Unstoppable Domains โ€” AI Assistant

alert Epik Had A Major Breach

SpaceshipSpaceship
Watch

DaveX

@GoDaveXTop Member
Impact
52,011
Last edited:
36
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
The hackers confirm this as part of the leak:
  • Domain purchases
  • Domain transfers
  • WHOIS history
  • DNS changes
  • Email forwards, catch-alls, etc.
  • Payment history
  • Account credentials
  • Over 500,000 private keys
  • An employee's mailbox
  • Git repositories
  • /home/ and /root/ directories of a core system

private keys of what? epik doesnt store crypto keys
 
3
•••
4
•••
Last edited:
11
•••
The entire DB leak is the only one, and it is Epik.
 
2
•••
Last edited:
3
•••
Wow I have been out of the loop on this, just caught up to the last post.

This is the type of attack the left loves to see, as you can witness from the relentless commentary of those on the left everywhere, their foundation of hatred is shown when one of their adversaries suffers a loss of any kind. The left wants total control of speech in a hegemonic way, and if you think Epik getting attacked like this is good, you are likely an authoritarian that belongs to that group of individuals. Liberty ends when speech is controlled, that's why we must fight with everything we have to ensure companies like Epik survive. Domains are the last frontier for our liberty worldwide, no doubt they will be attacked relentlessly.

The good thing is this, domains are a strong frontier. These tools are way stronger than any social media handle individually, and that's what we have to remember when we see a whole registrar come under attack in a coordinated effort. This is a WAR and the losers always play dirty.

As far as Auth codes go, you can just lock your domains and the auth codes won't matter. You can also have the domains "super locked" to prevent fast transfers inside your account, should you need that extra layer of security. Although I haven't been at Epik since the beginning of July, I don't see how this breach will affect domain names at all. It sounds like the person who wrote the description of the breach has little knowledge of how domain names truly operate.

The Epik tech team is highly skilled and competent, worked together with them for almost 2 years and I can say they are incredible human beings from the work they do every day. The only thing this attack will yield is a higher level of competence for that team, I have no doubt about it. I say that as a non-employee customer.

Stop politicizing criminal activity. Thats what got Epik into trouble to begin with. Leave religion and politics out of our businesses.
 
12
•••
2
•••
nearly? how does nearly stolen count for anything?

I dunno man. Just reporting as it might indicate your funds @epik are not safe.
 
4
•••
I canceled a card that was stored on Epik previously as a safety measure since we arenโ€™t getting details on the extent and likely never will.

This is why the dismissal by PP was so annoying. I donโ€™t like to store my credit cards anywhere else. How is Epik going to ensure going forward that our payment methods and our domains are safe is what I want to know.
 
Last edited:
13
•••
we arenโ€™t getting details on the extent and likely never will.

This is what bothers me most. By now they should have been able to assess some of the data and give an update.
 
6
•••
I canceled a card that was stored on Epik previously
If the issuing bank also has an opportunity to add the card to "stop list" - ask them to. Stop List is an extra security feature, which, unfortunately, is not used frequently. This is to avoid offline/delayed authorizations and the like (still possible)
 
4
•••
If the issuing bank also has an opportunity to add the card to "stop list" - ask them to. Stop List is an extra security feature, which, unfortunately, is not used frequently. This is to avoid offline/delayed authorizations and the like (still possible)

This is a good idea for sure. I see people talking about having extracted card + cvv numbers from the database. Again, can't verify but better to be safe.
 
3
•••
@Rob Monster
And remove all 3rd-party integrations/holes like amateur Estibot.
 
4
•••
I have a feeling this may be an internal hack from the employee(s) as Epik used to go to Forums like Namepros and hired them cheap. Someone here posted Epik has 37 members here worked for them.
Cutting the corner by hiring cheap employees is not good business along with other inadequate security measures like store data in plain text.
Another important thing is they never tell the customers (and they may never will) what are the damages and nor they tell the customers what should they do in this situation.
Leave the customers in the wonderland and let them find out what is going on is not good.
 
10
•••
And remove all 3rd-party integrations/holes like amateur Estibot.
Indeed. They are in data analytics business. In this business, everything is under radar. They sell "appraisals", but, actually, such companies should instead PAY for data they receive and analyze.
Swiss bank of domains should not have such a blackhole.
 
Last edited:
6
•••
This is what bothers me most. By now they should have been able to assess some of the data and give an update.

I canceled a card that was stored on Epik previously as a safety measure since we arenโ€™t getting details on the extent and likely never will.

This story has started to gain even more traction on popular websites like -

https://www.motherjones.com/politics/2021/09/epik-hack-anonymous-gab-parler/

https://arstechnica.com/information...of-data-from-epik-web-host-of-gab-and-parler/

https://www.dailydot.com/debug/epik-hack-far-right-sites-anonymous/

https://www.techtimes.com/articles/265416/20210915/anonymous-hackers-leak-epiks-databaseโ€”experts-confirm-gigabytes-data-obtained-8chan.htm

https://gizmodo.com/anonymous-claims-to-have-stolen-huge-trove-of-data-from-1847673935

Not much has come from Epik, and the few statements certainly do not seem to acknowledge the seriousness of the situation IMO.

Lots of deflection about politics from Epik connected parties. No one cares.

Epik is responsible for protecting their customer's data. Any excuse outside just taking responsibility is deflection.

The customers want to know -

What actually happened?
How did it happen?
What data have the hackers taken?
What they need to do?
What is going to stop it from happening again?

The ball is in Epik's court to answer those questions.

Brad
 
Last edited:
14
•••
Per this article -

https://arstechnica.com/information...of-data-from-epik-web-host-of-gab-and-parler/

"We are not aware of any breach. We take the security of our clients' data extremely seriously, and we are investigating the allegation," an Epik representative told Ars.

Hackers alter Epikโ€™s knowledge base to mock companyโ€™s response

Anonymous also tampered with Epik's knowledge base to mock the company's denial of the breach.

"On September 13, 2021, a group of kids calling themselves 'Anonymous', whom weโ€™ve never heard of, said they manage[d] to get a hold of, well, honestly, all our data, and then released it," said the altered knowledge base, as seen in an archived copy. "They claim it included all the user data. All of it. All usernames, passwords, e-mails, support queries, breaching all anonymization service we have. Of course itโ€™s not true. Weโ€™re not so stupid we'd allow that to happen."


Screenshot-2021-09-15-at-10.22.20-640x620.png

 
Last edited:
4
•••
This is obviously very worrying news.

It's also a bit disappointing that Epik hasn't updated their customers as to what exactly is going on.

An important question now which hopefully can be answered by the senior members of this forum would be, what should Epik customers do now?

Should they stop using Epik and get all there domains out of there after this event?
 
3
•••
You already know: where Moniker is now...
And their case was easier many times.
 
Last edited:
1
•••
Epik - why not to try to arrange something like this? Would be better:

vmc.jpg
 
Last edited:
1
•••
Dynadot โ€” .com TransferDynadot โ€” .com Transfer
Spaceship
Domain Recover
CatchDoms
DomainEasy โ€” Zero Commission
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back