2021 Epik data breach explained

The Epik data breach occurred in September and October 2021, targeting the American domain registrar and web hosting company Epik. The breach exposed a wide range of information including personal information of customers, domain history and purchase records, credit card information, internal company emails, and records from the company's WHOIS privacy service. More than 15million unique email addresses were exposed, belonging to customers and to non-customers whose information had been scraped. The attackers responsible for the breach identified themselves as members of the hacktivist collective Anonymous. The attackers released an initial 180gigabyte dataset on September 13, 2021, though the data appeared to have been exfiltrated in late February of the same year.[1] A second release, this time containing bootable disk images, was made on September 29. A third release on October 4 reportedly contained more bootable disk images and documents belonging to the Texas Republican Party, a customer of Epik's.[2]

Epik is known for providing services to websites that host far-right, neo-Nazi, and other extremist content.[3] Past and present Epik customers include Gab, Parler, 8chan, the Oath Keepers, and the Proud Boys.[4] The hack was described as "a Rosetta Stone to the far-right" because it has allowed researchers and journalists to discover links between far-right websites, groups, and individuals. Distributed Denial of Secrets (DDoSecrets) co-founder Emma Best said researchers had been describing the breach as "the Panama Papers of hate groups".

Epik was subsequently criticized for lax data security practices, in particular failing to properly encrypt sensitive customer data.

Background

Anonymous is a decentralized international hacktivist collective that is widely known for its various cyber attacks against several governments and governmental institutions, corporations, and the Church of Scientology.[5] Primarily active in the late 2000s and early 2010s, Anonymous' media profile diminished by 2018.[6] [7] The group re-emerged in 2020 to support the George Floyd protests and other causes.[8] [9]

In September 2021, Anonymous asked people to support "Operation Jane", an effort by the group to oppose the Texas Heartbeat Act, a six-week abortion ban that went into effect on September 1. On September 4, Epik had begun providing services to a "whistleblower" website run by the anti-abortion Texas Right to Life organization, which allowed people to anonymously report suspected violators of the bill. The website, which moved to Epik after being denied services by GoDaddy, went offline after Epik told the group they had violated their terms of service by collecting private information about third parties.[10] On September 11, Anonymous hacked the website of the Republican Party of Texas, which is hosted by Epik, to replace it with text about Operation Jane.[11] [12]

Data breach

Hackers identifying themselves as a part of Anonymous announced on September 13, 2021 that they had gained access to large quantities of Epik data, including domain purchase and transfer details, account credentials and logins, payment history, employee emails, and unidentified private keys.[13] The hackers claimed they had obtained "a decade's worth of data", including all customer data and records for all domains ever hosted or registered through the company, and which included poorly encrypted passwords and other sensitive data stored in plaintext.[14] The Distributed Denial of Secrets (DDoSecrets) organization announced later that day that they were working to curate the leaked data for public download, and said that it consisted of "180gigabytes of user, registration, forwarding and other information".[15]

Journalists and security researchers subsequently confirmed the veracity of the hack and the types of information that had been exposed.[16] [17] [18] The data included in the leak appeared to have been exfiltrated in late February 2021. The leak was later confirmed to include approximately 15million unique email addresses, which belonged both to customers and non-customers whose data had been scraped from WHOIS records.[19] It also included 843,000 transactions from a period of over ten years, and almost one million invoices.[20] An engineer performing an initial impact assessment for an Epik customer said that Epik's "entire primary database", which contained account usernames, passwords, SSH keys, and credit card numbers stored in plaintext, had also been compromised. Internal memos describing subpoenas and preservation requests were also found in the leaked data. Many of the data preservation requests appeared to be related to investigations following the January Capitol attack.[21]

A security researcher speaking to TechCrunch said he had identified a security vulnerability with Epik in January, which he had reported to Rob Monster, Epik CEO, but which had not been acknowledged. The vulnerability would have allowed attackers to execute arbitrary code on Epik servers, and the researcher said he suspected the same vulnerability had been exploited by the Anonymous attackers. Monster told TechCrunch he had seen the report, but mistook it for spam.

