Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Female Escort Review Site Data Breach Affects 470,000 Members

https://open.spotify.com/show/3Gmj15x6cGrgJEzmGnDTTj

Female Escort Review Site Data Breach Affects 470,000 Members

An online community promoting female escorts and reviews of their services has suffered a data breach after a hacker downloaded the site’s database.

EscortReviews.com is an adult online vBulletin forum community that allows US and Mexico-based escorts to promote their services, share profile pictures, contact information, and biographies to prospective clients. Clients can then post reviews about their experiences with the particular escort.

The site is very active with over 2.4 million topics, 12.5 million posts, and over 470,000 members.

EscortReviews.com member and post stats
EscortReviews.com member and post stats

Hackers posts stolen vBulletin database

This weekend a threat actor posted a link to a stolen vBulletin forum database for the EscortReviews.com website.

Leaked EscortReviews.com database
Leaked EscortReviews.com database

This database contains the registration information for over 472,695 members, including their display name, email address, MD5 hashed passwords, optional Skype account names, optional birthday, and IP address.

Also Read: Going Beyond DPO Meaning: Ever Heard of Outsourced DPO?

Database sample
Database sample

In a sample shared by cybersecurity intelligence firm Cyble, the most recent data is from September 2018.

BleepingComputer has reached out to some of the users listed in the database to confirm if the information belongs to them and is accurate. Only one member replied, who stated that the data is correct.

The site is currently displaying a vBulletin database error to visitors. It is unknown if the site is disabled due to the database’s posting or if the site was permanently shut down.

vBulletin error at EscortReviews.com
vBulletin error at EscortReviews.com

The last cached Google search page from the site is from January 21st, 2021.

The site ran vBulletin 3.8.9, which has known vulnerabilities that could allow attackers to breach the site. It is unknown if the forum was hacked using one of these vulnerabilities or if the site left an unsecured backup of the database online.

As the site uses MD5 hashed password, which can easily be cracked, it is strongly advised that members change their passwords at other sites using the same one.

Members of the EscortReviews.com site can also check if their information is part of the data breach using Cyble’s AmIBreached data breach notification services.

Also Read: Limiting Location Data Exposure: 8 Best Practices

Adult site data breaches can be devastating

Data breaches for adult sites, such as those promoting escort services or dating, can be devastating to members if their information is exposed publicly. 

This information can be used by threat actors to perform targeted blackmail or sextortion attacks, such as the attacks that occurred after the 2015 Ashley Madison data breach.

Even worse, there are known cases of data breaches leading to people committing suicide after information about their activities was posted online.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us