July 13th, 2024

Disney's Internal Slack Breached? NullBulge Leaks 1.1 TiB of Data

A hacktivist group, NullBulge, breached Disney's Slack system, leaking 1.1 TiB of data to protect artists' rights. The group's origins are unknown, possibly linked to the LockBit ransomware gang. Disney faces criticism for not compensating artists fairly. Recent breaches at AT&T and Ticketmaster highlight cybersecurity challenges.

Read original articleLink Icon
Disney's Internal Slack Breached? NullBulge Leaks 1.1 TiB of Data

A hacktivist group called NullBulge claims to have breached Disney's internal Slack system, leaking 1.1 TiB of data, including messages, files, and code. The group aims to protect artists' rights and fair compensation. The breach, posted on Breach Forums, allegedly contains extensive information from Disney's development team. NullBulge announced the hack on X (formerly Twitter), offering a glimpse behind Disney's doors. The group's origins are unknown, but rumors suggest a link to the LockBit ransomware gang. Disney has faced criticism for not paying royalties to artists and writers, with ongoing issues highlighted by figures like Neil Gaiman and Alan Dean Foster. Despite settlements, many creators struggle for fair compensation. The hack is part of a series affecting U.S. companies, with recent breaches at AT&T and Ticketmaster. AT&T reported hackers stole call and text records for nearly all customers, while Ticketmaster faced leaks of 10 million ticket barcodes. The situation underscores ongoing cybersecurity challenges for organizations.

Related

Snowflake breach snowballs as more victims, perps, come forward

Snowflake breach snowballs as more victims, perps, come forward

The Snowflake data breach expands to include Ticketek, Ticketmaster, and Advance Auto Parts. ShinyHunters claim involvement, Snowflake enforces security measures. CDK faces ransomware attack, Juniper and Apple vulnerabilities identified. Jetflicks operators convicted.

Ticketmaster has begun warning customers about data breach

Ticketmaster has begun warning customers about data breach

Ticketmaster notifies customers of a data breach involving personal information theft. 1.3 terabytes of data were compromised and sold on the dark web. Snowflake denies involvement. Ticketmaster enhances security measures.

Microsoft Alerts More Customers to Email Theft in Expanding

Microsoft Alerts More Customers to Email Theft in Expanding

Microsoft alerts more customers about email theft post-Midnight Blizzard hack by Russian government. Stolen emails accessed, shared with affected organizations for transparency. Ongoing attack used for planning further attacks. Assistance provided to mitigate risks.

Ransomware Gang Leaks Data Allegedly Stolen from Florida Department of Health

Ransomware Gang Leaks Data Allegedly Stolen from Florida Department of Health

The Ransomhub ransomware gang leaked over 100GB of data from the Florida Department of Health due to missed ransom payment. Sensitive information was exposed, impacting services. Florida DOH confirmed the cyber incident.

AT&T says criminals stole phone records of 'nearly all' customers in data breach

AT&T says criminals stole phone records of 'nearly all' customers in data breach

AT&T confirms a data breach affecting 110 million customers, involving phone records and location data from 2022-2023. Collaboration with authorities led to one arrest. Snowflake's breach impacted other companies, stressing the need for enhanced security measures.

Link Icon 26 comments
By @SoftTalker - 4 months
Again highlighting the unrecognized liability companies are taking on by logging every scrap of internal communication, no matter how informal or ill-conceived it may be.
By @1231232131231 - 4 months
I wonder why there are so few articles considering this happened last night. Also, it's sad how the "insider" (who probably was hacked/RATed) had his SSN and other info leaked :/
By @az226 - 4 months
This is going to be a anti-DEI treasure trove. The unsaid things will be shown to have very much been said.
By @shrubble - 4 months
Considering the social and political controversies that Disney is unvolved in, I would expect a lot of scrutiny of the contents of this link.
By @KomoD - 4 months
This is the same group that put malware in ComfyUI_LLMVISION and said they were against crypto but then extorted people for crypto.

(ComfyUI_LLMVISION is probably what caused this breach)

By @hd4 - 4 months
Anecdotally it feels like there has been an uptick in these high-profile hacks recently, maybe a result of more security people being laid off as a result of companies thinking they would replace everyone with AI?
By @486sx33 - 4 months
Seems like slack has a problem

Maybe a dumping tool that uses a stolen api key? Rate limiting and monitoring on slack’s part could help…

By @lopkeny12ko - 4 months
I don't understand the situation with the insider (Matthew J Van Andel). Is the implication that he was originally collaborating with the hackers to give them access, then regretted doing so and decided to cut off their access, and the hackers retaliated by doxxing him?
By @karaterobot - 4 months
They should learn opsec from the Disney Vault.
By @christkv - 4 months
Disney seems to be just shooting themselves in the foot over and over again recently.

It will be interesting to see what happens here. Information that leaks could actually impact share price.

By @pylua - 4 months
Is it even legal to view that data ?
By @matrix12 - 4 months
By @v3ss0n - 4 months
Thats for Ruining MCU!
By @indus - 4 months
Dark side of API-based access to everything on SaaS where companies have no control.

I can’t guard the front door effectively.

Nor, I can easily guard the back doors.

Will data breaches like these: AT&T, Ticketmaster, and now Disney—-a nail in Security coffins for SaaS?

By @drexlspivey - 4 months
I’d like to know if that’s really how Kathleen Kennedy eats her Linguini.
By @slowhadoken - 4 months
The spin from Disney is going to be entertaining.
By @ziofill - 4 months
It's clear that 1Tb is a lot of data, but I would have expected more from Disney's slack?
By @roxy9006 - 4 months
Any news on the contents in terms of unreleased films?
By @90210 - 4 months
where can i actually read it
By @postepowanieadm - 4 months
> leaked 1.1 TiB (1.2 TB)

I don't know why but I find this funny.

By @johndhi - 4 months
Can someone explain why hackers dump the files publicly rather than just tell the victim they got access? What's the point?
By @egypturnash - 4 months
I can’t stop giggling at this group’s name.