alert Epik Had A Major Breach

Spaceship Spaceship


Domains88.comTop Member
Last edited:
The views expressed on this page by users and staff are their own, not those of NamePros.
Does anyone think the Facebook .. Instagram and WhatsApp could be more possible hacking ???

so far as I know of .. Epik .. oath keepers .. are definite hacks with leaks .. I think there is 1 more as well ??
FB seems to think that it was their own modifications that broke everything.

CloudFlare has a good explanation of the effects:

Also, is it already clear where the hacked data was stored? I don't doubt it was stored on a server in the UK or Crimea, for example.

AWS was mentioned somewhere. Can't find the link right now.
FB seems to think that it was their own modifications that broke everything.

CloudFlare has a good explanation of the effects:


the reason I asked is the whistle blower on 60 minutes vs the outages happening less than 24 hours later .. coincidence and the unexplainable has become a feast since 2020 … or .. explainable but makes no sense to the contrary.

I remember when I first heard of Hackers .. it appeared more of strategy .. even perhaps a game of jail breaking code to experience the fall out. Some people say that some Hacking groups have been taken over by the CIA and the likes of .. that due to a great Hackers talent to retrieve intelligence Data from websites that are supposed to be Un Hackable … many theories and opinions have been circulating for years now regarding what a government does with these extremely talented hacker individuals once they are caught and a gov has them in custody … would it be far fetched to think a gov would ally with these individuals to do work for them ?? I would think it sounds very logical and practical for the Govs to use these individuals talents .. you have to have the best to defeat the best .. at any rate .. those theories and questions could only be answered by infamous hackers..

It seems Hacking has its own market as well .. it brings in billions if not trillions of dollars in revenue from the sale of coding ..the sale of data .. phone numbers .. softwares and apps .. the old but once very popular Firewall .. IT and internet security specialists .. all of these services derived from the day hacking became a name.. we all want a safe computer and safe websites .. right?? “HTTPS” protocol once sold for good $$$$s .. the price has gone down.. but these goods and services to detour Hacking is passed down to the average consumer buying these products to stay safe on the Net .. to protect your websites .. to protect yourself from identity theft … there’s a huge racket of billions of dollars that the consumer dishes out cash for identity monitoring.. enough is never enough because once you think you have everything safe .. bam .. out comes the next threat you must buy something for to protect your computer .. your website .. your identity .. so it’s a never ending game of shelling out cash for protection against hackers .. exploits ..

How much is enough??

as I have read .. it appears the Epik hack began as a exploit to gather data to expose certain people for their affiliations and so forth … in the end .. thousands of innocent people will have paid the price for the few .. as I doubt the numbers of the targeted will even make up 10% of the complete data dump .. to become a victim of circumstance is most usually construed as a victim heinous crime .. yes it happens as the world goes round .. innocent children and adults are shot by drive by shooters who are targeting a rival and ect … these crimes can not be justified under any circumstance .. not the lack of a innocent child playing outside wearing a bullet proof vest to survive a senseless drive by shooting .. the same applies with any Hack that affects thousands of innocent people .. bad security .. improper data storage .. there is no bad security and improper Data storage ..if someone doesn’t break into it and steal it ..

there is no justification to release millions of innocent non targeted peoples personal information and financials.. collateral damage must be imminent to achieve the objective ?? Tell that to the family who lost an innocent loved one to a drive by shooting .. a drunk driver .. a innocent person who lost their life in a convenient store because an armed robbery occurred while that person was there to by a energy drink..

Crimes are crimes .. when innocent people get caught up in crimes .. they become heinous crime ..
Last edited:
the reason I asked is the whistle blower on 60 minutes vs the outages happening less than 24 hours later .. coincidence and the unexplainable has become a feast since 2020 … or .. explainable but makes no sense to the contrary.

I remember when I first heard of Hackers .. it appeared more of strategy .. even perhaps a game of jail breaking code to experience the fall out. Some people say that some Hacking groups have been taken over by the CIA and the likes of .. that due to a great Hackers talent to retrieve intelligence Data from websites that are supposed to be Un Hackable … many theories and opinions have been circulating for years now regarding what a government does with these extremely talented hacker individuals once they are caught and a gov has them in custody … would it be far fetched to think a gov would ally with these individuals to do work for them ?? I would think it sounds very logical and practical for the Govs to use these individuals talents .. you have to have the best to defeat the best .. at any rate .. those theories and questions could only be answered by infamous hackers..