On September 29, Anonymous released another 300gigabytes of data including bootable disk images. According to a cybersecurity expert speaking to The Daily Dot, "Files are one thing, but a virtual machine disk image allows you to boot up the company's entire server on your own. We usually see breaches with database dumps, documents, configuration files, etc. In this case, we are talking about the entire server image, with all the programs and files required to host the application it is serving." The second leak included API keys and plaintext login credentials for Epik's systems, as well as for services including Coinbase, PayPal, and the company's Twitter account.[22]

A third release on October 4 reportedly contained more bootable disk images, as well as documents belonging to the Texas Republican Party.

Company response

On September 13, the day the hacked data was released, Epik said in statements to news outlets that they were "not aware of any breach".[23] When the company did not acknowledge the breach, the attackers vandalized Epik's support website.[17] On September 15, the company sent an email to customers notifying them of "an alleged security incident".

Monster acknowledged the hack in a September 16 four hour public video conference on PrayerMeeting.com, which The Daily Dot described as "chaotic and bizarre", which Le Monde characterized as "possibly one of the strangest responses to a computer security incident in history", and which CNN described as being "like a late-night campfire chat, albeit with an element of the surreal."[24] During the conference, Monster recited prayers to scare away demons, warned participants in the conference not to tamper with the hacked data due to it being "cursed", and spoke in friendly terms with neo-Nazi Andrew Auernheimer and a founder of Anonymous Aubrey Cottle. Also during the conference, Cottle denied carrying out the Epik data breach, but added that "I would never, ever, ever, ever admit to a federal crime in a space like this."

The company publicly confirmed the breach on September 17, and began emailing customers to inform them on September 19. Data breach monitoring service Have I Been Pwned? also began sending emails to all addresses that had been exposed on September 19.

Epik submitted a data-breach notice in the state of Maine, in which they reported that 110,000 people had been affected by the breach, and that financial account and credit card data had been exposed. In a statement to The Washington Post, an Epik spokesperson said that up to 38,000 credit card numbers had been leaked.[20]

Monster later said of the hack that "It didn't kill us" and "It's gonna make us stronger."[25]

Aftermath

The hack was described as "a Rosetta Stone to the far-right", allowing researchers and journalists to connect links between various far-right websites, groups, and individuals who were using Epik's services. DDoSecrets co-founder Emma Best said researchers had been describing the breach as "the Panama Papers of hate groups", and said that researchers would be "in for the long haul" with the amount of data that had been exposed. The Columbia Journalism Review similarly compared the data breach to the Panama Papers leak, stating "Like the Panama Papers, getting information out of the huge database and making sense of it is time-consuming, which may explain why coverage of the Epik hack lagged..."[26] Data from the hack was used to show that Ali Alexander, a far-right activist and key figure in the "Stop the Steal" conspiracy theory campaign, had worked to hide his connections to more than 100 websites after the 2021 United States Capitol attack.[27]

Reactions

Extremism researcher and computer scientist Megan Squire said of the hack, "It's massive. It may be the biggest domain-style leak I've seen and, as an extremism researcher, it's certainly the most interesting."[28] Internet anthropologist Gabriella Coleman predicted the hack would force far-right groups to find security providers outside of the United States, and said that the hack had "confirmed a lot of the details of the far-right ecosystem". Cybersecurity analyst and online extremism researcher Emily Crose said that the breach would likely intensify existing paranoia among far-right groups, who already felt like they were being surveilled after the Capitol attack.[29]

An engineer performing an initial impact assessment for an Epik client told The Daily Dot that "[Epik] are fully compromised end-to-end... Maybe the worst I've ever seen in my 20-year career". Following the hack, The Washington Post reported that "Epik's security protocols have been the target of ridicule among researchers, who've marveled at the site's apparent failure to take basic security precautions". Epik had been storing passwords using unsalted MD5, making them easy to crack. Other sensitive data, including credit card information, was being stored in plaintext.

