迪士尼的内部松弛被打破? NullBulge 泄漏 1.1 TiB 数据
Disney's Internal Slack Breached? NullBulge Leaks 1.1 TiB of Data

原始链接: https://hackread.com/disneys-internal-slack-breached-nullbulge-leak-data/

2024 年 7 月 12 日,黑客组织“NullBulge”声称对入侵迪士尼 Slack 系统负责,泄露了约 1 TB (1.1 TB) 敏感数据。 泄露的信息包括迪士尼开发团队的消息、文件和潜在的机密项目细节。 据黑客称,这个海量数据转储包含大约 10,000 个频道、大量未发布的项目、源代码、登录凭据以及内部 API 或网页的链接。 NullBulge 最初通过社交媒体平台宣布了此次黑客攻击,似乎与艺术家的倡导保持一致,声称他们希望揭露涉及创意补偿的不公平做法。 尽管这种联系仍是推测性的,但有传言指出 NullBulge 与著名勒索软件组织 LockBit 之间存在联系。 此前的报道显示,迪士尼在向创作《星球大战》和《异形》等利润丰厚的知识产权的作家和艺术家公平分配利润方面遇到了争议。 迪士尼目前正在对所报告的黑客事件的真实性和范围进行调查。 此外,该事件发生在一系列针对美国企业的重大数据泄露事件之后。 最近,电信巨头 AT&T 遭遇数据泄露,超过 1.1 亿用户的几乎所有客户通话记录和短信日志被泄露,而现场娱乐活动组织者 Ticketmaster 遭遇黑客攻击,导致与顶级名人音乐会活动相关的票务条形码泄露。 正在进行的调查将澄清针对迪士尼的指控的范围和有效性。

当跨国公司处理大量数据时,将敏感信息转移到异地存储,同时保持可访问性变得至关重要。 为了实现这一目标,企业部署云服务作为主存储,并为不常访问的数据部署归档服务。 冷存储是指长期档案解决方案,例如远程存储磁带,可降低成本,同时确保法规遵从性。 然而,检索冷存储数据需要将其加载回活动应用程序,这可能会导致延迟,并由于与文档相关的元数据丢失而影响员工的工作效率。 企业不是开发定制应用程序来保留原始数据并通过冷存储进行搜索,而是应用机器学习技术使用人工智能来索引和管理数据。 这样可以更快、更轻松地恢复所需记录,而不会影响安全性或准确性。 此外,通过离线存储非业务关键数据,组织可以减少总体攻击面,从而最大限度地减少与网络安全威胁相关的风险。
相关文章

原文

Hacktivist group NullBulge claims to have breached Disney, leaking 1.1 TiB of internal Slack data. The leak allegedly includes messages, files, code, and more. This comes amidst breaches affecting AT&T and Ticketmaster.

A self-proclaimed hacktivist group named NullBulge, aiming to “protect artists’ rights and ensure fair compensation for their work,” claims to have breached Disney and leaked 1.1 TiB (1.2 TB) of the company’s internal Slack infrastructure. These claims were posted on the notorious cybercrime and hacker platform Breach Forums on July 12, 2024.

The breach, which is yet to be verified, allegedly contains a complete copy of the company’s Slack communications used by their development team including messages, files, and other data exchanged within the Slack workspace.

The hackers further claim the dump includes “almost 10,000 channels, every message and file possible, unreleased projects, raw images, code, logins, links to internal API/web pages, and more!”

NullBulge also used X (formerly Twitter) to announce the alleged hack, stating, “Disney has had their entire dev Slack dumped. 1.1 TiB of files and chat messages. Anything we could get our hands on, we downloaded and packaged up. Want to see what goes on behind the doors? Go grab it.”

NullBulge Group: Who, Why, and How

The origins of the NullBulge Group are unknown. However, their official website claims the group aims to protect artists’ rights and ensure fair compensation for their work. Rumours suggest that NullBulge might be linked to the LockBit ransomware gang, as they appear to be using LockBit’s leaked builder.

As for Disney, in recent years, the company has faced criticism and legal issues regarding the payment of fair shares to artists and writers. Prominent figures like Neil Gaiman have highlighted that Disney has stopped paying royalties to some writers and artists for works that include novelizations and graphic novels of Disney-owned properties. This issue affected various creators who worked on popular franchises such as “Star Wars” and “Alien.

The problem came into the spotlight when author Alan Dean Foster publicly stated that he had not received royalties for his “Star Wars” and “Alien” novels after Disney acquired the respective franchises.

Despite some high-profile settlements, many writers and artists continue to struggle to get their due payments. Organizations like the Science Fiction & Fantasy Writers of America (SFWA) have been actively campaigning for these creators, forming task forces to pressure Disney into fulfilling its financial obligations​.

Hackread.com has reached out to Disney for comment. Meanwhile, VX-Underground, an online malware repository, tweeted that if proven legitimate, the hack could be the work of infostealer malware.

Nevertheless, the alleged data breach is just another in a series affecting companies based in the United States. On July 12, 2024, AT&T announced that hackers had stolen call records and text message logs of “nearly all” customers, impacting over 110 million Americans.

Meanwhile, the Ticketmaster data breach continues to cause headaches for Live Nation as hackers leaked 10 million ticketing barcodes related to top celebrities’ concerts. The hackers are demanding an $8 million ransom to stop future leaks.

Stay tuned as Disney is investigating the breach!

  1. Disney+ accounts being sold on dark web marketplaces
  2. Security and Entertainment Essentials Amid Rising Digital Risks
  3. LEGO Market BrickLink Hacked; Site Down Amid Unusual Activity
  4. Nickelodeon Data Leak Labeled ‘Old’: Interview with @GhostyTongue
  5. Soap2day Shuts Down Permanently – Free Legal and Paid Alternatives
联系我们 contact @ memedata.com