet activism, hacktivism, or hactivism (a portmanteau of '' hack'' and '' activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in h ...
collective A collective is a group of entities that share or are motivated by at least one common issue or interest, or work together to achieve a common objective. Collectives can differ from cooperatives in that they are not necessarily focused upon an ...
that is widely known for its various cyber attacks against several
governments A government is the system or group of people governing an organized community, generally a state. In the case of its broad associative definition, government normally consists of legislature, executive, and judiciary. Government is a ...
and governmental institutions, corporations, and the
Church of Scientology The Church of Scientology is a group of interconnected corporate entities and other organizations devoted to the practice, administration and dissemination of Scientology, which is variously defined as a cult, a scientology as a business, bu ...
. Primarily active in the late 2000s and early 2010s, Anonymous' media profile diminished by 2018. The group re-emerged in 2020 to support the
George Floyd protests The George Floyd protests were a series of protests and civil unrest against police brutality and racism that began in Minneapolis on May 26, 2020, and largely took place during 2020. The civil unrest and protests began as part of internati ...
and other causes. In September 2021, Anonymous asked people to support " Operation Jane", an effort by the group to oppose the
Texas Heartbeat Act The Texas Heartbeat Act, Senate Bill 8 (SB 8), is an act of the Texas Legislature that bans abortion after the detection of embryonic or fetal cardiac activity, which normally occurs after about six weeks of pregnancy. The law took effect ...
, a six-week abortion ban that went into effect on September 1. On September 4, Epik had begun providing services to a "whistleblower" website run by the
anti-abortion Anti-abortion movements, also self-styled as pro-life or abolitionist movements, are involved in the abortion debate advocating against the practice of abortion and its legality. Many anti-abortion movements began as countermovements in respons ...
Texas Right to Life organization, which allowed people to anonymously report suspected violators of the bill. The website, which moved to Epik after being denied services by
GoDaddy GoDaddy Inc. is an American publicly traded Internet domain registrar and web hosting company headquartered in Tempe, Arizona, and incorporated in Delaware. , GoDaddy has more than 21 million customers and over 6,600 employees worldwide. The co ...
, went offline after Epik told the group they had violated their terms of service by collecting private information about third parties. On September 11, Anonymous hacked the website of the
Republican Party of Texas The Republican Party of Texas (RPT) is the affiliate of the United States Republican Party in the state of Texas. It is currently chaired by Matt Rinaldi, succeeding Allen West who resigned prior to the expiration of his term to run for governo ...
, which is hosted by Epik, to replace it with text about Operation Jane.


Data breach

Hackers identifying themselves as a part of Anonymous announced on September 13, 2021 that they had gained access to large quantities of Epik data, including domain purchase and transfer details, account credentials and logins, payment history, employee emails, and unidentified private keys. The hackers claimed they had obtained "a decade's worth of data", including all customer data and records for all domains ever hosted or registered through the company, and which included poorly encrypted passwords and other sensitive data stored in
plaintext In cryptography, plaintext usually means unencrypted information pending input into cryptographic algorithms, usually encryption algorithms. This usually refers to data that is transmitted or stored unencrypted. Overview With the advent of comp ...
. The
Distributed Denial of Secrets Distributed Denial of Secrets, abbreviated DDoSecrets, is a non-profit whistleblower site for news leaks founded in 2018. Sometimes referred to as a successor to WikiLeaks, it is best known for its June 2020 publication of a large collection of ...
(DDoSecrets) organization announced later that day that they were working to curate the leaked data for public download, and said that it consisted of "180
gigabyte The gigabyte () is a multiple of the unit byte for digital information. The prefix ''giga'' means 109 in the International System of Units (SI). Therefore, one gigabyte is one billion bytes. The unit symbol for the gigabyte is GB. This defini ...
s of user, registration, forwarding and other information". Journalists and security researchers subsequently confirmed the veracity of the hack and the types of information that had been exposed. The data included in the leak appeared to have been exfiltrated in late February 2021. The leak was later confirmed to include approximately 15million unique email addresses, which belonged both to customers and non-customers whose data had been scraped from
WHOIS WHOIS (pronounced as the phrase "who is") is a query and response protocol that is widely used for querying databases that store the registered users or assignees of an Internet resource, such as a domain name, an IP address block or an autonomou ...
records. It also included 843,000 transactions from a period of over ten years, and almost one million invoices. An engineer performing an initial impact assessment for an Epik customer said that Epik's "entire primary database", which contained account usernames, passwords, SSH keys, and credit card numbers stored in plaintext, had also been compromised. Internal memos describing
subpoena A subpoena (; also subpœna, supenna or subpena) or witness summons is a writ issued by a government agency, most often a court, to compel testimony by a witness or production of evidence under a penalty for failure. There are two common types of ...
s and preservation requests were also found in the leaked data. Many of the data preservation requests appeared to be related to investigations following the January Capitol attack. A security researcher speaking to ''
TechCrunch TechCrunch is an American online newspaper focusing on high tech and startup companies. It was founded in June 2005 by Archimedes Ventures, led by partners Michael Arrington and Keith Teare. In 2010, AOL acquired the company for approximately ...
'' said he had identified a security vulnerability with Epik in January, which he had reported to
Rob Monster Robert W. Monster (born 1966 or 1967) is a Dutch-American technology executive and the founder and chief executive officer of Epik, a domain registrar and web host known for providing services to websites that host far-right, neo-Nazi, and extre ...
, Epik CEO, but which had not been acknowledged. The vulnerability would have allowed attackers to execute arbitrary code on Epik servers, and the researcher said he suspected the same vulnerability had been exploited by the Anonymous attackers. Monster told ''TechCrunch'' he had seen the report, but mistook it for
spam Spam may refer to: * Spam (food), a canned pork meat product * Spamming, unsolicited or undesired electronic messages ** Email spam, unsolicited, undesired, or illegal email messages ** Messaging spam, spam targeting users of instant messaging ( ...
. On September 29, Anonymous released another 300gigabytes of data including bootable disk images. According to a cybersecurity expert speaking to ''The Daily Dot'', "Files are one thing, but a virtual machine disk image allows you to boot up the company’s entire server on your own. We usually see breaches with database dumps, documents, configuration files, etc. In this case, we are talking about the entire server image, with all the programs and files required to host the application it is serving." The second leak included API keys and plaintext login credentials for Epik's systems, as well as for services including
Coinbase Coinbase Global, Inc., branded Coinbase, is an American publicly traded company that operates a cryptocurrency exchange platform. Coinbase is a distributed company; all employees operate via remote work and the company lacks a physical headquar ...
,
PayPal PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system in the majority of countries that support online money transfers, and serves as an electronic alternative to traditional paper ...
, and the company's
Twitter Twitter is an online social media and social networking service owned and operated by American company Twitter, Inc., on which users post and interact with 280-character-long messages known as "tweets". Registered users can post, like, and ...
account. A third release on October 4 reportedly contained more bootable disk images, as well as documents belonging to the
Texas Republican Party The Republican Party of Texas (RPT) is the affiliate of the United States Republican Party in the state of Texas. It is currently chaired by Matt Rinaldi, succeeding Allen West who resigned prior to the expiration of his term to run for governo ...
.


