TweakTown NewsRefine News by Category:
Avid Life Media is still trying to deal with a major PR disaster after The Impact Team breached Ashley Madison, and the company has offered up a $500,000 CAD ($377,000) bounty.
"You know The Impact Team has crossed the line," said Bryce Evans, acting staff superintendent of the Toronto Police, during a Monday morning press conference. "This hack is one of the largest data breaches in the world. The social impact behind this leak, we're talking about families, we're talking about children, we're talking about wives, we're talking about their male partners. It's going to have impacts on their lives... this is affecting all of us."
Evans also asked for the hacking community to "do the right thing" and help Avid Life Media and the police identify the hackers. Even if members of The Impact Team are identified, however, trying to bring them to justice could be extremely difficult - depending where they are located in the world.
After the Ashley Madison data dump, which featured more than 33 million accounts, it was no surprise that the fallout would ensnare plenty of people that would need to explain themselves. One political leader already claimed he used the site for "opposition research," and now Florida State Attorney Jeff Ashton publicly apologized after his name was discovered on Ashley Madison.
Ashton described his decision to sign up for Ashley Madison as a "bad, childish, stupid error" and he "did not commit a crime" by using the site. Ashton claims he typically logged in using a personal laptop and through public Wi-Fi networks. He reportedly didn't meet anyone via the site, and didn't have an affair.
"While I indulged my curiosity about the site it never went beyond that," Ashton said during a press conference. "These were incredibly stupid choices." In addition, Ashton won't step down and plans to return back to work: "I think I've humiliated myself enough for one weekend. Tomorrow morning I go back to work."
Avid Life Media and Avid Dating Life are not going to have a fun time following the fallout of Ashley Madison's data being publicly dumped to the Internet. Thousands of Canadians had their privacy violated following the breach, which included personal names, email addresses, home addresses, and message history - and the lawsuits are going to roll in.
Charney Lawyers and Sutts, Strosberg LLP filed a $578 million class-action lawsuit on behalf of Ashley Madison members located in Canada. The lawyers won't try to include the Impact Team in the class-action lawsuit, as seeking damages from a foreign-based hacker group would be difficult.
"Numerous former users of AshleyMadison.com have approached the law firms to inquire about their privacy rights under Canadian law," the law firms said. "They are outraged that AshleyMadison.com failed to protect its users' information. In many cases, the users paid an additional fee for the website to remove all of their user data, only to discover that the information was left intact and exposed."
Louisiana GOP Executive Director Jason Dore confirmed his name was one of millions exposed in the Ashley Madison data dump.
The Republican Party statewide director used his full name and former personal credit card billing address, but claims he was doing a bit of research for his Doré Jeansonne law firm:
"As the state's leading opposition research firm, our law office routinely searches public records, online databases and websites of all types to provide clients with comprehensive reports," Doré told The Times-Picayune. "Our utilization of this site was for standard opposition research. Unfortunately, it ended up being a waste of money and time."
DARPA wants to help develop new solutions to defend against distributed denial of service (DDoS) attacks, with foreign cybercriminals launching large volumes of attacks against US military and government targets.
The Extreme DDoS Defense (XD3) aims to provide a DDoS countermeasure system that is able to identify incoming attacks, and help defend networks. Depending on the attack sophistication, DARPA wants to have a response time of 10 seconds or less - a difficult challenge, but an important one that could be used in the private sector and by the government/military.
"In general, the program aims to thwart DDoS attacks by dispersing cyber assets (physically and/or logically), disguising the characteristics and behaviors of those assets, and mitigating the attacks (especially low-volume attacks) that still penetrate the targeted environment," according to the DARPA Broad Agency announcement, asking for applicants.
Well, it didn't take long before the scam artists and extortionists started taking advantage of the recent Ashley Madison data dump. People with email addresses exposed are receiving shady looking emails that demand payment in exchange for secrecy so their spouses and partners aren't informed.
Here is one email that was shared with Brian Krebs from Krebs on Security:
Unfortunately, your data was leaked in the recent hacking of Ashley Madison and I now have your information..."
Avid Life Media has gone on the offensive following the Ashley Madison data dump, sending takedown notices to social networking websites and file-sharing services.
Stolen data includes data of up to 33 million users, and while removing data from Twitter, Facebook, Reddit, and other sites has been successful, it's going to be nearly impossible to scrub the data dump from the Internet.
The data is out there, and there are plenty of links to anyone looking for a searchable database - yielding everything from names, usernames, email addresses, and sexual preferences - as Avid Life Media tries a desperate effort to fix its PR disaster.
It looks like spouses are calling divorce lawyers after finding potentially unfaithful partners listed as members of Ashley Madison.
A report published by The Times indicates relationship counseling services and divorce lawyers have seen an uptick in phone calls and correspondence from angry spouses. After 33 million members were exposed, it's likely a similar trend is likely to happen in the United States and elsewhere in the world - as more people search the database.
The data dump has created "lots of difficult emotions" for partners finding spouses in the Ashley Madison data dump, said Denise Knowles, a counselor at Relate counseling service, told The Times.
Avid Life Media has suffered a major PR disaster after hackers were able to spend a lengthy amount of time stealing data from the Ashley Madison website. The Impact Team hacker group, reportedly made up of "very" experienced hackers, has collected information from Ashley Madison "over the past few years."
"Bad. Nobody was watching," The Impact Team told Motherboard, when asked about security protocols. "No security. Only thing was segmented network. You could use Pass1234 from the Internet to VPN to root on all servers."
The group also has plenty of other information taken from Avid Life Media, including "300GB of employee emails and docs from internal network. Tens of thousands of Ashley Madison user pictures. Some Ashley Madison user chats and messages. 1/3 of pictures are dick pictures and we won't dump. Not dumping most employee emails either. Maybe other executives."
The feds might have successfully shuttered Silk Road, and locked away the site's founder, but there are plenty of other drug marketplaces available on the dark web. The underground marketplace is absolutely booming, with more than $100 million worth of drugs and other illegal substances sold each year, according to researchers from Carnegie Mellon University researchers.
Even after Silk Road 2 was also busted, the success from both sites revealed the huge business potential. Total sales volume ranges from $100 million to $180 million per year in sales volume, according to CMU computer professor Nicolas Christin.
Researchers found 70 percent of drug dealers sold less than $1,000, with only two percent racking up more than $100,000 in illicit sales. To make things difficult for federal agents and law enforcement, operators of these sites are embracing encryption and other tools to try to stay anonymous online.