It seems Hacking has its own market as well .. it brings in billions if not trillions of dollars in revenue from the sale of coding ..the sale of data .. phone numbers .. softwares and apps .. the old but once very popular Firewall .. IT and internet security specialists .. all of these services derived from the day hacking became a name.. we all want a safe computer and safe websites .. right?? “HTTPS” protocol once sold for good $$$$s .. the price has gone down.. but these goods and services to detour Hacking is passed down to the average consumer buying these products to stay safe on the Net .. to protect your websites .. to protect yourself from identity theft … there’s a huge racket of billions of dollars that the consumer dishes out cash for identity monitoring.. enough is never enough because once you think you have everything safe .. bam .. out comes the next threat you must buy something for to protect your computer .. your website .. your identity .. so it’s a never ending game of shelling out cash for protection against hackers .. exploits ..

How much is enough??

as I have read .. it appears the Epik hack began as a exploit to gather data to expose certain people for their affiliations and so forth … in the end .. thousands of innocent people will have paid the price for the few .. as I doubt the numbers of the targeted will even make up 10% of the complete data dump .. to become a victim of circumstance is most usually construed as a victim heinous crime .. yes it happens as the world goes round .. innocent children and adults are shot by drive by shooters who are targeting a rival and ect … these crimes can not be justified under any circumstance .. not the lack of a innocent child playing outside wearing a bullet proof vest to survive a senseless drive by shooting .. the same applies with any Hack that affects thousands of innocent people .. bad security .. improper data storage .. there is no bad security and improper Data storage ..if someone doesn’t break into it and steal it ..

there is no justification to release millions of innocent non targeted peoples personal information and financials.. collateral damage must be imminent to achieve the objective ?? Tell that to the family who lost an innocent loved one to a drive by shooting .. a drunk driver .. a innocent person who lost their life in a convenient store because an armed robbery occurred while that person was there to by a energy drink..

Crimes are crimes .. when innocent people get caught up in crimes .. they become heinous crime ..

I don't agree with your logic:
Everyone caught up in the hack was innocent, except for all of Epik's pedo porn site owners. None of them, as far as I know, were breaking the law in US, where EPIK resides. None of them deserve to have their data stolen or be doxed. None of them deserve to go to prison for things they believe in their hearts, even if they live in an oppressive country, a terrible country with hate speech laws or a country with sharia type laws.

I don't agree with your analogies:
Imagine a school with a bunch of kids, the parents trust their kids with that school but the school has no one at the door checking adults who enter, any ol pervert can enter and rape a child. Of course the perverts are wrong, but there are always perverts in the world, it is the school's responsibility to protect those children from the perverts.
Last edited:
Same here. Cannot login even though I changed my password after the breach and it worked fine just after that.
I reset password and have no problem logging in - have been in and out a number of times last day doing various things. Hope customer service are able to sort it out for you.
Rob, October 4, 2021, at 2:45 AM EDT
Subject: Derek
Hi Paul,

For the record, I barely know Derek. I have very rarely interacted with him since 2018 when he tried very hard to convince me that Gab should be put down. I ultimately concluded differently in part I because I found his testimony to be questionable.

At this point, I have no idea why he is obsessed with me, nor DNPlaybook who seems to work from the same script. What is the purpose of letting these nonsense-spouters persist on NP?


Paul, October 4, 2021, at 8:50 AM EDT:
Derek was restricted for unprofessional behavior in that thread on September 29. The post was allowed to remain in the interest of transparency, but I made a public post at the time condemning it. After a conversation with Derek in which he expressed he would make an effort to improve, as well as a series of posts indicating he was able to keep the vague accusations at bay, the restriction was removed. I haven't personally reviewed most of the posts he made over the weekend.