Company response

On September 13, the day the hacked data was released, Epik said in statements to news outlets that they were "not aware of any breach". When the company did not acknowledge the breach, the attackers vandalized Epik's support website. On September 15, the company sent an email to customers notifying them of "an alleged security incident". Monster acknowledged the hack in a September 16 public
video conference Video is an electronic medium for the recording, copying, playback, broadcasting, and display of moving visual media. Video was first developed for mechanical television systems, which were quickly replaced by cathode-ray tube (CRT) syste ...
, which ''The Daily Dot'' described as "chaotic and bizarre" and which ''
Le Monde ''Le Monde'' (; ) is a French daily afternoon newspaper. It is the main publication of Le Monde Group and reported an average circulation of 323,039 copies per issue in 2009, about 40,000 of which were sold abroad. It has had its own website si ...
'' characterized as "possibly one of the strangest responses to a computer security incident in history". The company publicly confirmed the breach on September 17, and began emailing customers to inform them on September 19. Data breach monitoring service
Have I Been Pwned? Have I Been Pwned? (HIBP; with "Pwned" pronounced like "poned", and stylized in all lowercase as "';--have i been pwned?" on the website) is a website that allows Internet users to check whether their personal data has been compromised by ...
also began sending emails to all addresses that had been exposed on September 19. Epik submitted a data-breach notice in the state of Maine, in which they reported that 110,000 people had been affected by the breach, and that financial account and credit card data had been exposed. In a statement to ''
The Washington Post ''The Washington Post'' (also known as the ''Post'' and, informally, ''WaPo'') is an American daily newspaper published in Washington, D.C. It is the most widely circulated newspaper within the Washington metropolitan area and has a large nati ...
'', an Epik spokesperson said that up to 38,000 credit card numbers had been leaked.