David Vladeck, a Georgetown law professor and the former head of the Federal Trade Commission's (FTC) consumer protection bureau, said, "Given Epik's boasts about security, and the scope of its web hosting, I would think it would be an FTC target, especially if the company was warned but failed to take protective action".

The Seattle branch of the Federal Bureau of Investigation (FBI) told CNN that they could neither confirm nor deny the existence of an investigation into the Epik data breach.

Other breaches

Two weeks after the initial release of data, hackers released data taken from the American far-right Oath Keepers militia. The hackers responsible for the Oath Keepers leak did not claim any connection to Anonymous or draw any connection to the Epik breach, though some journalists have speculated that the leak may have been related or made possible by information from the Epik data.[30] The Oath Keepers data consists of about 3.8gigabytes of email archives, chat logs, and a membership list. The data is also being disseminated by DDoSecrets, though the group restricted the list of members and files containing donor and finance information to journalists. The Oath Keepers had been a customer of Epik's since January 2021, when their website was taken offline after their hosting provider terminated service in the wake of the Capitol attack.[31]

See also

Notes and References

  1. Web site: Whittaker. Zack. September 17, 2021. Web host Epik was warned of a critical security flaw weeks before it was hacked. September 17, 2021. TechCrunch. en-US.
  2. Web site: Thalen. Mikael. October 4, 2021. Anonymous releases data on Texas GOP in latest Epik hack dump. live. October 4, 2021. The Daily Dot. en-US. https://web.archive.org/web/20211004144602/https://www.dailydot.com/debug/anonymous-texas-gop-epik/ . 2021-10-04 .
  3. Web site: Allyn. Bobby. February 8, 2021. 'Lex Luthor Of The Internet': Meet The Man Keeping Far-Right Websites Alive. live. February 9, 2021. NPR. en. February 9, 2021. https://web.archive.org/web/20210209015232/https://www.npr.org/2021/02/08/965448572/meet-the-man-behind-epik-the-tech-firm-keeping-far-right-websites-alive.
  4. News: Sharwood. Simon. September 30, 2021. Anonymous: We've leaked disk images stolen from far-right-friendly web host Epik. The Register. October 1, 2021.
  5. Web site: Beran. Dale. August 11, 2020. The Return of Anonymous. live. September 22, 2021. The Atlantic. en. April 25, 2021. https://web.archive.org/web/20210425224146/https://www.theatlantic.com/technology/archive/2020/08/hacker-group-anonymous-returns/615058/.
  6. News: Gilbert. David. November 2, 2016. Is Anonymous over?. Vice. September 22, 2021. July 10, 2019. https://web.archive.org/web/20190710123828/https://news.vice.com/en_us/article/ywna4w/anonymous-declared-war-on-trump-and-then-disappeared. live.
  7. News: Griffin. Andrew. August 7, 2018. Anonymous promises to uncover the truth behind 'QAnon' conspiracy theory. The Independent. September 22, 2021. February 9, 2020. https://web.archive.org/web/20200209171047/https://www.independent.co.uk/life-style/gadgets-and-tech/news/anonymous-qanon-donald-trump-latest-truth-identity-hacking-a8481511.html. live.
  8. News: Griffin. Andrew. June 1, 2020. 'Anonymous' is back and is supporting the Black Lives Matter protests. The Independent. September 22, 2021. June 15, 2020. https://web.archive.org/web/20200615084905/https://www.independent.co.uk/life-style/gadgets-and-tech/news/anonymous-george-floyd-black-lives-matter-facebook-twitter-video-k-pop-a9542666.html. live.