To answer your question, it's difficult to guide people away from uninformed speculation and assumptions. When we outright delete content, there is a cost: people tend to double-down on their opinions, cry censorship, and refuse to take in new information that may conflict with their existing opinions. That isn't conducive to a healthy, open-minded discussion and just results in furthering hatred and division. That cost has to be weighed with the impact of keeping the post up but publicly explaining the faults in reasoning or why it's inappropriate for NamePros. If it's going to result in an immediate flame war, it may need to be removed despite that cost.

That being said, if an individual's posts are professional and don't violate our rules, they're probably not going to be removed or condemned even if they don't make much sense. Censorship doesn't really seem to work well when it comes to dispelling rumors.

Rob, October 4, 2021 at 9:06 PM EDT:
If you are comfortable with his contributions to that cesspool thread, so be it. So we have an understanding, the content is now all being backed up continuously.

From my periodic review of what is there, I am pretty sure it is a TOS violation:


The level of defamation in that thread that is being permitted is absurd.

I was just making sure that you were comfortable with the posts from someone who apparently has no other reason to be on NP other than to defame Epik and Rob Monster. It is no wonder that his startups all fail, but that’s a different matter!


Paul, October 5, 2021 at 8:11 AM EDT:
I am not comfortable at all with much of the content posted to that thread and do not endorse it. That does not mean it will be removed.

If you have specific, actionable objections to pieces of content, you may present them; thus far, however, you have not done that. Your objections have been vague and directed at individuals.
Last edited:
Perhaps Rob should spend more of his time policing the TOS violations of his own service, like Joey Camp's. Rob already acknowledged it was against Epik TOS, yet multiple sites remain, despite many abuse reports. Or that's okay because you think Camp's targets deserve it?

Since you're reading this thread, Rob, do you plan to acknowledge that you instructed Camp to dox me and my family? Was posting a photo of a young child in my family wearing a bathing suit at your instruction too or did Joey Camp just throw that in as a freebie? How about sending my dox and those of my family to individuals known to be violent? Defaming me as a drug addict? Threatening that he was sending people to enter my home?
Last edited:
I reset password and have no problem logging in - have been in and out a number of times last day doing various things. Hope customer service are able to sort it out for you.

I wrote to EPIK support to reset PW. No reply till date.😟
I wrote to EPIK support to reset PW. No reply till date.😟

If you use the 'forgot Password' option it should work.

Edit: mail could end up in your spam.
Last edited:
the reason I asked is the whistle blower on 60 minutes vs the outages happening less than 24 hours later .. coincidence and the unexplainable has become a feast since 2020 … or .. explainable but makes no sense to the contrary.
It is only natural to try to see if there were connections. This seems to have been a technical mistake by Facebook.

On the hacking side of things, I suppose it gives people a sense of participation in all this in that it fulfills a need to belong. This is why there are various pile-ons with various groups and they end up being more like supporters of Football teams or political parties.

There is no such thing as an unhackable system as every system is effectively a set of security compromises necessary to make the system work and interact. True hacking is the pursuit of knowledge and the search for alternative solutions to tricky problems. It has become something completely different over the years.

The Epik situation has encouraged a lot of speculation as to what happened and how it happened. What we don't have are the facts about what exactly happened.

The analysis, so far, comes from people looking at the leaked data so it is a bit like people looking at the latest Tesla car without knowing what design decisions led to various features. Epik has only made some vague statements and this is exactly what it should be doing. If you look at other companies that have suffered a databreach, they do much the same thing where they confirm the breach and then let the lawyers and PR people take over.

Reverse-engineering a product or software is a lot more difficult than designing it. It is necessary to understand what was being done and why it was being done. In the Epik case, it requires an understanding of the entire system and how it operated in the domain name industry. Things that are inuitively obvious to people with experience (domain names on sale, WHOIS records, parking IPs, sales platforms etc) may not be obvious to some of the people researching the leaked data. The scale of the data leaked may also be overwhelming.

The Maine official breach notification ( ) mentioned that 110,000 people were affected by the databreach. The facts will eventually trickle out but by then the media coverage will have switched to the next big story.

Rob, October 4, 2021, at 2:45 AM EDT
Subject: Derek
Hi Paul,

For the record, I barely know Derek. I have very rarely interacted with him since 2018 when he tried very hard to convince me that Gab should be put down. I ultimately concluded differently in part I because I found his testimony to be questionable.

