News Update – The Return of Miss Madison
TL;DRThe 2015 Ashley Madison hack exposed 32M users' data; scammers are now using the leaked, cracked passwords to send targeted Bitcoin sextortion emails, passively validating threats by citing victims' real (old) passwords.
Jordan and Scott discuss what happens when old leaked passwords claw their way back from the grave.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: It's 2015 and the world is such a simple place. Just not for the users of a small dating site called Ashley Madison. Back in 2015, a group of hackers calling themselves Impact Team posts a link to a torrent on the dark web. With 10 gigs worth of leaked data concerning 32,000,000 users, the extramarital affair site Ashley Madison. The data dump included the real world names of users, their passwords, addresses, and phone numbers, nearly a decade's worth of credit card information and payment transaction details, and descriptions of what members were looking for on the affair site. This was a full blown, nothing left on the table data breach of a dating site. The story immediately popped off. Reams of media coverage, internet vigilantes combing through the data for high profile individuals to target in public humiliation campaigns, a dedicated search engine to peruse the leak. And most importantly, for the purposes of this story, the leak sparked a wave of sextortion scams around the world. Pay me a thousand bucks in Bitcoin, or I share this very sensitive information. Because if I have this, imagine what else I have. To be in that batch of leaked data was to be a bug hiding under a fridge. Suddenly, the fridge is gone, the lights are on, and you have nowhere to scurry. For some, you could shrug it off. For others, it was a manageable embarrassment. But for some, it was cataclysmic. Marriages ended, reputations bruised if not broken. It's hard to put an exact number, but I found at least five suicides linked to the leak. And then, the T Mobile hack happens in September. The secure is breached in November, another hack, another day. The world moves on. Until this last week, when my co host, Scott, got a message from a friend about a very strange email he got from some hackers. It seemed to know a lot about him. This is the return of Ashley Madison, sextortion scams and zombie passwords, on this hacked update. So tell me about this email.
Speaker 2: Well, this email, isn't unique. I get asked this sometimes weekly, sometimes quarterly, but constantly people who know me, ask me if this is a problem. And they pull out their phone or they forward me an email, and it says, hi, you know, John. We know your password is blah, and we know this, we know lots about you, and, you know, we've bugged a porn site, we've got, you know, some malware on your computer, whatever. There's always a different spin to the, manipulation in the email. But then they say, you know, pay us x Bitcoin or else, you know, or else. And, you know, whatever whatever the threat is, the or else is followed by.
Speaker 1: I wanna get to the password part of that. Sure. That seems like where the actual, meat of this is. But I did notice in researching these kinda emails that every single one, they put some sprinkles on top. They don't just say we have your password. We say we have your password, and we have webcam footage of you on important site. Sure. And we have leaked photos, and we have this other thing. Why do you think a hacker is reaching out to someone who has this, like, this little kinda nugget of information would add in this additional lie?
Speaker 2: I think it's, like, passive validation. Like, the you've they've validated that they know things about you by showing, you your password, and then they just assume that if they can, you know, sync the hook, they'll just believe whatever else they say.
Speaker 1: Right. Someone makes a claim like, yo, I have, like, webcam footage of you on some website. You're probably not gonna believe that. But if they proceeded with, like, hey, here's your password. I know this. Suddenly, all that stuff becomes, like, I don't know, passively validated.
Speaker 2: Well, the best thing is that everybody that forwards this to me, they all have the same thing. They say this is this is actually a password I used. Used. It's an old password. I haven't used it in a year or two, but it was a password that I used forever. And they know it, so, you know, should I take this seriously?
Speaker 1: I get an email saying, hey. Here's your password. Imagine what else we know about you. So if you don't want this getting out, send me some Bitcoin. What's actually happening there? Who are these people? How did they get this information? What's going on?
Speaker 2: Yeah. So a lot of high profile, data heists. I'll call them data heists because it sound cool. You know, if you go to haveibeenpwned.com, you can literally type in your email address, and it'll tell you which of the major data heists you've been a part of. So PlayStation Network, Ashley Madison, etcetera, etcetera. And what's happened is these, you know, data heists lead to these big piles of data that get spilled out on the Internet. And slowly and surely over time, you can run password crackers on the on the user table, like we talked about in the problem with passwords. And eventually, you get people's really like, real passwords. It might take years to pull them out, but you have them. And you also have their contact details and their emails and stuff like that because that's all part of kind of the user table. So, really, all this is is a bunch of people writing scripts to automate threats using, you know, data heist, data as the input for it. Does that make sense?
