AUTO-UPDATED

Elite network says it was hacked after members’ personal data was left exposed

The exclusive networking group Dialog, founded by Peter Thiel, exposed the private data of hundreds of high-profile members due to a significant security misconfiguration on its event website.

Key Points

  • Exposed data included dates of birth, cell phone numbers, emergency contacts, and internal rankings for approximately 200 influential members.
  • Affected individuals include a sitting NATO commander, the US Treasury Secretary, a White House intelligence official, and executives from major AI firms.
  • The breach occurred because a public signup page for an event app lacked password protection, allowing browser developer tools to access sensitive backend files.
  • Dialog attributed the incident to a criminal hack, though reports indicate the data was accessible simply by visiting a misconfigured web page.
  • The forms were built using the platform Fillout, which stated that customers are responsible for configuring their own data security and workflows.

Why it Matters

This incident highlights the growing risk of security misconfigurations, which now rank as the second-leading application security threat globally. By mislabeling simple data exposure as a sophisticated hack, organizations may discourage researchers from reporting vulnerabilities, ultimately leaving sensitive user information exposed for longer periods.
Malwarebytes.com Published by Danny Bradbury
Read original