  9. Web site: Molloy. David. Tidy. Joe. June 1, 2020. The return of the Anonymous hacker collective. live. September 22, 2021. BBC News. June 4, 2020. https://web.archive.org/web/20200604154827/https://www.bbc.com/news/technology-52879000.
  10. News: Kornfield. Meryl. September 6, 2021. A website for 'whistleblowers' to expose Texas abortion providers was taken down — again. The Washington Post. September 22, 2021. September 7, 2021. https://web.archive.org/web/20210907130836/https://www.washingtonpost.com/nation/2021/09/06/texas-abortion-ban-website/. live.
  11. Web site: Novell. Carly. September 11, 2021. Anonymous hacks Texas GOP website, floods it with memes. live. September 15, 2021. The Daily Dot. en-US. September 14, 2021. https://web.archive.org/web/20210914160644/https://www.dailydot.com/debug/anonymous-hacks-texas-gop-website-floods-it-with-memes/.
  12. Web site: September 15, 2021. Hackers steal 'decade's worth of data' from far-right webhost Epik. live. September 15, 2021. The Jerusalem Post. en-US. September 15, 2021. https://web.archive.org/web/20210915102500/https://www.jpost.com/diaspora/antisemitism/hackers-steal-decades-worth-of-data-from-far-right-webhost-epik-report-679573.
  13. Web site: Goforth. Claire. September 14, 2021. Anonymous to release massive data set of the far-right's preferred web hosting company. live. September 14, 2021. The Daily Dot. en-US. September 14, 2021. https://web.archive.org/web/20210914170758/https://www.dailydot.com/debug/anonymous-hack-far-right-web-host-epik/.
  14. Web site: Cimpanu. Catalin. September 15, 2021. Anonymous hacks and leaks data from domain registrar Epik. live. September 16, 2021. The Record by Recorded Future. en. September 16, 2021. https://web.archive.org/web/20210916033547/https://therecord.media/anonymous-hacks-and-leaks-data-from-domain-registrar-epik/.
  15. Web site: Ropek. Lucas. September 14, 2021. Anonymous Claims to Have Stolen Huge Trove of Data From Epik, the Right-Wing's Favorite Web Host. live. September 14, 2021. Gizmodo. en-us. September 14, 2021. https://web.archive.org/web/20210914220307/https://gizmodo.com/anonymous-claims-to-have-stolen-huge-trove-of-data-from-1847673935.
  16. Web site: Thalen. Mikael. September 16, 2021. 'Worst I've seen in 20 years': How the Epik hack reveals every secret the far-right tried to hide. live. September 16, 2021. The Daily Dot. en-US. September 16, 2021. https://web.archive.org/web/20210916140235/https://www.dailydot.com/debug/epik-hack-far-right-sites-anonymous/.
  17. News: Marks. Joseph. September 17, 2021. The battle for election security funding is back. en-US. The Washington Post. September 17, 2021. 0190-8286.
  18. News: Leloup. Damien. September 20, 2021. Epik, l'hébergeur Web favori de l'extrême droite américaine, victime d'un piratage d'ampleur. fr. Epik, the favorite webhost of the American far right, victim of major hack. Le Monde. https://ghostarchive.org/archive/W37ES?kreymer=false&url=https://www.lemonde.fr/pixels/article/2021/09/20/epik-l-hebergeur-web-favori-de-l-extreme-droite-americaine-victime-d-un-piratage-d-ampleur_6095330_4408996.html . 2021-09-25 . live . September 20, 2021.
  19. Web site: Sharma. Ax. September 20, 2021. Epik data breach impacts 15 million users, including non-customers. live. September 20, 2021. Ars Technica. en-us. September 20, 2021. https://web.archive.org/web/20210920131157/https://arstechnica.com/information-technology/2021/09/epik-data-breach-impacts-15-million-users-including-non-customers/.
