New Ashley Madison hack data dump includes internal emails, source code
The hackers behind the hacking of extra-marital affairs site Ashley Madison struck again Thursday dumping a new release of 19GB of data.
Serial cheaters may not have a huge amount to fear from the new release however, with the dump including a 13GB file named noel.biderman.mail.7z, suggesting that it contains e-mail from Noel Biderman, the Chief Executive Officer of Avid Life Media, Inc., the parent company of Ashley Madison.
Ars Technica reports that file can’t be unpacked because it is inexplicably corrupted, noting that security researchers are suggesting that it could be intentionally fake.
A note with the data dump though is inexplicably clear, with The Impact Team (the individual or group behind the hack) stating simply “Hey Noel, you can admit it’s real now?”, a reference to attempts by Biderman and others to cast doubt as to whether the earlier release of hacked Ashley Madison data was legitimate.
Also included in the dump was the full source code to the Ashley Madison site, potentially allowing other hacking groups to find new ways to hack the site.
As security firm Trustsec explained in a blog post:
Interesting enough—if this turns out to be legitimate which it in all aspects appears to be—having full source code to these websites means that other hacker groups now have the ability to find new flaws in Avid Life’s websites, and further compromise them more.
If there was any question to the validity of the data before – those should be removed now.
The spin stops here
Despite various attempts to deny that the data released previously in the hack is legitimate, worldwide media attention, including in some cases details of individual users being published, has proven that no matter how much Avid Life Media wants to spin it, the dump is real and the cat, having being released from the bag, is unable to be returned.
What isn’t being discussed publicly though is some of the activities Avid Life Media is undertaking to try to push a line that the data is fake.
In a comment on KrebsonSecurity, the site that broke the hacking news initially, one commenter notes that there are fake copies of the dump being circulated, suggesting perhaps that the folks behind Ashley Madison themselves are putting out “false flag” files in an attempt to muddy the waters.
“I downloaded yesterday -2- different sets of data. Both had the same file naming and the file sizes were comparable”, user Applestar wrote, before adding “while one of the data sets was full of fake data the other one was the real data.”
“For me the reason is clear: someone.. is desperately trying to tell the world the data spreading is ‘fake’ or at least ‘mixed’ and ‘inaccurate’…I guess they want to add some confusion so that mainstream media does not now what to write. And it might help some poor guys being caught with their credentials on the real files.”
With the new data dump expect more spin and lies from Avid Life Media as the people running the company desperately try in vain to save their reputations and business.
Update: check here for details on how to search the Ashley Madison hacked/leaked database online.
Image credit: Trusted Security.
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.