Aftermath

The hack was described as "a Rosetta Stone to the far-right", allowing researchers and journalists to connect links between various far-right websites, groups, and individuals who were using Epik's services. DDoSecrets co-founder Emma Best said researchers had been describing the breach as "the
Panama Papers The Panama Papers ( es, Papeles de Panamá) are 11.5 million leaked documents (or 2.6 terabytes of data) that were published beginning on April 3, 2016. The papers detail financial and attorney–client information for more than 214,488 ...
of hate groups", and said that researchers would be "in for the long haul" with the amount of data that had been exposed. The
Columbia Journalism Review The ''Columbia Journalism Review'' (''CJR'') is a biannual magazine for professional journalists that has been published by the Columbia University Graduate School of Journalism since 1961. Its contents include news and media industry trends, ana ...
similarly compared the data breach to the Panama Papers leak, stating "Like the Panama Papers, getting information out of the huge database and making sense of it is time-consuming, which may explain why coverage of the Epik hack lagged..." Data from the hack was used to show that
Ali Alexander Ali Alexander (born Ali Abdul-Razaq Akbar in ) is an American far-right activist, social media personality, and conspiracy theorist. Alexander is an organizer of Stop the Steal, a campaign to promote the conspiracy theory that widespread vo ...
, a far-right activist and key figure in the "
Stop the Steal After Joe Biden won the 2020 United States presidential election, then-incumbent Donald Trump pursued an unprecedented effort to overturn the election, with support and assistance from his campaign, proxies, political allies, and many of h ...
" conspiracy theory campaign, had worked to hide his connections to more than 100 websites after the
2021 United States Capitol attack On January 6, 2021, following the defeat of then-U.S. President Donald Trump in the 2020 presidential election, a mob of his supporters attacked the United States Capitol Building in Washington, D.C. The mob was seeking to keep Trump in pow ...
.


Reactions

Extremism researcher and computer scientist
Megan Squire Megan Squire is a professor of computer science at Elon University. A researcher and Anti-Defamation League fellow with a focus on right-wing political extremism online, her work has been described as operating as an intermediary between non-prof ...
said of the hack, "It's massive. It may be the biggest domain-style leak I've seen and, as an extremism researcher, it's certainly the most interesting." Internet anthropologist
Gabriella Coleman Enid Gabriella Coleman (usually known as Gabriella Coleman or Biella; born 1973) is an anthropologist, academic and author whose work focuses on cultures of hacking and online activism, particularly Anonymous. She previously held the Wolfe Ch ...
predicted the hack would force far-right groups to find security providers outside of the United States, and said that the hack had "confirmed a lot of the details of the far-right ecosystem". Cybersecurity analyst and online extremism researcher Emily Crose said that the breach would likely intensify existing paranoia among far-right groups, who already felt like they were being surveilled after the Capitol attack. An engineer performing an initial impact assessment for an Epik client told ''
The Daily Dot ''The Daily Dot'' is a digital media company covering the culture of the Internet and the World Wide Web. Founded by Nicholas White in 2011, ''The Daily Dot'' is headquartered in Austin, Texas. The site, conceived as the Internet's "hometown ...
'' that "
pik Pik may refer to: People * Pik, name used by comic creator Léo Quievreux as a musician * Fong Chong Pik (1924–2004), Malaysian politician * Pik Botha (1932–2018), former South African politician * Tzvika Pick (1949–2022), Israeli compose ...
are fully compromised end-to-end... Maybe the worst I've ever seen in my 20-year career". Following the hack, ''The Washington Post'' reported that "Epik's security protocols have been the target of ridicule among researchers, who've marveled at the site's apparent failure to take basic security precautions". Epik had been storing passwords using unsalted MD5, making them easy to crack. Other sensitive data, including credit card information, was being stored in
plaintext In cryptography, plaintext usually means unencrypted information pending input into cryptographic algorithms, usually encryption algorithms. This usually refers to data that is transmitted or stored unencrypted. Overview With the advent of comp ...
.
David Vladeck David C. Vladeck (born June 6, 1951) is the former director of the Bureau of Consumer Protection of the Federal Trade Commission, an independent agency of the United States government. He was appointed by the chairman of the FTC, Jon Leibowitz, on ...
, a Georgetown law professor and the former head of the Federal Trade Commission's (FTC)
consumer protection Consumer protection is the practice of safeguarding buyers of goods and services, and the public, against unfair practices in the marketplace. Consumer protection measures are often established by law. Such laws are intended to prevent business ...
bureau, said, "Given Epik's boasts about security, and the scope of its web hosting, I would think it would be an FTC target, especially if the company was warned but failed to take protective action".


Other breaches

Two weeks after the initial release of data, hackers released data taken from the American far-right
Oath Keepers Oath Keepers is an American far-right anti-government militia whose leaders have been convicted of violently opposing the government of the United States, including the transfer of Presidential power as prescribed by the US Constitution. ...
militia. The hackers responsible for the Oath Keepers leak did not claim any connection to Anonymous or draw any connection to the Epik breach, though some journalists have speculated that the leak may have been related or made possible by information from the Epik data. The Oath Keepers data consists of about 3.8gigabytes of email archives, chat logs, and a membership list. The data is also being disseminated by DDoSecrets, though the group restricted the list of members and files containing donor and finance information to journalists. The Oath Keepers had been a customer of Epik's since January 2021, when their website was taken offline after their hosting provider terminated service in the wake of the Capitol attack.


See also

*
List of security hacking incidents The list of security hacking incidents covers important or noteworthy events in the history of ''security hacking'' and cracking. 1900 1903 * Magician and inventor Nevil Maskelyne disrupts John Ambrose Fleming's public demonstration of Gugliel ...
* *


References

{{DEFAULTSORT:Epik data breach, 2021 Anonymous (hacker group) Data breaches in the United States Hacking in the 2020s September 2021 events in the United States