At this point, I have no idea why he is obsessed with me, nor DNPlaybook who seems to work from the same script. What is the purpose of letting these nonsense-spouters persist on NP?


Paul, October 4, 2021, at 8:50 AM EDT:
Derek was restricted for unprofessional behavior in that thread on September 29. The post was allowed to remain in the interest of transparency, but I made a public post at the time condemning it. After a conversation with Derek in which he expressed he would make an effort to improve, as well as a series of posts indicating he was able to keep the vague accusations at bay, the restriction was removed. I haven't personally reviewed most of the posts he made over the weekend.

To answer your question, it's difficult to guide people away from uninformed speculation and assumptions. When we outright delete content, there is a cost: people tend to double-down on their opinions, cry censorship, and refuse to take in new information that may conflict with their existing opinions. That isn't conducive to a healthy, open-minded discussion and just results in furthering hatred and division. That cost has to be weighed with the impact of keeping the post up but publicly explaining the faults in reasoning or why it's inappropriate for NamePros. If it's going to result in an immediate flame war, it may need to be removed despite that cost.

That being said, if an individual's posts are professional and don't violate our rules, they're probably not going to be removed or condemned even if they don't make much sense. Censorship doesn't really seem to work well when it comes to dispelling rumors.

Rob, October 4, 2021 at 9:06 PM EDT:
If you are comfortable with his contributions to that cesspool thread, so be it. So we have an understanding, the content is now all being backed up continuously.

From my periodic review of what is there, I am pretty sure it is a TOS violation:

Show attachment 201217

The level of defamation in that thread that is being permitted is absurd.

I was just making sure that you were comfortable with the posts from someone who apparently has no other reason to be on NP other than to defame Epik and Rob Monster. It is no wonder that his startups all fail, but that’s a different matter!


Paul, October 5, 2021 at 8:11 AM EDT:
I am not comfortable at all with much of the content posted to that thread and do not endorse it. That does not mean it will be removed.

If you have specific, actionable objections to pieces of content, you may present them; thus far, however, you have not done that. Your objections have been vague and directed at individuals.

Number of letter's from Rob Monster to Paul complaining about NamePros - 2 (plus follow-ups)
Number of updates from Rob Monster / Epik about the actual data breach since then - 0

I suggest you focus your time and energy on the actual issue.

Perhaps Rob should spend more of his time policing the TOS violations of his own service, like Joey Camp's. Rob already acknowledged it was against Epik TOS, yet multiple sites remain, despite many abuse reports. Or that's okay because you think Camp's targets deserve it?

Since you're reading this thread, Rob, do you plan to acknowledge that you instructed Camp to dox me and my family? Was posting a photo of a young child in my family wearing a bathing suit at your instruction too or did Joey Camp just throw that in as a freebie? How about sending my dox and those of my family to individuals known to be violent? Defaming me as a drug addict? Threatening that he was sending people to enter my home?

My encouragement to you is to view your current actions and choices through an eternal lens. If souls are eternal...

I have to question if that behavior is best for Rob's "eternal soul". The above was the exact wording he used in the letter to Paul.

Last edited:
That being said, if an individual's posts are professional and don't violate our rules, they're probably not going to be removed or condemned even if they don't make much sense. Censorship doesn't really seem to work well when it comes to dispelling rumors

Isn't removing speech you don't like considered "cancel culture"? I don't use the term myself, because it seems when most people use the term it is really just to due with repercussions from them being a douche.

Rob, October 4, 2021 at 9:06 PM EDT:
I was just making sure that you were comfortable with the posts from someone who apparently has no other reason to be on NP other than to defame Epik and Rob Monster. It is no wonder that his startups all fail, but that’s a different matter!


Who refers to themselves in third person? :xf.laugh:
Last edited:
The Maine official breach notification ( ) mentioned that 110,000 people were affected by the databreach. The facts will eventually trickle out but by then the media coverage will have switched to the next big story.

Still waiting for the data breach notification by The Republican Party of Texas, to be filed in all states.