Speaker 1: Yeah. I think so. I I wanna dwell on that a little bit because I know we've talked about it in previous episodes, the form these leaks take, but that user table that you mentioned, that's the product of one of these leaks. When these leaks happen, that's what gets out in the world.
Speaker 2: Yeah. So, like, a lot of websites, anything that you log into, I call it a user table just because it's often called users in the database, but, essentially, it's a database. All of these websites have databases behind them. And to log into a website, there needs to be data inside of that website to validate that your username and password are real. So that's often stored in, you know, the quote unquote users table, which will have also your name and your email and anything else associated kinda with you as a user. So you know when you go on my account profile, edit profile, all of that detail, all of those fields are often in the user table.
Speaker 1: You mentioned having to use a password, like, kinda cracker on that on that file. Is that supposed stuff supposed to be encrypted? Is it supposed to be plain text? Like, I feel like there's there's what happened with Ashley Madison, which feels like both a failure of securing that table and a failure of the table as, like, a structural thing. Is that common? Is it typically just like, here's all your stuff in a file, or is it typically supposed to be, like, locked down even if that file gets out, it's protected in some other way?
Speaker 2: I wish I had a different answer for you, but no. The the passwords were encrypted even with Ashley Madison, but the the table itself should really never get public. That's the whole point of the hack and the heist is to get that highly confidential piece of information. Or often, it's just to get that piece of information. Also, the, like, you know, quote, unquote credit cards table would be sweet to grab too if you were in the database, and is often a prize target too. But you get enough user accounts. You get enough, you know, transactional data. You could probably do a pretty pretty good chunk of damage anyway. Mhmm.
Speaker 1: So the person responsible for getting the information out of Ashley Madison, the person who hacked that company, that's almost certainly not the same people that are sending out these emails.
Speaker 2: No. Almost certainly not. So who's The people who hacked Ashley Madison were probably highly skilled, hackers. And the people who are generating these Bitcoin scams are just scammers.
Speaker 1: What talk to me about those scammers. Like, what's their process here? Are they just going on somewhere on the dark web and finding this document?
Speaker 2: Yeah. They would have downloaded the data repository when it came out. I remember it was super public. Like, there was, I think, m I or were you on ashleymadison.com? Like, that website that spun up, like, hours later where you could, like, test your colleagues' emails and see who was on Ashley Madison. And it was like that data was very, very public. So they find these pieces of data. They download them, and they try and figure out something that, you know, they can use to passively validate a threat. Mhmm. And that is the encrypted password. If you run enough kind of password cracking and decryption against it, eventually, you're gonna get a pretty big swath of passwords because most people don't have great ones. And especially in today's kind of computing resources world, you know, you could, you know, be pretty aggressive in a brute force password crack and probably get a lot, especially with that many accounts.
Speaker 1: Right. So inside that document, so many of the passwords are something really easily guessable.
Speaker 2: Yeah. Password2018 Sure. Exclamation.
Speaker 1: I don't know who signed up for Ashley Madison in 2018. But
Speaker 2: Oh, whatever. 2013. I don't remember when the heist was.
Speaker 1: But it makes it easier for you to be able to reverse engineer, the rest of the passwords inside of that document.
Speaker 2: Yeah. And and, yeah, it's not a it's not a complicated process. There's great tools for it. And, you know, it'd be pretty easy, especially with some of the larger word lists that you can download. And we do talk about this in problems with passwords. You can download these monster dictionaries of, like, lexicons of, you know, all these words and combinations and variations of them and quickly run those against, any kind of password list you have and often get a lot of wins. Mhmm. So they probably did that as well.
Speaker 1: So we've got the person who originally hacked Ashley Madison over here. We've got the people that are sending emails to your friends saying, hey. I've got your password. Imagine what else I have. Send me a bunch of Bitcoin. The people doing the decryption, the people turning that user table into actionable passwords associated with emails. That's is that someone in the middle of those two people? Is that the original hacker, or is that something that even the scammers can just be
Speaker 2: Yeah. Even the scammer. That's almost certainly being done by the scammer. It's really not that complicated. It's actually the saddest part because it's the most vulnerable part or one of the most vulnerable parts in that chain is that you can essentially decrypt a password by encrypting words and comparing them against the encrypted version. Right. So it it's not two way encryption where they're not, like, actually unencrypting it, but they're just doing encrypt like, they just encrypt words over and over until they get something that matches, and then they know what the password is.
Speaker 1: Right. You've got this giant ream of encrypted passwords, and then you figure out what encryption tool it used. They used to generate it, and then you just start encrypting, like, the word password, the word Password2013, and whatever you get out of that, you just test that against your original table.
