Disaster Hacking group says it’s extorting Pornhub after stealing users’ viewing data - Pornhub confirmed it was among several companies affected by an earlier breach at the widely used web and mobile analytics provider Mixpanel, which exposed unspecified “analytics events” of some Pornhub Premium users.

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
1.png
Image Credits:Bryce Durbin / TechCrunch

The hacking group Scattered Lapsus$ Hunters, which includes members of a gang known as ShinyHunters, said it is attempting to extort porn site Pornhub, after claiming to have stolen personal information belonging to the website’s premium members.

On Friday, Pornhub confirmed it was among several companies affected by an earlier breach at the widely used web and mobile analytics provider Mixpanel, which exposed unspecified “analytics events” of some Pornhub Premium users.

On Monday, Bleeping Computer reported seeing a sample of the stolen Pornhub data, which included personal information associated with Pornhub Premium members, including their registered email addresses and location; activity type, such as which videos and channels they watched, including the video name and web address; keywords associated with the video; and the date and time that the event was recorded.

Mixpanel chief executive Jen Taylor did not respond to TechCrunch’s request for comment. A Pornhub spokesperson, who did not provide their full name, did not answer questions sent by TechCrunch about the incident, referring us instead to the company’s published statement.

A spokesperson for the ShinyHunters gang told TechCrunch that the hackers have sent an extortion email only to Pornhub so far, and declined to say how many other companies were part of the Mixpanel incident.

Right before the U.S. holiday of Thanksgiving, Mixpanel revealed a breach that it discovered on November 8, which affected its corporate customers, without saying which ones, nor how they were affected. OpenAI later confirmed it was one of those affected customers, as well as CoinTracker and SwissBorg.

According to Mixpanel’s website, the company has around 8,000 customers, with each customer having potentially millions of users whose data was taken in the breach.

The type of data stolen likely depends on how each customer configured their Mixpanel account to collect data.

Generally speaking, companies use Mixpanel to track what their users do on their site or apps, similar to an app developer or website owner watching over a user’s shoulder to learn what they click, view, or swipe. Mixpanel can also log information about the user’s devices, such as the size of the screen, whether they are on Wi-Fi or a cellular network, and the name of the carrier, among other data.

Scattered Lapsus$ Hunters is a coalition of primarily English-speaking hackers who are believed to be in Western countries. The hackers have a long history of data breaches and are responsible for some of the largest hacks this year, including data thefts targeting Salesforce and Gainsight customers, which affected hundreds of companies.

Also on Friday, SoundCloud confirmed that about 20% of its users were affected by “unauthorized activity in an ancillary service dashboard,” likely referring to Mixpanel. The audio streaming giant said the stolen data includes email addresses and “information already visible on public SoundCloud profiles.”

SoundCloud did not respond to TechCrunch’s request for comment.

Article Link

Archive
 
Maybe some CSAM peddlers will get caught?
lolwat said:
OpenAI said it was affected by the breach because it relied on software provided by Mixpanel to help understand how OpenAI users interact with certain parts of its website
I am constantly amazed at the fact that a complete fucking retard like me managed to build that kind of service in-house-by-myself without billions of dollars but these fucking retards outsource it. I wonder if it is the jeet-to-jeet pipeline at work.
 
Last edited:
Oh shit, now people will know I jerk it exclusively to tasteful nude paintings, antique leather, and chinese watercolor.
 
I don't shed a tear for them.
Any company like this is surely extractive and sell the user data to advertisers.
 
The only reason I would even consider making a Pornhub account would be to gimmick shitpost in the comments. But then I’d have to actually use Pornhub.
 
Like with age verification horse shit it all starts at the places where the argument is sound, actual pornographic content, and exactly the way the age verification and mandatory self doxx crusade that was conviently launched across most of the first world all at the same this is the underlying threat to users, a hacker is going to get the data and leak it.

Laugh all you want that the gooners are getting rekt but what if your comments against the packs of "youths" commiting crime are pinned to you, or you got caught dissenting about mass migration on what was supposed to be an anonymous account with a pinky swear it wont be tied to your mandatory ID, or Allah forbid you were seen on the infamous trans suicide instigation site known as the kiwifarms after deer sneeder was forced to implement ID checks to comply with the law after one of the gazillion bills in multiple governments legislature to mandate this passes and the site suffers a hack.

It always starts with porn but don't forget it's just the testing ground to spread this across the web, the data leak deanonymization threat is real.
Why is it always laws that mandate information collection, and never laws that prohibit services from collecting your dox? We should pass laws that ban information collection.
 
This is gonna come out anyway so I might as well say it now. I type, "personality" into the search bar and exclusively beat it to videos of women telling me about their day while naked. Some days I feel so alone I could cry, but I don't. I never do. Because what would be the point? Not a single person in the entire universe would care.
 
Like with age verification horse shit it all starts at the places where the argument is sound, actual pornographic content, and exactly the way the age verification and mandatory self doxx crusade that was conviently launched across most of the first world all at the same this is the underlying threat to users, a hacker is going to get the data and leak it.

Laugh all you want that the gooners are getting rekt but what if your comments against the packs of "youths" commiting crime are pinned to you, or you got caught dissenting about mass migration on what was supposed to be an anonymous account with a pinky swear it wont be tied to your mandatory ID, or Allah forbid you were seen on the infamous trans suicide instigation site known as the kiwifarms after deer sneeder was forced to implement ID checks to comply with the law after one of the gazillion bills in multiple governments legislature to mandate this passes and the site suffers a hack.

It always starts with porn but don't forget it's just the testing ground to spread this across the web, the data leak deanonymization threat is real.
I keep seeing people say “it always starts with the porn,” but when and where has this actually played out to where suddenly I have to present ID to do anything on the internet?
 
I keep seeing people say “it always starts with the porn,” but when and where has this actually played out to where suddenly I have to present ID to do anything on the internet?

Have you tried to make an email address lately? 99% of email sites require a valid cell phone number to """prevent spam""".

Buying crypto now requires you to record a video of you holding up your passport due to Know Your Customer laws.

It's already happening, fucking look around
 
Back
Top Bottom