Last edited:
Isn't removing speech you don't like considered "cancel culture"? I don't use the term myself, because it seems when most people use the term it is really just to due with repercussions from them being a douche.
Rob's hypocrisy here proves one very important thing: All that "freeze peach warrior" talk he uses to defer responsibility for platforming Nazis and alt-righters is just that, talk. He platforms those views because he can't bear to see the dissemination of that reprehensible shit stopped for good.
Today I have received my 1st spam (Russian) as outcome of this leak...
To email address used only as my account email, I didn't share it publicly.
Last edited:
Rob's hypocrisy here proves one very important thing: All that "freeze peach warrior" talk he uses to defer responsibility for platforming Nazis and alt-righters is just that, talk. He platforms those views because he can't bear to see the dissemination of that reprehensible shit stopped for good.

Again, @Molly White (who posted above) was targeted by Epik for simply being a Wikipedia editor that they disagreed with.

It lead to harassment, threats, intimidation, and doxxing from parties connected to or supporters of Epik.

Joey Camp, also alleged that he was involved with Rob when it came to Molly White.

Last edited:
The Epik situation has encouraged a lot of speculation as to what happened and how it happened. What we don't have are the facts about what exactly happened.

We do have some facts such as things confirmed by Rob like, a hack did occur, the code was poorly written by Russian/Ukrainian dev team who kept the code captive, the code has not been updated since it was acquired. We also have facts reported by journalists such as what data was dumped by the hackers and class action investigation. There could be more.

But with Rob's reluctance to provide updates and information, we are left to speculate and ask questions. Which in turn frustrate Rob. As the second dump from the hack indicated, this could be a much worse situation. But left with no statements from E, that is only supposition.

Reverse-engineering a product or software is a lot more difficult than designing it. It is necessary to understand what was being done and why it was being done. In the Epik case, it requires an understanding of the entire system and how it operated in the domain name industry.

You don't really have to reverse engineer the source code if the source code is written on old compilers or languages with known vulnerabilities. A simple SQL injection can produce damage and reveal sensitive data.

Rob, October 4, 2021, at 2:45 AM EDT
Subject: Derek
Hi Paul,

For the record, I barely know Derek. I have very rarely interacted with him since 2018 when he tried very hard to convince me that Gab should be put down. I ultimately concluded differently in part I because I found his testimony to be questionable.

At this point, I have no idea why he is obsessed with me, nor DNPlaybook who seems to work from the same script. What is the purpose of letting these nonsense-spouters persist on NP?


Paul, October 4, 2021, at 8:50 AM EDT:
Derek was restricted for unprofessional behavior in that thread on September 29. The post was allowed to remain in the interest of transparency, but I made a public post at the time condemning it. After a conversation with Derek in which he expressed he would make an effort to improve, as well as a series of posts indicating he was able to keep the vague accusations at bay, the restriction was removed. I haven't personally reviewed most of the posts he made over the weekend.

To answer your question, it's difficult to guide people away from uninformed speculation and assumptions. When we outright delete content, there is a cost: people tend to double-down on their opinions, cry censorship, and refuse to take in new information that may conflict with their existing opinions. That isn't conducive to a healthy, open-minded discussion and just results in furthering hatred and division. That cost has to be weighed with the impact of keeping the post up but publicly explaining the faults in reasoning or why it's inappropriate for NamePros. If it's going to result in an immediate flame war, it may need to be removed despite that cost.

That being said, if an individual's posts are professional and don't violate our rules, they're probably not going to be removed or condemned even if they don't make much sense. Censorship doesn't really seem to work well when it comes to dispelling rumors.

Rob, October 4, 2021 at 9:06 PM EDT:
If you are comfortable with his contributions to that cesspool thread, so be it. So we have an understanding, the content is now all being backed up continuously.

From my periodic review of what is there, I am pretty sure it is a TOS violation:

Show attachment 201217

The level of defamation in that thread that is being permitted is absurd.

I was just making sure that you were comfortable with the posts from someone who apparently has no other reason to be on NP other than to defame Epik and Rob Monster. It is no wonder that his startups all fail, but that’s a different matter!