  20. News: Harwell. Drew. Allam. Hannah. Hannah Allam. Merrill. Jeremy B.. Timberg. Craig. September 25, 2021. Fallout begins for far-right trolls who trusted Epik to keep their identities secret. en-US. The Washington Post. September 25, 2021. 0190-8286. September 25, 2021. https://web.archive.org/web/20210925145339/https://www.washingtonpost.com/technology/2021/09/25/epik-hack-fallout/. live.
  21. Web site: Thalen. Mikael. September 24, 2021. Epik hack reveals prominent, Trump-supporting websites under subpoena investigation. live. September 24, 2021. The Daily Dot. en-US. September 24, 2021. https://web.archive.org/web/20210924140421/https://www.dailydot.com/debug/epik-hack-subpoenas-data-preservation-leak/.
  22. Web site: Thalen. Mikael. September 29, 2021. New leak of Epik data exposes company's entire server. live. September 29, 2021. The Daily Dot. en-US. https://web.archive.org/web/20210929195917/https://www.dailydot.com/debug/anonymous-new-epik-leak/ . 2021-09-29 .
  23. Web site: Sharma. Ax. September 15, 2021. Anonymous leaks gigabytes of data from alt-right web host Epik. live. September 16, 2021. Ars Technica. en-us. September 15, 2021. https://web.archive.org/web/20210915230031/https://arstechnica.com/information-technology/2021/09/anonymous-leaks-gigabytes-of-data-from-epik-web-host-of-gab-and-parler/.
  24. Web site: Thalen. Mikael. September 17, 2021. Epik CEO's live video response to hacking incident descends into complete chaos. live. September 17, 2021. The Daily Dot. en-US. September 17, 2021. https://web.archive.org/web/20210917181755/https://www.dailydot.com/debug/epik-ceos-live-video-response-hacking-inciden/.
  25. Web site: 2021-12-09 . Epik is a refuge for the deplatformed far right. Here's why its CEO insists on doing it . 2023-07-15 . CNN . en.
  26. News: Ingram. Mathew. September 24, 2021. Leaked files from alt-right host raise some hard questions. Columbia Journalism Review. October 1, 2021.
  27. Web site: Thalen. Mikael. September 20, 2021. After the Capitol riot, 'Stop the Steal' organizer Ali Alexander was scrambling to hide his digital footprint. live. September 20, 2021. The Daily Dot. en-US. September 22, 2021. https://web.archive.org/web/20210922012447/https://www.dailydot.com/debug/ali-alexander-epik-hack-web-domains-capitol-riot/.
  28. News: Harwell. Drew. Timberg. Craig. Allam. Hannah. Hannah Allam. September 21, 2021. Huge hack reveals embarrassing details of who's behind Proud Boys and other far-right websites. en-US. The Washington Post. September 21, 2021. 0190-8286. September 23, 2021. https://web.archive.org/web/20210923020618/https://www.washingtonpost.com/technology/2021/09/21/epik-far-right-hack-anonymous/. live.
  29. Web site: Lyngaas. Sean. September 21, 2021. 'Anonymous' hackers claim to hit website hosting firm popular with Proud Boys. live. September 22, 2021. CNN. September 22, 2021. https://web.archive.org/web/20210922014036/https://www.cnn.com/2021/09/21/politics/anonymous-epik-hack/index.html.
  30. Web site: McKay. Tom. September 27, 2021. The Oath Keepers Reportedly Get Their Emails Dumped for the World to See. live. October 4, 2021. Gizmodo. en-us. https://web.archive.org/web/20210927201354/https://gizmodo.com/the-oath-keepers-reportedly-get-their-emails-dumped-for-1847753977 . 2021-09-27 .
  31. Web site: Hernandez. Salvador. January 13, 2021. A Major Militia Group Said Its Website Was Taken Down Days After It Sent Members To The Capitol Riots. live. October 4, 2021. BuzzFeed News. en. https://web.archive.org/web/20210113231950/https://www.buzzfeednews.com/article/salvadorhernandez/oath-keepers-website-epik-down . 2021-01-13 .