DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Hackers Claim Breach Of Ku Klux Klan’s Security Company, Staminus (update2)

Posted on March 11, 2016 by Dissent

Thomas Fox-Brewster reports:

A website run by the Ku Klux Klan has been downed as part of what appears to be a significant breach of its host and security provider Staminus. The company, which promises to protect users from distributed denial of service (DDoS) attacks, was exposed by a crew going by the name of FTA, which leaked data online yesterday.

Dumped information included customer contact details and password hashes (the result of taking the plain text password on running it through a one-way algorithm to garble the text). The hackers also claimed to have accessed unencrypted credit card details, though FORBES could not verify that claim.

Read more on Forbes.

This is one of those situations where if you generally abhor hackers dumping personal information, but you hate the KKK or the organization whose member data got hacked, you may be tempted to silently cheer that the data were dumped.

Slippery slope.

Update: See also Brian Kreb’s coverage of this incident. This was a big breach and data dump, also impacting Intreppid (also offline as of this posting). Brian notes:

The authors of this particular e-zine indicated that they seized control over most or all of Staminus’s Internet routers and reset the devices to their factory settings. They also accuse Staminus of “using one root password for all the boxes,” and of storing customer credit card data in plain text, which is violation of payment card industry standards.

Staminus so far has not offered any additional details about what may have caused the outage, nor has it acknowledged any kind of intrusion.

Update 2: Staminus has released a statement:

To follow up on our communication from yesterday evening regarding the system outage, we can now confirm the issue was a result of an unauthorized intrusion into our network. As a result of this intrusion, our systems were temporarily taken offline and customer information was exposed. Upon discovering this attack, Staminus took immediate action including launching an investigation into the attack, notifying law enforcement and restoring our systems.

Based on the initial investigation, we believe that usernames, hashed passwords, customer record information, including name and contact information, and payment card data were exposed. It is important to note that we do not collect Social Security numbers or tax IDs.

While the investigation continues, we have and will continue to put additional measures into place to harden our security to help prevent a future attack. While the exposed passwords were protected with a cryptographic hash, we also strongly recommend that customers change their Staminus password.

I fully recognize that our customers put their trust in Staminus and, while we believe that the issue has been contained, we are continuing to take the appropriate steps needed to safeguard our clients’ information and enhance our data security policies.

There is also an FAQ on the incident with the statement, but it doesn’t really add much.

 

Category: Breach IncidentsExposureHackMiscellaneousOf NoteSubcontractorU.S.

Post navigation

← Plaintiffs Use Privacy Pledge Against Insurer in Data Breach Claim
Hacker picks 1-800-FLOWERS’ customers credit card info →

4 thoughts on “Hackers Claim Breach Of Ku Klux Klan’s Security Company, Staminus (update2)”

  1. Nola says:
    March 11, 2016 at 9:55 am

    No offense, but of course Forbes focused on the KKK. Hackers teal 30GB from anti-DDOS company, but Forbes puts KKK in the headline because they stole 200MB from them. Press these days…..

    1. Dissent says:
      March 11, 2016 at 10:31 am

      No offense taken at all. Most media sites go for headlines that they think will attract more readers.

  2. Michael says:
    March 11, 2016 at 10:41 am

    I fully agree with this. There was a helluva lot more data stolen than just on the KKK.

  3. hgg says:
    March 14, 2016 at 2:08 am

    This was fake look at the ezine in the mysql queries he miss spelt “where” and it still outputted results. i tried to post this on kreb’s comment section but he deleted the comment.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.