Paul, October 5, 2021 at 8:11 AM EDT:
I am not comfortable at all with much of the content posted to that thread and do not endorse it. That does not mean it will be removed.

If you have specific, actionable objections to pieces of content, you may present them; thus far, however, you have not done that. Your objections have been vague and directed at individuals.

Rob has specifically mentioned me in his letter to Paul. I have written some articles reporting about RM and E in the past during a different scandal or scandals. I opted not to write about this one since I do not want to give more oxygen to RM/E. Instead use this thread to contribute to and learn about the development of this story. I may end up doing a large piece eventually once all the facts are on the table. Rob has in the past reported my NP posts to take them down.
Last edited:
Reverse-engineering a product or software is a lot more difficult than designing it. It is necessary to understand what was being done and why it was being done.

It's worth noting that the fact that Rob had chosen to go with certain unorthodox teams and systems at the beginning could simply have been because of his personal ideologies and beliefs which might have prevented him from trusting the more mainstream options that were available to him at the time and some of those decisions are now affecting Epik today even though it now wants to project a more normal image.

As I have already mentioned on couple of occasions here the only good option at this point seems to be for Epik to rebrand as a whole new Registrar with a whole new name and to come up with a different kind of mindset, strategy, goal, and platform that can allow it to focus more on the business aspect of things.

Again, Molly White (who posted above) was targeted by Epik for simply being a Wikipedia editor that they disagreed with.

It lead to harassment, threats, intimidation, and doxxing from parties connected to or supporters of Epik.

Not to mention how Rob Monster admitted to hiring Joseph A Camp to do some "private investigation". The very same Joseph A Camp who has been doxxing and harassing journalists for daring to report on the Epik breach. A multitude of domains currently hosting Camp's doxxing website are still registered at Epik to this day, despite Rob Monster promising Steven Monacelli that he would take the site down while apologizing to Camp in the Jitsi meeting.



Screenshots from

$ whois yourdaddyjoey[.]org
Registry Domain ID: D402200000016131543-LROR
Registrar WHOIS Server:
Registrar URL:
Updated Date: 2021-10-04T23:12:02Z
Creation Date: 2021-03-01T00:09:24Z
Registry Expiry Date: 2022-03-01T00:09:24Z
Registrar Registration Expiration Date:
Registrar: Epik Inc.
Registrar IANA ID: 617
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4252025160
Domain Status: ok
Registrant Organization: Anonymize, Inc.
Registrant State/Province: WA
Registrant Country: US
We do have some facts such as things confirmed by Rob like, a hack did occur, the code was poorly written by Russian/Ukrainian dev team who kept the code captive, the code has not been updated since it was acquired. We also have facts reported by journalists such as what data was dumped by the hackers and class action investigation. There could be more.
No. We don't have the exact facts about what happened and how it happened. There have been no details released about the actual hack.

You don't really have to reverse engineer the source code if the source code is written on old compilers or languages with known vulnerabilities. A simple SQL injection can produce damage and reveal sensitive data.
Reverse-engineering a system a lot more complex than simply using an exploit to reveal some data. One doesn't reverse-engineer source code as much as try to understand it. With compiled software and the absence of source code, things become a bit more complex. With a system, it is necessary to understand what the software does, how it uses the data and what the system does. Each step is step away from simply grabbing some data with an SQL injection.

As I have already mentioned on couple of occasions here the only good option at this point seems to be for Epik to rebrand as a whole new Registrar with a whole new name and to come up with a different kind of mindset, strategy, goal, and platform that can allow it to focus more on the business aspect of things.

Well, that is not going to make the mountains of potential legal issues, liabilities, and bad PR go away.

You also have the practical issue that Epik = Rob Monster. A lot of the issues go far deeper than just the company name itself.

Reverse-engineering a system a lot more complex than simply using an exploit to reveal some data. One doesn't reverse-engineer source code as much as try to understand it. With compiled software and the absence of source code, things become a bit more complex. With a system, it is necessary to understand what the software does, how it uses the data and what the system does. Each step is step away from simply grabbing some data with an SQL injection.


Isn't it a bit embarrassing when you are basically at the mercy of your own development team, and the only way you can see your own code is after a massive data breach?

Last edited:
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.