Disaster Hacking group says it’s extorting Pornhub after stealing users’ viewing data - Pornhub confirmed it was among several companies affected by an earlier breach at the widely used web and mobile analytics provider Mixpanel, which exposed unspecified “analytics events” of some Pornhub Premium users.

  • 🏰 The Fediverse is up. If you know, you know.
  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
1.png
Image Credits:Bryce Durbin / TechCrunch

The hacking group Scattered Lapsus$ Hunters, which includes members of a gang known as ShinyHunters, said it is attempting to extort porn site Pornhub, after claiming to have stolen personal information belonging to the website’s premium members.

On Friday, Pornhub confirmed it was among several companies affected by an earlier breach at the widely used web and mobile analytics provider Mixpanel, which exposed unspecified “analytics events” of some Pornhub Premium users.

On Monday, Bleeping Computer reported seeing a sample of the stolen Pornhub data, which included personal information associated with Pornhub Premium members, including their registered email addresses and location; activity type, such as which videos and channels they watched, including the video name and web address; keywords associated with the video; and the date and time that the event was recorded.

Mixpanel chief executive Jen Taylor did not respond to TechCrunch’s request for comment. A Pornhub spokesperson, who did not provide their full name, did not answer questions sent by TechCrunch about the incident, referring us instead to the company’s published statement.

A spokesperson for the ShinyHunters gang told TechCrunch that the hackers have sent an extortion email only to Pornhub so far, and declined to say how many other companies were part of the Mixpanel incident.

Right before the U.S. holiday of Thanksgiving, Mixpanel revealed a breach that it discovered on November 8, which affected its corporate customers, without saying which ones, nor how they were affected. OpenAI later confirmed it was one of those affected customers, as well as CoinTracker and SwissBorg.

According to Mixpanel’s website, the company has around 8,000 customers, with each customer having potentially millions of users whose data was taken in the breach.

The type of data stolen likely depends on how each customer configured their Mixpanel account to collect data.

Generally speaking, companies use Mixpanel to track what their users do on their site or apps, similar to an app developer or website owner watching over a user’s shoulder to learn what they click, view, or swipe. Mixpanel can also log information about the user’s devices, such as the size of the screen, whether they are on Wi-Fi or a cellular network, and the name of the carrier, among other data.

Scattered Lapsus$ Hunters is a coalition of primarily English-speaking hackers who are believed to be in Western countries. The hackers have a long history of data breaches and are responsible for some of the largest hacks this year, including data thefts targeting Salesforce and Gainsight customers, which affected hundreds of companies.

Also on Friday, SoundCloud confirmed that about 20% of its users were affected by “unauthorized activity in an ancillary service dashboard,” likely referring to Mixpanel. The audio streaming giant said the stolen data includes email addresses and “information already visible on public SoundCloud profiles.”

SoundCloud did not respond to TechCrunch’s request for comment.

Article Link

Archive
 
Have you tried to make an email address lately? 99% of email sites require a valid cell phone number to """prevent spam""".

Buying crypto now requires you to record a video of you holding up your passport due to Know Your Customer laws.

It's already happening, fucking look around
These issues are complete divorced from the porn conversation though. You can’t conflate efforts to combat DDOSing, spammers, and fraud with stopping criminal activity surrounding sex or websites targeting minors to build lifelong porn consumers.
 
This is gonna come out anyway so I might as well say it now. I type, "personality" into the search bar and exclusively beat it to videos of women telling me about their day while naked. Some days I feel so alone I could cry, but I don't. I never do. Because what would be the point? Not a single person in the entire universe would care.
I care, but now I'm also aroused. Your angst has made me horny.
 
This is gonna come out anyway so I might as well say it now. I type, "personality" into the search bar and exclusively beat it to videos of women telling me about their day while naked. Some days I feel so alone I could cry, but I don't. I never do. Because what would be the point? Not a single person in the entire universe would care.
Hey bud don’t worry I’m here for you. And I just want to say if things ever get so tough you think about killing yourself… live stream it
 
These issues are complete divorced from the porn conversation though. You can’t conflate efforts to combat DDOSing, spammers, and fraud with stopping criminal activity surrounding sex or websites targeting minors to build lifelong porn consumers.

Sure you can. It normalizes requiring your personal identification for services that do not have a direct business need for it. Apple is even letting you store a digital ID on your phone for these purposes. Once there is a critical mass or standardization of this ID-as-a-login, every site will begin directly tie your personal info to your usage of their service. Every major website now lets you use centralized Google OAuth to login because Google made it easy to implement. Expect the same with whatever DigitalDox standard is sure to come.

"But the children!", I hear you cry. The government should not be doing parenting. Teach your kids porn is not realistic and can be as addictive as drugs. This is no different than teaching them about cigarettes, alcohol, or junk food.

All that being said, if you had a Pornhub Premium account you're a big loser.

Other privacy and identity related reading:
Four Horsemen of the Infopocalypse
EU trying to read every text you send to protect children
Apple scanning every iCloud photo you own to search for CSAM
 
Who the fuck signs up and/or pays for porn? Lmao just go incognito, bang it out and get back to whatever you were doing. I cannot fathom the gooner mindset.
 
These issues are complete divorced from the porn conversation though. You can’t conflate efforts to combat DDOSing, spammers, and fraud with stopping criminal activity surrounding sex or websites targeting minors to build lifelong porn consumers.
No it's not you fucking dumbass. The same way the Patriot Act eventually stopped being used to monitor terrorists and just turned into overall surveillance.
 
They got the Ashley Madison treatment then...

Stop wanking off to porn:

 
Lately it feels like alot places have been getting hit with data breaches. Wonder whats been goin on with that. Probably just me.
Who the fuck signs up and/or pays for porn? Lmao just go incognito, bang it out and get back to whatever you were doing. I cannot fathom the gooner mindset.
Porn sites tend to paywall the "good" stuff that causes porn addicts to immediately make an account or pay money to see even if they're just gonna be one and done session.
 
What kind of goonbrained retard creates a login for porn hub?:story:
A lot of these sites require at least a free account to download videos, and gooners aren't exactly gonna practice opsec when the compulsion to fill their external hard drive stashes hits
 
Back
Top Bottom