Speaker 2: Yeah. If they're the same, the password that you encrypted to compare against it is their password.
Speaker 1: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started. You can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 3: Ever wonder why scam calls feel so specific? Why they somehow already know your name, your city, or even your address? It's usually because of data brokers. These companies collect your personal information from across the Internet and sell it online, usually without you even realizing it. Things like your phone number, home address, family members, and even places you've lived. And once your information is out there, it spreads fast. That's where Aura comes in. Aura automatically finds your personal information on databurger sites and submits removal requests for you. Then, Aura keeps monitoring to help make sure your information stays gone. You can even see where your data was found and removed. And Aura goes beyond data removal. You also get a VPN, antivirus, password manager, spam call protection, dark web monitoring, and up to $5,000,000 in identity theft insurance. Right now, you can try Aura free at aura.com/hidden. That's aura.com/hidden.
Speaker 1: I feel like I know the answer to this. What do you do when you get one of these emails? It pops up. I know all this seedy stuff about you. Know how I know all that stuff. I have your e your password. What should you do with that email when you get it?
Speaker 2: Hit the delete key.
Speaker 1: Does it tell you that maybe you should think about any other accounts that might have used that password and go change them?
Speaker 2: Yeah. 100%. If you're still using that password, like, if your heart literally skips a beat because it's not your old password but your current password, then you might be dealing with something differently or something different, a different threat, or you you just haven't changed your password in forever. And if it's the latter, then you should probably go do that.
Speaker 1: Yeah. That leak was four or five years ago at this point. Why do you think that information is coming back again right now? Because there was a revival of it in 2018. There's been a surge of it now in the last couple months. Why do you think people keep going back to those old old pools of passwords? Is it just because people have forgotten about that original story and it might be relevant again? Like, can give me a little glimpse into the mind of the people running these scams.
Speaker 2: It's probably just, you know, them looking for new avenues to kind of brute force against. These people are looking to run, you know, quantity over quality scams, and they wanna run as many as they humanly can. So they're looking for any avenue to get any kind of leverage to cause people to think that they're in threat and crisis. Like, my phone rings four times a week threatening me with the IRS, you know. And it's all scammers. And, you know, it tricks some people. It doesn't trick me, but it tricks lots of people. And the reason why they keep doing it is because it works. Hey, everyone. This is two ish months of news updates. Not sure if you guys love them, hate them. We've heard some positive stuff. We haven't heard a ton of negative stuff. Love to know how you guys feel. Hit us up on Twitter at hack podcast. Yeah. If you're a patron, hit us up on Patreon.
Speaker 1: We're thinking about doing less kinda weekly update mini episodes and focusing on putting more time, more production value, more, like, structured storytelling into the big once a month episode. Sort of see what that sounds like. Maybe an occasional news update here and there, but really focusing on those as an experiment for a couple months. Hit us up if that sounds like what you'd like out of Hacked moving forward, and thank you for listening as we crack, you know, exactly what the show wants to be.
Speaker 4: You're great at protecting your data, but lots of places could still expose you to identity theft.
Speaker 3: I thought it was safe.
Speaker 4: If that happens, LifeLock gives you a US based restoration agent who will stick by your side from start to finish. Phone calls, filing documentation, preparing insurance claims, your agent handles it all. In fact, we're so confident restoration is guaranteed. Pour your money back. Isn't it nice to have someone like that on your side? Save up to 30% your first year at lifelock.com/podcast. Terms apply.
Speaker 5: The biggest tournament in soccer is finally here, and I've already started planning my watch parties. My go to move before kickoff is stopping at Total Wine and More to grab drinks for the whole crew. Wine, beer, seltzers, maybe a few ready to drink options. Everything we need for a full day of matches. With this many games, it definitely helps knowing you're getting the lowest prices. Total Wine makes it so easy because I can grab everything I need in one stop. Get match day ready with Total Wine and More today so you're set from kickoff to the final whistle. Spirits are not sold in Virginia and North Carolina. Drink responsibly. Must be 21.
Speaker 3: Shipping, billing, admin, payroll, marketing. You're managing all the things. So why waste time sending important documents the old fashioned way? Mail and ship when you want, how you want with stamps.com. Print postage on demand twenty four seven and schedule pickups from your office or home. Save up to 90% with automated rate shopping. That's why over 1,000,000 small businesses trust stamps.com. Go to stamps.com and use code podcast to try stamps.com risk free for 60 days.